Zoren AI
Business Associate Agreement and Services Terms
This agreement governs how Zoren, Inc. handles protected health information on behalf of the healthcare organizations that use Zoren AI. It is accepted by a representative authorized to bind the organization, or executed by signature.
This Business Associate Agreement and Services Terms (this "Agreement") is entered into by Zoren, Inc., with its principal place of business at 2615 N. Greenbrier, Santa Ana, California 92706 ("Zoren" or "Business Associate"), and [Customer Legal Entity Name], with a principal place of business at [Customer address] ("Customer"). Each of Customer and Zoren may be referred to individually as a "Party" and together as the "Parties."
This Agreement is a complete and standalone agreement. It contains both the Parties' obligations under HIPAA and related law with respect to Protected Health Information (Sections A through E) and the commercial terms governing Customer's use of the Eligible Services (Sections F through H). No separate services agreement is required for this Agreement to be fully effective. This Agreement may also be attached to, incorporated into, or executed alongside a master services agreement, terms of service, software-as-a-service or subscription agreement, service order, or other agreement governing the Eligible Services (an "Underlying Agreement"), in which case the order of precedence in Section H.10 applies.
A. Recitals
Customer is a "covered entity" or a "business associate," as those terms are defined under HIPAA, and is required to comply with HIPAA regarding the confidentiality, integrity, and availability of Protected Health Information.
Business Associate provides to Customer certain services (the "Eligible Services," defined below). In connection with the Eligible Services, the Parties anticipate that Business Associate may from time to time create, receive, maintain, or transmit Protected Health Information for or on behalf of Customer. By doing so, Business Associate becomes a "business associate" of Customer, where Customer is a covered entity, or a "subcontractor" of Customer, where Customer is itself a business associate, as those terms are defined under HIPAA, and has obligations regarding such Protected Health Information.
Sections A through E of this Agreement apply solely to the extent Business Associate creates, receives, maintains, or transmits Protected Health Information for or on behalf of Customer in a manner that results in Business Associate operating as a business associate or subcontractor under HIPAA.
B. Definitions
For purposes of this Agreement, capitalized terms have the meanings ascribed to them below. All capitalized terms used but not otherwise defined herein have the meaning ascribed to them by HIPAA. No definition in this Agreement is intended to be inconsistent with the corresponding definition under HIPAA.
"AI Subprocessors" means the third-party artificial intelligence model providers that Business Associate engages as Subcontractors in connection with the Eligible Services, as identified in Exhibit A. Business Associate has entered into a HIPAA business associate agreement with each AI Subprocessor prior to using that subprocessor to process PHI, as further described in Section C.5(b).
"Breach" has the meaning given to it under 45 CFR § 164.402.
"Covered Entity" has the meaning given to "covered entity" under 45 CFR § 160.103. Where Customer is a covered entity, references to the Covered Entity mean Customer. Where Customer is a business associate, references to the Covered Entity mean each covered entity on whose behalf Customer receives the PHI that Customer discloses to Business Associate.
"Customer Data" means data and content that Customer or its authorized users submit to, or generate through use of, the Eligible Services, including any PHI.
"De-Identified Information" means information that has been de-identified from PHI in accordance with the standard set forth in 45 CFR § 164.514(b), such that it no longer constitutes PHI under HIPAA, as further described in Section C.7.
"Designated Record Set" has the meaning given to it under 45 CFR § 164.501.
"Documentation" means Business Associate's then-current end-user documentation for the Eligible Services, as made generally available to Customer.
"Electronic Protected Health Information" or "ePHI" has the meaning given to "electronic protected health information" under 45 CFR § 160.103, limited to PHI.
"Eligible Services" means Business Associate's: (1) prior-authorization submission and workflow automation platform, including AI-assisted intake, drafting, and review of prior-authorization requests and related questionnaires; (2) automated interaction with payer/PBM portals (including CoverMyMeds and similar third-party utilization-management systems) for the purpose of transmitting and tracking prior-authorization requests at Customer's direction and following Customer's approval; (3) AI-assisted processing, extraction, and review of clinical and prescription documents and faxes submitted in connection with a prior-authorization request; (4) AI-assisted voice, telephony, and automated call-handling services, including inbound and outbound calls with patients, prescribers, pharmacies, payers, and other parties placed or received at Customer's direction, and related call recordings, transcripts, and summaries (the "Voice Services"); and (5) related case-management, document-storage, and workflow features made available as part of the foregoing.
Any product, feature, or environment that Business Associate makes available to Customer and that creates, receives, maintains, or transmits PHI is an Eligible Service and is subject to this Agreement, regardless of whether Business Associate designates it as generally available, beta, preview, or pilot. Business Associate will not enable for Customer any feature that processes PHI outside the scope of this Agreement. Business Associate will not remove a feature or service that is actively being used to process PHI from the scope of Eligible Services without providing Customer at least thirty (30) days' advance written notice (or, where a security or legal necessity makes that impracticable, as much notice as is reasonably practicable under the circumstances). "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended and supplemented by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and the regulations promulgated thereunder, including the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, in each case as amended from time to time.
"Individual" has the meaning given to it under 45 CFR § 160.103, and includes a person who qualifies as a personal representative in accordance with 45 CFR § 164.502(g).
"Protected Health Information" or "PHI" has the meaning given to "protected health information" under 45 CFR § 160.103, limited to such information that Business Associate creates, receives, maintains, or transmits for or on behalf of Customer or the Covered Entity in connection with the Eligible Services. PHI includes ePHI.
"Required by Law" has the meaning given to it under 45 CFR § 164.103.
"Secretary" means the Secretary of the U.S. Department of Health and Human Services or the Secretary's designee.
"Security Incident" has the meaning given to it under 45 CFR § 164.304.
"Subcontractor" has the meaning given to "subcontractor" under 45 CFR § 160.103.
"Unsecured PHI" has the meaning given to "unsecured protected health information" under 45 CFR § 164.402.
Customer Acting as a Business Associate. Where Customer is itself a business associate of one or more Covered Entities, Business Associate is Customer's Subcontractor with respect to the PHI Customer discloses to it, and: (i) Business Associate's reporting, access, amendment, accounting, and other obligations under this Agreement run to Customer, and Customer is responsible for communicating with the applicable Covered Entity; (ii) references in this Agreement to a use or disclosure that would violate HIPAA if made by the Covered Entity refer to the applicable Covered Entity; (iii) Customer's notification obligations under Section D apply to information that Customer receives from the Covered Entity; and (iv) Customer represents that its business associate agreement with each such Covered Entity permits Customer to disclose PHI to Business Associate for the uses and disclosures contemplated by this Agreement. Business Associate will not use or disclose PHI received from Customer in any manner in which Customer itself would not be permitted to use or disclose it under Customer's agreement with the applicable Covered Entity, and Customer will notify Business Associate in writing of any restriction in that agreement that limits the uses or disclosures otherwise permitted by this Agreement, including under Section C.7.
42 CFR Part 2. Records that are subject to 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) ("Part 2 Records") are PHI for purposes of this Agreement and are additionally subject to Part 2. This Agreement does not subject any information to Part 2 that is not otherwise subject to it.
The Parties acknowledge that the Eligible Services ingest data automatically from Customer's pharmacy management, dispensing, electronic health record, and customer relationship management systems, and that Business Associate cannot practicably identify Part 2 Records within those automated feeds. Accordingly, Customer will notify Business Associate in writing before transmitting any Part 2 Records to the Eligible Services, identifying the records or data sources involved and the basis on which they are disclosed (for example, a patient consent permitting use and disclosure for treatment, payment, and health care operations, or a qualified service organization arrangement). With respect to Part 2 Records that Customer so identifies, Business Associate will comply with the requirements of Part 2 that apply to it as a recipient of those records, including Part 2's restrictions on redisclosure and on the use or disclosure of such records in civil, criminal, administrative, or legislative proceedings against the patient absent patient consent or a court order meeting the requirements of Part 2. Where Part 2 requires a qualified service organization agreement or other additional terms, the Parties will execute a Part 2 addendum before Part 2 Records are processed. Part 2 Records that Customer transmits without the notice required by this paragraph remain PHI protected under this Agreement.
