Business Associate Agreement
Effective September 15, 2026 · Version v2.11
Version v2.11 · Effective September 15, 2026 · Published September 15, 2026
Effective September 15, 2026 · Version v2.11
Version v2.11 · Effective September 15, 2026 · Published September 15, 2026
WHEREAS, OCTICASE, INC., a corporation organized under the laws of the State of Delaware ("Provider"), operates the Octicase SaaS platform that may process Protected Health Information (PHI) on behalf of its customers and of the experts, consultants and vendors who receive PHI from those customers through the platform (each, "Customer", as Section 1A provides); and
WHEREAS, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations (45 CFR Parts 160, 162, and 164) require that certain entities execute a Business Associate Agreement when handling Protected Health Information on behalf of Covered Entities or their Business Associates;
NOW, THEREFORE, in consideration of the mutual covenants and agreements contained herein and incorporated by reference in the Terms of Service (the "Agreement"), the parties agree as follows:
This Business Associate Agreement applies to Customer if and only if Customer is acting as a Covered Entity or Business Associate under HIPAA when using the Services, and PHI is processed by Provider on Customer's behalf, except as paragraph (f) provides for Portal professionals. This Section clarifies which Customer Types (as defined in Section 3.1 of the Agreement), and which individuals who use the Services on their own behalf under the Consumer Terms of Service, are required to accept this BAA:
A law firm acts as a Business Associate where it receives PHI on behalf of a client that is itself a Covered Entity or Business Associate - for example, in medical malpractice defense, in workers' compensation representation of an employer or insurer, or in other engagements for healthcare providers or plans. A plaintiff-side firm that receives its own client's health records from that client is generally not acting as a Business Associate with respect to those records. Where a law firm does act as a Business Associate and the platform processes that PHI, this BAA applies. Law Firm Customers must accept this BAA as a condition of access to features that involve PHI handling.
Medical/Case-Review Customers (legal nurse consultants, IME providers, life-care planners, economists, etc.) typically act as Business Associates when reviewing or analyzing PHI obtained from healthcare Covered Entities or their clients in the course of providing expert opinions or case analysis. When such a customer processes PHI through the platform, this BAA applies. Medical/Case-Review Customers must accept this BAA.
Records/Vendor Customers retrieving medical records on behalf of attorneys, insurers, or other HIPAA-covered entities typically act as Business Associates of those Covered Entities. When retrieving, processing, or storing medical records (which constitute PHI) through the platform, this BAA applies. Records/Vendor Customers must accept this BAA.
Settlement/Claims Customers handling PHI in the course of lien resolution, settlement administration, structured settlement management, or claims processing typically have HIPAA obligations as Business Associates of payers, providers, or Covered Entities. When processing PHI on behalf of HIPAA-covered entities, this BAA applies. Settlement/Claims Customers must accept this BAA.
Pro Se Consumer Customers handling only their own health information are NOT Business Associates and NOT Covered Entities under HIPAA. When an individual processes only their own health records or medical information, they are the individual themselves, not a Covered Entity or Business Associate. HIPAA does not impose a Business Associate Agreement requirement when an individual handles their own Protected Health Information. THIS BUSINESS ASSOCIATE AGREEMENT DOES NOT APPLY TO PRO SE CONSUMER CUSTOMERS. Pro Se Consumer Customers are instead governed by the Consumer Terms of Service, the Privacy Policy, and applicable state health privacy laws (such as the California Confidentiality of Medical Information Act) and consumer privacy laws (such as the CCPA).
