If Customer of FortaTech Security, LLC d/b/a Bastion Intelligence ("FortaTech Security") is a Covered Entity or a Business Associate and includes Protected Health Information in Customer Data, this HIPAA Business Associate Agreement ("BAA") is incorporated into the Terms of Use agreement ("Agreement") by reference and becomes effective when Customer accepts the Agreement and first submits, uploads, transmits, or otherwise makes Protected Health Information available to the Services. No separate signature, attestation, or in-product designation is required for this BAA to take effect. If there is any conflict between a provision in this BAA and a provision in the Agreement, this BAA will control. With respect to Part 2 Records, the 42 CFR Part 2 and Qualified Service Organization Addendum controls over any conflicting provision of this BAA, as provided in Section 8(a) of that Addendum.
SECTION 01Definitions
Except as otherwise defined in this BAA, capitalized terms shall have the definitions set forth in HIPAA, and if not defined by HIPAA, such terms shall have the definitions set forth in the Agreement.
- Breach Notification RuleThe Breach Notification for Unsecured Protected Health Information Final Rule.
- Business AssociateShall have the same meaning as the term "business associate" in 45 CFR § 160.103 of HIPAA.
- Covered EntityShall have the same meaning as the term "covered entity" in 45 CFR § 160.103 of HIPAA.
- CustomerThe User (as defined in the Terms of Use) that has entered into the Agreement with FortaTech Security. For purposes of this BAA only, "Customer" also includes Customer's Affiliates that receive Services under the Agreement, to the extent such Affiliates transmit, make available, or otherwise provide Protected Health Information to FortaTech Security through the Services.
- HIPAACollectively means the administrative simplification provision of the Health Insurance Portability and Accountability Act enacted by the United States Congress, and its implementing regulations, including the Privacy Rule, the Breach Notification Rule, and the Security Rule, as amended from time to time, including by the Health Information Technology for Economic and Clinical Health ("HITECH") Act and by the Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules; Final Rule.
- Privacy RuleThe Standards for Privacy of Individually Identifiable Health Information.
- Protected Health InformationShall have the same meaning as the term "protected health information" in 45 CFR § 160.103 of HIPAA, provided that it is limited to such protected health information that is received by FortaTech Security from, or created, received, maintained, or transmitted by FortaTech Security on behalf of, Customer through the use of its services.
- Security RuleThe Security Standards for the Protection of Electronic Protected Health Information.
- SubcontractorShall have the same meaning as the term "subcontractor" in 45 CFR § 160.103 of HIPAA, and includes any person or entity to whom FortaTech Security delegates a function, activity, or service involving the creation, receipt, maintenance, or transmission of Protected Health Information on behalf of FortaTech Security, other than in the capacity of a member of the workforce of FortaTech Security.
SECTION 02Permitted Uses and Disclosures of Protected Health Information
a. Performance of the Agreement
Except as otherwise limited in this BAA, FortaTech Security may Use and Disclose Protected Health Information for, or on behalf of, Customer as specified in the Agreement; provided that any such Use or Disclosure would not violate HIPAA if done by Customer, unless expressly permitted under paragraph b of this Section.
b. Management, Administration, and Legal Responsibilities
Except as otherwise limited in this BAA, FortaTech Security may Use and Disclose Protected Health Information for the proper management and administration of FortaTech Security and/or to carry out the legal responsibilities of FortaTech Security, provided that any Disclosure may occur only if:
- Required by Law; or
- FortaTech Security obtains written reasonable assurances from the person to whom the Protected Health Information is Disclosed that it will be held confidentially and Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed to the person, and the person notifies FortaTech Security of any instances of which it becomes aware in which the confidentiality of the Protected Health Information has been breached.
SECTION 03Responsibilities of the Parties with Respect to Protected Health Information
a. FortaTech Security's Responsibilities
To the extent FortaTech Security is acting as a Business Associate, FortaTech Security agrees to the following:
(i) Limitations on Use and Disclosure
FortaTech Security shall not Use and/or Disclose the Protected Health Information other than as permitted or required by the Agreement and/or this BAA or as otherwise Required by Law. FortaTech Security shall not disclose, capture, maintain, scan, index, transmit, share or Use Protected Health Information for any activity not authorized under the Agreement and/or this BAA. The Services shall not use Protected Health Information for any advertising, Marketing or similar commercial purpose of FortaTech Security or any third party. FortaTech Security shall not violate the HIPAA prohibition on the sale of Protected Health Information. FortaTech Security shall make reasonable efforts to Use, Disclose, and/or request the minimum necessary Protected Health Information to accomplish the intended purpose of such Use, Disclosure, or request.
