Skip to main content

Be among the first to experience Heidi’s next chapter. Join the waitlist.

Heidi AI
Log inGet Heidi free
alt
alt

Resources

  • Explainers

  • FAQs

  • Progress Notes

  • Podcast

  • AI Tools

Why Heidi

  • Impact

  • Awards and Recognition

  • Evaluating Heidi

  • Patient Experience

Compliance

  • Trust Center

  • GDPR

  • HIPAA

  • AU/NZ

  • UK

  • Canada

Support

  • Help Centre

  • Heidi Guides

  • System Status

  • System Requirements

  • Contact Us

Legal

  • Privacy Policy

  • Terms of Service

  • Usage Policy

  • UKGDPR Policy

  • Accessibility

imxYAA

© 2026 Heidi. All rights reserved.

Heidi Desktop goes where the browser can’t.

Dictate anywhere on your screen, capture telehealth audio straight from the call,
and skip the second login.

Download for macOSDownload for Windows
  1. Home
  2. legal

Business Associate Agreement

Heidi Team

September 29, 2026•

Table of Contents

  • 1. Definitions

  • 2. Permitted uses and disclosures

  • 3. Safeguards

  • 4. Reporting

  • 5. Subcontractors

  • 6. Individual rights

  • 7. Covered Entity responsibilities

  • 8. Data ownership

  • 9. Term, termination, and return or destruction of PHI

  • 10. Liability

  • 11. General

This Business Associate Agreement (“BAA”) is entered into between the Heidi contracting entity that is a party to the Agreement (as identified in the Agreement or the applicable Order Form; for United States customers, Heidi Health Corp.) (“Business Associate” or “Heidi”) and the customer entity that is a party to the Agreement, together with each of its Affiliates that is a covered entity or business associate and uses the Services under the Agreement (collectively, “Covered Entity” or “Customer”). Customer enters into this BAA on its own behalf and as agent for each such Affiliate, and will give and receive all notices and exercise all rights and remedies under this BAA on each Affiliate’s behalf. “Agreement” means the Heidi Master Services Agreement, Heidi’s Terms of Service, or any other agreement between the parties governing Customer’s use of the Services, together with the Heidi Global Data Processing Agreement (“DPA”).

Execution. Where Customer is a “covered entity” or a “business associate” (as defined in HIPAA) and Protected Health Information is included in Customer Data, execution of the Agreement incorporating this BAA includes execution of this BAA, and no separate signature is required. If this BAA is adopted after the Agreement takes effect, it takes effect when the parties agree, in accordance with the Agreement, to incorporate it into the Agreement. This BAA replaces an earlier business associate agreement between the parties in respect of the same Services only where the parties expressly agree to that replacement.

1. Definitions

Capitalised terms not defined in this BAA have the meanings given in the Agreement or, failing that, in HIPAA. “HIPAA” means the Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act, together with the regulations at 45 CFR Parts 160 and 164 (including the Privacy, Security and Breach Notification Rules), each as amended. In this BAA:

1.1. “Affiliate” means, in relation to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with that party, where “control” means the ownership of more than fifty percent (50%) of the voting securities of an entity or the power to direct or cause the direction of its management and policies.

1.2. “Breach” has the meaning given in 45 CFR § 164.402, and “Unsecured PHI” has the meaning given in 45 CFR § 164.402, in each case limited to PHI held by Business Associate.

1.3. “Data Aggregation” has the meaning given in 45 CFR § 164.501.

1.4. “De-Identify” means to alter PHI so that the resulting information satisfies 45 CFR § 164.514(a)–(b), whether under the safe harbor method or a documented expert determination.

1.5. “Designated Record Set”, “Individual”, “Required by Law”, “Secretary” and “Security Incident” have the meanings given in 45 CFR Parts 160 and 164.

1.6. “Electronic PHI” means electronic protected health information as defined in 45 CFR § 160.103, limited to electronic protected health information created, received, maintained or transmitted by Business Associate from or on behalf of Covered Entity under the Agreement.

1.7. “Protected Health Information” or “PHI” has the meaning given in 45 CFR § 160.103, limited to information created, received, maintained or transmitted by Business Associate from or on behalf of Covered Entity under the Agreement, and includes Electronic PHI.

2. Permitted uses and disclosures

2.1. Business Associate may use and disclose PHI: (a) to provide, operate, maintain, secure and support the Services under the Agreement; (b) as permitted by this BAA; and (c) as Required by Law.