A professional who receives PHI from a Customer through the Expert and Vendor Portal or a Platform Engagement (an expert, consultant, records or service vendor under the Expert and Vendor Portal Terms, the Expert and Consultant Services Agreement or a Partner Agreement) is, where the disclosing Customer is a Covered Entity or a Business Associate, a Business Associate of that Customer in respect of that PHI (and, where that Customer is itself a Business Associate, a subcontractor within the meaning of 45 CFR 160.103), and Provider stores, transmits and processes that PHI on the professional's behalf as well. Where the disclosing Customer is not a Covered Entity or a Business Associate, HIPAA does not govern the professional's receipt of those records, but this BAA still applies to the professional as a contractual standard. This BAA applies to such a professional as "Customer" in respect of the PHI it holds through the Services, whether or not it also holds a subscription; a professional that also holds a subscription accepts this BAA once, and that acceptance covers PHI it holds in either capacity. Those professionals accept this BAA by the separate acceptance Section 15 describes, before any feature that involves PHI is enabled for them. For a professional under this paragraph (f) that holds no subscription, references in this BAA to the Agreement are to the Expert and Vendor Portal Terms, the Expert and Consultant Services Agreement or the Partner Agreement it has accepted; references to Section 12 and Section 16 of the Agreement are to the limitation-of-liability and dispute-resolution provisions of that document; the notification contact under Section 16 is the contact on its Portal account; and the remedy under Section 5 is termination of its Portal access or of that agreement, no fee having been prepaid. Such a professional shall report to Provider and to the disclosing Customer any use or disclosure of PHI not permitted, and any Security Incident affecting PHI it holds, without unreasonable delay and in any event within seventy-two (72) hours of discovering it.
An Unverified Customer under Section 2.11 of the Agreement (a support professional with an account in its own name, or an unverified law-firm account) does not accept a BAA of its own. It may handle PHI through the Services only for a law firm it has identified on its account, which must itself be a Customer that has accepted this BAA; on the firm's confirmation, the Unverified Customer is that firm's Authorized User for the purposes of the firm's BAA, and the firm is the Customer under this BAA for that PHI. An Unverified Customer that has not identified such a firm may not upload, store or transmit PHI through the Services.
Provider does not require Pro Se Consumer Customers to accept this BAA. Customers other than Pro Se Consumers and Unverified Customers must accept this BAA, at subscription, on the claim screen of Part D of the Portal Terms, at acceptance of the Expert and Consultant Services Agreement or a Partner Agreement, or at first access to a feature that involves PHI, as a condition of access to features that involve PHI handling. If a Customer is uncertain whether it qualifies as a Covered Entity or Business Associate, it should consult with its compliance officer or legal counsel.
Capitalized terms used but not defined in this BAA have the meanings set forth in 45 CFR 160.103, 164.304, 164.402 and 164.501. In particular, "Breach" and "Unsecured Protected Health Information" have the meanings given in 45 CFR 164.402, and "Security Incident" the meaning given in 45 CFR 164.304. Additional definitions specific to Provider's services are:
"PHI" means Protected Health Information as defined in 45 CFR 160.103, which is individually identifiable health information, including demographics, clinical information, and billing information.
"Covered Entity" means a health plan, healthcare clearinghouse, or healthcare provider as defined in 45 CFR 160.103.
"Business Associate" means a person or entity that performs certain functions or activities that involve the use or disclosure of PHI on behalf of a Covered Entity.
"Services" means the Octicase SaaS platform, which may include storage, processing, transmission, and access to PHI as permitted under this BAA.
Provider shall use and disclose PHI only: (a) to perform the Services on behalf of Customer and as permitted by the Agreement; (b) as required by law; or (c) with prior written authorization from Customer. Provider shall not use or disclose PHI for any purpose other than those specified. Provider shall limit its uses, disclosures and requests of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 CFR 164.502(b). Provider shall not combine PHI received from Customer with PHI received from any other customer or source, except where Provider provides data aggregation services relating to Customer's health care operations as this Section permits. For every other purpose, Provider de-identifies PHI received from Customer separately, under the De-identification paragraph of this Section, before any combination; what results is no longer PHI, and information so de-identified may be combined and used as that paragraph and Section 7.3 of the Agreement allow.
