Effective Date: February 20, 2026
This Business Associate Agreement ("BAA") is entered into by and between you, the healthcare provider or covered entity ("Covered Entity"), and Somatopia, LLC, doing business as Practice Harbor ("Business Associate"), and supplements the Terms of Service Agreement between the parties.
By creating an account with Practice Harbor, Covered Entity agrees to the terms of this BAA. This BAA shall remain in effect for the duration of the Covered Entity's use of the Services.
Capitalized terms used but not otherwise defined in this BAA shall have the meanings assigned to them in the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (collectively, "HIPAA"), and their implementing regulations, including the Privacy Rule (45 C.F.R. Part 160 and Part 164, Subparts A and E), the Security Rule (45 C.F.R. Part 160 and Part 164, Subparts A and C), and the Breach Notification Rule (45 C.F.R. Part 164, Subpart D).
"Protected Health Information" or "PHI" means any information, whether oral or recorded in any form or medium, that (a) relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual; (b) identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual; and (c) is created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
"Electronic Protected Health Information" or "ePHI" means PHI that is transmitted by or maintained in electronic media.
"Services" means the AI-powered clinical documentation platform and related features provided by Practice Harbor, as described in the Terms of Service.
Business Associate shall not use or disclose PHI other than as permitted or required by this BAA, the Terms of Service, or as required by law. Business Associate shall use and disclose PHI only to provide the Services to Covered Entity, as described in the Terms of Service, and as permitted under this BAA.
Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to prevent the use or disclosure of PHI other than as provided for by this BAA. Business Associate shall comply with the requirements of the Security Rule (45 C.F.R. Part 164, Subparts A and C) with respect to ePHI, including:
(a) Encrypting all ePHI in transit and at rest using industry-standard encryption protocols;
(b) Implementing access controls to limit access to ePHI to authorized personnel;
(c) Maintaining audit logs of access to and modifications of ePHI;
(d) Conducting regular risk assessments and security audits; and
(e) Maintaining a comprehensive information security program.
Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including any Security Incident or Breach of Unsecured PHI, using the following two-tier notification process:
(a) Preliminary Notification (72 hours). Business Associate shall provide initial written notice to Covered Entity within seventy-two (72) hours of discovering a suspected Breach or unauthorized use or disclosure of PHI. This preliminary notice shall include, to the extent known at the time: a brief description of the incident, the approximate date of occurrence, and an assessment of the scope and severity of the potential Breach.
(b) Detailed Notification (30 days). Business Associate shall provide a comprehensive written report to Covered Entity without unreasonable delay, and in no event later than thirty (30) calendar days after discovery. Such report shall include, to the extent available: (i) the nature of the Breach or unauthorized use or disclosure, including the types of PHI involved; (ii) the individuals whose PHI was or is believed to have been involved; (iii) the date of the Breach or unauthorized use or disclosure and the date of discovery; (iv) a description of what Business Associate is doing to investigate the Breach, mitigate harm, and prevent further occurrences; and (v) any other information reasonably requested by Covered Entity.
Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to the same restrictions, conditions, and requirements that apply to Business Associate under this BAA with respect to such PHI. Business Associate shall remain responsible for the acts and omissions of its subcontractors.
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make PHI available to Covered Entity within fifteen (15) business days of a request, in a form and format reasonably requested by Covered Entity, to enable Covered Entity to fulfill its obligations under 45 C.F.R. § 164.524. Business Associate shall also provide Covered Entity with the ability to export all PHI associated with Covered Entity's account at any time through the Services.
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make PHI available for amendment within fifteen (15) business days of a request from Covered Entity, and shall incorporate any amendments to PHI as directed by Covered Entity, in accordance with 45 C.F.R. § 164.526.
Business Associate shall maintain an accounting of disclosures of PHI made by Business Associate as required under 45 C.F.R. § 164.528 and shall make such accounting available to Covered Entity within thirty (30) days of a request.
