Mediphant Guardian
Back to home

Business Associate Agreement

Mediphant Guardian Platform

Last Updated: June 19, 2026

Version: 2.1

This Business Associate Agreement ("BAA" or "Agreement") is entered into by and between the healthcare organization identified in the applicable Commercial Agreement or account registration ("Covered Entity" or "you") and Mediphant Corporation ("Business Associate" or "Mediphant") and supplements the Mediphant Guardian Terms of Service (the "Terms").

Effective Date: For electronic acceptance, this BAA becomes effective on the date you click "I Agree" to accept this BAA or first access the Service after being presented with this BAA. Under HIPAA regulations (45 CFR § 164.504(e)), this BAA must be in place before any Protected Health Information (PHI) is created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.

RECITALS

WHEREAS, Covered Entity is a Covered Entity as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including the Privacy, Security, and Breach Notification Rules ("HIPAA");

WHEREAS, Business Associate provides healthcare information technology services to Covered Entity through the Mediphant Guardian platform (the "Services");

WHEREAS, in connection with providing the Services, Business Associate may create, receive, maintain, transmit, or otherwise access Protected Health Information ("PHI") on behalf of Covered Entity;

WHEREAS, HIPAA requires Covered Entity to enter into a business associate agreement with Business Associate that contains certain requirements;

NOW, THEREFORE, in consideration of the mutual covenants and agreements set forth herein, the parties agree as follows:

1. DEFINITIONS

Terms used but not otherwise defined in this BAA shall have the meanings set forth in HIPAA, including 45 CFR Parts 160 and 164.

"Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted by this BAA or the HIPAA Privacy Rule that compromises the security or privacy of the PHI, as further defined in 45 CFR § 164.402.

"Patient-Controlled Source Records" means patient health records, documents, files, or other information that an Individual controls through a Mediphant patient account and makes available to Covered Entity through a Connected Patient relationship or similar patient-controlled sharing feature.

"Protected Health Information" or "PHI" means individually identifiable health information that is transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium, as defined in 45 CFR § 160.103, and that is created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.

"Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system, as defined in 45 CFR § 164.304.

2. OBLIGATIONS OF BUSINESS ASSOCIATE

2.1 Permitted Uses and Disclosures

Business Associate may use or disclose PHI only as permitted by this BAA or as Required by Law, and may not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity.

2.2 Specific Use and Disclosure Provisions

Services to Covered Entity: Business Associate may use and disclose PHI to perform the Services for or on behalf of Covered Entity as specified in the Terms, provided that such use or disclosure would not violate the HIPAA Rules if done by Covered Entity.

Business Associate's Management and Administration: Business Associate may use PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that the use is necessary and Business Associate complies with disclosure requirements.

2.3 Prohibition on Unauthorized Use or Disclosure

Business Associate shall not use or disclose PHI other than as permitted or required by this BAA or as Required by Law.

2.4 Appropriate Safeguards

Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to prevent the use or disclosure of PHI other than as permitted by this BAA or Required by Law.

With respect to ePHI, Business Associate shall comply with the applicable requirements of the Security Rule, including:

  • Administrative Safeguards: Security management process, workforce security, information access management, security awareness training, security incident procedures, contingency planning
  • Physical Safeguards: Facility access controls, workstation use and security policies, device and media controls
  • Technical Safeguards: Access controls (unique user identification, emergency access, automatic logoff, encryption), audit controls, integrity controls, person authentication, transmission security

Encryption: Business Associate shall encrypt all ePHI at rest using AES-256 encryption or equivalent, and shall encrypt all ePHI in transit using TLS 1.2 or higher or equivalent technology.

2.5 Mitigation of Harmful Effects

Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of this BAA or the HIPAA Rules.

2.6 Reporting of Improper Uses and Disclosures

Security Incidents: Business Associate shall report to Covered Entity any Security Incident of which Business Associate becomes aware.

Breaches of Unsecured PHI: Business Associate shall report to Covered Entity any Breach of Unsecured PHI without unreasonable delay and in no case later than thirty (30) calendar days after discovery of the Breach. Such report shall include:

  • A brief description of what happened, including the date of the Breach and the date of discovery
  • The identification of the type and number of Individuals affected or potentially affected
  • The identification of the type and quantity of PHI involved
  • The identity of the person or entity who made the unauthorized use or disclosure
  • A brief description of what Business Associate is doing or has done to investigate, mitigate harm, and prevent future occurrences
  • Any other information reasonably requested by Covered Entity

2.7 Subcontractors

Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate enters into a written agreement that contains terms substantially similar to those in this BAA, including all requirements applicable to Business Associate under this BAA and the HIPAA Rules.

