HIPAA business associate terms for Covered Entities using Parsedit with PHI.
Last updated: August 19, 2026
Status: Counsel-reviewable draft. Not legal advice. Not a public claim that Parsedit or Cauldrn LLC is “HIPAA compliant.” The agreement is effective for a customer only after the account owner acknowledges it in-app (OTP) and hipaa_baa_signed_at is recorded.
This Business Associate Agreement (“BAA”) is between Cauldrn LLC (“Business Associate”) and the Covered Entity or Business Associate customer that executes it (“Covered Entity”). It supplements the Terms of Service and applies only to Protected Health Information (“PHI”) the Covered Entity uploads to Parsedit.
A BAA does not replace the Data Processing Addendum or Standard Contractual Clauses. DataRep (GDPR Art. 27) does not satisfy HIPAA.
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, the HITECH Act, and the Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164). Terms such as PHI, Covered Entity, Business Associate, and Breach have HIPAA meanings.
Business Associate may use or disclose PHI only to:
Business Associate shall not:
Business Associate shall implement administrative, physical, and technical safeguards required of business associates under the Security Rule, including access controls, audit controls (metadata only; no PHI in audit rows), integrity, transmission security, and workforce restrictions. Integration tokens are encrypted (AES-256-GCM). Tenant data is isolated with database row-level security. Files use private buckets and short-lived signed URLs.
Encryption at rest is a Supabase project control; it is not switched on from application code. HIPAA mode additionally requires multi-factor authentication, idle timeout, Extend zero-data-retention (or fail closed), and inbound email off unless a Postmark BAA is documented.
Business Associate shall ensure subcontractors that create, receive, maintain, or transmit PHI on its behalf agree to restrictions and conditions at least as protective as this BAA (HIPAA BAAs or equivalent). Material sub-processors that may see document bytes: Supabase and Extend. Postmark only if inbound email is enabled. Vercel and Sentry shall not be used as PHI repositories; if no BAA exists, PHI is kept out of those logs (scrub / feature-off).
Customer-directed integrations are not Business Associate subcontractors.
Business Associate shall, at Covered Entity’s request and as feasible in the Service, support access, amendment, and accounting of disclosures for PHI in the designated record set it holds (in-app document access, export, and deletion). PHI access is logged (view, download, export, delete, dsar) without storing PHI in the log.
Upon termination of the Service or this BAA, or when PHI is no longer needed for the permitted purposes, Business Associate shall return or destroy PHI in its possession.
Alignment with product retention: document files and extracted fields are destroyed on the plan window (60 days Free/Starter/Growth; 365 days Pro/Business, from document creation), on user delete, and on account deletion (~30 days thereafter for remaining Customer Content), except:
If destruction is infeasible (for example backup rotation), Business Associate shall extend protections and limit uses to those that make destruction infeasible until destruction occurs.
Business Associate shall notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery (45 C.F.R. 164.410), or sooner if this BAA or law requires. Notification shall include, to the extent known: what happened, dates, types of PHI involved, what Business Associate is doing, and contact for questions — without emailing raw medical files.
If GDPR also applies (for example an EU data subject in a US medical PDF), Business Associate will also follow GDPR processor-breach notice to the customer; DataRep is used only for GDPR representative duties.
This BAA is effective on in-app owner acknowledgment and continues until the Agreement ends and PHI is returned or destroyed as §6. Provisions that must survive (including 6-year documentation) survive.
Covered Entity may terminate if Business Associate has breached a material HIPAA obligation and has not cured within a reasonable time after notice, as required by 164.504(e).
This BAA is governed by the same law as the Agreement except where HIPAA requires otherwise. Nothing here makes Cauldrn a Covered Entity. Public marketing shall not state that Parsedit is HIPAA compliant unless Cauldrn’s internal go-live checklist is complete and counsel approves that statement.
Business Associate: Cauldrn LLC, [email protected] / [email protected].