Effective date: August 12, 2026
This Business Associate Agreement ("BAA") is entered into between the clinic organization identified at onboarding ("Covered Entity" - or, where the clinic is itself a business associate of another covered entity, "Subcontracting Business Associate") and MDside AI LLC ("Business Associate" or "MDside"), and is incorporated into the Clinic Terms of Service (the "Agreement"). In conflict, this BAA controls as to Protected Health Information ("PHI").
1. Definitions
Capitalized terms not defined here have the meanings in the HIPAA Rules (45 CFR Parts 160 and 164), including Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic PHI, Individual, Minimum Necessary, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured PHI, and Use. "PHI" means Protected Health Information received from, or created, maintained, or transmitted on behalf of, Covered Entity.
2. Permitted uses and disclosures
Business Associate may use or disclose PHI only:
- To perform the services in the Agreement: receiving patient intake submissions, preparing cases for review, presenting them to licensed reviewing providers, recording decisions and clinical notes, returning decisions to Covered Entity's systems, hosting Covered Entity's storefront, and maintaining legally required records and audit logs;
- As Required by Law;
- For Business Associate's proper management and administration or to carry out its legal responsibilities, provided any disclosure for such purposes is Required by Law or made with reasonable assurances of confidentiality and breach notification from the recipient;
- To provide Data Aggregation services relating to Covered Entity's health care operations, if requested;
- To de-identify PHI in accordance with 45 CFR 164.514(a)-(c); de-identified information is no longer PHI. Business Associate de-identifies case data before automated (AI) processing as described in Section 3.
Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, will apply Minimum Necessary standards, and will not sell PHI, use PHI for marketing, or use PHI to train machine-learning models.
3. Automated processing disclosure
The parties acknowledge that, as part of the services, Business Associate prepares each case for provider review using automated tools: a preliminary safety screen and a draft clinical note. Before such processing, the case record is de-identified (patient name removed, date of birth converted to age, identifying patterns redacted from free text). The automated output is decision support for the reviewing provider; all approval decisions are made by licensed providers. Automated processing is performed through the subcontractors listed in Exhibit 1.
4. Obligations of Business Associate
Business Associate will:
- Not use or disclose PHI other than as permitted by this BAA or Required by Law;
- Implement administrative, physical, and technical safeguards that comply with the Security Rule (45 CFR Part 164 Subpart C) for Electronic PHI, including access controls scoped by organization and role, encryption in transit, and an append-only audit log of PHI access;
- Report to Covered Entity any Use or Disclosure not permitted by this BAA, any Security Incident of which it becomes aware, and any Breach of Unsecured PHI without unreasonable delay and in no case later than 5 business days after discovery, including the information required by 45 CFR 164.410 as it becomes available;
- Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as restrictive as this BAA (45 CFR 164.502(e)(1)(ii)); current Subcontractors are listed in Exhibit 1;
- Make PHI in a Designated Record Set available to Covered Entity as needed to satisfy an Individual's rights of access (164.524) and amendment (164.526), and incorporate amendments as directed; Individuals' requests received directly by Business Associate will be forwarded to Covered Entity;
- Maintain and make available to Covered Entity the information required for an accounting of disclosures under 164.528 (Business Associate's append-only audit log records access and disclosure events, including actor, action, subject, timestamp, and IP address);
- Make its internal practices, books, and records relating to PHI available to the Secretary for determining compliance;
- To the extent Business Associate carries out a Covered Entity obligation under Subpart E, comply with the requirements that apply to that obligation.
5. Obligations of Covered Entity
Covered Entity will: notify Business Associate of limitations in its notice of privacy practices, of changes in or revocation of an Individual's permission, and of restrictions it has agreed to under 164.522, in each case to the extent they affect Business Associate's use or disclosure; not request uses or disclosures that would violate Subpart E; obtain any consents or authorizations needed before submitting PHI; and submit only the Minimum Necessary PHI through the platform's intake.
6. Term and termination
- This BAA is effective on acceptance and continues while Business Associate holds PHI under the Agreement.
- Either party may terminate the Agreement for the other's material breach of this BAA that is not cured within 30 days of written notice; if cure is infeasible, termination is immediate.
- On termination, Business Associate will return or destroy all PHI if feasible. The parties acknowledge that return or destruction is infeasible for records subject to legal retention obligations (including the 7-year clinical record retention and audit logs); Business Associate will extend the protections of this BAA to such retained PHI, limit further use and disclosure to the purposes making return infeasible, and destroy or return the PHI when retention obligations lapse.
7. Miscellaneous
A reference to a HIPAA section means it as amended. The parties will amend this BAA as needed for HIPAA compliance. Ambiguities are interpreted to permit compliance with HIPAA. Nothing in this BAA creates third-party beneficiary rights, or an agency relationship between the parties.
Exhibit 1 - Subcontractors
| Subcontractor | Function | PHI exposure | BAA in place |
|---|---|---|---|
| Neon, Inc. | Database hosting | Full database | Yes |
| Vercel, Inc. | Application hosting and file storage | PHI in transit through compute; prescription PDFs at rest in private Blob storage | Yes |
| Vercel, Inc. (AI Gateway) | Automated processing gateway | De-identified case data only (no PHI by design) | Covered by the Vercel BAA |
| Resend | Transactional email | None by design (notification + link) | Not required - receives no PHI |
This exhibit must be kept current: engaging a Subcontractor that creates, receives, maintains, or transmits PHI requires an updated exhibit and notice to Covered Entity before the Subcontractor handles PHI.