DentalX Business Associate Agreement and Health Data Processing Addendum
Document ID: BAA-US · Version: 1.0 · Language: English (a Spanish courtesy copy may be provided; English controls) · Effective date of this version: [[TO CONFIRM: publication date of v1.0]]
Status: final draft for counsel's review. Not yet published.
Applies to: every Clinic whose country recorded in DentalX is the United States. It includes Schedule A (state processor terms), Schedule B (California) and Schedule C (Texas). Schedules B and C apply only to Clinics in those states.
Drafting conventions. Text in «guillemets» is a merge field. The DentalX server fills it from the signup or acceptance record before display; the filled text is what is hashed and recorded. Text in
[[TO CONFIRM: …]]is a fact not yet known; each one is listed at the end.
Parties
- «Clinic legal name», a «Clinic entity type» with its principal place of practice at «Clinic address», «State», United States (the "Clinic"). Where the Clinic is a covered entity, it is also the "Covered Entity".
- VstreamX Studio Inc., a corporation incorporated under the laws of the Province of Manitoba, Canada, with its registered office at Office B – 1043 Rosser Ave, Brandon, Manitoba R7A 0L5, Canada ("VstreamX" or the "Business Associate").
Background
A. VstreamX provides DentalX, a cloud dental-practice management service, to the Clinic under the DentalX Terms of Service (the "Terms").
B. In providing DentalX, VstreamX creates, receives, maintains or transmits protected health information on the Clinic's behalf, and is therefore the Clinic's business associate under the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164 (together, "HIPAA").
C. The Terms prohibit the Clinic from entering protected health information into DentalX until this Agreement is in place, and DentalX does not let a US Clinic add patients until it is recorded.
D. The Parties enter into this Agreement to satisfy 45 C.F.R. §§ 164.308(b), 164.314(a), 164.502(e) and 164.504(e). They also enter into it to set out the terms that state law requires for the processing of health data.
1. Definitions
1.1 HIPAA terms. Capitalised terms used and not defined in this Agreement have the meanings given in HIPAA. These include: Breach, Covered Entity, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information and Use.
1.2 Other definitions.
- "PHI" means Protected Health Information, as defined at 45 C.F.R. § 160.103, that VstreamX creates, receives, maintains or transmits on behalf of the Clinic in providing the Services. It includes Electronic Protected Health Information.
- "Services" means DentalX as the Terms describe it, and the support VstreamX provides with it.
- "Discovery" means the first day on which VstreamX knows of a Breach of Unsecured PHI, or by exercising reasonable diligence would have known of it, as 45 C.F.R. § 164.410(a)(2) provides.
- "Health Data" means PHI and any other personal information about the Clinic's patients that VstreamX processes on the Clinic's behalf. This includes "consumer health data" under the state laws named in Schedule A.
1.3 Clinics that are not Covered Entities. Signup records whether the Clinic conducts standard electronic transactions (such as electronic insurance claims). A Clinic that does not is not a Covered Entity, and HIPAA may not apply to it. For such a Clinic:
- VstreamX nevertheless gives the commitments in this Agreement as contractual obligations, as if the Clinic were a Covered Entity and the Health Data were PHI; and
- Schedule A applies to the Health Data.
2. Permitted and required uses and disclosures
2.1 Services. VstreamX may Use and Disclose PHI only as necessary to perform the Services for the Clinic, as the Terms and this Agreement describe. It may not Use or Disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Clinic, except as section 2.3 allows.
2.2 Required by Law. VstreamX may Use and Disclose PHI as Required by Law, subject to section 3.12.
2.3 Management and administration. VstreamX may Use PHI for its proper management and administration, or to carry out its legal responsibilities, only to the extent necessary for operating, securing, backing up and supporting the Services, and for defending legal claims. VstreamX may Disclose PHI for those purposes only if:
- (a) the Disclosure is Required by Law; or
- (b) VstreamX obtains reasonable assurances from the person to whom the PHI is Disclosed that:
- it will be held confidentially;
- it will be Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed to that person; and
- the person will notify VstreamX of any instance of which it is aware in which the confidentiality of the PHI has been breached.
2.4 Prohibited uses. VstreamX will not:
- (a) provide Data Aggregation services;
- (b) de-identify PHI for its own use;
- (c) sell PHI, or receive remuneration in exchange for PHI (45 C.F.R. § 164.502(a)(5)(ii));
- (d) Use or Disclose PHI for marketing or advertising;
- (e) Use PHI, or any output derived from it, to train, fine-tune, evaluate or otherwise improve any artificial-intelligence model; or
- (f) Use or Disclose PHI for any purpose of its own other than as section 2.3 allows.
