Legal

Business Associate Agreement

Effective

This Business Associate Agreement ("BAA") supplements the Ansabell Terms of Service and Data Processing Addendum between Haven Technologies, Inc. ("Ansabell," "Business Associate," "we," or "us") and a Customer that is a Covered Entity or Business Associate under HIPAA ("Customer" or "Covered Entity"). It governs the creation, receipt, maintenance, and transmission of Protected Health Information ("PHI") by Ansabell on the Customer's behalf when the Customer uses the Ansabell AI voice receptionist service, and reflects the requirements of the HIPAA Privacy, Security, and Breach Notification Rules (45 CFR Parts 160 and 164). PHI may be submitted to the Ansabell service only under this executed BAA.

1. Definitions

Capitalized terms used but not defined in this BAA have the meanings given to them in the HIPAA Rules (45 CFR Parts 160 and 164) or, where not defined there, in the Agreement (the Ansabell Terms of Service and Data Processing Addendum, together with any order). The following terms have the meanings set out below:

  • "Agreement" means the Ansabell Terms of Service and Data Processing Addendum between the parties, together with any applicable order or subscription, into which this BAA is incorporated.
  • "Breach," "Covered Entity," "Data Aggregation," "Designated Record Set," "Disclosure," "Health Care Operations," "Individual," "Minimum Necessary," "Protected Health Information" ("PHI"), "Required By Law," "Secretary," "Security Incident," "Subcontractor," "Unsecured Protected Health Information," and "Use" have the meanings given to those terms in 45 CFR Parts 160 and 164.
  • "Business Associate" means Haven Technologies, Inc. (d/b/a Ansabell).
  • "Electronic PHI" ("ePHI") means PHI that is transmitted or maintained in electronic media.
  • "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164.
  • "Services" means the Ansabell AI voice receptionist service, including answering, recording, and transcribing calls, sending and receiving SMS messages, booking appointments, integrating with calendars and CRMs, and taking payments, in each case on the Customer's behalf.

2. Permitted Uses and Disclosures of PHI by Business Associate

Business Associate may Use or Disclose PHI only as necessary to perform the Services for, or on behalf of, Customer as set out in the Agreement, as permitted or required by this BAA, or as Required By Law. Business Associate will not Use or Disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Customer, except as set out in the Section titled "Permitted Management, Administration, and Data Aggregation."

Business Associate will make reasonable efforts to Use, Disclose, and request only the Minimum Necessary PHI to accomplish the intended purpose of the Use, Disclosure, or request, consistent with 45 CFR 164.502(b), and will not Use or Disclose PHI other than as permitted or required by this BAA or as Required By Law.

Business Associate will not Use or Disclose PHI for its own marketing or advertising, will not sell PHI, and will not Use End-Caller call content, recordings, or transcripts that contain PHI to train third-party foundation models. Business Associate's large-language-model, speech, and telephony subprocessors process such content transiently under terms that, by default, do not use API-submitted data to train foundation models.

3. Obligations and Activities of Business Associate

Business Associate agrees that it will:

  1. Not Use or Disclose PHI other than as permitted or required by this BAA or as Required By Law;
  2. Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided for by this BAA, as further described in the Section titled "Safeguards for Electronic PHI";
  3. Report to Customer any Use or Disclosure of PHI not provided for by this BAA of which it becomes aware, including Breaches of Unsecured PHI and Security Incidents, as set out in the Section titled "Breach and Security Incident Notification";
  4. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA;
  5. Make PHI available, and provide access to PHI, as necessary to satisfy Customer's obligations under 45 CFR 164.524, as set out in the Section titled "Individual Rights";
  6. Make available PHI for amendment and incorporate any amendments to PHI as necessary to satisfy Customer's obligations under 45 CFR 164.526;
  7. Maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy Customer's obligations under 45 CFR 164.528;
  8. To the extent Business Associate is to carry out one or more of Customer's obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Customer in the performance of those obligations;
  9. Make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules, as set out in the Section titled "Availability of Records to the Secretary"; and
  10. Restrict the Use or Disclosure of PHI where Customer notifies Business Associate of a restriction agreed to under 45 CFR 164.522, or of a revocation of an authorization, to the extent such restriction or revocation affects Business Associate's Use or Disclosure of PHI.

