Legal
HIPAA Business Associate Agreement
Effective date: June 15, 2025 · Last updated: June 15, 2025
BAA is included with all plans
By creating a ClinVox AI account and using the Service, you and DESVERSO LLC are entering into this Business Associate Agreement, which is incorporated into the Terms of Service. No separate signature is required for standard accounts. Enterprise customers may request a custom signed BAA by contacting legal@clinvox.ai.
1. Definitions
Terms used in this BAA have the meanings ascribed to them under HIPAA, the HITECH Act, and their implementing regulations (collectively, "HIPAA Rules"), unless otherwise defined herein.
- "Covered Entity" (CE) means you — the healthcare provider, clinician, or covered healthcare organization using ClinVox AI.
- "Business Associate" (BA) means DESVERSO LLC, operator of ClinVox AI.
- "Protected Health Information" (PHI) has the meaning given under 45 C.F.R. § 160.103, limited to PHI that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.
- "Services" means the ClinVox AI clinical documentation platform described in the Terms of Service.
2. Obligations of Business Associate
DESVERSO LLC agrees to:
- Not use or disclose PHI other than as permitted or required by this BAA, the Terms of Service, or as required by law.
- Use appropriate safeguards, and comply with the HIPAA Security Rule with respect to electronic PHI (ePHI), to prevent use or disclosure of PHI other than as provided for by this BAA.
- Report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including Breaches of Unsecured PHI, as required by 45 C.F.R. § 164.410, without unreasonable delay and in no case later than 60 days after discovery of such Breach.
- Ensure that any subcontractors (sub-BAs) that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions and conditions that apply to Business Associate.
- Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining Covered Entity's compliance with the HIPAA Rules.
- Upon termination or expiration of the BAA, return or destroy all PHI received from or created on behalf of Covered Entity, where feasible, or continue to protect such PHI in accordance with this BAA.
3. Permitted Uses and Disclosures
Business Associate may use or disclose PHI:
- As necessary to perform the Services described in the Terms of Service on behalf of Covered Entity.
- For the proper management and administration of Business Associate's business, provided that disclosures are required by law, or Business Associate obtains reasonable assurances of confidentiality from any recipient.
- To provide data aggregation services relating to the healthcare operations of Covered Entity.
- As required by law.
Business Associate shall not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted in this BAA.
4. Obligations of Covered Entity
Covered Entity agrees to:
- Notify Business Associate of any restrictions on the use or disclosure of PHI that Covered Entity has agreed to with individuals, to the extent such restrictions may affect Business Associate's use or disclosure of PHI.
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.
- Obtain patient consent for recording clinical consultations as required by applicable federal and state law prior to using the recording features of the Service.
5. Security Safeguards
Business Associate implements the following safeguards for ePHI:
- Administrative: Security officer designation, workforce training, access management, incident response procedures.
- Physical: Access controls at data center facilities managed by infrastructure provider.
- Technical: AES-256 encryption at rest, TLS 1.2+ in transit, unique user authentication, automatic session timeout, comprehensive audit logging.
6. Individual Rights
Business Associate agrees to assist Covered Entity in meeting its obligations to individuals under the HIPAA Rules, including:
- Providing access to PHI held by Business Associate in a designated record set, at the request of Covered Entity.
- Making amendments to PHI in a designated record set, at the direction of Covered Entity.
- Providing an accounting of disclosures of PHI, at the request of Covered Entity.
7. Subcontractors
Business Associate uses the following subcontractors who may access PHI in the course of providing the Services:
- OpenAI, L.L.C. — transcription and AI note generation (subject to OpenAI's Enterprise Privacy commitments)
- Hostinger International Ltd. — infrastructure and data storage
Business Associate ensures each subcontractor is bound by data processing obligations consistent with this BAA.
8. Term and Termination
This BAA is effective as of the date you first use the Service and shall remain in effect until the earlier of: (a) termination of the Terms of Service, or (b) written termination by either party with 30 days' notice.
Either party may terminate this BAA immediately upon written notice if the other party has materially breached a provision of this BAA and has not cured such breach within 30 days of written notice.
Upon termination, Business Associate shall destroy or return all PHI within 30 days, except where retention is required by law, in which case the obligations of this BAA extend to any retained PHI.
9. Miscellaneous
This BAA is incorporated into and made a part of the ClinVox AI Terms of Service. In the event of any conflict between this BAA and the Terms of Service with respect to PHI, this BAA shall govern. This BAA shall be interpreted as broadly as necessary to implement and comply with HIPAA.
10. Contact & Custom BAA
Enterprise customers requiring a custom executed BAA should contact us. Standard accounts are covered by this BAA upon account creation.