BUSINESS ASSOCIATE AGREEMENT

Omi Health B.V. -- Version 2.0 -- Effective date: 5 August 2026

This page publishes the standard text of the Omi Business Associate

Agreement. The published text is informational. A BAA takes effect only

when it is executed through the Omi console. The console generates the

completed agreement with Customer's legal-entity details, the recorded

capacity of Customer, the signatures, the document version and SHA-256

hash, and the UTC execution time. Customer changes to this text are not

accepted unless separately agreed in writing.

1. PARTIES, CAPACITY, AND DEFINITIONS

1.1 Parties. This Business Associate Agreement ("BAA") is between Omi

Health B.V., a company registered in the Netherlands,

with its seat in Eindhoven, the Netherlands ("Business Associate"), and

the customer executing it through the Omi console ("Customer"). It

applies to the speech-to-text services Business Associate provides to

Customer under the underlying service terms (the "Service").

1.2 Capacity. At execution, Customer records whether it enters into

this BAA as a Covered Entity or as a Business Associate of one or more

Covered Entities. Where Customer is itself a Business Associate, this

BAA is the subcontractor agreement required by 45 CFR 164.502(e)(1)(ii)

and 164.308(b)(2), and its requirements apply under 45 CFR 164.504(e)(5)

in the same manner as between a Covered Entity and a Business

Associate. References in this BAA to obligations of a Covered Entity

then refer to Customer's obligations to its upstream Covered Entity.

1.3 Definitions. The following terms used in this BAA have the same

meaning as in the HIPAA Rules: Breach, Data Aggregation, Designated

Record Set, Disclosure, Health Care Operations, Individual, Minimum

Necessary, Notice of Privacy Practices, Protected Health Information,

Required By Law, Secretary, Security Incident, Subcontractor, Unsecured

Protected Health Information, and Use. "HIPAA Rules" means the Privacy,

Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160

and Part 164. "PHI" means Protected Health Information that Business

Associate creates, receives, maintains, or transmits for or on behalf

of Customer through the Service. "Job Content" means submitted audio,

job-scoped custom vocabulary and job options, and the transcripts and

results generated from them.

2. PERMITTED USES AND DISCLOSURES

2.1 Service provision. Business Associate may use or disclose PHI only

as necessary to provide the Service under the underlying service terms:

to process submitted audio, return transcripts and results, and operate

and secure the Service.

2.2 Required By Law. Business Associate may use or disclose PHI as

Required By Law.

2.3 Management and administration. Business Associate may use PHI as

necessary for its proper management and administration or to carry out

its legal responsibilities. Business Associate may disclose PHI for

those purposes only if the disclosure is Required By Law, or if

Business Associate obtains reasonable assurances from the recipient

that the information will be held confidentially, will be used or

further disclosed only as Required By Law or for the purposes for which

it was disclosed, and that the recipient will notify Business Associate

of any instance of which it is aware in which the confidentiality of

the information has been breached.

2.4 Minimum Necessary. Business Associate limits its uses, disclosures,

and requests of PHI to the Minimum Necessary. By architecture, Job

Content is processed transiently to produce the requested transcript

and is not otherwise accessed; human access occurs only for security or

abuse investigation, under role-based access control, and is logged.

2.5 Prohibited uses. Except as permitted by Sections 2.2 and 2.3,

Business Associate will not use or disclose PHI in a manner that would

violate Subpart E of 45 CFR Part 164 if done by Customer. Business

Associate will not: de-identify PHI for any independent use; aggregate

PHI beyond operation of the Service; provide Data Aggregation services;

sell PHI; use PHI for marketing; or use PHI to train, fine-tune, or

evaluate any model.

3. OBLIGATIONS OF BUSINESS ASSOCIATE

3.1 No impermissible use or disclosure. Business Associate will not use

or disclose PHI other than as permitted or required by this BAA or as

Required By Law.

3.2 Safeguards. Business Associate will use appropriate safeguards, and

will comply with Subpart C of 45 CFR Part 164 with respect to

electronic PHI, to prevent use or disclosure of PHI other than as

provided for by this BAA. These safeguards include: encryption in

transit (TLS) and at rest (managed keys); access controls and least

privilege; audit controls through an immutable audit log whose schema

is designed to contain no Job Content; integrity and transmission

security; and a written workforce training and sanctions program.

