← Legal hub

Legal · HIPAA

Business Associate Agreement

Template BAA for customers operating as HIPAA Covered Entities or upstream Business Associates. This page describes the document; email contact@skdaddle.com to receive an executable signed version.

Effective June 9, 2026. This page describes the document. To request an executable signed version for your organization, email contact@skdaddle.com. Questions: contact@skdaddle.com.

Not currently offered.

ClearReport does not presently execute Business Associate Agreements and does not hold itself out as a HIPAA Business Associate. California RCFEs are generally not Covered Entities, so for most of our customers a BAA is not required. Several of our subprocessors have not executed BAAs with us, so we cannot pass HIPAA obligations upstream — signing one today would be a commitment we could not honour. The document below is retained as a statement of the terms we would expect to operate under if and when we pursue HIPAA readiness.

If you are a Covered Entity — for example you also operate a skilled-nursing facility — please contact contact@skdaddle.com before purchasing so we can tell you honestly whether ClearReport is appropriate for your compliance obligations.

Background

California Residential Care Facilities for the Elderly (RCFEs) are typically not HIPAA Covered Entities. Skilled Nursing Facilities (SNFs) and many adjacent businesses are. A Business Associate Agreement (BAA) would be relevant only to customers who, in whole or in part, operate as a HIPAA Covered Entity or as a Business Associate of a Covered Entity, and who require ClearReport to sign as their Business Associate.

The summary below describes the material terms we would expect such an agreement to carry. It is provided for evaluation only and is not an offer to enter into a BAA.

1. Definitions

Terms used but not defined have the meanings given in the HIPAA Rules (45 C.F.R. Parts 160 and 164), including Covered Entity, Business Associate, Protected Health Information (“PHI”), Electronic Protected Health Information (“ePHI”), Designated Record Set, and Security Incident.

2. Permitted uses and disclosures

ClearReport may use or disclose PHI only as necessary to perform the services described in the Terms of Service, and only as permitted by this BAA and the HIPAA Rules. Specifically, ClearReport may:

  • Store and process PHI to operate the ClearReport service;
  • Use de-identified PHI for product improvement, where de-identification meets the safe-harbor method under 45 C.F.R. § 164.514(b)(2);
  • Disclose PHI to Subprocessors that have signed equivalent BAA terms;
  • Use PHI for the proper management and administration of ClearReport, including legal responsibilities and providing data-aggregation services where authorized.

ClearReport will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Covered Entity. ClearReport will not sell PHI.

3. Safeguards

ClearReport will implement administrative, physical, and technical safeguards meeting the requirements of the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), including:

  • Encryption of ePHI in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls scoped by role and organization
  • Audit controls capturing every meaningful access and mutation
  • Integrity controls and authentication of users
  • Workforce training and sanction policies
  • A documented contingency plan and disaster-recovery procedure

4. Subcontractors

ClearReport will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to the same restrictions, conditions, and requirements as apply to ClearReport under this BAA. The current list of Subcontractors that may Process PHI is published at /legal/subprocessors.

As of the effective date, Anthropic has a BAA available for HIPAA customers using the Claude API. Voyage AI (used for vector embeddings) does not yet have a BAA with us; for that reason, embeddings of incident narrative text (the similar-incident-search feature) are disabled platform-wide. Only administrator-entered reporting-standards text is embedded. Narrative embeddings will not be enabled until an appropriate agreement is in place.

5. Reporting and breach notification

ClearReport will report to Customer:

  • Any use or disclosure of PHI not permitted by this BAA, of which it becomes aware, without unreasonable delay and in no case later than 30 days from discovery;
  • Any Security Incident as defined by 45 C.F.R. § 164.304, on a periodic basis if of minimal concern, or promptly if material;
  • Any Breach of Unsecured PHI without unreasonable delay and in no case later than 30 days from discovery, in accordance with 45 C.F.R. § 164.410. The breach notification will include the information specified in 45 C.F.R. § 164.410(c).

ClearReport will assist the Customer in fulfilling any obligation the Customer has under 45 C.F.R. § 164.404 to notify affected individuals or relevant authorities.

6. Access, amendment, and accounting

  • Access: at the Customer's written request, ClearReport will, within 30 days, provide access to PHI in a Designated Record Set, as required by 45 C.F.R. § 164.524.
  • Amendment: ClearReport will incorporate any amendments the Customer directs, in accordance with 45 C.F.R. § 164.526.
  • Accounting: ClearReport will document and make available such disclosures of PHI as required to permit the Customer to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528.

7. Compliance with Privacy Rule provisions

To the extent ClearReport carries out an obligation of the Customer under the HIPAA Privacy Rule, ClearReport will comply with the requirements of that Rule that apply to the Customer in the performance of that obligation.

8. HHS access

ClearReport will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by ClearReport on behalf of, the Customer available to the Secretary of Health and Human Services for purposes of determining the Customer's compliance with HIPAA.

9. Termination

The Customer may terminate this BAA and the underlying Terms of Service if it determines that ClearReport has materially breached a term of this BAA and has not cured the breach within 30 days of written notice. Upon termination, ClearReport will return or destroy all PHI received from, or created or received by ClearReport on behalf of, the Customer, retaining no copies, except to the extent such return or destruction is not feasible. Where infeasible (e.g. archived backups), ClearReport will extend the protections of this BAA to such PHI and limit further use to those purposes that make return or destruction infeasible, until such PHI is deleted.

10. Effect on the underlying Terms

This BAA forms part of the Terms of Service between the parties and supplements them solely with respect to the handling of PHI. In the event of any conflict between this BAA and the Terms of Service, the terms of this BAA control with respect to the Processing of PHI.

How to sign

Email contact@skdaddle.com with your organization's legal name, the name and email of the person who will sign, and any specific BAA requirements your compliance team has identified. We will return a counter-signature- ready BAA within two business days.