Provider may also use PHI for the proper management and administration of Provider and to carry out Provider's legal responsibilities, and may disclose PHI for those purposes where the disclosure is required by law, or where Provider obtains reasonable assurances from the recipient that the information will be held confidentially and used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the recipient will notify Provider of any breach of confidentiality. This paragraph is permitted by 45 CFR 164.504(e)(4).
Provider may provide data aggregation services relating to Customer's health care operations, as permitted by 45 CFR 164.504(e)(2)(i)(B), only where Customer instructs it in writing.
Provider shall not sell PHI, and shall not use or disclose PHI for marketing, advertising, audience building or fundraising, whether for Provider or for any third party. Nothing in Provider's marketing activities involves PHI. This paragraph reflects 45 CFR 164.502(a)(5)(ii) and 164.508(a)(3) and (a)(4). Information de-identified in accordance with this Section is not PHI, and its use or licensing is not a sale of PHI.
Disclosures on Customer's instruction to other Customers and to sellers. Where Customer transfers a matter to another Customer, gives another Customer access to it or collaborates with another Customer on it under Section 4.14 of the Agreement, or transmits PHI to an expert, consultant or vendor through the Expert and Vendor Portal or a Platform Engagement under Section 4.16 of the Agreement, the disclosure of PHI to that recipient is Customer's own disclosure, made on Customer's instruction through the Services, and Customer is responsible under Section 10 for its authority to make it. Provider transmits the PHI as directed and acts for each party under this BAA in respect of the PHI that party holds through the Services, as the Business Associate or subcontractor of that party where HIPAA so characterizes it; it is not a party to the arrangement between them. Both the disclosing and the receiving party must have accepted this BAA before the disclosure, as Section 1A and Sections 4.14 and 4.16 of the Agreement require, except that an Unverified Customer and the firm it has identified are covered by the firm's acceptance. On a transfer, the receiving Customer becomes the Customer under this BAA for the transferred PHI on acceptance; on view-only access or collaboration, the originating Customer remains so, and the other Customer holds the PHI under its own BAA on the originating Customer's instruction until that access is revoked and, after revocation, only in respect of anything it lawfully exported while access was open, which it then holds under its own BAA.
Artificial intelligence. Provider may process PHI through the artificial-intelligence features of the Services only to generate outputs for Customer. Neither Provider nor any subcontractor will use PHI to train, retrain, fine-tune or otherwise improve any foundation model or any model that serves another customer. No AI subcontractor retains PHI beyond the period necessary to return the output and to meet its own abuse-monitoring obligations. No subcontractor, and no further subcontractor engaged by it, processes PHI unless it is engaged under a Business Associate Agreement or equivalent written assurances, and Provider will not enable an AI feature for PHI until that is in place throughout the chain. This paragraph applies to PHI in the same terms as Section 4.9 of the Data Processing Addendum applies to Customer Personal Data.