3.3 Data minimisation and deletion. Submitted audio is deleted

automatically upon completion or terminal failure of processing.

Transcripts from synchronous requests are not stored. Results of

asynchronous requests are stored solely for retrieval and deleted

automatically at the end of the retention period selected by Customer

(1 to 72 hours; default 24 hours). Job-scoped custom vocabulary is

deleted with the job. Content is never written to operational logs or

backups. The retention period selected by Customer is Customer's

documented instruction. Persistent custom vocabulary that Customer

saves to its account outside an individual job is account

configuration, not Job Content: it may contain PHI, it is covered by

this BAA, Customer may delete it in the console at any time, and it is

deleted on account termination. Retention particulars, including the

effective minimum retention for jobs configured with webhook delivery,

are stated in the Service documentation.

3.4 Reporting.

(a) Impermissible uses and disclosures. Business Associate will report

to Customer any use or disclosure of PHI not provided for by this BAA

of which it becomes aware.

(b) Security Incidents. Business Associate will report to Customer any

successful Security Incident of which it becomes aware without

unreasonable delay. The parties acknowledge that unsuccessful attempts

that do not compromise electronic PHI (such as routine scans, pings,

and failed log-in attempts) occur routinely; this Section is notice of

such attempts, and no further reporting of them is required.

(c) Breach of Unsecured PHI. Business Associate will notify Customer of

any Breach of Unsecured PHI. Business Associate will provide an initial

notice within five (5) business days of discovery, based on the

information then known, and will supplement it on a rolling basis as

the investigation proceeds, so that Customer receives the information

required by 45 CFR 164.410. A Breach is treated as discovered as of the

first day on which it is known to Business Associate or, by exercising

reasonable diligence, would have been known to Business Associate,

including knowledge of any person, other than the person committing the

breach, who is a workforce member or agent of Business Associate. If a

law enforcement official states that a notification would impede a

criminal investigation or damage national security, notice may be

delayed as provided in 45 CFR 164.412.

3.5 Subcontractors. In accordance with 45 CFR 164.502(e)(1)(ii) and

164.308(b)(2), Business Associate will ensure that any Subcontractor

that creates, receives, maintains, or transmits PHI on behalf of

Business Associate agrees in writing to the same restrictions,

conditions, and requirements that apply to Business Associate with

respect to such information, including compliance with Subpart C of 45

CFR Part 164 for electronic PHI. Current chain: Amazon Web Services,

under a HIPAA business associate agreement accepted through AWS

Artifact; only HIPAA-eligible AWS services are used in the PHI path.

The current subcontractor and sub-processor list, and the mechanism for

at least thirty (30) days' advance notice of changes, are published at

/legal/sub-processors.

3.6 Individual access. To the extent Business Associate maintains PHI

in a Designated Record Set, Business Associate will make that PHI

available to Customer in the time and manner reasonably requested so

that Customer can meet its obligations under 45 CFR 164.524. Because

Job Content is ordinarily returned and deleted under Section 3.3,

Business Associate may hold no responsive PHI when a request is

received; it will promptly confirm that fact. Nothing in this BAA

requires Business Associate to recreate PHI deleted in accordance with

Customer's retention instruction. If an Individual makes a request

directly to Business Associate, Business Associate will forward the

request to Customer within five (5) business days.

3.7 Amendment. To the extent Business Associate maintains PHI in a

Designated Record Set, Business Associate will make that PHI available

for amendment and will incorporate any amendment as directed or agreed

by Customer under 45 CFR 164.526, or will take other measures

reasonably necessary to support Customer's obligations under that

section.

3.8 Accounting of disclosures. Business Associate will maintain and

make available to Customer the information required to provide an

accounting of disclosures under 45 CFR 164.528. Business Associate

records the disclosure metadata required by that section (including

date, recipient, and a description of the PHI and purpose) for any

disclosure outside Section 2.1, retains it for the period required by

law without retaining Job Content, and will provide it to Customer in

the time and manner reasonably requested.

