Version: 1.0 | Effective: upon your acceptance | Vaultus Technologies, Inc.
When you process real patient information through Vaultus, Vaultus is your Business Associate under HIPAA. We don't store your patient notes; we keep only de-identified safety metadata. This agreement sets out how we protect PHI, when we notify you of any breach, and your right (which you grant us) to use PHI to create de-identified data we may keep.
This Business Associate Agreement ("Agreement") is between you ("Covered Entity") — the individual provider, or the practice you identified, on whose behalf you are authorized to sign — and Vaultus Technologies, Inc. ("Business Associate"), effective upon your acceptance. It supplements and is incorporated into the Terms of Service.
Terms used but not defined have the meanings in the HIPAA Rules (45 CFR Parts 160 and 164). "PHI" means Protected Health Information that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.
Business Associate provides a deterministic documentation-safety service that evaluates clinical documentation against pre-defined safety rules and returns observations. Business Associate does not store raw clinical note text (processed in memory and hashed at every persistence boundary; an automated guard rejects persisting note/SOAP/free-text). Business Associate makes no clinical decisions, generates no clinical content, and never writes into or modifies the note.
(a) Business Associate may use/disclose PHI only as necessary to perform the service, as Required by Law, or as permitted here. (b) Business Associate may use PHI for its proper management and administration and to carry out its legal responsibilities, with the assurances required by 45 CFR 164.504(e)(4). (c) De-identification right. Pursuant to 45 CFR 164.502(d)(1) and 164.514(a)–(c), Covered Entity authorizes Business Associate to use PHI to create de-identified information, and to retain, use, and disclose that de-identified information for any lawful purpose. De-identified information that meets 45 CFR 164.514(b) is not PHI and is not subject to this Agreement once de-identified. De-identification is achieved by non-retention of note text plus Safe Harbor–style minimization. (d) Business Associate will not use/disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted in 3(b). (e) Minimum Necessary. The service's non-retention design operationalizes minimum necessary.
Business Associate maintains administrative, physical, and technical safeguards consistent with the Security Rule, including encryption at rest (SQLCipher AES, 256,000-iteration KDF) and in transit (TLS 1.2/1.3), access controls and authentication, and one-way pseudonymization of provider identity — except for controls noted as in-progress in Schedule A.
Per 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate ensures any subcontractor that handles PHI on its behalf agrees in writing to restrictions at least as restrictive as those here. Business Associate maintains a current Subprocessor Register and has a signed Business Associate Agreement with its infrastructure subprocessor, DigitalOcean.
(a) Business Associate will report any non-permitted use/disclosure, Security Incident, or Breach of Unsecured PHI of which it becomes aware. (b) For a Breach of Unsecured PHI, Business Associate will notify Covered Entity without unreasonable delay and no later than 15 calendar days after discovery (45 CFR 164.410). (c) The notice will include, to the extent known, the nature of the incident, the PHI involved, the individuals affected, and mitigation. (d) Routine unsuccessful Security Incidents (scans, pings, blocked attempts) need not be individually reported; this section serves as notice of their ongoing occurrence.
Because Business Associate does not retain raw note text or patient identifiers in a Designated Record Set, it does not maintain PHI supporting patient access (164.524), amendment (164.526), or accounting of disclosures (164.528) of clinical content. To the extent it holds any PHI that is part of Covered Entity's Designated Record Set, it will support those rights as directed by Covered Entity.
Business Associate will make its internal practices, books, and records relating to PHI available to the Secretary of HHS for determining Covered Entity's compliance.
(a) Effective on acceptance; continues until terminated or all PHI is returned/destroyed. (b) Covered Entity may terminate for an uncured material breach within 30 days of notice. (c) Return/destruction. On termination, Business Associate returns or destroys PHI it maintains, if feasible; where not feasible, it extends these protections and limits further use. The parties acknowledge Business Associate does not retain raw note text or patient identifiers; de-identified information created under Section 3(c) is not PHI and survives termination.
No third-party beneficiaries. This Agreement controls over the Terms of Service with respect to PHI. This Agreement is governed by the laws of the State of California.
Business Associate represents the Section 4 safeguards are implemented as of the Effective Date, except controls noted in Schedule A as in-progress.
Schedule A — Control status (as of 2026-06-23): Environment separation (staging/production database): in remediation. Plaintext backup elimination: in remediation. Tamper-evident integrity-chain validation: in remediation; not represented as operative until passing. This Schedule is updated by version as controls complete.
Vaultus Technologies, Inc.