Business Associate Agreement
HIPAA Business Associate Agreement for Data Shepherd healthcare customers.
Version 2.0 · Effective June 17, 2026
Business Associate Agreement
This Data Shepherd Business Associate Addendum ("BAA") is entered into by Data Shepherd, LLC ("Business Associate" or "Data Shepherd") and the customer identified in the signature block below ("Customer") and is hereby incorporated into and forms a part of the Data Shepherd Terms of Service (the "Terms"). Each of Customer and Data Shepherd may be referred to herein as a "Party" and together as the "Parties." Any capitalized terms used in this BAA that are not defined in this BAA have the meaning provided in the Terms or HIPAA (defined below).
The terms of this BAA will control over any conflicting terms in the Terms. All other non-conflicting terms of the Terms remain valid and enforceable.
A. Recitals
Customer is a Covered Entity or a business associate under HIPAA and is required to comply with HIPAA regarding the confidentiality and privacy of Protected Health Information.
Business Associate provides to Customer certain services ("Eligible Services") pursuant to the Terms between the Parties. In connection with the Eligible Services, the Parties anticipate that Business Associate may from time to time create, receive, maintain, or transmit Protected Health Information for or on behalf of Customer. To the extent required by HIPAA, by creating, receiving, maintaining, or transmitting Protected Health Information in its provision of Eligible Services to Customer, Business Associate is a business associate as defined under HIPAA and will therefore have obligations regarding the confidentiality and privacy of Protected Health Information that Business Associate creates for, or receives from or on behalf of, Customer. This BAA applies solely to the extent that Business Associate processes Protected Health Information for or on behalf of Customer in a manner that results in Data Shepherd operating as a Business Associate to Customer under HIPAA. For the avoidance of doubt, Business Associate may provide additional services to Customer that do not involve Protected Health Information or are not Eligible Services subject to the requirements of this Addendum or HIPAA.
B. Definitions
For purposes of this BAA, capitalized terms will have the meanings ascribed to them below. All capitalized terms used but not otherwise defined herein or in the Terms will have the meaning ascribed to them by HIPAA.
"Eligible Services" means the Data Shepherd data-transformation platform and any associated customer support and features, as provided pursuant to the Terms.
"HIPAA" means the Health Insurance Portability and Accountability Act of 1996 as amended and supplemented by the Health Information Technology for Economic and Clinical Health Act (HITECH) and their implementing regulations.
"Protected Health Information" or "PHI" is any information, to the extent received, maintained, or transmitted by Business Associate for or on behalf of Customer in connection with the provision of Eligible Services, that identifies an individual and relates to (i) the past, present, or future physical or mental health or condition of the individual; (ii) the provision of health care to the individual; or (iii) the past, present, or future payment for health care.
"Secretary" refers to the Secretary of the U.S. Department of Health and Human Services.
C. Business Associate Obligations
1. Use and Disclosure of PHI
(a) Business Associate (i) will use or disclose PHI only in connection with fulfilling its duties and obligations under this BAA and the Terms and to perform the Eligible Services; (ii) will not use or disclose PHI other than as permitted or required by the Terms or required by law; (iii) will not use or disclose PHI in any manner that violates applicable federal and state laws or would violate such laws if used or disclosed in such manner by Customer; and (iv) will only use and disclose the minimum necessary PHI to perform the permitted purposes.
(b) Subject to the restrictions set forth throughout this BAA, Business Associate may use the information received from Customer if necessary for (i) the proper management and administration of Business Associate, or (ii) to carry out the legal responsibilities of Business Associate.
(c) Subject to the restrictions set forth in this BAA, Business Associate may disclose PHI for the proper management and administration of Business Associate, provided that (i) disclosures are required by law, or (ii) Business Associate obtains reasonable assurances from the person or entity to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person or entity, and the person or entity notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
2. Safeguards
Business Associate will employ appropriate and reasonable administrative, technical, and physical safeguards to protect the confidentiality of PHI and to protect against the use or disclosure of PHI in any manner inconsistent with the terms of this BAA or the Terms, in each case as required by HIPAA. Business Associate will comply, where applicable, with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI to protect against use or disclosure of such electronic PHI other than as provided for by this BAA or the Terms as required by HIPAA.
