Skip to main content

[ Customer Agreements ]

Business Associate Agreement

Effective
August 6, 2026
Version
2026-08-06

This BAA governs the handling of Protected Health Information (PHI) under HIPAA. It supplements the Terms of Service and, for personal data that is not PHI, the Data Processing Addendum.

Read this before sending any PHI

This BAA is not automatic. It must be manually requested, reviewed, and signed by both parties before you route any PHI through the platform.

01 / Permitted Uses and Disclosures

  • Strict limitations. We will use or disclose PHI solely to provide the configured services, for internal management, or as Required By Law.
  • Prohibited uses. We strictly prohibit selling PHI, using PHI for marketing, or using PHI to train, fine-tune, or improve any machine learning model.

02 / Syntax Voice (Business Associate) Obligations

  • Safeguards. We implement administrative, physical, and technical safeguards, restricting PHI access to authorized personnel under confidentiality duties.
  • Subcontractors. We ensure all sub-processors handling PHI agree to identical written restrictions.
  • Individual rights. We will provide PHI to you for access, amendment, or accounting requests within 10 business days. Direct individual requests will be forwarded to you.
  • Breach notification. We will report any Breach of Unsecured PHI within 72 hours of discovery. You are responsible for notifying the Secretary, media, or Individuals.

03 / Safeguards and HIPAA Restricted Mode

  • Encryption. PHI is encrypted in transit (TLS 1.2+) and at rest (storage layer).
  • HIPAA Restricted Mode. When manually enabled by you per-agent, this mode provides AES-256-GCM encryption for transcripts and summaries, strips clinical terms and phone numbers before they reach language models, blocks outbound webhooks, and instructs the AI not to solicit clinical data.
  • Audit logging. PHI access through the API is audited; access fails closed if the audit log cannot be written.

04 / Customer (Covered Entity) Obligations

  • Configuration duties. You must manually enable HIPAA Restricted Mode on all relevant agents. You must strictly manage role-based access.
  • Data placement. You must keep PHI out of configuration fields, knowledge bases, prompts, and agent names, as these are not encrypted via the PHI path.
  • Legal consent. You are solely responsible for configuring legally compliant call-recording and AI-disclosure notices.

05 / Term and Termination

  • Termination. Either party may terminate for an uncured 30-day material breach.
  • Return or destruction. Upon termination, we will return or destroy all PHI. Encrypted backups containing PHI are cycled out automatically over a 30-day window and remain protected under this BAA until destroyed.

Request an executed copy.

Healthcare and NEMT workspaces on the Pro or Agency tier receive an executed BAA before the first call. Submit this form and a PDF will be sent to your work email within one business day.