Proxaradocs
Trust Center/Compliance

HIPAA Business Associate Agreement

Business Associate Agreement for healthcare customers, covering both products including Proxara Connect retrieval. PHI safeguards, breach notification, individual rights, HHS access, and the audit chain that supports accounting of disclosures under 45 CFR § 164.528.

Updated July 2026

HIPAA Business Associate Agreement

Last updated: July 2026

This Business Associate Agreement ("BAA") supplements the Master Subscription Agreement (the "Agreement") between Proxara, Inc. ("Business Associate" or "Proxara"), and the Customer identified in the applicable Order Form ("Covered Entity" or "Customer").

This BAA applies only to Proxara-Managed Dedicated Account deployments where Proxara may create, receive, maintain, or transmit Protected Health Information on behalf of Customer. It covers both Proxara products where subscribed: Endpoint Protection, the device agent, and Proxara Connect, whose retrieval of Covered Entity's mail, messages, and files can sweep PHI where the tenant contains it and is therefore within this BAA's scope. For Customer-Managed deployments, Proxara does not access or process PHI; this BAA does not apply, and Proxara is not a Business Associate under those deployment models.


1. Definitions

Terms used in this BAA that are defined in the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, "HIPAA"), shall have the meanings set forth in HIPAA. In addition:

"Breach" has the meaning set forth in 45 CFR § 164.402.

"Designated Record Set" has the meaning set forth in 45 CFR § 164.501.

"Electronic Protected Health Information" or "ePHI" means Protected Health Information that is transmitted by or maintained in electronic media.

"Individual" means the person who is the subject of the PHI, and includes a person who qualifies as a personal representative under 45 CFR § 164.502(g).

"Protected Health Information" or "PHI" has the meaning set forth in 45 CFR § 160.103, and is limited to PHI created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity pursuant to this BAA.

"Required by Law" has the meaning set forth in 45 CFR § 164.103.

"Secretary" means the Secretary of the U.S. Department of Health and Human Services.

"Security Incident" has the meaning set forth in 45 CFR § 164.304.

"Unsecured PHI" has the meaning set forth in 45 CFR § 164.402.


2. Permitted Uses and Disclosures

2.1 Service Performance

Business Associate may use and disclose PHI solely as necessary to perform its obligations under the Agreement. The services performed in connection with PHI are:

  • For Endpoint Protection, operating the classification API to analyze AI-bound prompts and responses for sensitive health information, using Amazon Bedrock (Anthropic Claude Haiku) inside Covered Entity's dedicated AWS account.
  • Intercepting and inspecting AI-bound network traffic through the device-level TLS proxy on macOS and Windows. Its root certificate authority carries X.509 Name Constraints excluding sign-in, banking, healthcare-provider, government, and security-tooling domains in the certificate itself, so traffic to them is never intercepted, and a connection is decrypted only on positive evidence the destination is an AI service.
  • Extracting and analyzing text from files uploaded to external AI tools (spreadsheets, PDFs, CSVs, documents) to detect PHI before transmission, and semantically redacting the 18 HIPAA-defined identifiers before prompts reach those services. For the device service, redacted values become reversible tokens, and only the redacted request reaches the third-party AI provider.
  • For Proxara Connect, where subscribed: retrieving mail, calendar items, messages, files, and tasks from Covered Entity's own Microsoft 365 tenant, on Covered Entity's instruction and under each signed-in workforce member's delegated permissions; classifying and reasoning over that raw material on a customer-contained inference plane inside Covered Entity's dedicated environment, which has no internet route and no route to an external model; releasing to Covered Entity's AI assistant only a payload assembled from the claims its policy admitted, with stand-ins for protected references including PHI identifiers; rendering the clear result only in a first-party origin under Covered Entity's single sign-on, bound to the exact recipient and artifact revision, which a host adapter may open but never read; and executing approved actions with exact values restored only inside that environment. Covered Entity's policy can hold designated classes inside that environment entirely, with no substantive content reaching an external AI service.
  • Observing and recording Model Context Protocol (MCP) tool activity from AI clients on managed devices. Proxara does not hold or proxy tool calls in the data path; it records signed audit events and lets Covered Entity block or quarantine a server.
  • Storing flagged audit records temporarily in Covered Entity's dedicated environment for compliance review, purged when the compliance officer archives the event or after seven days, whichever comes first.
  • Maintaining a signed audit chain (canonical JSON, Ed25519 per event, hash-chained per tenant) to support Covered Entity's accounting-of-disclosures obligation under 45 CFR § 164.528. Original PHI values are not stored in it; only entity types, counts, and SHA-256 hashes.
  • Routing flagged event notifications to the alert channels Covered Entity configures (Slack, email, and supported integrations), and providing the governance console for Covered Entity's compliance team.

