BUSINESS ASSOCIATE AGREEMENT
Omi Health B.V. -- Version 2.0 -- Effective date: 5 August 2026
This page publishes the standard text of the Omi Business Associate
Agreement. The published text is informational. A BAA takes effect only
when it is executed through the Omi console. The console generates the
completed agreement with Customer's legal-entity details, the recorded
capacity of Customer, the signatures, the document version and SHA-256
hash, and the UTC execution time. Customer changes to this text are not
accepted unless separately agreed in writing.
1. PARTIES, CAPACITY, AND DEFINITIONS
1.1 Parties. This Business Associate Agreement ("BAA") is between Omi
Health B.V., a company registered in the Netherlands,
with its seat in Eindhoven, the Netherlands ("Business Associate"), and
the customer executing it through the Omi console ("Customer"). It
applies to the speech-to-text services Business Associate provides to
Customer under the underlying service terms (the "Service").
1.2 Capacity. At execution, Customer records whether it enters into
this BAA as a Covered Entity or as a Business Associate of one or more
Covered Entities. Where Customer is itself a Business Associate, this
BAA is the subcontractor agreement required by 45 CFR 164.502(e)(1)(ii)
and 164.308(b)(2), and its requirements apply under 45 CFR 164.504(e)(5)
in the same manner as between a Covered Entity and a Business
Associate. References in this BAA to obligations of a Covered Entity
then refer to Customer's obligations to its upstream Covered Entity.
1.3 Definitions. The following terms used in this BAA have the same
meaning as in the HIPAA Rules: Breach, Data Aggregation, Designated
Record Set, Disclosure, Health Care Operations, Individual, Minimum
Necessary, Notice of Privacy Practices, Protected Health Information,
Required By Law, Secretary, Security Incident, Subcontractor, Unsecured
Protected Health Information, and Use. "HIPAA Rules" means the Privacy,
Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160
and Part 164. "PHI" means Protected Health Information that Business
Associate creates, receives, maintains, or transmits for or on behalf
of Customer through the Service. "Job Content" means submitted audio,
job-scoped custom vocabulary and job options, and the transcripts and
results generated from them.
2. PERMITTED USES AND DISCLOSURES
2.1 Service provision. Business Associate may use or disclose PHI only
as necessary to provide the Service under the underlying service terms:
to process submitted audio, return transcripts and results, and operate
and secure the Service.
2.2 Required By Law. Business Associate may use or disclose PHI as
Required By Law.
2.3 Management and administration. Business Associate may use PHI as
necessary for its proper management and administration or to carry out
its legal responsibilities. Business Associate may disclose PHI for
those purposes only if the disclosure is Required By Law, or if
Business Associate obtains reasonable assurances from the recipient
that the information will be held confidentially, will be used or
further disclosed only as Required By Law or for the purposes for which
it was disclosed, and that the recipient will notify Business Associate
of any instance of which it is aware in which the confidentiality of
the information has been breached.
2.4 Minimum Necessary. Business Associate limits its uses, disclosures,
and requests of PHI to the Minimum Necessary. By architecture, Job
Content is processed transiently to produce the requested transcript
and is not otherwise accessed; human access occurs only for security or
abuse investigation, under role-based access control, and is logged.
2.5 Prohibited uses. Except as permitted by Sections 2.2 and 2.3,
Business Associate will not use or disclose PHI in a manner that would
violate Subpart E of 45 CFR Part 164 if done by Customer. Business
Associate will not: de-identify PHI for any independent use; aggregate
PHI beyond operation of the Service; provide Data Aggregation services;
sell PHI; use PHI for marketing; or use PHI to train, fine-tune, or
evaluate any model.
3. OBLIGATIONS OF BUSINESS ASSOCIATE
3.1 No impermissible use or disclosure. Business Associate will not use
or disclose PHI other than as permitted or required by this BAA or as
Required By Law.
3.2 Safeguards. Business Associate will use appropriate safeguards, and
will comply with Subpart C of 45 CFR Part 164 with respect to
electronic PHI, to prevent use or disclosure of PHI other than as
provided for by this BAA. These safeguards include: encryption in
transit (TLS) and at rest (managed keys); access controls and least
privilege; audit controls through an immutable audit log whose schema
is designed to contain no Job Content; integrity and transmission
security; and a written workforce training and sanctions program.
