Legal

Business Associate Agreement

Last updated: 1 January 2026. This Business Associate Agreement (“BAA”) is entered into between the Covered Entity (“You”) and GATMEDI Ltd, trading as ClinixSummary (“Business Associate”, “we”, “us”).

1. Definitions

“Business Associate” means GATMEDI Ltd, which creates, receives, maintains or transmits Protected Health Information on behalf of the Covered Entity in connection with the ClinixSummary platform. “Covered Entity” means the healthcare provider, health plan or healthcare clearinghouse that enters into this BAA. “Protected Health Information” (PHI) means individually identifiable health information as defined under 45 CFR § 160.103. “Electronic PHI” (ePHI) means PHI that is created, received, maintained or transmitted in electronic form.

2. Obligations of Business Associate

Business Associate agrees to: (a) not use or disclose PHI other than as permitted by this BAA or as required by law; (b) implement administrative, physical and technical safeguards to protect ePHI; (c) report any Security Incident or Breach of Unsecured PHI to Covered Entity within 72 hours of discovery; (d) make PHI available to Covered Entity to fulfil data subject access requests; (e) make its internal practices and records relating to PHI available for audit; (f) return or destroy all PHI upon termination where feasible.

3. Permitted Uses and Disclosures

Business Associate may use and disclose PHI solely for the purpose of providing the ClinixSummary clinical documentation service to the Covered Entity, and as required by law. Business Associate shall not use PHI for marketing, sale, or any purpose other than service delivery without prior written consent.

4. Safeguards

Business Associate maintains the following safeguards to protect ePHI: AES-256 encryption at rest; TLS 1.2+ encryption in transit; SOC 2-aligned administrative and technical controls; role-based access controls and audit logging; immediate and permanent deletion of audio recordings upon note generation; regular penetration testing and vulnerability assessments.

5. Breach Notification

Business Associate shall notify the Covered Entity within 72 hours of discovering a Breach of Unsecured PHI. Notification shall include: the nature and extent of the PHI involved; the identity of any unauthorised person who accessed or used the PHI; whether the PHI was actually acquired or viewed; and the corrective actions taken or planned.

6. Term and Termination

This BAA remains in effect for the duration of the underlying service agreement between the parties. Either party may terminate this BAA if the other party materially breaches its obligations and fails to cure the breach within 30 days of written notice. Upon termination, Business Associate shall return or destroy all PHI in its possession. If return or destruction is not feasible, Business Associate shall extend the protections of this BAA to any retained PHI.

7. Return or Destruction of PHI

Upon termination of this BAA, Business Associate shall, at the Covered Entity’s election, return or destroy all PHI received from or created on behalf of the Covered Entity. Business Associate shall retain no copies of PHI except where required by law. Destruction shall be carried out using methods consistent with NIST SP 800-88 guidelines.

8. Contact

For questions about this BAA or to request execution, contact compliance@clinixsummary.ai.

Assegurado pelo processo de gestão de qualidade ClinixQM