™HIPAA Business Associate Agreement
Business Associate Agreement
The HIPAA agreement between your practice and Hybreu Digital LLC (ABAIQ) for the protected health information processed through the Services.
| Document | Business Associate Agreement · ABAIQ-BAA |
| Version | 2.0 |
| Effective date | October 2, 2026 (for you: the date you accept it) |
| Replaces | Version 1.1 (September 21, 2026) and version 1.0 |
| Parties | Hybreu Digital LLC, doing business as ABAIQ (Business Associate), and the Customer that accepts this Agreement (Covered Entity or Business Associate) |
| Acceptance | Electronic: the registration checkbox and, for the QA Suite, the e-sign flow with signature. For an agency, acceptance by its authorized representative or signature of the Agency Agreement. Every Customer accepts version 2.0 again. |
| Related documents | Terms of Service · QA Suite Terms of Use · Privacy Policy · Security & Development Practices |
Preamble
This Business Associate Agreement (this "Agreement" or "BAA") is entered into between HYBREU DIGITAL LLC, a Florida limited liability company doing business as ABAIQ, with its principal place of business at 9555 SW 175th Terrace #799, Palmetto Bay, Florida 33157 ("ABAIQ"), and the individual or legal entity that accepts the terms of this Agreement electronically or otherwise affirmatively manifests assent ("Customer").
ABAIQ and Customer are each a "Party" and together the "Parties." This Agreement is incorporated into and made part of the ABAIQ Terms of Service and, for the QA Suite, the QA Suite Terms of Use entered between the Parties (together, the "Services Agreement"). Where this Agreement and the Services Agreement conflict regarding the handling of Protected Health Information, this Agreement controls. Where Customer has signed a written Agency Agreement with ABAIQ, that agreement and this Agreement are read together, and this Agreement controls as to Protected Health Information.
1. Purpose and Applicability
1.1 Background
Customer is either a "covered entity" or a "business associate" under the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act of 2009 ("HITECH"), and the regulations promulgated thereunder at 45 C.F.R. Parts 160 and 164, including the Privacy Rule, the Security Rule and the Breach Notification Rule (collectively, "HIPAA"). In providing the Services, ABAIQ may create, receive, maintain, or transmit Protected Health Information on behalf of Customer and is therefore a business associate of Customer under HIPAA. ABAIQ acknowledges that it is directly obligated to comply with the Security Rule, with the provisions of the Privacy Rule made applicable to business associates by HITECH, and with the Breach Notification Rule, and that it may be directly liable to the Secretary and to state attorneys general for non-compliance.
1.2 Who the Customer is
"Customer" means the person or entity that accepts this Agreement, whether (a) an ABA practice or agency, acting through an authorized representative; (b) an independent clinician, or the professional entity through which that clinician practices, that is itself a covered entity or a business associate of a covered entity; or (c) an individual licensed or certified clinician who is a member of an organization's workforce (for example an employed Registered Behavior Technician) and who accepts this Agreement in the course of that work. In case (c), the individual represents that the organization has authorized the use of the Services with its clients' Protected Health Information, and the organization is the covered entity or business associate on whose behalf ABAIQ acts; where that organization later accepts this Agreement or signs an Agency Agreement, the organization is the Customer.
1.3 Services Description
ABAIQ provides a software-as-a-service platform consisting of a Chrome browser extension and supporting backend infrastructure that assists licensed or certified clinical professionals practicing Applied Behavior Analysis, including Board Certified Behavior Analysts (BCBAs), Board Certified Assistant Behavior Analysts (BCaBAs), Registered Behavior Technicians (RBTs), and other qualified personnel, in generating clinical documentation drafts through artificial intelligence. Such documentation may include session notes, Behavior Intervention Plan (BIP) extractions, supervision notes, caregiver training notes, protocol modification notes, monthly reports, graphs and related clinical content (collectively, the "Services"). The Services also include the optional ABAIQ QA Suite, through which a supervising clinician receives completed notes for AI-assisted documentation-quality review, whether sent by a connected technician from the extension or uploaded by the supervisor as PDF, Word or ZIP files exported from Customer's electronic record (batch review, "Tasks"), together with the agency portal, the "Flag an AI error" reporting channel and the reports the QA Suite produces.
