HIPAA Business Associate Agreement Addendum

For Firms Handling Protected Health Information (PHI)

⚠ AVAILABLE ON COMPLETE AND ENTERPRISE TIERS ONLY

This Business Associate Agreement (BAA) supplements the Terms of Service and Data Processing Agreement for law firm customers who represent clients in matters involving Protected Health Information (PHI), such as medical malpractice, personal injury, workers' compensation, or other health-related litigation.

⚠ LEGAL REVIEW REQUIRED — This BAA template must be reviewed by HIPAA counsel before execution. HIPAA requires specific contractual provisions; this template covers the basics but may require firm-specific modifications.

1. Definitions

Capitalized terms have the meanings given in 45 CFR §§ 160.103, 164.501, and this BAA.

  • "BA" means Business Associate (Trial Commander / Navarro Hernandez, P.L.)
  • "CE" means Covered Entity-adjacent; the law firm using Trial Commander to handle PHI received from covered entities
  • "Breach" has the meaning given in 45 CFR § 164.402
  • "PHI" means Protected Health Information, as defined in 45 CFR § 160.103, that BA receives from or on behalf of the firm

2. Permitted Uses and Disclosures

2.1 Permitted Uses

BA may use PHI only:

  • To perform services for the firm as described in the Terms of Service
  • For BA's proper management and administration (narrowly construed)
  • To provide data aggregation services (not applicable in this context)
  • As required by law

2.2 Prohibited Uses

BA shall NOT:

  • Use PHI for its own commercial purposes
  • Sell PHI
  • Use PHI for marketing or fundraising
  • Disclose PHI except as permitted by this BAA or required by law
  • Use or disclose PHI in a manner that would violate HIPAA if done by the firm

3. Safeguards

BA shall:

3.1 Implement administrative, physical, and technical safeguards per the HIPAA Security Rule (45 CFR § 164.308-316) to protect PHI, including:

  • Access controls with MFA
  • Encryption of PHI in transit (TLS 1.2+) and at rest (AES-256)
  • Audit controls (our tamper-evident audit log)
  • Person or entity authentication (Clerk-based identity)
  • Transmission security
  • Facility access controls (via SOC 2 compliant hosting providers)

3.2 Ensure that workforce members with access to PHI receive HIPAA training.

3.3 Conduct periodic security risk assessments.

3.4 Execute BAAs with any subcontractors that will handle PHI (Anthropic, Postmark, etc.). Microsoft Azure — which hosts both the application and the database — is covered automatically: its HIPAA BAA is part of the Microsoft Product Terms and requires no separate signature.

4. Minimum Necessary

BA will make reasonable efforts to use, disclose, and request only the minimum amount of PHI necessary to accomplish the intended purpose.

5. Breach Notification

5.1 BA will notify the firm of any Breach of Unsecured PHI within 72 hours of discovery, including:

  • A description of the Breach
  • Types of Unsecured PHI involved
  • Identification of affected individuals
  • Steps the firm should take to protect themselves
  • Actions BA is taking to investigate, mitigate, and prevent recurrence
  • A contact point for more information

5.2 The notification will be sent to the firm's designated HIPAA contact via email and phone.

5.3 BA will cooperate with the firm's breach-notification obligations under HIPAA § 13402 (45 CFR § 164.410).

6. Individual Rights

6.1 Access (§ 164.524). BA will provide access to PHI in a Designated Record Set to the firm within 15 days of request, to facilitate the firm's response to individual access requests.

6.2 Amendment (§ 164.526). BA will make amendments to PHI in a Designated Record Set as directed by the firm.

6.3 Accounting (§ 164.528). BA will maintain and provide an accounting of disclosures of PHI as required by HIPAA (our audit log supports this).

7. Subcontractors (Sub-BAs)

BA uses the following sub-processors that may handle PHI. BA will not accept PHI from the firm until a BAA is executed with every sub-processor marked below as required. The "BAA status" column states the current position for each and is updated as agreements are executed.

Sub-processorServiceHIPAA TierBAA status
Microsoft Corporation (Azure)Application hosting and databaseHIPAA-eligibleIncluded — the HIPAA BAA is part of the Microsoft Product Terms/DPA and is executed by the subscription agreement itself; there is no separate contract to sign
AnthropicAI processingZDR + HIPAA compliance tierRequired — not yet executed
PostmarkEmailHIPAA-compliant planRequired — not yet executed
Cloudflare R2File storageHIPAA-eligibleRequired — not yet executed

Opt-out options: The firm may request we disable AI features or other sub-processors that handle PHI.

8. Term and Termination

8.1 Term. This BAA is effective on execution and continues while BA maintains PHI.

8.2 Termination. Either party may terminate this BAA if the other materially breaches and fails to cure within 30 days.

8.3 Upon termination:

  • BA will return or destroy all PHI within 60 days
  • If return or destruction is infeasible, BA will extend protections and limit further use
  • BA will provide written certification of destruction upon request

9. Indemnification

Standard Terms indemnification applies. BA additionally indemnifies the firm against HIPAA penalties resulting from BA's willful misconduct or gross negligence (but not ordinary breach).

10. Audit and Assistance

10.1 BA will provide information to the Secretary of HHS as required to investigate HIPAA compliance.

10.2 BA will assist the firm in responding to HIPAA investigations affecting the firm.

11. Miscellaneous

11.1 Regulatory References. References to HIPAA regulations mean the regulation as amended from time to time.

11.2 Interpretation. Any ambiguity is resolved in favor of HIPAA compliance.

11.3 Survival. Sections 5, 6, 8.3, 9, 10 survive termination.

12. Execution

This BAA becomes effective upon acceptance during checkout (for Complete/Enterprise tier subscriptions with PHI handling enabled).

Business Associate (BA): Navarro Hernandez, P.L. d/b/a Trial Commander 66 West Flagler St, 6th Floor, Miami, FL 33130

Covered Entity-Adjacent / Firm: On acceptance of Terms of Service with PHI handling checkbox affirmed


Appendix A — Implementation Specifications

Encryption Standards:

  • At rest: AES-256 (Azure service-managed encryption + our field-level encryption for privileged data)
  • In transit: TLS 1.2 minimum, TLS 1.3 preferred
  • Backup: AES-256 encrypted at the application level before S3 storage

Access Controls:

  • Role-based (Firm Admin, Attorney, Associate, Paralegal, Read-Only, Client)
  • MFA required for Enterprise tier; recommended for all tiers
  • Session timeout: 30 minutes of inactivity default
  • IP allowlist available on Enterprise tier

Audit Controls:

  • Every access to and modification of PHI logged
  • Tamper-evident via Merkle-chain integrity
  • Retention: 7 years minimum (exceeds HIPAA 6-year requirement)

Integrity Controls:

  • Cryptographic hashes on fee agreements and other critical documents
  • Write-once audit log (no deletion possible)
  • Void-not-delete on financial/trust records

Data Backup:

  • Daily automated backups
  • 30-day retention
  • Encrypted at rest
  • Tested restore procedures (documented quarterly drill)
  • Geographic redundancy

Incident Response:

  • 72-hour Breach notification commitment (exceeds HIPAA 60-day)
  • Documented incident response plan
  • Post-incident review and remediation

BAA template v1.0 — requires HIPAA counsel review before execution.