Clovai
← Home Español
Get started
Book a demo
Legal

Business Associate Agreement

Version 1.0 · Last updated: October 5, 2026

This Business Associate Agreement ("BAA") is entered into between the customer that accepts it online during sign-up at clovai.us ("Covered Entity") and Tagnara LLC, provider of Clovai ("Business Associate"). It takes effect when the Covered Entity's authorized representative accepts it, and it forms part of the Terms of Service. The acceptance date, the name of the person who accepted and this version number are recorded with the account.

1. Definitions

Capitalized terms not defined here have the meaning given in the HIPAA Rules (45 C.F.R. Parts 160 and 164), including Breach, Business Associate, Covered Entity, Designated Record Set, Electronic Protected Health Information, Individual, Minimum Necessary, Protected Health Information ("PHI"), Required by Law, Secretary, Security Incident, Subcontractor and Unsecured PHI. "HIPAA Rules" means the Privacy, Security, Breach Notification and Enforcement Rules, as amended by the HITECH Act. If the Covered Entity is itself a business associate of another covered entity, it acts here in that capacity and Business Associate acts as its subcontractor.

2. Obligations of Business Associate

Business Associate will:

  1. Not use or disclose PHI other than as permitted or required by this BAA or as Required by Law.
  2. Use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to Electronic PHI, to prevent use or disclosure of PHI other than as provided by this BAA.
  3. Report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including Breaches of Unsecured PHI as required by 45 C.F.R. 164.410, without unreasonable delay and in no case later than 30 calendar days after discovery, with the information Covered Entity needs to meet its own notification obligations. Unsuccessful Security Incidents — such as pings, port scans, blocked log-in attempts and denial-of-service attempts that do not result in unauthorized access — are hereby reported in the aggregate, and no further notice is required for them.
  4. Ensure, in accordance with 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2), that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate.
  5. Within 15 business days of a request, make PHI in a Designated Record Set available to Covered Entity so that it can meet its obligations under 45 C.F.R. 164.524, and make amendments as directed by Covered Entity under 164.526. Most of these functions are available to Covered Entity directly in the platform.
  6. Maintain and make available the information required for Covered Entity to provide an accounting of disclosures under 45 C.F.R. 164.528.
  7. To the extent it carries out Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in performing them.
  8. Make its internal practices, books and records relating to PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules.
  9. Request, use and disclose only the Minimum Necessary PHI.

3. Permitted uses and disclosures

  1. Business Associate may use and disclose PHI as necessary to provide the Clovai platform and related services to Covered Entity under the Terms of Service.
  2. Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, and may disclose it for those purposes if the disclosure is Required by Law, or if it obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
  3. Business Associate may provide data aggregation services relating to Covered Entity's health care operations only if Covered Entity requests them.
  4. Business Associate may de-identify PHI in accordance with 45 C.F.R. 164.514(a)–(c) and use de-identified information to operate and improve its services. De-identified information is not PHI.
  5. Business Associate will not sell PHI or use or disclose it for marketing, and will not use PHI to train AI models made available to other customers.

4. Obligations of Covered Entity

  1. Notify Business Associate of any limitation in its notice of privacy practices, any change in or revocation of an Individual's permission, and any restriction it agrees to under 45 C.F.R. 164.522, to the extent they affect Business Associate's use or disclosure of PHI.
  2. Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.
  3. Configure user access in the platform according to its workforce's roles and promptly remove access of users who no longer need it.

5. Term and termination

  1. This BAA remains in effect while Business Associate creates, receives, maintains or transmits PHI for Covered Entity, and ends when all PHI is returned or destroyed as provided below.
  2. If either party determines that the other has violated a material term of this BAA, it may give written notice and an opportunity to cure within 30 days; if the violation is not cured, it may terminate the BAA and the Terms of Service.
  3. On termination, Business Associate will make PHI available for export for 30 days and then return or destroy all PHI it maintains, retaining no copies. If return or destruction is infeasible — for example, data held in encrypted backups until they expire on their regular schedule — Business Associate will extend the protections of this BAA to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible.

6. Miscellaneous

  1. Amendment. The parties will amend this BAA as necessary to comply with changes to the HIPAA Rules. Business Associate may publish an updated version on this page, effective 30 days after notice to Covered Entity, if it is needed to comply with law or does not reduce the protections for PHI.
  2. Interpretation. Any ambiguity will be resolved in favor of a meaning that permits compliance with the HIPAA Rules. In case of conflict with the Terms of Service regarding PHI, this BAA controls.
  3. No third-party beneficiaries. Nothing in this BAA confers rights on any person other than the parties.
  4. Survival. Section 5(c) survives termination.
  5. Notices. Notices to Business Associate go to security@clovai.us; notices to Covered Entity go to the account administrator's email.
Clovai

The operating system for ambulatory care — built for how U.S. practices actually get paid.

Tagnara LLC
U.S. sales & support — remote-first, all 50 states

🌎 clovai.co — Colombia & LATAM
Platform
Scheduling™Care™Supply™Billing™Finance™People™Intelligence™Connect™Hospital™ Clovy™ AI
Company
Pricing Compliance & risk Security & HIPAA Interoperability Implementation Book a demo
Contact
hello@clovai.us sales@clovai.us +1 (555) 010-0142 app.clovai.us
© 2026 Tagnara LLC. All rights reserved. · Terms · Privacy · BAA CPT® is a registered trademark of the American Medical Association. All other marks belong to their respective owners.