Version 1.0 — Effective upon execution
This Business Associate Agreement (“BAA”) is entered into between RGX Systems (“Business Associate”) and the Partner executing this agreement (“Covered Entity” or “Covered Business Associate”). It supplements the RGX Systems Master Service Agreement and governs the handling of Protected Health Information (“PHI”) in connection with services provided under that agreement.
Technical note: RGX Systems processes PHI exclusively in-memory using automated scrubbing prior to any LLM call. Raw PHI is never written to persistent storage. De-identified text — PHI replaced with numbered tokens ({{REDACTED_PHI_N}}) and person names replaced separately with [NAME_N] tokens — is what reaches the LLM provider. Where Covered Entity runs its own AI model instead of an RGX-hosted one (passthrough: true), this same scrubbing still applies before the de-identified text is returned to Covered Entity; no raw PHI or name reaches Covered Entity's own model either. This architecture is described in the RGX Data Flow Document available at /data-flow.
Terms used but not defined in this BAA have the meanings given to them in the HIPAA Rules (45 CFR Parts 160 and 164).
RGX Systems may use or disclose PHI only as follows:
RGX Systems shall not use or disclose PHI in any manner that would violate HIPAA Rules if done by Covered Entity. RGX Systems shall not:
RGX Systems shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI, including:
{{REDACTED_PHI_N}} token placeholders[NAME_N], independent of the PHI patterns above — applied whether RGX or Covered Entity's own model performs the inference. Name tokens are rehydrated back to the real name only in RGX-hosted responses, using a mapping held solely in process memory and purged within 30 minutes of inactivity; the mapping is never written to disk, logs, or the database, and is never rehydrated at all when Covered Entity runs its own modelcompliance_redaction_events audit table/api/v1/process request matching the healthcare industry profile — no manual intervention required; scrubbing cannot be bypassed by API callers, including when Covered Entity routes inference to its own model via passthrough: trueRGX Systems shall:
RGX Systems shall require any subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree, in writing, to the same restrictions, conditions, and requirements that apply to RGX Systems under this BAA.
Current infrastructure subcontractors with executed HIPAA BAAs:
To the extent RGX Systems holds PHI in a Designated Record Set, RGX Systems shall make PHI available to Covered Entity as necessary for Covered Entity to fulfill individuals’ rights to access (45 CFR §164.524), amendment (45 CFR §164.526), and accounting of disclosures (45 CFR §164.528). Given that RGX Systems processes PHI in-memory without persistent storage of raw PHI, no Designated Record Set is maintained by RGX Systems in the ordinary course of operations.
RGX Systems shall use, disclose, and request only the minimum amount of PHI necessary to accomplish the purpose of each use, disclosure, or request.
Upon termination of the Master Service Agreement, RGX Systems shall, within 30 days of written request:
Note: Given that RGX Systems does not persist raw PHI in the ordinary course of operations, termination data return obligations primarily apply to usage metadata logs, which are purged within 30 days upon written request.
Covered Entity shall notify RGX Systems of any limitation in its notice of privacy practices that affects RGX Systems’ permitted uses or disclosures of PHI.
Covered Entity shall notify RGX Systems of any changes in, or revocation of, permission from an individual regarding use or disclosure of PHI, to the extent such changes affect RGX Systems’ permitted uses or disclosures.
Covered Entity shall notify RGX Systems of any restriction agreed to with individuals under 45 CFR §164.522 that restricts a use or disclosure otherwise permitted under this BAA.
Covered Entity shall not request RGX Systems to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.
Covered Entity shall ensure that PHI transmitted to RGX Systems is limited to the minimum necessary to accomplish the intended purpose of each request.
This BAA shall be effective upon execution and shall remain in effect until the termination of the Master Service Agreement, unless earlier terminated as provided herein.
Either party may terminate this BAA and the underlying Master Service Agreement upon 30 days’ written notice if the other party materially breaches any provision of this BAA and fails to cure such breach within the notice period. Covered Entity may terminate immediately if RGX Systems violates any material term and cure is not possible.
Upon termination, the provisions of Section 2.8 (Return or Destruction of PHI) shall apply. Sections 1, 4, 5, and 6 shall survive termination of this BAA.
Any reference in this BAA to a section of the HIPAA Rules shall mean the section as in effect or amended at the time of the relevant use or disclosure, including any successor provision.
This BAA, together with the Master Service Agreement, constitutes the entire agreement between the parties with respect to PHI and supersedes all prior agreements relating to the same subject matter. In the event of a conflict between this BAA and the Master Service Agreement with respect to PHI, this BAA shall control.
This BAA may be amended only by a written instrument signed by both parties. RGX Systems may amend this BAA unilaterally to the extent necessary to comply with changes in applicable law, with 30 days’ notice to Covered Entity.
This BAA is made for the exclusive benefit of the parties. Nothing herein is intended to, or shall, create any rights in any third party.
This BAA shall be governed by federal law to the extent applicable. To the extent state law applies, this BAA shall be governed by the laws of the State of Delaware, without regard to conflict of law principles.
Each party shall indemnify and hold the other harmless from and against any claims, damages, penalties, or costs arising from its breach of this BAA or violation of the HIPAA Rules, to the extent caused by such party’s acts or omissions.
By executing below, the parties agree to the terms of this Business Associate Agreement. Electronic signatures are binding.
RGX Systems
Contact: legal@rgxsystems.com
To request a signed BAA or for questions about HIPAA compliance, contact legal@rgxsystems.com. Supporting documents: Data Flow Diagram · Privacy Policy · Data Processing Agreement · Security Overview