M ManySignal

Legal · ManySignal

Business Associate Agreement

Download PDF
Effective: Jul 01, 2026 Last updated: Aug 09, 2026 Version: 2026-Q3

Healthcare organisations and their business associates may require ManySignal to execute a HIPAA Business Associate Agreement before transmitting Protected Health Information through the platform. This BAA is our standard form. Enterprise customers requiring a countersigned original should contact their account team.

01

Purpose and applicability

This Business Associate Agreement ("BAA") is entered into by and between the Customer identified on the applicable ManySignal order form ("Covered Entity" or "Business Associate," as applicable) and ManySignal, Inc. ("Business Associate"). This BAA is effective as of the date Customer executes the applicable order form or accepts the Terms of Service, whichever is earlier.

This BAA is entered into in connection with the services ManySignal provides under the Terms of Service or applicable Master Services Agreement ("Services Agreement"), to the extent those services involve the creation, receipt, maintenance, or transmission of Protected Health Information ("PHI") on behalf of the Covered Entity.

This BAA is intended to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and the regulations promulgated thereunder, codified at 45 C.F.R. Parts 160 and 164 (the "HIPAA Rules").

02

Definitions

Capitalized terms used but not defined in this BAA have the meanings given to them in the HIPAA Rules. Key terms include: "Protected Health Information" (PHI) means individually identifiable health information as defined at 45 C.F.R. § 160.103, limited to PHI that ManySignal creates, receives, maintains, or transmits on behalf of the Covered Entity in connection with the Services. "Electronic Protected Health Information" (ePHI) means PHI that is transmitted by electronic media or maintained in electronic media as defined at 45 C.F.R. § 160.103.

"Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of the PHI as defined at 45 C.F.R. § 164.402. "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of ePHI or interference with system operations in an information system as defined at 45 C.F.R. § 164.304.

03

Permitted uses and disclosures

ManySignal may use or disclose PHI only as necessary to provide the Services described in the Services Agreement, or as required by law. Specifically, ManySignal may: (a) use PHI to perform functions, activities, or services for, or on behalf of, the Covered Entity as specified in the Services Agreement; (b) use PHI for the proper management and administration of ManySignal's operations or to carry out its legal responsibilities; (c) use PHI to provide data aggregation services to the Covered Entity as permitted under 45 C.F.R. § 164.504(e)(2)(i)(B); and (d) disclose PHI as required by law, provided that ManySignal shall notify the Covered Entity of any such requirement in advance unless prohibited by applicable law.

ManySignal shall not use or disclose PHI for marketing purposes without written authorisation from the Covered Entity. ManySignal shall not sell PHI or use it to train external machine-learning models.

04

Obligations of ManySignal as Business Associate

ManySignal agrees to: (a) not use or disclose PHI other than as permitted or required by this BAA or as required by law; (b) implement and maintain appropriate administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of the Covered Entity, in accordance with 45 C.F.R. Part 164, Subpart C (the "Security Rule"); (c) ensure that any agent or subcontractor that creates, receives, maintains, or transmits ePHI on behalf of ManySignal agrees in writing to the same conditions that apply to ManySignal with respect to such information; and (d) make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services ("HHS") for purposes of determining compliance with the HIPAA Rules.

ManySignal will not intimidate, threaten, coerce, discriminate against, or take any other retaliatory action against any individual for exercising their rights under the HIPAA Rules.

05

Safeguards and security program

ManySignal maintains a comprehensive information security program that includes physical, administrative, and technical safeguards aligned with the HIPAA Security Rule. This program includes: encryption of ePHI at rest (AES-256) and in transit (TLS 1.2 or higher); access control with role-based permissions and multi-factor authentication for all personnel with access to systems containing ePHI; audit logging of all access to and operations performed on ePHI, with logs retained for a minimum of six years; periodic risk analysis and risk management processes in accordance with 45 C.F.R. § 164.308(a)(1); and workforce training on HIPAA obligations at least annually.

ManySignal undergoes independent third-party audits, including SOC 2 Type II examination against the Security and Availability Trust Services Criteria. Reports are available to Covered Entities upon request under a confidentiality agreement.

06

Breach notification

ManySignal will notify the Covered Entity of any Breach of Unsecured PHI, as defined under HIPAA, without unreasonable delay and in no case later than 60 calendar days after ManySignal discovers the Breach. ManySignal will be deemed to have discovered a Breach as of the first day on which such Breach is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing the Breach) who is an employee, officer, or other agent of ManySignal.

The notification will include, to the extent possible and available at the time: (a) the identification of each individual whose PHI was or is reasonably believed to have been accessed, acquired, used, or disclosed; (b) a description of the Breach, including the date of the Breach and the date of discovery; (c) a description of the types of PHI involved; (d) the steps individuals should take to protect themselves; (e) the steps ManySignal has taken or will take to investigate and mitigate the Breach; and (f) contact information for ManySignal's privacy officer.

ManySignal will cooperate with the Covered Entity's breach-notification obligations under 45 C.F.R. §§ 164.404–164.414, including providing any additional information reasonably requested by the Covered Entity in connection with such notifications. Notification to ManySignal shall be provided to [email protected].

07

Individual rights access and amendment

To the extent ManySignal maintains a Designated Record Set on behalf of the Covered Entity, ManySignal will: (a) provide access to PHI in a Designated Record Set to the Covered Entity or, as directed by the Covered Entity, to an individual who is the subject of the PHI, within 15 business days of a request, in the form and format requested by the Covered Entity if it is readily producible in such form; and (b) make amendments to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 C.F.R. § 164.526.

"Designated Record Set" has the meaning given to it at 45 C.F.R. § 164.501. ManySignal does not expect to maintain a Designated Record Set in connection with the Services as described in the Services Agreement; however, if circumstances change, ManySignal will notify the Covered Entity and these provisions will apply.

08

Audit rights

Upon reasonable notice and no more than once per calendar year (unless a Breach requires more frequent review), ManySignal will permit the Covered Entity or its designated auditor to inspect ManySignal's facilities, systems, books, and records relating to PHI to verify ManySignal's compliance with this BAA. ManySignal may satisfy audit requests by making available its then-current SOC 2 Type II report covering the period in question.

ManySignal will cooperate with any investigation or inquiry by HHS relating to the Covered Entity's HIPAA compliance that involves ManySignal's services or systems.

09

Term and termination

This BAA is effective as of the date of execution and will terminate automatically upon expiration or termination of the Services Agreement. Upon termination, ManySignal will, at the Covered Entity's election: (a) return all PHI to the Covered Entity; or (b) destroy all PHI that ManySignal maintains in any form, including copies held in backup systems, within 60 days of termination, and certify in writing that it has done so. If return or destruction is not feasible, ManySignal will continue to protect the PHI and limit its use and disclosure to the purposes that make return or destruction infeasible.

Either party may terminate this BAA immediately upon written notice if the other party is in material breach of any provision of this BAA and does not cure such breach within 30 days after written notice. In the event of termination for breach, ManySignal will return or destroy PHI as described above.

10

Miscellaneous

This BAA shall be governed by and construed in accordance with the laws of the State of Delaware and HIPAA federal law. In the event of any conflict between this BAA and the Services Agreement with respect to the subject matter of this BAA, this BAA shall govern.

This BAA constitutes the entire agreement between the parties with respect to PHI and supersedes all prior agreements, representations, and understandings relating to the same subject matter. This BAA may be amended only by a written instrument signed by both parties. For questions about this BAA or to request a countersigned copy, contact [email protected].

Questions about this document?

Contact our legal team at [email protected]. For security disclosure, use [email protected].