PDM

Business Associate Agreement

Version v2-20260815 · Effective August 15, 2026

Standing terms. These terms are offered by Unboxed Labs LLC on a self-serve basis and take effect when an authorized representative of a Covered Entity accepts them by attestation for a file routed for clinical identifier coverage. Acceptance is required before payment and before processing begins. A separate signature is not required for these terms to take effect. A countersigned copy is available on request (see Section 12).

This Agreement is built to conform to the required provisions for business associate contracts at 45 CFR 164.504(e), using the U.S. Department of Health and Human Services, Office for Civil Rights sample business-associate-contract provisions as its base text, adapted only where the Business Associate’s actual data practices require.

Declining. Acceptance of these terms is not required to use the service. Where a file is routed for clinical identifier coverage, the Covered Entity may instead decline, in which case this Agreement does not take effect for that file, the file is processed with the Business Associate’s standard identifier coverage rather than the clinical identifier set, and the declination is recorded with the job. A Covered Entity that declines is responsible for determining that the file it submits for standard processing does not contain Protected Health Information.

1. Parties, Purpose, and Definitions

This Business Associate Agreement (“Agreement”) is between the customer that accepts it (the “Covered Entity”) and Unboxed Labs LLC, operator of PDM — PII Data Masking (the “Business Associate”). It governs Protected Health Information (“PHI”) that the Business Associate creates, receives, maintains, or transmits on behalf of the Covered Entity when the Covered Entity submits a file for clinical identifier coverage. Terms used but not defined here have the meaning given in the HIPAA Rules (45 CFR Parts 160 and 164).

2. Permitted Uses and Disclosures of PHI

  • The Business Associate may use or disclose PHI only as necessary to perform the masking service the Covered Entity requests — to detect and mask identifiers within the submitted file and return a masked file — and as Required by Law.
  • The Business Associate may use PHI for its own proper management and administration or to carry out its legal responsibilities, and may disclose PHI for those purposes only if the disclosure is Required by Law, or it obtains reasonable written assurances that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose disclosed, and that the recipient will notify the Business Associate of any breach.
  • The Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by the Covered Entity, except for the management, administration, and legal responsibilities above.
  • The Business Associate will not sell PHI, will not use or disclose PHI for marketing, and will not use or disclose PHI — or anything derived from it — to train, improve, fine-tune, or develop any model, product, or service.

3. Obligations of the Business Associate

The Business Associate will:

  • Not use or further disclose PHI other than as permitted or required by this Agreement or as Required by Law;
  • Use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement (see Section 6);
  • Report to the Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required by 45 CFR 164.410, and any Security Incident of which it becomes aware (see Section 5);
  • In accordance with 45 CFR 164.502(e)(1)(ii), ensure that any subcontractors that create, receive, maintain, or transmit PHI on its behalf agree in writing to the same restrictions and conditions that apply to the Business Associate (see Section 4);
  • Make PHI available to the Covered Entity as necessary to satisfy the Covered Entity’s obligations under 45 CFR 164.524 (individual access), to the extent the Business Associate holds such PHI in a Designated Record Set (see Section 7);
  • Make PHI available for amendment, and incorporate amendments, in accordance with 45 CFR 164.526, to the extent the Business Associate holds such PHI (see Section 7);
  • Make available the information required to provide an accounting of disclosures in accordance with 45 CFR 164.528;
  • To the extent the Business Associate is to carry out a Covered Entity obligation under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to the Covered Entity in performing it;
  • Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining the Covered Entity’s compliance with the HIPAA Rules.

4. Subcontractors

The Business Associate processes PHI on cloud infrastructure operated by Google Cloud Platform and maintains a Business Associate Agreement with that provider, under which the provider agrees to safeguards and restrictions at least as protective of PHI as those in this Agreement. Before any other subcontractor handles PHI on the Business Associate’s behalf, the Business Associate will obtain equivalent written assurances.

5. Reporting and Breach Notification

The Business Associate will notify the Covered Entity following discovery of a Breach of Unsecured PHI without unreasonable delay and no later than the timeframe required by 45 CFR 164.410, and will report any other impermissible use or disclosure and any Security Incident of which it becomes aware. Notice will follow the Business Associate’s breach-response procedure and include the information required by 45 CFR 164.410(c) to the extent known. Routine unsuccessful Security Incidents (such as pings, port scans, and failed access attempts that result in no unauthorized access to PHI) need not be reported individually.

6. Safeguards

The Business Associate processes files inside a sealed cloud perimeter with no public network exposure, encrypts PHI in transit and at rest, restricts access to the authorized processes that perform masking, and keeps PHI-clean operational logs that record counts and coverage decisions — never the values of the Covered Entity’s cells.

7. Retention, Return, and Destruction

The Business Associate does not retain PHI beyond the processing window. The Covered Entity’s uploaded file and every intermediate copy the Business Associate creates are destroyed the moment the masked file is delivered, or automatically within 48 hours, whichever comes first. No copy of the PHI is retained after that point.

Because the Business Associate does not retain PHI beyond that window, it holds no Designated Record Set on the Covered Entity’s behalf after the window closes. The access, amendment, and accounting obligations in Section 3 are satisfied by producing any PHI still held within the window and, thereafter, by the fact that no PHI remains; the Covered Entity remains the custodian of the source data.

This automatic destruction lifecycle applies at all times and does not depend on termination — a stronger term than the return-or-destroy-upon-termination provision typical of business associate agreements, since PHI is destroyed on schedule whether or not this Agreement remains in effect. The Business Associate may retain non-content job metadata (row count, column names flagged as sensitive, price, and the attestation record), which does not include PHI.

Processing receipt. The Business Associate issues a processing receipt for each completed job and delivers it to the Covered Entity with the masked file. The receipt records the version of this Agreement accepted and the timestamp of the Covered Entity’s attestation, the processing configuration applied, and counts of the identifiers masked by type. It also carries SHA-256 hashes of both the file submitted and the masked file returned, so that the Covered Entity — or any party to which the Covered Entity provides them — can verify independently that the receipt describes those exact files. The receipt records counts, coverage decisions, and the file name as submitted; it does not contain the values of the Covered Entity’s cells.

8. Obligations of the Covered Entity

The Covered Entity will not request the Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by the Covered Entity, and is responsible for having the authority to submit the PHI for processing.

9. Term and Termination

These terms take effect when accepted by attestation and apply to each file submitted under them.

The Covered Entity may terminate for cause if it determines that the Business Associate has violated a material term and the Business Associate has not cured within a reasonable time, consistent with 45 CFR 164.504(e)(2)(iii). Upon termination, the return-or-destroy obligation is satisfied by the automatic destruction lifecycle in Section 7; because no PHI is retained beyond that lifecycle, no PHI remains to be returned or destroyed.

10. Interpretation and Survival

Any ambiguity in this Agreement will be resolved to permit compliance with the HIPAA Rules. Obligations that by their nature survive termination — including the safeguards and destruction obligations in Sections 6–7 with respect to any PHI still held — survive. This Agreement creates no rights in any third party.

11. Regulatory Basis

This Agreement is intended to satisfy the required provisions for business associate contracts at 45 CFR 164.504(e). Coverage of each required element is documented in PDM’s internal clause-by-clause conformance record.

12. Standing Terms and Countersignature

These are standing terms accepted electronically by attestation; a separate signature is not required for them to take effect. A countersigned copy is available on request — contact us and reference your job.