De-identification and re-identification. Customer authorizes Provider, under 45 CFR 164.502(d)(1), to create de-identified information from PHI in accordance with 45 CFR 164.514(b), by the safe-harbor method of 164.514(b)(2) or by expert determination under 164.514(b)(1), and, for information that is medical information under the California Confidentiality of Medical Information Act, to the same standard. Information so de-identified is not PHI (45 CFR 164.502(d)(2)) and Provider may retain, use, analyze, combine and license it, including to third parties and for commercial purposes, under and subject to the conditions of Section 7.3 of the Agreement, which include a written prohibition on re-identification in every license and the terms California Civil Code Section 1798.148 requires. Provider shall not re-identify, nor attempt to re-identify, any information de-identified from Customer's PHI, and shall not disclose to any person the keys, parameters or other details that would permit re-identification; the method of de-identification itself is published in the Privacy Policy, as Section 7.3(e) of the Agreement requires. Where Customer holds PHI as a Portal professional, as an Unverified Customer, or under Section 4.14 of the Agreement on another Customer's instruction, the authorization in this paragraph is given by the Customer that controls the matter, as Section 7.3 of the Agreement provides, and not by the recipient. Where Customer is itself a Business Associate, Customer represents that its agreement with the Covered Entity permits it to create de-identified information and to engage Provider for that purpose, and the authorization in this paragraph is limited accordingly. Provider shall not use information de-identified from Customer's PHI to train, retrain or fine-tune any model, unless Customer agrees to that use in writing. Customer gives or withholds that agreement on a separate screen presented at onboarding and available at any time in Customer's account settings, whose wording is Screen B1 of our Consent Screens, which states the categories of data concerned, that the models trained on them are Provider's and serve Provider's other customers, and how to withdraw. Withdrawal is effective for data created after it and does not require Provider to retrain or discard a model already trained, except where a court, a regulator or applicable law requires it, in which case Provider will do so; Provider states this on that screen rather than leaving it to be discovered. Provider records the agreement, the version of the text shown and the date, and never applies it retroactively, as Section 7.3(d) of the Agreement provides. That agreement covers only information already de-identified under this paragraph; PHI itself is never used to train, retrain or fine-tune any model, and no agreement under this paragraph authorizes it. This restriction is stated expressly because de-identified information is neither PHI nor Personal Data, and would otherwise fall outside both this BAA and the Data Processing Addendum.
Provider shall comply with the applicable requirements of Subpart C of 45 CFR Part 164 with respect to electronic PHI, as required by 45 CFR 164.314(a)(2)(i)(A), and shall ensure that any subcontractor that creates, receives, maintains or transmits electronic PHI on Provider's behalf agrees to do the same. Provider shall report to Customer any Security Incident of which it becomes aware, including Breaches of unsecured PHI as required by 45 CFR 164.410, as 45 CFR 164.314(a)(2)(i)(C) requires. A Security Incident that compromised or may have compromised the confidentiality, integrity or availability of PHI is reported without unreasonable delay and in any event within seventy-two (72) hours of Provider becoming aware of it, in the manner Section 4 provides, whether or not it is a Breach and whether or not it involved any use or disclosure. Unsuccessful Security Incidents that did not compromise PHI are reported as Section 4 provides, and this sentence is notice of their ongoing occurrence. Provider implements and maintains a comprehensive information security program including administrative, physical and technical safeguards to protect the confidentiality, integrity and availability of PHI. Those safeguards include encryption of PHI in transit and at rest, access controls and audit controls, and are described in Annex II to the Data Processing Addendum, which also states which measures are not yet in place: as at the date of this BAA Provider has not performed a vulnerability scan or a third-party penetration test, and Provider will establish a quarterly vulnerability scanning program and commission an annual third-party penetration test as that Annex provides.
Workforce. Provider shall train each workforce member who has access to PHI on the requirements of HIPAA and on Provider's own policies, before granting access and periodically thereafter; shall apply appropriate sanctions against workforce members who fail to comply; shall carry out background screening to the extent permitted by applicable law; and shall terminate access promptly on a workforce member's departure or change of role. Provider shall impose the same obligations on any subcontractor whose personnel access PHI, including personnel placed with Customer under Section 2.9 of the Agreement.
Provider shall notify Customer of a Breach of Unsecured PHI without unreasonable delay after discovery, and in any event within seventy-two (72) hours. The notification shall include, to the extent known, the nature of the Breach, the types and approximate volume of information involved, the individuals affected or likely affected, the date and time of the Breach and of its discovery, remedial action taken, and a contact for further information. Provider shall supplement the notification as further information becomes available and shall cooperate with Customer's investigation and with Customer's notification obligations under 45 CFR 164.404 to 164.408. This period is the same one that applies under Section 4.6 of the Data Processing Addendum, so a single deadline governs whether or not the affected data is PHI.
Provider shall also report to Customer any use or disclosure of PHI not provided for by this BAA of which Provider becomes aware, whether or not it constitutes a Breach, without unreasonable delay and in any event within seventy-two (72) hours of becoming aware of it. This obligation is required by 45 CFR 164.504(e)(2)(ii)(C).
