Back to Home

Business Associate Agreement (BAA)

Effective Date: June 10, 2026

This Business Associate Agreement (“BAA”) is entered into between VeritaMed.ai, LLC (“Business Associate”) and the Healthcare Provider (“Covered Entity”).

1. Purpose

This BAA ensures that VeritaMed.ai complies with the Health Insurance Portability and Accountability Act (HIPAA) when processing Protected Health Information (PHI) on behalf of the Covered Entity.

2. Permitted Uses and Disclosures

The Business Associate may use or disclose PHI only as necessary to perform the services described in the underlying service agreement, or as required by law. Any other use or disclosure is strictly prohibited.

3. Safeguards

The Business Associate agrees to implement appropriate administrative, physical, and technical safeguards (including AES‑256 encryption for data at rest and TLS 1.3 for data in transit) to prevent unauthorized access, use, or disclosure of PHI.

4. Breach Notification

In the event of a security incident or breach of unsecured PHI, the Business Associate will notify the Covered Entity within 72 hours of discovery, in accordance with the HIPAA Breach Notification Rule (45 CFR § 164.408).

5. Subcontractors

The Business Associate shall ensure that any subcontractor that receives PHI agrees to the same restrictions and conditions as this BAA through a written agreement.

6. Access and Amendment

Upon request, the Business Associate shall provide access to PHI in a designated record set and shall make amendments as required by the Covered Entity.

7. Termination

This BAA terminates upon termination of the underlying service agreement. Upon termination, the Business Associate shall return or destroy all PHI received from the Covered Entity.

8. Requesting a Signed BAA

A signed BAA is required prior to the processing of any PHI. To initiate the BAA process, please contact our legal team at legal@veritamed.ai.

VeritaMed.ai, LLC – Virginia, USA

Last updated: June 10, 2026