Business Associate Agreement — SideClick sync relay & patient portal
(HIPAA — the "no-view" BAA for the Practice edition and legacy Sync licences)
Under HHS guidance a service that maintains electronic protected health information is a business associate even when the information is encrypted and the service holds no decryption key, and the "conduit" exception covers only transmission with transient storage — this relay persists ciphertext, so we offer this BAA affirmatively. The Cloud edition's BAA is provided at onboarding.
This Business Associate Agreement ("BAA") is between the subscribing practice ("Covered Entity") and SideClick (Pty) Ltd ("Business Associate"), and applies when the Covered Entity enables the sync relay or patient portal services. It is entered into when the Covered Entity accepts the Terms of Service and enables those services; either party may also request a countersigned copy using the signature block below.
1. The factual posture, stated plainly
The relay stores and routes electronic Protected Health Information ("ePHI") — including phone-captured clinical media (photos and voice memos) — only in encrypted form, without the keys. Content is encrypted on the Covered Entity's own devices before transmission; the Business Associate cannot decrypt, view, or use it. The information the Business Associate can access is limited to the service metadata inventoried in Annex A of the companion relay DPA (incorporated here by reference), of which only the licensee's name and email are directly identifying — and those identify the practice, not patients.
2. Permitted uses and disclosures
The Business Associate may use or disclose ePHI (in its encrypted form) and service metadata only: (a) to provide the relay and portal services to the Covered Entity; (b) for the proper management and administration of the Business Associate and to carry out its legal responsibilities, provided any disclosure is required by law or made under written assurances of confidentiality; and (c) as required by law. No other use or disclosure is permitted. The Business Associate will not — and by design cannot — use ePHI for its own purposes, de-identify it, aggregate it, or sell it.
3. Safeguards
The Business Associate implements the safeguards of Annex B of the relay DPA — end-to-end encryption with no Business Associate key custody, encryption at rest and in transit, minimisation enforced by automated schema tests, hashed connection records — and complies with the Security Rule (45 CFR Part 164, Subpart C) with respect to the ePHI it holds. Under the HHS breach-notification guidance, ePHI encrypted consistently with the referenced NIST standards is not "unsecured" PHI, and its compromise falls within the breach safe harbor unless the decryption key is also compromised — which is the intended effect of this architecture, where the Business Associate never holds the keys at all. The client-side encryption uses AES-256-GCM for stored content and TLS for transport, designed to be consistent with that guidance; the Business Associate does not claim formal validation of its cryptographic modules.
Because the Business Associate never holds keys, authentication and access control for the readable records are performed by the Covered Entity within the software; the parties record that allocation here, as the HHS cloud-computing guidance expects.
4. Reporting
The Business Associate reports to the Covered Entity: (a) any use or disclosure not permitted by this BAA, and any Security Incident, of which it becomes aware, without unreasonable delay; and (b) any Breach of Unsecured PHI without unreasonable delay and in no case later than 60 days after discovery, with the content required by 45 CFR §164.410. The parties record that a compromise of relay storage alone exposes ciphertext and metadata, which bears on whether PHI was "unsecured"; the assessment is made per incident under the Business Associate's incident-response process.
5. Subcontractors
The Business Associate ensures any subcontractor that creates, receives, maintains, or transmits ePHI on its behalf (Annex C of the relay DPA, the sub-processor register) agrees in writing to restrictions and conditions at least as protective as this BAA.
Push notifications to enrolled iPhones are delivered via the Apple Push Notification service. The pushed payloads are engineered to contain no PHI — a fixed alert text, an opaque record identifier, and a count, enforced by automated test — so Apple receives no ePHI through this path. Apple is listed in the register as a delivery carrier for that reason.
6. Individual rights — division of labour
Because the Business Associate cannot read ePHI, requests under 45 CFR §§164.524 (access), 164.526 (amendment), and 164.528 (accounting of disclosures) are fulfilled by the Covered Entity, which holds the readable designated record set and the software's built-in tooling for access, amendment, and disclosure accounting. The Business Associate's obligations are to: (a) maintain the availability and portability floors of the relay DPA §8 so the Covered Entity can always retrieve its data; (b) forward any individual request it receives directly to the Covered Entity within 10 days; and (c) provide, on request, its record of disclosures of metadata, if any.
For the same reason, the Business Associate operates no key escrow and no assisted-restore capability: it cannot decrypt stored ePHI, produce plaintext in response to any request, or recover data whose client-held keys or recovery material the Covered Entity has lost (the no-vendor-recovery rule, EULA §7.6). The §8 portability floor is a ciphertext floor; maintaining recovery material — and therefore the continued producibility of the designated record set — remains the Covered Entity's obligation, supported by the software's export, multi-device, and in-practice key-share tooling.
7. Availability to HHS
The Business Associate makes its internal practices, books, and records relating to ePHI available to the Secretary of HHS for determining the Covered Entity's compliance.
8. Term and termination
This BAA runs with the underlying services. The Covered Entity may terminate the services on the Business Associate's material breach of this BAA that is not cured within 30 days of notice. On termination, the Business Associate returns (by the portability floor — the Covered Entity drains its data) and then destroys the ePHI it holds; where return or destruction is infeasible, protections continue for as long as the ePHI is held. Nothing in termination affects the Covered Entity's local copies.
9. Precedence and construction
For PHI obligations this BAA prevails over the Terms of Service and over any marketplace or app-store terms; a marketplace transaction never substitutes for, replaces, or waives this BAA. This BAA is construed to permit the parties to comply with HIPAA.
Signatures (optional — this BAA takes effect on acceptance of the Terms of Service; a countersigned copy is available on request)
| Covered Entity | Business Associate | |
|---|---|---|
| Entity | ______________________ | SideClick (Pty) Ltd |
| Name, title | ______________________ | ______________________ |
| Date, signature | ______________________ | ______________________ |
Version 1.1 · Published 2026-09-12