BAA
Business Associate Agreement
Between you (Covered Entity) and Honest Comply, the service operated by Peakstone Innovations LLC (Business Associate).
1. Purpose
This Business Associate Agreement governs the handling of Protected Health Information that may be created, received, maintained, or transmitted by Honest Comply on behalf of Covered Entity. It is executed pursuant to 45 CFR 164.504(e) and the HITECH Act.
2. Permitted uses and disclosures
Business Associate may use or disclose PHI only as necessary to perform the services described in the Terms of Service, as authorized by Covered Entity in writing, or as required by law.
3. Safeguards
Business Associate will implement administrative, physical, and technical safeguards (45 CFR 164.308, 164.310, 164.312) appropriate to protect the confidentiality, integrity, and availability of PHI. This includes encryption at rest (Supabase Postgres + Storage), encryption in transit (TLS 1.2+), audit logging, and role-based access control.
4. Breach notification
Business Associate will notify Covered Entity of any breach of unsecured PHI without unreasonable delay and in no case later than 30 days after discovery. Notice will include the information required by 45 CFR 164.410(c).
5. Subcontractors
Business Associate will require all subcontractors that receive PHI (Supabase, Stripe, Resend, Vercel, Anthropic) to enter into a written agreement no less protective than this BAA. Current subcontractor BAAs are maintained at /security.
6. Termination
On termination, Business Associate will return or destroy all PHI it maintains on behalf of Covered Entity and retain no copies, except where return or destruction is infeasible, in which case Business Associate will extend the protections of this BAA to that PHI and limit further uses and disclosures. Compliance documentation and audit logs that are not PHI (for example, training-completion records) are retained on Covered Entity's behalf for the period stated in the Privacy Policy.
7. Effective date
This BAA is effective as of the date Covered Entity completes checkout and remains in effect for the duration of the subscription, plus the survival periods stated above.
8. Required terms (45 CFR 164.504(e)(2))
Business Associate will: make PHI available to Covered Entity as needed to satisfy individuals' rights of access (45 CFR 164.524), amendment (164.526), and accounting of disclosures (164.528); mitigate, to the extent practicable, any harmful effect of an improper use or disclosure of PHI; report security incidents and breaches of which it becomes aware; and make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining Covered Entity's compliance.
9. Limitation of liability and indemnity
Each party will defend and indemnify the other only for third-party claims to the extent caused by that party's own breach of this BAA, negligence, or willful misconduct in handling PHI. Neither party indemnifies the other for the other party's own acts or omissions. Each party's aggregate liability under this BAA is capped at the fees paid by Covered Entity in the trailing twelve (12) months, and excludes any civil monetary penalty, settlement, or resolution amount assessed against Covered Entity by HHS or OCR, which is imposed on Covered Entity by statute and cannot be transferred by contract. Neither party is liable for indirect, consequential, or punitive damages.
10. No third-party beneficiaries
Nothing in this BAA creates any rights in any third party, including any patient, individual, workforce member, or member of the public. There are no third-party beneficiaries of this BAA. HIPAA provides no private right of action, and nothing in this BAA is intended to create one. Enforcement rights run solely between Covered Entity and Business Associate.
11. Minimum necessary
Business Associate will request, use, and disclose only the minimum necessary PHI to perform the Services. The workforce roster is limited to each member's name, work email, and role.
