HIPAA Business Associate Agreement (BAA)
Standard Enterprise Support Exhibit · Version 2.1 · Effective Date: September 2026
Notice to Healthcare Information Security & Legal Teams:
This Business Associate Agreement ("BAA") governs software maintenance, enterprise support, and deployment services provided by Taleshape OÜ for the self-hosted Shaper analytics platform.
Because Shaper is deployed directly within your own cloud VPC or on-premise infrastructure, Taleshape operates under an architecture of non-access (zero direct access to production databases or patient records). This agreement formalizes safeguards, mutual covenants against transmitting PHI, and incident notification procedures in the unlikely event of incidental disclosure.
This Business Associate Agreement ("Agreement" or "BAA") is entered into by and between the customer identified in the applicable order form, enterprise support agreement, or statement of work ("Covered Entity" or "Customer") and Taleshape OÜ, a company incorporated in Estonia with commercial registry number 16962132, having its registered address at Sepapaja tn 6, 15551 Tallinn, Estonia ("Business Associate" or "Taleshape").
Covered Entity and Business Associate may collectively be referred to as the "Parties" or individually as a "Party".
Recitals
- Covered Entity and Business Associate have entered into an agreement pursuant to which Business Associate provides enterprise software support, priority feature engineering, and deployment guidance ("Underlying Agreement") relating to the open-source Shaper analytics platform.
- Covered Entity is a "covered entity" or "business associate" subject to the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and the regulations promulgated thereunder at 45 CFR Parts 160 and 164 (collectively, "HIPAA").
- The Parties acknowledge and agree that the Shaper software executes exclusively within infrastructure owned, provisioned, and managed by Covered Entity. Business Associate does not require, solicit, or routinely access Protected Health Information ("PHI") to perform its obligations under the Underlying Agreement.
- The Parties enter into this BAA to provide mutual assurances complying with the administrative, physical, and technical safeguard requirements of HIPAA, addressing any incidental or inadvertent exposure to PHI that may arise during technical support.
1. Definitions
Terms used, but not otherwise defined, in this Agreement shall have the same meaning as those terms in 45 CFR §§ 160.103, 164.304, 164.402, and 164.501.
- Breach: Shall have the meaning given to such term in 45 CFR § 164.402.
- Electronic Protected Health Information (ePHI): Shall have the meaning given to such term in 45 CFR § 160.103, limited to the information created, received, maintained, or transmitted by Business Associate from or on behalf of Covered Entity.
- Individual: Shall have the meaning given to such term in 45 CFR § 160.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR § 164.502(g).
- Privacy Rule: The Standards for Privacy of Individually Identifiable Health Information at 45 CFR Part 160 and Part 164, Subparts A and E.
- Protected Health Information (PHI): Shall have the meaning given to such term in 45 CFR § 160.103, limited to information created, received, maintained, or transmitted by Business Associate from or on behalf of Covered Entity.
- Security Incident: The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system, as defined in 45 CFR § 164.304.
- Security Rule: The Health Insurance Reform: Security Standards at 45 CFR Part 160 and Part 164, Subpart C.
2. Architectural Scope & Covered Entity Covenants
- Infrastructure Isolation: Covered Entity acknowledges that Shaper is a self-contained, on-premise application operating within Covered Entity's private cloud VPC or physical data centers. Covered Entity maintains exclusive administrative control, network firewalls, database credentials, and physical security over the hosting environment.
- Clean-Room Support Protocol: Covered Entity shall use all reasonable efforts to ensure that its employees, agents, and contractors do not send, upload, or transmit any unmasked, un-redacted, or identifiable PHI to Business Associate in connection with support tickets, emails, GitHub issues, chat channels, or screen-sharing sessions.
- Data Sanitization: When submitting error logs, diagnostic traces, or schema definitions to Business Associate for troubleshooting, Covered Entity shall redact, sanitize, or replace any patient identifiers with synthetic or placeholder data prior to transmission.
- Live Debugging Sessions: During any interactive technical support or screen-sharing sessions, Covered Entity agrees to ensure that patient records are closed or de-identified. Business Associate personnel will not accept remote control of workstations displaying live PHI.
3. Obligations and Activities of Business Associate
- Appropriate Safeguards: Business Associate shall implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any ePHI that Business Associate may receive from or create on behalf of Covered Entity, in accordance with the Security Rule (45 CFR §§ 164.308, 164.310, 164.312, and 164.316).