2.5 Minimum Necessary. VstreamX requests, Uses and Discloses only the Minimum Necessary PHI to accomplish the intended purpose, in accordance with 45 C.F.R. §§ 164.502(b) and 164.514(d).
3. Obligations of the Business Associate
3.1 Limits on use and disclosure. VstreamX will not Use or further Disclose PHI other than as permitted or required by this Agreement or as Required by Law.
3.2 Safeguards.
- VstreamX will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to Electronic Protected Health Information, to prevent Use or Disclosure of PHI other than as provided for by this Agreement.
- The safeguards in force are described in Exhibit 1.
3.3 Reporting. VstreamX will report to the Clinic:
- (a) any Use or Disclosure of PHI not provided for by this Agreement of which it becomes aware;
- (b) any Breach of Unsecured PHI, as 45 C.F.R. § 164.410 requires; and
- (c) any Security Incident of which it becomes aware.
3.4 Timing and content of reports.
- When. VstreamX will make each report under section 3.3 without unreasonable delay, and in no case later than 5 business days after Discovery (for a Breach) or after becoming aware (for any other matter).
- What a Breach report contains. For a Breach, the report will include, to the extent possible:
- the identification of each Individual whose Unsecured PHI has been, or is reasonably believed by VstreamX to have been, accessed, acquired, Used or Disclosed during the Breach; and
- any other available information the Clinic is required to include in its notification to Individuals under 45 C.F.R. § 164.404(c), including a description of what happened, the dates of the Breach and of its Discovery, the types of PHI involved, the steps Individuals should take to protect themselves, and what VstreamX is doing to investigate, mitigate and prevent recurrence.
- Information that arrives later. VstreamX will supplement the report as information becomes available.
3.5 Unsuccessful Security Incidents.
- Notice given now. The Parties agree that this section is notice, given now and requiring no further notice, of the ongoing existence and occurrence of attempted but unsuccessful Security Incidents. Examples are pings and other broadcast attacks on firewalls, port scans, unsuccessful log-on attempts, denials of service, and any combination of the above.
- Condition. This applies only so long as no such incident results in unauthorised access, Use or Disclosure of PHI.
3.6 Mitigation. VstreamX will mitigate, to the extent practicable, any harmful effect known to it of a Use or Disclosure of PHI by VstreamX in violation of this Agreement. On request, it will help the Clinic perform the four-factor risk assessment under 45 C.F.R. § 164.402.
3.7 Subcontractors.
- Flow-down. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), VstreamX will ensure that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions, conditions and requirements that apply to VstreamX under this Agreement.
- Subcontractors at the effective date. They are listed in Exhibit 2. Google LLC is VstreamX's Subcontractor under the Google Cloud Business Associate Agreement, which covers only the Google services Google lists as covered. VstreamX uses only covered services to create, receive, maintain or transmit PHI.
- No PHI to the following. VstreamX does not send PHI to any provider that has not signed a business associate agreement with it. For US Clinics:
- WhatsApp is blocked by the server, not merely switched off by default, because Meta does not sign business associate agreements. No setting lets a US Clinic turn it on;
- email to patients is sent only from a Google Workspace account that the Google Workspace business associate agreement covers. Until it does, DentalX sends no email to the patients of US Clinics. Sending links instead of attachments does not change this, because the message itself, sent by a dental clinic to a patient and stored in the sending mailbox, is PHI [[BLOCKING TO CONFIRM: Google Workspace BAA accepted for the sending account]];
- Google reCAPTCHA is loaded only on pages without PHI; and
- Stripe receives no PHI.
- New Subcontractors. VstreamX will not engage a new Subcontractor for PHI until a business associate agreement with it is in place. It will publish the change on the DentalX sub-processors page, and notify the Clinic by email, at least 30 days before it takes effect.
3.8 Access (45 C.F.R. § 164.524).
- Self-service. The Services let the Clinic retrieve and export PHI in a Designated Record Set itself, in the electronic form and format requested where it is readily producible.
- Further help. Where the Clinic needs VstreamX's help to respond to an Individual's request for access, VstreamX will provide it within 5 business days of the Clinic's written request, so that the Clinic can meet its 30-day period and any shorter state period.
