BUSINESS ASSOCIATE AGREEMENT
VeriOp AI, LLC
Effective Date: the date the Covered Entity accepts this Agreement electronically or, for a signed Order Form, the Order Form Effective Date.
This Business Associate Agreement ("BAA") is entered into between VeriOp AI, LLC, a Florida limited liability company with offices at 9841 SW 130th Street, Miami, Florida 33176 ("Business Associate" or "VeriOp"), and the healthcare provider, group practice, ambulatory surgery center, or other person or entity that registers for or is granted access to the VeriOp Service ("Covered Entity"). Business Associate and Covered Entity are each a "Party."
RECITALS
A. Covered Entity is a "covered entity" (or a business associate of a covered entity) as defined at 45 C.F.R. § 160.103 and is subject to the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164, each as amended (collectively, "HIPAA").
B. VeriOp provides a cloud-based clinical decision-support and perioperative documentation platform, described at https://www.veriop.ai and in the VeriOp Terms of Service (the "Service"), in the course of which VeriOp creates, receives, maintains, or transmits Protected Health Information on behalf of Covered Entity.
C. The Parties enter this BAA to satisfy 45 C.F.R. §§ 164.502(e) and 164.504(e) and 45 C.F.R. § 164.314(a).
1. DEFINITIONS
Capitalized terms not defined here have the meanings given in HIPAA. "PHI" means Protected Health Information, including Electronic PHI, that VeriOp creates, receives, maintains, or transmits on behalf of Covered Entity. "Breach," "Security Incident," "Unsecured PHI," "Designated Record Set," "Subcontractor," and "Required by Law" have the meanings at 45 C.F.R. §§ 160.103, 164.304, and 164.402. "Underlying Agreement" means the VeriOp Terms of Service and any Order Form between the Parties. "De-identified Information" means health information de-identified in accordance with 45 C.F.R. § 164.514(a)–(c).
2. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
2.1 Services. VeriOp may use and disclose PHI only as necessary to perform the Service for Covered Entity as described in the Underlying Agreement, including processing PHI through automated clinical decision-support models to generate pre-anesthesia assessments, readiness tracking, anesthesia records, prior-authorization drafts, and coding suggestions for review by Covered Entity's licensed clinicians.
2.2 Management and administration. VeriOp may use PHI for its proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes if the disclosure is Required by Law or VeriOp obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify VeriOp of any breach of confidentiality.
2.3 De-identification. VeriOp may use PHI to create De-identified Information in accordance with 45 C.F.R. § 164.514(b)(2) (Safe Harbor). De-identified Information is not PHI, is owned by VeriOp, and may be used by VeriOp for any lawful purpose, including product improvement, validation studies, analytics, and licensed research datasets, subject to the re-identification prohibitions in Section 4.7 and the disclosures in the Terms of Service and Privacy Policy.
2.4 Data aggregation. VeriOp may use PHI to provide Data Aggregation services relating to Covered Entity's Health Care Operations as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
2.5 Required by Law. VeriOp may use or disclose PHI as Required by Law.
2.6 Prohibitions. VeriOp shall not (a) use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted in Sections 2.2–2.4; (b) sell PHI; (c) use or disclose PHI for marketing or fundraising; or (d) use PHI to train, fine-tune, or otherwise improve any artificial-intelligence or machine-learning model. For clarity, De-identified Information created under Section 2.3 may be used for model and product improvement.
3. OBLIGATIONS OF BUSINESS ASSOCIATE
3.1 Safeguards. VeriOp shall implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of Electronic PHI as required by Subpart C of 45 C.F.R. Part 164, including the measures in Section 5.
3.2 Minimum necessary. VeriOp shall limit its uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b) and Covered Entity's minimum-necessary policies communicated to VeriOp in writing.
