Business Associate Agreement for healthcare customers, covering both products including Proxara Connect retrieval. PHI safeguards, breach notification, individual rights, HHS access, and the audit chain that supports accounting of disclosures under 45 CFR § 164.528.
Updated July 2026
Last updated: July 2026
This Business Associate Agreement ("BAA") supplements the Master Subscription Agreement (the "Agreement") between Proxara, Inc. ("Business Associate" or "Proxara"), and the Customer identified in the applicable Order Form ("Covered Entity" or "Customer").
This BAA applies only to Proxara-Managed Dedicated Account deployments where Proxara may create, receive, maintain, or transmit Protected Health Information on behalf of Customer. It covers both Proxara products where subscribed: Endpoint Protection (the device agent) and Proxara Connect (the hosted connector, whose retrieval of Covered Entity's mail, messages, and files can sweep PHI where Covered Entity's tenant contains it, and is therefore deliberately within this BAA's scope rather than excluded from it). For Customer-Managed deployments, Proxara does not access or process PHI; this BAA does not apply, and Proxara is not a Business Associate under those deployment models.
Terms used in this BAA that are defined in the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, "HIPAA"), shall have the meanings set forth in HIPAA. In addition:
"Breach" has the meaning set forth in 45 CFR § 164.402.
"Designated Record Set" has the meaning set forth in 45 CFR § 164.501.
"Electronic Protected Health Information" or "ePHI" means Protected Health Information that is transmitted by or maintained in electronic media.
"Individual" means the person who is the subject of the PHI, and includes a person who qualifies as a personal representative under 45 CFR § 164.502(g).
"Protected Health Information" or "PHI" has the meaning set forth in 45 CFR § 160.103, and is limited to PHI created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity pursuant to this BAA.
"Required by Law" has the meaning set forth in 45 CFR § 164.103.
"Secretary" means the Secretary of the U.S. Department of Health and Human Services.
"Security Incident" has the meaning set forth in 45 CFR § 164.304.
"Unsecured PHI" has the meaning set forth in 45 CFR § 164.402.
Business Associate may use and disclose PHI solely as necessary to perform its obligations under the Agreement. The services performed in connection with PHI are:
Business Associate may use and disclose PHI for its proper management and administration or to carry out its legal responsibilities, provided that: (a) the disclosure is Required by Law; or (b) Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or disclosed only as Required by Law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instances of which it is aware that the confidentiality of the PHI has been breached.
Business Associate shall limit its use and disclosure of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 CFR § 164.502(b) and 45 CFR § 164.514(d).
Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, in accordance with 45 CFR § 164.306 and § 164.312. These safeguards include:
Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which Business Associate becomes aware, including any Security Incident. Business Associate shall report any Breach of Unsecured PHI in accordance with Section 5.
Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate under this BAA. Business Associate's current subcontractors are listed in the Subprocessor List.
Business Associate shall make PHI available to Covered Entity or, as directed by Covered Entity, to an Individual, in a Designated Record Set within thirty (30) days of a request, to satisfy Covered Entity's obligations under 45 CFR § 164.524.
Business Associate shall make PHI available for amendment and incorporate amendments to PHI in a Designated Record Set within thirty (30) days of a request from Covered Entity, to satisfy Covered Entity's obligations under 45 CFR § 164.526.
Business Associate shall maintain and make available information required to provide an accounting of disclosures to satisfy Covered Entity's obligations under 45 CFR § 164.528. Business Associate shall provide such accounting within sixty (60) days of a request.
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA.
Business Associate shall mitigate, to the extent practicable, any harmful effect of a use or disclosure of PHI in violation of this BAA of which Business Associate becomes aware.
Covered Entity shall notify Business Associate of any limitations in its Notice of Privacy Practices that may affect Business Associate's use or disclosure of PHI. Covered Entity shall notify Business Associate of any restrictions on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522.
Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
Covered Entity warrants that it has obtained any necessary consents, authorizations, or other permissions required under applicable law for the disclosure of PHI to Business Associate.
Following the discovery of a Breach of Unsecured PHI, Business Associate shall notify Covered Entity without unreasonable delay and in no event later than sixty (60) calendar days after discovery of the Breach, consistent with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). Business Associate is deemed to have discovered a Breach as of the first day the Breach is known or, by exercising reasonable diligence, would have been known.
For context on timing across deployments: healthcare deployments under this BAA follow the 60-day HIPAA standard. All other Proxara deployments (governed by the standard Data Processing Addendum) receive the more protective 72-hour notice period.
The notification shall include, to the extent available:
Covered Entity is responsible for providing notification to affected Individuals and the Secretary in accordance with 45 CFR §§ 164.404 and 164.408. Business Associate shall cooperate with Covered Entity in fulfilling these obligations.
This BAA shall be effective as of the Effective Date and shall remain in effect for the duration of the Agreement, unless terminated earlier as provided herein.
Either Party may terminate this BAA upon thirty (30) days' written notice if the other Party materially breaches this BAA and fails to cure the breach within the notice period. If cure is not feasible, the non-breaching Party may terminate immediately.
Upon termination of this BAA, Business Associate shall, at Covered Entity's election:
If return or destruction is infeasible, Business Associate shall extend the protections of this BAA to the PHI for as long as it is retained and limit further uses and disclosures to those purposes that make return or destruction infeasible.
For Proxara-Managed deployments, PHI resides in Covered Entity's dedicated AWS sub-account. Upon termination, Covered Entity may elect to take ownership of that account, or Proxara will delete all data and certify destruction. Proxara's deletion includes crypto-erasure of all identity-vault keys, rendering tokenized original values unrecoverable.
The obligations of Business Associate under Sections 3 and 5 shall survive the termination or expiration of this BAA to the extent Business Associate retains any PHI.
Any reference to a section of HIPAA shall mean that section as in effect or as amended.
The Parties agree to take such action as is necessary to amend this BAA from time to time to comply with HIPAA and any other applicable laws.
Any ambiguity in this BAA shall be resolved to permit compliance with HIPAA.
Nothing in this BAA shall confer upon any person other than the Parties any rights or remedies, except that Individuals are intended third-party beneficiaries of Sections 3.4, 3.5, and 3.6.
This BAA is governed by the laws of the State of California, USA, without regard to conflict-of-laws principles, to the extent not preempted by HIPAA.
Questions regarding this BAA or data-handling practices should be directed to support@proxara.ai. Security incidents and vulnerability disclosures should be sent to security@proxara.ai.
Proxara, Inc.
28 Geary St. Suite 650 PMB 5328
San Francisco, CA 94108