HIPAA Business Associate Agreement Addendum
For Firms Handling Protected Health Information (PHI)
⚠ AVAILABLE ON COMPLETE AND ENTERPRISE TIERS ONLY
This Business Associate Agreement (BAA) supplements the Terms of Service and Data Processing Agreement for law firm customers who represent clients in matters involving Protected Health Information (PHI), such as medical malpractice, personal injury, workers' compensation, or other health-related litigation.
⚠ LEGAL REVIEW REQUIRED — This BAA template must be reviewed by HIPAA counsel before execution. HIPAA requires specific contractual provisions; this template covers the basics but may require firm-specific modifications.
1. Definitions
Capitalized terms have the meanings given in 45 CFR §§ 160.103, 164.501, and this BAA.
- "BA" means Business Associate (Trial Commander / Navarro Hernandez, P.L.)
- "CE" means Covered Entity-adjacent; the law firm using Trial Commander to handle PHI received from covered entities
- "Breach" has the meaning given in 45 CFR § 164.402
- "PHI" means Protected Health Information, as defined in 45 CFR § 160.103, that BA receives from or on behalf of the firm
2. Permitted Uses and Disclosures
2.1 Permitted Uses
BA may use PHI only:
- To perform services for the firm as described in the Terms of Service
- For BA's proper management and administration (narrowly construed)
- To provide data aggregation services (not applicable in this context)
- As required by law
2.2 Prohibited Uses
BA shall NOT:
- Use PHI for its own commercial purposes
- Sell PHI
- Use PHI for marketing or fundraising
- Disclose PHI except as permitted by this BAA or required by law
- Use or disclose PHI in a manner that would violate HIPAA if done by the firm
3. Safeguards
BA shall:
3.1 Implement administrative, physical, and technical safeguards per the HIPAA Security Rule (45 CFR § 164.308-316) to protect PHI, including:
- Access controls with MFA
- Encryption of PHI in transit (TLS 1.2+) and at rest (AES-256)
- Audit controls (our tamper-evident audit log)
- Person or entity authentication (Clerk-based identity)
- Transmission security
- Facility access controls (via SOC 2 compliant hosting providers)
3.2 Ensure that workforce members with access to PHI receive HIPAA training.
3.3 Conduct periodic security risk assessments.
3.4 Execute BAAs with any subcontractors that will handle PHI (Anthropic, Postmark, etc.). Microsoft Azure — which hosts both the application and the database — is covered automatically: its HIPAA BAA is part of the Microsoft Product Terms and requires no separate signature.
4. Minimum Necessary
BA will make reasonable efforts to use, disclose, and request only the minimum amount of PHI necessary to accomplish the intended purpose.
5. Breach Notification
5.1 BA will notify the firm of any Breach of Unsecured PHI within 72 hours of discovery, including:
- A description of the Breach
- Types of Unsecured PHI involved
- Identification of affected individuals
- Steps the firm should take to protect themselves
- Actions BA is taking to investigate, mitigate, and prevent recurrence
- A contact point for more information
5.2 The notification will be sent to the firm's designated HIPAA contact via email and phone.
5.3 BA will cooperate with the firm's breach-notification obligations under HIPAA § 13402 (45 CFR § 164.410).
6. Individual Rights
6.1 Access (§ 164.524). BA will provide access to PHI in a Designated Record Set to the firm within 15 days of request, to facilitate the firm's response to individual access requests.
6.2 Amendment (§ 164.526). BA will make amendments to PHI in a Designated Record Set as directed by the firm.
6.3 Accounting (§ 164.528). BA will maintain and provide an accounting of disclosures of PHI as required by HIPAA (our audit log supports this).
7. Subcontractors (Sub-BAs)
BA uses the following sub-processors that may handle PHI. BA will not accept PHI from the firm until a BAA is executed with every sub-processor marked below as required. The "BAA status" column states the current position for each and is updated as agreements are executed.
| Sub-processor | Service | HIPAA Tier | BAA status |
|---|---|---|---|
| Microsoft Corporation (Azure) | Application hosting and database | HIPAA-eligible | Included — the HIPAA BAA is part of the Microsoft Product Terms/DPA and is executed by the subscription agreement itself; there is no separate contract to sign |
| Anthropic | AI processing | ZDR + HIPAA compliance tier | Required — not yet executed |
| Postmark | HIPAA-compliant plan | Required — not yet executed | |
| Cloudflare R2 | File storage | HIPAA-eligible | Required — not yet executed |
Opt-out options: The firm may request we disable AI features or other sub-processors that handle PHI.
8. Term and Termination
8.1 Term. This BAA is effective on execution and continues while BA maintains PHI.
8.2 Termination. Either party may terminate this BAA if the other materially breaches and fails to cure within 30 days.
8.3 Upon termination:
- BA will return or destroy all PHI within 60 days
- If return or destruction is infeasible, BA will extend protections and limit further use
- BA will provide written certification of destruction upon request
9. Indemnification
Standard Terms indemnification applies. BA additionally indemnifies the firm against HIPAA penalties resulting from BA's willful misconduct or gross negligence (but not ordinary breach).
10. Audit and Assistance
10.1 BA will provide information to the Secretary of HHS as required to investigate HIPAA compliance.
10.2 BA will assist the firm in responding to HIPAA investigations affecting the firm.
11. Miscellaneous
11.1 Regulatory References. References to HIPAA regulations mean the regulation as amended from time to time.
11.2 Interpretation. Any ambiguity is resolved in favor of HIPAA compliance.
11.3 Survival. Sections 5, 6, 8.3, 9, 10 survive termination.
12. Execution
This BAA becomes effective upon acceptance during checkout (for Complete/Enterprise tier subscriptions with PHI handling enabled).
Business Associate (BA): Navarro Hernandez, P.L. d/b/a Trial Commander 66 West Flagler St, 6th Floor, Miami, FL 33130
Covered Entity-Adjacent / Firm: On acceptance of Terms of Service with PHI handling checkbox affirmed
Appendix A — Implementation Specifications
Encryption Standards:
- At rest: AES-256 (Azure service-managed encryption + our field-level encryption for privileged data)
- In transit: TLS 1.2 minimum, TLS 1.3 preferred
- Backup: AES-256 encrypted at the application level before S3 storage
Access Controls:
- Role-based (Firm Admin, Attorney, Associate, Paralegal, Read-Only, Client)
- MFA required for Enterprise tier; recommended for all tiers
- Session timeout: 30 minutes of inactivity default
- IP allowlist available on Enterprise tier
Audit Controls:
- Every access to and modification of PHI logged
- Tamper-evident via Merkle-chain integrity
- Retention: 7 years minimum (exceeds HIPAA 6-year requirement)
Integrity Controls:
- Cryptographic hashes on fee agreements and other critical documents
- Write-once audit log (no deletion possible)
- Void-not-delete on financial/trust records
Data Backup:
- Daily automated backups
- 30-day retention
- Encrypted at rest
- Tested restore procedures (documented quarterly drill)
- Geographic redundancy
Incident Response:
- 72-hour Breach notification commitment (exceeds HIPAA 60-day)
- Documented incident response plan
- Post-incident review and remediation
BAA template v1.0 — requires HIPAA counsel review before execution.