Current Subcontractors that may access PHI include:

  • Amazon Web Services (AWS) – cloud hosting and infrastructure services
  • Microsoft Azure – cloud hosting, infrastructure, and AI services
  • Groq – AI inference services
  • Pinecone – vector database and search infrastructure

For AI, model, inference, hosting, or infrastructure Subcontractors that process PHI, Business Associate shall require such Subcontractors to process PHI only to provide the Services, maintain security, troubleshoot service issues, comply with law, or perform other functions permitted by this BAA, the Terms, and applicable law. Business Associate shall not permit Subcontractors to use PHI to train general-purpose AI models and shall require appropriate retention, confidentiality, access control, and human review restrictions consistent with the sensitivity of PHI.

2.8 Access to PHI

Upon request by Covered Entity, Business Associate shall provide Covered Entity or, as directed by Covered Entity, an Individual with access to PHI about the Individual contained in a Designated Record Set maintained by Business Associate, in the time and manner designated by Covered Entity, to enable Covered Entity to meet its obligations under 45 CFR § 164.524.

If Business Associate maintains an Individual's PHI in a Designated Record Set electronically and the Individual requests an electronic copy, Business Associate shall provide such access within fifteen (15) calendar days of Covered Entity's request.

2.9 Amendment of PHI

Upon request by Covered Entity, Business Associate shall make PHI contained in a Designated Record Set maintained by Business Associate available to Covered Entity for amendment, and shall incorporate any amendments to PHI in accordance with 45 CFR § 164.526, in the time and manner designated by Covered Entity.

Business Associate shall incorporate amendments within fifteen (15) calendar days of Covered Entity's request.

2.10 Accounting of Disclosures

Business Associate shall document all disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to an Individual's request for an accounting of disclosures in accordance with 45 CFR § 164.528.

Upon request by Covered Entity, Business Associate shall provide an accounting of disclosures within thirty (30) calendar days, or such shorter time period as may be required by applicable law.

2.11 Availability of Books and Records

Business Associate agrees to make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining Covered Entity's compliance with the HIPAA Rules. Business Associate shall provide such access within ten (10) business days of a written request from the Secretary or as otherwise required by law.

2.12 Prohibition on Sale of PHI

Business Associate shall not directly or indirectly receive remuneration in exchange for PHI, except as permitted by 45 CFR § 164.502(a)(5)(ii) or as otherwise permitted by law. For clarity, fees paid by Covered Entity to Business Associate for the Services do not constitute prohibited remuneration.

2.13 Marketing Prohibition

Business Associate shall not use or disclose PHI for marketing purposes, as defined in 45 CFR § 164.501, unless Covered Entity obtains a valid authorization from the Individual in accordance with 45 CFR § 164.508, or the communication falls within one of the exceptions to the definition of marketing.

3. OBLIGATIONS OF COVERED ENTITY

3.1 Permissible Requests

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.

3.2 Notice of Privacy Practices

Covered Entity shall provide Business Associate with a copy of its Notice of Privacy Practices and any amendments thereto, to the extent that such notice or amendment may affect Business Associate's use or disclosure of PHI.

3.3 Notice of Restrictions

Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

3.4 Patient Authorization

Covered Entity is solely responsible for obtaining any authorizations, consents, or permissions from Individuals that are required under applicable law for Business Associate's use or disclosure of PHI under this BAA.

4. TERM AND TERMINATION

4.1 Term

This BAA shall commence on the Effective Date (the date of your acceptance of this BAA) and shall remain in effect until the termination of the Terms and completion of Business Associate's destruction obligations under Section 4.3. This BAA will continue to apply to any PHI retained because destruction is infeasible or retention is required by law.

4.2 Termination for Cause by Covered Entity

Covered Entity may terminate this BAA and the Terms immediately upon written notice to Business Associate if Covered Entity determines that Business Associate has materially breached this BAA, and either:

  • Business Associate does not cure the breach within thirty (30) calendar days of receiving written notice of the breach; or
  • The breach cannot be cured; or
  • Immediate termination is necessary to comply with applicable law

4.3 Effect of Termination

Upon termination of this BAA or the Terms for any reason:

  • Destruction of Covered Entity PHI: Business Associate shall, if feasible, destroy PHI received from Covered Entity, or created, received, or maintained by Business Associate solely on behalf of Covered Entity, after any applicable export period described in the Terms or written agreement. Business Associate is not required to return PHI to Covered Entity unless required by applicable law or expressly agreed in writing.
  • Certification: If Business Associate destroys PHI under this Section, Business Associate shall provide written certification of destruction upon request.
  • Patient-Controlled Source Records: Patient-Controlled Source Records are controlled by the Individual through the Individual's Mediphant account and are not returned to Covered Entity or destroyed merely because Covered Entity's account terminates. Termination ends Covered Entity's access to Patient-Controlled Source Records, unless otherwise required by applicable law or expressly agreed in writing. Covered Entity is responsible for downloading, exporting, or incorporating any Patient-Controlled Source Records it needs for its own designated record set or legal medical record while access is active.
  • Infeasible Destruction or Required Retention: If destruction is infeasible or retention is required by law, Business Associate shall continue to protect such PHI in accordance with this BAA and limit further uses and disclosures to those purposes that make destruction infeasible or retention required.
  • Compliance Data Retention: Business Associate may retain account records, audit logs, legal records, billing records, security records, and compliance-related data as required by law and in accordance with the Privacy Policy, provided that any retained PHI remains protected under this BAA.

5. INDEMNIFICATION AND LIMITATION OF LIABILITY

5.1 Indemnification by Business Associate

Business Associate shall defend, indemnify, and hold harmless Covered Entity from and against third-party claims, and any resulting liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees), to the extent arising out of Business Associate's material breach of this BAA or the HIPAA Rules or Business Associate's unauthorized use or disclosure of PHI.

5.2 Indemnification by Covered Entity

Covered Entity shall defend, indemnify, and hold harmless Business Associate from and against third-party claims, and any resulting liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees), to the extent arising out of Covered Entity's breach of this BAA or the HIPAA Rules, Covered Entity's failure to obtain or maintain any patient authorization or consent required by applicable law, or any request by Covered Entity that Business Associate use or disclose PHI in a manner not permitted by the HIPAA Rules.

5.3 Procedure

The party seeking indemnification will promptly notify the indemnifying party of the claim, give the indemnifying party sole control of the defense and settlement (provided that no settlement may impose any liability, obligation, or admission of fault on the indemnified party without its prior written consent), and provide reasonable cooperation at the indemnifying party's expense.

5.4 Limitation of Liability

Notwithstanding anything to the contrary in this BAA, each party's liability arising out of or relating to this BAA — including any indemnification obligation and any liability relating to a Security Incident or a Breach of Unsecured PHI — is subject to, and shall not exceed, the exclusions and limitations of liability set forth in the Terms. Nothing in this BAA is intended to expand either party's liability beyond the limitations set forth in the Terms.

6. MISCELLANEOUS PROVISIONS

6.1 Regulatory Changes

The parties acknowledge that the HIPAA Rules are subject to change and amendment. The parties agree to negotiate in good faith to amend this BAA as necessary to comply with any changes to the HIPAA Rules or other applicable privacy and security laws.

6.2 Electronic Acceptance and Signatures

Pursuant to the Electronic Signatures in Global and National Commerce Act (ESIGN Act), 15 U.S.C. § 7001 et seq., the Uniform Electronic Transactions Act (UETA), and other applicable law:

  • Electronic signatures, records, and contracts are valid and enforceable
  • Electronic acceptance of this BAA has the same legal force and effect as a handwritten signature
  • This BAA shall not be denied legal effect solely because it is in electronic form

Business Associate shall maintain records of electronic acceptance of this BAA for at least six (6) years from the date of acceptance or termination of this BAA, whichever is later. These records shall include:

  • The Effective Date (date and time of acceptance)
  • The identity of the authorized representative who accepted (name, email, title)
  • The Organization name
  • The IP address from which acceptance occurred
  • The version of the BAA accepted

7. REPRESENTATIONS AND WARRANTIES

Business Associate represents and warrants that:

  • It is familiar with and understands the requirements of the HIPAA Rules
  • It has implemented and will maintain administrative, physical, and technical safeguards that comply with the Security Rule
  • It has policies and procedures in place to ensure compliance with this BAA and the HIPAA Rules
  • It provides regular HIPAA training to its workforce members who access PHI
  • It has entered into compliant business associate agreements with all Subcontractors

8. CONTACT INFORMATION

All communications, notices, and requests under this BAA to Business Associate should be directed to:

Privacy Officer
Mediphant Corporation
539 W Commerce St. #7718
Dallas, TX 75208
Email: compliance@mediphant.com
Security Incidents: security@mediphant.com

Version History

  • Version 2.1 (June 19, 2026): Aligned Commercial Agreement terminology with the Terms and clarified destruction, patient-controlled source record handling, infeasibility, and retained-compliance-record handling upon termination.
  • Version 2.0 (June 11, 2026): Updated Mediphant contact information and Guardian domain references; added AI subcontractor commitments and updated subcontractor disclosures; strengthened breach reporting, safeguards, indemnification, limitation-of-liability, and electronic acceptance provisions.
  • Version 1.0 (October 20, 2025): Initial release.