3.3 Subcontractors. VeriOp shall ensure, by written agreement meeting 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.504(e)(1)(i), that any Subcontractor that creates, receives, maintains, or transmits PHI on VeriOp's behalf agrees to restrictions and conditions at least as protective as those in this BAA. Covered Entity acknowledges and consents to the following Subcontractors as of the Effective Date: (a) Amazon Web Services, Inc. — hosting, storage, encryption, email delivery, and access to Anthropic Claude foundation models through Amazon Bedrock, each within VeriOp's AWS environment under the AWS Business Associate Addendum (PHI is not transmitted to Anthropic, PBC directly); Twilio Inc. is not a Subcontractor: it transmits only a fixed, content-free visit reminder ("your visit starts in about 30 minutes") and provider booking alerts, receives no PHI beyond a mobile number the recipient supplied for that purpose, and each message record is deleted from Twilio upon delivery; fasting instructions, results, and all clinical content are delivered by email within the AWS environment. VeriOp shall maintain a current list of Subcontractors and make it available on request. Stripe, Inc. (payments) and Mixpanel, Inc. (product analytics) are not Subcontractors under this BAA: VeriOp does not send PHI from the clinical Service to either, session recording is disabled on every authenticated clinical route, and form inputs are masked wherever recording runs.
3.4 Reporting. VeriOp shall report to Covered Entity in writing: (a) any use or disclosure of PHI not permitted by this BAA; (b) any Security Incident; and (c) any Breach of Unsecured PHI, in each case without unreasonable delay and no later than ten (10) calendar days after Discovery. This period is shorter than the sixty-day outer limit in 45 C.F.R. § 164.410 and is set to satisfy the ten-day third-party-agent notice required by the Florida Information Protection Act, § 501.171(6), Florida Statutes, so that Covered Entity can meet its own thirty-day individual-notice deadline. The Parties agree that this Section constitutes notice of, and no further reporting is required for, Unsuccessful Security Incidents, meaning pings and other broadcast attacks on VeriOp's firewall, port scans, unsuccessful log-on attempts, denial-of-service attacks that do not result in unauthorized access, and similar activity that does not result in unauthorized access to, or use or disclosure of, PHI.
3.5 Breach content and cooperation. A Breach report shall include, to the extent known and supplemented as information becomes available: the identity of each individual whose Unsecured PHI was or is reasonably believed to have been affected; a description of what happened, the dates of the Breach and of Discovery, and the types of PHI involved; the steps affected individuals should take; and what VeriOp is doing to investigate, mitigate, and prevent recurrence. VeriOp shall cooperate with Covered Entity's risk assessment under 45 C.F.R. § 164.402(2) and shall, at Covered Entity's direction and at VeriOp's expense where the Breach arose from VeriOp's breach of this BAA, assist with individual, media, and HHS notifications Covered Entity is required to make.
3.6 Mitigation. VeriOp shall mitigate, to the extent practicable, any harmful effect known to VeriOp of a use or disclosure of PHI in violation of this BAA.
3.7 Access. Within fifteen (15) days of Covered Entity's written request, VeriOp shall make PHI maintained in a Designated Record Set available to Covered Entity so that Covered Entity may meet its obligations under 45 C.F.R. § 164.524. If an individual requests access directly from VeriOp, VeriOp shall forward the request to Covered Entity within five (5) business days. The Parties acknowledge that under the Terms of Service the Service is not the Covered Entity's system of record and that Covered Entity's Designated Record Set is maintained in Covered Entity's own medical record.
3.8 Amendment. VeriOp shall, within fifteen (15) days of Covered Entity's written direction, make PHI available for amendment and incorporate amendments as required by 45 C.F.R. § 164.526.
3.9 Accounting of disclosures. VeriOp shall document disclosures of PHI and related information as would be required for Covered Entity to respond to a request for an accounting under 45 C.F.R. § 164.528, and shall provide such documentation within fifteen (15) days of written request.
3.10 Delegated obligations. To the extent VeriOp carries out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, VeriOp shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligations.
3.11 Books and records. VeriOp shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA. Nothing in this Section waives any applicable privilege or protection, including with respect to trade secrets and confidential commercial information.
3.12 Workforce. VeriOp shall train workforce members with access to PHI on HIPAA and this BAA before access is granted and at least annually, and shall apply sanctions for violations.
3.13 Location of data. VeriOp shall store and process PHI only in data centers located in the United States (currently the AWS US East (N. Virginia) region, including model inference) and shall not permit access to PHI from outside the United States without Covered Entity's prior written consent.
3.14 Legal process. If VeriOp receives a subpoena, court order, civil investigative demand, or other governmental or third-party request for PHI, VeriOp shall, to the extent legally permitted, notify Covered Entity promptly and before disclosure so that Covered Entity may seek a protective order or other remedy, and shall disclose only the minimum PHI required.
