← Home

Data Processing Agreement

1. Roles

You (the practitioner) are the Covered Entity. RafaNest acts as your Business Associate and creates, receives, maintains, or transmits Protected Health Information (PHI) on your behalf only to provide the service and on your documented instructions. Capitalized terms not defined here have the meaning given in 45 CFR Parts 160 and 164 (HIPAA).

2. Permitted uses and disclosures

We will not use or disclose PHI other than as permitted by this agreement or as required by law, and never in a way that would violate HIPAA if done by you. We may use PHI as necessary for our own proper management and administration and to carry out our legal responsibilities, and we may provide data-aggregation services relating to your health care operations. Any use or disclosure not described here will be made only with your prior authorization.

3. Safeguards & Security Rule

We will use appropriate administrative, physical, and technical safeguards and will comply with the applicable requirements of Subpart C of the Security Rule (45 CFR §§164.302–318) with respect to electronic PHI. These include AES-256 encryption at rest, TLS in transit, append-only audit logging of PHI access, and least-privilege access controls. Infrastructure runs on AWS under a signed Business Associate Agreement.

4. Subprocessors

We use AWS (Amplify, Aurora, Cognito, S3) as our infrastructure subprocessor, and may engage additional subprocessors (for example, email and SMS providers). Any subcontractor that creates, receives, maintains, or transmits PHI on our behalf will first be bound by a written agreement imposing restrictions and conditions at least as protective as, and no less stringent than, those in this agreement — including Security Rule compliance and the obligation to report breaches and security incidents.

5. Breach notification

We will report to you any use or disclosure of PHI not permitted by this agreement of which we become aware. Following discovery of a breach of unsecured PHI, we will notify you without unreasonable delay and in no event later than 60 calendar days after discovery, with the information you need to meet your obligations to notify affected individuals under 45 CFR §164.404.

6. Security incidents

We will report to you any security incident affecting electronic PHI of which we become aware, consistent with 45 CFR §164.314(a). Routine unsuccessful attempts that do not result in unauthorized access (such as ordinary firewall or scan activity) are reported in the aggregate on request.

7. Patient rights

We will make PHI available so you can meet your obligations to provide individuals with access (§164.524), to amend records (§164.526), and to provide an accounting of disclosures (§164.528). Patients can see that accounting in their portal, and can additionally request a report of who within your clinic viewed their records.

8. Access for compliance review

We will make our internal practices, books, and records relating to the use and disclosure of PHI available to the U.S. Department of Health and Human Services (the Secretary) for purposes of determining your compliance with HIPAA.

9. Return or destruction on termination

On termination of this agreement, we will return or destroy all PHI we hold on your behalf and retain no copies. Where return or destruction is not feasible (for example, where law requires continued retention), we will extend the protections of this agreement to that PHI and limit further use or disclosure to the purposes that make return or destruction infeasible, for as long as we retain it.

10. Termination for breach

If we breach a material term of this agreement, you may terminate the underlying service. This agreement remains in effect until all PHI is returned, destroyed, or protected as described above.

11. Changes in law

The parties agree to take such action as is necessary to amend this agreement from time to time as needed for you to comply with HIPAA, the Security Rule, and the HITECH Act as they may be amended.

12. Governing law

This agreement is governed by the laws of the State of Colorado and applicable U.S. federal law, without regard to conflict-of-laws principles.

Effective August 24, 2026. By creating a practitioner account and using RafaNest to process PHI, you agree to this Business Associate Agreement. A countersigned copy is available on request.