Business Associate Agreement
If your organization is a HIPAA Covered Entity and ATTENDING AI will create, receive, maintain, or transmit protected health information on your behalf, we need an executed Business Associate Agreement in place before any PHI touches the system. We treat this as a precondition of a pilot, not paperwork to catch up on later.
We will sign yours or provide ours. If your compliance team has standard BAA paper, send it — that is usually the fastest path. If you'd rather start from ours, ask and we'll send it over.
What our BAA covers
- Permitted uses and disclosures — limited to performing the services and to our own proper management and legal obligations.
- Safeguards — administrative, physical, and technical safeguards under the HIPAA Security Rule, including encryption in transit and at rest.
- Subcontractors — every subcontractor that touches PHI is bound by terms at least as protective as ours.
- Breach notification — prompt notice of any use or disclosure not permitted by the agreement, with the detail you need to meet your own notification obligations.
- Individual rights support — we support your responses to access, amendment, and accounting-of-disclosures requests.
- Return or destruction — at termination, PHI is returned or destroyed, or protections continue for as long as retention is required.
- No sale, no marketing, no model training — we do not sell PHI, do not use it for marketing, and do not permit AI vendors to train on it.
Subprocessors that may handle PHI
We will disclose the current, specific list during BAA negotiation. Categories:
| Category | Purpose | Status |
|---|---|---|
| Cloud infrastructure and database hosting | Running the application and storing records | BAA required before production use |
| AI model providers | Clinical language understanding and reasoning support | BAA required before production use |
| Error monitoring and observability | Fault diagnosis; configured to mask PHI | BAA required where PHI could be incidentally captured |
We will give you advance notice before adding a subprocessor that handles PHI, and you may object.
What to send us
- Legal entity name and entity type (practice, hospital, health system, other).
- Primary compliance contact, name and title.
- Whether you want to use your BAA paper or ours.
- Anticipated go-live date, so we can sequence the security review.
Security documentation
Provider organizations commonly ask for our security posture alongside the BAA. We can share our information security policy, access control policy, risk assessment, incident response plan, and business continuity plan under NDA. Ask when you request the BAA and we'll send the package together.