ABANOTES LLC
BUSINESS ASSOCIATE AGREEMENT
Version 1.0
Publication Date: July 31, 2026
Status: Draft for Attorney Review — Not Effective Until Approved and Executed
Document Control
| Field | Information |
|---|---|
| Document Owner | ABANotes LLC — Legal and Compliance |
| Document Title | Business Associate Agreement |
| Version | 1.0 |
| Publication Date | July 31, 2026 |
| Primary Legal Contact | legal@abanotes.ai |
| Privacy Contact | privacy@abanotes.ai |
| Security and Incident Contact | security@abanotes.ai |
| Related Agreement | ABANotes Master Subscription Agreement, Version 1.0 |
| Related Policies | Security Overview; Subprocessor List; Data Retention and Destruction Policy; Incident Response & Breach Notification Policy; AI Use & Human Oversight Policy; Disaster Recovery Overview; Business Continuity Summary |
Revision History
| Version | Date | Description | Approved By |
|---|---|---|---|
| 1.0 | July 31, 2026 | Initial attorney-review draft for commercial launch | Pending |
Table of Contents
- Definitions
- Applicability and Relationship to the MSA
- Permitted Uses and Disclosures of PHI
- Prohibited Uses and Disclosures
- Safeguards
- Subcontractors
- Security Incidents
- Breach Notification
- Individual Rights Support
- Governmental and Legal Requests
- Minimum Necessary and Data Minimization
- Electronic PHI, Cloud Services, and Mobile Access
- AI Processing of PHI
- Compliance Documentation and Audit Cooperation
- Customer Obligations
- Term and Termination
- Return or Destruction of PHI
- Miscellaneous
Signature Page
Appendix A — Permitted Uses Matrix
Appendix B — Security Safeguards Summary
Appendix C — Subprocessor Categories
Appendix D — Incident Reporting Contacts
Appendix E — Return and Destruction Procedures
This Business Associate Agreement (the “BAA”) is entered into by and between ABANotes LLC, a Florida limited liability company with an address at 8821 NW 153 Terrace, Miami Lakes, Florida 33018 (“ABANotes”), and the customer identified in the applicable Order Form or signature block (“Customer”). ABANotes and Customer may each be a “Party” and together the “Parties.”
This BAA is incorporated into and forms part of the ABANotes Master Subscription Agreement, Version 1.0 (the “MSA”). Except as expressly modified by this BAA, the MSA remains in full force and effect. If there is a conflict concerning Protected Health Information, HIPAA obligations, Security Incidents involving PHI, or Breach notification obligations, this BAA controls. Commercial terms, fees, service levels, intellectual-property rights, indemnification, limitations of liability, insurance, dispute resolution, and other matters not expressly modified by this BAA remain governed by the MSA and applicable Order Form.
Customer may be a Covered Entity or a Business Associate. ABANotes acts as Customer’s Business Associate or subcontractor Business Associate, as applicable, when ABANotes creates, receives, maintains, or transmits PHI on Customer’s behalf. The Parties intend this single BAA to satisfy the requirements applicable to either relationship.
1. Definitions
1.1 Incorporation of HIPAA Definitions
Capitalized terms not defined in this BAA have the meanings given in the MSA. The following terms have the meanings assigned in HIPAA: Breach, Business Associate, Covered Entity, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use. Any reference to a regulatory section includes its successor provision.
1.2 “Applicable Privacy and Security Law”
“Applicable Privacy and Security Law” means HIPAA and any other federal or state privacy, security, data-breach, health-record, or confidentiality law applicable to a Party’s performance under this BAA, including, when applicable, section 501.171, Florida Statutes.
1.3 “Discovery” or “Discovered”
A Breach is “Discovered” on the first day it is known to ABANotes or, by exercising reasonable diligence, would have been known to ABANotes. ABANotes is deemed to have knowledge when the Breach is known, or by reasonable diligence would have been known, to any workforce member or agent other than the person committing the Breach, consistent with 45 C.F.R. § 164.410(a)(2).
1.4 “HIPAA”
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164, each as amended.
1.5 “PHI” and “ePHI”
“PHI” means Protected Health Information that ABANotes creates, receives, maintains, or transmits on Customer’s behalf under the MSA. “ePHI” means the electronic form of such PHI. PHI does not include information that no longer constitutes PHI under HIPAA, including information properly de-identified under 45 C.F.R. § 164.514.
1.6 “Reportable Security Incident”
“Reportable Security Incident” means a Security Incident involving PHI that results in, or creates a material risk of, unauthorized access, Use, Disclosure, modification, destruction, loss, or unavailability of PHI. It does not include Routine Unsuccessful Security Activity unless that activity results in unauthorized access, Use, Disclosure, modification, destruction, loss, or material interference with system operations.
1.7 “Routine Unsuccessful Security Activity”
“Routine Unsuccessful Security Activity” means unsuccessful pings, port scans, login attempts, denial-of-service attempts, malware blocked by controls, and similar unsuccessful events that do not result in unauthorized access, Use, Disclosure, modification, destruction, loss, or material interference with system operations.
2. Applicability and Relationship to the MSA
2.1 Effective Date
This BAA becomes effective on the earliest of: (a) the date of the last signature below; (b) the effective date stated in an Order Form that expressly incorporates this BAA; or (c) the date ABANotes first creates, receives, maintains, or transmits PHI on Customer’s behalf after both Parties have accepted this BAA (the “BAA Effective Date”).
2.2 Scope
This BAA applies only to PHI that ABANotes creates, receives, maintains, or transmits on Customer’s behalf in connection with the Services, including the ABANotes web application and supported My ABANotes iOS and Android applications. It applies regardless of whether Customer is acting as a Covered Entity or Business Associate.