- Requests made to VstreamX. If an Individual asks VstreamX directly, VstreamX will forward the request to the Clinic within 2 business days.
3.9 Amendment (45 C.F.R. § 164.526).
- Self-service. The Services let the Clinic amend or append to PHI in a Designated Record Set.
- Further help. Where VstreamX's help is needed, VstreamX will make the PHI available for amendment, and incorporate any amendment the Clinic directs, within 5 business days of the Clinic's written request.
3.10 Accounting (45 C.F.R. § 164.528).
- What VstreamX records. VstreamX will document Disclosures of PHI that it makes and that would be subject to an accounting.
- Further help. It will provide that information to the Clinic within 5 business days of the Clinic's written request, so that the Clinic can respond to an Individual's request for an accounting of Disclosures.
3.11 Performing the Clinic's obligations. To the extent VstreamX carries out an obligation of the Clinic under Subpart E of 45 C.F.R. Part 164, VstreamX will comply with the requirements of Subpart E that apply to the Clinic in performing that obligation.
3.12 Books and records.
- The Secretary. VstreamX will make its internal practices, books and records relating to the Use and Disclosure of PHI available to the Secretary, for purposes of determining the Clinic's compliance with HIPAA.
- Notice to the Clinic. Unless prohibited by law, VstreamX will notify the Clinic of any such request, and of any other request by a government authority for PHI. It will disclose only the Minimum Necessary.
3.13 US storage.
- Storage at rest. VstreamX stores PHI at rest in the Services' database, file storage, backups, caches it controls, and exports it generates only in Google Cloud data centres located in the United States.
- AI requests. For US Clinics, VstreamX routes requests to the AI features only to the Google Cloud us-central1 region in the United States. [[BLOCKING TO CONFIRM: Vertex AI regional US endpoint live for US Clinics before publication; the code default today is the global endpoint, and until it changes this covenant is not accurate and must not be published]]
- Email. Email to patients, once enabled under section 3.7, is stored by Google Workspace, which may store it outside the United States unless a data-region policy pins it to the United States. For Texas Clinics, Schedule C.1(d) applies.
3.14 Remote access from Canada.
- Where VstreamX's personnel work. VstreamX is a Canadian company. Its personnel administer and support the Services remotely from Canada, using individual accounts with multi-factor authentication.
- No copies outside the US. PHI is not copied to their devices or stored outside the United States, except transiently in the course of an access needed for section 2.1 or 2.3. [[TO CONFIRM: that no PHI is exported to or kept on personnel devices]]
- Lawful under HIPAA. The Clinic acknowledges that such remote access is lawful under HIPAA.
3.15 Security commitments. In addition to Exhibit 1, VstreamX will:
- (a) maintain a written risk analysis and risk management plan for its own environment under 45 C.F.R. § 164.308(a)(1) [[TO CONFIRM: VstreamX's own HIPAA risk analysis completed]];
- (b) require multi-factor authentication for all of its own personnel with access to PHI;
- (c) make multi-factor authentication available to every User of the Clinic, and let the Clinic's owner make it mandatory for the Clinic's owners and managers (Exhibit 1) [[TO CONFIRM: if mandatory MFA for US owners and managers ships before publication, this item may say 'required by default'; it must not say so before]];
- (d) encrypt PHI in transit and at rest;
- (e) provide the Clinic, on request and at least once a year, written verification that it has deployed the technical safeguards required by the Security Rule; and
- (f) adopt any further safeguard required by a final rule amending the Security Rule, within the compliance period that rule allows.
3.16 Workforce. VstreamX will:
- train its workforce members who have access to PHI on HIPAA and this Agreement;
- apply appropriate sanctions to those who violate them; and
- bind them to confidentiality.
4. Obligations of the Clinic
4.1 The Clinic will notify VstreamX of:
- (a) any limitation in its Notice of Privacy Practices, to the extent it may affect VstreamX's Use or Disclosure of PHI;
- (b) any change in, or revocation of, an Individual's permission to Use or Disclose PHI, to the extent it may affect VstreamX; and
- (c) any restriction on the Use or Disclosure of PHI that the Clinic has agreed to under 45 C.F.R. § 164.522, to the extent it may affect VstreamX.
4.2 The Clinic will not ask VstreamX to Use or Disclose PHI in any manner that would not be permissible under Subpart E if done by the Clinic.
4.3 The Clinic will not connect to the Services, or send PHI to, any account or service of its own (such as its own Google account for calendar sync) unless its own agreement with that provider covers PHI. Such services are not VstreamX's Subcontractors.