C. Business Associate Obligations
1. Use and Disclosure of PHI
(a) Business Associate: (i) will use or disclose PHI only in connection with fulfilling its duties and obligations under this Agreement and to perform the Eligible Services; (ii) will not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law; (iii) will not use or disclose PHI in any manner that violates applicable federal or state law, or that would violate Subpart E of 45 CFR Part 164 if used or disclosed in such manner by the Covered Entity; and (iv) will use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose of the use, disclosure, or request. Customer is responsible for the data it elects to submit to the Eligible Services. Business Associate is responsible for designing the data flows, model prompts and payloads, and logging practices of the Eligible Services to limit the PHI processed, transmitted, or exposed to what is reasonably necessary to provide the Eligible Services.
(b) Notwithstanding Section C.1(a)(iii), and subject to the other restrictions set forth in this Agreement, Business Associate may use PHI received from Customer if necessary for: (i) the proper management and administration of Business Associate; or (ii) to carry out the legal responsibilities of Business Associate, as permitted by 45 CFR § 164.504(e)(4) (together, "Administrative Purposes"). Administrative Purposes include maintaining records of the Eligible Services provided and related transactions; billing, accounting, and financial records; audit, security, and access logs; investigating and responding to Security Incidents, complaints, claims, disputes, and legal proceedings; responding to audits, inquiries, and investigations by the Secretary, other regulators, or Customer; and backup and disaster recovery. Administrative Purposes do not include using PHI to develop, train, or improve products or models, for analytics, or to provide services to anyone other than Customer.
(c) Notwithstanding Section C.1(a)(iii), and subject to the other restrictions set forth in this Agreement, Business Associate may disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that: (i) the disclosure is Required by Law; or (ii) Business Associate obtains reasonable assurances from the person or entity to whom the information is disclosed that it will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the person or entity will notify Business Associate of any instance of which it becomes aware in which the confidentiality of the information has been breached.
(d) Business Associate may create and use De-Identified Information as described in Section C.7.
(e) State Law. Business Associate will comply with state laws governing the privacy and security of health or medical information to the extent those laws apply to Business Associate's performance of the Eligible Services, including, where applicable, the California Confidentiality of Medical Information Act (Cal. Civ. Code § 56 et seq.). Where applicable state law is more protective of PHI than HIPAA and is not preempted by HIPAA, the more protective requirement applies to the extent it applies to Business Associate. Customer will notify Business Associate in writing of any state-law requirement applicable to Customer's PHI that would require Business Associate to handle PHI differently from this Agreement, and the Parties may document such requirements in a state law addendum. Customer remains responsible for any notification to Individuals, regulators, or others that state breach-notification law requires of Customer.
(f) Business Associate will not use PHI to provide data aggregation services relating to the health care operations of Customer or any Covered Entity except as the Parties agree in writing. Business Associate may use PHI to report violations of law to appropriate federal and state authorities, consistent with 45 CFR § 164.502(j)(1).
2. Safeguards. Business Associate will implement and maintain appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI and to prevent use or disclosure of PHI other than as permitted by this Agreement. Business Associate will comply with the applicable requirements of Subpart C of 45 CFR Part 164 with respect to ePHI, including, as applicable, risk analysis and risk management, security policies and procedures, security awareness training, access and audit controls, contingency planning, and device and media controls.
As of the Effective Date, Business Associate's safeguards include: encryption of data in transit between users and the Eligible Services, and between the Eligible Services and external services, using industry-standard transport-layer security; application-level encryption of designated PHI fields at rest; role-based access controls limiting access to PHI to authorized personnel on a role-appropriate basis; audit logging of access to PHI; rate-limiting and lockout controls on authentication endpoints; and multi-factor authentication available for user accounts. Business Associate may modify its safeguards from time to time, provided that no modification materially reduces the overall protection of PHI under this Agreement.
Business Associate maintains a documented security-remediation program and addresses identified findings on a risk-prioritized basis. No set of safeguards eliminates all risk: Business Associate does not warrant that the Eligible Services will be free of Security Incidents or that its safeguards will prevent every unauthorized access to PHI, and the occurrence of a Security Incident is not, by itself, a breach of this Section C.2. This Section C.2 does not represent that Business Associate has obtained any third-party certification or attestation (such as SOC 2, HITRUST, or ISO 27001) or completed any particular penetration test, and no such representation should be inferred absent separate written confirmation from Business Associate.
3. Audits and Records.
(a) To the extent required by HIPAA, Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA. Business Associate will promptly notify Customer of any such request that relates to Customer's PHI, unless notice is prohibited by law or by the Secretary.
(b) No more than once every twelve (12) months (or, in addition, following an event reported to Customer under Section C.6), and upon reasonable prior written request, Business Associate will: (i) provide Customer a summary of its then-current administrative, technical, and physical safeguards for PHI; and (ii) respond in writing to Customer's reasonable questions regarding those safeguards (e.g., a standard security questionnaire), in each case subject to Section F.9. This Section C.3(b) does not obligate Business Associate to undergo a third-party audit, obtain or produce a specific certification, or permit on-site inspection.
(c) Nothing in this Section C.3 grants Customer any right to access Business Associate's facilities, systems, networks, or source code, to access the data of any other customer, or to conduct penetration testing, vulnerability scanning, or other security testing of the Eligible Services without Business Associate's prior written consent. Each Party bears its own costs under this Section C.3. If Business Associate obtains an independent third-party audit report or attestation relevant to its safeguards, Business Associate may provide it, subject to Section F.9, in full or partial satisfaction of Section C.3(b).
4. Individuals' Rights
(a) Access. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will, within ten (10) business days of Customer's written request, make that PHI available to Customer as necessary for Customer or the Covered Entity to meet its obligations under 45 CFR § 164.524, including in electronic form where the PHI is maintained electronically. If an Individual requests access to PHI directly from Business Associate, Business Associate will direct the Individual to submit the request to Customer or, to the extent Business Associate knows Customer's identity, will forward the request to Customer. As between the Parties, Customer is solely responsible for determining whether to grant or deny any such request, and for resolving any related appeal or complaint.
(b) Amendment. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will, within ten (10) business days of Customer's written request, make that PHI available for amendment and incorporate any amendment that Customer directs in accordance with 45 CFR § 164.526, which Business Associate may accomplish by enabling Customer to make the amendment through functionality then available in the Eligible Services. Requests received directly from an Individual will be redirected or forwarded to Customer as described in Section C.4(a). As between the Parties, Customer is solely responsible for determining whether to grant or deny any such request.
(c) Designated Record Set. The Parties intend that Business Associate operate as a workflow-automation layer and not as Customer's system of record. Customer is responsible for maintaining its own authoritative patient records and for determining whether any PHI maintained by Business Associate forms part of its or the Covered Entity's Designated Record Set; Business Associate's obligations under Sections C.4(a) and C.4(b) apply to PHI that does. Independently of whether PHI forms part of a Designated Record Set, Business Associate will provide reasonable assistance, using the functionality then available in the Eligible Services (such as search and export), to help Customer locate and retrieve PHI maintained by Business Associate that Customer needs in order to respond to an Individual's request.
(d) Accounting of Disclosures. Business Associate will document its disclosures of PHI, and information related to those disclosures, as would be required for Customer or the Covered Entity to respond to a request for an accounting of disclosures under 45 CFR § 164.528, and will retain that documentation for six (6) years from the date of each disclosure. Within ten (10) business days of Customer's written request, Business Associate will make that information available to Customer. Requests received directly from an Individual will be redirected or forwarded to Customer as described in Section C.4(a). As between the Parties, Customer is solely responsible for preparing and delivering any accounting to an Individual.
