Dr. Redact
HIPAA Compliance Document
Business Associate Agreement
⚕ HIPAA 45 C.F.R. Parts 160 & 164 · Health Insurance Portability and Accountability Act of 1996

HIPAA Business Associate Agreement

This Business Associate Agreement ("Agreement" or "BAA") is entered into between the Covered Entity or Business Associate identified below ("Customer") and Dr. Redact LLC ("Business Associate"), collectively referred to as the "Parties."

Business Associate: Dr. Redact LLC · drredact.com · 4539 N 22nd St, STE N, Phoenix, Arizona 85016
Privacy Officer: privacy@drredact.com
Customer (CE/BA): As identified in the Dr. Redact account profile at time of execution
Underlying Agreement: Dr. Redact Terms of Service (drredact.com/terms), incorporated herein by reference
Effective Date: Date of electronic execution or account activation, whichever is earlier

RECITALS. Customer uses the Dr. Redact document redaction platform to process documents that may contain Protected Health Information ("PHI") as defined under HIPAA. In the course of providing these services, Business Associate may create, receive, maintain, or transmit PHI on behalf of Customer. The Parties enter into this Agreement to satisfy the requirements of 45 C.F.R. §164.314(a) and to protect the privacy and security of PHI in accordance with HIPAA and HITECH.

1 Definitions

Capitalized terms have the meanings given in HIPAA unless otherwise defined here.

"HIPAA" means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and all implementing regulations at 45 C.F.R. Parts 160 and 164, as amended.
"PHI" means Protected Health Information as defined at 45 C.F.R. §160.103, limited to PHI that Business Associate creates, receives, maintains, or transmits on behalf of Customer in connection with the Services.
"Services" means the document redaction, storage, and processing services provided by Dr. Redact under the Terms of Service.
"Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under this Agreement that compromises the security or privacy of PHI, as defined at 45 C.F.R. §164.402.
"Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
"Subcontractor" means a person or entity that creates, receives, maintains, or transmits PHI on behalf of Business Associate in performing the Services. Dr. Redact's Subcontractors include Amazon Web Services, Inc. (encrypted storage infrastructure), with whom a Business Associate Agreement is in place, and Anthropic, PBC (AI-assisted detection of sensitive information within documents), with whom Dr. Redact is in the process of establishing a Business Associate Agreement.

2 Obligations of Business Associate

2.1 Permitted Uses and Disclosures

Business Associate may use and disclose PHI only as follows:

  • To perform the Services on behalf of Customer as described in the Terms of Service
  • As required by law
  • For the proper management and administration of Business Associate's business, provided that disclosures are required by law or Business Associate obtains reasonable assurances from the recipient
  • To report violations of law to appropriate federal and state authorities

Business Associate shall not use or disclose PHI in any manner that would violate HIPAA if done by Customer.

2.2 Safeguards

Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI, including:

  • AES-256 encryption for PHI stored at rest
  • TLS 1.3 or higher encryption for PHI in transit
  • Role-based access controls with minimum necessary access to PHI
  • Audit logging of all PHI access and modification events
  • Regular risk assessments as required by 45 C.F.R. §164.308(a)(1)
  • Employee training on HIPAA Privacy and Security Rules
  • Incident response procedures including Breach notification processes

2.3 Reporting

Business Associate shall report to Customer:

  • Breach of PHI: Without unreasonable delay and no later than 60 calendar days after discovery, in accordance with 45 C.F.R. §164.410. Reports will be sent to the email address on the Customer's Dr. Redact account.
  • Security Incidents: Unsuccessful Security Incidents will be reported in aggregate on a quarterly basis unless a successful Security Incident occurs, which shall be reported without unreasonable delay.
  • Unauthorized disclosures: Any use or disclosure of PHI not provided for by this Agreement promptly upon discovery.

2.4 Subcontractors

Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees to the same restrictions and conditions that apply to Business Associate under this Agreement. Business Associate has entered into a Business Associate Agreement with Amazon Web Services, Inc. (storage infrastructure) and is in the process of establishing a HIPAA Business Associate Agreement with its AI subprocessor, Anthropic, PBC (AI-assisted detection of sensitive information). Until that agreement is executed, Customer must not submit Protected Health Information to the Service on any plan.