1.4 Scope
This Agreement applies only to Protected Health Information that Customer transmits to, processes through, or causes to be processed by the Services. This Agreement does not apply to information that is not Protected Health Information, to data submitted outside the Services, or to Customer's use of any third-party products or integrations not provided by ABAIQ.
2. Definitions
Capitalized terms not defined below have the meanings given to them in HIPAA.
Breach means the acquisition, access, use, or disclosure of Protected Health Information in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of such information, as defined at 45 C.F.R. § 164.402.
Protected Health Information or "PHI" means individually identifiable health information, as defined at 45 C.F.R. § 160.103, that ABAIQ creates, receives, maintains, or transmits on behalf of Customer through the Services. References to PHI include electronic Protected Health Information ("ePHI") where applicable.
Secretary means the Secretary of the United States Department of Health and Human Services or any officer or employee to whom the Secretary has delegated authority.
Security Incident has the meaning given at 45 C.F.R. § 164.304 and includes, without limitation, attempts to gain unauthorized access to ePHI or to a system that contains ePHI, unwanted disruption or denial of service to systems that contain ePHI, unauthorized use of a system for the processing or storage of ePHI, and changes to system hardware, firmware or software without the owner's knowledge, instruction or consent. Unsuccessful Security Incident means attempted but unsuccessful events of a trivial and routine nature, including without limitation port scans, pings, denial-of-service attempts that do not affect service availability, invalid login attempts, and similar broadcast events that do not result in actual compromise of PHI.
Subprocessor means any third-party service provider engaged by ABAIQ that, in the course of providing services to ABAIQ, creates, receives, maintains, or transmits PHI on ABAIQ's behalf.
Upstream Customer means an individual or entity for whom Customer acts as a business associate.
Workforce has the meaning given at 45 C.F.R. § 160.103.
3. Permitted and Prohibited Uses and Disclosures by ABAIQ
3.1 Permitted Uses and Disclosures
ABAIQ may create, receive, maintain, use, and disclose PHI solely as follows:
- To provide and operate the Services for Customer in accordance with the Services Agreement and this Agreement, including the documentation-quality review of notes, the production of reports for Customer, and the investigation of errors Customer reports;
- For the proper management and administration of ABAIQ, provided that any such use or disclosure outside ABAIQ requires either (i) that the disclosure be required by law, or (ii) that ABAIQ obtain from the recipient written assurances that the PHI will be kept confidential, used only for the purpose disclosed or as required by law, and that any breach of confidentiality will be reported promptly to ABAIQ;
- To carry out ABAIQ's legal responsibilities, subject to the same conditions in the preceding subsection;
- To report to appropriate federal or state authorities violations of law that ABAIQ becomes aware of, consistent with 45 C.F.R. § 164.502(j)(1); and
- As otherwise required by law.
3.2 Prohibited Uses and Disclosures
ABAIQ will not:
- Use or disclose PHI in any manner that would violate the HIPAA Privacy Rule if such use or disclosure were made by Customer;
- Use or disclose PHI for marketing purposes as defined at 45 C.F.R. § 164.501;
- Sell PHI within the meaning of 45 C.F.R. § 164.502(a)(5)(ii);
- De-identify PHI for any purpose of its own; ABAIQ keeps only service metadata that contains no PHI (account codes, timestamps, counts, note types, verdict categories and finding labels) to operate, secure and bill the Services;
- Use Customer's PHI to train, fine-tune, develop, evaluate, benchmark, or improve any artificial intelligence or machine learning model, including any large language model, owned or operated by ABAIQ or by any third party, except as ephemeral inputs and outputs strictly necessary to deliver the response to Customer's request in real time. ABAIQ has configured its artificial intelligence Subprocessors under Zero Data Retention terms, meaning such Subprocessors do not retain Customer's inputs or outputs beyond the duration of the request.
3.3 Minimum Necessary
ABAIQ will use, disclose, and request only the minimum amount of PHI reasonably necessary to perform the Services. The Parties acknowledge and agree that the PHI transmitted by Customer through the Services constitutes the minimum necessary for ABAIQ to perform the Services as configured by Customer.
4. Safeguards
4.1 Administrative, Physical, and Technical Safeguards
ABAIQ will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, consistent with the HIPAA Security Rule at 45 C.F.R. Part 164, Subpart C, and will maintain written policies and procedures implementing its obligations under HIPAA and this Agreement, available to Customer for review on written request.