3.3 Data minimisation and deletion. Submitted audio is deleted
automatically upon completion or terminal failure of processing.
Transcripts from synchronous requests are not stored. Results of
asynchronous requests are stored solely for retrieval and deleted
automatically at the end of the retention period selected by Customer
(1 to 72 hours; default 24 hours). Job-scoped custom vocabulary is
deleted with the job. Content is never written to operational logs or
backups. The retention period selected by Customer is Customer's
documented instruction. Persistent custom vocabulary that Customer
saves to its account outside an individual job is account
configuration, not Job Content: it may contain PHI, it is covered by
this BAA, Customer may delete it in the console at any time, and it is
deleted on account termination. Retention particulars, including the
effective minimum retention for jobs configured with webhook delivery,
are stated in the Service documentation.
3.4 Reporting.
(a) Impermissible uses and disclosures. Business Associate will report
to Customer any use or disclosure of PHI not provided for by this BAA
of which it becomes aware.
(b) Security Incidents. Business Associate will report to Customer any
successful Security Incident of which it becomes aware without
unreasonable delay. The parties acknowledge that unsuccessful attempts
that do not compromise electronic PHI (such as routine scans, pings,
and failed log-in attempts) occur routinely; this Section is notice of
such attempts, and no further reporting of them is required.
(c) Breach of Unsecured PHI. Business Associate will notify Customer of
any Breach of Unsecured PHI. Business Associate will provide an initial
notice within five (5) business days of discovery, based on the
information then known, and will supplement it on a rolling basis as
the investigation proceeds, so that Customer receives the information
required by 45 CFR 164.410. A Breach is treated as discovered as of the
first day on which it is known to Business Associate or, by exercising
reasonable diligence, would have been known to Business Associate,
including knowledge of any person, other than the person committing the
breach, who is a workforce member or agent of Business Associate. If a
law enforcement official states that a notification would impede a
criminal investigation or damage national security, notice may be
delayed as provided in 45 CFR 164.412.
3.5 Subcontractors. In accordance with 45 CFR 164.502(e)(1)(ii) and
164.308(b)(2), Business Associate will ensure that any Subcontractor
that creates, receives, maintains, or transmits PHI on behalf of
Business Associate agrees in writing to the same restrictions,
conditions, and requirements that apply to Business Associate with
respect to such information, including compliance with Subpart C of 45
CFR Part 164 for electronic PHI. Current chain: Amazon Web Services,
under a HIPAA business associate agreement accepted through AWS
Artifact; only HIPAA-eligible AWS services are used in the PHI path.
The current subcontractor and sub-processor list, and the mechanism for
at least thirty (30) days' advance notice of changes, are published at
/legal/sub-processors.
3.6 Individual access. To the extent Business Associate maintains PHI
in a Designated Record Set, Business Associate will make that PHI
available to Customer in the time and manner reasonably requested so
that Customer can meet its obligations under 45 CFR 164.524. Because
Job Content is ordinarily returned and deleted under Section 3.3,
Business Associate may hold no responsive PHI when a request is
received; it will promptly confirm that fact. Nothing in this BAA
requires Business Associate to recreate PHI deleted in accordance with
Customer's retention instruction. If an Individual makes a request
directly to Business Associate, Business Associate will forward the
request to Customer within five (5) business days.
3.7 Amendment. To the extent Business Associate maintains PHI in a
Designated Record Set, Business Associate will make that PHI available
for amendment and will incorporate any amendment as directed or agreed
by Customer under 45 CFR 164.526, or will take other measures
reasonably necessary to support Customer's obligations under that
section.
3.8 Accounting of disclosures. Business Associate will maintain and
make available to Customer the information required to provide an
accounting of disclosures under 45 CFR 164.528. Business Associate
records the disclosure metadata required by that section (including
date, recipient, and a description of the PHI and purpose) for any
disclosure outside Section 2.1, retains it for the period required by
law without retaining Job Content, and will provide it to Customer in
the time and manner reasonably requested.