4.4 The Clinic remains responsible for its own obligations under HIPAA, including its Notice of Privacy Practices, workforce training, risk analysis, and notification of Individuals, the Secretary and the media.
5. Term and termination
5.1 Term. This Agreement takes effect when the Clinic accepts it, and before any PHI is entered. It continues until all PHI has been returned or destroyed under section 5.4.
5.2 Termination by the Clinic.
- Right to terminate. If the Clinic determines that VstreamX has violated a material term of this Agreement, the Clinic may terminate this Agreement and the Terms. Before doing so, it must give VstreamX written notice and 30 days to cure.
- Without a cure period. The Clinic may terminate immediately if cure is not possible.
5.3 Termination by VstreamX. If VstreamX knows of a pattern of activity or practice of the Clinic that constitutes a material breach of its obligations under this Agreement, it may terminate this Agreement and the Terms. It must first give the Clinic written notice and 30 days to cure, unless cure is not possible.
5.4 Return or destruction. On termination, VstreamX will return or destroy all PHI, as follows:
- (a) Return. The Clinic receives a complete export of its data, which is the return of the PHI. The Clinic can export at any time. After the subscription ends, VstreamX keeps the data for 60 days and then prepares the complete export (Terms §§ 13.2–13.4).
- (b) Destruction. VstreamX deletes the PHI within 30 days after 90 days have passed since the subscription ended, or 30 days after the Clinic's written instruction. It tells the Clinic by email at least 30 days before the deletion date (Terms § 8.11).
- (c) What is infeasible to destroy at once. Only copies in database backups. They expire within 7 days of the deletion and are used only to recover from a failure until then. To the extent they remain PHI, VstreamX extends the protections of this Agreement to them, and limits further Uses and Disclosures to the purpose that makes their immediate destruction infeasible.
- File versions. Earlier versions of files in the storage service's version history are destroyed with the rest of the PHI on the deletion date [[TO CONFIRM: automatic removal at the deletion date live; until then VstreamX removes them manually as part of each deletion]].
- Audit trail. The audit trail is returned to the Clinic in the complete export. On the deletion date VstreamX destroys its copy, or keeps only information de-identified to the standard of 45 C.F.R. § 164.514(b), which is not PHI [[TO CONFIRM: product implementation]].
- (d) Certification. On request, VstreamX certifies the destruction in writing.
5.5 Survival. Sections 2.4, 3.1, 3.2, 3.3, 3.12, 5.4, 7 and 9, and any provision that by its nature should survive, survive termination for as long as VstreamX keeps any PHI.
6. Independent contractor
VstreamX performs the Services as an independent contractor. It is not the Clinic's agent under the federal common law of agency, and the Clinic does not control the manner in which VstreamX performs the Services.
7. Relationship to the Terms; liability
7.1 Precedence. For PHI, this Agreement prevails over the Terms and over any other agreement between the Parties. The DentalX Master Data Processing Agreement does not apply to US Clinics.
7.2 Liability. Each Party's liability under this Agreement is subject to Section 18 of the Terms, except that nothing in the Terms limits:
- (a) VstreamX's liability for a Use or Disclosure of PHI that section 2 does not permit, made for VstreamX's own purposes or through its wilful misconduct; or
- (b) any liability that applicable law does not allow to be limited.
[[TO CONFIRM: owner decision on whether VstreamX reimburses the Clinic's reasonable costs of Breach notification caused by VstreamX, and whether inside or above the Terms cap (e.g. a separate data-breach cap)]]
7.3 Indemnities. The indemnities in Section 19 of the Terms apply.
8. Amendment and interpretation
8.1 Changes in law. The Parties will amend this Agreement as needed for either of them to comply with any change in HIPAA or in the state laws in the Schedules. VstreamX proposes such an amendment as a new version under section 8.2. A provision that conflicts with HIPAA is read to comply with HIPAA.
8.2 New versions. VstreamX gives the Clinic at least 30 days' notice of a new version that changes the Parties' rights or obligations, unless the law requires an earlier effective date. The Clinic accepts it in the Services.
- Until the Clinic accepts. If the Clinic has not accepted the new version by its effective date, the Clinic's access to features that create or change PHI is restricted until it does. The Clinic can still export its data.
- Clarifications. Clarifications that do not change rights or obligations take effect on publication.