(e) Restrictions and Confidential Communications. Business Associate will comply with any restriction on the use or disclosure of PHI under 45 CFR § 164.522(a), and any accommodation for confidential communications under 45 CFR § 164.522(b), that Customer or the Covered Entity has agreed to or is required to accommodate and that Customer has communicated to Business Associate in writing, to the extent it affects Business Associate's use or disclosure of PHI. If Business Associate cannot accommodate a communicated restriction or requirement within the Eligible Services, it will promptly notify Customer so that Customer may determine whether to disclose the affected PHI to Business Associate.
5. Subcontractors.
(a) In accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement with respect to such PHI, including compliance with the applicable requirements of Subpart C of 45 CFR Part 164 with respect to ePHI.
(b) AI Subprocessors. Business Associate represents that it has entered into a HIPAA business associate agreement with each of its AI Subprocessors prior to using that subprocessor to process PHI in connection with the Eligible Services. Business Associate further covenants that it will not disclose PHI to any artificial intelligence model provider unless a HIPAA business associate agreement with that provider is then in effect, and that its agreements with each AI Subprocessor, including that provider's applicable commercial terms, prohibit the provider from using Customer's PHI to train, fine-tune, or improve that provider's models. Business Associate accesses Google's models only through Google Cloud Vertex AI, under Google Cloud's HIPAA business associate agreement.
(c) Subprocessor Disclosure. Exhibit A lists each Subcontractor that creates, receives, maintains, or transmits PHI in connection with the Eligible Services. Business Associate will use commercially reasonable efforts to keep Exhibit A current, will make its then-current subprocessor list available to Customer upon reasonable written request, and will notify Customer in writing at least thirty (30) days before adding a new category of Subcontractor that will process PHI, except where a shorter period is necessary to address a security or availability need.
(d) Responsibility for Subcontractors. Business Associate remains responsible to Customer for the performance by its Subcontractors of the obligations with respect to PHI that Business Associate is required to impose on them under this Section C.5, to the same extent as if Business Associate had performed those obligations itself.
(e) Subcontractor Violations. If Business Associate knows of a pattern of activity or practice of a Subcontractor that constitutes a material breach or violation of the Subcontractor's obligations with respect to PHI, Business Associate will take reasonable steps to cure the breach or end the violation and, if those steps are unsuccessful, will terminate its arrangement with that Subcontractor, if feasible, consistent with 45 CFR § 164.504(e)(1)(iii).
(f) Data Location. Exhibit A identifies, where known, the location in which each Subcontractor processes PHI. Business Associate will not move its primary storage of PHI at rest to a location outside the United States without at least thirty (30) days' prior written notice to Customer.
6. Reporting of Impermissible Uses and Disclosures, Security Incidents, and Breaches.
(a) Standards. For purposes of this Section C.6: (i) an "Impermissible Use or Disclosure" is any use or disclosure of PHI not permitted by this Agreement; (ii) a Security Incident includes, among other things, ransomware or other malicious software that encrypts, exfiltrates, or otherwise affects ePHI; and (iii) consistent with 45 CFR § 164.402, an acquisition, access, use, or disclosure of Unsecured PHI in a manner not permitted by Subpart E of 45 CFR Part 164 is presumed to be a Breach unless an exception in that section applies or it is demonstrated, through a risk assessment of at least the factors set out in that section, that there is a low probability that the PHI has been compromised. Not every Security Incident is a Breach, and not every Impermissible Use or Disclosure is a Breach of Unsecured PHI.
(b) Discovery. A Breach, Impermissible Use or Disclosure, or Security Incident is treated as discovered by Business Associate on the first day on which it is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate, including to any person (other than the person committing it) who is a workforce member or agent of Business Associate, consistent with 45 CFR § 164.410(a)(2). This Section C.6 applies to events involving Business Associate's Subcontractors of which Business Associate becomes aware.
(c) Initial Report. Business Associate will report to Customer any Impermissible Use or Disclosure (including any that may constitute a Breach of Unsecured PHI) and any successful Security Incident without unreasonable delay, and in no event later than ten (10) business days after discovery. The initial report will describe what is then known and need not await completion of Business Associate's investigation.
(d) Content and Supplementation. Business Associate will provide Customer, as the information becomes available: (i) identification of each Individual whose Unsecured PHI has been, or is reasonably believed by Business Associate to have been, accessed, acquired, used, or disclosed; (ii) a description of what happened, including the date of the event and the date of its discovery, if known; (iii) the types of PHI involved; (iv) the steps Business Associate has taken to investigate, contain, and mitigate the event and to protect against recurrence; (v) information reasonably available to Business Associate that is relevant to the risk assessment described in Section C.6(a); and (vi) any other information available to Business Associate that Customer or the Covered Entity is required to include in notifications under 45 CFR § 164.404(c). Business Associate will supplement its report promptly as additional information becomes available, and will provide all such information then available to it no later than sixty (60) calendar days after discovery, consistent with 45 CFR § 164.410.
(e) Risk Assessment and Notification. Business Associate will conduct a reasonable investigation of each event reportable under Section C.6(c) and share its findings with Customer. As between the Parties, Customer (or, where Customer is a business associate, the Covered Entity) is responsible for determining whether a Breach of Unsecured PHI has occurred that requires notification, and for providing any notification to Individuals, the Secretary, the media, or others, unless the Parties agree in writing that Business Associate will perform the risk assessment or provide notifications on Customer's behalf. Business Associate will not notify Individuals, regulators, or the media of an event involving Customer's PHI without Customer's prior written consent, except as Required by Law.
(f) Law Enforcement Delay. Business Associate may delay a report under this Section C.6 to the extent a law enforcement official states that the report would impede a criminal investigation or cause damage to national security, in accordance with 45 CFR § 164.412.
(g) Unsuccessful Security Incidents. The Parties acknowledge that unsuccessful Security Incidents — such as pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, and blocked malicious traffic, in each case that do not result in unauthorized access, use, disclosure, modification, or destruction of PHI or in interference with system operations — occur in the ordinary course of business. This Section C.6(g) constitutes notice by Business Associate to Customer of the ongoing existence of such unsuccessful Security Incidents, and no further report of them is required.
(h) Events Caused by Customer. Business Associate's reporting obligations under this Section C.6 apply to events discovered by Business Associate regardless of cause. Business Associate is not responsible for any Impermissible Use or Disclosure, Security Incident, or Breach to the extent caused by Customer, its authorized users, or systems or credentials under Customer's control.
7. De-Identified Information.
(a) Right to de-identify. Business Associate may use PHI it creates, receives, maintains, or transmits in connection with the Eligible Services to create De-Identified Information, in accordance with the de-identification standard set forth at 45 CFR § 164.514(b) — using either: (i) the "Safe Harbor" method under 45 CFR § 164.514(b)(2), under which all eighteen categories of identifiers of the individual or of relatives, employers, or household members of the individual enumerated in that section (including, without limitation, names; geographic subdivisions smaller than a state; all elements of dates other than year; telephone and fax numbers; email addresses; Social Security numbers; medical record, health plan, and account numbers; certificate/license numbers; vehicle and device identifiers; URLs and IP addresses; biometric identifiers; full-face photographs and comparable images; and any other unique identifying number, characteristic, or code) are removed, and Business Associate has no actual knowledge that the remaining information could be used, alone or in combination, to identify the individual; or (ii) the "Expert Determination" method under 45 CFR § 164.514(b)(1), under which a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable determines that the risk is very small that the information could be used, alone or in combination with other reasonably available information, to identify the individual, and documents the methods and results of that analysis.
(b) Scope of the right. This right attaches only to information that actually satisfies the de-identification standard described in Section C.7(a). It does not extend to, and nothing in this Section C.7 authorizes any use of, PHI or any other information that has not been de-identified in accordance with that standard. Aggregated, pseudonymized, tokenized, or summarized information that does not meet that standard remains PHI. Business Associate will not represent information as de-identified, or treat it as outside the scope of this Agreement's PHI-handling restrictions, unless it in fact meets the Safe Harbor or Expert Determination standard.
