Orchard← Back to site

Business Associate Agreement

HIPAA · draft · supplements the Data Processing Agreement

Entered into where Orchard creates, receives, maintains or transmits Protected Health Information on behalf of a Customer that is a Covered Entity or a Business Associate. It supplements, and does not replace, the Data Processing Agreement.

This Business Associate Agreement ("BAA") is entered into by and between Enter the Orchard Syndicate, a Delaware corporation with its principal place of business at 2909 Wayzata Blvd, Suite 52608, Minneapolis, MN 55405, USA ("Orchard"); and [CUSTOMER LEGAL ENTITY NAME], [ADDRESS] ("Customer").

Customer is either a Covered Entity, or a Business Associate of one or more Covered Entities. Where Customer is a Business Associate, Orchard acts as its Subcontractor, and every obligation below applies to Orchard as though it were a Business Associate of the Covered Entity, as required by 45 CFR § 164.502(e)(1)(ii). This BAA is incorporated into and governed by the parties' Master Services Agreement and Data Processing Agreement (together, the "Agreement"). Where this BAA and the Agreement conflict with respect to PHI, this BAA controls.

1. Definitions

Capitalised terms not defined here have the meaning given in the HIPAA Rules (45 CFR Parts 160 and 164, as amended, including by the HITECH Act and the 2013 Omnibus Rule).

  • PHI — Protected Health Information, limited to information Orchard creates, receives, maintains or transmits for or on behalf of Customer.
  • ePHI — PHI transmitted by or maintained in electronic media.
  • Captured Activity — the semantic activity data the Orchard watcher records, as defined and bounded in Section 5 of the Data Processing Agreement.
  • Endpoint — a device on which the Orchard watcher is enrolled and running.
  • Subcontractor — a person or entity to whom Orchard delegates a function involving PHI, as defined at 45 CFR § 160.103.

2. Scope — what PHI reaches Orchard

Orchard does not select PHI and does not process it as a subject matter. Any PHI Orchard receives is incidental to observing work performed on an Endpoint, and arrives inside Captured Activity — principally as window titles and as the values of on-screen fields in applications the Endpoint operator is using.

Customer controls the scope. Customer decides which Endpoints are enrolled, which of its clients are subject to observation, and the capture tier applied to each. Those configuration choices determine whether, and how much, PHI reaches Orchard. Orchard has no means of identifying PHI within Captured Activity, and nothing in this BAA obliges it to attempt that identification.

Customer therefore acknowledges that: (a) enrolling an Endpoint whose operator accesses PHI will cause PHI to be transmitted to and maintained by Orchard; (b) reducing the capture tier reduces, but does not reliably eliminate, that transmission, because window titles alone may constitute PHI; and (c) Customer is responsible for determining, before enrollment, whether a given Endpoint falls within the scope of this BAA.

[COUNSEL: CONFIRM WHETHER CUSTOMER WISHES TO SCHEDULE SPECIFIC ENROLLED ENDPOINTS OR CLIENT ENVIRONMENTS AS IN-SCOPE, RATHER THAN TREATING THE WHOLE DEPLOYMENT AS IN-SCOPE.]

3. Permitted uses and disclosures

Orchard may use and disclose PHI only: (a) to perform the services described in the Agreement, and only as necessary to do so; (b) as required by law, provided Orchard notifies Customer before disclosure unless the law prohibits that notice; (c) for the proper management and administration of Orchard, or to carry out its legal responsibilities — and where Orchard discloses PHI for that purpose, only if the disclosure is required by law, or Orchard obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the recipient will notify Orchard of any breach of confidentiality; and (d) to provide data aggregation services relating to the health care operations of Customer, as permitted by 45 CFR § 164.504(e)(2)(i)(B). [DELETE (d) IF CUSTOMER DOES NOT WANT THIS PERMITTED]

Orchard will limit its uses, disclosures and requests of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 CFR § 164.502(b).

