BUSINESS ASSOCIATE AGREEMENT
Omi Health B.V. -- Version 2.0 -- Effective date: 5 August 2026
This page publishes the standard text of the Omi Business Associate Agreement. The published text is informational. A BAA takes effect only when it is executed through the Omi console. The console generates the completed agreement with Customer's legal-entity details, the recorded capacity of Customer, the signatures, the document version and SHA-256 hash, and the UTC execution time. Customer changes to this text are not accepted unless separately agreed in writing.
1. PARTIES, CAPACITY, AND DEFINITIONS
1.1 Parties. This Business Associate Agreement ("BAA") is between Omi Health B.V., a company registered in the Netherlands, with its seat in Eindhoven, the Netherlands ("Business Associate"), and the customer executing it through the Omi console ("Customer"). It applies to the speech-to-text services Business Associate provides to Customer under the underlying service terms (the "Service").
1.2 Capacity. At execution, Customer records whether it enters into this BAA as a Covered Entity or as a Business Associate of one or more Covered Entities. Where Customer is itself a Business Associate, this BAA is the subcontractor agreement required by 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), and its requirements apply under 45 CFR 164.504(e)(5) in the same manner as between a Covered Entity and a Business Associate. References in this BAA to obligations of a Covered Entity then refer to Customer's obligations to its upstream Covered Entity.
1.3 Definitions. The following terms used in this BAA have the same meaning as in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164. "PHI" means Protected Health Information that Business Associate creates, receives, maintains, or transmits for or on behalf of Customer through the Service. "Job Content" means submitted audio, job-scoped custom vocabulary and job options, and the transcripts and results generated from them.
2. PERMITTED USES AND DISCLOSURES
2.1 Service provision. Business Associate may use or disclose PHI only as necessary to provide the Service under the underlying service terms: to process submitted audio, return transcripts and results, and operate and secure the Service.
2.2 Required By Law. Business Associate may use or disclose PHI as Required By Law.
2.3 Management and administration. Business Associate may use PHI as necessary for its proper management and administration or to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only if the disclosure is Required By Law, or if Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially, will be used or further disclosed only as Required By Law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instance of which it is aware in which the confidentiality of the information has been breached.
2.4 Minimum Necessary. Business Associate limits its uses, disclosures, and requests of PHI to the Minimum Necessary. By architecture, Job Content is processed transiently to produce the requested transcript and is not otherwise accessed; human access occurs only for security or abuse investigation, under role-based access control, and is logged.
2.5 Prohibited uses. Except as permitted by Sections 2.2 and 2.3, Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Customer. Business Associate will not: de-identify PHI for any independent use; aggregate PHI beyond operation of the Service; provide Data Aggregation services; sell PHI; use PHI for marketing; or use PHI to train, fine-tune, or evaluate any model.
3. OBLIGATIONS OF BUSINESS ASSOCIATE
3.1 No impermissible use or disclosure. Business Associate will not use or disclose PHI other than as permitted or required by this BAA or as Required By Law.
3.2 Safeguards. Business Associate will use appropriate safeguards, and will comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this BAA. These safeguards include: encryption in transit (TLS) and at rest (managed keys); access controls and least privilege; audit controls through an immutable audit log whose schema is designed to contain no Job Content; integrity and transmission security; and a written workforce training and sanctions program.
3.3 Data minimisation and deletion. Submitted audio is deleted automatically upon completion or terminal failure of processing. Transcripts from synchronous requests are not stored. Results of asynchronous requests are stored solely for retrieval and deleted automatically at the end of the retention period selected by Customer (1 to 72 hours; default 24 hours). Job-scoped custom vocabulary is deleted with the job. Content is never written to operational logs or backups. The retention period selected by Customer is Customer's documented instruction. Persistent custom vocabulary that Customer saves to its account outside an individual job is account configuration, not Job Content: it may contain PHI, it is covered by this BAA, Customer may delete it in the console at any time, and it is deleted on account termination. Retention particulars, including the effective minimum retention for jobs configured with webhook delivery, are stated in the Service documentation.
3.4 Reporting.
(a) Impermissible uses and disclosures. Business Associate will report to Customer any use or disclosure of PHI not provided for by this BAA of which it becomes aware.
(b) Security Incidents. Business Associate will report to Customer any successful Security Incident of which it becomes aware without unreasonable delay. The parties acknowledge that unsuccessful attempts that do not compromise electronic PHI (such as routine scans, pings, and failed log-in attempts) occur routinely; this Section is notice of such attempts, and no further reporting of them is required.
(c) Breach of Unsecured PHI. Business Associate will notify Customer of any Breach of Unsecured PHI. Business Associate will provide an initial notice within five (5) business days of discovery, based on the information then known, and will supplement it on a rolling basis as the investigation proceeds, so that Customer receives the information required by 45 CFR 164.410. A Breach is treated as discovered as of the first day on which it is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate, including knowledge of any person, other than the person committing the breach, who is a workforce member or agent of Business Associate. If a law enforcement official states that a notification would impede a criminal investigation or damage national security, notice may be delayed as provided in 45 CFR 164.412.
