AI clinical documentation SaaS — pay per report.
Version 2026-07-us-v2 · Last updated: July 2026
Draft — pending counsel review. Cleannote may replace this text with counsel-approved wording; you may be asked to re-accept a new version. Acceptance in the Cleannote application (clickwrap) is the intended binding method.
This Business Associate Agreement (“BAA”) is entered into between the healthcare provider or organization accepting it (the “Covered Entity” or “CE”) and Cleannote (the “Business Associate” or “BA”). This BAA becomes effective when an authorized individual accepts it in the Cleannote application by providing their name and confirming authority to bind CE (electronic / clickwrap acceptance). Cleannote records the agreement type, version, acceptance timestamp, IP address, user agent, signer name, and a cryptographic hash of the accepted text as evidence of assent.
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, the HITECH Act, and the implementing Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164), as amended. “PHI” means Protected Health Information as defined by HIPAA. “Electronic PHI” or “ePHI” means PHI transmitted or maintained in electronic media. “Breach” means the acquisition, access, use, or disclosure of Unsecured PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI, subject to HIPAA’s Breach Notification Rule exceptions and risk assessment. Terms not defined here have the meanings given in HIPAA.
BA provides clinical documentation services that may create, receive, maintain, or transmit PHI on CE’s behalf, including audio or text intake, transcription or drafting, report formatting, style learning from samples CE uploads, secure delivery of outputs, and related customer support (the “Services”). This BAA applies only to PHI handled in connection with the Services.
BA may use and disclose PHI solely as necessary to perform the Services, as required by law, or as otherwise expressly permitted by this BAA and HIPAA. BA will not sell PHI, will not use or disclose PHI for marketing, and will not use PHI for unrelated commercial analytics. BA will request, use, and disclose only the minimum PHI reasonably necessary to perform the applicable Service function, consistent with the minimum necessary standard.
BA will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, consistent with the HIPAA Security Rule. Without limiting that obligation, BA will: (a) encrypt finished clinical outputs at rest using AES-256-GCM (or equivalent or stronger encryption); (b) transmit PHI only over encrypted channels (HTTPS/TLS); (c) limit workforce access to PHI to personnel who need access to operate or support the Services; and (d) maintain policies and procedures designed to prevent unauthorized access, use, or disclosure of PHI. BA does not warrant that the Services are “HIPAA certified”; CE remains responsible for its own HIPAA compliance as a Covered Entity.
BA will notify CE without unreasonable delay, and in no case later than sixty (60) calendar days after discovery, of any Breach of Unsecured PHI attributable to BA or its agents, as required by 45 C.F.R. § 164.410 (or any successor). BA will also notify CE without unreasonable delay of Security Incidents of which BA becomes aware that involve PHI maintained for CE, to the extent required by the Security Rule. Notification will include, to the extent then known: a description of what happened; the types of PHI involved; steps individuals or CE should take; what BA is doing to investigate, mitigate harm, and prevent recurrence; and contact information for follow-up. BA will supplement the notice as additional information becomes available.
BA may engage subcontractors or subprocessors (including cloud infrastructure and artificial-intelligence service providers) that create, receive, maintain, or transmit PHI on BA’s behalf only if each such party agrees in writing to restrictions and safeguards that are no less protective of PHI than those in this BAA, as required by HIPAA. BA remains responsible to CE for the performance of those subcontractors with respect to PHI under this BAA.
BA will, within a reasonable time after CE’s documented written request, make available PHI in BA’s possession that is part of a Designated Record Set as reasonably necessary for CE to respond to an individual’s request for access or amendment under the Privacy Rule. BA will also provide information about disclosures of PHI by BA as reasonably needed for CE to respond to an accounting-of-disclosures request. CE remains responsible for responding to individuals; BA’s role is limited to reasonable assistance regarding PHI BA actually maintains.
Session audio and generated clinical reports are retained for a limited operational window (currently about six (6) days) and then deleted under Cleannote’s retention policy, except where longer retention is required by law, a documented legal hold, or CE’s documented written request for temporary workflow retention. Style samples, letterhead, and feedback that CE chooses to keep remain until CE removes them or the account is closed. Upon termination of the Services relationship, BA will return or destroy PHI as required by HIPAA, except for (a) PHI still within the operational retention window pending deletion, (b) materials CE elects to retain in the account, and (c) copies required by law or legal hold. If return or destruction of particular PHI is infeasible, BA will continue to protect that PHI under this BAA and limit further uses and disclosures to those that make return or destruction infeasible.
This BAA is effective upon CE’s clickwrap acceptance in the Cleannote application and continues for so long as BA provides Services involving PHI for CE. Either party may terminate this BAA for material breach if the breach is not cured within thirty (30) days after written notice describing the breach (or sooner if required by law). CE may also terminate as permitted under HIPAA if BA has violated a material term. Provisions that by their nature should survive (including confidentiality, breach notification, and post-termination protections for retained PHI) survive termination.
BA will comply with applicable requirements of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule that apply to business associates, and with the HITECH Act as applicable. If HIPAA or related regulations change in a way that requires amendment of this BAA, Cleannote may publish an updated version; continued use of paid Services after notice may require CE to accept the updated version in the application. Other amendments must be reflected in a new versioned text accepted through the same clickwrap process (or another writing signed by both parties).
This BAA, together with Cleannote’s applicable terms of service for the medical product, constitutes the parties’ agreement regarding BA’s handling of PHI for the Services and supersedes prior informal discussions on that subject. If there is a conflict between this BAA and those terms regarding PHI, this BAA controls. Nothing in this BAA creates a partnership, joint venture, or employment relationship. If any provision is held unenforceable, the remainder remains in effect. This BAA does not constitute legal advice to CE; CE is responsible for determining whether the Services and this BAA meet CE’s HIPAA and professional compliance obligations.
Document type: BAA · Region: US · Review & accept in your account