← All legal documents
Version 1.0Effective July 24, 2026sha256 90e3e3c3155c6ea6ab4e5a6502689121ab090993ec9fd437f0f1490f8dacfe41

Dion Health — HIPAA Business Associate Agreement

Version: 1.0 Effective Date: July 24, 2026 Last Updated: July 24, 2026

This Business Associate Agreement (this "BAA") supplements and is incorporated into the Dion Health Master Subscription Agreement (the "Agreement") between Dion Health Management Company LLC ("Business Associate" or "Dion") and the customer entity identified in the applicable Order Form ("Covered Entity" or "Customer").

This BAA must be executed by both parties before Customer transmits any Protected Health Information to the Services. Unlike the Agreement, this BAA is not accepted by click-through; it is a signed instrument. Contact privacy@dionhealth.com to execute.

Where Customer is itself a business associate of another covered entity (for example, a dental support organization providing services to affiliated practices), Customer acts as a business associate and Dion acts as its subcontractor under 45 C.F.R. § 160.103, and this BAA applies with the corresponding substitutions.


1. Definitions

Capitalized terms used but not defined in this BAA have the meaning given in the Agreement or, where applicable, in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 C.F.R. Parts 160 and 164, as amended by the HITECH Act (collectively, "HIPAA").

"Breach," "Designated Record Set," "Disclosure," "Electronic Protected Health Information," "Health Care Operations," "Individual," "Minimum Necessary," "Required By Law," "Secretary," "Security Incident," "Subcontractor," "Unsecured Protected Health Information," and "Use" have the meanings given in 45 C.F.R. Parts 160 and 164.

"Protected Health Information" or "PHI" means Protected Health Information as defined at 45 C.F.R. § 160.103, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity under the Agreement.

"De-Identified Data" means health information that has been de-identified in accordance with 45 C.F.R. § 164.514(a)–(c), such that it is not individually identifiable health information and, per 45 C.F.R. § 164.502(d)(2), is not subject to HIPAA.

"Services" means the services provided by Business Associate under the Agreement.


2. Obligations of Business Associate

2.1 Permitted Uses and Disclosures

Business Associate will not Use or Disclose PHI other than as permitted or required by this BAA, the Agreement, or as Required By Law. Business Associate may Use and Disclose PHI:

(a) To provide the Services to Covered Entity as described in the Agreement and applicable Order Form;

(b) For the proper management and administration of Business Associate or to carry out Business Associate's legal responsibilities, as permitted by 45 C.F.R. § 164.504(e)(4)(i). Business Associate may Disclose PHI for these purposes only if the Disclosure is Required By Law, or if Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, Used or further Disclosed only as Required By Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality;

(c) To provide Data Aggregation services relating to the Health Care Operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B);

(d) To de-identify PHI in accordance with Section 3 of this BAA; and

(e) To report violations of law to appropriate federal or state authorities, consistent with 45 C.F.R. § 164.502(j)(1).

2.2 Minimum Necessary

Business Associate will limit its Use, Disclosure, and request of PHI to the Minimum Necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b) and § 164.514(d).

2.3 Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to Electronic Protected Health Information, to prevent Use or Disclosure of PHI other than as provided by this BAA.

2.4 Reporting

Business Associate will report to Covered Entity:

(a) Impermissible Use or Disclosure — any Use or Disclosure of PHI not provided for by this BAA of which it becomes aware, without unreasonable delay and in no case later than ten (10) business days after discovery;

(b) Breach of Unsecured PHI — any Breach of Unsecured PHI, without unreasonable delay and in no case later than thirty (30) calendar days after discovery, together with the information required by 45 C.F.R. § 164.410(c) to the extent known: the identification of each Individual whose PHI was or is reasonably believed to have been accessed, acquired, used, or disclosed; a description of what happened; the date of the Breach and the date of discovery; the types of information involved; the steps Individuals should take; and what Business Associate is doing to investigate, mitigate, and prevent recurrence. Business Associate will supplement this information as it becomes available;

(c) Security Incidents — any successful Security Incident of which it becomes aware, in accordance with subsections (a) and (b). The parties acknowledge that unsuccessful Security Incidents — such as pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, denial-of-service attempts, and malware that is blocked and does not result in unauthorized access to PHI — occur routinely and that no individual report of such incidents is required; this Section constitutes notice of their ongoing occurrence.

