Legal
Business Associate Agreement
Last updated: 8 August 2026
A Business Associate Agreement (BAA) is available to enterprise customers and is signed before any protected health information (PHI) is processed. This summary describes the obligations a signed BAA sets out; the executed agreement controls.
Permitted uses
We use and disclose PHI only to provide the service as instructed by the customer, and as permitted by HIPAA. We do not use PHI for our own purposes.
Safeguards
We maintain administrative, physical, and technical safeguards, including encryption in transit and at rest, access controls, and audit logging, to protect PHI.
Breach notification
We notify the customer without unreasonable delay of any breach of unsecured PHI, with the information needed to meet their obligations.
Subcontractors
Any subcontractor that handles PHI is bound by terms at least as protective as this agreement.
Access, amendment, and return
We support the customer's obligations to provide individuals access to and amendment of their PHI, and we return or destroy PHI on termination where feasible.
Requesting a BAA
To request a signed BAA, contact hello@agilimed.com.