4.2 Specific Safeguards Implemented
Without limiting the generality of the foregoing, ABAIQ currently maintains the following safeguards:
- Encryption in transit. All PHI transmitted between Customer's browser, ABAIQ's backend services, and ABAIQ's Subprocessors is encrypted using Transport Layer Security version 1.2 or higher.
- HIPAA-eligible infrastructure in the United States. ABAIQ's backend services are hosted on Amazon Web Services infrastructure located in the United States and designated by AWS as HIPAA-eligible, pursuant to a Business Associate Addendum that ABAIQ has accepted with AWS. PHI stored by ABAIQ is encrypted at rest.
- Zero Data Retention with AI Subprocessors. ABAIQ has configured Zero Data Retention with its artificial intelligence Subprocessors so that PHI inputs and outputs are not retained beyond the duration of the request.
- Access controls. ABAIQ implements role-based access controls, requires strong authentication for administrative access, and logs access to systems handling PHI. Within the Services, a note is visible only to the person who sent or uploaded it, the supervisor it was sent to, and, for an agency, the agency's administrator.
- No persistent storage of generated documentation (base note-writing feature). Clinical notes generated through the base note-writing feature are not stored on ABAIQ's servers after delivery to Customer's browser, other than transient processing artifacts.
- QA Suite retention. Where Customer uses the QA Suite, ABAIQ transmits, stores, and retains each reviewed note together with its note type, service date, client identifiers (initials for notes sent from the extension; the client name for notes uploaded in batch review, used to file the note under the right client and plan), sender and supervisor identity, the AI quality evaluation, any supervisor feedback, the uploaded files as received and any corrected versions, the batch reports, and any "Flag an AI error" report with the reason given, on the HIPAA-eligible, BAA-covered AWS infrastructure described above, encrypted in transit and at rest, for the purposes of delivering the review workflow, maintaining the supervision and audit record, and investigating reported errors, and for the retention period described in Section 6 of the QA Suite Terms of Use. The client's date of birth and insurance identifiers present in an exported note are discarded at intake and not stored in the review record. This retention is a permitted use for the Services as configured by Customer. Customer may delete a batch and its files through the Services at any time.
5. Customer Obligations
5.1 Permitted Submissions Only
Customer represents and warrants that Customer has all necessary authorizations, consents, and legal rights to disclose to ABAIQ any PHI Customer submits to the Services, and that any individual who submits PHI under Customer's account or organization is authorized by Customer to do so.
5.2 Qualified Personnel
Customer represents and warrants that the Services will be used only by personnel who hold the licenses, certifications, registrations, or other authorizations required under applicable state and federal law to perform the clinical activities for which the Services are used (including without limitation BCBAs, BCaBAs, RBTs, and other duly qualified clinical staff).
5.3 Customer Maintains the Designated Record Set
The Parties acknowledge and agree that ABAIQ does not maintain PHI in a Designated Record Set on Customer's behalf and does not use PHI to make decisions about individuals. The Services are not an electronic health record, electronic medical record, system of record, or medical device. Customer's own record system is and remains the Designated Record Set, and Customer is solely responsible for maintaining it and for responding to individuals' requests regarding access, amendment, accounting, and restrictions concerning their PHI. PHI retained by the QA Suite is a documentation and supervision workflow record, not a Designated Record Set.
5.4 Prohibited Submissions
Customer will not include PHI in:
- Customer support tickets, email correspondence, or feedback submissions to ABAIQ, other than the in-app "Flag an AI error" control, which is designed to carry the note it refers to;
- The user profile fields, practice name, billing information, criteria text, agency rules, or any other registration or account-management field;
- Screenshots, videos, or other documentation submitted to ABAIQ for technical support or feedback purposes; or
- Any field, communication channel, or component of the Services not specifically designed to process PHI.
5.5 No Substitution for Clinical Judgment
Customer acknowledges that the Services use artificial intelligence to assist in generating and reviewing clinical documentation drafts. Customer represents that its qualified personnel will review, edit, and verify all output of the Services prior to incorporating such output into the Customer's clinical records, regulatory submissions, or billing. ABAIQ does not provide clinical advice, diagnoses, or treatment recommendations. The Services are not a medical device and are not intended to substitute for the professional judgment of duly licensed or certified clinical practitioners.
5.6 Transparency to Upstream Customers
To the extent Customer provides any output of the Services to an Upstream Customer or to a third party, Customer will not represent that such output was generated solely by a human or that no artificial intelligence was used in its preparation.
5.7 QA Suite and Batch Review Submissions
Where Customer uses the QA Suite, Customer represents and warrants that (i) the notes it sends or uploads are notes of clients for whom Customer is a covered entity or a business associate; (ii) Customer is authorized to disclose those notes to ABAIQ for documentation-quality review as a treatment or health care operations activity of Customer; (iii) Customer will enable the QA Suite only for its qualified personnel and will review the output through such personnel as provided in Section 5.5; and (iv) Customer will not send or upload notes for any purpose other than the review of its own clinical documentation. ABAIQ uses QA Suite submissions solely to deliver the review to Customer and never for the purposes prohibited in Section 3.2.
5.8 Client and Caregiver Consent
Consistent with the CASP Practice Parameters for Artificial Intelligence Use in Applied Behavior Analysis and the BACB Ethics Code, Customer is responsible for informing clients and caregivers of the use of AI-assisted documentation, of its risks and benefits, and of their right to decline, and for documenting that consent in the client's record. ABAIQ provides a template consent form for that purpose; ABAIQ does not obtain client consent on Customer's behalf.
5.9 State Law Compliance
Customer is responsible for ensuring its use of the Services complies with all applicable state laws, including without limitation the Florida Information Protection Act, Fla. Stat. § 501.171, and any state laws more restrictive than HIPAA regarding the use, disclosure, or breach notification of identifiable health information.
5.10 Permitted Requests Only
Customer will not request ABAIQ to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Customer, and will notify ABAIQ in writing of any restriction on the use or disclosure of PHI that Customer has agreed to under 45 C.F.R. § 164.522 to the extent it affects ABAIQ's performance of the Services.
6. Reporting
6.1 Breach Notification
ABAIQ will notify Customer of any Breach of Unsecured PHI without unreasonable delay following discovery by ABAIQ, and in no event later than thirty (30) calendar days after discovery by ABAIQ. Where the Breach is first reported to ABAIQ by a Subprocessor, ABAIQ will forward such notification to Customer within five (5) business days after ABAIQ's receipt of the Subprocessor's notification, recognizing that the originating Subprocessor's notification timeline (which may extend up to sixty (60) calendar days under the Subprocessor's own Business Associate Addendum with ABAIQ) may affect the total elapsed time between the underlying event and Customer's receipt of notice.
Each Breach notification will include, to the extent then known to ABAIQ: a description of what happened, including the date of the Breach and the date of discovery; a description of the types of Unsecured PHI involved; the identification of each affected individual, to the extent the information held by ABAIQ allows it; steps individuals should take to protect themselves; what ABAIQ is doing to investigate, mitigate and prevent a recurrence; and contact procedures for further inquiry. ABAIQ will cooperate with Customer in the investigation of the Breach and in the preparation of the notices HIPAA requires to affected individuals, the Secretary and, where applicable, the media, and will bear the reasonable costs of that investigation and notification where ABAIQ caused the Breach, subject to Section 11.1.
6.2 Reporting of Non-Breach Unauthorized Uses
ABAIQ will report to Customer any use or disclosure of PHI not permitted by this Agreement of which ABAIQ becomes aware, but which does not rise to the level of a Breach, within fifteen (15) business days after discovery by ABAIQ.
6.3 Reporting of Security Incidents
ABAIQ will report to Customer Security Incidents (other than Unsuccessful Security Incidents) of which ABAIQ becomes aware that involve PHI without unreasonable delay following discovery. Where the Security Incident is reported to ABAIQ by a Subprocessor, the reporting cadence will match the cadence ABAIQ receives from the Subprocessor, which may be on a quarterly basis. Notice of Unsuccessful Security Incidents is hereby given by this provision and ABAIQ has no further obligation to report them individually.
6.4 Mitigation
ABAIQ will take reasonable steps to mitigate, to the extent practicable, any harmful effect known to ABAIQ, or brought to ABAIQ's attention by Customer, of a use or disclosure of PHI in violation of this Agreement.
7. Subprocessors
ABAIQ engages Subprocessors only where ABAIQ has entered into a written agreement with the Subprocessor obligating the Subprocessor to restrictions and conditions at least as protective of PHI as those imposed on ABAIQ under this Agreement, including reasonable and appropriate safeguards for ePHI. As of the effective date of this version, ABAIQ maintains executed Business Associate Agreements with all Subprocessors that create, receive, maintain, or transmit PHI on its behalf, including its artificial intelligence and cloud infrastructure providers, and those Subprocessors process PHI in the United States. A current list of ABAIQ's Subprocessors, identifying each provider, the service it performs, and its BAA status, is available to Customers upon request by contacting support@abaiq.ai.