3. Audits and Records
To the extent required by HIPAA, Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA.
4. Individual Rights
(a) Access Requests. To the extent Business Associate maintains PHI in a Designated Record Set pursuant to 45 CFR Section 164.524, Business Associate, within thirty (30) calendar days upon receipt of written request by Customer, will make available to Customer such PHI. If any Individual requests access to PHI directly from Business Associate, Business Associate will direct the Individual to make the request directly to Customer or, to the extent Business Associate knows the identity of the Customer, forward such request to Customer. As between the Parties, Customer will be responsible for determining whether to grant access and for any denial of access pursuant to 45 CFR Section 164.524, including resolution or reporting of all appeals or complaints arising from denials.
(b) Amendment Requests. To the extent Business Associate maintains PHI in a Designated Record Set and receives a request for an amendment to PHI, Business Associate will make available to Customer such PHI. If any Individual requests amendment of PHI directly from Business Associate, Business Associate will direct the Individual to make the request directly to Customer or, to the extent Business Associate knows the identity of the Customer, forward such request to Customer. As between the Parties, Customer will be solely responsible for determining whether to amend PHI pursuant to 45 CFR Section 164.526, and Business Associate will make no such determinations.
(c) Designated Record Sets. The Parties acknowledge and agree that Business Associate shall not maintain PHI in a Designated Record Set for or on behalf of Customer. Customer shall maintain a separate copy of all PHI provided to Business Associate, including all information needed to respond to Individuals as described in this Section 4.
(d) Accounting Requests. To the extent Business Associate is required to provide information for an accounting pursuant to 45 CFR Section 164.528, Business Associate will make available to Customer such PHI as required by HIPAA. If any Individual requests an accounting of disclosures of PHI directly from Business Associate, Business Associate will direct the Individual to make the request directly to Customer or, to the extent Business Associate knows the identity of the Customer, forward such request to Customer. As between the Parties, Customer will be solely responsible for preparing and delivering an accounting to an Individual.
5. Subcontractors
Business Associate will obtain and maintain a written agreement with each subcontractor that receives, creates, maintains, or transmits PHI for or on behalf of Business Associate, whereby each subcontractor agrees to be bound by the same types of restrictions, terms, and conditions that apply to Business Associate pursuant to this BAA with respect to such PHI as required by HIPAA. The subcontractors and subprocessors Business Associate uses, and the manner in which each is bound, are identified in Schedule A.
6. Security Incidents or Breaches
Business Associate will report any Security Incident or Breach to Customer promptly, and in any event within thirty (30) calendar days after the date the Breach is discovered. The notice of a Breach will include, to the extent such information is known to Business Associate: (1) the identification of each individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, or disclosed during the Breach; (2) the date of the Breach, if known, and the date of discovery of the Breach; and (3) a description of Business Associate's response to the Breach.
If Business Associate becomes aware of a use or disclosure of PHI that is not permitted under this BAA but does not constitute a Breach, Business Associate will report such use or disclosure to Customer within thirty (30) calendar days after the date on which Business Associate becomes aware of such use or disclosure.
The Parties acknowledge that unsuccessful Security Incidents (e.g., pings and other broadcast attacks on a firewall, denial-of-service attacks, port scans, unsuccessful login attempts) occur within the normal course of business, and the Parties stipulate and agree that this paragraph constitutes notice by Business Associate to Customer of such unsuccessful Security Incidents.
D. Customer Obligations
-
Customer will not request Business Associate to use or disclose PHI in any manner that would violate HIPAA or any other applicable federal and state laws. Customer will only use or disclose the minimum amount of PHI necessary when using the Eligible Services.
-
Customer will use or disclose PHI through the Eligible Services only as permitted by and in accordance with HIPAA or any other applicable federal and state law. Customer will be compliant with all applicable laws and regulations pertaining to PHI that Customer shares with, sends, or directs to be sent to Business Associate.