Business Associate may use and disclose PHI for its proper management and administration or to carry out its legal responsibilities, provided that: (a) the disclosure is Required by Law; or (b) Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or disclosed only as Required by Law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instances of which it is aware that the confidentiality of the PHI has been breached.

2.3 Minimum Necessary

Business Associate shall limit its use and disclosure of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 CFR § 164.502(b) and 45 CFR § 164.514(d).


3. Obligations of Business Associate

3.1 Safeguards

Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, in accordance with 45 CFR § 164.306 and § 164.312. These safeguards include:

  • Encryption at rest: AES-256 via AWS KMS customer-managed keys in Covered Entity's dedicated AWS account. The deployment record names who administers them; where Covered Entity does, Proxara holds use rights only and Covered Entity may revoke that access at any time.
  • Encryption in transit: TLS 1.2 minimum, TLS 1.3 supported, on all endpoints. RDS enforces TLS for every connection.
  • Access controls: role-based access to the governance console and the dedicated environment; unique user identification; automatic session timeout.
  • Audit controls: append-only logging of all access to flagged records; reviewer identity tracking. Every observed MCP tool-call event on a managed device produces a signed Ed25519 audit entry in a per-tenant hash chain whose Merkle batch roots anchor to Sigstore Rekor by default; only the 32-byte root hash is transmitted, never PHI.
  • Transmission security: classification occurs within the dedicated environment. For Endpoint Protection that inference runs on Amazon Bedrock in Covered Entity's AWS account over TLS. For Proxara Connect, classification of raw or sensitive material runs on the customer-contained inference plane there; a managed endpoint reached over a private network link is still a managed external processor, so network privacy is not treated as containment.
  • Integrity controls: for the device service, redaction token maps sit in an on-device encrypted vault, session-scoped and short-lived, removed on agent uninstall, with no original values stored server-side. For Proxara Connect, retrieved content, stand-in mappings, workflow state, and grant tokens stay in that environment under Covered Entity's own KMS keys, fetched when asked rather than copied in bulk, and deleted on offboarding or termination. S3 Object Lock is available for immutable audit archive retention.

3.2 Reporting

Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which Business Associate becomes aware, including any Security Incident. Business Associate shall report any Breach of Unsecured PHI in accordance with Section 5.

3.3 Subcontractors

Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate under this BAA. Business Associate's current subcontractors are listed in the Subprocessor List.

3.4 Access

Business Associate shall make PHI available to Covered Entity or, as directed by Covered Entity, to an Individual, in a Designated Record Set within thirty (30) days of a request, to satisfy Covered Entity's obligations under 45 CFR § 164.524.

3.5 Amendment

Business Associate shall make PHI available for amendment and incorporate amendments to PHI in a Designated Record Set within thirty (30) days of a request from Covered Entity, to satisfy Covered Entity's obligations under 45 CFR § 164.526.

3.6 Accounting of Disclosures

Business Associate shall maintain and make available information required to provide an accounting of disclosures to satisfy Covered Entity's obligations under 45 CFR § 164.528. Business Associate shall provide such accounting within sixty (60) days of a request.

3.7 HHS Access

Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA.