2.3 Customer as Business Associate
If Customer is a Business Associate, references in this BAA to obligations owed to a Covered Entity mean obligations owed to Customer to the extent required for Customer to satisfy its agreement with the applicable upstream Covered Entity. Customer represents that its instructions to ABANotes are consistent with Customer’s obligations to that Covered Entity and that Customer has authority to engage ABANotes as a subcontractor Business Associate.
2.4 Excluded Data and Environments
This BAA does not apply to data that is not PHI, data properly de-identified under HIPAA, or data submitted to a feature or environment that ABANotes has expressly identified as not approved for PHI. Customer must not submit PHI to a beta, preview, development, testing, or other non-production environment unless ABANotes expressly confirms in writing that the environment is approved for PHI and covered by this BAA.
2.5 No Expansion of Services
This BAA does not require ABANotes to perform a service or support a workflow not included in the applicable Order Form or MSA. It governs PHI handled through the Services Customer has purchased.
3. Permitted Uses and Disclosures of PHI
3.1 Services for Customer
ABANotes may Use and Disclose PHI only as necessary to perform the Services for Customer and as permitted by this BAA, the MSA, Customer’s documented instructions, and Applicable Privacy and Security Law. Permitted activities may include hosting, storing, organizing, displaying, transmitting, backing up, restoring, securing, troubleshooting, supporting, exporting, and deleting PHI; enabling clinical and administrative workflows; and processing PHI through approved AI-assisted features at Customer’s direction.
3.2 Management and Administration
ABANotes may Use PHI for its proper management and administration or to carry out its legal responsibilities only when the Use is permitted by 45 C.F.R. § 164.504(e)(4). ABANotes may Disclose PHI for those purposes only if the Disclosure is Required by Law or ABANotes obtains reasonable written assurances from the recipient that the PHI will remain confidential, will be Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed, and the recipient will notify ABANotes of any known compromise of confidentiality.
3.3 Data Aggregation
ABANotes may provide Data Aggregation services relating to Customer’s Health Care Operations only to the extent expressly authorized by Customer and permitted by HIPAA. ABANotes may create de-identified information in accordance with 45 C.F.R. § 164.514. Once properly de-identified, such information is not PHI; its use remains subject to the MSA’s restrictions on de-identified and aggregated data.
3.4 Required by Law
ABANotes may Use or Disclose PHI as Required by Law, subject to Article 10 and the limits of HIPAA. Where legally permitted, ABANotes will notify Customer before the Disclosure and will disclose only the legally required portion.
3.5 Customer Instructions
ABANotes may act on Customer’s documented instructions if the resulting Use or Disclosure would be permissible for Customer under HIPAA. ABANotes will not comply with an instruction that ABANotes knows would violate HIPAA. The Parties will cooperate in good faith to identify a lawful alternative.
3.6 No Impermissible Use by Customer
ABANotes is not required to make any Use or Disclosure that would violate HIPAA if made by Customer, except for Uses and Disclosures expressly permitted to a Business Associate for its proper management and administration, legal responsibilities, or Data Aggregation under this BAA and HIPAA.
4. Prohibited Uses and Disclosures
4.1 General Prohibition
ABANotes will not Use or Disclose PHI except as permitted or required by this BAA or Required by Law. ABANotes will not permit PHI to be Used in a manner that would violate the HIPAA Privacy Rule if done by Customer, except as expressly permitted for a Business Associate.
4.2 No Sale, Marketing, or Advertising
ABANotes will not sell PHI; receive remuneration in exchange for PHI except as permitted by HIPAA; Use PHI for marketing or targeted advertising; create marketing profiles from PHI; or disclose PHI to a data broker, advertiser, or unrelated commercial party without Customer’s prior written direction and any authorization required by law.
4.3 No General-Purpose AI Training
ABANotes will not Use Customer PHI to train a general-purpose artificial-intelligence or machine-learning model. ABANotes will contractually restrict approved AI subprocessors from using Customer PHI to train general-purpose models, except where Customer expressly directs and lawfully authorizes that use in a separate written agreement signed by authorized representatives of both Parties.
4.4 No Re-identification
ABANotes will not attempt to re-identify information properly de-identified under HIPAA, except as permitted by law to test the effectiveness of de-identification safeguards and subject to appropriate controls.
4.5 No Unauthorized Secondary Use
ABANotes will not Use PHI for an independent purpose unrelated to providing, securing, supporting, or lawfully administering the Services. Product analytics and service improvement involving PHI are permitted only to the extent necessary to operate and improve the Services for Customer and consistent with HIPAA; analytics used for broader purposes must be properly de-identified or aggregated as required by the MSA.
5. Safeguards
5.1 General Safeguards
ABANotes will use appropriate administrative, physical, and technical safeguards to prevent Use or Disclosure of PHI other than as provided by this BAA. ABANotes will comply with the applicable requirements of the HIPAA Security Rule with respect to ePHI.
5.2 Security Program
ABANotes will maintain a written information-security program reasonably designed to protect the confidentiality, integrity, and availability of ePHI. The program will include, as applicable to ABANotes’ risk profile and Services:
- risk analysis and risk-management processes;
- assigned security responsibility;
- workforce authorization, training, confidentiality, and sanction controls;
- identity, authentication, role-based access, and least-privilege controls;
- access review and termination procedures;
- audit logging, security monitoring, and incident response;
- encryption in transit and at rest, where reasonable and appropriate;
- secure configuration, change management, vulnerability management, and malware protection;
- backup, contingency, disaster-recovery, and business-continuity processes;
- vendor risk management and subcontractor oversight;
- facility, workstation, device, and media controls appropriate to ABANotes’ operations; and
- periodic evaluation and documentation required by HIPAA.
5.3 Security Measures, Not Absolute Guarantees
ABANotes will maintain the safeguards described in this BAA, the Security Overview, and Applicable Privacy and Security Law. No security measure eliminates all risk. Descriptions of safeguards are commitments to maintain reasonable and appropriate controls, not a warranty that a Security Incident or Breach can never occur.
5.4 Mitigation
To the extent practicable, ABANotes will mitigate known harmful effects of any Use or Disclosure of PHI by ABANotes or its subcontractors in violation of this BAA.
5.5 Documentation and Retention
ABANotes will maintain policies, procedures, and documentation required of it under HIPAA for the period required by 45 C.F.R. § 164.316(b) or other Applicable Privacy and Security Law.
6. Subcontractors
6.1 Authorization
Customer authorizes ABANotes to engage subcontractors to perform the Services, subject to this Article and the MSA’s Subprocessor provisions. Material subprocessors and their functions will be identified in ABANotes’ then-current Subprocessor List.
6.2 Downstream Obligations
Before a subcontractor creates, receives, maintains, or transmits PHI on ABANotes’ behalf, ABANotes will enter into a written agreement requiring the subcontractor to comply with restrictions, conditions, and requirements that apply to ABANotes with respect to that PHI, including applicable HIPAA Security Rule requirements and Breach-reporting duties.
6.3 Responsibility
ABANotes remains responsible for the performance of its subcontractors to the extent required by the MSA, this BAA, and Applicable Privacy and Security Law. Use of a subcontractor does not relieve ABANotes of its obligations under this BAA.
6.4 Changes
Notice of material subprocessor changes and Customer’s objection rights are governed by the MSA and Subprocessor List. ABANotes will not authorize a new subprocessor to process PHI before required contractual protections are effective.
6.5 Approved Configurations
ABANotes will permit PHI to be processed only through service configurations it has approved for the applicable PHI workflow. A vendor’s general availability or public claim of HIPAA eligibility does not, by itself, authorize PHI processing.
7. Security Incidents
7.1 Incident Identification and Response
ABANotes will maintain procedures to identify, investigate, contain, mitigate, remediate, document, and, where required, report Security Incidents involving PHI.
7.2 Reportable Security Incidents
ABANotes will report a Reportable Security Incident to Customer without unreasonable delay and, unless a shorter period is required by Applicable Privacy and Security Law or the incident constitutes a Breach governed by Article 8, no later than ten (10) business days after ABANotes confirms that a Reportable Security Incident occurred. An initial report may be based on information reasonably available at that time and may be supplemented as the investigation continues.
ABANotes will also report any Use or Disclosure of PHI not provided for by this BAA of which ABANotes becomes aware, even if the event is not ultimately determined to be a Breach. The report will be made without unreasonable delay and within the same ten-business-day contractual period unless Article 8 or a shorter legal deadline applies.
7.3 Report Content
To the extent known and legally permitted, a report will include: (a) the nature of the incident; (b) the dates of occurrence and discovery; (c) the categories of PHI and systems involved; (d) known or reasonably suspected effects; (e) containment and mitigation measures; (f) actions reasonably requested of Customer; and (g) a contact for follow-up.
7.4 Routine Unsuccessful Security Activity
Customer acknowledges that Routine Unsuccessful Security Activity occurs continuously. This Section constitutes notice of such activity, and ABANotes is not required to report each event individually. ABANotes will maintain appropriate monitoring and will provide summary information when reasonably requested and available, subject to security and confidentiality restrictions.
7.5 Cooperation and Preservation
The Parties will cooperate in good faith to investigate a Reportable Security Incident, preserve relevant evidence, coordinate communications, and avoid actions that would unreasonably compromise containment, investigation, privilege, law-enforcement activity, or system security.
7.6 No Premature Admission
An incident report is not an admission that a Breach occurred, that PHI was compromised, or that ABANotes violated law or this BAA. Breach determinations will be made under Article 8 and Applicable Privacy and Security Law.
8. Breach Notification
8.1 Notification Duty
Following Discovery of a Breach of Unsecured PHI, ABANotes will notify Customer without unreasonable delay and no later than ten (10) calendar days after Discovery, except to the extent a law-enforcement delay permitted by 45 C.F.R. § 164.412 applies. This contractual ten-day period is intended to provide Customer time to meet its own obligations and does not extend any shorter deadline under Applicable Privacy and Security Law.
8.2 Initial and Supplemental Notice
ABANotes will not delay the initial notice solely because complete information is unavailable. ABANotes may provide information in phases and will supplement the notice without unreasonable delay as material information becomes available.
8.3 Required Information
To the extent known, ABANotes’ notice will include the information required by 45 C.F.R. § 164.410(c), including:
- identification of each affected or potentially affected Individual, if known;
- a brief description of what happened, including the date of the Breach and date of Discovery, if known;
- the types of Unsecured PHI involved;
- known unauthorized recipients or acquisition, access, Use, or Disclosure;
- steps ABANotes has taken or plans to take to investigate, contain, mitigate, and protect against further harm;
- information reasonably available to support Customer’s notices to Individuals, HHS, regulators, media, or others; and
- a contact for follow-up.
8.4 Risk Assessment
Unless an impermissible Use or Disclosure is presumed to be a Breach or clearly falls within an exception, ABANotes will support a risk assessment consistent with 45 C.F.R. § 164.402. The Parties will exchange information reasonably necessary for Customer to make any determination legally assigned to Customer. Neither Party will unreasonably withhold relevant facts.