-
Customer will notify Business Associate of any limitation in any applicable notice of privacy practices in accordance with 45 CFR Section 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.
-
Customer will notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.
-
Customer will notify Business Associate of any restriction to the use or disclosure of PHI that Customer has agreed to in accordance with 45 CFR Section 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.
-
Customer will be solely responsible for its obligations to retain PHI under HIPAA, and Customer acknowledges and agrees that any Customer data and outputs will be retained by Business Associate pursuant to the Terms.
-
Customer acknowledges and agrees that Customer controls how the Eligible Services are used and configured and that some uses and configuration options available in the Eligible Services could be inconsistent with the requirements of HIPAA. Business Associate is not responsible for any configuration choices or usage decisions made by Customer. Customer further acknowledges and agrees that using the Eligible Services in a manner that complies with HIPAA requires that Customer comply with Business Associate's published documentation and usage guidance for the Eligible Services. Customer represents, warrants, and covenants that it has received, reviewed, and will at all times comply with, and appropriately inform its authorized users regarding, the appropriate use of the Eligible Services, including that documentation and usage guidance, as it may be updated and made available to Customer from time to time by Business Associate. Without limitation to the foregoing, Customer represents, warrants, and covenants that any data it submits to, collects with, or uses through the Eligible Services in a manner that does not comply with that documentation and usage guidance is not PHI.
E. Term and Termination
-
Term. This BAA is effective as of the date Customer accepts it (the "Effective Date") and will terminate upon (a) termination of the Terms, (b) as expressly authorized by Section E.2, or (c) when all PHI has been disposed of in strict compliance with the terms of this BAA, whichever occurs later.
-
Termination for Material Breach. Where either Party has knowledge of a material breach by the other Party, the non-breaching Party will provide the breaching Party with an opportunity to cure. Where said breach is not cured to the reasonable satisfaction of the non-breaching Party within thirty (30) days of notice from the non-breaching Party of said breach, the non-breaching Party will terminate this BAA and the portion(s) of the Terms affected by the material breach. Where either Party has knowledge of a material breach by the other Party and cure is not possible, the non-breaching Party will terminate this BAA and the portion(s) of the Terms affected by the material breach.
-
Return or Destruction of PHI. While Customer continues to have access to the Eligible Services under this BAA, depending on the type of Eligible Services, Customer may have the ability to use the export functionality to export Customer data from the Eligible Services. Business Associate will maintain and permit access to Customer data (including any PHI) in its possession for thirty (30) days following the termination or expiration of this BAA. Thereafter, or upon termination of this BAA for any reason, Business Associate will:
(a) If feasible as determined by Business Associate, return or destroy all PHI created, received, maintained, or transmitted by Business Associate for or on behalf of Customer that Business Associate or any of its subcontractors and agents still maintain in any form, and, in those cases, Business Associate will retain no copies of such information; or
(b) If Business Associate determines that such return or destruction is not feasible, extend the protections of this BAA to such information and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI. The obligations of this Section 3 will survive the termination of this BAA.
F. General
-
Amendment. If any of the regulations promulgated under HIPAA or interpretive guidance issued by the U.S. Department of Health and Human Services are amended or interpreted by the Secretary in a manner that requires amendment of this BAA to comply with HIPAA, the Parties will cooperate in good faith to amend this BAA to the extent necessary to comply with such amendments or interpretations. If Business Associate and Customer are not able to reach agreement on amendments to this BAA, or a Party believes in good faith that the change makes it commercially impracticable to provide and/or use the Eligible Services in compliance with applicable law, either Party may terminate this BAA by giving written notice at least thirty (30) days prior to the termination date specified in such notice.
-
Interpretation. Any ambiguity in this BAA will be resolved to permit the Parties to comply with HIPAA.
-
Integration. This BAA supersedes all other understandings or agreements between the Parties regarding the subject matter of, and Eligible Services covered by, this BAA, including any prior BAAs entered between the Parties.
-
Governing Law. This BAA is governed by and construed in accordance with the laws of the State of Missouri, without regard to its conflict-of-laws principles, except to the extent preempted by federal law (including the HIPAA Rules).
