Business Associate Agreement

Version 1. Effective .

Permanent address of version 1: https://toposphora.com/legal/baa-v1.html

About this agreement

Toposphora signs a Business Associate Agreement with customers who need one. You need this agreement if you are a HIPAA covered entity or business associate and you will put protected health information into Toposphora. To ask for it, email legal@toposphora.com with your account email, your legal name, and whether you are a covered entity or a business associate. This agreement has no effect until we confirm in writing that it is in effect for your account.

1. Definitions

1.1 In this Business Associate Agreement (BAA), “we”, “us” and “our” mean Toposphora LLC. “You” means the customer named in our written confirmation under Section 2.

1.2 HIPAA Rules means the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164.

1.3 These words have the meanings given in the HIPAA Rules: Breach, Business Associate, Covered Entity, Data Aggregation, Designated Record Set, Individual, Minimum Necessary, Required by Law, Secretary, Security Incident, Subcontractor and Unsecured Protected Health Information. The words “use” and “disclose”, in any form, have the meanings given in 45 CFR 160.103.

1.4 Covered Services and Excluded Services have the meanings given in Section 3.

1.5 PHI means protected health information, as defined in 45 CFR 160.103, that we create, receive, maintain or transmit for you through the Covered Services.

1.6 Terms means the Toposphora Terms of Service that apply to your account.

2. The parties and when this BAA takes effect

2.1 The parties to this BAA are Toposphora LLC, a Mississippi limited liability company, and you. This BAA adds to the Terms.

2.2 If you are a Covered Entity, we are your Business Associate. If you are a Business Associate, we are your Subcontractor, and so a Business Associate as well, and our reports and duties under this BAA run to you. In either case, this BAA is the written agreement between you and us that 45 CFR 164.502(e), 164.504(e), 164.308(b) and 164.314(a) require.

2.3 You may ask for this BAA on any plan, including a trial. You may ask on any practice profile: expert witness, attorney, or Toposphora Core. There is no charge.

2.4 To ask, email legal@toposphora.com. Give your account email, your legal name, and whether you are a Covered Entity or a Business Associate. Do not put PHI in the email. The person who asks confirms that they may bind you. By asking, you agree to the version of this BAA published on the day you ask. Our confirmation names that version.

2.5 This BAA takes effect on the date in our written confirmation. The confirmation names the version of this BAA and the date it takes effect for you. With the confirmation we send a copy of this BAA signed for Toposphora LLC. Neither party will deny the effect of this BAA because it was formed by email or signed electronically.

2.6 If you are a Covered Entity or a Business Associate, do not put PHI into Toposphora before this BAA takes effect for you.

3. Covered Services and Excluded Services

3.1 Covered Services. “Covered Services” means the Toposphora workspace at app.toposphora.com, its API, and its iOS app. This includes file and record storage, inbound email capture at your workspace’s intake address, share-link uploads, filing from the Outlook add-in and the Gmail add-on from the moment a message reaches our servers, AI features, text extraction, malware scanning, the help assistant, and backups.

3.2 Excluded Services. The following are not Covered Services, and this BAA does not apply to them:

  • (a) email that you, or anyone using your account, send from Toposphora, including messages, replies and the text they quote, templates, and notices sent at your request, until we tell you in writing that outbound email runs on a provider that has signed a business associate agreement with us;
  • (b) electronic signature, including agreements and other documents sent for signature;
  • (c) payments, invoices, payment links, time-entry descriptions that appear on invoices, the AI Wallet, and subscription billing;
  • (d) what your own email, calendar or other providers receive, hold or display, including content that the Outlook add-in or the Gmail add-on shows inside an email client, and entries that a calendar application reads from the Toposphora calendar feed; and
  • (e) communications that you send to us outside the Covered Services, such as email to our support or legal addresses, and messages sent through the app’s support form.

3.3 You will not put PHI into the Excluded Services in 3.2(a), (b), (c) and (e). We will keep showing our cautions where you write email, templates, invoices and time entries. Every invoice also shows the matter’s reference number and title, and the name on its Attn line. Keep PHI out of the title of any matter that you invoice. While this BAA is in effect, replies sent from your account do not quote the earlier email.

3.4 Disclosures you direct. When you, or anyone using your account, send, share, export, download or sync information to a person or system outside Toposphora, that is your disclosure. This includes files that a person views or downloads through a share link you send. Our obligations under this BAA for that copy end when we deliver it.

4. How we may use and disclose PHI

4.1 We may use and disclose PHI only:

  • (a) to provide the Covered Services under the Terms and as you direct;
  • (b) as Required by Law; and
  • (c) for our proper management and administration, and to carry out our legal responsibilities, as 45 CFR 164.504(e)(4) allows.

4.2 We may disclose PHI under 4.1(c) only in two cases. The first is when the law requires the disclosure. The second is when the recipient gives us reasonable assurance of three things: it will keep the PHI confidential, it will use or disclose the PHI only as the law requires or for the purpose of the disclosure, and it will tell us of any breach of that confidentiality it learns of.