8.5 Notification Responsibility
Unless the Parties agree otherwise in writing or Applicable Privacy and Security Law directly requires ABANotes to notify, Customer is responsible for determining and making notifications to affected Individuals, HHS, state authorities, media, or other third parties. ABANotes will not issue a public statement naming Customer or communicate with affected Individuals about the Breach without Customer’s prior written approval, unless Required by Law.
8.6 Cooperation and Costs
ABANotes will reasonably cooperate with Customer’s investigation, risk assessment, notifications, mitigation, regulatory response, and remediation. Allocation of costs, indemnification, and liability arising from a Breach is governed by the MSA and Applicable Privacy and Security Law; this BAA does not create an uncapped remedy or alter the MSA’s liability provisions.
8.7 Florida and Other State Requirements
Each Party will comply with state breach-notification duties directly applicable to it. When section 501.171, Florida Statutes, or another state law imposes obligations relating to an event involving PHI, the Parties will cooperate so the legally responsible Party can meet applicable content, timing, regulator-notification, and recordkeeping requirements.
9. Individual Rights Support
9.1 Access to PHI
If ABANotes maintains PHI in a Designated Record Set, ABANotes will make that PHI available to Customer in the time and manner reasonably requested by Customer so Customer can satisfy 45 C.F.R. § 164.524. Unless Customer expressly authorizes direct fulfillment in writing, ABANotes will refer an Individual requesting access to Customer and will not independently determine the Individual’s right of access.
9.2 Electronic Access and Fees
ABANotes will provide PHI in the electronic form and format supported by the Services or, if not readily producible in the requested form and format, in another readable form reasonably agreed with Customer, to the extent required by HIPAA. Any fee charged for special work will be consistent with the MSA and Applicable Privacy and Security Law and will not prevent Customer from meeting a legally required access obligation.
9.3 Amendment
If ABANotes maintains PHI in a Designated Record Set, ABANotes will make PHI available for amendment and incorporate amendments as directed by Customer in accordance with 45 C.F.R. § 164.526. Customer retains responsibility for deciding whether to accept or deny an amendment request unless the Parties expressly agree otherwise.
9.4 Accounting of Disclosures
ABANotes will document Disclosures of PHI and information relating to those Disclosures as necessary for Customer to respond to a request for an accounting under 45 C.F.R. § 164.528. ABANotes will provide the information to Customer within twenty (20) calendar days after a reasonably detailed written request, or sooner when reasonably necessary for Customer to meet a legal deadline.
9.5 Restrictions
Customer will notify ABANotes of any restriction on the Use or Disclosure of PHI under 45 C.F.R. § 164.522 that applies to ABANotes. ABANotes will comply with the restriction to the extent Customer identifies the affected PHI and ABANotes can reasonably implement the restriction within the Services. If ABANotes cannot implement it, ABANotes will promptly notify Customer so the Parties can identify a lawful alternative.
9.6 Confidential Communications
Customer is responsible for receiving and evaluating requests for confidential communications. ABANotes will reasonably support Customer’s implementation of an accepted request when the applicable workflow is supported by the Services and Customer provides clear instructions.
9.7 Notices and Authorizations
Customer will notify ABANotes of limitations in Customer’s Notice of Privacy Practices and of changes in, or revocation of, an Individual’s authorization to the extent the limitation or change may affect ABANotes’ Use or Disclosure of PHI.
9.8 Delegated Privacy Rule Duties
To the extent the Parties expressly agree in writing that ABANotes will carry out one or more of Customer’s obligations under the HIPAA Privacy Rule, ABANotes will comply with the requirements of the Privacy Rule that apply to Customer in performing the delegated obligation. No Privacy Rule obligation is delegated merely because the Services provide tools that Customer may use to perform it.
10. Governmental and Legal Requests
10.1 HHS Access
ABANotes will make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received on behalf of, Customer available to the Secretary for purposes of determining Customer’s or ABANotes’ compliance with HIPAA, in the time and manner designated by the Secretary.
10.2 Legal Process and Government Requests
ABANotes may respond to a subpoena, court order, warrant, administrative demand, or other governmental request only as permitted or required by Applicable Privacy and Security Law. To the extent legally permitted, ABANotes will promptly notify Customer, give Customer a reasonable opportunity to seek protective relief, and disclose only the minimum information legally required.
10.3 Regulatory Investigations
ABANotes will reasonably cooperate with Customer in responding to a lawful HHS Office for Civil Rights inquiry, audit, or investigation relating to ABANotes’ performance under this BAA. ABANotes may communicate directly with regulators and obtain its own counsel. Neither Party may make a representation on behalf of the other without authorization.
10.4 Confidentiality and Privilege
Cooperation under this Article does not require either Party to waive attorney-client privilege, work-product protection, or another applicable protection. The Parties will use reasonable efforts to provide non-privileged factual information needed for compliance.
11. Minimum Necessary and Data Minimization
11.1 ABANotes Obligations
ABANotes will request, Use, and Disclose only the minimum PHI reasonably necessary to accomplish the intended purpose, to the extent the HIPAA Minimum Necessary standard applies. ABANotes will use role-based permissions, workforce authorization, and process controls reasonably designed to limit PHI access to personnel and subcontractors who require it for authorized duties.
11.2 Customer Obligations
Customer determines the minimum PHI necessary for its workflows and is responsible for configuring user roles, limiting AI Input, assigning clients and care teams, and preventing unnecessary PHI from being entered into free-text fields, support tickets, exports, or integrations.
11.3 Exceptions
The Minimum Necessary standard will not be applied where HIPAA provides that it does not apply, including certain Disclosures for treatment, to the Individual, pursuant to an authorization, to HHS for enforcement, Required by Law, or required for HIPAA compliance.
