HIPAA Compliance

BUSINESS
ASSOCIATE
AGREEMENT

Version 1.0 — Effective upon execution

This Business Associate Agreement (“BAA”) is entered into between RGX Systems (“Business Associate”) and the Partner executing this agreement (“Covered Entity” or “Covered Business Associate”). It supplements the RGX Systems Master Service Agreement and governs the handling of Protected Health Information (“PHI”) in connection with services provided under that agreement.

Technical note: RGX Systems processes PHI exclusively in-memory using automated scrubbing prior to any LLM call. Raw PHI is never written to persistent storage. De-identified text — PHI replaced with numbered tokens ({{REDACTED_PHI_N}}) and person names replaced separately with [NAME_N] tokens — is what reaches the LLM provider. Where Covered Entity runs its own AI model instead of an RGX-hosted one (passthrough: true), this same scrubbing still applies before the de-identified text is returned to Covered Entity; no raw PHI or name reaches Covered Entity's own model either. This architecture is described in the RGX Data Flow Document available at /data-flow.

1. Definitions

Terms used but not defined in this BAA have the meanings given to them in the HIPAA Rules (45 CFR Parts 160 and 164).

2. Obligations of Business Associate (RGX Systems)

2.1 Permitted Uses and Disclosures

RGX Systems may use or disclose PHI only as follows:

2.2 Prohibited Uses

RGX Systems shall not use or disclose PHI in any manner that would violate HIPAA Rules if done by Covered Entity. RGX Systems shall not:

2.3 Appropriate Safeguards

RGX Systems shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI, including:

2.4 Reporting of Security Incidents and Breaches

RGX Systems shall:

2.5 Subcontractors

RGX Systems shall require any subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree, in writing, to the same restrictions, conditions, and requirements that apply to RGX Systems under this BAA.

Current infrastructure subcontractors with executed HIPAA BAAs:

2.6 Individual Rights

To the extent RGX Systems holds PHI in a Designated Record Set, RGX Systems shall make PHI available to Covered Entity as necessary for Covered Entity to fulfill individuals’ rights to access (45 CFR §164.524), amendment (45 CFR §164.526), and accounting of disclosures (45 CFR §164.528). Given that RGX Systems processes PHI in-memory without persistent storage of raw PHI, no Designated Record Set is maintained by RGX Systems in the ordinary course of operations.

2.7 Minimum Necessary

RGX Systems shall use, disclose, and request only the minimum amount of PHI necessary to accomplish the purpose of each use, disclosure, or request.

2.8 Return or Destruction of PHI

Upon termination of the Master Service Agreement, RGX Systems shall, within 30 days of written request:

Note: Given that RGX Systems does not persist raw PHI in the ordinary course of operations, termination data return obligations primarily apply to usage metadata logs, which are purged within 30 days upon written request.

3. Obligations of Covered Entity

3.1 Notice of Privacy Practices

Covered Entity shall notify RGX Systems of any limitation in its notice of privacy practices that affects RGX Systems’ permitted uses or disclosures of PHI.

3.2 Individual Permissions

Covered Entity shall notify RGX Systems of any changes in, or revocation of, permission from an individual regarding use or disclosure of PHI, to the extent such changes affect RGX Systems’ permitted uses or disclosures.

3.3 Restriction Agreements

Covered Entity shall notify RGX Systems of any restriction agreed to with individuals under 45 CFR §164.522 that restricts a use or disclosure otherwise permitted under this BAA.

3.4 Lawful Requests Only

Covered Entity shall not request RGX Systems to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.

3.5 Minimum Necessary

Covered Entity shall ensure that PHI transmitted to RGX Systems is limited to the minimum necessary to accomplish the intended purpose of each request.

4. Term and Termination

4.1 Term

This BAA shall be effective upon execution and shall remain in effect until the termination of the Master Service Agreement, unless earlier terminated as provided herein.

4.2 Termination for Cause

Either party may terminate this BAA and the underlying Master Service Agreement upon 30 days’ written notice if the other party materially breaches any provision of this BAA and fails to cure such breach within the notice period. Covered Entity may terminate immediately if RGX Systems violates any material term and cure is not possible.

4.3 Effect of Termination

Upon termination, the provisions of Section 2.8 (Return or Destruction of PHI) shall apply. Sections 1, 4, 5, and 6 shall survive termination of this BAA.

5. Miscellaneous

5.1 Regulatory References

Any reference in this BAA to a section of the HIPAA Rules shall mean the section as in effect or amended at the time of the relevant use or disclosure, including any successor provision.

5.2 Entire Agreement

This BAA, together with the Master Service Agreement, constitutes the entire agreement between the parties with respect to PHI and supersedes all prior agreements relating to the same subject matter. In the event of a conflict between this BAA and the Master Service Agreement with respect to PHI, this BAA shall control.

5.3 Amendment

This BAA may be amended only by a written instrument signed by both parties. RGX Systems may amend this BAA unilaterally to the extent necessary to comply with changes in applicable law, with 30 days’ notice to Covered Entity.

5.4 No Third-Party Beneficiaries

This BAA is made for the exclusive benefit of the parties. Nothing herein is intended to, or shall, create any rights in any third party.

5.5 Governing Law

This BAA shall be governed by federal law to the extent applicable. To the extent state law applies, this BAA shall be governed by the laws of the State of Delaware, without regard to conflict of law principles.

5.6 Indemnification

Each party shall indemnify and hold the other harmless from and against any claims, damages, penalties, or costs arising from its breach of this BAA or violation of the HIPAA Rules, to the extent caused by such party’s acts or omissions.

6. Execution

By executing below, the parties agree to the terms of this Business Associate Agreement. Electronic signatures are binding.

Business Associate

Company

RGX Systems

Authorized Signature
Printed Name & Title
Date

Contact: legal@rgxsystems.com

Covered Entity / Business Associate

Company Name
Authorized Signature
Printed Name & Title
Date

To request a signed BAA or for questions about HIPAA compliance, contact legal@rgxsystems.com. Supporting documents: Data Flow Diagram · Privacy Policy · Data Processing Agreement · Security Overview