Provider shall mitigate, to the extent practicable, any harmful effect known to Provider of a use or disclosure of PHI in violation of this BAA, whether by Provider or by a subcontractor.
Costs of a Breach. Where a Breach arises from Provider's act or omission or that of its subcontractor, Provider shall bear the reasonable and documented costs Customer incurs in meeting its notification obligations under 45 CFR 164.404 to 164.408, including forensic investigation attributable to the Breach, notification to individuals, media and the Secretary, a call center where the volume reasonably requires one, and credit monitoring where it is customary for the categories of information involved. Those costs are subject to Section 12 of the Agreement, including Section 12.3A.
Security incidents that do not compromise PHI. A security incident as defined in 45 CFR 164.304 includes attempted as well as successful unauthorized access. Unsuccessful attempts and routine events that do not compromise the security, privacy or integrity of PHI, including pings and other broadcast attacks on a firewall, port scans, unsuccessful log-in attempts, malware blocked before execution and denial-of-service attacks, are reported to Customer in aggregate on request rather than individually. This paragraph does not limit Provider's obligation to report any incident that does compromise PHI.
Provider may use subcontractors to assist in providing the Services, including cloud hosting providers. Before engaging any subcontractor that will have access to PHI, Provider shall require the subcontractor to execute a Business Associate Agreement (or equivalent) with terms at least as protective as this BAA. For a subcontractor engaged before the Effective Date, Provider shall obtain that agreement before this BAA takes effect as to Customer. Provider remains liable to Customer for subcontractor compliance. A Customer, Portal professional, Unverified Customer or Authorized User that receives PHI on a Customer's instruction under Section 2 receives it for that Customer, not for Provider, and is not Provider's subcontractor for the purposes of this Section.
Notice and objection. Before engaging a new subcontractor that will have access to PHI, Provider shall give Customer at least thirty (30) days' notice, by email, in-app notice or the subprocessor feed. Customer may object on reasonable grounds within that period; the parties will seek in good faith to resolve the objection, failing which Customer may terminate the affected Services and Provider shall refund the pro-rata portion of any prepaid subscription fees, where any were paid, covering the period after termination. This mirrors Section 4.3 of the Data Processing Addendum, so that Customer's control over who handles its PHI is no weaker than its control over who handles its other Personal Data.
Scope note on placed personnel. No case manager is placed with any Customer today, and no subcontractor creates, receives, maintains or transmits Protected Health Information in that capacity. Where Customer purchases staffing services under Section 2.9 of the Agreement, the case managers placed with Customer will access Protected Health Information in the ordinary course of working Customer's matters; their employer will be a subcontractor of Provider for the purposes of 45 CFR 164.308(b)(2) and 164.502(e)(1)(ii); and Provider shall obtain from that employer written assurances no less protective than this BAA covering that operational access, and shall give the notice and objection rights stated in this Section, before any placement begins.
Provider shall, at Customer's request and as required by 45 CFR 164.524, make PHI available to Customer in the form and format requested (or a reasonable alternative) for Customer's own use or amendment. Customer is responsible for responding to individual access requests. Provider shall respond within ten (10) business days of Customer's request, so that Customer can meet the period allowed to it by 45 CFR 164.524.
Provider shall, at Customer's request and as required by 45 CFR 164.526, allow Customer to amend PHI. Provider shall document amendments as required by HIPAA. Provider shall act within ten (10) business days of Customer's request, so that Customer can meet the period allowed to it by 45 CFR 164.526.
Designated record set. Customer determines what constitutes its designated record set for the purposes of 45 CFR 164.501. To the extent PHI that Provider maintains on Customer's behalf forms part of that designated record set, this Section applies to it. Provider does not itself maintain a designated record set of its own in respect of Customer's PHI.
