Healthcare is one of the three industries we build for. If you are a covered entity or a business associate and you want to send protected health information to a lane or put it in a GPU rental, you need a signed Business Associate Agreement first. This is our standard one.
To get a signed copy, email [email protected] with your organization's legal name and the person who signs. We countersign and return it before any protected health information reaches us. Without a signed copy, do not send any.
This text takes effect for a customer when the customer and Texas Inference Inc ("Texas Inference") have both signed it. Reading it here creates no agreement.
1. Definitions
1.1 Terms in capital letters that this agreement does not define have the meaning given in the Health Insurance Portability and Accountability Act of 1996 and its implementing rules at 45 CFR Parts 160 and 164 ("HIPAA"), as amended by the HITECH Act.
1.2 Customer is the organization that signs this agreement. Services are the lanes and GPU rentals Texas Inference provides to Customer under its order and the Terms of Service.
1.3 PHI means the protected health information that Customer, or a user acting for Customer, sends to or stores in the Services. PHI is a part of Customer Content as the Data Processing Addendum defines it.
2. Roles
2.1 Texas Inference is a business associate of Customer for PHI it creates, receives, maintains, or transmits for Customer through the Services. If Customer is itself a business associate, Texas Inference is its subcontractor.
2.2 Texas Inference cannot read PHI in plaintext. PHI exists in plaintext only inside a confidential virtual machine whose memory the hardware encrypts. Texas Inference holds no key to it. This agreement applies all the same.
3. What Texas Inference may do with PHI
3.1 Texas Inference uses and discloses PHI only to provide the Services to Customer, as the agreement and Customer's instructions direct, and as this agreement and the law allow.
3.2 Texas Inference does not use PHI for its own purposes, does not sell it, and does not use it to train, fine tune, evaluate or improve any model.
3.3 Texas Inference may use PHI for its own proper management and administration, or to carry out its legal duties, only where HIPAA allows it for a business associate. Texas Inference cannot read PHI. It expects no such use.
3.4 Texas Inference does not de-identify PHI and does not combine it with data from anyone else.
4. Safeguards
4.1 Texas Inference uses the safeguards in Schedule 2 of the DPA and complies with the HIPAA Security Rule, 45 CFR Part 164 Subpart C, for electronic PHI.
4.2 Texas Inference processes and stores PHI only in data centers located in the State of Texas.
5. Reporting
5.1 Texas Inference reports to Customer any use or disclosure of PHI that this agreement does not allow, any Security Incident, and any Breach of Unsecured PHI that it learns of.
5.2 Texas Inference sends the report without unreasonable delay and within 48 hours after it confirms the event. A report of a Breach includes, as far as Texas Inference knows, the identity of each affected individual, what happened and what PHI was involved, and what Texas Inference has done and recommends Customer do.
5.3 Customer decides whether to notify individuals, regulators, or the media. Texas Inference helps on request.
5.4 Unsuccessful attempts that cause no harm, such as pings, port scans, and blocked logins, are Security Incidents that Texas Inference reports only on request.
6. Subcontractors
6.1 Texas Inference makes sure each subcontractor that creates, receives, maintains, or transmits PHI for it agrees in writing to the same restrictions that apply to Texas Inference under this agreement.
6.2 No subcontractor listed on the subprocessors page receives PHI, because none of them receives Customer Content.
7. Individual rights
7.1 Texas Inference keeps no designated record set for Customer. It retains no PHI after a request is answered or a rental ends. There is nothing to make available for access or to amend. It keeps no log of disclosures of PHI to account for.
7.2 If an individual asks Texas Inference for access to PHI, an amendment, or an accounting, Texas Inference forwards the request to Customer within 10 business days and does not respond to the individual itself.
8. Government access
8.1 Texas Inference makes its internal practices, books and records on the use and disclosure of PHI available to the Secretary of Health and Human Services for the purpose of checking compliance with HIPAA.
8.2 Texas Inference tells Customer of any legal demand for PHI before it responds unless the law forbids notice. It says in its response that it holds no plaintext. Section 10 of the DPA governs.
9. Customer's duties
9.1 Customer sends PHI only after both parties have signed this agreement.
9.2 Customer is responsible for having every authorization and notice that HIPAA requires, for limiting PHI to the minimum necessary, and for how it uses outputs.
9.3 On a GPU rental, Customer decides what goes into the rental and holds the key to its disk. Texas Inference cannot recover data if Customer loses the key.
9.4 Customer tells Texas Inference of any restriction on the use of PHI that it has agreed to and that would affect the Services.
10. Term and termination
10.1 This agreement lasts as long as Texas Inference holds PHI for Customer and the Services continue.
10.2 Either party may end this agreement and the affected Services if the other materially breaks it and does not fix the breach within 30 days of notice. Customer may end it at once if Texas Inference breaks a material term and a cure is not possible.
10.3 When the Services end, no PHI remains to return. Ephemeral lanes keep none. Persistent lane state is dropped. Rentals are erased under section 6.3 of the DPA. Texas Inference keeps nothing else. This agreement's protections continue for anything it retains.
11. General
11.1 This agreement is part of the Terms of Service. The DPA applies to it. If they conflict on PHI, this agreement governs, then the DPA, then the Terms.
11.2 The parties amend this agreement as needed to comply with changes in HIPAA.
11.3 Nothing in this agreement gives anyone other than the parties any right. Texas law governs it, to the extent HIPAA does not.
11.4 This agreement does not promise that the Services meet every legal duty Customer has under HIPAA. Texas Inference holds no HIPAA certification and does not claim one.
12. Signatures
Texas Inference Inc: signed by Cooper Scanlon, Founder.
Customer: signed by an authorized signer, with name, title, and date.