4. Prohibited uses and disclosures

Orchard will not use or disclose PHI other than as permitted by Section 3, as required by law, or as Customer directs in writing. Orchard will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Customer, except as permitted at § 164.504(e)(2)(i)(A). Without limiting the above, Orchard will not: (a) sell PHI, or receive remuneration in exchange for PHI, except as permitted at 45 CFR § 164.502(a)(5)(ii); (b) use or disclose PHI for marketing or fundraising; (c) use PHI to train, fine-tune, or otherwise improve any machine-learning model made available to any party other than Customer; or (d) combine PHI with data from any other customer or source, except as strictly necessary to provide the services to Customer.

5. Safeguards

Orchard will use appropriate administrative, physical and technical safeguards, and will comply with Subpart C of 45 CFR Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as this BAA permits. The safeguards in force are summarised at Annex A. Orchard will maintain written policies and procedures, conduct and document a risk analysis as required by 45 CFR § 164.308(a)(1)(ii)(A), and designate a security official responsible for their development and implementation.

6. Reporting breaches and security incidents

Orchard will report to Customer: (a) any use or disclosure of PHI not permitted by this BAA of which it becomes aware, without unreasonable delay and in no event later than seventy-two (72) hours after discovery — the same window Orchard commits to for personal-data breaches under the Data Processing Agreement; (b) any Breach of Unsecured PHI, within the same window, with the information required by 45 CFR § 164.410(c) to the extent then known, and further detail supplied promptly as it becomes available; and (c) any successful Security Incident of which it becomes aware.

Unsuccessful Security Incidents. Attempted but unsuccessful events that do not result in unauthorised access, use, disclosure, modification or destruction of ePHI — including pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, denial-of-service attempts, and malware intercepted before execution — are reported on Customer's written request rather than individually. This paragraph is Customer's ongoing notice of such events. Orchard will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this BAA.

7. Subcontractors

Orchard will ensure that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this BAA, as required by 45 CFR § 164.502(e)(1)(ii) and § 164.308(b)(2). The Subcontractors that may handle PHI are listed at Annex B. Orchard will give Customer at least thirty (30) days' prior written notice of any addition or replacement, and Customer may object on reasonable grounds relating to the protection of PHI. Annex B also names sub-processors that must not receive PHI; Orchard will maintain technical controls preventing PHI from reaching them.

8. Individual rights

Captured Activity is not maintained by Orchard as, or as part of, a Designated Record Set, and Orchard does not expect to hold PHI in one. To the extent Orchard nevertheless does: (a) Access — Orchard will make PHI available to Customer as necessary for Customer to meet its obligations under 45 CFR § 164.524, within [TEN (10)] business days of written request; (b) Amendment — Orchard will make PHI available for amendment and incorporate any amendment Customer directs, as necessary for Customer to meet its obligations under 45 CFR § 164.526; (c) Accounting — Orchard will document disclosures of PHI and related information as would be required for Customer to respond to a request for an accounting under 45 CFR § 164.528, and make that documentation available to Customer.

Where Orchard is to carry out an obligation of Customer under Subpart E of 45 CFR Part 164, Orchard will comply with the requirements of Subpart E that apply to Customer in performing that obligation. Orchard will forward to Customer, without responding, any request it receives directly from an individual concerning that individual's PHI.

9. Availability to the Secretary

Orchard will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Customer's compliance with the HIPAA Rules. Orchard will notify Customer of any such request unless prohibited from doing so.

10. De-identification and aggregate data

This section is called out because the Data Processing Agreement permits Orchard to retain anonymized aggregates derived from Captured Activity after the underlying records are deleted, and creating de-identified information from PHI is itself a use of PHI that must be expressly permitted or it is not permitted at all.

Orchard may de-identify PHI in accordance with 45 CFR § 164.514(b), and may use and disclose the resulting de-identified information for any lawful purpose, only if this section is retained. De-identified information is not PHI and is not subject to the return-or-destruction obligation at Section 12.

[COUNSEL: THIS IS A REAL ELECTION, NOT BOILERPLATE. IF CUSTOMER STRIKES THIS SECTION, ORCHARD MUST EXCLUDE THAT CUSTOMER'S DATA FROM AGGREGATE LEARNING, AND THE PLATFORM MUST BE ABLE TO ENFORCE THAT PER-TENANT. CONFIRM IT CAN BEFORE AGREEING TO STRIKE IT.]