3.5 Subcontractors. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information, including compliance with Subpart C of 45 CFR Part 164 for electronic PHI. Current chain: Amazon Web Services, under a HIPAA business associate agreement accepted through AWS Artifact; only HIPAA-eligible AWS services are used in the PHI path. The current subcontractor and sub-processor list, and the mechanism for at least thirty (30) days' advance notice of changes, are published at /legal/sub-processors.
3.6 Individual access. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make that PHI available to Customer in the time and manner reasonably requested so that Customer can meet its obligations under 45 CFR 164.524. Because Job Content is ordinarily returned and deleted under Section 3.3, Business Associate may hold no responsive PHI when a request is received; it will promptly confirm that fact. Nothing in this BAA requires Business Associate to recreate PHI deleted in accordance with Customer's retention instruction. If an Individual makes a request directly to Business Associate, Business Associate will forward the request to Customer within five (5) business days.
3.7 Amendment. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make that PHI available for amendment and will incorporate any amendment as directed or agreed by Customer under 45 CFR 164.526, or will take other measures reasonably necessary to support Customer's obligations under that section.
3.8 Accounting of disclosures. Business Associate will maintain and make available to Customer the information required to provide an accounting of disclosures under 45 CFR 164.528. Business Associate records the disclosure metadata required by that section (including date, recipient, and a description of the PHI and purpose) for any disclosure outside Section 2.1, retains it for the period required by law without retaining Job Content, and will provide it to Customer in the time and manner reasonably requested.
3.9 Delegated obligations. To the extent Business Associate is to carry out one or more of Customer's obligations under Subpart E of 45 CFR Part 164, Business Associate will comply with the requirements of Subpart E that apply to Customer in the performance of such obligations.
3.10 Access by the Secretary. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules.
4. CUSTOMER OBLIGATIONS
4.1 Notice of restrictions. Customer will notify Business Associate of any limitation in its Notice of Privacy Practices, any change in or revocation of an Individual's permission, and any restriction agreed to or required under 45 CFR 164.522, in each case to the extent it may affect Business Associate's use or disclosure of PHI.
4.2 Permissible requests. Customer will not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Customer, except as permitted for Business Associate's management and administration under Section 2.3.
4.3 Customer responsibilities. Customer remains responsible for its own obligations under the HIPAA Rules, for not submitting PHI through the Service before this BAA is executed, and for retrieving results within the retention period it selects.
5. TERM AND TERMINATION
5.1 Term. This BAA is effective when its execution is confirmed in the console and continues until the underlying Service relationship between the parties terminates.
5.2 Termination for cause. Customer may terminate this BAA and the affected Service if Business Associate has violated a material term of this BAA and has not cured the violation within a reasonable period specified by Customer, or immediately if cure is not possible or immediate termination is reasonably necessary.
5.3 Return or destruction. At termination of this BAA for any reason, Business Associate will, if feasible and as directed by Customer, return or destroy all PHI received from Customer, or created, maintained, or received by Business Associate on behalf of Customer, that Business Associate or its Subcontractors still maintain in any form, and will retain no copies. Retrieval of results through the API before termination constitutes return of Job Content. Any remaining Job Content is destroyed by the standing deletion mechanics in Section 3.3, and in no event later than the end of the retention period selected by Customer. Persistent custom vocabulary is deleted on account termination under Section 3.3. Written confirmation of destruction is available on request. If return or destruction of particular PHI is infeasible, Business Associate will notify Customer of the PHI concerned and the conditions that make return or destruction infeasible, will extend the protections of this BAA to that PHI, and will limit further uses and disclosures to those purposes that make its return or destruction infeasible, for so long as it is maintained.
5.4 Survival. The obligations of Business Associate under Section 5.3 survive termination of this BAA.
6. MISCELLANEOUS
6.1 Regulatory references. A reference in this BAA to a section in the HIPAA Rules means the section as in effect or as amended.
6.2 Amendment. This BAA may be amended only by written or electronic agreement of the parties. Where an amendment is reasonably necessary for compliance with the HIPAA Rules or other applicable law, Business Associate may issue an updated version with notice to Customer; Customer may terminate the affected Service before a materially adverse change takes effect. The parties agree to take such action as is necessary to amend this BAA from time to time as required for compliance with the HIPAA Rules.
6.3 Interpretation. Any ambiguity in this BAA shall be interpreted to permit compliance with the HIPAA Rules.
6.4 Governing law; HIPAA. This BAA is governed by the law of the Netherlands, as provided in the underlying service terms. HIPAA and the HIPAA Rules govern the interpretation of the duties this BAA defines by reference to them, and nothing in this BAA limits the enforcement authority of the U.S. Department of Health and Human Services.
6.5 No third-party beneficiaries. Nothing in this BAA confers any right or remedy on any person other than the parties and their permitted successors and assigns.
6.6 Precedence. For the use and disclosure of PHI, this BAA prevails over any conflicting term of the underlying service terms.
END OF STANDARD TEXT. The console-generated executed copy appends: Customer legal name, registered address, and jurisdiction; Customer's recorded capacity (Covered Entity or Business Associate); signatory name, title, and email; the authority representation; this document's version and SHA-256 hash; and the UTC execution timestamp.