- Limitations on Use and Disclosure: Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement, the Underlying Agreement, or as Required By Law.
- Workstation & Credential Security: Business Associate maintains full-disk encryption (AES-256) on all developer workstations, enforces universal multi-factor authentication (MFA), utilizes zero-knowledge password vaulting (Proton Pass), and operates corporate communications through end-to-end encrypted infrastructure (Proton Mail).
- Mitigation: Business Associate agrees to mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this Agreement.
- Subcontractors: In accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to substantially equivalent restrictions and conditions that apply to Business Associate with respect to such information.
- Designated Record Set Disclaimer: The Parties agree that Business Associate does not maintain, possess, or control a "Designated Record Set" on behalf of Covered Entity. Accordingly, Business Associate has no obligations regarding individual access (45 CFR § 164.524), amendment (45 CFR § 164.526), or accounting of disclosures (45 CFR § 164.528) to individual patients. Any such requests received directly by Business Associate shall be forwarded to Covered Entity within five (5) business days.
- Access to Books and Records: Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services (HHS) for purposes of determining compliance with the Privacy Rule, subject to attorney-client or other applicable legal privileges.
4. Reporting of Breaches and Security Incidents
- Reporting of Security Incidents: Business Associate shall promptly report to Covered Entity any Security Incident of which it becomes aware. The Parties acknowledge that routine, unsuccessful reconnaissance attempts (such as pings, port scans, broadcast attacks, and unsuccessful login attempts) occur on a continuous basis and that this section constitutes formal notice of such routine attempts without requiring individual notifications.
- Reporting of Breaches of Unsecured PHI: In accordance with 45 CFR § 164.410, Business Associate shall notify Covered Entity without unreasonable delay, and in no event later than ten (10) business days, following the confirmation of any Breach of Unsecured PHI.
- Content of Notice: To the extent available, the notice shall include the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, or disclosed; a description of the incident; the categories of PHI involved; and the corrective actions taken by Business Associate.
- Incidental Disclosure Containment: In the event Covered Entity inadvertently provides PHI to Business Associate (such as an un-redacted error log), Business Associate shall within twenty-four (24) hours of discovery securely purge and permanently delete such data from all local storage, caches, and communication tools, and certify such deletion to Covered Entity.
5. Permitted Uses and Disclosures by Business Associate
Except as otherwise limited in this Agreement, Business Associate may:
- Use or disclose PHI strictly to perform technical support, troubleshooting, and maintenance functions pursuant to the Underlying Agreement.
- Use PHI for the proper management and administration of Business Associate or to carry out legal responsibilities, provided disclosures are Required By Law or Business Associate obtains reasonable written assurances of confidentiality.
- De-identify PHI in accordance with the de-identification standards set forth in 45 CFR § 164.514.
6. Term and Termination
- Term: This Agreement shall become effective on the effective date of the Underlying Agreement and shall terminate upon termination or expiration of the Underlying Agreement, or upon termination for cause under Section 6.2.
- Termination for Cause: If either Party determines that the other Party has committed a material breach of this Agreement, the non-breaching Party shall provide written notice detailing the breach. If the breaching Party fails to cure the breach within thirty (30) days of receiving notice, the non-breaching Party may immediately terminate this Agreement and the Underlying Agreement.
- Effect of Termination: Upon termination of this Agreement for any reason, Business Associate shall, if feasible, return or securely destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity that Business Associate maintains in any form. If return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures strictly to those purposes that make the return or destruction infeasible.
7. Miscellaneous
- Regulatory References: A reference in this Agreement to a section in HIPAA or the CFR means the section as in effect or as amended.
- Amendment: The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity or Business Associate to comply with the requirements of HIPAA and other applicable healthcare regulations.
- Interpretation: Any ambiguity in this Agreement shall be interpreted to permit compliance with HIPAA. In the event of any conflict between the terms of this BAA and the Underlying Agreement, the terms of this BAA shall control with respect to HIPAA and PHI matters.
- Governing Law: This Agreement shall be governed by the laws governing the Underlying Agreement, without regard to conflict of laws principles, except to the extent preempted by federal HIPAA regulations.
Execution & Signatures
IN WITNESS WHEREOF, the Parties hereto have caused this Business Associate Agreement to be executed by their duly authorized representatives:
