Effective Date: May 8, 2026
This Business Associate Agreement ("Agreement") is entered into between you, the healthcare provider or covered entity ("Covered Entity"), and Pablo Health, LLC, the operator of this therapy assistant platform ("Business Associate").
Terms used but not otherwise defined in this Agreement have the meanings given to them in the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), and their implementing regulations, including the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164.
Protected Health Information (PHI): Information that relates to the past, present, or future physical or mental health of an individual, including demographic information, that identifies the individual or could be used to identify the individual.
Electronic Protected Health Information (ePHI): PHI that is transmitted or maintained in electronic media.
Breach: The acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the PHI.
Required by Law: A mandate contained in law that compels an entity to make a use or disclosure of PHI.
Security Incident: The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
Identity Tombstone: A minimum-necessary record retained by Business Associate after physical deletion of clinical content. Each tombstone contains only patient identifier, name, date of birth, medical record number, and tenant identifier — no clinical content. The tombstone exists solely to allow Business Associate to answer regulatory identity-resolution requests during the audit-log retention period.
Part 2 Program: A federally-assisted program, as defined at 42 CFR § 2.12, that holds itself out as providing the diagnosis, treatment, or referral for treatment of a substance use disorder, and whose patient records are accordingly governed by the Federal Confidentiality of Substance Use Disorder Patient Records regulations at 42 CFR Part 2.
2.1 Services. Business Associate may use and disclose PHI only as necessary to perform the following services on behalf of Covered Entity:
2.2 Minimum Necessary. Business Associate shall limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose, consistent with HIPAA requirements.
2.3 Business Associate Operations. Business Associate may use PHI for its proper management and administration, or to carry out legal responsibilities, provided:
2.4 Prohibited Uses. Business Associate shall not, and shall not permit any subcontractor to:
2.5 Usage Restriction — 42 CFR Part 2 Programs. This platform is not currently authorized for use by Part 2 Programs. Covered Entity represents and warrants that it is not a Part 2 Program. The HIPAA Business Associate Agreements covering the platform's subprocessor chain (held by Business Associate's parent, LLL Solutions, LLC, and flowed through to Business Associate via the inter-company BAA described in Section 5.1) do not, as of the Effective Date, include Qualified Service Organization Agreements covering the full chain — specifically, Google Cloud, which provides the underlying hosting and AI inference, has not contractually assumed Part 2 obligations. Until that gap is closed, federally-assisted programs subject to 42 CFR Part 2 should not use this platform to process patient records. Incidental references to substance use within otherwise non-Part 2 records (e.g., a private-practice therapist's notes that mention a patient's reported alcohol use) are governed by HIPAA and applicable state law and do not bring those records within Part 2's scope.
3.1 Safeguards. Business Associate shall:
3.2 No Unauthorized Use or Disclosure. Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law.
3.3 Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effect of a use or disclosure of PHI by Business Associate in violation of this Agreement.
3.4 Reporting. Business Associate shall report to Covered Entity:
Each notification shall include, to the extent then known and as required by 45 CFR § 164.410:
Business Associate retains breach-notification documentation for six (6) years from discovery or resolution, as required by 45 CFR § 164.414.
4.1 Access to PHI. Within ten (10) business days of a request from Covered Entity, Business Associate shall make available PHI in a Designated Record Set to Covered Entity or, as directed by Covered Entity, to an individual to meet Covered Entity's obligations under 45 CFR § 164.524. The platform provides a self-service per-patient export endpoint and a tenant-wide export tool that produces a portable archive (JSON for machine portability and PDF for human readability) of every patient, session, transcript, note, and audit-log entry in Covered Entity's tenant.
4.2 Amendment of PHI. Within fifteen (15) business days of receipt of a request from Covered Entity, Business Associate shall make any amendments to PHI in a Designated Record Set as directed by Covered Entity pursuant to 45 CFR § 164.526. The platform supports in-application editing of clinical content; every edit is itself audit-logged.
4.3 Accounting of Disclosures. Within fifteen (15) business days of notice from Covered Entity, Business Associate shall make available to Covered Entity the information required to provide an accounting of disclosures in accordance with 45 CFR § 164.528. Covered Entity may also pull its own audit log at any time through the application or via GET /api/users/me/audit-log.
4.4 Privacy Practices. Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.
5.1 Subcontractor Obligations. Business Associate shall ensure that any subcontractors, agents, or other persons to whom it provides PHI received from, or created or received by Business Associate on behalf of, Covered Entity agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such PHI, including implementing reasonable and appropriate safeguards. Business Associate's parent company, LLL Solutions, LLC, holds the operational HIPAA Business Associate Agreements with the cloud and AI subprocessors listed in Section 5.2 below; the protections of those agreements flow through to Business Associate via the LLL Solutions ↔ Pablo Health inter-company HIPAA Business Associate Agreement, under which LLL Solutions acts as a Subcontractor Business Associate to Business Associate within the meaning of 45 CFR § 160.103. Business Associate shall not allow PHI to flow to any subprocessor that is not covered by a written BAA in this chain.
5.2 Current Subprocessors. As of the Effective Date, Business Associate uses the following subprocessors:
| Subprocessor | Purpose | Data category | BAA |
|---|---|---|---|
| Google Cloud Platform (incl. Vertex AI) | Hosting, database, AI inference (Gemini, Anthropic Claude routed via Vertex) | All PHI | Yes — held by LLL Solutions; flow-through via inter-company BAA |
| Google Cloud Speech-to-Text | Real-time transcription (Practice Mode) | Practitioner audio only | Yes — held by LLL Solutions; flow-through via inter-company BAA |
| AssemblyAI | Optional transcription provider for recorded sessions | Session audio | Yes — held by LLL Solutions; flow-through via inter-company BAA |
| Stripe | Billing and subscription management | Email + Stripe customer ID only (no PHI) | Not required (no PHI) |
| ElevenLabs | Text-to-speech for AI patient (Practice Mode) | Synthetic patient text only (no real PHI) | Not required (no PHI) |
| Firebase / Identity Platform | Authentication, multi-factor enrollment | Email, MFA enrollment, sign-in events | Yes — held by LLL Solutions; flow-through via inter-company BAA |
5.3 Prohibition on Untracked Subprocessors. Business Associate shall not introduce a new subprocessor that may receive PHI without first executing a HIPAA Subcontractor Business Associate Agreement with that subprocessor and updating this list. Egress to non-allowlisted hosts is monitored by Business Associate's weekly internal security review.
6.1 Term. This Agreement shall become effective on the date Covered Entity accepts this Agreement and shall continue until terminated in accordance with this Section.
6.2 Termination for Cause. Either party may terminate this Agreement if the other party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) days after receiving written notice of the breach.
6.3 Termination by Covered Entity (Offboarding). Covered Entity may terminate this Agreement at any time by initiating offboarding through the platform or by written notice to Business Associate. Upon receipt of a termination notice:
(a) Sixty (60) day grace period. Business Associate shall provide Covered Entity sixty (60) calendar days of continued read and export access to the platform, during which Covered Entity may export, transfer, or otherwise act upon the PHI in its tenant.
(b) Tenant-wide export. Business Associate shall make available to Covered Entity, throughout the grace period, a single-action export tool that produces a portable archive of every patient, session, transcript, note, and audit-log entry remaining in Covered Entity's tenant.
(c) End of grace period. At the expiration of the grace period, Business Associate shall physically destroy Covered Entity's tenant database schema — including every patient, session, transcript, note, calendar token, vault document, and recorded audio file — and shall write a TENANT_DELETED event to the platform-level audit log. The destruction shall be completed within five (5) business days of grace expiration.
(d) What survives. After the schema is destroyed, Business Associate retains only the records described in Section 6.5 (Surviving Records).
6.4 Effect of Termination. Upon termination of this Agreement for any reason, Business Associate shall destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, except as expressly permitted in Section 6.5. Business Associate shall not retain any copies of the PHI other than the records described in Section 6.5.
6.5 Surviving Records. The parties acknowledge that certain records cannot be destroyed at termination because they are subject to independent retention obligations. Business Associate shall retain only the following records following termination:
(a) Audit logs (HIPAA § 164.312(b) and § 164.530(j)(2)). Audit-log entries describing who accessed what PHI, when, and on which resource. Audit-log payloads are PHI-free by design — a runtime check rejects any audit-log write that would include clinical content. Audit-log entries are retained for seven (7) years from the date of the underlying action and are then physically destroyed by an automated purge job.
(b) Identity Tombstones (limited PHI). A minimum-necessary tombstone for each patient — patient identifier, name, date of birth, medical record number, and tenant identifier — kept in a separate, locked compliance schema reachable only by a designated compliance-investigator role and never by the application's normal request path. Tombstones exist solely to enable Business Associate to answer regulatory identity-resolution requests during the audit-log retention window. Each tombstone is retained for seven (7) years from the date of the patient's deletion or the tenant's offboarding (whichever applies) and is then physically destroyed on the same purge schedule as the corresponding audit-log entries. Once both have been destroyed, the question "who was patient X" is permanently unanswerable.
(c) Breach-notification records (HIPAA § 164.414). Documentation of any breach involving Covered Entity's PHI, the investigation, and notifications, retained for six (6) years from discovery or resolution.
(d) Compliance documentation (HIPAA § 164.530(j)(2)). This Agreement, internal policies, training records, risk assessments, and similar artifacts, retained for at least six (6) years.
