Business Associate Agreement
For U.S. Covered Entities. This BAA applies to Clients who transmit HIPAA-regulated Protected Health Information (PHI) to MK Flow. It works alongside our Terms of Service and Data Processing Agreement. Fields marked [TO BE DETERMINED] are placeholders pending completion.
1Definitions
Terms used but not defined in this BAA have the meanings given to them under HIPAA, including the HIPAA Privacy Rule (45 CFR Part 164, Subparts A and E) and the HIPAA Security Rule (45 CFR Part 164, Subparts A and C).
“Protected Health Information” or “PHI” — Individually identifiable health information transmitted or maintained in any form or medium by MK Flow on behalf of the Covered Entity, as defined in 45 CFR §160.103. This includes, but is not limited to, patient references, clinical notes, STL files, dental radiographs, treatment plans and clinical photographs uploaded to the platform.
“Electronic Protected Health Information” or “ePHI” — PHI that is created, stored, transmitted or received electronically.
“Breach” — Has the meaning given in 45 CFR §164.402.
“Security Incident” — Has the meaning given in 45 CFR §164.304.
2Permitted Uses and Disclosures by Business Associate
MK Flow may use or disclose PHI only as follows:
a) To provide services. MK Flow may use and disclose PHI as necessary to provide the MK Flow platform, including case coordination, secure file sharing, workflow management, communication between the Covered Entity and independent providers, platform security, audit logging, and backup and disaster recovery.
b) As required by law. MK Flow may use or disclose PHI as required by applicable law, including HIPAA.
c) For Business Associate's operations. MK Flow may use PHI for its own proper management and administration, or to carry out its legal responsibilities, provided that disclosures are required by law or MK Flow obtains reasonable assurances from the recipient that the PHI will be kept confidential.
d) No other uses or disclosures. MK Flow will not use or disclose PHI in any manner not permitted by this BAA or HIPAA.
3Obligations of Business Associate
MK Flow agrees to:
a) Not use or disclose PHI other than as permitted or required by this BAA or applicable law.
b) Implement safeguards. Use appropriate administrative, physical and technical safeguards to protect the confidentiality, integrity and availability of ePHI, in accordance with the HIPAA Security Rule (45 CFR Part 164, Subpart C).
c) Report breaches and security incidents. Notify the Covered Entity of: any Breach of Unsecured PHI within 30 days of discovery, including the information required by 45 CFR §164.410; and any Security Incident of which MK Flow becomes aware, including attempted but unsuccessful incidents, in accordance with 45 CFR §164.314(a)(2)(i)(C). Reports should be directed to [EMAIL TO BE DETERMINED] or to the contact provided by the Covered Entity.
d) Sub-processors and subcontractors. Ensure that any subcontractor or sub-processor that creates, receives, maintains or transmits PHI on behalf of MK Flow agrees to the same restrictions and conditions as apply to MK Flow under this BAA. See §4 for disclosure of current PHI-accessing sub-processors.
e) Access and amendment. Provide access to PHI in a Designated Record Set to the Covered Entity or, as directed, to the individual, in accordance with 45 CFR §164.524. Accommodate requests to amend PHI in accordance with 45 CFR §164.526.
f) Accounting of disclosures. Make available the information required for the Covered Entity to provide an accounting of disclosures in accordance with 45 CFR §164.528.
g) Compliance assistance. Make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with HIPAA.
h) Minimum necessary. Use, disclose or request only the minimum PHI necessary to accomplish the intended purpose.
i) No sale of PHI. MK Flow will not directly or indirectly receive remuneration in exchange for PHI, except as permitted under HIPAA.
j) No AI training on PHI. MK Flow will not use identifiable PHI to train artificial intelligence or machine learning models.