Provider shall maintain and make available to Customer, as required by 45 CFR 164.528, the information necessary for Customer to respond to a request for an accounting of disclosures of PHI made by Provider. The record shall include the date, nature, recipient and purpose of each disclosure that is subject to accounting under that section, and need not include a disclosure that section excepts, including a disclosure to carry out treatment, payment or health care operations, a disclosure to the individual who is the subject of the PHI, and a disclosure made pursuant to an authorization. Provider shall provide the record within thirty (30) days of Customer's written request.
Provider shall implement and maintain policies and procedures to protect PHI from improper alteration or destruction, as 45 CFR 164.312(c)(1) requires. Provider is not responsible for the accuracy, completeness or timeliness of the content of the PHI that Customer places on the Services, which is Customer's responsibility under Section 10. Provider shall maintain audit controls to record and examine PHI access. Provider shall maintain audit controls to record and examine PHI access.
Upon termination or expiration of this BAA, or upon Customer's request, Provider shall return or securely destroy all PHI it maintains on Customer's behalf, at Customer's choice, and shall retain no copies of that PHI except where return or destruction is not feasible, in which case this Section provides what applies instead. Customer has the thirty (30) day retrieval window provided by Section 4.7 of the Data Processing Addendum, and Provider shall complete the return or destruction from active production systems within sixty (60) days of termination, the same period that governs Customer Data generally under that Section. Provider shall certify that completion to Customer in writing. Where return or destruction is not feasible, as is the case for PHI residing in encrypted backup images, Provider shall extend the protections of this BAA to that information and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as Provider maintains it; those images are overwritten in the ordinary retention cycle described in Annex II to the Data Processing Addendum and are not accessed or used for any other purpose in the meantime. The parties agree that return or destruction is not feasible where a law, regulation, professional rule, litigation hold, preservation obligation or compulsory legal process requires Provider to retain the information, including the audit, incident and transaction records the Data Retention and Deletion Policy lists. In those circumstances Provider retains the minimum PHI necessary for that purpose, extends the protections of this BAA to it, limits further uses and disclosures to the purposes that make return or destruction infeasible, and deletes it once that obligation ends. De-identified information meeting the standard of 45 CFR 164.514(b) is not PHI and may be retained, used and licensed by Provider under Section 2 and Section 7.3 of the Agreement; it is not subject to return or destruction. Where Customer is a Portal professional, this Section applies to the PHI held in its own engagement records and does not affect the disclosing Customer's copy, which remains subject to that Customer's BAA; the export period for a Portal professional is the one stated in the Data Retention and Deletion Policy. Where Customer holds PHI under Section 4.14 of the Agreement on another Customer's instruction, revocation of access has the effect of termination for that PHI.
Upon termination of the Agreement, this BAA terminates automatically. Customer may also terminate this BAA independently if it determines that Provider has breached a material term of it. Customer may, at its option, give Provider thirty (30) days to cure before terminating, but is not required to do so and does not waive its right to terminate by doing so. Provider's obligations under Sections 3, 4, 5, 6, 7, 8 and 12 survive termination as necessary to fulfill them, and the restrictions in Section 2 on re-identification and on the use of de-identified information survive indefinitely, for as long as Provider retains information derived from Customer's PHI. Customer's authorization under Section 2 and the conditions attached to it survive as to information de-identified before termination, as Section 7.3 of the Agreement provides; the rules in Section 2 on PHI held after revocation of access under Section 4.14 of the Agreement survive for as long as that PHI is held; and the Liability paragraph of Section 16 survives as to claims arising before termination.
Either party may request amendments to this BAA as necessary to comply with changes in HIPAA law or regulations. Amendments must be in writing and signed by authorized representatives.
Pro Se Consumer Customers are not required to accept this BAA, for the reasons set out in Section 1A(e). If a Pro Se Consumer Customer's status changes, for example because they form or join a law firm or enter into an arrangement that makes them a Covered Entity or a Business Associate, they shall notify Provider and accept this BAA before handling PHI on behalf of another person through the Services.