(ii) Safeguards
FortaTech Security shall: (1) use reasonable and appropriate safeguards to prevent Use and Disclosure of Protected Health Information other than as permitted in Section 2 herein; and (2) comply with the applicable requirements of 45 CFR Part 164 Subpart C of the Security Rule.
(iii) Reporting
FortaTech Security shall report to Customer:
- Any Use and/or Disclosure of Protected Health Information that is not permitted or required by this BAA of which FortaTech Security becomes aware;
- Any Security Incident of which it becomes aware, provided that notice is hereby deemed given for Unsuccessful Security Incidents and no further notice of such Unsuccessful Security Incidents shall be given; and/or
- Any Breach of Customer's Unsecured Protected Health Information that FortaTech Security may discover (in accordance with 45 CFR § 164.410 of the Breach Notification Rule).
Notification of a Breach will be made without unreasonable delay, but in no event more than seventy-two (72) hours after FortaTech Security's discovery of a Breach. Taking into account the level of risk reasonably likely to be presented by the Use, Disclosure, Security Incident, or Breach, the timing of other reporting will be made consistent with FortaTech Security's and Customer's legal obligations.
For purposes of this Section, "Unsuccessful Security Incidents" mean, without limitation, pings and other broadcast attacks on FortaTech Security's firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and any combination of the above, as long as no such incident results in unauthorized access, acquisition, Use, or Disclosure of Protected Health Information.
Notification(s) under this Section, if any, will be delivered to contacts identified by Customer pursuant to Section 3b(ii) (Contact Information for Notices) of this BAA by any means FortaTech Security selects, including through e-mail. FortaTech Security's obligation to report under this Section is not and will not be construed as an acknowledgement by FortaTech Security of any fault or liability with respect to any Use, Disclosure, Security Incident, or Breach.
(iv) Subcontractors
In accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2) of HIPAA, FortaTech Security shall require its Subcontractors who create, receive, maintain, or transmit Protected Health Information on behalf of FortaTech Security to agree in writing to: (1) the same or more stringent restrictions and conditions that apply to FortaTech Security with respect to such Protected Health Information; (2) appropriately safeguard the Protected Health Information; and (3) comply with the applicable requirements of 45 CFR Part 164 Subpart C of the Security Rule. FortaTech Security remains responsible for its Subcontractors' compliance with obligations in this BAA.
(v) Disclosure to the Secretary
FortaTech Security shall make available its internal practices, records, and books relating to the Use and/or Disclosure of Protected Health Information received from Customer to the Secretary of the Department of Health and Human Services for purposes of determining Customer's compliance with HIPAA, subject to attorney-client and other applicable legal privileges. If FortaTech Security receives a subpoena, civil investigative demand, court order, warrant, or other legally binding request from a governmental authority or third party for Protected Health Information, FortaTech Security shall, to the extent permitted by applicable law: (1) promptly notify Customer of the request before disclosing any Protected Health Information, so that Customer may seek a protective order or other appropriate remedy; (2) reasonably cooperate, at Customer's expense, with Customer's efforts to limit, quash, or challenge the request; and (3) Disclose only the minimum Protected Health Information legally required to comply with the request.
(vi) Access and Amendment
The Services are not intended to serve as Customer's medical record or system of record. Customer is responsible for maintaining its Designated Record Sets in its own systems, and FortaTech Security does not undertake that function.
To the extent FortaTech Security is deemed to maintain Protected Health Information in a Designated Record Set for Customer, it shall (1) make such Protected Health Information available to Customer within fifteen (15) days of a written request, so that Customer may meet its obligations under 45 CFR § 164.524, and (2) make such Protected Health Information available for amendment and incorporate any amendment directed by Customer within fifteen (15) days of a written request, so that Customer may meet its obligations under 45 CFR § 164.526. The Parties agree that either obligation may be satisfied through the access and export capabilities available to Customer within the Services.
(vii) Accounting of Disclosure
FortaTech Security, at the request of Customer, shall within thirty (30) days make available to Customer such information relating to Disclosures made by FortaTech Security as required for Customer to make any requested accounting of Disclosures in accordance with 45 CFR § 164.528 of the Privacy Rule.
(viii) Performance of a Covered Entity's Obligations
To the extent FortaTech Security is to carry out a Covered Entity obligation under the Privacy Rule, FortaTech Security shall comply with the requirements of the Privacy Rule that apply to Customer in the performance of such obligation.
(ix) Mitigation
FortaTech Security shall mitigate, to the extent practicable, harmful effects known to it of a Use or Disclosure of Protected Health Information in violation of this BAA, and shall reasonably cooperate with Customer's mitigation efforts.
