# Business Associate Agreement (BAA) — Medroxa

**Last updated:** July 2026

This Business Associate Agreement ("**BAA**") supplements the [Terms of Service](/legal/terms-of-service.md) and [Privacy Policy](/legal/privacy-policy.md) when a **Covered Entity** or **Business Associate** (as defined under HIPAA) uses Medroxa to process **Protected Health Information (PHI)** on behalf of patients.

> **Template notice:** This document is a technical compliance template for enterprise deployments. Execute a countersigned BAA with qualified legal counsel before processing PHI in production.

---

## 1. Definitions

- **Covered Entity** — A health plan, health care clearinghouse, or health care provider that transmits health information in electronic form in connection with a HIPAA-covered transaction.
- **Business Associate** — Medroxa and its authorized subprocessors that create, receive, maintain, or transmit PHI on behalf of the Covered Entity.
- **PHI** — Individually identifiable health information as defined in 45 C.F.R. § 160.103.

---

## 2. Permitted uses and disclosures

Medroxa will use and disclose PHI **only** to:

- Provide clinical decision-support services authorized by the Covered Entity
- Perform data aggregation services as permitted under 45 C.F.R. § 164.504(e)(2)(i)(B)
- Carry out legal responsibilities of the Business Associate, subject to Section 3

Medroxa will **not** use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by the Covered Entity.

---

## 3. Safeguards

Medroxa agrees to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, including:

| Control | Description |
| ------- | ----------- |
| **Encryption** | TLS in transit; encryption at rest where PHI storage is enabled |
| **Access controls** | Role-based authentication; session management; least-privilege access |
| **Audit logging** | Access events logged without retaining clinical prompt content by default |
| **De-identification guidance** | UI warnings requiring de-identified inputs unless PHI processing is authorized |
| **Subprocessor disclosure** | AI processors (Microsoft Azure OpenAI), STT, and auth/billing vendors disclosed in Privacy Policy |

---

## 4. Reporting and breach notification

Medroxa will report to the Covered Entity any **Security Incident** or **Breach of Unsecured PHI** without unreasonable delay and in no case later than **60 days** after discovery, including:

- Nature of the breach and PHI involved
- Steps taken to mitigate harm
- Contact point for further information

---

## 5. Subcontractors

Medroxa may engage subprocessors (e.g., cloud AI, speech-to-text, authentication) that create, receive, maintain, or transmit PHI. Medroxa will:

- Ensure subprocessors agree to the same restrictions and conditions
- Maintain a current list in the [Privacy Policy](/legal/privacy-policy.md)
- Provide **60 days' notice** before adding a new subprocessor where contractually required

**Note:** Stripe processes billing data only, not clinical PHI in prompts. Azure OpenAI PHI processing requires an eligible Microsoft BAA and compliant deployment configuration.

---

## 6. Access, amendment, and accounting

Upon request, Medroxa will:

- Make PHI available for access, amendment, and accounting as required by 45 C.F.R. §§ 164.524, 164.526, and 164.528
- Incorporate amendments to PHI as directed by the Covered Entity
- Document disclosures as required for an accounting of disclosures

---

## 7. Return or destruction of PHI

Upon termination of services, Medroxa will return or destroy all PHI received from, or created on behalf of, the Covered Entity where feasible. If return or destruction is infeasible, Medroxa will extend the protections of this BAA to such PHI and limit further uses and disclosures.

**Default deployment:** Clinical content in tool forms is processed in server memory for the duration of the request and is **not stored in a clinical database** unless explicitly configured for enterprise retention.

---

## 8. Obligations of the Covered Entity

The Covered Entity agrees to:

- Provide only PHI that Medroxa needs to perform services
- Notify Medroxa of any limitations on use or disclosure
- Ensure workforce members use de-identified data unless PHI processing is authorized
- Not use Medroxa outputs as definitive diagnosis, prescribing, or treatment without licensed clinician verification

---

## 9. Term and termination

This BAA is effective upon account creation or countersignature (whichever applies) and terminates when all PHI is returned or destroyed, or when the underlying service agreement ends.

Either party may terminate if the other party materially breaches this BAA and fails to cure within **30 days** of written notice.

---

## 10. Regulatory references

This BAA is intended to satisfy the requirements of **45 C.F.R. § 164.504(e)** and applicable provisions of the HIPAA Privacy and Security Rules.

---

## 11. Contact

For BAA execution, compliance questions, or breach reporting:

**Mohammadamin Asadirad**  
Cell: (209) 684-2978  
Cell: (925) 529-2345  
Email: [support@medroxa.com](mailto:support@medroxa.com)

---

*Consult qualified legal counsel before relying on this template. Medroxa does not provide legal advice.*