2.2. Business Associate may use PHI for its proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes where the disclosure is Required by Law or where Business Associate obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any breach of its confidentiality.

2.3. Business Associate may use PHI to provide Data Aggregation services relating to Covered Entity’s health care operations, and may use PHI to report violations of law to appropriate authorities consistent with 45 CFR § 164.502(j)(1).

2.4. De-identification. Business Associate may De-Identify PHI only as permitted by the Agreement. Information that has been De-Identified in accordance with 45 CFR § 164.514(b) is no longer PHI and is no longer subject to this BAA; Business Associate’s use of such information is governed by the Agreement (including its restrictions on the use of De-Identified Data).

2.5. Business Associate will not attempt to re-identify De-Identified information and will contractually require the same of any recipient.Limits. Business Associate will not use or disclose PHI other than as permitted by this BAA, the Privacy Rule or Required by Law. Business Associate will limit its uses, disclosures and requests of PHI to a limited data set where practicable, or otherwise to the minimum necessary to accomplish the intended purpose.

2.6. Limits. Business Associate will not sell PHI, will not use or disclose PHI for marketing purposes, will not use PHI to select, target or measure advertising, and will not use PHI as an input to train, fine-tune or otherwise improve any artificial intelligence model (this restriction does not limit the use of PHI to provide, operate, secure, support, test and evaluate the Services for Covered Entity).

3. Safeguards

Business Associate will use appropriate safeguards to prevent the use or disclosure of PHI other than as provided by this BAA, will comply with the Security Rule with respect to Electronic PHI, and will implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of Electronic PHI it creates, receives, maintains or transmits on behalf of Covered Entity — including the measures described in Annex 2 of the DPA (encryption of Electronic PHI in transit and at rest consistent with the guidance specified by the Secretary under 42 USC § 17932(h), access controls, logging, training and testing). Current certifications and security documentation are available via Heidi’s Trust Centre at https://trust.heidihealth.com.

4. Reporting

4.1. Breaches and Security Incidents. Business Associate will notify Covered Entity in writing without unreasonable delay, and in any event within 72 hours, after discovery of (a) a Breach of Unsecured PHI, or (b) any successful Security Incident affecting Covered Entity’s Electronic PHI. Business Associate will report any other use or disclosure of PHI not permitted by this BAA within 10 business days of becoming aware of it. Notification will include, to the extent known, the information described in 45 CFR § 164.410(c), including the identification of affected Individuals, and Business Associate will supplement the notification as further information becomes available. Business Associate’s notification is not an acknowledgement of fault or liability.

4.2. Unsuccessful incidents. The parties acknowledge that this Section constitutes notice of unsuccessful Security Incidents that do not result in unauthorised access to or acquisition, use or disclosure of PHI — such as pings, port scans, denial-of-service attempts that do not compromise PHI, and blocked malware or log-in attempts — and no further reporting of such unsuccessful incidents is required.

4.3. Mitigation and cooperation. Business Associate will investigate, take reasonable steps to mitigate any harmful effect known to it of a Breach or impermissible use or disclosure, and reasonably cooperate with Covered Entity’s own investigation and notification obligations. Where a Breach results from Business Associate’s violation of this BAA, Business Associate will reimburse Covered Entity’s reasonable, documented costs of the notifications required by Subpart D of 45 CFR Part 164, subject to Section 10 (Liability).

5. Subcontractors

Business Associate will ensure that each subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing, in accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.504(e)(5), to restrictions and conditions no less protective than those that apply to Business Associate under this BAA, including implementation of reasonable and appropriate safeguards for Electronic PHI. The current list of Business Associate’s subcontractors that may receive PHI, including their roles and locations, is maintained at https://trust.heidihealth.com/subprocessors, which includes a mechanism to subscribe to notifications; Business Associate will update the list before a new subcontractor receives PHI, and the notice and objection mechanics of the DPA apply to changes.

6. Individual rights

6.1. Access. Business Associate will make PHI in a Designated Record Set available to Covered Entity within 10 business days of a request, to enable Covered Entity to meet its obligations under 45 CFR § 164.524. The Services also provide functionality through which Covered Entity can retrieve this information directly.