ABAIQ will provide Customer with notice of material changes to its Subprocessor list, including any Subprocessor that would process PHI outside the United States, at least thirty (30) days in advance of the change taking effect, except where shorter notice is necessary to address emergency circumstances, security concerns, or to comply with applicable law. If Customer objects to a new Subprocessor on reasonable data-protection grounds, Customer may terminate the Services Agreement without penalty before the change takes effect.
8. Individual Rights
Because ABAIQ does not maintain PHI as a Designated Record Set on Customer's behalf, ABAIQ has no independent obligation to provide access, amendment, or accounting to individuals. If ABAIQ receives such a request directly, ABAIQ will forward it to Customer within ten (10) business days. Where Customer needs a copy of a note retained by the QA Suite to answer an individual's request, ABAIQ will provide it to Customer within ten (10) business days of written request. ABAIQ will document any disclosures of PHI it makes for purposes other than treatment, payment, or healthcare operations that are reportable under 45 C.F.R. § 164.528, and make such records available to Customer within ten (10) business days of written request. To the extent ABAIQ carries out any of Customer's obligations under the Privacy Rule, ABAIQ will comply with the requirements of the Privacy Rule that apply to Customer in the performance of that obligation.
9. HHS Access
ABAIQ will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary, in the time and manner designated by the Secretary, for the purpose of determining Customer's or ABAIQ's compliance with HIPAA, and will make documentation of its safeguards and procedures available to Customer on written request for Customer's own compliance review. Nothing in this Section waives any privilege or protection available under applicable law, including with respect to trade secrets and confidential commercial information.
10. Term and Termination
10.1 Term
This Agreement is effective on the date Customer accepts it and continues in effect for as long as ABAIQ creates, receives, maintains or transmits PHI on Customer's behalf, until terminated as provided herein.
10.2 Termination for Material Breach
A Party may terminate this Agreement for the other Party's material breach, provided that the non-breaching Party first gives the breaching Party written notice and a period of thirty (30) days to cure. If the breach is not cured within the cure period, or if the breach is not capable of cure, the non-breaching Party may terminate this Agreement and the Services Agreement. If this Agreement is terminated and not replaced, ABAIQ will cease providing the Services to Customer to the extent they involve PHI.
10.3 Effect of Termination
Upon termination, Customer will cease transmitting PHI to the Services. ABAIQ will, within thirty (30) calendar days following termination, return to Customer or destroy all PHI maintained by ABAIQ on Customer's behalf, including PHI held by Subprocessors, and retain no copies, except where return or destruction is infeasible, including where a retention period required by law or by Customer's written instructions has not yet elapsed. Where infeasible, ABAIQ will give Customer written notice of the conditions that make return or destruction infeasible, extend the protections of this Agreement to such PHI, and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as ABAIQ retains the PHI. Upon Customer's written request, ABAIQ will provide a written certification that PHI has been returned, destroyed, or extended under continuing protection.
11. Liability and General Provisions
11.1 Limitation of Liability
Except for a Party's gross negligence or willful misconduct, neither Party will be liable to the other under this Agreement for indirect, incidental, special, consequential, exemplary, or punitive damages. ABAIQ's total aggregate liability arising under or in connection with this Agreement, including under Section 6.1 and Section 11.2, will not exceed the greater of (i) ten thousand United States dollars ($10,000), or (ii) the total fees paid by Customer to ABAIQ in the twelve (12) months immediately preceding the event giving rise to the liability. This cap does not apply to ABAIQ's willful misconduct.
11.2 Indemnification
Customer will indemnify, defend and hold harmless ABAIQ and its members, managers, officers, employees and agents from any third-party claim, demand, action, fine, or penalty, including reasonable attorneys' fees, arising out of Customer's submission of PHI in violation of Section 5.4, use of the Services by personnel who do not qualify under Section 5.2, failure to obtain the authorizations or consents required under Sections 5.1 and 5.8, lack of authority of a person who submitted PHI under Customer's account, or any other act or omission of Customer that violates this Agreement or HIPAA.
