AbaAiCheck

Business Associate Agreement

Effective and last updated: September 21, 2026 · Version 2026-09-21.3

The short version
  • If you are a HIPAA covered entity or a business associate of one, this agreement (“BAA”) applies when you use AbaAiCheck with protected health information (“PHI”).
  • We use PHI only to provide the Service, we do not store the text of the notes you submit (unless you choose to share your review history with a supervisor), and we share more than quality metrics with an agency only if you opt in, and we protect what we hold with safeguards required by the HIPAA Security Rule.
  • We report breaches and security incidents to you, and we return or destroy PHI when the agreement ends.

This Business Associate Agreement is part of, and incorporated into, the Terms of Service between you (“Covered Entity”, or a business associate acting for a covered entity) and AbaAiCheck (“Business Associate”). It takes effect when you accept it during sign-up and stays in effect while you use the Service. Capitalized terms not defined here have the meanings given in HIPAA (the Health Insurance Portability and Accountability Act of 1996, the HITECH Act and their regulations at 45 CFR Parts 160 and 164).

1. Permitted uses and disclosures

Business Associate may use and disclose PHI only (a) to perform the Service you request — reviewing session notes against documentation guidelines and returning the result to you; (b) as required by law; (c) at your direction, to keep and show a read-only history of your reviews to a supervisor you have accepted through the Service (peer supervision), for as long as you keep that supervisor; and (d) for Business Associate’s proper management and administration, or to carry out its legal responsibilities, provided that any disclosure is required by law or made with reasonable assurances that the recipient will keep the PHI confidential and notify us of any breach. Business Associate will not use or disclose PHI in a way that would violate the HIPAA Privacy Rule if done by Covered Entity, will not sell PHI, and will not use PHI for marketing.

2. Safeguards

Business Associate will use appropriate administrative, physical and technical safeguards, and comply with the HIPAA Security Rule (45 CFR Part 164, Subpart C) with respect to electronic PHI, to prevent use or disclosure of PHI other than as this BAA allows. Note text is processed to produce the analysis and is not stored by the Service, with one exception: if you accept a supervisor, the Service keeps a history of the notes you review from that moment (date, patient name, score and note text) that only that supervisor can read, and deletes it when you remove the supervisor. Records the Service does keep (such as patient plans you enter) are encrypted at rest and transmitted only over encrypted connections.

3. Reporting

Business Associate will report to Covered Entity, without unreasonable delay and in any event within five (5) business days of discovery, (a) any use or disclosure of PHI not permitted by this BAA, (b) any Security Incident involving PHI, and (c) any Breach of Unsecured PHI as required by 45 CFR 164.410, including, to the extent known, the identity of affected individuals and the information involved. Unsuccessful attempts such as pings and port scans are reported in aggregate on request.

4. Subcontractors

In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits PHI on its behalf, including providers of the artificial-intelligence analysis used by the Service, agrees in writing to the same restrictions and conditions that apply to Business Associate under this BAA.

5. Individual rights

Because the Service does not maintain a designated record set of note text, Business Associate will, to the extent it holds PHI in a designated record set, make it available to Covered Entity within thirty (30) days of a request so Covered Entity can meet its obligations for access (45 CFR 164.524), amendment (45 CFR 164.526) and an accounting of disclosures (45 CFR 164.528), and will forward to Covered Entity any request it receives directly from an individual.

6. Books and records

Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with HIPAA. To the extent Business Associate carries out an obligation of Covered Entity under the Privacy Rule, it will comply with the requirements that apply to Covered Entity in performing that obligation.

7. Covered Entity’s responsibilities

Covered Entity will (a) submit only the minimum PHI necessary for the review; (b) not ask Business Associate to use or disclose PHI in a way that would violate HIPAA; (c) keep its account credentials confidential and tell us promptly of any suspected unauthorized access; and (d) notify Business Associate of any restriction on use or disclosure of PHI that Covered Entity has agreed to and that may affect the Service.

8. Agencies and quality metrics

Where you use the Service under an agency’s EHR domain, quality metrics generated by the Service (date, CPT code, compliance score and counts of errors and warnings — never the note text) may be shared with that agency’s administrators for compliance purposes, as disclosed at sign-up and in the Privacy Policy. Beyond those metrics, Business Associate will disclose to an agency’s administrators the detailed results of an individual user’s audits (client name, AI analysis and supervisor review status, but not the full note text) only if that user has affirmatively opted in, for audits run under that agency’s EHR domain after the opt-in, until the user revokes the opt-in or leaves the agency, at which point access ends and the detailed records kept for the agency are deleted.

9. Term and termination

This BAA lasts as long as Business Associate holds PHI for Covered Entity. Either party may terminate the Service if the other materially breaches this BAA and does not cure the breach within thirty (30) days of written notice. On termination, Business Associate will return or destroy all PHI it still maintains, if feasible; if not feasible, it will extend the protections of this BAA to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible.

10. General

Any ambiguity is resolved in favor of a meaning that permits compliance with HIPAA. If HIPAA is amended in a way that requires changes to this BAA, the parties will make them. Nothing here creates rights in any third party. This BAA is governed by the same law as the Terms of Service, except where federal law applies.

11. Contact

Questions about this BAA or to report a suspected incident: abaaicheck@gmail.com