2.5 Individual Rights

Business Associate shall:

  • Make PHI available to Customer for inspection and copying, and if directed by Customer, to the individual whose PHI is held, within 30 days of request
  • Make PHI available for amendment and incorporate any amendments directed by Customer
  • Make available to Customer information required to provide an accounting of disclosures, as required by 45 C.F.R. §164.528
  • Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for compliance review

2.6 Minimum Necessary

Business Associate shall use, disclose, and request PHI in accordance with the minimum necessary standard, using only the amount of PHI reasonably necessary to accomplish the permitted purpose.

3 Obligations of Customer

Customer agrees to:

  • Notify Business Associate of any limitation in Customer's Notice of Privacy Practices that may affect Business Associate's use or disclosure of PHI
  • Notify Business Associate of any changes in or revocation of permission by an individual to use or disclose PHI
  • Not request Business Associate to use or disclose PHI in any manner that would violate HIPAA if done by Customer
  • Ensure that only authorized users access the Dr. Redact account and that account credentials are kept secure
  • Maintain a current and accurate account profile, including a valid email address for Breach notifications
  • Not upload PHI using the free trial (3-page) account, for which no BAA is in effect

4 Term and Termination

4.1 Term

This Agreement is effective on the date of execution and shall remain in effect for the duration of the Services relationship between the Parties, unless earlier terminated as provided herein.

4.2 Termination for Cause

Either Party may terminate this Agreement if the other Party materially breaches a provision of this Agreement and fails to cure the breach within 30 days of receiving written notice. If cure is not possible, the non-breaching party may immediately terminate the Agreement and the underlying Services.

4.3 Effect of Termination

Upon termination of this Agreement for any reason, Business Associate shall:

  • Return or destroy all PHI received from Customer or created on behalf of Customer, if feasible. Business Associate shall retain no copies of PHI following the agreed-upon retention period.
  • If return or destruction is not feasible, notify Customer and continue to apply the protections of this Agreement for as long as Business Associate retains PHI
  • Provide Customer with 30 days to download all documents from the platform before deletion upon account termination

5 General Provisions

5.1 Amendment

The Parties agree to amend this Agreement as necessary to comply with changes in applicable law, including amendments to HIPAA and HITECH. Business Associate will provide 30 days' notice of material changes to this Agreement.

5.2 Interpretation

This Agreement shall be interpreted in light of the requirements of HIPAA. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Customer to comply with HIPAA. This Agreement is intended to supplement, not replace, the restrictions and conditions imposed by HIPAA on the use and disclosure of PHI.

5.3 No Third-Party Beneficiaries

Nothing in this Agreement shall confer any rights or remedies upon any person other than the Parties and their respective successors and assigns.

5.4 Survival

The obligations of Business Associate under Section 4.3 (Effect of Termination) and all obligations relating to PHI that Business Associate retains after termination shall survive the termination of this Agreement.

5.5 Governing Law

This Agreement shall be governed by HIPAA and applicable federal law, and where not preempted, the laws of the State of Arizona.

5.6 Entire Agreement

This Agreement, together with the Dr. Redact Terms of Service and Privacy Policy, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements relating to the protection of PHI.

Execution

By signing below (or by clicking "I Agree" on the Dr. Redact platform for click-wrap execution), the Parties acknowledge that they have read and understand this Agreement and agree to be bound by its terms.

Click-Wrap Execution (PAYG and Standard Subscription Plans)
For PAYG Starter Pack, PAYG Standard Pack, Professional, Business, Business Plus, and Business Pro plans, this BAA may be executed electronically by checking the acknowledgment box in Account Settings and clicking "Execute Business Associate Agreement." The electronic record of acceptance, including the date, time, IP address, and account identifier, constitutes a valid and binding execution of this Agreement under the Electronic Signatures in Global and National Commerce Act (E-Sign Act), 15 U.S.C. §7001 et seq. Notice: Dr. Redact is in the process of establishing a Business Associate Agreement with its AI subprocessor (Anthropic, PBC). Until that agreement is executed, executing this BAA does not authorize the submission of Protected Health Information, and Customer must not submit PHI to the Service on any plan.
Enterprise Plans — Wet or DocuSign Execution
Enterprise Starter, Enterprise Pro, and Enterprise Custom plans require a fully executed BAA with authorized signatures from both Parties. Dr. Redact will deliver the BAA via DocuSign within 5 business days of plan activation. PHI must not be uploaded until the executed BAA is returned and confirmed by Dr. Redact.