12. Electronic PHI, Cloud Services, and Mobile Access
12.1 Cloud Processing
Customer authorizes ABANotes to host and process ePHI through cloud infrastructure providers identified in the Subprocessor List. ABANotes will use written agreements and approved service configurations appropriate for PHI and will maintain the safeguards required by this BAA.
12.2 Encryption
ABANotes will use industry-standard encryption to protect ePHI in transit over public networks and at rest in production systems where reasonable and appropriate, as described in the Security Overview. Encryption does not replace access control, authentication, logging, backup, incident response, or other required safeguards.
12.3 Access Controls and Audit Logs
ABANotes will maintain authentication and role-based access controls reasonably designed to restrict ePHI to authorized users. ABANotes will maintain audit and activity logging for material events supported by the Services, which may include authentication, access attempts, record creation or modification, signatures, deletions, exports, permission changes, and administrative changes. Log availability, retention, and customer access are governed by the MSA, Security Overview, Documentation, and applicable Order Form.
12.4 Mobile Applications
This BAA applies to PHI accessed through supported My ABANotes mobile applications. ABANotes will apply safeguards appropriate to mobile access within the application and ABANotes-controlled services. Customer remains responsible for mobile-device management, device passcodes, operating-system updates, physical possession, user training, network security, local downloads, screenshots, notifications, and other device settings outside ABANotes’ control.
12.5 Backups and Continuity
ABANotes will maintain backup, disaster-recovery, and business-continuity processes described in its then-current policies. Backup media containing PHI will remain protected and will not be restored for routine business use except as necessary for disaster recovery, security recovery, legal necessity, or another purpose permitted by this BAA and Applicable Privacy and Security Law.
12.6 Customer-Controlled Systems
Once Customer exports, downloads, prints, transmits, or integrates PHI outside the Services, Customer is responsible for the security of the destination device, system, recipient, transmission method, and retained copy, except to the extent ABANotes controls the applicable transmission or integration.
13. AI Processing of PHI
13.1 Assistive Processing
AI-assisted features are drafting and workflow aids. They may help generate, transform, organize, summarize, or review clinical and administrative text. They do not replace clinical judgment, establish medical necessity, determine coding, verify that services occurred, or create a final medical record without the human review required by the MSA.
13.2 Customer Authorization
Customer authorizes ABANotes to process PHI through an AI-assisted feature only when an Authorized User affirmatively invokes or configures the approved workflow. The authorization is limited to generating the requested output and performing related security, support, and operational functions permitted by this BAA.
13.3 Approved Providers and Configurations
ABANotes may use AI providers identified in the then-current Subprocessor List, including providers such as OpenAI and Anthropic. When AI Input contains PHI, ABANotes will use only providers and configurations approved by ABANotes for that PHI workflow and subject to required downstream business-associate protections. ABANotes may change a provider or model subject to the MSA’s Subprocessor and service-change provisions.
13.4 No General-Purpose Model Training
Neither ABANotes nor an approved AI subprocessor may use Customer PHI to train a general-purpose AI model, except under a separate written agreement that documents Customer’s explicit direction, all legally required authorizations, and the applicable safeguards. Transient processing necessary to generate AI Output and permitted security or abuse monitoring do not constitute model training.
13.5 Status and Ownership of AI Content
PHI submitted as AI Input remains Customer PHI. AI Output retained in Customer’s tenant is Customer Data and remains PHI to the extent it contains PHI. ABANotes acquires no ownership of Customer PHI by processing it through an AI-assisted feature.
13.6 Human Review Required
Customer must ensure that an appropriately qualified Professional User reviews every AI Output against the underlying record, corrects inaccuracies or unsupported statements, and approves and signs the document before it becomes part of the medical record. AI Output may be inaccurate, incomplete, biased, inconsistent, outdated, or unsupported and may describe facts absent from the source record. Customer remains responsible for clinical accuracy, professional judgment, medical necessity, payer requirements, coding, billing, authentication, and lawful record use.
13.7 Data Minimization for AI
Customer will submit only the PHI reasonably necessary for the requested AI workflow. ABANotes will configure approved AI processing to limit data transmission and retention consistent with the feature’s purpose, the provider agreement, and Applicable Privacy and Security Law.
13.8 AI Incident Handling
A Security Incident or Breach involving an AI subprocessor or AI workflow is subject to Articles 6 through 8 on the same basis as any other PHI processing. Suspension or unavailability of an AI feature does not authorize PHI to be moved to an unapproved consumer AI service.
14. Compliance Documentation and Audit Cooperation
14.1 Documentation
ABANotes will maintain documentation required to demonstrate its compliance with obligations applicable to it under HIPAA and this BAA. On reasonable written request, ABANotes will provide Customer with then-current standard documentation reasonably available for Customer’s business-associate oversight, subject to confidentiality and security restrictions.
14.2 Standard Evidence
Standard evidence may include relevant portions of the Security Overview, Subprocessor List, incident-response or continuity summaries, security-assessment summaries, policy attestations, or other materials ABANotes then makes available. ABANotes may redact information that would create a security risk, expose another customer’s data, violate a third party’s rights, or reveal privileged or confidential information unrelated to Customer.
14.3 Additional Reviews
Customer may request additional questionnaires, interviews, or remote review no more than once annually, except after a material Reportable Security Incident, a regulator’s request, or a material change reasonably affecting Customer’s PHI. The Parties will agree on scope, timing, safeguards, and any reasonable fees for non-standard work. Onsite access is not required where equivalent evidence reasonably addresses the request.
