This Business Associate Agreement (this “BAA”) is between you, the FrontDesk Talk customer (“Covered Entity”), and FrontDesk Talk, LLC (“Business Associate”). It is part of, and amends, the Terms of Service between Covered Entity and Business Associate (the “Agreement”).
This BAA applies when Covered Entity is a “covered entity,” or a “business associate” of a covered entity, under HIPAA, and Business Associate creates, receives, maintains, or transmits protected health information on Covered Entity’s behalf through the FrontDesk Talk service (the “Services”). If Covered Entity is itself a business associate, “Covered Entity” in this BAA means Covered Entity in that role, and this BAA is a subcontractor business associate agreement.
How this BAA is accepted. Covered Entity accepts this BAA when its FrontDesk Talk account is created, by checking the box agreeing to this BAA, the Terms of Service, and the Privacy Policy. By doing so, the person creating the account confirms they are authorized to accept this BAA for Covered Entity, and this BAA is formed between Covered Entity and Business Associate, effective at that moment (the “Effective Date”). That acceptance is Covered Entity’s electronic signature, and Business Associate’s posting of this BAA and recording of the acceptance is Business Associate’s. Business Associate records the version accepted (this is version 2026-10-03), the time, the person who accepted it, Covered Entity’s business name, and the IP address and device used. If this BAA changes, or an account was created before it was accepted at sign-up, an account owner of Covered Entity accepts the current version in the app by checking the box to agree, with the same effect and the same record. The app’s Settings show who accepted the BAA and when.
Want a countersigned copy for your records? Email help@frontdesk.talk with your business name and account email and we will send one. If you and we have signed a separate business associate agreement, that signed agreement controls instead of this one. Covered Entity must not use the Services for PHI until this BAA (or a signed one) is in effect.
1. Purpose
This BAA governs the use and disclosure of Protected Health Information under the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164, as amended (together, “HIPAA”). Its purpose is to meet the requirements of HIPAA for business associate contracts, including 45 C.F.R. §§ 164.308(b), 164.314(a), 164.502(e), and 164.504(e).
2. Definitions
Capitalized terms used but not defined in this BAA have the meanings given in HIPAA, including Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use. Any ambiguity is resolved in favor of a meaning that permits compliance with HIPAA.
- “Protected Health Information” or “PHI” has the meaning given in 45 C.F.R. § 160.103, limited to information that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity through the Services. It includes Electronic Protected Health Information (“ePHI”).
- “Breach” has the meaning given in 45 C.F.R. § 164.402.
- “Security Incident” has the meaning given in 45 C.F.R. § 164.304.
- “Reportable Event” means (i) a Use or Disclosure of PHI not permitted by this BAA, (ii) a Security Incident involving ePHI, or (iii) a Breach of Unsecured PHI.
- “Subcontractor” has the meaning given in 45 C.F.R. § 160.103.
3. Permitted uses and disclosures
Except as otherwise limited in this BAA, Business Associate may:
- Use and disclose PHI to perform the Services for Covered Entity as described in the Agreement and as Covered Entity directs through its settings in the Services, if the Use or Disclosure would not violate HIPAA if done by Covered Entity.
- Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities.
- Disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, if (i) the Disclosure is Required by Law, or (ii) Business Associate gets reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any instance it knows of in which the confidentiality of the PHI has been breached.
- Provide Data Aggregation services relating to the Health Care Operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
- De-identify PHI in accordance with 45 C.F.R. § 164.514(a) through (c). De-identified information is not PHI. Business Associate will use it only to operate, secure, measure, and improve the Services, will not attempt to re-identify it, and will not use it to train artificial intelligence models.
- Use PHI to report violations of law to appropriate federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1).
Business Associate will not:
- Sell PHI, or receive direct or indirect payment in exchange for PHI, except as HIPAA permits
- Use or disclose PHI for marketing or fundraising
- Use PHI to train, fine-tune, or improve artificial intelligence or machine learning models, whether its own or a third party’s
- Use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as this section permits for management, administration, and Data Aggregation
4. Obligations of Business Associate
Limits on Use and Disclosure
Business Associate will not Use or Disclose PHI other than as permitted or required by this BAA or as Required by Law.
Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided by this BAA. As of the Effective Date these safeguards include encryption of data in transit, encryption at rest through Business Associate’s hosting providers, role-based access controls for Covered Entity’s users, limits on and logging of Business Associate staff access, and the measures described on the Security page. Business Associate may change its safeguards if the change does not reduce the overall protection of PHI.
Minimum Necessary
Business Associate will limit its Uses, Disclosures, and requests of PHI to the Minimum Necessary to accomplish the intended purpose, as required by 45 C.F.R. § 164.502(b).
Workforce
Business Associate will ensure that members of its workforce who may access PHI are trained on their obligations, are bound by written confidentiality obligations, and are subject to sanctions for violations.