(x) No Use for Model Training or De-Identification
FortaTech Security shall not Use Protected Health Information, or any data derived from Protected Health Information, to train, fine-tune, evaluate, test, or develop any artificial intelligence or machine learning model maintained by FortaTech Security or any third party, including any third-party model provider. This prohibition applies to every channel identified as covered in Schedule A.
FortaTech Security shall not de-identify, anonymize, or aggregate Protected Health Information, whether or not the result would satisfy 45 CFR § 164.514, and shall not Use or Disclose any de-identified, anonymized, or aggregated data derived from Protected Health Information for any purpose. Customer does not authorize the creation of de-identified information from Protected Health Information under 45 CFR § 164.502(d)(1), and no such authorization arises from any other provision of the Agreement, including any definition of Customer Data that excludes aggregate or de-identified data.
FortaTech Security shall not Use Protected Health Information to provide data aggregation services as described in 45 CFR § 164.504(e)(2)(i)(B).
This Section controls over any inconsistent provision of the Agreement.
b. Customer Responsibilities
(i) No Impermissible Requests
Customer shall not request FortaTech Security to Use or Disclose Protected Health Information in any manner that would not be permissible under HIPAA if done by a Covered Entity (unless permitted by HIPAA for a Business Associate).
(ii) Contact Information for Notices
Customer hereby agrees that any reports, notification, or other notice by FortaTech Security pursuant to this BAA will be provided as set forth in the Agreement.
(iii) Safeguards and Appropriate Use of Protected Health Information
Customer is responsible for implementing appropriate privacy and security safeguards to protect its Protected Health Information in compliance with HIPAA. The Services are designed to receive Protected Health Information only through the BastionGPT application itself, meaning chat prompts, file and document uploads, audio submitted for transcription, and the outputs generated from them, in each case within Customer's authenticated Account. This BAA is in effect for those channels.
Without limitation, it is Customer's obligation to not include Protected Health Information in any of the following channels:
- support communications of any kind, including support tickets, support chat, and support email, together with any attachment, screenshot, or log excerpt sent with them;
- community forums, discussion boards, product feedback, feature requests, surveys, reviews, or testimonials;
- public website forms, demonstration or scheduling requests, sales inquiries, and billing or account administration communications;
- account, profile, organization, or configuration fields not designated for clinical content; and
- any other feature, integration, or channel identified as not supported for Protected Health Information in Schedule A to this BAA, as updated from time to time in accordance with Section 6(b).
Paragraphs (1) through (5) do not apply where FortaTech Security has directed Customer in writing to provide Protected Health Information through a specified channel, such as a secure file transfer link supplied for a support investigation. This BAA applies to Protected Health Information submitted through any channel so directed.
Customer shall instruct its workforce members and other authorized users of the Services accordingly.
In addition, FortaTech Security does not act as, or have the obligations of, a Business Associate under HIPAA with respect to Customer Data that Customer transmits to, or receives from, third parties outside the FortaTech Security Services, or with respect to Protected Health Information that Customer submits through a channel listed above, except where submitted as directed under this Section. FortaTech Security will nonetheless protect any Protected Health Information it actually receives through such a channel in accordance with its generally applicable security safeguards and, upon becoming aware of it, will work with Customer in good faith to delete it. For the avoidance of doubt, this limitation does not apply to Customer Data in transit to or from the FortaTech Security Services over the public Internet in the ordinary course of Customer's authorized use of the Services.
SECTION 04Applicability of BAA
This BAA applies to all Services through which Customer transmits, makes available, or otherwise provides Protected Health Information to FortaTech Security, or through which FortaTech Security creates, receives, maintains, or transmits Protected Health Information on behalf of Customer. It is Customer's obligation not to store, process, or transmit Protected Health Information (as that term is defined in 45 CFR § 160.103 of HIPAA) through any Service, feature, or channel for which this BAA is not in effect, as described in Section 3(b)(iii).
SECTION 05Term and Termination
a. Term
This BAA shall continue in effect until the earlier of (1) termination by a Party for breach as set forth in Section 5.b., below, or (2) expiration of Customer's Agreement.
b. Termination for Breach
Upon written notice, either Party immediately may terminate the Agreement and this BAA if the other Party is in material breach or default of any obligation in this BAA. Either party may provide the other a thirty (30) calendar day period to cure a material breach or default within such written notice.
c. Return, Destruction, or Retention of Protected Health Information Upon Termination
Upon expiration or termination of this BAA, FortaTech Security shall return or destroy all Protected Health Information in its possession, and shall retain no copies of such Protected Health Information, in accordance with this Section 5(c).
For thirty (30) days following expiration or termination (the "Retrieval Period"), FortaTech Security will retain Customer's Protected Health Information and will make it available for export, whether through Customer's continued access to export functionality within the Services or by producing an export for Customer, and will do so notwithstanding any suspension or termination of Customer's access to the Services. On Customer's written request made within the Retrieval Period, FortaTech Security will deliver an export within fifteen (15) days of the request.