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
Business Associate shall limit its use, disclosure, and request of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.502(b) and the minimum necessary policies and procedures of the Privacy Rule.
Covered Entity shall: (a) obtain any consent or authorization that may be required under applicable law prior to furnishing PHI to Business Associate; (b) notify Business Associate promptly of any restrictions on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent that such restrictions may affect Business Associate's use or disclosure of PHI; (c) notify Business Associate promptly of any changes in, or revocation of, the permission by an individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI; and (d) not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
Business Associate may use and disclose PHI as necessary to perform the Services described in the Terms of Service, provided that such use or disclosure would not violate HIPAA if done by Covered Entity.
Business Associate may use PHI for the proper management and administration of its business or to carry out its legal responsibilities, provided that the disclosures are required by law or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and be used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c). De-identified information is not subject to the terms of this BAA. Business Associate may use de-identified data for service analytics and aggregate reporting, provided that Business Associate shall not attempt to re-identify any de-identified information and shall not use de-identified data to train, fine-tune, or otherwise develop any artificial intelligence or machine learning models.
Covered Entity acknowledges that the Services use artificial intelligence and machine learning to process PHI for the purpose of generating clinical documentation. Business Associate shall ensure that all AI processing of PHI complies with the requirements of this BAA and HIPAA.
Business Associate shall not use Protected Health Information, or any data derived therefrom (including but not limited to embeddings, vector representations, statistical summaries, or model weights), to train, develop, improve, fine-tune, or otherwise enhance any machine learning model, artificial intelligence system, algorithm, or similar technology, whether for the benefit of Covered Entity, Business Associate, or any third party. The only permitted AI interaction with PHI is transient processing (inference) for the purpose of delivering the Services. This prohibition applies regardless of whether the data has been pseudonymized, aggregated, de-identified, or otherwise transformed.
To the extent Business Associate uses third-party artificial intelligence services (including cloud-hosted large language models, speech-to-text services, or other AI inference APIs) to process PHI on behalf of Covered Entity, Business Associate shall: (a) maintain a current list of all AI subprocessors that handle PHI, which shall be made available to Covered Entity upon request; (b) ensure that each AI subprocessor has executed a Business Associate Agreement or equivalent data processing agreement that includes protections no less restrictive than those set forth in this BAA; (c) ensure that no AI subprocessor uses PHI for model training or product improvement purposes; (d) notify Covered Entity of any material changes to its AI subprocessors within thirty (30) days; and (e) ensure that all PHI transmitted to AI subprocessors is encrypted in transit and that no PHI is persisted by the subprocessor beyond the duration of the processing request, and is deleted immediately upon completion.
Business Associate shall apply the minimum necessary standard to all AI processing of PHI, limiting the data elements provided to AI systems to those strictly necessary for the intended purpose. Audio recordings, transcriptions, and other transient data processed by AI systems shall be deleted immediately upon completion of processing. We do not store recordings. Business Associate shall document its data retention practices for AI-processed PHI and make such documentation available to Covered Entity upon request.
Business Associate shall provide Covered Entity with sufficient information about how AI systems process PHI to enable Covered Entity to fulfill its obligations under HIPAA, including updating its Notice of Privacy Practices and responding to patient inquiries about AI processing. Business Associate shall make available, upon request, a description of the categories of PHI processed by AI systems, the purposes of such processing, and the safeguards in place to protect PHI during AI processing.
This BAA shall become effective on the date Covered Entity creates an account with Practice Harbor and shall remain in effect until the earlier of: (a) termination of the Terms of Service; or (b) termination of this BAA as provided herein.
Either party may terminate this BAA if the other party materially breaches any provision of this BAA and fails to cure such breach within thirty (30) days after receiving written notice of the breach. If cure is not feasible, the non-breaching party may terminate this BAA immediately upon written notice.