8.3 Interpretation. Any ambiguity is resolved to permit the Parties to comply with HIPAA. A reference to a section of HIPAA is to that section as in effect or as amended.
8.4 No third-party beneficiaries. Nothing in this Agreement confers any right or remedy on any person other than the Parties.
9. Governing law and courts
9.1 Governing law.
- Federal law first. This Agreement is governed by federal law where federal law applies.
- State law otherwise. Otherwise it is governed by the law of the state in which the Clinic's principal place of practice is located («State»), without regard to its conflict-of-laws rules.
- Manitoba law does not govern this Agreement. Section 23 of the Terms does not apply to it.
9.2 Courts. The state and federal courts located in that state have jurisdiction over disputes under this Agreement.
10. Formation, signature and notices
10.1 Electronic acceptance.
- How the Agreement is formed. The Clinic's authorised signatory accepts this Agreement electronically in the Services. VstreamX accepts it in advance: the electronic signature of its authorised officer appears on the acceptance certificate.
- A written agreement signed by both. The Parties agree that the electronic acceptance record is a written agreement signed by both Parties, under the Electronic Signatures in Global and National Commerce Act (15 U.S.C. § 7001) and the state's Uniform Electronic Transactions Act or equivalent law. This satisfies the requirement of a written contract under 45 C.F.R. § 164.504(e), and the Terms' requirement of a Business Associate Agreement "signed by both".
10.2 Authority. The person who accepts for the Clinic represents and warrants that they are authorised to bind the Clinic, and that the classification the Clinic gave at signup is accurate.
10.3 Executed copy. VstreamX emails the executed copy, with an acceptance certificate, to the signatory and to the Clinic's owner address. It keeps the copy and the acceptance record for at least six years after this Agreement was last in effect.
10.4 Notices. Notices are given as Section 22 of the Terms provides. Breach and Security Incident reports go to the Clinic's owner email and its privacy official recorded in the Services, and also appear in the Services. Notices to VstreamX go to admin@vstreamx.com and to its registered office. [[TO CONFIRM: a dedicated privacy/HIPAA notice address]]
Exhibit 1 — Safeguards
The technical and organisational safeguards are those in Schedule 2 of the DentalX Master Data Processing Agreement, incorporated here for US Clinics. In summary:
- Encryption. TLS in transit; Google encryption at rest; AES-256-GCM field encryption of the patient record's name, date of birth, telephone, address, emergency contact, medical history and insurance details, and of consent forms and prescriptions; key held in Google Secret Manager with restricted access.
- Access. Deny-by-default tenant isolation; role-based access; individual logins; multi-factor authentication available to every User, which the Clinic's owner can make mandatory for owners and managers; automatic sign-out after 8 hours of inactivity; expiring links and single-use consent links.
- Logging and backups. Audit trail of chart openings, exports, deletions and changes, kept 7 years while the account is active and returned in the export at the end (section 5.4(c)); daily backups, 7 days of retention and 7 days of point-in-time recovery.
- Development. Dependency audit before every production deployment; Content-Security-Policy; no analytics or advertising tools.
- Features off for US Clinics. WhatsApp messaging (blocked by the server), AI analysis of radiographs and dictation; and email to patients until the Google Workspace business associate agreement covers the sending account.
Exhibit 2 — Subcontractors (PHI)
| Subcontractor | Service | PHI | Location | BAA |
|---|---|---|---|---|
| Google LLC: Google Cloud / Firebase (Firestore, Cloud Storage, Cloud Functions; sign-in via Identity Platform [[TO CONFIRM: that the project runs on Identity Platform, which Google lists as a covered service]]) | Hosting, database, storage, functions, backups | All PHI | United States | Google Cloud BAA, covered services only |
| Google LLC: Vertex AI | AI features | Content of AI requests | United States: us-central1 [[BLOCKING TO CONFIRM: regional US endpoint live]] | Google Cloud BAA, covered services only |
| Google LLC: Google Workspace (Gmail) | Email to patients | Recipient address and message | United States and the other countries where Google stores Workspace data; Texas: United States only, by data-region policy (Schedule C.1(d)) | [[BLOCKING TO CONFIRM: Google Workspace BAA accepted for the sending account, which must be a Google Workspace account, never consumer Gmail. Until then DentalX sends no email to the patients of US Clinics; links instead of attachments do not cure this]] |
Not Subcontractors for PHI: Meta (WhatsApp is off for US Clinics), Google reCAPTCHA (PHI-free pages only) and Stripe (billing only).