3.9 Delegated obligations. To the extent Business Associate is to carry

out one or more of Customer's obligations under Subpart E of 45 CFR

Part 164, Business Associate will comply with the requirements of

Subpart E that apply to Customer in the performance of such

obligations.

3.10 Access by the Secretary. Business Associate will make its internal

practices, books, and records relating to the use and disclosure of PHI

available to the Secretary for purposes of determining compliance with

the HIPAA Rules.

4. CUSTOMER OBLIGATIONS

4.1 Notice of restrictions. Customer will notify Business Associate of

any limitation in its Notice of Privacy Practices, any change in or

revocation of an Individual's permission, and any restriction agreed to

or required under 45 CFR 164.522, in each case to the extent it may

affect Business Associate's use or disclosure of PHI.

4.2 Permissible requests. Customer will not request Business Associate

to use or disclose PHI in any manner that would not be permissible

under Subpart E of 45 CFR Part 164 if done by Customer, except as

permitted for Business Associate's management and administration under

Section 2.3.

4.3 Customer responsibilities. Customer remains responsible for its own

obligations under the HIPAA Rules, for not submitting PHI through the

Service before this BAA is executed, and for retrieving results within

the retention period it selects.

5. TERM AND TERMINATION

5.1 Term. This BAA is effective when its execution is confirmed in the

console and continues until the underlying Service relationship between

the parties terminates.

5.2 Termination for cause. Customer may terminate this BAA and the

affected Service if Business Associate has violated a material term of

this BAA and has not cured the violation within a reasonable period

specified by Customer, or immediately if cure is not possible or

immediate termination is reasonably necessary.

5.3 Return or destruction. At termination of this BAA for any reason,

Business Associate will, if feasible and as directed by Customer,

return or destroy all PHI received from Customer, or created,

maintained, or received by Business Associate on behalf of Customer,

that Business Associate or its Subcontractors still maintain in any

form, and will retain no copies. Retrieval of results through the API

before termination constitutes return of Job Content. Any remaining Job

Content is destroyed by the standing deletion mechanics in Section 3.3,

and in no event later than the end of the retention period selected by

Customer. Persistent custom vocabulary is deleted on account

termination under Section 3.3. Written confirmation of destruction is

available on request. If return or destruction of particular PHI is

infeasible, Business Associate will notify Customer of the PHI

concerned and the conditions that make return or destruction

infeasible, will extend the protections of this BAA to that PHI, and

will limit further uses and disclosures to those purposes that make its

return or destruction infeasible, for so long as it is maintained.

5.4 Survival. The obligations of Business Associate under Section 5.3

survive termination of this BAA.

6. MISCELLANEOUS

6.1 Regulatory references. A reference in this BAA to a section in the

HIPAA Rules means the section as in effect or as amended.

6.2 Amendment. This BAA may be amended only by written or electronic

agreement of the parties. Where an amendment is reasonably necessary

for compliance with the HIPAA Rules or other applicable law, Business

Associate may issue an updated version with notice to Customer;

Customer may terminate the affected Service before a materially adverse

change takes effect. The parties agree to take such action as is

necessary to amend this BAA from time to time as required for

compliance with the HIPAA Rules.

6.3 Interpretation. Any ambiguity in this BAA shall be interpreted to

permit compliance with the HIPAA Rules.

6.4 Governing law; HIPAA. This BAA is governed by the law of the

Netherlands, as provided in the underlying service terms. HIPAA and the

HIPAA Rules govern the interpretation of the duties this BAA defines by

reference to them, and nothing in this BAA limits the enforcement

authority of the U.S. Department of Health and Human Services.

6.5 No third-party beneficiaries. Nothing in this BAA confers any right

or remedy on any person other than the parties and their permitted

successors and assigns.

6.6 Precedence. For the use and disclosure of PHI, this BAA prevails

over any conflicting term of the underlying service terms.

END OF STANDARD TEXT. The console-generated executed copy appends:

Customer legal name, registered address, and jurisdiction; Customer's

recorded capacity (Covered Entity or Business Associate); signatory

name, title, and email; the authority representation; this document's

version and SHA-256 hash; and the UTC execution timestamp.