Business Associate Agreement

Sign a BAA with ScribeGo.ai

Before ScribeGo.ai processes any Protected Health Information on behalf of your organization, we require an executed Business Associate Agreement, the legally binding contract defining how we protect the PHI you entrust to us.

Download our BAA template

PDF format. Review with your legal or compliance team. Based on the HHS sample BAA with ScribeGo-specific provisions.

ScribeGo.ai BAA (PDF)

What the BAA covers

Our BAA contains the provisions required by 45 CFR § 164.504(e) and 45 CFR § 164.314(a), written in a form suitable for most healthcare providers. The key commitments:

Permitted uses & disclosures

We only use PHI as needed to provide our service, as required by law, or as the BAA allows.

Security safeguards

We comply with the HIPAA Security Rule (45 CFR Part 164, Subpart C) for all ePHI we handle.

Minimum necessary

We only request and use the minimum PHI necessary to do our job.

Reporting obligations

We report Security Incidents and Breaches without unreasonable delay; our internal target is 72 hours.

Subcontractor controls

Any subcontractor we use (today, only AWS) is bound by an equivalent BAA.

No training on your data

We explicitly warrant we do not use your PHI to train or fine-tune any AI model.

Individual rights

We support your patients’ HIPAA rights (access, amendment, accounting) via you.

HHS cooperation

We make our books and records available to the Secretary of HHS upon request.

Return or destruction

Upon termination, we return or destroy all PHI. If infeasible, we extend BAA protections indefinitely.

Next steps

  1. 1

    Download and review. Your legal or compliance team reviews the template above.

  2. 2

    Redline (optional). We'll consider reasonable negotiated edits. Alternatively, if your organization maintains its own BAA template, we're happy to review and execute yours instead.

  3. 3

    Counter-sign. Your authorized signatory signs on page 6; you email us a signed copy at hello@scribego.ai.

  4. 4

    We counter-sign and send back. Our Security Officer executes within 2 business days. You'll receive a fully-executed copy.

  5. 5

    Begin using ScribeGo.ai with PHI. The BAA is effective as of the last-signed date and governs all PHI processing thereafter.

Disclosure: pending legal review

This BAA template is a draft pending review by ScribeGo.ai's counsel before first execution. If you are considering using ScribeGo.ai in production for patient data, please contact us at hello@scribego.ai and we will coordinate the attorney-reviewed final version through your legal team.

Security & HIPAA overview·Privacy notice·hello@scribego.ai