Reporting Reportable Events
Business Associate will report to Covered Entity any Reportable Event of which it becomes aware, without unreasonable delay and in no case later than sixty (60) calendar days after discovery, as discovery is defined in 45 C.F.R. § 164.410(a)(2). The report will include, to the extent known and as it becomes available:
- The identity of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, Used, or Disclosed
- A description of what happened, including the date of the Reportable Event and the date of discovery
- The types of PHI involved
- The steps Business Associate has taken to investigate, mitigate harm, and protect against further events
- Any other information Covered Entity reasonably needs to meet its notification obligations under 45 C.F.R. §§ 164.404 through 164.408
This section is notice to Covered Entity of the ongoing existence of unsuccessful Security Incidents, such as pings, port scans, denied log-in attempts, and denial-of-service attempts that do not result in unauthorized access to, or Use or Disclosure of, PHI. No further notice of these is required.
Mitigation
Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a Reportable Event, and will cooperate with Covered Entity in investigating it and in determining whether it is a Breach of Unsecured PHI.
Subcontractors
Under 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to substantially the same restrictions, conditions, and requirements that apply to Business Associate under this BAA. On request, Business Associate will give Covered Entity a list of its Subcontractors that handle PHI.
Access
To the extent Business Associate maintains PHI in a Designated Record Set, it will, within fifteen (15) business days after Covered Entity’s written request, make that PHI available to Covered Entity (through the Services or another reasonable format) so Covered Entity can meet its obligations under 45 C.F.R. § 164.524, including providing a copy in electronic form.
Amendment
To the extent Business Associate maintains PHI in a Designated Record Set, it will, within fifteen (15) business days after Covered Entity’s written request, make amendments Covered Entity directs or agrees to under 45 C.F.R. § 164.526, or give Covered Entity the means to make them.
Accounting of Disclosures
Business Associate will document Disclosures of PHI that would require an accounting under 45 C.F.R. § 164.528, and will, within fifteen (15) business days after Covered Entity’s written request, give Covered Entity the information it needs to respond to an Individual’s request for an accounting.
Requests from Individuals
If an Individual asks Business Associate directly for access, amendment, an accounting, a restriction, or confidential communications, Business Associate will forward the request to Covered Entity within ten (10) business days, and will not respond to the Individual except as Covered Entity directs or as Required by Law.
Carrying out Covered Entity’s obligations
To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 C.F.R. Part 164, it will comply with the requirements of Subpart E that apply to Covered Entity in performing that obligation.
Books and records
Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA. Doing so does not waive any attorney-client, accountant-client, or other legal privilege.
Other business associates of Covered Entity
At Covered Entity’s direction, Business Associate may disclose PHI to, and receive PHI from, other business associates of Covered Entity (for example, a calendar or email service Covered Entity connects to the Services). Covered Entity is responsible for having business associate agreements with its other business associates.
5. Obligations of Covered Entity
- Notice of Privacy Practices. Covered Entity will notify Business Associate in writing of any limitation in its Notice of Privacy Practices that may affect Business Associate’s Use or Disclosure of PHI.
- Changes in permission. Covered Entity will notify Business Associate of any change in, or revocation of, an Individual’s permission to Use or Disclose PHI that may affect Business Associate.
- Restrictions. Covered Entity will notify Business Associate of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to under 45 C.F.R. § 164.522 that may affect Business Associate.
- Permissible requests. Covered Entity will not ask Business Associate to Use or Disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
- Minimum Necessary. Covered Entity will give Business Associate, and configure the Services to collect, only the PHI reasonably necessary for the Services. Covered Entity will not enter PHI into the receptionist’s business information, greeting, or instructions.
- Excluded records. Covered Entity will not use the Services to store psychotherapy notes, or records protected by 42 C.F.R. Part 2 (substance use disorder treatment records), unless Business Associate agrees in writing first.
- Its own compliance. Covered Entity remains responsible for its own HIPAA program, including its Notice of Privacy Practices, its policies on communicating with patients, managing which of its users have access to the Services and what role they have, and protecting the devices and accounts its users use to reach the Services.
6. How the Services handle PHI
Covered Entity understands and agrees that:
- Protective notifications. The Services ask whether Covered Entity’s callers may share health information. Unless Covered Entity answers “no,” call notices (Talk Notes) and alerts sent by text message, email, and mobile push notification contain no caller name, phone number, call summary, intake answers, or text message words, only that a call, message, or documents came in, with a link to the app. Covered Entity will not answer “no” while its callers may share PHI. If Covered Entity answers “no” (or changes its answer to “no”), the Services send detailed notifications, which can include caller details, to the phone numbers, email addresses, and users Covered Entity chooses, at Covered Entity’s direction and responsibility. Accepting this BAA sets the answer to “yes.”