14.4 Corrective Action
If a review identifies a material deficiency in ABANotes’ compliance with this BAA, ABANotes will develop and implement a reasonable corrective-action plan based on risk, legal requirements, and technical feasibility. Customer will treat nonpublic security materials as ABANotes Confidential Information under the MSA.
15. Customer Obligations
15.1 Lawful Authority and Instructions
Customer represents that it has authority to disclose PHI to ABANotes and to instruct ABANotes to process PHI under the MSA and this BAA. Customer will not instruct ABANotes to Use or Disclose PHI in a manner that would violate HIPAA if performed by Customer.
15.2 Notices to ABANotes
Customer will notify ABANotes of: (a) limitations in Customer’s Notice of Privacy Practices that affect ABANotes; (b) changes in or revocations of authorizations that affect ABANotes; (c) restrictions on Use or Disclosure that Customer has agreed to and that affect ABANotes; (d) confidential-communication requirements that affect supported workflows; and (e) Customer-side Security Incidents that may affect the Services or PHI processed by ABANotes.
15.3 Customer Safeguards
Customer is responsible for safeguards within its control, including workforce training and sanctions; physical and device security; accurate user provisioning and termination; role and client assignments; minimum-necessary determinations; secure networks and endpoints; protection of credentials; and security of exported, printed, or locally stored PHI.
15.4 Individual Rights and Regulatory Notices
Unless expressly delegated in writing, Customer is responsible for receiving and deciding Individual requests, maintaining its Notice of Privacy Practices, obtaining authorizations, determining legally required restrictions, and issuing notices to Individuals, HHS, state regulators, media, or others.
15.5 Contact Information
Customer will maintain current privacy, security, legal, and administrative contacts in the Services or Order Form. Delay caused by Customer’s failure to maintain current contact information does not extend ABANotes’ legal reporting deadlines but may affect delivery of contractual notices.
16. Term and Termination
16.1 Term
This BAA begins on the BAA Effective Date and continues until the later of: (a) expiration or termination of all Services under which ABANotes handles PHI for Customer; or (b) completion of ABANotes’ obligations concerning retained PHI under Article 17.
16.2 Termination for Material Breach
If either Party knows of a pattern of activity or practice by the other Party that constitutes a material breach or violation of this BAA, the non-breaching Party will provide written notice and a reasonable opportunity to cure. If the breach is not cured, the non-breaching Party will terminate this BAA and the affected Services if feasible. If termination is not feasible, the Party required to do so will report the violation to the Secretary as required by 45 C.F.R. § 164.504(e).
16.3 Immediate Protective Action
ABANotes may suspend affected access or processing when reasonably necessary to prevent or mitigate an imminent threat to PHI, comply with law, or stop a material violation of this BAA. ABANotes will provide notice when practicable, limit the scope and duration, and cooperate to restore lawful access. ABANotes will not withhold Customer’s access to PHI in violation of HIPAA.
16.4 Effect of Termination
On termination, ABANotes will cease Uses and Disclosures of PHI except as required to return or destroy PHI, maintain residual PHI when return or destruction is infeasible, comply with law, or exercise rights that expressly survive under HIPAA and this BAA.
16.5 Survival
Articles 4, 5.4, 8, 9, 10, 14, 16.4, 17, and 18, and any other provision that by its nature must survive, continue for as long as ABANotes retains PHI or as otherwise required by law.
17. Return or Destruction of PHI
17.1 Customer Retrieval
Customer may retrieve PHI using available export tools during the term and any post-termination retrieval period stated in the MSA or Order Form. ABANotes will not deny Customer reasonable access to PHI it maintains on Customer’s behalf when access is required by HIPAA, subject to reasonable identity verification and security controls.
17.2 Return or Destruction
At termination, if feasible, ABANotes will return or destroy all PHI received from Customer or created, maintained, or received on Customer’s behalf that ABANotes or its subcontractors retain. ABANotes will not retain copies except as stated in this Article.
17.3 Infeasibility
If ABANotes determines that return or destruction of particular PHI is infeasible, ABANotes will notify Customer of the condition that makes return or destruction infeasible. ABANotes will extend the protections of this BAA to the retained PHI and limit further Uses and Disclosures to the purposes that make return or destruction infeasible for as long as ABANotes retains the PHI.
17.4 Backups and Residual Copies
PHI may remain temporarily in encrypted or otherwise protected backups, disaster-recovery copies, logs, or other residual media until overwritten or deleted through ABANotes’ ordinary documented lifecycle. Such PHI will be isolated from routine business use, remain subject to this BAA, and be restored only for disaster recovery, security recovery, legal necessity, or another purpose permitted by law. If restored, applicable deletion procedures will be reapplied when feasible.
17.5 Legal Retention
ABANotes may retain limited PHI when Required by Law or reasonably necessary to establish compliance, respond to legal process, preserve evidence, or resolve a dispute. ABANotes will retain only the minimum necessary, restrict access and Uses, protect it under this BAA, and securely destroy it when the retention basis ends.
17.6 Certification
On Customer’s written request after completion of the applicable process, ABANotes will provide a written certification of return or destruction or a written statement identifying categories of PHI retained because destruction is infeasible or legally prohibited. Certification does not require ABANotes to disclose information that would compromise security or another customer’s confidentiality.
18. Miscellaneous
18.1 Regulatory References and Amendment
A reference to HIPAA means the provision as amended or superseded. The Parties will amend this BAA as reasonably necessary to comply with changes in Applicable Privacy and Security Law. If a legally required amendment must take effect before the Parties can execute it, the Parties will comply with the controlling law and work promptly to document the amendment.