Schedule A — Subcontractors and Subprocessors
This Schedule identifies the third parties Business Associate uses, distinguishing those that may handle PHI (and are bound by flow-down obligations under Section C.5) from those that must not receive PHI. Business Associate maintains this Schedule and will update it to reflect material changes.
Data residency / no offshore processing. Business Associate will configure the subcontractors in Part 1 so that PHI is stored and processed in the United States, and will not route PHI to processing locations outside the United States, except as Customer expressly authorizes in writing or as required by law. Specifically: (a) the Azure resources used to store and process PHI are provisioned in the Central US Azure region; and (b) PHI transmitted to Anthropic for build-phase (and, if enabled, Auto-heal) processing is processed under Anthropic's U.S.-based service terms and Business Associate's executed Anthropic BAA.
Part 1 — Subcontractors That May Handle PHI (flow-down required)
| Subcontractor | Role / Services | PHI Handling | How Bound (Flow-Down) |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Cloud infrastructure: Azure SQL, Azure Functions, Storage, Key Vault, App Service | May store/process PHI in U.S. Azure region(s) (data at rest and in transit; deterministic execution; logically isolated per-org / multi-tenant with org-scoped separation) | Microsoft Business Associate Agreement is in place automatically via the Microsoft Product Terms / Data Protection Addendum (no separate signature). The listed services are HIPAA in-scope under Microsoft's terms. |
| Anthropic (Anthropic PBC) — Claude / Messages API | AI model used during the build phase to author transformation scripts, and — only if Customer enables the off-by-default Auto-heal feature — at run time to assist with error correction | May process build-phase sample data (and, if Auto-heal is enabled, run-time inputs) that could contain PHI | Business Associate has executed Anthropic's commercial 1P API Business Associate Agreement, effective April 8, 2026, on the Anthropic organization that owns Data Shepherd's production API key, and operates in Anthropic's HIPAA mode. The Anthropic Messages API is a HIPAA-Eligible Service covered by that BAA. Covered models use Anthropic's standard data-retention terms applicable to HIPAA-covered API use (Zero Data Retention is not available in HIPAA mode). The BAA covers programmatic API use only; consumer plans (Claude Free/Pro/Max) and the web Console/Workbench are out of scope and are not used by Data Shepherd. |
Part 2 — Subprocessors That Will NOT Receive PHI (PHI contractually and technically excluded)
| Subprocessor | Role / Services | PHI Status |
|---|---|---|
| Stripe | Payment processing / billing | No PHI. Only billing and account-administration data is sent to Stripe. Stripe does not sign BAAs and instructs customers not to send PHI through its services; PHI is excluded accordingly. |
| Resend | Transactional / notification email delivery | No PHI. Notification emails are "lean" — they contain only the customer-defined transformation/schedule name, the status, and a dashboard link — never the uploaded file name, data values, or error text. Customer is responsible for not placing PHI in those names (see Section D, paragraph 7). Resend therefore does not receive PHI. |
Business Associate will not route PHI to any subprocessor listed in Part 2. Customer agrees not to place PHI into fields or content delivered to these subprocessors (e.g., billing identifiers or email subject/body content).
Signature / Acceptance
This BAA is accepted by Customer electronically through the Data Shepherd application. By accepting, the accepting individual represents that they are authorized to bind Customer to this BAA, and the Parties agree that such electronic acceptance has the same legal effect as a handwritten signature.
Business Associate — Data Shepherd, LLC
- By: Scott Delia
- Title: Owner
- Date: June 17, 2026
Customer — accepted electronically
- Organization: (captured from account record)
- Accepting Representative (Name): (captured at acceptance)
- Title: (captured at acceptance)
- Date of Acceptance: (captured at acceptance)
Addresses for Notices
- To Business Associate: Email support@datashepherd.ai; Address 117 South Lexington Street, Ste 100, Harrisonville, MO 64701 (c/o registered agent).
- To Customer: the administrative contact and email on file for Customer's account/organization, and any notice address Customer designates in the application or in writing.