Notification under this Section is not an acknowledgment by Business Associate of fault or liability.

2.5 Mitigation

Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a Use or Disclosure of PHI in violation of this BAA.

2.6 Subcontractors

In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this BAA. Business Associate remains responsible for its Subcontractors' performance. A current list of Subcontractors that process PHI is available on request.

2.7 Access

Business Associate will make PHI in a Designated Record Set available to Covered Entity, or as directed by Covered Entity to an Individual, within ten (10) business days of a written request, as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524. Where Business Associate receives a request directly from an Individual, it will forward the request to Covered Entity rather than responding, unless Covered Entity directs otherwise.

2.8 Amendment

Business Associate will make PHI in a Designated Record Set available for amendment, and incorporate any amendment directed by Covered Entity, within ten (10) business days of a written request, as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.526.

2.9 Accounting of Disclosures

Business Associate will document Disclosures of PHI and information related to such Disclosures as would be required for Covered Entity to respond to a request for an accounting under 45 C.F.R. § 164.528, and will make such documentation available to Covered Entity within ten (10) business days of a written request. Business Associate maintains an audit log of access to and disclosure of PHI through the Services for this purpose.

2.10 Covered Entity Obligations

To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 C.F.R. Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation.

2.11 Availability to the Secretary

Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA. Business Associate will notify Covered Entity of any such request unless prohibited by law.

2.12 Direct Liability

Business Associate acknowledges that it is directly liable under HIPAA for compliance with the provisions applicable to business associates, including the Security Rule, the Breach Notification Rule, and the applicable provisions of the Privacy Rule.


3. De-Identification

3.1 Express Authorization

Covered Entity expressly authorizes Business Associate to de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c). This authorization is granted under 45 C.F.R. § 164.504(e)(2)(i), which permits a business associate agreement to specify additional permitted uses of PHI, and is a material term of the Agreement.

3.2 Method

Business Associate will de-identify PHI using one or both of the methods recognized under HIPAA:

(a) Expert Determination under 45 C.F.R. § 164.514(b)(1) — a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable determines that the risk is very small that the information could be used, alone or in combination with other reasonably available information, to identify an Individual, and documents the methods and results of that analysis; or

(b) Safe Harbor under 45 C.F.R. § 164.514(b)(2) — removal of the eighteen enumerated identifiers, with no actual knowledge that the remaining information could be used to identify an Individual.

Business Associate will maintain documentation of its de-identification methodology and, where expert determination is used, of the expert's analysis and certification. Business Associate will re-certify its expert determination not less frequently than every three (3) years or upon a material change to the de-identification process or the data. This documentation is available to Covered Entity on request.

3.3 Status and Ownership of De-Identified Data

Health information de-identified in accordance with this Section 3 is, per 45 C.F.R. § 164.502(d)(2), not individually identifiable health information and is not subject to HIPAA. As between the parties, and as set out in Section 8.3 of the Agreement, Business Associate owns De-Identified Data and may Use and Disclose it for any lawful purpose, including to develop, train, and improve machine-learning models and artificial-intelligence features, to produce benchmarks and research, and to develop and market products and services.

3.4 No Re-Identification

Business Associate will not attempt to re-identify De-Identified Data, will not attempt to contact any Individual whose information contributed to it, and will contractually prohibit the same by any recipient. Business Associate will maintain De-Identified Data in de-identified form and will implement reasonable safeguards against re-identification.

3.5 Segregation

Business Associate will not combine De-Identified Data with PHI or with other data in a manner that would render it individually identifiable.

3.6 State Law

Where applicable state law — including the California Confidentiality of Medical Information Act, Texas Health and Safety Code Chapter 181, or other state medical-information, genetic-privacy, or artificial-intelligence statutes — imposes requirements on de-identification or secondary use that are more stringent than HIPAA, Business Associate will comply with the more stringent requirement, and the rights in Section 3.3 apply only to the extent permitted by it.


