Business Associate Agreement
Last updated: 2026-09-17
Version: Draft - September 17, 2026
Status: Draft for Legal Review
This Business Associate Agreement (this “BAA”) is entered into by and between Topmuse Pte. Ltd., doing business as Denti Note (“Business Associate”), and the individual or entity accepting this BAA (“Covered Entity”). If this BAA is accepted on behalf of an entity, the individual accepting it represents and warrants that the individual is authorized to bind that entity. This BAA is effective on the date of electronic acceptance or, for a digitally signed copy of the same standard BAA, on the date specified in that copy (the “Effective Date”).
Business Associate and Covered Entity are each a “Party” and together the “Parties.”
Please contact us if you need a digitally signed copy of this BAA.
RECITALS
- The Parties have entered into, or Covered Entity has accepted, the Denti Note Terms of Use or another agreement governing Covered Entity’s access to and use of the Denti Note mobile application, web application, and related services (the “Services Agreement”).
- Under the Services Agreement, Business Associate provides Services that involve creating, receiving, maintaining, transmitting, storing, or securely disposing of Protected Health Information on behalf of Covered Entity.
- The Parties intend this BAA to satisfy the applicable requirements of the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations, in each case as amended from time to time.
The Parties therefore agree as follows.
1. DEFINITIONS
1.1 HIPAA Terms
The following terms have the meanings assigned to them under the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
1.2 Business Associate
“Business Associate” has the meaning assigned to “business associate” in 45 C.F.R. § 160.103 and, for purposes of this BAA, means Topmuse Pte. Ltd., doing business as Denti Note. “PHI Processing” means creating, receiving, maintaining, transmitting, storing, or securely disposing of PHI.
1.3 Covered Entity
“Covered Entity” has the meaning assigned to “covered entity” in 45 C.F.R. § 160.103 and, for purposes of this BAA, means the individual or entity identified as Covered Entity in the opening paragraph.
1.4 HIPAA Rules
“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164.
1.5 PHI
“PHI” means Protected Health Information received from Covered Entity, or created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity. PHI includes electronic Protected Health Information (“ePHI”) where applicable. PHI does not include information de-identified in accordance with 45 C.F.R. § 164.514(a)-(c).
1.6 APP and Services
“APP” means the Denti Note mobile application and web interface. “Services” means the functions provided through the APP and described in the Services Agreement, including the following:
- record audio during dental sessions or appointments through the mobile application;
- process audio to generate transcripts and speaker or timestamp metadata;
- process patient identifiers, session metadata, dental clinical information, and clinician input;
- generate draft clinical notes, draft odontograms or tooth charts, patient instructions, referral letters, medical leave letters, patient explanation letters, and other template-based draft documents;
- allow Covered Entity or its authorized users to review, edit, copy, download, and otherwise manage draft outputs through the APP; and
- process limited technical, security, support, and audit information necessary to operate, secure, troubleshoot, and document use of the Services.
The Services do not automatically read from or write to a practice-management system or electronic health record through an application programming interface. Covered Entity may manually transfer reviewed content to such a system. Any transcript, note, odontogram, letter, or other content generated by the APP is “AI-generated Draft Content” and requires independent professional review before use as clinical documentation or placement in an official patient record.
2. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
2.1 Provision of Services
Business Associate may Use and Disclose PHI only:
- as necessary to perform the Services and its obligations under the Services Agreement;
- as expressly permitted by this BAA; or
- as Required by Law.
Business Associate will not Use or Disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except for the specific Uses and Disclosures permitted by Sections 2.3 and 2.4.
2.2 Service-Specific Restrictions
Business Associate will not:
- sell PHI or receive remuneration in exchange for PHI except as expressly permitted by the HIPAA Rules;
- Use or Disclose PHI for advertising, unrelated marketing, fundraising, or another independent commercial purpose;
- Use PHI to train a general-purpose or cross-customer artificial-intelligence or machine-learning model unless Covered Entity has separately authorized that Use in writing and the Use is permitted by the HIPAA Rules;
- use PHI to make autonomous diagnosis, treatment, medication, coding, billing, or other clinical decisions;
- represent AI-generated draft content as independently verified clinical fact; or
- automatically transmit draft clinical content to a practice-management system, electronic health record, or official patient record without a separate authorized integration and appropriate clinician review and confirmation.
2.3 Proper Management and Administration
Business Associate may Use PHI for its proper management and administration or to carry out its legal responsibilities. Business Associate may Disclose PHI for those purposes only if the Disclosure is Required by Law or Business Associate obtains reasonable written assurances from the recipient that the information will remain confidential, will be Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed, and the recipient will notify Business Associate of any Breach of confidentiality of which it becomes aware.
2.4 Data Aggregation
Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity only to the extent such services are included in the Services Agreement and permitted by the HIPAA Rules.