(c) Use of De-Identified Information. Once information meets the de-identification standard described in Section C.7(a), it is no longer PHI under HIPAA. As between the Parties, and solely with respect to such De-Identified Information, Business Associate may use and disclose it for: (i) internal analytics and reporting; (ii) product and service improvement; (iii) benchmarking; and (iv) training, fine-tuning, and evaluating Business Associate's own artificial intelligence models and algorithms.
Business Associate will not exercise the rights in clause (iv) until it has documented, in writing, a de-identification methodology meeting the Safe Harbor or Expert Determination standard described in Section C.7(a), and has completed an internal compliance review of that methodology confirming it is actually applied in practice. At least thirty (30) days before first exercising, or resuming after a material change to the methodology or to the models or data combinations to which it is applied, the rights in clause (iv), Business Associate will notify Customer in writing and, upon Customer's written request, provide a summary of the documented methodology and confirmation that the compliance review has occurred. Business Associate will re-validate the methodology at least annually and will not continue to exercise clause (iv) on the basis of a stale validation.
Business Associate will not use or disclose De-Identified Information in a manner that identifies Customer (e.g., by pharmacy or practice name) as its source. De-Identified Information is Business Associate's data for these purposes and is not Customer Data or PHI subject to Section E.3 (Return or Destruction of PHI).
(d) No re-identification. Business Associate will not attempt to re-identify De-Identified Information, or use it alone or in combination with other information to identify any Individual, and will not disclose De-Identified Information to any third party unless that third party agrees in writing not to attempt to re-identify it.
8. Performance of Covered Entity Obligations. To the extent Business Associate is to carry out any obligation of Customer or the Covered Entity under Subpart E of 45 CFR Part 164, Business Associate will comply with the requirements of Subpart E that apply to Customer or the Covered Entity in the performance of that obligation, as required by 45 CFR § 164.504(e)(2)(ii)(H). For the avoidance of doubt, and consistent with Section C.4(c), the Parties do not intend for Business Associate to carry out any such obligation except as expressly agreed in writing.
9. Mitigation and Cooperation. Business Associate will mitigate, to the extent practicable, any harmful effect known to Business Associate of an Impermissible Use or Disclosure by Business Associate or its Subcontractors, including by containing the event and remediating the underlying vulnerability. Following an event reportable under Section C.6 that was caused by Business Associate or its Subcontractors, Business Associate will, at its own cost: (a) preserve evidence reasonably relevant to the event, consistent with its legal obligations; (b) reasonably cooperate with Customer's investigation and with Customer's performance of its notification obligations under 45 CFR §§ 164.404 through 164.408, including by providing the information described in Section C.6(d); and (c) reasonably cooperate with any resulting inquiry or investigation by the Secretary or another regulator concerning the event. Where an event was caused by Customer, its authorized users, or systems or credentials under Customer's control, Business Associate will provide reasonable cooperation at Customer's reasonable expense.
10. No Sale of PHI; No Marketing or Fundraising. Business Associate will not sell PHI, or receive direct or indirect remuneration in exchange for PHI, except as permitted by 45 CFR § 164.502(a)(5)(ii), and will not use or disclose PHI for marketing or fundraising purposes.
11. Workforce Security. Business Associate has designated a security official responsible for the development and implementation of its security policies and procedures, as required by 45 CFR § 164.308(a)(2), who is identified in the signature block of this Agreement and may be changed by written notice to Customer. Business Associate will provide security awareness training to members of its workforce who have access to PHI, apply appropriate sanctions against workforce members who fail to comply with its security policies and procedures, and terminate a workforce member's access to PHI when that access is no longer required, in each case consistent with 45 CFR § 164.308(a).
12. Artificial Intelligence and Machine Learning.
(a) PHI as input. Business Associate may process PHI using artificial intelligence and machine-learning systems, including those of its AI Subprocessors, solely to perform the Eligible Services for Customer and otherwise as permitted by Section C.1. Business Associate's obligations with respect to AI Subprocessors are set out in Section C.5(b).
(b) No training on PHI. Business Associate will not use PHI to train, fine-tune, or otherwise improve any artificial intelligence or machine-learning model, whether its own or a third party's, including any general-purpose model. Business Associate may use De-Identified Information for those purposes only as set out in Section C.7.
(c) No cross-customer use. Business Associate will not use Customer's PHI to provide services to, or for the benefit of, any other customer, will not use any other customer's PHI in providing the Eligible Services to Customer, and, except as permitted by Section C.7 for De-Identified Information, will not combine Customer's PHI with the PHI of any other customer.
(d) Inputs, outputs, and derived data. Prompts, inputs, outputs, generated content, embeddings and other vector or numerical representations, call audio and recordings, transcripts, logs, caches, and metadata that contain PHI, or that are derived from PHI and have not been de-identified in accordance with Section C.7(a), are PHI for purposes of this Agreement and are subject to the same protections and return or destruction obligations as other PHI. Business Associate's models, model weights, prompt templates, algorithms, and other technology that do not contain PHI are not Customer Data and remain subject to Section F.3.
13. Legal Process and Government Requests. If Business Associate receives a subpoena, court order, warrant, discovery request, administrative or law-enforcement request, or other legal process seeking PHI, Business Associate will: (a) disclose PHI only to the extent the disclosure is Required by Law or otherwise permitted by HIPAA and this Agreement, and only the minimum necessary to comply; (b) where legally permitted, promptly notify Customer before disclosing, so that Customer may seek a protective order or other remedy, and reasonably cooperate with those efforts at Customer's expense; and (c) where appropriate, refer the requester to Customer. Business Associate is not required to notify Customer where notice is prohibited by law or by the terms of the legal process. This Section C.13 does not apply to requests by the Secretary under Section C.3(a).
14. Recordkeeping. Business Associate will retain the documentation it is required to maintain under 45 CFR § 164.316(b) for six (6) years from the date of its creation or the date when it was last in effect, whichever is later, and will retain the disclosure documentation described in Section C.4(d) for the period stated there. This Section C.14 concerns HIPAA compliance documentation; it does not require Business Associate to retain PHI or medical records, which are addressed in Sections D.6 and E.3.
15. Ownership of PHI. As between the Parties, Customer or the Covered Entity retains all rights in PHI. Nothing in this Agreement transfers ownership of PHI to Business Associate, and Business Associate's creation, receipt, maintenance, processing, or transmission of PHI does not give it any ownership interest in PHI. Business Associate's rights with respect to De-Identified Information are limited to those set out in Section C.7.
16. Voice Services. To the extent Customer uses the Voice Services:
(a) Call audio, recordings, transcripts, summaries, voicemail content, and call metadata that contain or are derived from PHI are PHI for purposes of this Agreement and are subject to Section C.12(d).
(b) Business Associate will design the Voice Services to limit the PHI disclosed during calls and in voicemail messages to the minimum necessary for the purpose of the call, consistent with the call scripts, identity-verification steps, and settings Customer configures.
(c) Business Associate will honor confidential-communication preferences and contact restrictions that Customer communicates or configures, as provided in Section C.4(e).
(d) A call placed to an unintended recipient, or a disclosure of PHI to a person who has not been verified in accordance with Customer's configuration, is reportable under Section C.6. Consistent with Section C.6(h), Business Associate is not responsible for such a disclosure to the extent it results from inaccurate contact information, call lists, or instructions provided by Customer.
D. Customer Obligations
-
Customer will not request that Business Associate use or disclose PHI in a manner that would violate HIPAA or other applicable federal or state law if done by the Covered Entity. Customer will use or disclose only the minimum amount of PHI necessary in its use of the Eligible Services.
-
Customer will use and disclose PHI through the Eligible Services only as permitted by, and in accordance with, HIPAA and other applicable federal and state law, and will comply with all applicable laws and regulations pertaining to PHI that Customer shares with, sends, or directs to be sent to, Business Associate.
-
Customer will notify Business Associate of any limitation in the notice of privacy practices of Customer or, where Customer is a business associate, of the Covered Entity to the extent known to Customer, under 45 CFR § 164.520, to the extent such limitation may affect Business Associate's use or disclosure of PHI.
