Business Associate Agreement (BAA), Terms of Use, and Privacy Policy -
Barnabus Inc.

Business Associate
Agreement (BAA)

Effective Date

Aug 27, 2025

A Living System, Not a Static Platform

This Business Associate Agreement ("Agreement") is entered into by and between Barnabus Inc., a corporation incorporated in Ontario, Canada under provincial and federal law ("Business Associate" or "Barnabus"), and the applicable healthcare provider, organization, or licensed professional ("Covered Entity").
This Agreement is incorporated into and forms part of the Barnabus Terms of Use. It governs how Barnabus handles Protected Health Information ("PHI") and Electronic Protected Health Information ("ePHI") in accordance with:

circle check

The Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as amended

circle check

The Health Information Technology for Economic and Clinical Health Act ("HITECH"),

circle check

And applicable Canadian privacy laws, including but not limited to PIPEDA, PHIPA (Ontario), and other provincial acts.

Purpose

Barnabus provides AI-powered services that may involve creating, receiving, maintaining, or transmitting PHI for clinical decision support, diagnostics, workflow automation, or research. This Agreement ensures compliance with HIPAA and Canadian laws and defines the mutual obligations for safeguarding PHI.

Definitions

Terms such as "Protected Health Information (PHI)," "Electronic PHI (ePHI)," "Individual," "Subcontractor," "Use," and "Disclosure" have the meanings set forth in 45 C.F.R. §160.103 and applicable Canadian privacy law.

Obligations of Barnabus (Business Associate)

Barnabus agrees to:

circle check

Use or disclose PHI only as permitted by this Agreement or as Required by Law.

circle check

Implement appropriate administrative, technical, and physical safeguards to protect ePHI in accordance with 45 C.F.R. §164 Subpart C and equivalent Canadian standards.

circle check

Report to Covered Entity any breach, unauthorized use, or security incident involving PHI within 10 business days of discovery.

circle check

Notify Covered Entity of any attempted but unsuccessful security incidents.

circle check

Ensure that subcontractors with PHI access enter into agreements with obligations no less stringent than this Agreement.

circle check

Make PHI available to Covered Entity to meet access or amendment obligations under HIPAA and applicable Canadian regulations.

circle check

Refer any individual requests for PHI access or changes directly to Covered Entity unless otherwise instructed in writing.

circle check

Cooperate with audits by the U.S. Secretary of Health and Human Services or Canadian regulators.

Permitted Uses and Disclosures

Barnabus may:

circle check

Use PHI to provide services under its Terms of Use.

circle check

Use PHI for its internal operations, legal compliance, or de-identification (in accordance with HIPAA §164.514 and Canadian anonymization standards).

circle check

Disclose PHI as Required by Law.

circle check

Use PHI for Data Aggregation related to healthcare operations.

circle check

Share PHI with authorized subcontractors under appropriate agreements.

Additional Canadian-Specific Commitments

Barnabus agrees to:

circle check

Comply with PIPEDA, PHIPA (Ontario), and other applicable provincial legislation where PHI is collected, used, or disclosed.

circle check

Address any conflicts between HIPAA and Canadian law by applying the most protective standard.

circle check

Disclose PHI as Required by Law.

circle check

Use PHI for Data Aggregation related to healthcare operations.

circle check

Share PHI with authorized subcontractors under appropriate agreements.

Data Residency and Cross-Border Transfers

Covered Entity acknowledges that Barnabus may use secure cloud infrastructure located in the United States, Canada, or other approved jurisdictions. All cross-border transfers of PHI shall be encrypted and governed by appropriate contractual and technical safeguards.

Subcontractor Accountability

Barnabus remains directly responsible for its subcontractors’ handling of PHI and shall require them to:

circle check

Enter written agreements with equivalent privacy and security obligations.

circle check

Notify Barnabus of any security incident or breach related to Covered Entity’s PHI.

Breach Notification and Incident Handling

circle check

Barnabus will notify Covered Entity of any confirmed breach or material incident involving PHI within 10 business days.

circle check

Where full impact assessment is delayed, Barnabus will provide an initial notice and issue updates as more details become available.

Liability Limitation

Except in cases of gross negligence or willful misconduct, Barnabus’s total liability under this Agreement is limited to the total amount paid by Covered Entity for services in the twelve (12) months preceding any claim.

Right to Audit

Covered Entity may, no more than once annually and with reasonable advance notice, request evidence of Barnabus’s HIPAA and Canadian privacy compliance. Barnabus may provide:

circle check

Summaries of third-party security assessments (e.g., SOC 2, ISO 27001),

circle check

Documentation of internal safeguards,

circle check

Annual risk audit summaries, All subject to a mutually agreed non-disclosure agreement or standard confidentiality protections.

Term & Termination

Covered Entity shall:

circle check

Effective Date: Upon activation of Covered Entity’s Barnabus account.

circle check

Termination for Cause: Either party may terminate this Agreement with 30 days’ notice upon a material breach.

circle check

Post-Termination:
• Barnabus will retain only PHI needed for legal or operational purposes.
• Return or securely destroy remaining PHI where feasible.
• Maintain protections and restrict use of retained PHI.

Miscellaneous

circle check

Governing Law: Laws of Ontario, Canada, unless overridden by applicable federal privacy laws or HIPAA.

circle check

Dispute Resolution: Any dispute shall be resolved via binding arbitration under the rules of JAMS, with hearings held in a mutually agreed location.

circle check

Amendments: May be modified to reflect legal changes or regulatory updates.

circle check

Severability: If a provision is found unenforceable, the remainder shall still apply.

circle check

No Third-Party Rights: This Agreement benefits only Barnabus and the Covered Entity.

Acceptance

By registering for and using Barnabus services, the Covered Entity agrees to the terms of this Business Associate Agreement.

© 2016 - 2026 Barnabus. All rights reserved.