3.15 State law. Where a state law that applies to Covered Entity's PHI is more stringent than HIPAA and is not preempted, including the Florida Information Protection Act, § 501.171, Florida Statutes, VeriOp shall comply with the more stringent requirement in performing this BAA.
3.16 Assessment and cooperation. Not more than once per twelve-month period, and on thirty (30) days' written notice, VeriOp shall provide Covered Entity with reasonable documentary evidence of the safeguards described in Section 5 — including its current information-security policy, risk-analysis summary, subprocessor list, and any third-party assessment or attestation VeriOp then holds — and shall complete Covered Entity's reasonable written security questionnaire. VeriOp shall also cooperate in good faith with any HHS investigation or compliance review of Covered Entity that concerns PHI processed by VeriOp. On-site inspection is not required; Covered Entity bears its own costs of review.
4. OBLIGATIONS OF COVERED ENTITY
4.1 Covered Entity shall notify VeriOp of any limitation in its notice of privacy practices, any change in or revocation of an individual's permission, and any restriction on use or disclosure agreed to under 45 C.F.R. § 164.522, in each case to the extent it may affect VeriOp's use or disclosure of PHI, and shall not agree to any such restriction that would prevent VeriOp from performing the Service without first giving VeriOp written notice and a reasonable opportunity to terminate the affected Service.
4.2 Covered Entity represents that it has obtained all consents and authorizations, and provided all notices, required under HIPAA and applicable state law for VeriOp to receive and process PHI as contemplated by the Underlying Agreement, including any state-law consent for the disclosure of specially protected information (e.g., mental health, substance use disorder under 42 C.F.R. Part 2, HIV, genetic information) that Covered Entity elects to submit.
4.3 Covered Entity shall not request VeriOp to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except as permitted by Section 2.
4.4 Covered Entity is responsible for the acts and omissions of its workforce members and authorized users, for administering user access within its VeriOp practice account (including promptly removing departed users), and for maintaining its own legal medical record as provided in the Terms of Service.
4.5 Covered Entity acknowledges that the Service provides clinical decision support only; that every assessment, record, code suggestion, and draft produced by the Service must be reviewed by a licensed clinician exercising independent professional judgment; and that Covered Entity and its clinicians retain sole responsibility for patient care decisions.
4.6 Marketplace clinicians. Where a patient obtains a clearance through the VeriOp patient marketplace, the independent licensed clinician who performs the evaluation is the covered entity for that encounter, and VeriOp acts as that clinician's business associate under a separate BAA. Covered Entity acknowledges that clearance documents it receives through the marketplace originate from that clinician.
4.7 Submission channels. Covered Entity shall submit PHI to VeriOp only through the Service's designated upload, intake, and charting features, which are encrypted and logged, and not by email, text message, chat support, or any other channel, unless VeriOp has confirmed in writing that the channel is covered by this BAA.
5. SECURITY REPRESENTATIONS
VeriOp represents that, as of the Effective Date, it maintains at least the following and will not materially reduce them during the term:
(a) encryption of Electronic PHI in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent; (b) unique user identification for every account; role-based access controls limiting each user to the patients of their own practice and role; practice-level data isolation; support for phishing-resistant passkey (WebAuthn) authentication for all users; multi-factor authentication enforced for all VeriOp administrative and infrastructure access; (c) logging of infrastructure and API activity (AWS CloudTrail, multi-region, with log-file integrity validation) retained for not less than six (6) years, and append-only application audit trails for signed anesthesia records; (d) automated de-identification with no human access to identified PHI in the analytics pipeline; (e) hosting exclusively on HIPAA-eligible AWS services covered by the AWS Business Associate Addendum; (f) a written information-security policy and incident-response plan, and a risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A) reviewed at least annually and after any significant change, most recently completed in September 2026; (g) processing of PHI by artificial-intelligence models solely to generate the output requested by Covered Entity; no PHI is used to train, fine-tune, or evaluate models; model inference runs on Amazon Bedrock within VeriOp's AWS environment, where, under AWS's published service terms, prompts and outputs are not stored, are not shared with the model developer, and are not used to train or improve any model.
