Business Associate Agreement
This Business Associate Agreement (“BAA”) is between Attunement, Inc. (“Attunement”) and the organization identified by the individual accepting this BAA (“Customer”).
This BAA applies solely to Customer’s use of the Attunement Redaction Assistant (the “Service”) and supplements the Attunement Redaction Assistant Terms of Service (“Terms”).
By accepting this BAA on behalf of Customer, the individual accepting represents that they have authority to bind Customer.
1. Applicability and Definitions
Capitalized terms not defined in this BAA have the meanings given to them under the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations at 45 C.F.R. Parts 160 and 164 (“HIPAA”).
This BAA applies only where Customer is a Covered Entity or Business Associate and Attunement creates, receives, maintains, or transmits Protected Health Information (“PHI”) on Customer’s behalf through the Service.
Where Customer is a Covered Entity, Attunement acts as Customer’s Business Associate. Where Customer is itself a Business Associate, Attunement acts as Customer’s Subcontractor Business Associate.
Customer represents that it is authorized to disclose PHI to Attunement for processing through the Service.
If HIPAA does not require a Business Associate relationship between Customer and Attunement, Customer’s use of the Service remains governed by the Terms and Privacy Policy.
2. Permitted Uses and Disclosures
Attunement may use or disclose PHI only:
- as reasonably necessary to provide, operate, secure, maintain, and troubleshoot the Service;
- for Attunement’s proper management and administration or to carry out its legal responsibilities, to the extent permitted by HIPAA; or
- as Required by Law.
Attunement will not use or disclose PHI in a manner not permitted by this BAA or applicable HIPAA requirements.
Attunement will not:
- sell PHI;
- use PHI for advertising or marketing; or
- use PHI or Customer Content to train or fine-tune generalized machine-learning or artificial-intelligence models.
To the extent applicable, Attunement will make reasonable efforts to limit uses, disclosures, and requests for PHI to the minimum necessary for the intended purpose.
3. Safeguards
Attunement will implement appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI and will comply with the applicable requirements of the HIPAA Security Rule with respect to electronic PHI.
Attunement will take reasonable measures to prevent uses or disclosures of PHI other than those permitted by this BAA.
Attunement will mitigate, to the extent practicable and required by HIPAA, harmful effects known to Attunement resulting from a use or disclosure of PHI by Attunement in violation of this BAA.
4. Subcontractors
Attunement will require any Subcontractor that creates, receives, maintains, or transmits PHI on Attunement’s behalf in connection with the Service to agree to restrictions, conditions, and safeguards applicable to such PHI as required by HIPAA.
5. Breaches and Security Incidents
Attunement will report to Customer any use or disclosure of PHI not permitted by this BAA of which Attunement becomes aware, as required by HIPAA.
Attunement will notify Customer following Discovery of a Breach of Unsecured PHI without unreasonable delay and in no event later than thirty (30) calendar days after Discovery. Attunement will provide the information required by 45 C.F.R. § 164.410 to the extent known and applicable.
Attunement will report Security Incidents as required by HIPAA.
The parties acknowledge that unsuccessful attempts to gain unauthorized access to systems occur routinely. This BAA constitutes ongoing notice of routine unsuccessful attempts that do not result in unauthorized access, use, disclosure, modification, or destruction of PHI, and separate notice of each such attempt is not required.
6. Individual Rights and Regulatory Access
To the extent Attunement maintains PHI in a Designated Record Set on Customer’s behalf, Attunement will provide reasonable assistance necessary for Customer to satisfy applicable obligations concerning access and amendment under 45 C.F.R. §§ 164.524 and 164.526.
Attunement will document and make available information regarding disclosures of PHI to the extent required for Customer to satisfy applicable accounting obligations under 45 C.F.R. § 164.528.
Attunement will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services to the extent required by HIPAA.
7. Retention and Deletion
Unless otherwise Required by Law or reasonably necessary in connection with a security incident or legal obligation, Customer Content submitted to the Service is deleted from active processing systems no later than seven (7) days after upload.
Encrypted backup copies may persist for up to fourteen (14) additional days through Attunement’s ordinary backup lifecycle and will remain subject to applicable safeguards until deletion.
Attunement does not retain Customer Content beyond these periods for generalized model training, advertising, or marketing.
8. Customer Responsibilities and Service Limitations
Customer represents that it has the rights, permissions, authorizations, and legal authority necessary to submit Customer Content to the Service.
The Service uses automated techniques to assist in identifying and masking potential identifiers. Automated detection may produce false positives, false negatives, incomplete redactions, or other errors.
Attunement does not represent, warrant, certify, or determine that output from the Service satisfies the HIPAA de-identification requirements, including the Safe Harbor or Expert Determination methods.
Customer must review processed documents before relying upon, sharing, publishing, transmitting, or otherwise disclosing them.
Customer remains responsible for determining whether Customer Content may be submitted to the Service and whether resulting output may lawfully be used or disclosed.
9. Term and Termination
This BAA becomes effective when accepted by an authorized representative of Customer and remains effective while Attunement acts as Customer’s Business Associate or Subcontractor Business Associate in connection with the Service.
Either party may terminate the relationship in accordance with the Terms.
If either party materially breaches this BAA, the other party may provide a reasonable opportunity to cure the breach and, if the breach is not cured, terminate the relationship to the extent required by HIPAA.
Upon termination, Attunement will return or destroy PHI when feasible and as required by HIPAA. Attunement may satisfy this obligation through destruction in accordance with Section 7.
If return or destruction is infeasible, Attunement will continue to protect retained PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible.
10. Relationship to Terms
This BAA governs Attunement’s handling of PHI through the Service.
If this BAA conflicts with the Terms regarding a use or disclosure of PHI or an obligation expressly required by HIPAA, this BAA controls solely to the extent of that conflict.
Except to the extent prohibited by applicable law, the Terms otherwise remain in effect, including their provisions concerning warranties, acceptable use, limitations of liability, indemnification, and dispute resolution.
Nothing in this BAA is intended to create contractual rights in any patient or other third party.
11. General
This BAA will be interpreted to permit compliance with HIPAA.
Nothing in this BAA is intended to expand either party’s obligations beyond applicable HIPAA requirements and the express contractual commitments stated here.
Attunement may update this BAA as reasonably necessary to reflect changes in applicable law or the Service. Material changes will be communicated to Customer, and additional acceptance will be obtained where required by applicable law.
This BAA may be accepted electronically. Attunement may maintain records establishing the identity of the accepting user, the Customer organization, date and time of acceptance, and version accepted.
This BAA is governed by the laws of the State of California, except to the extent federal law controls.
If any provision is unenforceable, the remaining provisions remain effective.
Attunement, Inc.
legal@attunement.ai