11. Term and termination

This BAA takes effect on the date of the last signature below and continues until all PHI is returned or destroyed under Section 12, or the Agreement terminates, whichever is later. Termination for cause: Customer may terminate the Agreement if Orchard materially breaches this BAA and fails to cure within thirty (30) days of written notice, or immediately if cure is not possible.

12. Return or destruction of PHI

On termination, Orchard will return or destroy all PHI it maintains in any form, and retain no copies, within thirty (30) days — matching Section 12 of the Data Processing Agreement — and will require the same of its Subcontractors. Captured Activity is in any event swept automatically on a schedule, with a default retention of [90] days, configurable per deployment; Customer may request deletion of Captured Activity at any time.

Where return or destruction is infeasible, Orchard will notify Customer of the conditions making it infeasible, extend the protections of this BAA to that PHI, and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as it is retained. Backups containing PHI expire within their ordinary rotation cycle and are not restored to active use. Orchard will certify completion of deletion in writing on request.

13. Miscellaneous

(a) Interpretation — any ambiguity is resolved in favour of a meaning that permits compliance with the HIPAA Rules. (b) Amendment — the parties will negotiate in good faith to amend this BAA as necessary for either to comply with changes to the HIPAA Rules. (c) Regulatory references — a reference to a section of the HIPAA Rules means that section as in effect or as amended. (d) No third-party beneficiaries. (e) Survival — Sections 4, 6, 8, 9, 12 and 13 survive termination. (f) Governing law & venue — the law and venue stated in the Agreement, or, if none, the State of Delaware, USA (matching Section 13 of the Data Processing Agreement), without regard to conflict-of-laws rules and in every case subject to the HIPAA Rules where they control.

Signed for Orchard: _______________________ Name/title: _______________ Date: __________

Signed for Customer: _______________________ Name/title: _______________ Date: __________


Annex A — Safeguards in force

Summarised from the Trust Center and Annex B of the Data Processing Agreement. This annex is the representation a security reviewer will test.

SafeguardImplementation
Tenant isolationEvery record scoped to the Customer's tenant and enforced in the database with PostgreSQL Row-Level Security. A query arriving without tenant context returns nothing.
Encryption in transitCurrent TLS between Endpoints, the Orchard API and the console. Passwords and tokens are never written to logs.
Encryption at restManaged database encryption. Credential capture, where enabled, is sealed on the Endpoint under a per-workspace key before transmission.
Access controlOwner / admin / read-only roles per workspace. Agent and enrollment tokens are locked to a single tenant. Logins rate-limited and uniformly timed.
AuthenticationApp-based TOTP two-factor with recovery codes; owners may require it workspace-wide. Required on Orchard's own staff console.
Vendor accessOrchard support tooling is a separate system with separate credentials and MFA, on a restricted database role. Every read is written to an immutable audit log.
Capture boundaryNo screenshots, no screen recording, no keystroke text, at any tier. Fields flagged IsPassword are skipped on the Endpoint unless credential capture is deliberately enabled.
NetworkThe managed database has no public address and sits on a private network.
RetentionCaptured Activity swept on a schedule, default [90] days, configurable per deployment.
Risk analysis[DATE OF MOST RECENT DOCUMENTED RISK ANALYSIS]
Security official[NAME, TITLE]

Annex B — Subcontractors

May handle PHI — BAA in place:

SubcontractorFunctionBAA
Google Cloud PlatformCloud infrastructure and the managed PostgreSQL database, hosted in the United States.[CONFIRM EXECUTED]
CloudflareEdge network and TLS termination in front of the platform.[CONFIRM EXECUTED]

Must not receive PHI:

Sub-processorFunctionStatus
ResendTransactional email only — password resets and account notices.EXCLUDED
DeepgramLive call transcription, where enabled.[CONFIRM SCOPE — audio may carry PHI; treat as in-scope or exclude]

Orchard will maintain technical controls ensuring no PHI reaches an excluded sub-processor, including that no notification email quotes Captured Activity content such as a window title or field value.


Draft for legal review; not legal advice. Orchard's general processing obligations are set out in the Data Processing Agreement; this BAA supplements them where Protected Health Information is involved and controls over them in the event of conflict.

TrustPrivacyDPAEULAHidden DeploymentDeployment PackBAA

Orchard © 2026 · Enter the Orchard Syndicate