2.5 De-identification
Business Associate may de-identify PHI only in accordance with 45 C.F.R. § 164.514(a)-(c). Business Associate may Use or Disclose properly de-identified information to operate, secure, maintain, support, and improve the Services, conduct lawful analytics, and fulfill other lawful business purposes, provided that Business Associate will not attempt to re-identify the information and will not permit a recipient to re-identify it. De-identification does not authorize Business Associate to use PHI for a purpose prohibited by Section 2.2 before de-identification.
2.6 Minimum Necessary
Business Associate will limit its Uses, Disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose, to the extent the Minimum Necessary standard applies.
3. OBLIGATIONS OF BUSINESS ASSOCIATE
3.1 Privacy and Security Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards to prevent Use or Disclosure of PHI other than as provided by this BAA. With respect to ePHI, Business Associate will comply with the applicable requirements of Subpart C of 45 C.F.R. Part 164. Business Associate will maintain a written privacy and security program appropriate to the size and complexity of its operations, the nature and scope of its activities, and the sensitivity of the PHI it processes.
3.2 Mitigation
Business Associate will mitigate, to the extent practicable, any harmful effect known to Business Associate resulting from a Use or Disclosure of PHI by Business Associate in violation of this BAA.
3.3 Reporting Impermissible Uses, Disclosures, and Security Incidents
Business Associate will report to Covered Entity any Use or Disclosure of PHI not permitted by this BAA and any Security Incident of which Business Associate becomes aware. The report will be made without unreasonable delay and will include the information then available to Business Associate that is reasonably necessary for Covered Entity to evaluate and respond to the event.
The Parties acknowledge that unsuccessful attempts to access, use, disclose, modify, or destroy ePHI, including routine port scans, pings, unsuccessful log-in attempts, denial-of-service attempts, and similar events that do not result in unauthorized access, Use, Disclosure, modification, or destruction of ePHI or material interference with system operations, occur frequently. This Section constitutes notice of such unsuccessful events, and no additional report is required unless Covered Entity reasonably requests it or the event becomes a reportable Security Incident or Breach.
3.4 Breach Notification
Following Discovery of a Breach of Unsecured PHI, Business Associate will notify Covered Entity without unreasonable delay and in no event later than ten (10) calendar days after Discovery, except to the extent a law-enforcement delay permitted by 45 C.F.R. § 164.412 applies.
To the extent possible, the notice will include:
- the identification of each Individual whose Unsecured PHI was, or is reasonably believed to have been, accessed, acquired, Used, or Disclosed;
- a brief description of what happened, including the date of the Breach and the date of Discovery, if known;
- a description of the types of Unsecured PHI involved;
- the identity or category of any unauthorized recipient, if known;
- the corrective and mitigation actions taken or planned by Business Associate; and
- any other information then available that Covered Entity is required to include in a notification under the HIPAA Rules.
Business Associate will supplement the notice promptly as additional material information becomes available and will reasonably cooperate with Covered Entity’s investigation, risk assessment, and legally required notifications. Unless the Parties agree otherwise in writing, Covered Entity will control notifications to Individuals, the Secretary, and the media.
3.5 Business Associate Subcontractors
In accordance with 45 C.F.R. §§ 164.308(b)(2) and 164.502(e)(1)(ii), Business Associate will ensure that each Business Associate Subcontractor performing PHI Processing on its behalf agrees in writing to the same applicable restrictions, conditions, and requirements that apply to Business Associate under this BAA. Business Associate will conduct appropriate due diligence and ongoing oversight for each such Business Associate Subcontractor.
3.6 Access to PHI
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make that PHI available to Covered Entity, or as directed by Covered Entity to an Individual or the Individual’s designee, as necessary for Covered Entity to satisfy 45 C.F.R. § 164.524. Unless the Parties agree otherwise, Business Associate will provide the requested information within fifteen (15) calendar days after receiving Covered Entity’s written request. If Business Associate receives an access request directly from an Individual, Business Associate will promptly forward it to Covered Entity and will not deny the request on Covered Entity’s behalf.
3.7 Amendment of PHI
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make amendments to that PHI as directed or agreed to by Covered Entity and will incorporate the amendments as necessary for Covered Entity to satisfy 45 C.F.R. § 164.526. Unless the Parties agree otherwise, Business Associate will act within fifteen (15) calendar days after receiving Covered Entity’s written direction.
3.8 Accounting of Disclosures
Business Associate will document Disclosures of PHI and information relating to such Disclosures as necessary for Covered Entity to respond to a request for an accounting under 45 C.F.R. § 164.528. Business Associate will make that information available to Covered Entity within fifteen (15) calendar days after receiving Covered Entity’s written request, unless the Parties agree otherwise.