4. Obligations of Covered Entity

4.1 Notice of Privacy Practices

Covered Entity will notify Business Associate of any limitation in its notice of privacy practices under 45 C.F.R. § 164.520, to the extent it affects Business Associate's Use or Disclosure of PHI.

4.2 Changes in Authorization

Covered Entity will notify Business Associate of any change in, or revocation of, an Individual's permission to Use or Disclose PHI, to the extent it affects Business Associate's Use or Disclosure.

4.3 Restrictions

Covered Entity will notify Business Associate of any restriction on the Use or Disclosure of PHI agreed to under 45 C.F.R. § 164.522, to the extent it affects Business Associate's Use or Disclosure. Business Associate is not bound by a restriction of which it has not been notified.

4.4 Permissible Requests

Covered Entity will not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except as permitted under Sections 2.1(b), 2.1(c), and 3 of this BAA.

4.5 Lawful Collection and Authority

Covered Entity represents and warrants that it has obtained all consents, authorizations, and notices required by law for the PHI it transmits to the Services, and has the authority to grant Business Associate access to the systems from which PHI is retrieved.

4.6 Appropriate Transmission

Covered Entity will not transmit PHI to any Service, module, field, or channel that the Documentation does not designate as intended to receive PHI.


5. Term and Termination

5.1 Term

This BAA takes effect on the date of last signature and continues until all PHI is returned, destroyed, or protected under Section 5.4, notwithstanding expiration or termination of the Agreement.

5.2 Termination for Cause

Covered Entity may terminate this BAA and the Agreement if Business Associate materially breaches this BAA and fails to cure within thirty (30) days of written notice. If cure is not feasible, Covered Entity may terminate immediately. Where neither termination nor cure is feasible, Covered Entity will report the violation to the Secretary.

5.3 Return or Destruction

Upon termination, Business Associate will, if feasible, return or destroy all PHI it created, received, maintained, or transmitted on behalf of Covered Entity, including PHI held by Subcontractors, and will retain no copies. Consistent with Section 14.5 of the Agreement, Business Associate will make PHI available for export for ninety (90) days following termination before proceeding under this Section.

5.4 Infeasibility

Where return or destruction is not feasible — including PHI retained in immutable backups, archival systems, or as Required By Law — Business Associate will extend the protections of this BAA to that PHI and limit further Uses and Disclosures to the purposes that make return or destruction infeasible, for so long as it retains the PHI.

5.5 De-Identified Data Not Subject to Return

De-Identified Data created under Section 3 is not PHI and is not subject to return or destruction under this Section 5. This survives termination.


6. General

6.1 Regulatory References

A reference to a section of HIPAA means the section as in effect or as amended, and includes any successor provision.

6.2 Amendment

The parties will take such action as is necessary to amend this BAA from time to time as is necessary for compliance with HIPAA and other applicable law.

6.3 Interpretation

Any ambiguity in this BAA will be resolved in favor of a meaning that permits compliance with HIPAA.

6.4 Conflict

In the event of a conflict between this BAA and the Agreement with respect to PHI, this BAA controls. In all other respects the Agreement governs, including its provisions on limitation of liability, indemnification, and dispute resolution.

6.5 No Third-Party Beneficiaries

Nothing in this BAA confers any right, remedy, or benefit on any person other than the parties.

6.6 Survival

Sections 3.3, 3.4, 5.3, 5.4, 5.5, and 6 survive termination.


Execution

DION HEALTH MANAGEMENT COMPANY LLC ("Business Associate")

Signature: ______________________________ Name: ______________________________ Title: ______________________________ Date: ______________________________

CUSTOMER ("Covered Entity")

Legal Entity Name: ______________________________ Signature: ______________________________ Name: ______________________________ Title: ______________________________ Date: ______________________________


Contact

Dion Health Management Company LLC 450 Sutter Street, Suite 1519 San Francisco, CA 94108

  • Privacy Officer: privacy@dionhealth.com
  • Security: security@dionhealth.com
  • Legal: legal@dionhealth.com

All legal documents · legal@dionhealth.com

Dion Health Management Company LLC · 450 Sutter Street, Suite 1519 · San Francisco, CA 94108