← SampsonBusiness Associate Agreement

Business Associate Agreement

Version 1.0 · Published August 17, 2026

SAMPSON SCRIBE — BUSINESS ASSOCIATE AGREEMENT
Version 1.0 — Effective upon electronic acceptance (published August 17, 2026)

This Business Associate Agreement ("Agreement" or "BAA") is entered into between:

COVERED ENTITY: the licensed healthcare provider accepting this Agreement, acting individually or on behalf of the practice or entity for which the provider renders services ("Covered Entity," "you"). The legal name associated with your Sampson account is recorded with your electronic acceptance.

BUSINESS ASSOCIATE: Sampson Scribe LLC ("Sampson," "Business Associate").

This Agreement supplements the Sampson Terms of Service (the "Service Agreement"). With respect to Protected Health Information, this Agreement controls over any conflicting term of the Service Agreement.

RECITALS

WHEREAS, Business Associate provides clinical documentation-assistance services to Covered Entity (the "Service") that involve the creation, receipt, maintenance, and transmission of Protected Health Information ("PHI"); and

WHEREAS, the parties intend to protect the privacy and security of PHI in compliance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, the "HIPAA Rules");

NOW, THEREFORE, the parties agree as follows:

1. DEFINITIONS

Capitalized terms used but not otherwise defined in this Agreement have the meanings given to them in the HIPAA Rules, including "Breach" (45 CFR 164.402), "Protected Health Information" and "Electronic Protected Health Information" (45 CFR 160.103), "Security Incident" (45 CFR 164.304), "Designated Record Set," "Secretary," and "Subcontractor." "PHI" in this Agreement is limited to information Business Associate creates, receives, maintains, or transmits from or on behalf of Covered Entity.

2. PERMITTED USES AND DISCLOSURES

a. Services. Business Associate may use and disclose PHI as necessary to provide the Service to Covered Entity, including: (i) recording and transcription of provider-dictated audio; (ii) AI-assisted generation of draft clinical documentation; and (iii) storage, syncing, and retrieval of that documentation for Covered Entity.

b. As Required by Law. Business Associate may use or disclose PHI as required by law.

c. Management and Administration. Business Associate may use PHI for its proper management and administration and to carry out its legal responsibilities, including security monitoring, fraud and abuse investigation, and enforcement of the Service Agreement's acceptable-use terms. Business Associate may disclose PHI for these purposes only if the disclosure is required by law or Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially and used or further disclosed only as required by law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

d. De-identification. Business Associate may de-identify PHI in accordance with 45 CFR 164.514(b). De-identified information is no longer PHI and is not subject to this Agreement; Business Associate's use of de-identified information is described in its Privacy Policy.

e. Prohibitions. Business Associate will not: (i) use or disclose PHI other than as permitted by this Agreement or required by law; (ii) sell PHI; or (iii) use identifiable PHI to train artificial-intelligence models without a separate, explicit authorization.

3. OBLIGATIONS OF BUSINESS ASSOCIATE

Business Associate agrees to:

a. Safeguards. Use appropriate administrative, physical, and technical safeguards, and comply with the HIPAA Security Rule with respect to Electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. This includes encryption of PHI in transit and at rest.

b. Reporting. Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including any Breach of Unsecured PHI as required by 45 CFR 164.410, and any successful Security Incident, without unreasonable delay and in no case later than thirty (30) calendar days after discovery. The parties acknowledge the ongoing existence and occurrence of attempted but unsuccessful Security Incidents (such as pings, port scans, and denied log-in attempts) for which no additional notice is required; this sentence constitutes notice of such unsuccessful incidents.

c. Mitigation. Mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this Agreement.

d. Subcontractors. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate (including cloud hosting, speech-to-text, and AI-processing providers) agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement. Business Associate's current subcontractors are listed in its Privacy Policy.

e. Access. Make PHI in a Designated Record Set available to Covered Entity (or, at Covered Entity's direction, to an individual) as necessary for Covered Entity to satisfy its obligations under 45 CFR 164.524.

f. Amendment. Make PHI in a Designated Record Set available to Covered Entity for amendment, and incorporate any amendments, as necessary for Covered Entity to satisfy its obligations under 45 CFR 164.526.

g. Accounting. Document disclosures of PHI, and make such documentation available to Covered Entity, as necessary for Covered Entity to satisfy its obligations under 45 CFR 164.528.

h. HHS. Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules.

i. Minimum Necessary. Limit its uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose.

j. Delegated Obligations. To the extent Business Associate carries out an obligation of Covered Entity under the HIPAA Privacy Rule, comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of that obligation.

4. DATA RETENTION AND DISPOSAL IN THE ORDINARY COURSE

In the ordinary course of the Service: audio recordings are deleted within approximately 48 hours of processing, and clinical notes are automatically deleted approximately 14 days after creation. Covered Entity is responsible for copying any needed documentation into its medical record system before automatic deletion. Limited records (such as audit logs and acceptance records) are retained longer for security, compliance, and legal purposes and remain protected under Section 7(c).

5. OBLIGATIONS OF COVERED ENTITY

Covered Entity shall: (a) notify Business Associate of any limitation in its notice of privacy practices, any change in or revocation of an individual's permission, or any restriction on the use or disclosure of PHI that Covered Entity has agreed to, in each case to the extent it may affect Business Associate's use or disclosure of PHI; (b) not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity; and (c) obtain any consents or authorizations required under applicable law before recording patient encounters through the Service.

6. NO AGENCY

Business Associate is an independent contractor of Covered Entity. Nothing in this Agreement creates an agency relationship between the parties.

7. TERM AND TERMINATION

a. Term. This Agreement is effective on the date of Covered Entity's electronic acceptance and remains in effect for as long as Covered Entity uses the Service, unless terminated earlier as provided herein.

b. Termination for Cause. Either party may terminate this Agreement and the underlying Service arrangement if the other party has violated a material term of this Agreement and fails to cure the violation within thirty (30) days of written notice.

c. Effect of Termination. Upon termination, Business Associate shall, if feasible, return or destroy all PHI it maintains in any form (automatic deletion under Section 4 satisfies this obligation for audio and notes). If return or destruction is infeasible (for example, retained audit logs or records subject to legal hold), Business Associate shall extend the protections of this Agreement to such PHI and limit further use and disclosure to the purposes that make return or destruction infeasible, for as long as it maintains the PHI. This Section survives termination.

8. MISCELLANEOUS

a. Amendment. The parties agree to amend this Agreement as necessary to comply with changes to the HIPAA Rules. Business Associate may publish updated versions of this Agreement; material changes require re-acceptance, and each accepted version is archived and identified by version number and cryptographic hash.

b. Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the parties to comply with the HIPAA Rules.

c. No Third-Party Beneficiaries. Nothing in this Agreement confers any right or remedy upon any person other than the parties.

d. Governing Law. This Agreement is governed by federal law, including HIPAA, and to the extent not preempted, by the laws of the State of Nevada.

ELECTRONIC ACCEPTANCE

By checking the acceptance box and continuing, you (i) agree to this Business Associate Agreement on behalf of yourself and, if applicable, the practice or entity for which you provide services; (ii) represent that you have authority to bind that Covered Entity; and (iii) agree that your electronic acceptance — recorded with your legal name, account email, timestamp, and the version and hash of this document — constitutes a valid and binding signature.

Questions or BAA requests: admin@sampsonscribe.ai