-
Customer will notify Business Associate of any change in, or revocation of, an Individual's permission to use or disclose PHI, to the extent such change may affect Business Associate's use or disclosure of PHI.
-
Customer will notify Business Associate of any restriction on the use or disclosure of PHI that Customer or the Covered Entity has agreed to or is required to comply with under 45 CFR § 164.522, to the extent such restriction may affect Business Associate's use or disclosure of PHI.
-
Customer is solely responsible for its own obligations to retain PHI and medical records under applicable law, and should not rely on the Eligible Services as a substitute for its own records-retention program. Business Associate retains PHI processed through the Eligible Services for the duration of this Agreement and does not automatically delete it. During the term, Customer may export Customer Data using the functionality then available in the Eligible Services. Following termination or expiration of this Agreement, PHI is handled as set out in Section E.3.
-
Customer acknowledges and agrees that Customer controls how the Eligible Services are used and configured, including what data Customer submits, which staff or systems are authorized to access the Eligible Services, and how AI-assisted features are used in Customer's workflow, and that some uses or configuration choices available within the Eligible Services could be inconsistent with the requirements of HIPAA. Business Associate is not responsible for configuration choices or usage decisions made by Customer or Customer's authorized users. Customer represents, warrants, and covenants that it will appropriately inform its authorized users regarding the appropriate use of the Eligible Services in a manner consistent with HIPAA and with any implementation or configuration documentation Business Associate makes available to Customer from time to time.
-
Customer will notify Business Associate before transmitting any Part 2 Records, as described in Section B, and is responsible for identifying and configuring the data sources it connects to the Eligible Services accordingly.
-
Customer represents, warrants, and covenants that: (a) it has full legal authority to provide, and to direct Business Associate to create, receive, maintain, or transmit, all PHI and other data it submits to or generates through the Eligible Services; (b) it has obtained and will maintain all consents, authorizations, notices of privacy practices, and other permissions required under HIPAA and applicable federal and state law (including, where applicable, the California Confidentiality of Medical Information Act) for Business Associate to process such PHI as contemplated by this Agreement, including processing by Business Associate's Subcontractors and AI Subprocessors; and (c) Business Associate is entitled to rely on Customer's representations in this Section D.9 without independent investigation. Business Associate has no obligation to obtain, verify, or maintain any patient consent or authorization, and Customer is solely responsible for its relationship with, and its disclosures to, the Individuals whose PHI it submits.
-
Nothing in this Section D relieves Business Associate of any obligation it has under HIPAA or under Sections A through E of this Agreement.
E. Term and Termination
1. Term. This Agreement is effective as of the date last signed by the Parties below, or the date of Customer's electronic acceptance under Exhibit B, whichever occurs first (the "Effective Date"), and will terminate upon the earliest of: (a) termination under Section E.2; (b) termination under Section G.10; or (c) if the Eligible Services are provided under an Underlying Agreement, the termination or expiration of that Underlying Agreement, unless the Parties continue the Eligible Services under another agreement to which this Agreement applies. In each case, Sections A through E will continue to apply to any PHI retained by Business Associate after such termination until disposition of all such PHI in accordance with Section E.3.
Retroactive Application. Where Business Associate created, received, maintained, or transmitted PHI for or on behalf of Customer prior to the Effective Date, Sections A through E of this Agreement apply retroactively to all such PHI, and to Business Associate's acts and omissions with respect to it, from the date Business Associate first received such PHI, as if this Agreement had been in effect on that date.
2. Termination for Material Breach. If a Party determines that the other Party has violated a material term of this Agreement, the non-breaching Party will provide the breaching Party written notice and an opportunity to cure. If the breach is not cured to the reasonable satisfaction of the non-breaching Party within thirty (30) days of the breaching Party's receipt of notice of the breach, the non-breaching Party may terminate this Agreement. If cure is not possible, the non-breaching Party may terminate this Agreement upon written notice.
Notwithstanding the foregoing, Customer may suspend the transmission of PHI to Business Associate immediately, and may terminate this Agreement immediately upon written notice and without a cure period, in the event of a Breach of Unsecured PHI caused by the material failure of Business Associate or its Subcontractors to comply with this Agreement, or a material failure of Business Associate's safeguards under Section C.2. Suspension under this paragraph is not a breach by Customer of any obligation under this Agreement.
3. Return or Destruction of PHI. While Customer continues to have access to the Eligible Services, Customer may use available export functionality to export Customer Data (including PHI) from the Eligible Services, as further described in the Documentation. Business Associate will maintain and permit Customer access to Customer Data (including PHI) in its possession for thirty (30) days following termination or expiration of this Agreement. Thereafter, Business Associate will:
(a) retain only that PHI which is necessary for Administrative Purposes, as defined in Section C.1(b);
(b) return to Customer or destroy all remaining PHI created, received, maintained, or transmitted by Business Associate for or on behalf of Customer that Business Associate or its Subcontractors still maintain in any form, if feasible;
(c) if return or destruction of any remaining PHI is not feasible — meaning applicable law prohibits it, or it is not technically possible to do so without disproportionate cost or effort — retain that PHI and limit further use and disclosure to those purposes that make return or destruction infeasible;
(d) continue to extend the protections of this Agreement, including the safeguards required by Section C.2, to any PHI retained under clause (a) or (c), and not use or disclose that PHI other than for the purposes for which it was retained; and
(e) return or destroy PHI retained under clause (a) when it is no longer needed for the purposes for which it was retained.
Business Associate's obligations under this Section E.3 survive termination. Upon Customer's written request, Business Associate will provide Customer a written explanation of the basis for retaining any PHI under clause (a) or (c), including a general description of the PHI retained and the purpose(s) for which it is retained.
PHI contained in backup or archival media will be destroyed in the ordinary course of Business Associate's backup rotation rather than on an accelerated basis, will not be restored except as necessary for disaster recovery, and will remain subject to the protections of this Agreement until destroyed. Upon Customer's written request, Business Associate will certify in writing that return or destruction under this Section E.3 has been completed, subject to the retention described in this Section E.3.
For the avoidance of doubt, this Section E.3 does not apply to De-Identified Information, which Business Associate may retain and use as described in Section C.7, or to documentation retained under Section C.14, which remains subject to Section E.3(d) to the extent it contains PHI.
F. The Services
1. Provision of the Services. Subject to Customer's compliance with this Agreement, Business Associate grants Customer a non-exclusive, non-transferable, non-sublicensable right, during the term, for Customer's authorized users to access and use the Eligible Services solely for Customer's own internal business operations, in accordance with the Documentation.
2. Restrictions. Customer will not, and will not permit any third party to: (a) reverse engineer, decompile, or attempt to derive the source code of the Eligible Services, except to the extent such restriction is prohibited by applicable law; (b) sell, resell, sublicense, rent, or lease the Eligible Services to any third party; (c) use the Eligible Services to build a competing product; or (d) use the Eligible Services in violation of applicable law.
3. Reservation of Rights. Business Associate and its licensors retain all right, title, and interest in and to the Eligible Services, the Documentation, and any underlying software, models, and technology, including all intellectual property rights therein. No rights are granted to Customer other than as expressly set forth in this Agreement.
4. No Healthcare Services; No Clinical or Coverage Determinations. Business Associate is a software and workflow-automation company, not a healthcare provider, health plan, pharmacy, or payer, and does not practice medicine or pharmacy. The Eligible Services assist Customer's licensed personnel in preparing, organizing, and transmitting prior-authorization requests; they do not diagnose, treat, or make any clinical, coverage, medical-necessity, or prescribing determination.
All clinical judgments, treatment decisions, and decisions to submit, modify, or rely on any prior-authorization request or its content are made solely by Customer and Customer's licensed personnel, who remain solely responsible for their accuracy, medical appropriateness, and timeliness, and for Customer's compliance with all professional, licensing, and standard-of-care obligations applicable to Customer's practice. Any AI-generated suggestion, draft, or extraction is a drafting aid only and creates no obligation for any payer or third party. The Eligible Services transmit a prior-authorization request to a payer or utilization-management portal only after review and approval by Customer's authorized personnel, and at Customer's direction.