(e) Billing records. Stripe customer identifier and subscription state. Underlying transaction records are retained by Stripe under its own terms and U.S. tax-record requirements; Business Associate does not retain financial transaction records itself.
(f) Records subject to legal hold. Records covered by a litigation hold, subpoena, or regulatory investigation. Business Associate shall promptly notify Covered Entity when a hold is in effect for Covered Entity's records and again when it is lifted.
6.6 Backups. Encrypted database backups are rotated on a thirty-day cycle. PHI deleted from the live database disappears from any backup older than thirty (30) days. Business Associate shall not restore PHI from backup to recover deleted data except under Covered Entity's written instruction.
7.1 Three-stage deletion. When a user of the platform deletes a patient or session, Business Associate processes the deletion in three stages:
(a) Stage 1 — Soft-delete (Day 0). The row is immediately marked deleted and disappears from every list, search, export, and report. The audit-log entry for the deletion is written in the same database transaction so the action and the trail are atomic.
(b) Stage 2 — Day-30 hard purge of clinical content. A scheduled job running daily processes patients whose 30-day undo window has expired. For each, the job writes a minimum-necessary identity tombstone (Section 6.5(b)) to the compliance schema, and then physically deletes every row associated with that patient — sessions, transcripts, notes, recorded audio, and the patient row itself. Both writes occur in a single database transaction so the tombstone exists if and only if the clinical content is gone.
(c) Stage 3 — Year 7 expiry. Seven years after the original deletion, the audit-log entry and the identity tombstone both expire on the same day, removed by a separate purge cron.
7.2 Records custodianship. Business Associate is not the legal records custodian for Covered Entity's clinical records. Most U.S. states require behavioral-health providers to retain patient records for six to ten years after last treatment, and longer for minors. Compliance with state-board retention rules is Covered Entity's obligation, not Business Associate's. Business Associate facilitates Covered Entity's compliance by providing per-patient and tenant-wide export tooling at any time. Before each destructive deletion, the platform requires the deleting user to attest that they have met their professional retention obligations for that record; the attestation is itself audit-logged.
7.3 Audio retention. Recorded session audio is governed by a per-practice retention window, with a default of three hundred sixty-five (365) days, configurable by Covered Entity's practice administrator from thirty (30) days to seven (7) years. A daily purge job removes audio older than the configured threshold and writes an audit-log entry for each deletion. Covered Entity may also delete audio for any individual session at any time through the application; deletion of a session or its patient cascades to the audio.
7.4 Practice-mode audio. Audio streamed through Practice Mode (AI patient simulation) is processed in real time by the speech-to-text provider and discarded the moment the transcript line is produced. Business Associate does not persist Practice Mode audio in any form. Only the resulting conversation transcript is stored on the session record.
The obligations of Business Associate under Sections 6.3 (Termination by Covered Entity), 6.4 (Effect of Termination), 6.5 (Surviving Records), and 6.6 (Cloud SQL backups), and the rights and obligations of both parties under Section 9 (Liability, Indemnification, and Limitation of Liability), Section 10.6 (Governing Law), Section 10.7 (Dispute Resolution), and Section 10.8 (Attorneys' Fees) shall survive the termination of this Agreement.
9.1 Compliance with Laws. Each party shall comply with all applicable federal and state laws and regulations regarding the privacy and security of PHI.
9.2 HITECH Act. Business Associate acknowledges that certain provisions of the HITECH Act apply directly to Business Associates and agrees to comply with such provisions, including but not limited to:
9.3 Indemnification by Business Associate. Business Associate shall indemnify, defend, and hold harmless Covered Entity and its officers, directors, employees, and agents from and against any and all claims, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to any breach of this Agreement caused by the negligence, willful misconduct, or violation of applicable law by Business Associate or its subcontractors, agents, or employees.
9.4 Indemnification by Covered Entity. Covered Entity shall indemnify, defend, and hold harmless Business Associate and its officers, directors, members, employees, and agents from and against any and all claims, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to any breach of this Agreement caused by the negligence, willful misconduct, or violation of applicable law by Covered Entity or its employees or agents, including but not limited to Covered Entity's failure to comply with its own obligations under HIPAA or applicable state-law records-retention rules.
