SMILE EDITOR โ HIPAA INFORMATION
Informational page โ not itself a contractual BAA
HIPAA is a United States healthcare privacy and security framework. There is no general US-government "HIPAA certification" that automatically certifies a software product.
Smile Editor may support HIPAA-regulated customers only when:
- the Customer is eligible and HIPAA applies to the relationship;
- an effective Business Associate Agreement ("BAA") is in place;
- the specific Smile Editor configuration and features are approved for PHI;
- relevant subprocessors that handle PHI satisfy applicable contractual requirements;
- required administrative, technical and physical safeguards are implemented.
A BAA is a legal agreement. Accepting a public Privacy Policy is not a substitute for a BAA.
Do not publish "HIPAA certified".
Any public statement should accurately describe the actual assessment, controls and BAA availability.
SMILE EDITOR โ BUSINESS ASSOCIATE AGREEMENT (BAA) TEMPLATE
For eligible accounts only โ requires legal and infrastructure approval before activation
This Business Associate Agreement ("BAA") is entered into between [CUSTOMER LEGAL NAME] ("Covered Entity" or "Customer") and [LEGAL ENTITY NAME], doing business as Smile Editor ("Business Associate"), and supplements the parties' Service Agreement.
1. Applicability
This BAA applies only to Protected Health Information ("PHI") that Business Associate creates, receives, maintains or transmits on behalf of Customer in circumstances subject to HIPAA.
Terms not defined here have the meanings assigned under HIPAA where applicable.
2. Permitted Uses and Disclosures
Business Associate may use or disclose PHI only:
- to perform services for Customer under the Agreement;
- for proper management and administration as permitted by HIPAA;
- as required by law;
- as otherwise expressly permitted by this BAA and HIPAA.
Business Associate will not use PHI for advertising, sale of PHI, generalized AI model training, or unrelated commercial purposes.
3. Safeguards
Business Associate will implement appropriate administrative, physical and technical safeguards designed to protect the confidentiality, integrity and availability of electronic PHI and to prevent uses or disclosures not permitted by this BAA.
4. Security Rule
To the extent required by HIPAA, Business Associate will comply with applicable provisions of the HIPAA Security Rule concerning electronic PHI.
5. Reporting
Business Associate will report to Customer without unreasonable delay:
- uses or disclosures of PHI not permitted by this BAA;
- Security Incidents required to be reported;
- Breaches of Unsecured PHI as required by HIPAA.
The parties may define operational notice contacts and escalation procedures in an Order Form or Security Addendum.
6. Subcontractors
Business Associate will ensure that subcontractors that create, receive, maintain or transmit PHI on its behalf agree in writing to restrictions and safeguards applicable to their role as required by HIPAA.
No feature may route PHI to a vendor that requires a BAA unless an appropriate BAA or equivalent required agreement is in effect.
7. Minimum Necessary
Business Associate will use reasonable efforts to limit PHI to the minimum necessary to accomplish permitted purposes, to the extent the minimum-necessary standard applies.
8. Access
To the extent Business Associate maintains PHI in a Designated Record Set on behalf of Customer, Business Associate will make such PHI available to Customer as reasonably necessary for Customer to fulfill applicable access obligations.
9. Amendment
To the extent applicable, Business Associate will make PHI available for amendment or incorporate amendments as instructed by Customer.
10. Accounting of Disclosures
Business Associate will maintain and provide information concerning disclosures to the extent reasonably necessary for Customer to satisfy applicable accounting-of-disclosures obligations.
11. HHS Access
Business Associate will make internal practices, books and records relating to use and disclosure of PHI available to the US Department of Health and Human Services to the extent required by HIPAA.
12. Customer Obligations
Customer will:
- use the Service in compliance with HIPAA;
- configure users and permissions appropriately;
- not submit PHI to non-HIPAA-eligible features;
- notify Business Associate of restrictions that materially affect permitted processing;
- maintain appropriate workforce and endpoint safeguards under Customer's control.
13. Prohibited Uses
Business Associate will not:
- sell PHI except as expressly permitted by HIPAA;
- use PHI for targeted advertising;
- use identifiable PHI for generalized AI model training;
- combine PHI with unrelated datasets for independent commercial profiling.
14. Term and Termination
This BAA remains effective while Business Associate maintains PHI on Customer's behalf.
Customer may terminate the affected Service for a material violation of this BAA if Business Associate fails to cure within a reasonable period where cure is possible, subject to rights required by HIPAA.
15. Return or Destruction
Upon termination, Business Associate will return or destroy PHI where feasible and as required by HIPAA. If return or destruction is not feasible, Business Associate will continue to protect retained PHI and limit further uses and disclosures to the reasons that make return or destruction infeasible.
Backup expiration may constitute part of the destruction process if PHI is isolated from routine processing.
16. Interpretation
This BAA will be interpreted to permit compliance with HIPAA. If this BAA conflicts with the Service Agreement concerning PHI, this BAA controls to the extent required by HIPAA.
17. Electronic Acceptance
This BAA becomes effective only when:
- accepted electronically by an authorized Customer administrator; and
- Smile Editor has designated the Customer account/plan as BAA-eligible.
Smile Editor will record BAA version, organization, accepting administrator, timestamp and evidence of acceptance.
18. Contact
HIPAA / Privacy: [PRIVACY EMAIL]
Security incidents: [SECURITY EMAIL]