4. Subcontractors

Business Associate uses Subcontractors to provide the Services, including its cloud infrastructure provider (Amazon Web Services) and its telephony, speech-to-text, text-to-speech, and language-model providers. Where a Subcontractor creates, receives, maintains, or transmits PHI on behalf of Business Associate, Business Associate will enter into a written agreement with that Subcontractor that imposes restrictions and conditions on the Subcontractor that are at least as protective of PHI as those imposed on Business Associate by this BAA, consistent with 45 CFR 164.502(e)(1)(ii) and 164.308(b).

Business Associate will not permit a Subcontractor to create, receive, maintain, or transmit PHI on its behalf unless and until such a written agreement is in place. Customer's authorization of Business Associate's Subcontractors is governed by the subprocessor provisions of the Data Processing Addendum.

5. Individual Rights (Access, Amendment, and Accounting)

To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will, within [ten (10) business days] of a written request from Customer, make such PHI available to Customer (or, at Customer's direction, to the Individual) as necessary for Customer to meet its access obligations under 45 CFR 164.524.

Business Associate will, within [ten (10) business days] of a written request from Customer, make PHI available for amendment and incorporate any amendment to PHI in a Designated Record Set as necessary for Customer to meet its obligations under 45 CFR 164.526.

Business Associate will document, and within [ten (10) business days] of a written request from Customer make available, the information required for Customer to provide an accounting of disclosures of PHI in accordance with 45 CFR 164.528. Business Associate will retain such documentation for six (6) years from the date of the disclosure.

If an Individual makes a request for access, amendment, or an accounting directly to Business Associate, Business Associate will, within a reasonable time, forward the request to Customer and will not respond to the Individual directly except as directed by Customer or as Required By Law.

6. Availability of Records to the Secretary

Business Associate will make its internal practices, books, and records, including policies and procedures relating to the Use and Disclosure of PHI received from, or created or received by Business Associate on behalf of, Customer, available to the Secretary of the U.S. Department of Health and Human Services for purposes of the Secretary determining Customer's or Business Associate's compliance with the HIPAA Rules. Disclosure to the Secretary under this Section does not waive any applicable privilege or protection.

7. Safeguards for Electronic PHI

With respect to ePHI that it creates, receives, maintains, or transmits on behalf of Customer, Business Associate will comply with the applicable requirements of the Security Rule (45 CFR 164.308, 164.310, 164.312, and 164.316) and will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI. Without limiting the foregoing, Business Associate:

  • Encrypts ePHI in transit using TLS and encrypts call recordings and other ePHI at rest in access-controlled, private object storage;
  • Serves recordings and transcripts only through short-lived, signed URLs, scoped to the owning Customer, and logs access to that PHI in an audit trail;
  • Enforces role-based access controls, unique user authentication, session and refresh-token controls, and least-privilege access to Customer environments;
  • Maintains logging, monitoring, and error-tracking configured to exclude PHI from event payloads; and
  • Maintains policies and procedures, and workforce practices, reasonably designed to comply with the Security Rule and to detect, contain, and respond to Security Incidents.

Business Associate will retain the documentation required by 45 CFR 164.316 for six (6) years from the date of its creation or the date when it last was in effect, whichever is later.

8. Breach and Security Incident Notification

Business Associate will report to Customer any Use or Disclosure of PHI not permitted by this BAA, any Breach of Unsecured PHI, and any Security Incident (as defined at 45 CFR 164.304) of which it becomes aware, in accordance with this Section and 45 CFR 164.410.

For a Breach of Unsecured PHI, Business Associate will notify Customer without unreasonable delay and in no event later than [thirty (30)] calendar days after discovery of the Breach. The notification will include, to the extent known and available, the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, Used, or Disclosed; a description of what happened; the types of PHI involved; and the steps Business Associate has taken or will take to investigate, mitigate, and protect against further Breaches. Business Associate will supplement the notification as further information becomes available.

Unsuccessful Security Incidents that do not result in unauthorized access, Use, Disclosure, modification, or destruction of PHI — such as routine pings, port scans, denials of service, and unsuccessful log-in attempts — are reported by this paragraph as an ongoing basis and require no separate individual notice, provided that no such incident resulted in unauthorized access to PHI.