5. Submission Status and Failure Notification. Business Associate will make available within the Eligible Services a current status for each prior-authorization request, and will surface within the Eligible Services any request that Business Associate's systems determine has failed to transmit or has been rejected by the payer or portal. Customer remains responsible for monitoring the status of its prior-authorization requests and for following up with payers as its clinical and business judgment requires. Business Associate does not guarantee that any prior-authorization request will be approved, accepted, or processed within any particular time.
6. Customer Data; License to Business Associate. As between the Parties, Customer retains all right, title, and interest in and to Customer Data. Customer grants Business Associate a non-exclusive, worldwide, royalty-free license to host, copy, process, transmit, display, and otherwise use Customer Data as necessary to provide, maintain, secure, and support the Eligible Services, to perform its obligations under this Agreement, and to comply with applicable law. The license in this Section F.6 does not extend to PHI except as necessary to provide the Eligible Services, and Business Associate will not process PHI through any feature, product, or environment that is not an Eligible Service.
Business Associate may also collect and use technical, usage, configuration, and performance data relating to the operation of the Eligible Services — in each case excluding PHI and excluding data that identifies Customer — to operate, analyze, secure, support, and improve the Eligible Services. Business Associate will implement and maintain technical measures designed to exclude PHI from its error-tracking, telemetry, and analytics systems.
Nothing in this Section F.6 limits, and this Section F.6 is expressly subject to, Business Associate's rights under Section C.7; De-Identified Information is not Customer Data.
7. Fees and Payment. Customer will pay the fees set forth in the applicable order form or other written pricing agreement between the Parties (each, an "Order Form"). Except as otherwise stated in an Order Form, fees are due within thirty (30) days of the invoice date; are non-refundable except as expressly provided in this Agreement; and are exclusive of applicable taxes, which are Customer's responsibility (excluding taxes on Business Associate's net income). Late payments may accrue interest at the lesser of one and one-half percent (1.5%) per month or the maximum rate permitted by law.
8. Warranty Disclaimer. Except as expressly stated in this Agreement, the Eligible Services are provided "as is," and Business Associate disclaims all other warranties, express or implied, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranty arising from course of dealing or usage of trade, to the maximum extent permitted by applicable law.
Without limiting the foregoing, Customer acknowledges that the Eligible Services incorporate artificial intelligence and machine-learning components, and that AI-generated output is probabilistic in nature: it may be incomplete, inaccurate, or unsuitable for a particular purpose, and identical inputs may produce different outputs. Business Associate does not warrant that any AI-generated suggestion, draft, extraction, or summary will be accurate or complete, or that the Eligible Services will be uninterrupted or error-free. Consistent with Section F.4, Customer's licensed personnel are responsible for reviewing all output before relying on or submitting it.
9. Confidentiality. Each Party will protect the other Party's non-public business, technical, and financial information that is designated as confidential or that a reasonable person would understand to be confidential ("Confidential Information") using at least reasonable care, will use it only to perform under this Agreement, and will disclose it only to its employees, contractors, and advisors who need to know it and are bound by confidentiality obligations at least as protective as this Section F.9, or as required by law. Confidential Information does not include information that is or becomes public through no fault of the receiving Party, was known to the receiving Party without restriction before disclosure, is received from a third party without restriction, or is independently developed without use of the disclosing Party's Confidential Information. Security documentation, questionnaire responses, and audit reports that Business Associate provides under Section C.3 are Business Associate's Confidential Information. PHI is governed exclusively by Sections A through E, and this Section F.9 does not expand or narrow the definition of PHI.
10. Voice Services.
(a) Customer responsibilities. Customer determines whom the Voice Services call and for what purpose. Where Customer uses the Voice Services, Customer represents, warrants, and covenants that it will: (i) obtain and maintain any consent required under the Telephone Consumer Protection Act (47 U.S.C. § 227) and its implementing regulations, including for calls using artificial or AI-generated voices, and under applicable state automated-calling and telemarketing laws, and honor applicable do-not-call requests; (ii) obtain any consent, and configure any notice, required by federal or state laws governing the recording or monitoring of calls, including laws requiring the consent of all parties to a call; (iii) configure any disclosure required by applicable law that a caller is an automated or artificial intelligence system; (iv) provide accurate contact information and call lists; and (v) ensure that the call scripts and content of calls placed at its direction comply with applicable law.
(b) Not for emergencies or clinical advice. The Voice Services are not an emergency service and do not provide medical advice, triage, or clinical determinations. Customer will not use the Voice Services for those purposes and will ensure that people who need to reach Customer's personnel can do so.
(c) No guarantee of call outcomes. Business Associate does not guarantee that any call will connect, be completed, or produce any particular result. AI-generated speech, transcripts, and summaries are subject to Section F.8.
G. Liability, Indemnification, and Insurance
1. Exclusion of Certain Damages. To the maximum extent permitted by applicable law, in no event will either Party be liable to the other for any indirect, incidental, consequential, special, exemplary, or punitive damages, or for any loss of profits, revenue, or goodwill, arising out of or related to this Agreement, regardless of the theory of liability, even if such Party has been advised of the possibility of such damages.
2. Liability Cap. Subject to Sections G.3 and G.4, each Party's total, aggregate liability arising out of or related to this Agreement will not exceed an amount equal to the total fees paid or payable by Customer to Business Associate in the twelve (12) months immediately preceding the event giving rise to the claim (the "Liability Cap").
3. Carve-Outs from the Caps. The exclusions in Section G.1, the Liability Cap, and the Enhanced Cap do not apply to: (a) Business Associate's obligations under Section G.6(a); (b) Customer's obligations under Sections G.7(a), G.7(c), and G.7(d); (c) either Party's fraud, gross negligence, or willful misconduct; or (d) Customer's payment obligations under Section F.7. Nothing in this Agreement limits or excludes either Party's liability to the extent such limitation or exclusion is prohibited by applicable law, including California Civil Code § 1668.
4. Enhanced Cap for Data Protection Claims. In lieu of the Liability Cap, each Party's total, aggregate liability arising out of or relating to any unauthorized access to, use, or disclosure of PHI or Customer Data, or to a breach of its obligations under Sections A through E, regardless of the theory of liability (including contract, tort, negligence, statute, and indemnification, including under Sections G.6(b) and G.7(b)), will not exceed the greater of: (a) two million dollars ($2,000,000); or (b) three (3) times the total fees paid or payable by Customer to Business Associate in the twelve (12) months immediately preceding the event giving rise to the claim (the "Enhanced Cap").
For the avoidance of doubt, Section G.1 does not exclude direct damages, breach-notification and credit-monitoring costs, regulatory fines and penalties, or forensic-investigation costs incurred as a result of a matter subject to this Section G.4, and the Enhanced Cap does not limit the liability described in Section G.3.
The Parties agree that the Liability Cap and the Enhanced Cap reflect a deliberate and bargained-for allocation of risk between them, that the fees for the Eligible Services were set in reliance on that allocation, and that these limitations apply regardless of whether a limited remedy fails of its essential purpose.
5. Limitations Period. Except for claims for non-payment, claims arising from unauthorized access to, use, or disclosure of PHI, and either Party's indemnification obligations, neither Party may bring any claim arising out of or related to this Agreement more than one (1) year after the date on which the claiming Party knew or reasonably should have known of the facts giving rise to the claim. This Section G.5 does not apply to the extent applicable law prohibits contractual shortening of the limitations period for the claim at issue, and does not shorten any statutory notification or enforcement period applicable to a governmental authority.
6. Indemnification by Business Associate. Business Associate will defend Customer against any third-party claim to the extent arising from: (a) an allegation that the Eligible Services, as provided by Business Associate and used by Customer in accordance with this Agreement, infringe or misappropriate a third party's U.S. intellectual property rights; or (b) Business Associate's breach of its obligations regarding PHI under Sections A through E; and will indemnify Customer against damages finally awarded (or amounts agreed in settlement) as a result.
