Legal - HIPAA agreement
Business Associate Agreement
Version 2026-06-v1
1. Parties & purpose
This Business Associate Agreement (“BAA”) is entered into between you or your organization (“Customer”, acting as a HIPAA Covered Entity or Business Associate) and PartnerMe AI (“PartnerMe AI”, acting as your Business Associate - or, where you are yourself a Business Associate, as your Subcontractor). It governs PartnerMe AI’s creation, receipt, maintenance, and transmission of PHI on your behalf. A separate BAA applies to each HIPAA-enabled workspace (a Team or a personal account); you may hold several independent BAAs.
2. Definitions
Capitalized terms (PHI, ePHI, Breach, Security Incident, Required by Law, Covered Entity, Business Associate, Subcontractor, Unsecured PHI, etc.) have the meanings given in HIPAA, the HITECH Act, and 45 CFR Parts 160 and 164.
3. Permitted & required uses of PHI
PartnerMe AI may use and disclose PHI only to provide the contracted services to you, as permitted by this BAA, or as Required by Law. PartnerMe AI will make disclosures only as you direct or as the services require, and will limit uses and disclosures to the minimum necessary.
4. Prohibited uses
PartnerMe AI will not, and its systems are designed not to:
- sell PHI, or use or disclose PHI for marketing;
- use PHI to train AI models, for analytics, or for product improvement;
- process PHI for a workspace without a signed, active BAA (see the scope appendix below).
5. Safeguards
PartnerMe AI maintains administrative, physical, and technical safeguards required by the HIPAA Security Rule, including:
- deny-by-default segmentation - the HIPAA safeguards (BAA-covered AI models, the PHI access log and the controls below) engage only inside an active, BAA-signed HIPAA workspace, and PHI is not permitted outside one;
- encryption of ePHI at rest (AES-256-GCM, with key management and rotation) and in transit (TLS); end-to-end encryption (MLS) for user-to-user messages;
- a tamper-evident, hash-chained PHI access audit log, retained for at least six years and never deleted on account erasure, with automated integrity verification;
- role-based least-privilege access and mandatory two-factor authentication for anyone accessing a HIPAA workspace;
- minimum-necessary controls that keep PHI out of analytics, application logs, and email notifications.
6. Security incidents & breach notification
PartnerMe AI will report to you any use or disclosure of PHI not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI, without unreasonable delay and within the timeframe stated in your agreement after discovery, with the information required by 45 CFR §164.410. Unsuccessful routine security events are reported in aggregate.
7. Subcontractors
PartnerMe AI will ensure any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those here. Current subprocessors are listed in our subprocessor register; only BAA-covered providers and models supplied through Azure may process PHI.
8. Individual rights
PartnerMe AI will make PHI available to enable you to meet your obligations regarding individuals’ rights of access (§164.524), amendment (§164.526), and an accounting of disclosures (§164.528), and will make its internal practices, books, and records available to HHS as required.
9. Your obligations
- determine whether you are a Covered Entity or Business Associate, and obtain any authorizations/notices the law requires;
- handle PHI only in a workspace with an active BAA - and for anything you send or publish through your own connected channels, hold the authorisations those disclosures require;
- enable two-factor authentication and manage your users’ access;
- configure the workspace appropriately: provision your users and roles, and manage your connected channels.
10. AI processing & support access
All AI features - inside and outside a HIPAA-enabled workspace - run on BAA-covered AI infrastructure. What a HIPAA-enabled workspace adds is the BAA between us plus the PHI safeguards in section 5. Outside a HIPAA-enabled workspace no BAA is in force between us, so PHI must not be submitted there: keeping PHI inside a HIPAA-enabled workspace is your responsibility, and our agents are instructed not to process PHI they encounter elsewhere and to point you to enabling HIPAA instead. PartnerMe AI support and workforce access PHI only through an approved, audited, minimum-necessary workflow; all such access is recorded in the access log.
11. Term, termination & return/destruction of PHI
This BAA is effective on signing and continues until terminated. On termination, PartnerMe AI will return or destroy all PHI it maintains for you where feasible; where infeasible, it will extend the protections of this BAA to that PHI and limit further use. The signed record is retained for the legal trail, and the access log is retained for at least six years (§164.316(b)(2)) and remains available to you and to regulators on request.
Appendix: HIPAA scope - our safeguards, your decisions
One rule opens everything: if you handle PHI on the platform or through your connected channels, sign the BAA first. PHI requires a HIPAA-enabled workspace with a signed, active BAA; with that in place, the whole platform is available to you - nothing is closed to a HIPAA customer. The split of responsibilities is:
| What PartnerMe AI controls (enforced for every HIPAA workspace) | How |
|---|---|
| AI models | AI text processing runs on BAA-covered AI infrastructure. Outside a HIPAA-enabled workspace no BAA is in force between us, so PHI must not be submitted there. AI image and video generation in a HIPAA-enabled workspace runs only on BAA-covered providers; if none is enabled for it, the request is refused rather than sent to a non-covered provider. |
| Encryption | TLS in transit; AES-256-GCM at rest with field-level encryption of PHI fields; end-to-end encryption (MLS) for user-to-user messages. |
| Audit | PHI access is recorded on a tamper-evident, hash-chained audit log retained for six years, with automated integrity verification. |
| Access | Multi-factor authentication is mandatory for HIPAA workspaces; PHI-capable processing is deny-by-default outside them. |
| Our own data handling | No PHI in our analytics, application logs, or notification emails and push (message previews are suppressed in HIPAA workspaces); support access to PHI is audited. |
| Never | PHI is never used for marketing, analytics, product improvement or model training. |
| What you decide (your HIPAA compliance) | Your responsibility |
|---|---|
| What PHI you handle, and in which features | Messages, agent chats, voice notes, media prompts, automations - all available under your active BAA, on a minimum-necessary basis. |
| What you send or publish through connected platforms | Platforms you connect (for example LinkedIn, Instagram, Threads, WordPress, Wix, Webflow, Circle) are your own channels: disclosures you make on them - including published or public content - are yours to authorise under HIPAA (45 C.F.R. 164.508 where required). |
| Who accesses your HIPAA workspace | You provision and remove your own users and roles on a least-privilege basis, and require MFA for them. |
| Your status and authorisations | You determine your own status as a Covered Entity or Business Associate and maintain the notices, consents and authorisations your disclosures require. |
That is the whole model: our safeguards are always on for a HIPAA workspace; your placement and disclosure decisions are always yours.