4Sub-processors with Access to PHI
The following MK Flow sub-processors may have access to PHI in the course of providing platform services. MK Flow maintains appropriate agreements with each:
| Sub-processor | Role | PHI Access |
|---|---|---|
| Supabase, Inc. | Database, file storage, authentication | Yes. All structured data and clinical files are stored on Supabase infrastructure (AWS-backed). AES-256 at rest, TLS in transit. |
| AI Processing Providers (variable) | AI-assisted case analysis | Yes. When activated by the Covered Entity, signed file URLs and case metadata are transmitted to the provider's endpoint. See §4.1. |
4.1 AI Sub-processors
MK Flow works with one or more AI providers to deliver AI-assisted case processing features. When a Covered Entity activates an AI job, case files and clinical metadata are transmitted to the relevant AI provider. This constitutes PHI disclosure to a subcontractor.
MK Flow maintains BAA-equivalent agreements with AI providers that access PHI. Covered Entities should not activate AI-assisted processing unless they have accepted this BAA and understand that PHI will be transmitted to the relevant AI provider under those protections.
MK Flow will maintain and make available an up-to-date list of AI sub-processors upon written request to [EMAIL TO BE DETERMINED].
5Obligations of the Covered Entity
The Covered Entity agrees to:
a) Notify MK Flow of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to in accordance with 45 CFR §164.522, to the extent such restriction may affect MK Flow's use or disclosure of PHI.
b) Notify MK Flow of any changes in or revocation of consent or authorization of individuals to use or disclose PHI, to the extent this affects MK Flow's permitted uses and disclosures.
c) Not request MK Flow to use or disclose PHI in any manner that would not be permissible under HIPAA if done by the Covered Entity.
d) Obtain all required patient authorizations and consents before uploading PHI to the MK Flow platform.
e) Implement appropriate access controls for its own users of the MK Flow platform and ensure that only authorized personnel upload or access PHI.
f) Use opaque patient references (e.g., a case number or initials) where clinically appropriate, rather than full patient names or other direct identifiers, to minimize PHI exposure on the platform.
6Term and Termination
a) Term. This BAA is effective upon the Covered Entity's acceptance of the MK Flow Terms of Service or DPA, and remains in effect for the duration of the service relationship.
b) Termination for cause. Either party may terminate this BAA immediately if the other party materially breaches a HIPAA obligation and fails to cure the breach within 30 days of written notice.
c) Obligations on termination. Upon termination, MK Flow will, at the direction of the Covered Entity, return or destroy all PHI received from or created on behalf of the Covered Entity, to the extent feasible. Where return or destruction is not feasible (for example, PHI held in backup systems), MK Flow will extend the protections of this BAA to such PHI for as long as it is retained, and will limit further uses and disclosures to those purposes that make the return or destruction infeasible.
d) Data deletion. PHI deletion requests are fulfilled via a managed process within 30 days of written request to [EMAIL TO BE DETERMINED]. Payment and audit records may be retained in pseudonymized form to meet legal and regulatory obligations.
7Amendments
MK Flow may amend this BAA from time to time to remain compliant with HIPAA and other applicable law. Material changes will be communicated to Covered Entities with reasonable advance notice. Continued use of the platform following notice of an amendment constitutes acceptance.
8Miscellaneous
a) Regulatory references. Any reference to a HIPAA regulation includes any amendments or successor provisions.
b) No third-party beneficiaries. This BAA is for the benefit of the parties only and does not create rights in any third party, including any patient.
c) Relationship to DPA. Where this BAA conflicts with the MK Flow DPA on matters relating to PHI, this BAA governs. In all other respects the DPA applies.
d) Governing law. This BAA is governed by the laws of [TO BE DETERMINED], subject to applicable federal law including HIPAA.
e) Entire agreement. This BAA, together with the MK Flow DPA and Terms of Service, constitutes the entire agreement between the parties with respect to HIPAA compliance.
f) Severability. If any provision of this BAA is found unenforceable, the remaining provisions continue in full force.
9Contact
To exercise rights under this BAA, report a Security Incident or Breach, or request a list of AI sub-processors:
Email: [EMAIL TO BE DETERMINED]
Company: MK Flow
Questions about this BAA?
Contact us through the early access form and our team will follow up directly.