FortaTech Security will return or destroy Protected Health Information within thirty (30) days after the later of the close of the Retrieval Period and the fulfilment of any request properly made within it, or sooner upon Customer's written request, and will purge it from backup media within its ordinary backup cycle and in any event within thirty (30) days.
If FortaTech Security determines that returning or destroying any portion of the Protected Health Information is infeasible, FortaTech Security shall: (1) provide Customer with written notification of the conditions that make return or destruction infeasible, including a description of the categories of Protected Health Information at issue and the basis for the determination of infeasibility; (2) extend the protections of this BAA, without limitation, to such Protected Health Information and limit any further Use or Disclosure of the Protected Health Information to those purposes that make the return or destruction infeasible, for so long as FortaTech Security retains the Protected Health Information; and (3) return or destroy the Protected Health Information promptly upon, and to the extent that, return or destruction becomes feasible. The obligations in this Section 5(c) shall survive termination of this BAA.
SECTION 06Miscellaneous
a. Interpretation
The Parties intend that this BAA be interpreted consistently with their intent to comply with HIPAA and other applicable federal and state law. Except where this BAA conflicts with the Agreement, all other terms and conditions of the Agreement remain unchanged. With respect to Part 2 Records, the Part 2 Addendum controls over both this BAA and the Agreement in any conflict, as provided in Section 8(a) of the Part 2 Addendum. Any captions or headings in this BAA are for the convenience of the Parties and shall not affect the interpretation of this BAA.
b. Amendments; Waiver
FortaTech Security may amend this BAA, including Schedule A, in accordance with the amendment and notice provisions of the Agreement, provided that (1) no such amendment will reduce the protections afforded to Protected Health Information below those required by HIPAA, and (2) Customer may terminate the Agreement without penalty if Customer objects to a material amendment. This BAA may also be amended in a writing duly signed by authorized representatives of the Parties. A waiver with respect to one event shall not be construed as continuing, as a bar to, or as a waiver of any right or remedy as to subsequent events.
c. No Third-Party Beneficiaries
Nothing express or implied in this BAA is intended to confer, nor shall anything in this BAA confer, upon any person other than the Parties, and the respective successors or assigns of the Parties, any rights, remedies, obligations, or liabilities whatsoever.
d. Severability
In the event that any provision of this BAA is found to be invalid or unenforceable, the remainder of this BAA shall not be affected thereby, but rather the remainder of this BAA shall be enforced to the greatest extent permitted by law.
e. No Agency Relationship
It is not intended that an agency relationship (as defined under the Federal common law of agency) be established hereby expressly or by implication between Customer and FortaTech Security under HIPAA or the Privacy Rule, Security Rule, or Breach Notification Rule. No terms or conditions contained in this BAA shall be construed to make or render FortaTech Security an agent of Customer.
SCHEDULE AProtected Health Information Channel Matrix
This Schedule A is incorporated into this BAA at Section 3(b)(iii)(5) and into the 42 CFR Part 2 and Qualified Service Organization Addendum at Section 5(c). It sets out which channels are covered for the submission of Protected Health Information and Part 2 Records, and which are not. FortaTech Security may update this Schedule in accordance with Section 6(b), and will publish the current version here.
| Channel | What it includes | PHI permitted? |
|---|---|---|
| BastionGPT application, inside your signed-in account | Chat prompts, file and document uploads, audio submitted for transcription, saved instructions, note templates, and the outputs generated from them | YesCovered by the BAA |
| API | Programmatic access to the Services | YesCovered by the BAA |
| Beta and early-access features | Pre-release features inside the application | YesCovered by the BAA |
| Channels we direct you to | A secure file transfer link, or another channel we ask you in writing to use, usually for a support investigation | YesCovered by the BAA |
| Support channels | Support chat, support tickets, and support email, including any attachment, screenshot, or log excerpt sent with them | NoUnless we direct otherwise |
| Other business email | Sales, legal, billing, and general enquiry addresses | No |
| Public websites | Forms on bastiongpt.com and bastionintelligence.com, demonstration and scheduling requests | No |
| Billing and payment | The billing portal, invoices, payment queries, and account administration | No |
| Product feedback | Feature requests, surveys, reviews, and testimonials | No |
| Community channels | Forums, discussion boards, and similar shared channels | No |
| Account and profile fields | Account names, user names, team and workspace names, billing contacts, and other configuration fields | No |
If Protected Health Information reaches a channel marked "No", tell us at legal@bastionintelligence.com. We will remove it from the systems we control and confirm in writing what was removed.