6.2. Amendment. Business Associate will make PHI in a Designated Record Set available for amendment, and will incorporate amendments Covered Entity directs, within 15 business days of the direction, per 45 CFR § 164.526.

6.3. Accounting. Business Associate will document disclosures of PHI as required by 45 CFR § 164.528 (date, recipient and address if known, description, and purpose) and will provide that information to Covered Entity within 10 business days of a written request.

6.4. Forwarding. If an Individual delivers a request for access, amendment or an accounting directly to Business Associate, Business Associate will forward it to Covered Entity within 10 business days. Responding to Individuals is Covered Entity’s responsibility.

6.5. Restrictions and HHS. Business Associate will comply with restrictions and limitations notified under Section 7, and will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA. To the extent Business Associate is to carry out a Covered Entity obligation under the Privacy Rule, it will comply with the requirements that apply to Covered Entity in the performance of that obligation.

7. Covered Entity responsibilities

Covered Entity will: (a) notify Business Associate of any limitation in its notice of privacy practices, any change in or revocation of an Individual’s permission, and any restriction agreed under 45 CFR § 164.522, in each case to the extent it may affect Business Associate’s use or disclosure of PHI; (b) not request Business Associate to use or disclose PHI in a manner not permissible under HIPAA if done by Covered Entity (except for Data Aggregation and Business Associate’s management and administration as permitted by this BAA); and (c) obtain any consents and authorisations required for the collection and use of PHI through the Services, as provided in the Agreement.

8. Data ownership

Business Associate acquires no ownership rights in PHI. As between the parties, Customer Data (including PHI) remains Covered Entity’s, as provided in the Agreement.

9. Term, termination, and return or destruction of PHI

9.1. Term. This BAA takes effect as described under Execution above (or, if later, when PHI is first included in Customer Data) and continues until all PHI is returned, destroyed, or protected under Section 9.4.

9.2. Termination for cause. Either party may terminate this BAA and the affected portions of the Agreement if the other party has materially breached this BAA and fails to cure within 30 days of written notice. If termination is not feasible, the non-breaching party may report the violation to the Secretary.

9.3. Return or destruction. On expiry or termination of the Agreement, Business Associate will, in accordance with the timelines and procedures of the DPA (Section 14): return PHI to Covered Entity (including through export functionality) and destroy PHI, including PHI held by subcontractors, retaining no copies — except that PHI in backup and archival systems will be destroyed within 90 days, and will remain isolated, protected and subject to this BAA in the interim. On written request, Business Associate will certify the destruction in writing. These obligations apply to all PHI processed under the Services, including PHI in task instructions, screen captures, recordings, outputs and task-related logs, and copies held by subcontractors.

9.4. Infeasibility. If return or destruction of particular PHI is infeasible (including where retention is Required by Law), Business Associate will notify Covered Entity of the conditions making it infeasible, will extend the protections of this BAA to that PHI for as long as it is retained, and will limit further uses and disclosures to the purposes that make return or destruction infeasible. This Section 9 survives termination.

10. Liability

Each party’s and its Affiliates’ total aggregate liability arising out of or relating to this BAA, whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement, including any enhanced cap that the Agreement applies to breaches of confidentiality, security or privacy obligations. Nothing in this Section limits liability that cannot lawfully be limited.

11. General

11.1. Effect and precedence. This BAA is part of and subject to the Agreement. Subject to the mandatory priority of applicable standard contractual clauses or other legally required data transfer terms, in the event of a conflict with respect to PHI, this BAA governs over the DPA and the Agreement. Nothing in those terms permits a use or disclosure of PHI prohibited by HIPAA. This BAA creates no rights in any third party.

11.2. Regulatory references; amendment for law. A reference to a provision of HIPAA means the provision as in effect or amended from time to time. The parties will amend this BAA as necessary to comply with changes to HIPAA; Heidi may make such an amendment on reasonable written notice, provided it does not materially reduce the protection of PHI, and if the parties cannot agree on an amendment required for compliance, either party may terminate this BAA on 30 days’ written notice.

11.3. Interpretation. Any ambiguity will be interpreted to permit compliance with HIPAA. No agency, partnership or joint venture is created by this BAA.

11.4. Notices. Notices under this BAA may be given by email: to Business Associate at compliance@heidihealth.com, and to Covered Entity at the email address on Customer’s account or, where one exists, the notice or billing email specified in the applicable Order Form.