3.9 Covered Entity Privacy Rule Functions
To the extent Business Associate carries out one or more obligations of Covered Entity under Subpart E of 45 C.F.R. Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.
3.10 Government Access
Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, available to the Secretary for purposes of determining compliance with the HIPAA Rules. To the extent legally permitted, Business Associate will notify Covered Entity of such a request.
3.11 Data Retention and Deletion
The following service-specific rules apply, subject to the HIPAA Rules, the Services Agreement, Covered Entity’s instructions, legal holds, and Business Associate’s documented retention and deletion policies:
- Original audio. Business Associate will retain each original audio segment for thirty (30) calendar days after that segment ends and will then delete it. A supplemental recording does not restart the retention period for an earlier segment. Encrypted local or temporary upload copies will be removed after Business Associate confirms successful upload, except where temporary retention is reasonably necessary to complete or retry the upload. Deletion of original audio does not by itself delete an existing transcript or generated output.
- Other PHI during the subscription. Business Associate may retain non-audio PHI while Covered Entity’s subscription remains active as necessary to provide the Services.
- After termination. Business Associate will return or destroy PHI in accordance with Section 6.4. If retention is Required by Law or return or destruction is infeasible, Business Associate may retain only the PHI necessary for its proper management and administration or legal responsibilities, for no longer than the applicable retention period, and subject to the protections and use restrictions in Section 6.4.
- Agreement records. Business Associate will maintain the electronic acceptance record, the applicable agreement snapshot, and any digitally signed copy of the same standard BAA as a single retrievable agreement record associated with Covered Entity’s account. These records are compliance records rather than clinical PHI records and will be retained for seven (7) years after expiration or termination of the applicable Services relationship, or longer if Required by Law or subject to a litigation hold. Upon expiration of the applicable retention period, Business Associate will securely destroy the records in accordance with its documented disposal procedures.
4. OBLIGATIONS OF COVERED ENTITY
4.1 Lawful Instructions and Minimum Necessary Information
Covered Entity will not request Business Associate to Use or Disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except for Uses or Disclosures permitted for Business Associate’s proper management and administration, legal responsibilities, or Data Aggregation under this BAA. Covered Entity will provide only the PHI reasonably necessary for the Services.
4.2 Notice of Privacy Practices
Covered Entity will notify Business Associate of any limitation in Covered Entity’s notice of privacy practices under 45 C.F.R. § 164.520 to the extent the limitation may affect Business Associate’s Use or Disclosure of PHI.
4.3 Changes in Permission
Covered Entity will notify Business Associate of any change in, or revocation of, an Individual’s permission to Use or Disclose PHI to the extent the change may affect Business Associate’s permitted or required Uses or Disclosures.
4.4 Restrictions
Covered Entity will notify Business Associate of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522 to the extent the restriction may affect Business Associate’s permitted or required Uses or Disclosures.
4.5 Authority, Patient Notice, and Consent
Covered Entity represents and warrants that:
- the person accepting this BAA on behalf of Covered Entity is authorized to bind Covered Entity;
- Covered Entity has the right and authority to provide PHI to Business Associate for processing under this BAA;
- Covered Entity has provided all notices and obtained all permissions, authorizations, and consents required by applicable law and professional obligations, including any consent required to record a patient-clinician conversation; and
- Covered Entity is responsible for maintaining evidence of patient-specific consent where required. A general in-product acknowledgement is not evidence that consent was obtained from each patient.
4.6 Clinical Responsibility
Covered Entity and its authorized users remain solely responsible for professional judgment, patient assessment, and review of all AI-generated Draft Content for accuracy, completeness, and appropriateness before use. Covered Entity is responsible for the final signing, submission, and placement of clinical documentation in its official patient record or PMS/EHR.
5. INDIVIDUAL REQUESTS AND COOPERATION
5.1 Requests Received by Business Associate
Business Associate will handle requests for access, amendment, and an accounting of disclosures in accordance with Sections 3.6 through 3.8. If Business Associate receives directly from an Individual any other request concerning PHI processed on behalf of Covered Entity, it will promptly forward the request to Covered Entity unless Required by Law to respond directly.
5.2 Cooperation
The Parties will reasonably cooperate in responding to regulatory inquiries, Individual requests, investigations, and compliance obligations relating to PHI processed under this BAA. Cooperation under this Section does not alter the allocation of responsibilities established by the HIPAA Rules or the Services Agreement.
6. TERM AND TERMINATION
6.1 Term
This BAA begins on the Effective Date and remains in effect while Business Associate creates, receives, maintains, transmits, or retains PHI on behalf of Covered Entity, unless terminated earlier in accordance with this BAA.
6.2 Termination for Cause
Covered Entity may terminate this BAA and the affected Services if Covered Entity determines that Business Associate has violated a material term of this BAA and Business Associate does not cure the violation or end the offending practice within thirty (30) days after receiving written notice, provided that Covered Entity may terminate immediately if cure is not feasible. If termination is not feasible, Covered Entity may report the violation to the Secretary.
