# BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement ("BAA") supplements and is incorporated into the Master Services Agreement ("Agreement") between **Auroa** ("Business Associate") and **[CUSTOMER LEGAL NAME]** ("Covered Entity"), effective **[DATE]**.

This BAA is entered into to comply with the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, "HIPAA").

In case of conflict between this BAA and the Agreement, this BAA controls for matters involving Protected Health Information.

---

## 1. DEFINITIONS

Capitalized terms not defined here have the meanings given in HIPAA.

- **"Protected Health Information" or "PHI"** means individually identifiable health information transmitted or maintained in any form or medium by Business Associate on behalf of Covered Entity, limited to the information described in Section 3.
- **"Electronic PHI" or "ePHI"** means PHI transmitted by or maintained in electronic media.
- **"Breach"** has the meaning given at 45 C.F.R. § 164.402.
- **"Security Incident"** has the meaning given at 45 C.F.R. § 164.304.
- **"Subcontractor"** means a person or entity to whom Business Associate delegates a function involving PHI.

---

## 2. ROLES

2.1 Covered Entity is a HIPAA-regulated entity (or business associate of one). Business Associate provides the Auroa software-as-a-service platform for resident wellness logging, family notifications, and compliance reporting.

2.2 Business Associate will Use or Disclose PHI only as permitted by this BAA, the Agreement, or as Required By Law.

---

## 3. CATEGORIES OF PHI PROCESSED

The Service is designed to minimize PHI exposure. Business Associate Processes the following limited categories:

- Resident names (**encrypted client-side; Business Associate cannot decrypt**)
- Room numbers
- Wellness log notes — general status, mood, activities (**encrypted client-side; Business Associate cannot decrypt**)
- Family member contact details (name, email, phone)
- Staff member names and login credentials

Business Associate does **not** process diagnoses, treatment records, medications, lab results, or billing/insurance information.

---

## 4. PERMITTED USES AND DISCLOSURES

4.1 Business Associate may Use or Disclose PHI only:
- (a) To perform the Services described in the Agreement.
- (b) For the proper management and administration of Business Associate, or to carry out Business Associate's legal responsibilities.
- (c) As Required By Law.
- (d) For Data Aggregation services relating to the Health Care Operations of Covered Entity, if requested.

4.2 Business Associate will **not**:
- Use or Disclose PHI for marketing, advertising, or sale.
- Use or Disclose PHI in a manner that would violate HIPAA if done by Covered Entity.
- De-identify PHI except as permitted in writing by Covered Entity.

---

## 5. SAFEGUARDS

5.1 Business Associate will implement and maintain administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) to protect the confidentiality, integrity, and availability of ePHI. These include:

- **Client-side encryption.** Resident names and wellness notes are encrypted in the user's browser using AES-256-CBC with PBKDF2 key derivation (150,000 rounds). The passphrase is held solely by Covered Entity. **Business Associate has no technical ability to decrypt this PHI.**
- **Encryption in transit.** TLS 1.2 or higher for all communication.
- **Encryption at rest.** AES-256 encryption on all databases and backups.
- **Access controls.** Unique user IDs, role-based access, multi-factor authentication for administrators, and row-level security at the database layer.
- **Audit controls.** All access to PHI is logged with user ID, timestamp, and action; logs are retained for at least 6 years.
- **Integrity controls.** Cryptographic verification of stored encrypted PHI.
- **Workforce training.** All Business Associate personnel with potential PHI access receive HIPAA training annually.
- **Sanction policy.** Business Associate disciplines personnel who violate this BAA, up to and including termination.

---

## 6. SUBCONTRACTORS

6.1 Business Associate will not allow a Subcontractor to create, receive, maintain, or transmit PHI on its behalf unless that Subcontractor has signed a written agreement with terms substantially similar to this BAA.