9.5 Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
(a) Cap on Direct Damages. EXCEPT FOR OBLIGATIONS ARISING UNDER SECTIONS 9.3 AND 9.4 (INDEMNIFICATION), THE TOTAL AGGREGATE LIABILITY OF BUSINESS ASSOCIATE ARISING OUT OF OR RELATED TO THIS AGREEMENT SHALL NOT EXCEED THE TOTAL FEES PAID BY COVERED ENTITY TO BUSINESS ASSOCIATE DURING THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
(b) Exclusion of Consequential Damages. IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER PARTY FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOST PROFITS, LOST REVENUE, OR LOSS OF BUSINESS, ARISING OUT OF OR RELATED TO THIS AGREEMENT, REGARDLESS OF THE THEORY OF LIABILITY (CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE), EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
(c) Exceptions. The limitations in Sections 9.5(a) and 9.5(b) shall not apply to: (i) either party's indemnification obligations under Sections 9.3 and 9.4; (ii) liability arising from a party's gross negligence or willful misconduct; or (iii) regulatory fines or penalties imposed directly on a party by a governmental authority for that party's own violations of HIPAA or the HITECH Act.
10.1 Regulatory Changes and Amendment Process. The parties agree to take such action as is necessary to amend this Agreement to comply with changes in applicable laws and regulations, including HIPAA and the HITECH Act. Business Associate may update or amend this Agreement from time to time, including to reflect changes in applicable law, regulatory guidance, or Business Associate's services. When a material amendment is made, Business Associate will notify Covered Entity via the email address associated with Covered Entity's account and will publish the updated Agreement on the platform. Covered Entity must accept the updated Agreement through the platform's electronic acceptance process in order to continue using the platform. If Covered Entity does not accept the updated Agreement within thirty (30) calendar days of notification, Business Associate may suspend or terminate Covered Entity's access to the platform until the updated Agreement is accepted.
10.2 Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with HIPAA and the HITECH Act.
10.3 No Third-Party Beneficiaries. Nothing in this Agreement shall confer upon any person other than the parties and their respective successors or assigns any rights, remedies, obligations, or liabilities.
10.4 Entire Agreement. This Agreement constitutes the entire agreement between the parties with respect to Business Associate's use and disclosure of PHI and supersedes all prior agreements, whether written or oral.
10.5 Severability. If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
10.6 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the State of Georgia, without regard to its conflict of laws principles, except to the extent preempted by federal law, including HIPAA and the HITECH Act.
10.7 Dispute Resolution. Any dispute, claim, or controversy arising out of or relating to this Agreement shall be resolved as follows:
10.8 Attorneys' Fees. In any action or proceeding to enforce this Agreement, the prevailing party shall be entitled to recover its reasonable attorneys' fees and costs from the non-prevailing party.
10.9 Data Residency. Pablo's infrastructure is in the United States (Google Cloud us-central1). All PHI is processed and stored in the United States and is subject to U.S. law. Business Associate does not support EU, UK, or Canadian-hosted deployments.
Legal Effect of Electronic Signature: By using this platform, you consent to conducting business with us electronically and to signing this Agreement electronically. You agree that your electronic acceptance of this Agreement, executed by clicking the "I Accept" button below and providing your professional credentials, has the same legal force and effect as a handwritten signature under the Electronic Signatures in Global and National Commerce Act (ESIGN Act, 15 U.S.C. § 7001 et seq.) and applicable state electronic signature laws, including the Uniform Electronic Transactions Act (UETA).
Your Rights and Responsibilities: Before accepting this Agreement electronically, please understand:
To view, accept, and retain this Agreement electronically, you must have:
Required:
Recommended:
If you do not have access to the required hardware or software, you may request a paper copy of this Agreement as described in Section 11.3 below.
You have the right to receive a paper copy of this Agreement at any time, even after you have accepted it electronically.
To request a paper copy:
We will send you a paper copy:
The paper copy will be:
You may withdraw your consent to conduct business electronically at any time by contacting us as described below.
To withdraw consent:
Consequences of withdrawal:
Note: If you wish to continue using the platform after withdrawing electronic consent, you will need to execute a paper Business Associate Agreement, which may take 2-4 weeks to process.
We recommend you save or print a copy of this Agreement for your records.
To save a copy:
We will store a copy of the Agreement you accepted, including:
You must keep your email address current to receive important notices about this Agreement, including:
To update your email address:
If your email address becomes invalid, we may terminate this Agreement and your access to the platform until you provide a valid email address.
By clicking the "I Accept" button below and providing your professional credentials, you acknowledge and agree that:
By clicking "I Accept" below, you are creating a legally binding electronic signature.
About This Agreement: If you have questions about the terms of this Business Associate Agreement, please contact:
About Your HIPAA Obligations: If you have questions about your obligations under HIPAA as a covered entity, we recommend you consult with a qualified healthcare attorney. We cannot provide legal advice.
Technical Support: If you experience technical difficulties accessing or accepting this Agreement:
Contact Information: Pablo Health, LLC 8735 Dunwoody Place, Ste R, Atlanta, GA 30350 Email: support@pablo.health For questions about this Business Associate Agreement or to request a paper copy, please contact us at the email above.
Legal Counsel: If you have questions about your HIPAA compliance obligations, please consult with your legal counsel.
Version: 2026-05-08