Business Associate Agreement — Template v1

Status: Template for review. This document is a starting point, not executed legal advice. Have counsel review before relying on it for production PHI workloads.

---

Business Associate Agreement (Template v1)

This Business Associate Agreement ("Agreement") is entered into by and between the covered entity or business associate that accepts it electronically ("Covered Entity") and LetsCompl.ai LLC ("Business Associate"), effective as of the electronic acceptance timestamp recorded in the LetsCompl.ai platform ("Effective Date").

1. Purpose

The Covered Entity uses the LetsCompl.ai platform ("Services") to evaluate application payloads, which may include Protected Health Information ("PHI"), against configured compliance rulesets. The parties intend to comply with the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the HITECH Act (collectively, "HIPAA").

2. Permitted Uses and Disclosures

Business Associate may use or disclose PHI solely:

a. To provide the Services as configured by Covered Entity, including evaluation, redaction, persistence of redacted payloads only, and evidence logging;

b. As required by law;

c. As otherwise agreed in writing.

Business Associate shall not use PHI for product improvement, model training, marketing, or any purpose beyond operating the Services.

3. Safeguards

Business Associate shall implement administrative, physical, and technical safeguards that reasonably protect the confidentiality, integrity, and availability of PHI, including:

  • Encryption in transit (TLS) and at rest for persisted data;
  • API keys stored only as SHA-256 hashes;
  • Redaction-before-persistence: raw request payloads are discarded after local/gateway redaction and never written to durable storage;
  • Access controls limiting PHI access to workforce members who require it.

Covered Entity acknowledges that the Services' redaction is pattern-based and documented; see the published data-handling documentation for the exact pattern boundary. Covered Entity is responsible for configuring rules appropriate to its PHI risk profile.

4. Reporting

Business Associate shall report to Covered Entity any security incident involving PHI of which it becomes aware, without unreasonable delay and within the time frame required by 45 C.F.R. § 164.410.

5. Subcontractors

Business Associate shall ensure subcontractors that create, receive, maintain, or transmit PHI on its behalf are bound by written agreements imposing the same restrictions and conditions as this Agreement.

6. Availability of Records

Business Associate shall make its policies and books relating to the use and disclosure of PHI available to Covered Entity (or the Secretary of HHS) to the extent required for Covered Entity's compliance obligations.

7. Amendment and Termination

The parties shall amend this Agreement as necessary for compliance. Business Associate may terminate the Agreement and the associated HIPAA regime access if it becomes aware of a pattern of activity by Covered Entity that constitutes a material breach or violation, in accordance with 45 C.F.R. § 164.504(e).

8. Electronic Acceptance

Acceptance is effected by an authorized administrator of the Covered Entity's workspace clicking the acceptance control in the LetsCompl.ai dashboard, after reviewing: (a) this template, and (b) the platform's legal disclaimer stating that LetsCompl.ai is a technical enforcement tool and not a legal compliance service. The acceptance timestamp, template version, and accepting user identity are recorded in the platform and constitute the record of execution.