- Messages to patients. Texts the Services send to patients (such as missed-call text backs, appointment confirmations, and upload links) are sent at Covered Entity’s direction. Covered Entity is responsible for deciding what they say and for honoring patients’ communication preferences and requests for confidential communications.
- Connected services. Calendars and email inboxes that Covered Entity connects or sends to are Covered Entity’s own accounts, and are not Subcontractors of Business Associate. Covered Entity is responsible for having a business associate agreement with those providers where HIPAA requires one.
- Recordings and consent. Covered Entity is responsible for giving any notice and getting any consent that federal or state law requires before calls are recorded or processed by AI.
- AI is not a clinician. The receptionist is an AI that answers calls. It does not give medical advice, diagnose, or triage, and it is not a substitute for clinical judgment or for 911. Transcripts and Talk Notes may contain errors. Covered Entity is responsible for reviewing them before relying on them for any clinical or treatment purpose.
- Not a record system. The Services are not an electronic health record. Covered Entity is responsible for copying any information it needs for its medical records into its own record system.
7. Term and termination
Term
This BAA starts on the Effective Date and continues until the Agreement ends and all PHI has been returned or destroyed as described below, unless it is terminated earlier under this section.
Termination for cause
If either party determines that the other has violated a material term of this BAA, it will give the other written notice describing the violation in enough detail to understand it, and an opportunity to cure. If the violation is not cured within thirty (30) days after the notice, the non-breaching party may terminate this BAA and the Agreement. If cure is not possible, the non-breaching party may terminate immediately.
Effect of termination
When this BAA ends for any reason, Business Associate will, within thirty (30) days after the later of the end of the Agreement and Covered Entity’s written request (or, if Covered Entity deletes its account, within thirty (30) days after the deletion), return or destroy all PHI it and its Subcontractors maintain in any form, and keep no copies. Before the Agreement ends, Covered Entity may download or ask for a copy of PHI it wants to keep. If return or destruction is not feasible (for example, for PHI in backups that roll off on a fixed schedule, or records Business Associate must keep by law), Business Associate will:
- Keep only the PHI for which return or destruction is not feasible
- Extend the protections of this BAA to that PHI, and continue to comply with the Security Rule for ePHI, for as long as it keeps the PHI
- Not Use or Disclose that PHI except for the purposes that make return or destruction infeasible
- Return or destroy that PHI when it becomes feasible
This section survives the end of this BAA.
8. Liability and indemnification
Each party is responsible for its own violations of this BAA and of HIPAA. Each party will indemnify and hold harmless the other from third-party claims, fines, penalties, and reasonable costs (including reasonable attorneys’ fees) to the extent caused by its own breach of this BAA or its own negligent acts or omissions.
To the extent permitted by law, all liability under this BAA, including the indemnities above and any breach of HIPAA, is subject to the limitation of liability in the Agreement: Business Associate’s total liability for all claims combined under the Agreement and this BAA will not exceed the lesser of the fees Covered Entity paid in the 12 months before the event that gave rise to the first claim, or $1,200. This is a total, not a limit per claim or per incident. The limitation does not apply to a party’s gross negligence or willful misconduct, or where the law does not allow liability to be limited.
9. Miscellaneous
- Regulatory references and amendment. A reference to HIPAA means the section as in effect or as amended. If HIPAA changes in a way that requires a change to this BAA, this BAA is amended to the extent needed to comply, and the parties will work in good faith on any further amendment. Business Associate may update this BAA by posting a new version and notifying Covered Entity as the Agreement provides; otherwise, amendments must be in writing.
- Interpretation and precedence. Any ambiguity is resolved in favor of a meaning that permits compliance with HIPAA. If this BAA conflicts with the Agreement or the Privacy Policy about PHI, this BAA controls.
- Independent contractors. The parties are independent contractors. Business Associate is not Covered Entity’s agent for purposes of HIPAA or otherwise.
- No third-party beneficiaries. Nothing in this BAA gives any rights or remedies to anyone other than the parties and their permitted successors and assigns.
- Severability. If any provision is held invalid or unenforceable, the rest of this BAA stays in effect.
- Governing law. This BAA is governed by the law that governs the Agreement, except where federal law controls.
- Notices. Notices to Business Associate must be in writing and sent by email to help@frontdesk.talk with the subject “BAA notice,” with a copy by mail to FrontDesk Talk, LLC, Attn: Privacy, 17350 State Hwy 249, Ste 220, Houston, TX 77064. Notices to Covered Entity will be sent to the email address of the account owner. Either party may change its notice address by notice to the other.
- Survival. Business Associate’s obligations for PHI it keeps after this BAA ends, and the liability section, survive.
10. Questions
Questions about this BAA, or need a countersigned copy? Email help@frontdesk.talk. For an overview of how FrontDesk Talk protects health information, see our HIPAA page.