4.3 We will not use or disclose PHI in a way that would break Subpart E of 45 CFR Part 164 if you did it, except as 4.1(c) allows.

4.4 We will not de-identify PHI for our own use. We will not provide Data Aggregation services. We will not sell PHI, use it for marketing, or use it to train AI models.

4.5 We limit our own uses and disclosures of PHI, and our requests for it, to the Minimum Necessary. Our personnel access PHI only to give support that you ask for, to keep the Covered Services secure or investigate abuse of them, or as Required by Law.

4.6 If we receive a subpoena, court order or other legal demand for PHI, we will tell you before we disclose PHI, unless the law forbids it.

4.7 We do not carry out any of your obligations under Subpart E of 45 CFR Part 164. If we agree in writing to carry one out, we will comply with the requirements of Subpart E that apply to you when we do it.

5. Safeguards

5.1 We will use appropriate administrative, physical and technical safeguards to prevent any use or disclosure of PHI that this BAA does not allow. For electronic PHI, we will comply with Subpart C of 45 CFR Part 164 (the Security Rule).

5.2 We encrypt PHI in transit and at rest.

5.3 We store and process PHI in the Covered Services only in the United States.

5.4 This BAA gives no audit rights. On request, we will give you a written summary of our safeguards.

6. Reports of incidents and Breaches

6.1 Breach. We will notify you of a Breach of Unsecured Protected Health Information without unreasonable delay, and no later than 5 business days after we discover it. “Discover” has the meaning in 45 CFR 164.410(a)(2). The first notice gives the facts we know then. We will add the information that 45 CFR 164.410(c) requires as we learn it, and in every case within 60 calendar days after discovery. That information includes, as far as we can, each Individual whose PHI was involved.

6.2 Security Incidents. We will report a successful Security Incident to you within 5 business days after we discover it.

6.3 Other uses and disclosures. We will report any other use or disclosure of PHI that this BAA does not allow within 5 business days after we discover it.

6.4 Unsuccessful attempts. This BAA is our notice to you, now and for the future, of unsuccessful Security Incidents. These include pings, port scans, blocked sign-in attempts, and denial-of-service attempts that do not result in unauthorized access to PHI. We will not report them further.

6.5 We will take reasonable steps to limit any harmful effect of a use or disclosure that this BAA does not allow.

6.6 We will not notify Individuals, the Secretary or the media for you unless both parties agree in writing.

6.7 We send these reports as Section 16 provides.

7. Subcontractors

7.1 We will ensure that each Subcontractor that creates, receives, maintains or transmits PHI for us agrees in writing to the same restrictions, conditions and requirements that apply to us under this BAA.

7.2 Amazon Web Services hosts, stores and processes PHI in the Covered Services for us. This includes the AI features, which run on Amazon Bedrock. Amazon Web Services does this work under its business associate agreement with us.

7.3 We will give you 30 days’ notice by email before a new Subcontractor holds PHI. On request, we will give you a list of the Subcontractors that hold PHI. If you object to a new Subcontractor, you may end this BAA under 11.4.

8. Access, amendment and accounting

8.1 You can open, download, change and delete PHI in the Covered Services yourself. You can also ask for an export of your workspace under Section 12. This lets you meet your duties under 45 CFR 164.524 (access) and 164.526 (amendment) for PHI in a Designated Record Set.

8.2 If you need a change to PHI that you cannot make yourself in the Covered Services, we will make it at your written direction.

8.3 If an Individual asks us directly for access, amendment or an accounting of disclosures, we will send the request to you within 10 business days. You answer the Individual.

8.4 We will record each disclosure of PHI that we make ourselves and that 45 CFR 164.528 requires you to account for. When you ask, we will promptly give you that record, so you can meet 45 CFR 164.528.

9. Books and records

9.1 We will make our internal practices, books and records about the use and disclosure of PHI available to the Secretary. The Secretary may use them to decide whether you and we comply with the HIPAA Rules.

10. Your duties

10.1 You will:

  • (a) tell us of any restriction on, or change to, an Individual’s permission to use or disclose PHI, and of any limit in your notice of privacy practices, to the extent it affects what we may do with PHI;
  • (b) not ask us to use or disclose PHI in a way that would break Subpart E of 45 CFR Part 164 if you did it, except as 4.1(c) allows;
  • (c) make only lawful requests of us;
  • (d) have the right, under the HIPAA Rules and every agreement that binds you, to put PHI into the Covered Services and to have us process it as this BAA allows;
  • (e) if you are a Business Associate, hold an agreement with the Covered Entity or Business Associate that engaged you that lets you use a Subcontractor for this work;
  • (f) configure and use the Covered Services properly, which includes keeping your sign-in details secure, controlling who can use your account, choosing who receives your share links and when they expire, and revoking share links you no longer need;
  • (g) not put PHI into the Excluded Services in 3.2(a), (b), (c) and (e); and
  • (h) have your own business associate agreement with any email, calendar or other provider that you use for PHI with the Outlook add-in, the Gmail add-on or the calendar feed. Google states that its business associate agreement does not cover add-ons. Neither that agreement nor this BAA covers what the Gmail add-on shows in Gmail.

