Business Associate Agreement (BAA)
Last updated: August 20, 2026
MedicalAgentOS enters into a Business Associate Agreement with every customer whose use of the Service involves protected health information (PHI). This page summarizes the standard terms; the executed BAA for your organization is available in the Trust Center.
Summary of standard terms
- Permitted uses: we use and disclose PHI only to provide the Service, as permitted by the BAA, or as required by law.
- Safeguards: we implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule.
- Minimum necessary: agent skills access only the PHI required for the task, enforced by per-skill permissions.
- Subcontractors: subprocessors that handle PHI are bound by written agreements at least as protective; the current list is published in the Trust Center.
- Individual rights: we support the practice in responding to access, amendment, and accounting-of-disclosures requests.
- Breach notification: we notify the practice of any breach of unsecured PHI without unreasonable delay, and no later than the period specified in the BAA.
- Termination: upon termination, PHI is returned or destroyed where feasible; where not feasible, protections continue to apply.
Requesting a BAA
A BAA is included in every paid plan and is presented for e-signature during onboarding. Enterprise customers with their own BAA templates can contact legal@medicalagentos.com.