1. Parties and purpose
This Business Associate Agreement ("BAA") supplements the Terms of Service between you ("Covered Entity") and WeHearYou ("Business Associate"). It applies where your use of the service involves Protected Health Information as defined at 45 CFR 160.103.
It is required by the HIPAA Privacy and Security Rules and is intended to satisfy 45 CFR 164.504(e). Terms not defined here carry the meaning given in those rules.
2. What is treated as protected health information here
In this service, the following are treated as PHI when you are a covered entity, because each identifies an individual and relates to their receipt of health care from you:
- Contact records — name, email address, telephone number — since their presence in your account indicates the individual is your patient.
- Private feedback submitted by a patient, including any description of their care or treatment.
- Review content authored by a patient where it relates to services you provided.
- Video testimonials recorded by patients, which contain image and voice as well as any spoken content.
- Resolution case records, and communications logged against them.
3. Permitted uses and disclosures
Business Associate may use and disclose PHI only to perform the services described in the Terms of Service, as required by law, or as permitted by this BAA.
Specifically, Business Associate may:
- Transmit review requests to individuals you identify, by the channels you select.
- Store, organise and display PHI within your account for your authorised users.
- Disclose PHI to the subprocessors listed in the accompanying schedule, each bound by written terms no less protective than this BAA.
- Use PHI for its own proper management and administration, and to carry out its legal responsibilities, as permitted by 45 CFR 164.504(e)(4).
- De-identify PHI in accordance with 45 CFR 164.514(b), after which the de-identified data is not PHI.
4. Prohibited uses and disclosures
Business Associate will not:
- Use or disclose PHI other than as this BAA permits or as required by law.
- Sell PHI, or use or disclose it for marketing purposes, except as expressly permitted by you and by law.
- Use PHI, including review text and private feedback, to train machine learning models, whether our own or a third party's.
- Use PHI for any purpose that Covered Entity itself would not be permitted to pursue under the Privacy Rule.
5. Safeguards
Business Associate will implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of electronic PHI, and will comply with the Security Rule at 45 CFR Part 164 Subpart C with respect to that information.
Current technical measures include the following. They are stated so you can assess them, and may change as the service develops provided protection is not reduced:
- Encryption in transit for all connections to the service and to every subprocessor.
- Encryption at rest for the hosted database, and application-level encryption of third-party access tokens.
- Access to each organisation's data restricted to that organisation's authorised users, enforced in the application.
- An audit record of authentication events and actions taken within an account, retained and available to Covered Entity on request.
- Rate limiting on authentication and on publicly reachable endpoints.
6. Workforce and subcontractors
Business Associate will ensure that any agent or subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this BAA, as required by 45 CFR 164.502(e)(1)(ii).
Business Associate will limit PHI access to workforce members who require it, and will terminate that access promptly when it is no longer required.
7. Reporting breaches and security incidents
Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this BAA, any security incident affecting electronic PHI, and any breach of unsecured PHI, without unreasonable delay and in no case later than ten (10) business days after discovery.
The report will describe what happened, the individuals and categories of PHI involved so far as known, what has been done to mitigate and investigate, and what will be done to prevent recurrence.
Covered Entity is responsible for determining whether an incident requires notification to individuals, to the Secretary of Health and Human Services, or to the media, and for making those notifications. Business Associate will provide the information reasonably needed to do so.
Unsuccessful attempts that do not compromise PHI — blocked scans, failed sign-ins, denied access attempts — are reported in aggregate on request rather than individually.
8. Individual rights
Business Associate will assist Covered Entity in meeting its obligations to individuals:
- Access — make PHI in a designated record set available to Covered Entity so it can respond to a request under 45 CFR 164.524, within ten (10) business days of request.
- Amendment — make PHI available for amendment, and incorporate amendments Covered Entity directs, as required by 45 CFR 164.526.
- Accounting of disclosures — document disclosures and provide the information Covered Entity needs to respond to a request under 45 CFR 164.528.
- Restriction and confidential communication — comply with any restriction Covered Entity has agreed to and communicated to Business Associate.
9. Availability to the Secretary
Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining Covered Entity's compliance with the Privacy Rule.
10. Covered Entity's obligations
Covered Entity will:
- Obtain any consent or authorisation required before adding an individual's information to the service, including consent to contact them by the channels selected.
- Notify Business Associate of any limitation in its notice of privacy practices, any change to or revocation of an individual's permission, and any restriction it has agreed to, where these affect Business Associate's use or disclosure of PHI.
- Not request Business Associate to use or disclose PHI in a way that would breach the Privacy Rule if done by Covered Entity itself.
- Configure the service, including retention and access settings, consistently with its own obligations — Business Associate cannot determine what is minimum necessary for Covered Entity's purposes.
11. Term and termination
This BAA takes effect on acceptance and continues until all PHI is returned or destroyed, or protections are extended under section 12.
Covered Entity may terminate this BAA and the Terms of Service if Business Associate materially breaches this BAA and fails to cure within thirty (30) days of written notice, or immediately where cure is not possible.
12. Return or destruction of PHI
On termination, Business Associate will return or destroy all PHI it maintains on Covered Entity's behalf, and will retain no copies, within ninety (90) days, subject to the export period in the Terms of Service.
Where return or destruction is not feasible — for example where PHI persists in routine backups until those expire — Business Associate will extend the protections of this BAA to that information and limit further use or disclosure to the purposes that make return or destruction infeasible, for as long as it is retained.
13. Interpretation
Any ambiguity in this BAA will be resolved to permit compliance with HIPAA. Where this BAA and the Terms of Service conflict in relation to PHI, this BAA governs.
Amendments required to keep the parties compliant with changes to HIPAA will be negotiated in good faith.
Questions, and requests made under sections 8 and 9: privacy@wehearyou.app.
Schedule — subprocessors
Third parties that receive customer or patient data in the normal operation of the service.
| Subprocessor | Purpose | Data received |
|---|---|---|
| Neon | Primary database hosting (US-East-1) | All stored customer and patient records |
| Vercel | Application hosting and file storage | All request traffic; uploaded logos, images and recorded video testimonials |
| Resend | Transactional email delivery | Patient name and email address, message content |
| Twilio | SMS delivery | Patient name and mobile number, message content |
| Google (Business Profile API) | Review synchronisation and reply publishing | Public review content, reply text, business identifiers |
| Google (Gemini API) | Review summaries, suggested replies, feedback rewriting | Review text and private feedback text submitted for processing |
| Meta | Facebook page rating synchronisation | Public recommendation content |
| Stripe | Subscription billing | Billing contact and payment details only — no patient data |