Business Associate may terminate this BAA and the affected Services if it determines that Covered Entity has materially violated this BAA and does not cure the violation within thirty (30) days after receiving written notice, or immediately if cure is not feasible.
6.3 Withdrawal Request
A request to withdraw electronic acceptance does not, by itself, terminate this BAA or require immediate deletion of PHI. Any resulting termination of the Services and disposition of PHI will be governed by the Services Agreement and this Section 6.
6.4 Obligations Upon Termination
Upon termination of this BAA for any reason, Business Associate will, if feasible and as directed by Covered Entity, return to Covered Entity or destroy all PHI received from Covered Entity or created, maintained, or received by Business Associate on behalf of Covered Entity that Business Associate still maintains in any form, and Business Associate will retain no copies.
If return or destruction is infeasible, or if Business Associate is Required by Law to retain specified PHI, Business Associate will:
- notify Covered Entity of the conditions that make return or destruction infeasible, unless prohibited by law;
- retain only the PHI necessary for the applicable legal, management, or administrative purpose;
- continue to apply the safeguards and restrictions of this BAA for as long as it retains the PHI;
- not Use or Disclose retained PHI except for the purpose that makes return or destruction infeasible or as Required by Law; and
- return or destroy the retained PHI when the reason for retention no longer applies.
This Section also applies to PHI held by Business Associate’s Subcontractors.
6.5 Survival
Business Associate’s obligations under Sections 3.10, 3.11, 5, 6.4, and 6.5 survive termination of this BAA for so long as Business Associate retains PHI.
7. GENERAL TERMS
7.1 Relationship to the Services Agreement
This BAA is incorporated into and forms part of the Services Agreement. If this BAA conflicts with the Services Agreement, this BAA controls solely with respect to the Use, Disclosure, safeguarding, return, or destruction of PHI. Except as stated in this BAA, the Services Agreement remains in effect, including its provisions concerning fees, disclaimers, limitations of liability, indemnification, dispute resolution, governing law, and notices.
7.2 Regulatory References
A reference in this BAA to a provision of the HIPAA Rules means that provision as in effect or as amended, and for which compliance is required.
7.3 Amendment to Comply with Law
The Parties will take such action as is reasonably necessary to amend this BAA to comply with the HIPAA Rules and other applicable laws governing the privacy or security of PHI. Business Associate may update the standard BAA prospectively through the process permitted by the Services Agreement, but an update will not retroactively alter the terms applicable to an event that occurred before the update’s effective date unless Required by Law.
7.4 Interpretation
Any ambiguity in this BAA will be interpreted to permit compliance with the HIPAA Rules. Headings are for convenience only and do not affect interpretation.
7.5 No Third-Party Beneficiaries
Nothing in this BAA confers any right, remedy, obligation, or liability on any person other than the Parties and their permitted successors and assigns.
7.6 Assignment
Neither Party may assign this BAA except as permitted under the Services Agreement. Any permitted successor or assign remains bound by this BAA.
7.7 Electronic Acceptance; Counterparts
This BAA may be accepted electronically through a clickwrap process that provides access to the then-current Privacy Policy, Terms of Use, and BAA and requires affirmative acceptance. Business Associate may retain the applicable agreement version or snapshot, account identifier, accepting account email, acceptance date and time, and acceptance status as evidence of acceptance. The version of this BAA made available for electronic acceptance is Business Associate’s standard form. At Covered Entity’s request, the Parties may execute a digitally signed copy of the same standard BAA. Any such copy will include the optional signature block in Section 8, must be identical in substance to the standard BAA then in effect, supplements and does not replace the original electronic acceptance record, and will be associated with the same account and maintained in accordance with Section 3.11. Counterparts and electronic signatures have the same effect as an original.
7.8 Entire Agreement as to PHI
This BAA and the applicable provisions of the Services Agreement constitute the entire agreement between the Parties concerning Business Associate’s processing of PHI on behalf of Covered Entity and supersede prior or contemporaneous understandings on that subject.
8. OPTIONAL SIGNATURE COPY
The following signature block is used only when Covered Entity requests a digitally signed copy of the same standard BAA. The Effective Date for that digitally signed copy is the date inserted below. If no date is inserted, it is the date of the last signature.
Effective Date: ______________________________
8.1 COVERED ENTITY
Legal name: ________________________________
By: _______________________________________
Name: ____________________________________
Title: _____________________________________
Date: _____________________________________
Notice address/email: ________________________
8.2 BUSINESS ASSOCIATE
Topmuse Pte. Ltd., doing business as Denti Note
By: _________________________________________
Name: ______________________________________
Title: _______________________________________
Date: _______________________________________
Notice address/email: __________________________