18.2 Interpretation
Any ambiguity will be interpreted to permit the Parties to comply with HIPAA. Headings are for convenience and do not affect interpretation. “Including” means “including without limitation.”
18.3 No Third-Party Beneficiaries
Nothing in this BAA creates a private right of action or makes an Individual, patient, caregiver, payer, regulator, or other person a third-party beneficiary, except to the extent such rights cannot lawfully be disclaimed.
18.4 Governing Law and Preemption
The governing-law, venue, dispute-resolution, limitation-of-liability, indemnification, and insurance provisions of the MSA apply to this BAA. Florida law applies as stated in the MSA, except where preempted or superseded by federal law or another controlling law. Nothing in this BAA limits a regulator’s jurisdiction or either Party’s obligations under HIPAA.
18.5 Notices
Formal legal notices under this BAA must be provided under the MSA’s notice provision. Incident and Breach notices must also be sent through the contacts in Appendix D. Operational notice by email does not replace any formal notice method expressly required by the MSA, but failure to duplicate a timely incident notice through a formal channel does not invalidate an otherwise received incident report.
18.6 Entire Agreement on PHI
This BAA, together with the MSA and documents expressly incorporated into them, is the complete agreement between the Parties concerning ABANotes’ handling of PHI. It supersedes prior or contemporaneous discussions or agreements on that subject. A Customer purchase order, security questionnaire, portal term, or onboarding document does not modify this BAA unless signed by authorized representatives and expressly identifies the provision modified.
18.7 Amendments and Waiver
Except for updates expressly permitted by the MSA that do not materially reduce Customer’s rights or ABANotes’ HIPAA obligations, an amendment to this BAA must be in writing and signed by authorized representatives of both Parties. A waiver must be in writing and applies only to the specific instance stated.
18.8 Assignment
Assignment of this BAA is governed by the MSA. A permitted assignee is bound by this BAA. No assignment relieves the assigning Party of obligations arising before the assignment unless the other Party agrees in writing.
18.9 Severability
If a provision is held unenforceable, it will be reformed to the minimum extent necessary to make it enforceable while preserving HIPAA compliance. The remaining provisions continue in effect.
18.10 Independent Contractors
The Parties are independent contractors. This BAA does not create a partnership, joint venture, fiduciary relationship, employment relationship, or agency except to the limited extent federal common law of agency applies to a Breach-discovery determination under HIPAA.
18.11 Counterparts and Electronic Signatures
This BAA may be executed in counterparts, each deemed an original and together one instrument. Electronic signatures and electronically retained records are effective to the maximum extent permitted by applicable federal and state electronic-transactions law.
18.12 Authority
Each person signing or accepting this BAA represents that the person is authorized to bind the applicable Party.
Signature Page
The authorized representatives below agree to this Business Associate Agreement as of the BAA Effective Date.
| ABANOTES LLC | CUSTOMER |
|---|---|
| Legal Name: ABANotes LLC | Customer Legal Name: ______ |
| State of Formation: Florida | State of Formation: ______ |
| By: __________ | By: __________ |
| Name: ________ | Name: ________ |
| Title: _________ | Title: _________ |
| Email: legal@abanotes.ai | Email: _________ |
| Date: __________ | Date: __________ |
BAA Effective Date (if different from last signature date): ______
Customer HIPAA Status (select one):
☐ Covered Entity
☐ Business Associate
☐ Other or uncertain — describe: ____________
Customer Privacy Contact:
Name/Title: __________
Email: _____ Telephone: ________
Customer Security/Incident Contact:
Name/Title: __________
Email: _____ Telephone: ________
Appendix A — Permitted Uses Matrix
This Appendix summarizes permitted processing. The numbered Articles control if a summary conflicts with the body of this BAA.
| Service Function | Permitted PHI Activity | Primary Controls and Limits |
|---|---|---|
| Clinical documentation | Create, receive, store, edit, transmit, render, export, and retain notes and related records | Customer-authorized roles; audit logging; minimum necessary; human authentication |
| Assessments and reassessments | Store and process assessment data, observations, plans, and reports | Role-based access; Customer professional judgment; supported workflows only |
| Protocol modification, caregiver training, and supervision | Process documentation and supporting data | Qualified user review; Customer responsibility for clinical and payer compliance |
| Scheduling and authorization tracking | Process identifiers, service schedules, authorization details, and alerts | Minimum necessary; Customer-configured permissions; alerts are administrative aids |
| Client, staff, billing-support, and reporting workflows | Organize and report PHI required for supported administrative functions | No independent billing or coverage determination; authorized access only |
| Electronic signatures | Present, capture, associate, and retain signature records and related evidence | Customer determines signer authority and legal sufficiency; audit controls where supported |
| Secure document storage | Upload, store, retrieve, transmit, and delete documents | Encryption, authentication, access control, logging, retention policy |
| Hosting, backup, and disaster recovery | Maintain production and protected recovery copies | Approved cloud configurations; restricted restoration; lifecycle deletion |
| Support and troubleshooting | Access the minimum PHI necessary to resolve an authorized request | Trained authorized personnel; access limitation; confidentiality; logging where supported |
| Security and abuse prevention | Monitor, analyze, preserve, and disclose PHI as necessary to protect the Services and comply with law | Least privilege; incident response; legal limits; no unrelated secondary use |
| AI-assisted drafting | Transmit necessary AI Input and return draft AI Output through an approved workflow | Approved subprocessors/configurations; no general-purpose training; human review mandatory |
| Data Aggregation | Combine PHI for Customer’s Health Care Operations when authorized | HIPAA-permitted purpose; no impermissible cross-customer disclosure |
| De-identification | Create information de-identified under 45 C.F.R. § 164.514 | Required method and documentation; no prohibited re-identification |
| Legal compliance | Use or disclose minimum necessary PHI as Required by Law | Customer notice where legally permitted; Article 10 applies |
Appendix B — Security Safeguards Summary
This Appendix is a contractual summary, not a technical architecture diagram or certification. The then-current Security Overview provides additional operational detail.
