Business Associate Agreement
Last updated September 17, 2026
This Business Associate Agreement is between the practice that signs it (“you”, a covered entity under HIPAA) and Sup AI (“we”, your business associate). It applies from the moment you sign it to all protected health information your Sup AI employees create, receive, keep, or send while working for you, and it is part of our Terms. Where the two disagree about protected health information, this agreement wins.
1. Words
“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164. Breach, designated record set, disclosure, individual, minimum necessary, protected health information, required by law, Secretary, security incident, subcontractor, unsecured protected health information, and use mean what the HIPAA Rules say they mean. “Your information” here means the protected health information we handle for you.
2. What we may do with your information
We use and disclose your information only to do the work you hire your employees for (answering and placing calls, texts and email, and work in the systems you sign them in to), as you direct by your word to them, as this agreement allows, and as required by law. We keep to the minimum necessary for the task. We do not use or disclose your information in any way that would break Subpart E of 45 CFR Part 164 if you did it, except that we may use it for our own proper management and administration and to meet our legal responsibilities, and may disclose it for those purposes when the disclosure is required by law, or when whoever receives it promises in writing to keep it confidential, to use it only for the purpose it was given for or as required by law, and to tell us of any breach of that confidence.
We do not sell your information, we do not use it for marketing, and we do not train models on it. We send it only to subcontractors whose terms forbid them to train on it.
3. What we promise
Safeguards. We use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 for electronic protected health information, to prevent any use or disclosure this agreement does not allow. Recordings, transcripts, screenshots, and files are kept in private storage, encrypted in transit and at rest, and every link to one is signed and short-lived. Each employee has a computer of its own, shared with no other business.
Reporting. We tell you of any use or disclosure of your information this agreement does not allow, any security incident, and any breach of unsecured protected health information as 45 CFR 164.410 requires, without unreasonable delay and no later than 10 days after we discover it, with what happened, when, which individuals and what information were involved as far as we know, and what we have done about it. Unsuccessful attempts that touch no information (pings, scans, refused sign-ins) happen constantly; this sentence is our notice of them, and we report them further only if you ask.
Subcontractors. As 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2) require, every subcontractor that creates, receives, keeps, or sends your information for us agrees in writing to the same restrictions and conditions that apply to us here. Who they are, what reaches each, and the state of each agreement are listed at sup.ai/subprocessors.
Individuals’ rights. Within ten business days of your asking, we make your information in a designated record set available to you so you can meet 45 CFR 164.524, make the amendments you direct under 45 CFR 164.526, and give you what you need to account for disclosures under 45 CFR 164.528. If an individual asks us directly, we send them to you. Your employee keeps a record of who looked at what (recordings played, transcripts opened, screens watched), and you can read it under Account, Data.
Your duties done by us. Where we carry out a duty of yours under Subpart E, we meet the requirements of Subpart E that apply to you in doing it.
Books and records. We make our internal practices, books, and records about your information available to the Secretary for determining compliance with the HIPAA Rules.
4. What you promise
You tell us of any limitation in your notice of privacy practices, any change in or withdrawal of an individual’s permission, and any restriction you have agreed to, where it affects what we do. You do not ask us to use or disclose protected health information in a way the HIPAA Rules would not allow you. You sign your employees in only to systems you have the right to give them, and you tell them, in your own words, how your practice confirms who a caller is before anything about a patient is said.
5. How long, and what happens after
This agreement lasts as long as you have an employee with us and until all of your information is returned or destroyed. Either of us may end it, and the service with it, if the other breaks a material term and does not cure the break within thirty days of written notice; if cure is not possible, at once.
When it ends, or when you let an employee go, we keep your records read-only for thirty days with an export of transcripts, recordings, and notes, then destroy them, including the employee’s computer, or sooner when you say so. Backups age out within the window shown at sup.ai/subprocessors. Where returning or destroying something is not feasible, we keep protecting it under this agreement and use it for nothing but what makes its return or destruction infeasible. Anything you ask us to hold for a legal matter is held until you lift the hold.
6. The rest
A reference to a section of the HIPAA Rules means the section as it stands at the time. We will both amend this agreement when the law requires it; a new version is signed the way this one was and never replaces a signature silently. Any ambiguity is read the way that lets us both comply with the HIPAA Rules. Nothing here gives rights to anyone but the two of us. Sections 3 and 5 survive the end of the agreement for as long as we hold any of your information.
Questions: support@sup.ai.