3.9 Delegated obligations. To the extent Business Associate is to carry
out one or more of Customer's obligations under Subpart E of 45 CFR
Part 164, Business Associate will comply with the requirements of
Subpart E that apply to Customer in the performance of such
obligations.
3.10 Access by the Secretary. Business Associate will make its internal
practices, books, and records relating to the use and disclosure of PHI
available to the Secretary for purposes of determining compliance with
the HIPAA Rules.
4. CUSTOMER OBLIGATIONS
4.1 Notice of restrictions. Customer will notify Business Associate of
any limitation in its Notice of Privacy Practices, any change in or
revocation of an Individual's permission, and any restriction agreed to
or required under 45 CFR 164.522, in each case to the extent it may
affect Business Associate's use or disclosure of PHI.
4.2 Permissible requests. Customer will not request Business Associate
to use or disclose PHI in any manner that would not be permissible
under Subpart E of 45 CFR Part 164 if done by Customer, except as
permitted for Business Associate's management and administration under
Section 2.3.
4.3 Customer responsibilities. Customer remains responsible for its own
obligations under the HIPAA Rules, for not submitting PHI through the
Service before this BAA is executed, and for retrieving results within
the retention period it selects.
5. TERM AND TERMINATION
5.1 Term. This BAA is effective when its execution is confirmed in the
console and continues until the underlying Service relationship between
the parties terminates.
5.2 Termination for cause. Customer may terminate this BAA and the
affected Service if Business Associate has violated a material term of
this BAA and has not cured the violation within a reasonable period
specified by Customer, or immediately if cure is not possible or
immediate termination is reasonably necessary.
5.3 Return or destruction. At termination of this BAA for any reason,
Business Associate will, if feasible and as directed by Customer,
return or destroy all PHI received from Customer, or created,
maintained, or received by Business Associate on behalf of Customer,
that Business Associate or its Subcontractors still maintain in any
form, and will retain no copies. Retrieval of results through the API
before termination constitutes return of Job Content. Any remaining Job
Content is destroyed by the standing deletion mechanics in Section 3.3,
and in no event later than the end of the retention period selected by
Customer. Persistent custom vocabulary is deleted on account
termination under Section 3.3. Written confirmation of destruction is
available on request. If return or destruction of particular PHI is
infeasible, Business Associate will notify Customer of the PHI
concerned and the conditions that make return or destruction
infeasible, will extend the protections of this BAA to that PHI, and
will limit further uses and disclosures to those purposes that make its
return or destruction infeasible, for so long as it is maintained.
5.4 Survival. The obligations of Business Associate under Section 5.3
survive termination of this BAA.
6. MISCELLANEOUS
6.1 Regulatory references. A reference in this BAA to a section in the
HIPAA Rules means the section as in effect or as amended.
6.2 Amendment. This BAA may be amended only by written or electronic
agreement of the parties. Where an amendment is reasonably necessary
for compliance with the HIPAA Rules or other applicable law, Business
Associate may issue an updated version with notice to Customer;
Customer may terminate the affected Service before a materially adverse
change takes effect. The parties agree to take such action as is
necessary to amend this BAA from time to time as required for
compliance with the HIPAA Rules.
6.3 Interpretation. Any ambiguity in this BAA shall be interpreted to
permit compliance with the HIPAA Rules.
6.4 Governing law; HIPAA. This BAA is governed by the law of the
Netherlands, as provided in the underlying service terms. HIPAA and the
HIPAA Rules govern the interpretation of the duties this BAA defines by
reference to them, and nothing in this BAA limits the enforcement
authority of the U.S. Department of Health and Human Services.
6.5 No third-party beneficiaries. Nothing in this BAA confers any right
or remedy on any person other than the parties and their permitted
successors and assigns.
6.6 Precedence. For the use and disclosure of PHI, this BAA prevails
over any conflicting term of the underlying service terms.
END OF STANDARD TEXT. The console-generated executed copy appends:
Customer legal name, registered address, and jurisdiction; Customer's
recorded capacity (Covered Entity or Business Associate); signatory
name, title, and email; the authority representation; this document's
version and SHA-256 hash; and the UTC execution timestamp.