ABAIQ will indemnify, defend and hold harmless Customer and its members, managers, officers, employees and agents from any third-party claim, demand, action, fine, or penalty, including reasonable attorneys' fees, to the extent it results from an act or omission of ABAIQ that violates this Agreement or HIPAA, including a Breach of Unsecured PHI caused by ABAIQ, subject to the limitation stated in Section 11.1.
11.3 General Confidentiality
The terms of this Agreement are construed as a general confidentiality agreement that binds ABAIQ even if it is determined that ABAIQ is not a business associate as that term is used in HIPAA.
11.4 Amendment Upon Regulatory Change
If HIPAA or its implementing regulations are amended in a manner that requires modification of this Agreement, the Parties will cooperate in good faith to amend. If the Parties cannot agree on an amendment within sixty (60) days, either Party may terminate upon thirty (30) days' written notice. ABAIQ may also publish a revised version of this Agreement; a revision that materially changes the handling of PHI, the obligations of either Party or the limitation of liability requires Customer's acceptance in-app before continued use with PHI, and ABAIQ will give at least thirty (30) days' notice of such a revision.
11.5 Electronic Acceptance and Signatures
Customer's affirmative click of the acceptance checkbox during registration, Customer's acceptance and signature in the QA Suite e-sign flow, or other electronic manifestation of assent, constitutes Customer's electronic signature under the Electronic Signatures in Global and National Commerce Act, 15 U.S.C. § 7001 et seq., and the Florida Electronic Signature Act, Fla. Stat. § 668.50, and is enforceable to the same extent as a handwritten signature. ABAIQ retains records of Customer's electronic acceptance including timestamp, IP address, user agent, printed name, signature where captured, and the version of this Agreement accepted, and makes a signed certificate available to Customer in the QA Suite.
11.6 Notices
Notices to ABAIQ must be sent in writing to:
HYBREU DIGITAL LLC
Attn: Privacy Officer
9555 SW 175th Terrace #799
Palmetto Bay, Florida 33157
Email: admin@abaiq.ai
Notices to Customer will be sent to the email address and physical address provided by Customer during registration or as subsequently updated by Customer in account settings.
11.7 Governing Law
This Agreement is governed by the laws of the State of Florida, without regard to its conflict-of-laws principles, except to the extent preempted by federal law including HIPAA, and is interpreted so as to comply with HIPAA. Venue for any dispute lies in the state and federal courts located in Miami-Dade County, Florida.
11.8 No Third-Party Beneficiaries; No Agency
This Agreement is for the benefit of the Parties and does not create rights in any third party, including Customer's clients or their legal representatives. Nothing in this Agreement makes either Party the agent, partner, joint venturer or employee of the other; ABAIQ is an independent contractor of Customer.
11.9 Assignment
Neither Party may assign this Agreement without the other Party's written consent, except that ABAIQ may assign it to a successor to all or substantially all of its business or assets that assumes ABAIQ's obligations under this Agreement, with notice to Customer.
11.10 Severability
If any provision of this Agreement is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision will be reformed to the minimum extent necessary to render it valid and enforceable while satisfying the requirements of HIPAA for a business associate agreement.
11.11 Entire Agreement; Survival
This Agreement, together with the Services Agreement and, where one exists, the Agency Agreement, constitutes the entire agreement between the Parties regarding the subject matter of this Agreement and supersedes all prior or contemporaneous agreements regarding the same subject matter. The provisions of this Agreement dealing with breach notification, mitigation, indemnification, general confidentiality, and the return, destruction or continued protection of PHI survive termination.
11.12 Interpretation
Any ambiguity in this Agreement will be resolved in favor of an interpretation that allows the Parties to comply with HIPAA.
12. Related Policies
Please also review:
- Terms of Service
- QA Suite Terms of Use
- Privacy Policy
- Security & Development Practices
- Client and caregiver consent template: English · Spanish
13. Contact
For questions regarding this Agreement:
HYBREU DIGITAL LLC (dba ABAIQ)
Email: admin@abaiq.ai
Acceptance
| HYBREU DIGITAL LLC (ABAIQ)By its authorized representative The current version is published at the address above and issued on behalf of the Company by its authorized representative. | Customer / UserAccepted electronically. The Service records the acceptance: printed name, handwritten electronic signature where captured, date and time (UTC), IP address, user agent and the version accepted. A signed certificate is available in the QA Suite, under Legal. |