Business Associate will reasonably cooperate with Customer in Customer's investigation and, where a Breach requires notification under 45 CFR 164.404–164.408, in Customer's provision of notifications to Individuals, the Secretary, and, where applicable, the media. As between the parties, Customer is responsible for making the determinations and notifications required of a Covered Entity under the Breach Notification Rule, unless the parties otherwise agree in writing.

9. Permitted Management, Administration, and Data Aggregation

Except as otherwise limited by this BAA, Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, and may Disclose PHI for such purposes if the Disclosure is Required By Law, or if Business Associate obtains reasonable assurances from the person to whom the PHI is Disclosed that it will remain confidential and will be Used or further Disclosed only as Required By Law or for the purpose for which it was Disclosed, and that the person will notify Business Associate of any instance of which it is aware in which the confidentiality of the PHI has been breached.

Except as otherwise limited by this BAA, Business Associate may Use PHI to provide Data Aggregation services relating to the Health Care Operations of Customer as permitted by 45 CFR 164.504(e)(2)(i)(B). Business Associate may de-identify PHI in accordance with 45 CFR 164.514(a)–(c); de-identified information is not PHI and is not subject to this BAA.

10. Term and Termination

This BAA is effective as of the date the parties execute it (or, if earlier, the date Customer first submits PHI to the Services under an accepted Agreement) and remains in effect until all PHI provided by Customer to Business Associate, or created, received, or maintained by Business Associate on behalf of Customer, is destroyed or returned as set out in the Section titled "Return or Destruction of PHI," or, if return or destruction is infeasible, protections are extended to that PHI in accordance with that Section.

If either party knows of a material breach or violation by the other party of its obligations under this BAA, the non-breaching party will provide the breaching party with written notice and an opportunity to cure the breach within [thirty (30)] calendar days. If the breach is not cured within that period, the non-breaching party may terminate this BAA and the Agreement. If cure is not feasible, the non-breaching party may terminate this BAA and the Agreement immediately upon written notice. A party may also report the violation to the Secretary if termination is not feasible.

11. Return or Destruction of PHI

Upon termination of this BAA for any reason, Business Associate will, if feasible, return to Customer or destroy all PHI received from Customer, or created, maintained, or received by Business Associate on behalf of Customer, that Business Associate still maintains in any form, and will retain no copies of the PHI. This obligation extends to PHI held by Business Associate's Subcontractors.

If Business Associate determines that returning or destroying the PHI is infeasible, Business Associate will notify Customer of the conditions that make return or destruction infeasible and will extend the protections of this BAA to that PHI, and limit further Uses and Disclosures of it to those purposes that make return or destruction infeasible, for so long as Business Associate maintains the PHI.

Business Associate will complete return or destruction within [thirty (30)] calendar days of termination unless a longer period is agreed in writing or Required By Law, and, upon request, will certify in writing that it has done so.

12. Miscellaneous

Regulatory references. A reference in this BAA to a section of the HIPAA Rules means the section as in effect or as amended, and for which compliance is required.

Amendment. The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for the parties to comply with the requirements of the HIPAA Rules and other applicable law.

Interpretation. Any ambiguity in this BAA is to be resolved to permit the parties to comply with the HIPAA Rules. In the event of a conflict between this BAA and the Data Processing Addendum or the remainder of the Agreement with respect to the processing of PHI, this BAA controls to the extent of the conflict.

No third-party beneficiaries. Nothing in this BAA is intended to confer, nor will it confer, any rights on any person other than the parties and their respective successors and permitted assigns.

Survival. The obligations of Business Associate under the Sections titled "Return or Destruction of PHI" and "Availability of Records to the Secretary," and any other provisions that by their nature should survive, survive termination of this BAA.

Governing law. This BAA is governed by the laws of the State of Washington, without regard to its conflict-of-laws rules, except to the extent preempted by federal law, and is subject to the same venue provisions as the Agreement.

How to execute. To request or execute this BAA, contact legal@ansabell.com. PHI must not be submitted to the Services until this BAA has been executed by both parties.

Questions about this document? Email legal@ansabell.com.