3.8 Mitigation

Business Associate shall mitigate, to the extent practicable, any harmful effect of a use or disclosure of PHI in violation of this BAA of which Business Associate becomes aware.


4. Obligations of Covered Entity

4.1 Notices and Restrictions

Covered Entity shall notify Business Associate of any limitations in its Notice of Privacy Practices that may affect Business Associate's use or disclosure of PHI. Covered Entity shall notify Business Associate of any restrictions on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522.

4.2 Permissions

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.

Covered Entity warrants that it has obtained any necessary consents, authorizations, or other permissions required under applicable law for the disclosure of PHI to Business Associate.


5. Breach Notification

5.1 Notification to Covered Entity

Following the discovery of a Breach of Unsecured PHI, Business Associate shall notify Covered Entity without unreasonable delay and in no event later than sixty (60) calendar days after discovery of the Breach, consistent with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). Business Associate is deemed to have discovered a Breach as of the first day the Breach is known or, by exercising reasonable diligence, would have been known.

Timing across deployments: healthcare deployments under this BAA follow the 60-day HIPAA standard, and all other Proxara deployments, governed by the Data Processing Addendum, receive the more protective 72-hour notice period.

5.2 Contents of Notification

The notification shall include, to the extent available:

  • The identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the Breach.
  • A description of what happened, including the date of the Breach and the date of its discovery.
  • A description of the types of Unsecured PHI involved.
  • Any steps Business Associate recommends that affected Individuals take to protect themselves.
  • A description of what Business Associate is doing to investigate the Breach, mitigate harm, and protect against further Breaches.

5.3 Covered Entity Responsibilities

Covered Entity is responsible for providing notification to affected Individuals and the Secretary in accordance with 45 CFR §§ 164.404 and 164.408. Business Associate shall cooperate with Covered Entity in fulfilling these obligations.


6. Term and Termination

6.1 Term

This BAA shall be effective as of the Effective Date and shall remain in effect for the duration of the Agreement, unless terminated earlier as provided herein.

6.2 Termination for Cause

Either Party may terminate this BAA upon thirty (30) days' written notice if the other Party materially breaches this BAA and fails to cure the breach within the notice period. If cure is not feasible, the non-breaching Party may terminate immediately.

6.3 Effect of Termination

Upon termination of this BAA, Business Associate shall, at Covered Entity's election:

  • Return all PHI to Covered Entity; or
  • Destroy all PHI and certify destruction in writing.

If return or destruction is infeasible, Business Associate shall extend the protections of this BAA to the PHI for as long as it is retained and limit further uses and disclosures to those purposes that make return or destruction infeasible.

For Proxara-Managed deployments, PHI resides in Covered Entity's dedicated AWS account. Upon termination, Covered Entity may elect to take ownership of that account, or Proxara will delete all data and certify destruction. Proxara's deletion includes crypto-erasure of all identity-vault keys, rendering tokenized original values unrecoverable.

6.4 Survival

The obligations of Business Associate under Sections 3 and 5 shall survive the termination or expiration of this BAA to the extent Business Associate retains any PHI.


7. Miscellaneous

7.1 Regulatory References

Any reference to a section of HIPAA shall mean that section as in effect or as amended.

7.2 Amendment

The Parties agree to take such action as is necessary to amend this BAA from time to time to comply with HIPAA and any other applicable laws.

7.3 Interpretation

Any ambiguity in this BAA shall be resolved to permit compliance with HIPAA.

7.4 No Third-Party Beneficiaries

Nothing in this BAA shall confer upon any person other than the Parties any rights or remedies, except that Individuals are intended third-party beneficiaries of Sections 3.4, 3.5, and 3.6.

7.5 Governing Law

This BAA is governed by the laws of the State of California, USA, without regard to conflict-of-laws principles, to the extent not preempted by HIPAA.

7.6 Contact

Questions about this BAA or data-handling practices: support@proxara.ai. Security incidents and vulnerability disclosures: security@proxara.ai.

Proxara, Inc.

28 Geary St. Suite 650 PMB 5328

San Francisco, CA 94108