For Customers other than Pro Se Consumers: this BAA is a condition of Customer's subscription or, for a Portal expert, consultant or vendor, of its Portal access, and in every case of the use of features that involve PHI. Customer accepts it by accepting the Agreement or, for a Portal expert, consultant or vendor, by the separate acceptance the Expert and Vendor Portal presents on the claim screen of Part D of the Portal Terms or at first access to a feature that involves PHI, or on the acceptance screen of the Expert and Consultant Services Agreement or of a Partner Agreement where that screen so indicates; an Unverified Customer does not accept it and acts under the BAA of the firm it has identified, as Section 1A(g) provides. That acceptance is an electronic signature under the ESIGN Act and the Uniform Electronic Transactions Act, as described in Provider's ESIGN/UETA Consent and Disclosure.
This BAA is governed by the laws of the State of Delaware and by the HIPAA Privacy, Security and Breach Notification Rules. Where Delaware law conflicts with HIPAA, HIPAA controls. Any dispute arising out of or relating to this BAA is subject to the dispute resolution provisions of the agreement through which the party accepted it: Section 16 of the Terms of Service for a Customer; Section 11.2 of the Expert and Consultant Services Agreement for an expert or consultant; Section 12.2 of the Partner Agreement for a partner; and Section C.9 of the Expert and Vendor Portal Terms for any other Portal professional. A professional who accepted this BAA under the Expert and Consultant Services Agreement, a Partner Agreement or the Expert and Vendor Portal Terms is governed by the dispute resolution provisions of that agreement for every dispute under this BAA, whether or not it also holds a subscription. That sentence governs the forum only; where such a professional also holds a subscription, the limitation-of-liability provisions of the Terms of Service, including Section 12.3A, continue to apply to it.
More stringent State law. HIPAA sets a floor and not a ceiling. Where a State law governing medical or health information imposes requirements more protective than HIPAA, including the California Confidentiality of Medical Information Act (Cal. Civ. Code sections 56 et seq.), Provider shall comply with the more protective requirement in respect of the information that law covers.
Liability. Each party's liability under this BAA is governed by the limitation-of-liability provisions of the Agreement, which for a Customer under the Terms of Service are Section 12, including Section 12.3A (Security Incidents Affecting Customer Data). Nothing in this BAA displaces that Section, and the precedence given to this BAA in respect of PHI does not create a separate or uncapped liability regime.
Term. This BAA takes effect on the effective date of the Agreement or on the first occasion on which Provider processes PHI on Customer's behalf, whichever is earlier, and continues until terminated in accordance with Section 13.
Audit. Customer's right to information demonstrating Provider's compliance, and any audit beyond the review of audit reports, is governed by Section 4.8 of the Data Processing Addendum and applies equally to Provider's handling of PHI.
Notices. A notification under Section 4 shall be given to Customer at the security or privacy contact identified on the Subscription Confirmation or, for a Portal professional, on its Portal account and, failing that, at the administrative contact on Customer's account, by email with confirmation of receipt and, where the matter is urgent, by telephone as well. Notices to Provider shall be sent to security@octicase.com with a copy to legal@octicase.com and, where a formal notice is required, to OCTICASE, INC., 2140 S Dupont Highway, Camden, Kent County, Delaware 19934. Each party shall keep its notification contact current.
Interpretation. Any ambiguity in this BAA shall be resolved to permit Provider and Customer to comply with HIPAA. Where HIPAA is amended in a way that requires a change to this BAA, the parties shall negotiate in good faith to make that change, and until they do, this BAA shall be read to give effect to the amended requirement.
No third-party beneficiaries; severability. Nothing in this BAA creates any right in favor of any person other than Provider and Customer, and in particular no individual whose PHI is processed acquires a right of action under it. If any provision of this BAA is held unenforceable, the remainder continues in effect.