Section G.6(a) does not apply to the extent a claim arises from: (i) Customer Data; (ii) modification of the Eligible Services by anyone other than Business Associate; (iii) combination of the Eligible Services with products or services not provided by Business Associate; or (iv) Customer's use of the Eligible Services other than in accordance with this Agreement and the Documentation. If the Eligible Services become, or Business Associate reasonably believes they may become, the subject of an infringement claim, Business Associate may, at its option: procure the right for Customer to continue using the Eligible Services; modify or replace them to make them non-infringing; or, if neither is commercially reasonable, terminate the affected services and refund Customer any prepaid, unused fees for the terminated portion. This Section G.6(a) states Business Associate's entire liability, and Customer's sole remedy, for infringement claims.
7. Indemnification by Customer. Customer will defend Business Associate against any third-party claim — including, without limitation, a claim brought by a patient or other Individual, or by Customer's own employee, contractor, or agent — to the extent arising from: (a) Customer's or its authorized users' misuse or misconfiguration of the Eligible Services, including use inconsistent with the Documentation or Customer's responsibilities under Section D.7; (b) PHI or other data that Customer submitted, or directed Business Associate to receive, create, maintain, or transmit, without authorization or without the consents required under Section D.9 (including any Part 2 Records transmitted without the notice required by Section D.8); (c) any clinical, medical-necessity, coverage, or prescribing determination, or any decision to submit or not to submit a prior-authorization request, made or approved by Customer or its licensed personnel, consistent with Section F.4; or (d) any call placed or received through the Voice Services at Customer's direction, to the extent the claim arises from Customer's failure to comply with Section F.10(a), including any claim under the Telephone Consumer Protection Act or laws governing call recording, automated calling, or disclosure of artificial intelligence; and will indemnify Business Associate against damages finally awarded (or amounts agreed in settlement) as a result.
Customer's obligations under this Section G.7 do not apply to the extent the claim arises from Business Associate's breach of this Agreement or from Business Associate's negligence, error, omission, or failure of the Eligible Services.
8. Indemnification Procedure. The indemnified Party will: (a) promptly notify the indemnifying Party of the claim in writing (provided that failure to promptly notify only relieves the indemnifying Party of its obligations to the extent it is materially prejudiced); (b) give the indemnifying Party sole control of the defense and settlement of the claim (except that the indemnifying Party may not settle any claim in a manner that admits fault by, or imposes any obligation on, the indemnified Party without its prior written consent); and (c) provide reasonable cooperation, at the indemnifying Party's expense.
9. Insurance.
(a) Business Associate. Business Associate will maintain, throughout the term of this Agreement, insurance coverage of the types and at the minimum limits set out below, and will provide a certificate of insurance evidencing such coverage upon Customer's reasonable written request:
- Commercial General Liability: $1,000,000 per occurrence / $2,000,000 aggregate
- Cyber Liability / Data Breach (covering, at minimum, unauthorized access to or disclosure of PHI and other confidential information, and breach response costs): $2,000,000 per claim / $2,000,000 aggregate
- Technology Errors & Omissions: $2,000,000 per claim / $2,000,000 aggregate
The cyber liability and technology errors and omissions coverage may be provided under a single combined policy, provided its limits are not less than $2,000,000 per claim and in the aggregate.
(b) Customer. Customer will maintain, throughout the term of this Agreement, at its own expense: (i) professional liability (medical malpractice) insurance of not less than $1,000,000 per claim and $3,000,000 in the aggregate; and (ii) commercial general liability insurance of not less than $1,000,000 per occurrence, in each case covering claims arising from Customer's clinical, coverage, and prescribing decisions and its provision of health care services, including claims described in Section G.7. Customer will provide a certificate of insurance evidencing such coverage upon Business Associate's reasonable written request.
The existence of insurance coverage does not limit or expand either Party's liability or obligations under this Agreement, including the Liability Cap and the Enhanced Cap.
10. Termination for Convenience. Either Party may terminate this Agreement for convenience upon thirty (30) days' prior written notice to the other Party, effective no earlier than the end of the then-current term under the applicable Order Form. Business Associate may additionally suspend or terminate Customer's access to the Eligible Services immediately upon notice if Customer's use poses a security risk, may expose Business Associate to liability, or is fraudulent.
11. Effect of Termination. Upon termination or expiration of this Agreement: (a) Customer's right to access and use the Eligible Services ends; (b) Customer remains liable for all fees accrued through the effective date of termination; and (c) handling, return, and destruction of PHI is governed by Section E.3. Sections C.7 (De-Identified Information), C.14 (Recordkeeping), C.15 (Ownership of PHI), E.3 (Return or Destruction of PHI), F.2 (Restrictions), F.3 (Reservation of Rights), F.4 (No Healthcare Services), F.6 (Customer Data; License — solely as necessary to perform Business Associate's obligations under Section E.3 and to retain De-Identified Information), F.8 (Warranty Disclaimer), F.9 (Confidentiality), F.10 (Voice Services), G (Liability, Indemnification, and Insurance), and H (General) survive any termination or expiration of this Agreement, as do Sections A through E with respect to any PHI that Business Associate retains, as provided in Section E.1.
H. General
1. Relationship of the Parties; No Agency. The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, or agency relationship. For purposes of 45 CFR §§ 164.402, 164.404(a)(2), and 164.410(a)(2), Business Associate is an independent contractor and not an agent of Customer; Customer does not have the right to control the manner and means by which Business Associate performs the Eligible Services, and Business Associate's discovery of a Breach is not imputed to Customer.
2. Amendment; Changes in Law. This Agreement may be amended only by a written instrument signed or electronically accepted by both Parties. Business Associate may offer an updated version of this Agreement from time to time; an updated version binds Customer only upon Customer's Organization Acceptance of it under Exhibit B or its execution by both Parties, and until then the version previously accepted or executed continues to apply. If HIPAA, 42 CFR Part 2, or other law applicable to PHI, or binding guidance issued by the U.S. Department of Health and Human Services, is amended or interpreted in a manner that requires amendment of this Agreement, the Parties will cooperate in good faith to amend this Agreement to the extent necessary to comply, within any compliance period provided for the change. If the Parties cannot agree on necessary amendments, or if a Party believes in good faith that the change makes it commercially impracticable to provide or use the Eligible Services in compliance with applicable law, either Party may terminate this Agreement on at least thirty (30) days' written notice.
3. Interpretation. Any ambiguity in Sections A through E will be resolved in favor of a meaning that permits the Parties to comply with HIPAA. A reference in this Agreement to a section of HIPAA, 42 CFR Part 2, or other law means that section as in effect from time to time, including any amendment or successor provision. Headings are for convenience only.
4. No Third-Party Beneficiaries. Nothing in this Agreement confers any rights, remedies, obligations, or liabilities upon any person other than the Parties and their respective successors and permitted assigns — including, without limitation, any Individual whose PHI is processed under this Agreement, or any patient, employee, contractor, or agent of Customer. No such person is a third-party beneficiary of, or may bring any claim to enforce, this Agreement.
5. Assignment. Neither Party may assign this Agreement without the other Party's prior written consent, except that either Party may assign this Agreement without consent in connection with a merger, acquisition, or sale of all or substantially all of its assets. This Agreement binds and benefits the Parties' permitted successors and assigns.
6. Notices. Notices under this Agreement must be in writing and delivered to the contacts set forth in the signature block. Notices sent by email are effective on confirmation of delivery. Reports under Section C.6 must be sent by email to the recipient's designated HIPAA contact and may additionally be made by telephone. Notices of termination must additionally be sent by a nationally recognized overnight courier to the recipient's address in the signature block.
7. Force Majeure. Neither Party is liable for any failure or delay in performance (other than payment obligations and obligations under Section C.6) due to causes beyond its reasonable control.