| Safeguard Domain | ABANotes Commitment | Shared-Responsibility Boundary |
|---|---|---|
| Governance and risk | Written security program; assigned responsibility; periodic risk evaluation and treatment | Customer assesses its own environment, workforce, devices, and use |
| Workforce security | Authorization, confidentiality, training, and sanctions appropriate to role | Customer manages its workforce and Authorized Users |
| Identity and access | Authentication, role-based permissions, least privilege, and access termination processes | Customer configures roles, assignments, and timely deprovisioning |
| Encryption | Industry-standard protection in transit and at rest where reasonable and appropriate | Customer protects exported data, endpoints, local storage, and external transmissions |
| Logging and monitoring | Logging and monitoring for material supported security and activity events | Customer reviews available reports relevant to its compliance program |
| Application and infrastructure security | Secure configuration, change, vulnerability, malware, and environment-management controls | Customer uses supported software, secure networks, and updated devices |
| Incident response | Documented identification, containment, investigation, mitigation, remediation, and reporting process | Customer promptly reports account compromise and cooperates with response |
| Backup and recovery | Protected backup lifecycle and documented recovery and continuity processes | Customer exports and retains records required beyond contracted retention |
| Vendor management | Risk-based review, written obligations, and HIPAA flow-down for PHI subprocessors | Customer reviews the Subprocessor List and raises timely documented objections |
| Physical and media security | Controls appropriate to cloud and ABANotes-controlled facilities, devices, and media | Customer secures its offices, devices, printers, and removable media |
Appendix C — Subprocessor Categories
The current Subprocessor List, not this categorical summary, identifies material providers and processing details. ABANotes may change providers in accordance with the MSA, this BAA, and the Subprocessor List.
| Category | Typical Function | PHI Conditions |
|---|---|---|
| Cloud infrastructure | Compute, database, storage, networking, backup, and recovery | Approved services and configurations; required contractual safeguards |
| AI model services | AI-assisted generation, transformation, organization, summarization, or review | Approved PHI workflow; downstream business-associate protection; no general-purpose training |
| Security and monitoring | Threat detection, logging, alerting, vulnerability management, and incident support | Minimum necessary; restricted access; confidentiality and security obligations |
| Communications | Transactional notices, support communications, or messaging | PHI limited to approved use; no PHI in unapproved marketing systems |
| Support and operations | Authorized technical support, maintenance, and service administration | Need-to-know access; workforce controls; contractual confidentiality |
| Document and signature services | Document rendering, storage, transmission, or signature support | Approved configuration; access controls; retention and audit requirements |
ABANotes will not treat a service as approved for PHI merely because its provider offers a BAA. Approval requires the applicable agreement, service configuration, purpose limitation, and security review to be in place.
Appendix D — Incident Reporting Contacts
D.1 ABANotes Contacts
| Purpose | Contact |
|---|---|
| Security Incident or suspected Breach | security@abanotes.ai |
| Privacy matter | privacy@abanotes.ai |
| Legal notice | legal@abanotes.ai |
| Mailing address | ABANotes LLC, 8821 NW 153 Terrace, Miami Lakes, Florida 33018 |
Customer should mark urgent incident emails “URGENT — SECURITY INCIDENT” and should not include unnecessary PHI in the email. ABANotes may provide a secure channel for supporting evidence.
D.2 Customer Contacts
Customer’s contacts are those listed on the Signature Page, Order Form, or Customer account. Customer must promptly update them. If a role is vacant, notice may be sent to Customer’s authorized administrator or legal-notice contact.
D.3 Notice Content
An incident report should include, to the extent known and safe to transmit: Customer name and tenant; reporter name and callback information; date and time discovered; affected accounts, records, or devices; actions already taken; and whether credentials may be compromised. Passwords, authentication secrets, or full PHI records must not be sent by ordinary email.
Appendix E — Return and Destruction Procedures
E.1 Pre-Termination Preparation
Customer should review its legal retention obligations, use available export tools, validate exported records, preserve audit or signature evidence it requires, and identify any pending Individual-rights requests before termination.
E.2 Standard Process
Subject to the MSA, Order Form, and Applicable Privacy and Security Law, ABANotes will:
- maintain Customer access during the applicable retrieval period;
- provide supported export capabilities or agreed reasonable assistance;
- remove PHI from active production systems after the retrieval period and applicable operational holds;
- delete or overwrite residual backup copies through the ordinary documented lifecycle;
- direct applicable subcontractors to return or destroy PHI under their agreements; and
- retain only PHI subject to a documented infeasibility or legal-retention basis.
E.3 Secure Destruction
Destruction methods will be appropriate to the media and risk and reasonably designed to render PHI unreadable, indecipherable, and not practicably reconstructable, consistent with applicable law and ABANotes policy.
E.4 Exceptions and Holds
Deletion may be delayed by a legal hold, regulatory instruction, active security investigation, disaster-recovery integrity requirement, technical infeasibility, or legal retention duty. ABANotes will restrict retained PHI to the applicable purpose and destroy it when the exception ends.
E.5 Confirmation
On written request, ABANotes will provide the certification or infeasibility statement described in Section 17.6 after the applicable return and destruction process is complete.
END OF BUSINESS ASSOCIATE AGREEMENT — VERSION 1.0