Upon termination of this BAA, Business Associate shall delete all PHI received from Covered Entity or created or received by Business Associate on behalf of Covered Entity within sixty (60) days, except where retention is required by law (e.g., tax records) or necessary to resolve an active billing dispute. Business Associate will confirm deletion upon request. Covered Entity may export all PHI through the Services at any time prior to termination.
In the event of a Breach of Unsecured PHI, Business Associate shall notify Covered Entity using the two-tier process described in Section 2.3: preliminary notification within seventy-two (72) hours of discovery and a comprehensive report within thirty (30) calendar days. Business Associate shall cooperate with Covered Entity in investigating the Breach and in meeting Covered Entity's obligations under the Breach Notification Rule (45 C.F.R. §§ 164.400–414).
Business Associate shall bear the reasonable costs of notification to affected individuals if the Breach is directly caused by the material acts or omissions of Business Associate, provided that such costs shall be subject to the limitation of liability set forth in Section 7.3.
Each party (the "Indemnifying Party") shall indemnify, defend, and hold harmless the other party and its officers, directors, employees, and agents (the "Indemnified Party") from and against any third-party claims, losses, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) directly resulting from the Indemnifying Party's material breach of this BAA or willful violation of HIPAA, but only to the extent such claims are proximately caused by the Indemnifying Party's acts or omissions.
The Indemnified Party shall: (a) provide the Indemnifying Party with prompt written notice of any claim for which indemnification is sought (provided that failure to give prompt notice shall not relieve the Indemnifying Party of its obligations except to the extent it is materially prejudiced by such failure); (b) grant the Indemnifying Party sole control over the defense and settlement of the claim, provided that the Indemnifying Party shall not settle any claim that imposes any obligation on the Indemnified Party without the Indemnified Party's prior written consent; and (c) provide reasonable cooperation in the defense of the claim at the Indemnifying Party's expense.
Except for a party's obligations under Section 7.1 (Indemnification) and except in cases of gross negligence or willful misconduct, each party's total aggregate liability under this BAA shall not exceed the greater of: (a) the total fees paid or payable by Covered Entity to Business Associate during the twelve (12) months immediately preceding the event giving rise to the claim; or (b) fifty thousand dollars ($50,000). For claims arising specifically from a Breach of Unsecured PHI, each party's total aggregate liability shall not exceed the greater of: (i) the total fees paid or payable during the twenty-four (24) months immediately preceding the event giving rise to the claim; or (ii) one hundred thousand dollars ($100,000).
Except for a party's indemnification obligations under Section 7.1, neither party shall be liable to the other party for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, loss of revenue, loss of business opportunities, or reputational harm, regardless of whether such damages are based on contract, tort (including negligence), strict liability, or any other theory, even if the party has been advised of the possibility of such damages. For the avoidance of doubt, indemnification obligations under Section 7.1 shall be deemed direct damages and shall not be subject to this exclusion.
Any reference in this BAA to a section of HIPAA or its implementing regulations means the section as in effect or as amended. This BAA shall be interpreted consistently with HIPAA and its implementing regulations, as amended from time to time.
The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for compliance with HIPAA and its implementing regulations. Business Associate may update this BAA by posting a revised version on its website and providing notice to Covered Entity via email or through the Services.
The obligations of Business Associate under Sections 2, 4.5, 5.3, 6, and 7 of this BAA shall survive the termination of this BAA.
Any ambiguity in this BAA shall be interpreted to permit compliance with HIPAA. In the event of a conflict between this BAA and the Terms of Service, this BAA shall control with respect to the protection of PHI.
This BAA shall be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of laws provisions, except to the extent preempted by federal law, including HIPAA.
All notices under this BAA shall be in writing and sent to the email address associated with the applicable party's account or, in the case of Business Associate, to privacy@progressnotes.app.
If you have questions about this Business Associate Agreement, please contact us at:
Somatopia, LLC d/b/a Practice Harbor
Email: privacy@progressnotes.app
By creating an account with Practice Harbor, you acknowledge that you have read, understood, and agree to be bound by this Business Associate Agreement.