11. Term and termination

11.1 This BAA lasts from its effective date until we delete your workspace under Section 12, unless it ends earlier under 11.2, 11.3 or 11.4.

11.2 If we break a material term of this BAA and do not cure it within 30 days after your written notice, you may terminate this BAA and close your account under the Terms.

11.3 If you break a material term of this BAA and do not cure it within 30 days after our written notice, we may terminate this BAA.

11.4 You may also end this BAA by written notice if you object to a new Subcontractor under 7.3 or to a new version of this BAA under 15.2.

11.5 If this BAA ends while your workspace still exists, you will stop putting PHI into the Covered Services. Within 30 days after this BAA ends, you will delete the PHI from your workspace and tell us in writing that you have done so. If you do not, your access ends on the 30th day, and that day is the end date under 12.2. Section 12 then applies, and we will delete the workspace under 12.4. Until the PHI is deleted, this BAA keeps protecting it. Ending this BAA never lets us withhold PHI from you.

12. Return and destruction of PHI

12.1 While you can open your workspace, you can download PHI from the Covered Services yourself. You can also ask us for a complete export of your workspace, from inside the app or by email to support@toposphora.com.

12.2 When your subscription, or complimentary access under the Terms, ends for any reason, you can no longer open the workspace. Its share links and its intake address stop working. We keep the workspace for three months from the end date (the retention period). You may return by subscribing again during the retention period. You may ask in writing to extend the retention period. We extend it only when you ask.

12.3 During the retention period, you may ask by email to support@toposphora.com for a complete export of your workspace. We will deliver it within 10 business days, at no charge. If we suspend your access under the Terms, you may ask for an export in the same way. We will not withhold PHI to settle a payment dispute.

12.4 When the retention period ends, we will delete the workspace permanently. We will do so earlier if you ask us to delete your account, from inside the app or by email to support@toposphora.com. The deletion removes the workspace’s records and files, including earlier versions of the files. After it, we keep no copy of PHI except as 12.5 states.

12.5 Copies of PHI in backups, logs, export files and other temporary copies are removed on their normal schedules. We set those schedules so that such copies are removed within 90 days after we delete the workspace. Security audit logs are the exception: they can hold file names, and we keep them for as long as we keep audit records. Until then, return or destruction of those copies is not feasible. The same applies to any copy that the law requires us to keep. For each such copy, we will extend the protections of this BAA to it, and we will use or disclose it only for the purposes that make its return or destruction not feasible.

12.6 This Section survives the end of this BAA.

13. Limits on liability

13.1 Each party’s liability under this BAA is subject to the limitation of liability and the exclusion of indirect and consequential damages in section 23 of the Terms, including the exceptions that section states. Claims under this BAA and claims under the Terms share one limit. This BAA creates no indemnity by us.

14. Order of precedence

14.1 If this BAA conflicts with the Terms, the Privacy Notice, or any other Toposphora document about PHI, this BAA controls. In all other respects the Terms apply.

14.2 This BAA and our written confirmation are the whole agreement of the parties about PHI. They replace any other business associate terms that you send us, unless we sign those terms.

15. Changes

15.1 If a change in the HIPAA Rules requires a change to this BAA, both parties will amend it to comply.

15.2 We may publish a new version of this BAA at toposphora.com/baa.html. A new version applies to new requests from the day we publish it. For an existing BAA, it takes effect 30 days after we send you notice of it, or sooner if the law requires. If you do not agree to it, you may end this BAA by written notice before it takes effect.

15.3 No other change to this BAA is effective unless both parties agree in writing.

15.4 A reference in this BAA to a section of the HIPAA Rules means that section as in effect or as amended. Any unclear term in this BAA is read to permit compliance with the HIPAA Rules.

16. Notices

16.1 Send notices to us by email to legal@toposphora.com, or by mail to Toposphora LLC, 1220 Northside Dr., Ste 170, PMB #176, Jackson, MS 39211.

16.2 We send notices and reports to you by email. We use the account holder’s email address on file and any notice address you give in your request. You will keep these addresses current.

16.3 Notices in either direction must not contain PHI, except the information that 45 CFR 164.410(c) requires in our Breach notices. Do not send PHI to our support, legal or other contact addresses. This does not apply to your workspace’s intake address, which is part of the Covered Services.

16.4 An email notice is given when it is sent to the right address, unless the sender learns that it was not delivered.

17. General terms

17.1 Nothing in this BAA gives any right or remedy to anyone other than you and us.

17.2 Mississippi law governs this BAA, except where federal law governs. Sections 25, 26 and 27 of the Terms, including where a claim may be brought and the jury trial and class action waivers, apply to any dispute about this BAA.

17.3 Sections 12, 13, 16 and 17, and any other term that by its nature should continue, survive the end of this BAA.

Contact Toposphora

Ask a question or request access. We’ll reply by email.

Human verification