8. No Waiver; Severability. No failure or delay by either Party in exercising any right under this Agreement operates as a waiver of that right. If any provision is held unenforceable, the remaining provisions remain in full force and effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable.
9. Governing Law and Venue. This Agreement is governed by the laws of the State of California, without regard to its conflict-of-laws principles, except to the extent federal law, including HIPAA, governs. The Parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Orange County, California, for any dispute arising out of or relating to this Agreement.
10. Entire Agreement; Order of Precedence. This Agreement, together with all Order Forms and Exhibits, constitutes the entire agreement between the Parties regarding its subject matter and supersedes all prior or contemporaneous understandings regarding that subject matter. If this Agreement is attached to, incorporated into, or executed alongside an Underlying Agreement: (a) Sections A through E of this Agreement control over any conflicting term of the Underlying Agreement or any Order Form on any matter concerning PHI, HIPAA, 42 CFR Part 2, privacy, security, Security Incidents, or Breaches; (b) the Underlying Agreement controls on fees, liability, indemnification, insurance, and other commercial matters to the extent it expressly addresses them and expressly states that it supersedes Sections F through H of this Agreement; and (c) otherwise, this Agreement controls. If the Parties execute a separate business associate agreement that expressly states that it supersedes Sections A through E of this Agreement, that agreement governs the matters it addresses. In the event of a conflict between this Agreement and an Order Form, the Order Form controls solely with respect to the commercial terms it sets out.
11. Counterparts; Electronic Acceptance. This Agreement may be executed in counterparts, including by electronic signature, each of which is deemed an original. This Agreement may alternatively be accepted electronically in accordance with Exhibit B, and such acceptance has the same legal effect as a handwritten signature under the federal Electronic Signatures in Global and National Commerce Act and the California Uniform Electronic Transactions Act.
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the Effective Date.
| Zoren, Inc. | Customer |
|---|---|
| Zoren, Inc. | [Customer Legal Entity Name] |
| By: ___ | By: ___ |
| Name: Kevin Vu | Name: |
| Title: Chief Executive Officer | Title: |
| Date: | Date: |
| Notice contact: Kevin Vu, Chief Executive Officer, Zoren, Inc., 2615 N. Greenbrier, Santa Ana, CA 92706, [email protected] | Notice contact: [Name, Title, Email, Address] |
| Security official and incident contact: Jason Frager, Security Official, [email protected] (incident reports also to [email protected]) | HIPAA contact: [Name, Title, Email] |
| Customer is a: ☐ Covered Entity ☐ Business Associate |
Exhibit A — Subprocessors
Subcontractors that may create, receive, maintain, or transmit PHI in connection with the Eligible Services, as of the Effective Date:
| Subprocessor | Purpose | Category | Processing Location |
|---|---|---|---|
| Google LLC (Google Cloud Vertex AI) | AI model inference through Vertex AI (primary provider; real-time voice agent for Voice Services) | AI Subprocessor | United States |
| Anthropic, PBC | AI model inference (drafting, extraction, review; fallback provider) | AI Subprocessor | United States |
| OpenAI, L.L.C. | AI model inference (document and fax optical character recognition; speech-to-text, text-to-speech, and embeddings for Voice Services) | AI Subprocessor | United States |
| Microsoft Corporation (Azure) | Application hosting, document storage, and call recording storage | Infrastructure | United States |
| Neon (managed PostgreSQL) | Primary database | Infrastructure | United States (AWS us-east-1) |
| Cloudflare, Inc. | DNS, CDN, WAF, TLS termination | Infrastructure | Global edge network |
| Salesforce, Inc. | Customer relationship management synchronization | Integration | Customer's Salesforce instance |
| Twilio Inc. | SMS notifications; voice calling (Elastic SIP Trunking) for Voice Services | Integration | United States |
| Cisco Systems, Inc. (Webex Calling) | Webex Calling interconnection for Voice Services | Integration | United States |
| MetroFax; iFax | Inbound and outbound fax | Integration | United States |
| Google LLC (Workspace) | Email transmission and platform mailbox | Integration | United States |
| Functional Software, Inc. (Sentry) | Error tracking and monitoring | Operations | United States |
| DigitalRx / DBS | Pharmacy dispense data synchronization | Integration | United States |
The call-handling platform used to provide the Voice Services (Asterisk) is open-source software that Business Associate operates within its own hosting environment, and is not a separate Subcontractor.
Exhibit B — Electronic Acceptance
Part 1 — Two-Tier Acceptance Model
Acceptance of this Agreement operates at two distinct levels. The distinction is material: an individual user cannot bind Customer to this Agreement unless that individual is an Authorized Representative.
(a) Organization Acceptance (binding). This Agreement is accepted on behalf of Customer by an individual with actual authority to bind Customer (an "Authorized Representative"). Only Organization Acceptance, or execution of a signed counterpart, forms this Agreement, including its business associate provisions in Sections A through E.
(b) Individual User Acknowledgment (non-binding on Customer). Each individual who is granted access to the Eligible Services accepts the End User Terms in Part 3. An Individual User Acknowledgment does not form, modify, or evidence Customer's acceptance of this Agreement, does not bind Customer, and creates no business associate relationship.
Electronic acceptance is an alternative to, and not a replacement for, signature; Customer may request a countersigned copy of this Agreement instead. Business Associate will request Organization Acceptance or execution of this Agreement from each organization for which it creates, receives, maintains, or transmits PHI.
Existing customers. Where an organization began using the Eligible Services before Organization Acceptance was available, Business Associate will obtain Organization Acceptance (or a signed counterpart) from an Authorized Representative of that organization, and the retroactivity provision in Section E.1 applies to PHI processed before that acceptance.
Part 2 — Organization Acceptance Terms
By completing Organization Acceptance, the accepting individual represents and warrants that: (a) they are an Authorized Representative with actual authority to bind Customer to this Agreement; (b) they have read and accept this Agreement in its entirety, including the business associate provisions in Sections A through E and the liability and indemnification provisions in Section G; and (c) the organization identified in the acceptance record is the legal entity being bound.
Customer's continued use of the Eligible Services after Organization Acceptance constitutes ratification of that acceptance.
Part 3 — End User Terms (Individual Users)
These terms apply to each individual granted access to the Eligible Services. They govern that individual's use only; the agreement between Business Associate and the individual's employing organization governs everything else.
- Authorized use. You may use the Eligible Services only for the legitimate business purposes of the organization that granted you access, and only in accordance with that organization's policies.
- Credentials. You will not share your login credentials or allow any other person to use your account. You will notify your organization and Business Associate promptly if you believe your credentials have been compromised.
- Data you submit. You will submit only information you are authorized by your organization to submit, and only through the features intended for it.
- AI output requires your review. The Eligible Services generate drafts, extractions, and suggestions using artificial intelligence. These may be incomplete or inaccurate. You are responsible for reviewing output before relying on it or submitting it to a payer. The Eligible Services do not provide clinical advice and do not make clinical or coverage determinations.
- Confidentiality. You will treat patient information accessed through the Eligible Services as confidential and will not disclose it except as permitted by your organization and applicable law.
- Logging. Your access to and actions within the Eligible Services, including access to patient information, are logged for security and compliance purposes.
- No individual agreement with your employer's terms. You are not agreeing on behalf of your organization to any contract with Business Associate, and you are not accepting any business associate agreement.
Part 4 — Manner of Electronic Acceptance
Organization Acceptance is completed by an Authorized Representative through an acceptance screen within the Eligible Services that: (a) links to the version of this Agreement being accepted; (b) requires the Authorized Representative to affirmatively select an unchecked checkbox agreeing to this Agreement on Customer's behalf; (c) requires a separate affirmative attestation of authority to bind Customer; and (d) requires the Authorized Representative's name and title.
Individual User Acknowledgment is completed through an acceptance screen that links to the End User Terms and requires the individual to affirmatively select an unchecked checkbox.
For each acceptance, Business Associate records the document and version accepted, the date and time, the accepting individual and organization, and the originating IP address and user agent. Acceptance is not inferred from use alone.