6. TERM AND TERMINATION
6.1 Term. This BAA is effective on the Effective Date and continues for so long as VeriOp maintains any PHI on behalf of Covered Entity.
6.2 Termination for cause. Either Party may terminate this BAA and the Underlying Agreement if the other Party materially breaches this BAA and fails to cure within thirty (30) days after written notice, or immediately if cure is not possible.
6.3 Effect of termination; return or destruction. Upon termination of the Underlying Agreement, VeriOp shall make all PHI available to Covered Entity for export in a commonly used electronic format at no charge, and shall return or destroy the PHI within thirty (30) days of Covered Entity's written direction, certifying destruction in writing.
Absent that direction, VeriOp retains the PHI, protected by this BAA and used for no purpose other than making it available to Covered Entity. The Parties agree this is the arrangement that best serves the individuals whose information is at issue: Service outputs (including signed pre-anesthesia assessments and intra-operative anesthesia records) form part of the patient's medical record, Covered Entity bears the retention obligations under 45 C.F.R. § 164.316(b)(2), state law, and applicable accreditation standards, and unilateral destruction by VeriOp on a timer could destroy a record Covered Entity is required to keep. Return or destruction therefore occurs when Covered Entity says so, not on a schedule VeriOp sets.
Where return or destruction is infeasible, VeriOp shall extend the protections of this BAA to such PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible. Encrypted backups containing destroyed PHI are purged in the ordinary backup cycle within thirty-five (35) days. Signed records are never altered after signature; corrections are appended as addenda. De-identified Information is not PHI and is not subject to return or destruction.
6.4 Survival. Sections 2.6, 3.4–3.6, 3.11, 3.14, 3.15, 6.3, 7, and 8 survive termination.
7. LIABILITY AND INDEMNITY
7.1 Each Party shall indemnify, defend, and hold harmless the other Party from third-party claims, fines, penalties, and reasonable costs (including notification costs and reasonable attorneys' fees) to the extent arising from the indemnifying Party's breach of this BAA or violation of HIPAA.
7.2 Except for VeriOp's obligations under Section 7.1 for a Breach caused by VeriOp's breach of this BAA, the limitations and exclusions of liability in the Underlying Agreement apply to this BAA.
8. MISCELLANEOUS
8.1 Regulatory references. A reference to a section of HIPAA means the section as in effect or amended.
8.2 Amendment. The Parties shall amend this BAA as necessary to comply with changes in HIPAA or other applicable law. VeriOp may update this BAA on thirty (30) days' notice to the extent required by law; other amendments require a writing signed or electronically accepted by both Parties.
8.3 Interpretation; order of precedence. Any ambiguity shall be resolved to permit compliance with HIPAA. In a conflict concerning PHI, this BAA controls over the Underlying Agreement; in all other matters the Underlying Agreement controls.
8.4 No third-party beneficiaries. Nothing in this BAA confers rights on any third party, including individuals whose PHI is processed.
8.5 Independent contractors. The Parties are independent contractors; nothing here creates an agency relationship.
8.6 Governing law; venue. Florida law governs, without regard to conflict-of-laws rules; disputes are resolved as provided in the Underlying Agreement.
8.7 Notices. To VeriOp: privacy@veriop.ai and the address above, attention Privacy Officer. To Covered Entity: the account owner's email of record.
8.8 Electronic acceptance. Covered Entity may accept this BAA by clicking "I agree" or similar affirmative action during registration or invitation acceptance, or by executing an Order Form that incorporates it. Electronic acceptance has the same force as a handwritten signature under the E-SIGN Act and Florida's Uniform Electronic Transaction Act.
8.9 Entire agreement. This BAA, together with the Underlying Agreement, is the Parties' entire agreement concerning PHI and supersedes the prior "MyPreOp.ai Business Associate Agreement," which is replaced in its entirety with respect to PHI processed on or after the Effective Date; PHI processed before that date remains protected on terms no less protective than those herein.
| COVERED ENTITY | BUSINESS ASSOCIATE — VeriOp AI, LLC |
|---|---|
| Signature: | Signature: |
| Name: | Name: Dennis Diaz, CRNA |
| Title / credentials: | Title: President |
| Organization: | Date: |
| Date: |
Related: Terms of Service · Privacy Policy · Subprocessors