6.2 Current Subcontractors:

| Subcontractor | Function | BAA Status |
|---|---|---|
| Supabase, Inc. | Encrypted database hosting | BAA in place |
| Twilio Inc. | SMS delivery (no PHI in SMS body) | BAA in place |
| Resend / Mailgun | Transactional email (no PHI in email body) | BAA in place |
| Stripe, Inc. | Payment processing (no PHI; payment data only) | Not applicable |

6.3 Business Associate will give Covered Entity **15 days' notice** before adding a Subcontractor that will handle PHI.

---

## 7. INDIVIDUAL RIGHTS

7.1 **Access (§ 164.524).** Within 15 business days of Covered Entity's request, Business Associate will provide PHI in a Designated Record Set to enable Covered Entity to respond to an individual's access request. Because resident names and notes are client-side encrypted, Covered Entity must decrypt the export using its passphrase before providing it to the individual.

7.2 **Amendment (§ 164.526).** Business Associate will incorporate amendments Covered Entity makes to PHI in the Designated Record Set within 15 business days.

7.3 **Accounting (§ 164.528).** Business Associate will document Disclosures of PHI sufficient to allow Covered Entity to respond to accounting requests and will provide that documentation within 30 days of request.

7.4 **Direct requests.** If an individual contacts Business Associate directly with a HIPAA rights request, Business Associate will forward the request to Covered Entity within 5 business days and not respond except to confirm receipt and direct the individual to Covered Entity.

---

## 8. BREACH AND SECURITY INCIDENT NOTIFICATION

8.1 **Breach.** Business Associate will notify Covered Entity of any Breach of Unsecured PHI **without unreasonable delay and no later than 30 calendar days** after Discovery. Notification will include, to the extent known:
- Identification of each individual whose Unsecured PHI was or is reasonably believed to have been accessed, acquired, Used, or Disclosed.
- A description of what happened, the date of the Breach, and the date of Discovery.
- The types of Unsecured PHI involved.
- Mitigation steps taken.
- Contact information for further inquiry.

8.2 **Security Incidents.** Business Associate will report Security Incidents of which it becomes aware. The Parties agree that unsuccessful Security Incidents (e.g., pings, port scans, failed login attempts) that do not result in actual Unauthorized Access need not be reported individually; Business Associate will report such activity in summary form upon request.

8.3 **Cooperation.** Business Associate will cooperate with Covered Entity's investigation, notification, and mitigation obligations under 45 C.F.R. §§ 164.404–164.410.

---

## 9. ACCESS BY HHS

Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.

---

## 10. MITIGATION

Business Associate will mitigate, to the extent practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI in violation of this BAA.

---

## 11. TERM AND TERMINATION

11.1 **Term.** This BAA takes effect on the Effective Date of the Agreement and continues until terminated as provided here or until the Agreement terminates and all PHI has been returned or destroyed.

11.2 **Termination for Cause.** Covered Entity may terminate the Agreement and this BAA immediately if it determines Business Associate has materially breached this BAA and Business Associate fails to cure within 30 days of written notice.

11.3 **Return or Destruction of PHI.** Upon termination, Business Associate will:
- (a) Make all PHI available for export by Covered Entity for **30 days**.
- (b) After the export window, **permanently delete** all PHI from production systems within 14 days and from backups within 90 days.
- (c) Provide written certification of destruction upon request.

11.4 **Infeasible return.** If return or destruction is infeasible, Business Associate will extend the protections of this BAA to the retained PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible.

---

## 12. MISCELLANEOUS

12.1 **Regulatory References.** A reference to a HIPAA section means the section as in effect or as amended.

12.2 **Amendment.** The Parties will negotiate in good faith to amend this BAA as needed to comply with changes to HIPAA.

12.3 **Survival.** Sections 8, 9, 10, and 11.3 survive termination.

12.4 **Interpretation.** Ambiguities will be resolved in favor of a meaning that permits compliance with HIPAA.

12.5 **No Third-Party Beneficiaries.** Nothing in this BAA creates rights in any third party.

---

**SIGNED**

**BUSINESS ASSOCIATE: AUROA**

Signature: ______________________________

Name: __________________________________

Title: ___________________________________

Date: ___________________________________

**COVERED ENTITY: [CUSTOMER LEGAL NAME]**

Signature: ______________________________

Name: __________________________________

Title: ___________________________________

Date: ___________________________________
