Vestibo
All legal documents

Legal

Business associate agreement

Business Associate Agreement (BAA) — template

Version: v1.0 — 2026-07-23 Effective date: the date both parties counter-sign this BAA.

This is the template BAA. It applies only to customers on the HIPAA-eligible tier and takes effect only once both parties counter-sign it.

This Business Associate Agreement ("BAA") is entered into between Vestibo ("Business Associate") and the customer entity identified on the signature page ("Covered Entity", "Customer"). It supplements the parties' Terms of Service and Data Processing Addendum (together, the "Principal Agreement"), and is required where the Customer is a HIPAA Covered Entity or upstream Business Associate that intends to disclose Protected Health Information ("PHI") to Vestibo through the Service. This BAA is required for any Customer enabling the HIPAA-eligible tier and submitting PHI.

1. Definitions

Capitalised terms not defined in this BAA have the meanings set out at 45 CFR Parts 160 and 164. In particular:

  • "PHI" has the meaning at 45 CFR § 160.103, limited to PHI that Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity.
  • "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH and the HIPAA Omnibus Final Rule.
  • "Security Incident" has the meaning at 45 CFR § 164.304.
  • "Breach" has the meaning at 45 CFR § 164.402.

2. Permitted uses and disclosures

2.1 Business Associate may use and disclose PHI only as permitted or required by this BAA, the Principal Agreement, or as required by law.

2.2 Service provision. Business Associate may use and disclose PHI to provide the Service, including hosting, transcription, generation of agent responses, audit logging, and assistance with abuse prevention and support, in accordance with the documented configuration of the Service by Covered Entity.

2.3 Sub-processors. Business Associate may disclose PHI to its Sub-processors listed in SUBPROCESSORS.md only where the Sub-processor has executed a Business Associate Agreement with Business Associate that complies with 45 CFR § 164.504(e). Sub-processors that have not executed a HIPAA BAA must not receive PHI; the HIPAA-eligible tier route gates these by configuration.

2.4 Business Associate's own operations. Business Associate may use and disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that disclosures are required by law or that Business Associate obtains reasonable assurances of confidentiality and reporting of any breach.

2.5 Aggregated services. Business Associate may de-identify PHI in accordance with 45 CFR § 164.514(b) and use the de-identified information for its own operations, including service improvement. De-identified data is not PHI.

2.6 Prohibited uses. Business Associate must not (a) sell PHI in violation of 42 USC § 17935(d); (b) use or disclose PHI for marketing in violation of 45 CFR § 164.508; or (c) train any third-party foundation model on PHI.

3. Safeguards

3.1 Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI as required by Subpart C of 45 CFR Part 164 (the Security Rule). Those safeguards are described in the Security Overview and Schedule 2 of the DPA, and include:

  • access controls (RBAC, MFA, just-in-time production access);
  • audit controls (per-request audit log, append-only);
  • integrity controls (HMAC-chained audit log);
  • person or entity authentication (magic link + TOTP);
  • transmission security (TLS 1.2+);
  • encryption at rest (AES-256 at the storage layer);
  • application-layer Fernet encryption (AES-128-CBC + HMAC-SHA-256) for Customer-supplied credentials;
  • training (annual HIPAA training for all personnel with PHI access).

3.2 Minimum necessary. Business Associate will limit the use, disclosure, and request of PHI to the minimum necessary to perform the Service.

4. Reporting

4.1 Security Incidents. Business Associate will report to Covered Entity any Security Incident of which it becomes aware. The parties acknowledge and agree that unsuccessful Security Incidents (such as routine port scans and pings of firewalls that do not result in unauthorised access) are reported in the aggregate via the Trust portal and do not require individual notification. Successful Security Incidents are reported under § 4.2.

4.2 Breaches. Business Associate will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay and in any event within forty-eight (48) hours of discovery. The notification will include, to the extent then known, the information required by 45 CFR § 164.410(c). Business Associate will provide reasonable assistance to Covered Entity in meeting Covered Entity's Breach notification obligations under 45 CFR §§ 164.404 and 164.406.

4.3 Other uses or disclosures. Business Associate will report any use or disclosure of PHI not permitted by this BAA of which it becomes aware.

5. Individual rights

5.1 Access (45 CFR § 164.524). Within fifteen (15) business days of Covered Entity's written request, Business Associate will provide Covered Entity (or, at Covered Entity's direction, an Individual) with access to PHI in a Designated Record Set in the electronic format requested where readily producible.

5.2 Amendment (45 CFR § 164.526). Within thirty (30) business days of Covered Entity's written request, Business Associate will make any amendment Covered Entity directs to PHI in a Designated Record Set.

5.3 Accounting of disclosures (45 CFR § 164.528). Business Associate will document disclosures of PHI and information related to those disclosures as would be required for Covered Entity to respond to an Accounting request, and provide that information to Covered Entity within thirty (30) business days of request. Where audit logging is sufficient to satisfy the request, the audit log export is the canonical record.

5.4 Restrictions and confidential communications. Business Associate will support Covered Entity's compliance with restrictions and confidential communication requests communicated to Business Associate in writing.

6. Books and records / Secretary access

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA, subject to attorney-client and other applicable privileges.

7. Term and termination

7.1 Term. This BAA is effective on the Effective Date and continues until the Principal Agreement terminates, or this BAA is otherwise terminated under § 7.2.

7.2 Termination for cause. If either party knows of a pattern of activity or practice of the other party that constitutes a material breach of this BAA, that party will:

  • (a) provide written notice of the breach and a thirty (30)-day cure period;
  • (b) on failure to cure, terminate this BAA and (where feasible) the affected portion of the Principal Agreement;
  • (c) if termination is not feasible, report the violation to the Secretary.

7.3 Effect of termination. On termination of this BAA, Business Associate will return or destroy all PHI received from, or created or received on behalf of, Covered Entity, and will retain no copies, in accordance with § 9 of the DPA. Where return or destruction is infeasible, Business Associate will extend the protections of this BAA to the PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for as long as Business Associate retains the PHI. Backups containing PHI are purged within ninety (90) days.

8. Miscellaneous

8.1 Regulatory amendment. The parties agree to take such action as is necessary to amend this BAA from time to time so that the parties may continue to comply with HIPAA. Where neither party proposes an amendment within sixty (60) days of a regulatory change, the more conservative reading of the regulation governs.

8.2 Interpretation. Any ambiguity in this BAA is to be resolved in favour of a meaning that permits Covered Entity to comply with HIPAA.

8.3 Order of precedence. In a conflict between this BAA and the Principal Agreement on the handling of PHI, this BAA prevails.

8.4 Survival. Sections 4.2, 6, 7.3, and 8 survive termination.


Signature block

PartySignatureNameTitleDate
Covered Entity
Business Associate — Vestibo

Changelog

  • v1.0 (2026-07-23) — first published version; rebranded to Vestibo and reconciled to the current product.
  • v0.1 (2026-05-16) — initial internal draft.

Questions? Email legal@vestibo.com.