Business Associate Agreement
For U.S. Covered Entities. This BAA applies to clinic organizations who transmit HIPAA-regulated Protected Health Information (PHI) to Behery Dental's workflow platform. It works alongside our Terms of Service and Data Processing Agreement. Fields marked [TO BE DETERMINED] are placeholders pending completion.
1Definitions
Terms used but not defined in this BAA have the meanings given to them under HIPAA, including the HIPAA Privacy Rule (45 CFR Part 164, Subparts A and E) and the HIPAA Security Rule (45 CFR Part 164, Subparts A and C).
“Protected Health Information” or “PHI” — Individually identifiable health information transmitted or maintained in any form or medium by Behery Dental on behalf of the Covered Entity, as defined in 45 CFR §160.103. On the platform, this may include: the case record (a clinic-chosen patient reference, case type, status history, notes), treatment plans and treatment-plan review notes, case files the clinic chooses to upload (which may include STL or similar scan files, clinical photographs, treatment-plan exports, or other clinical documents) together with any files Behery Dental adds to the case in the course of delivering the design and production service, and case-thread messages exchanged between the clinic and Behery Dental.
Behery Dental's platform is designed by default not to require a patient's full legal name or a complete medical record: the case record is built to hold a clinic-chosen patient reference (e.g., initials plus a case number) rather than a direct identifier — see §5(f). This design choice meaningfully limits the identifiable PHI that passes through the platform, but it does not eliminate it — a Covered Entity could still include identifying details in a clinical photograph, a file name, or a note or message field. Whether the information handled for a given Covered Entity constitutes PHI depends on what that Covered Entity actually enters into notes, messages, or uploaded files, which remains within the Covered Entity's control.
“Electronic Protected Health Information” or “ePHI” — PHI that is created, stored, transmitted or received electronically.
“Breach” — Has the meaning given in 45 CFR §164.402.
“Security Incident” — Has the meaning given in 45 CFR §164.304.
2Permitted Uses and Disclosures by Business Associate
Behery Dental may use or disclose PHI only as follows:
a) To provide services. Behery Dental may use and disclose PHI as necessary to provide the Behery Dental platform, including case-status workflow tracking, treatment-plan review and approval, secure case file storage, case-thread messaging between the Covered Entity and Behery Dental, transactional email notifications about case activity (see §4), platform security, audit logging, and backup and disaster recovery. Behery Dental directly bills the Covered Entity for its design, production, and platform services — through a monthly subscription plan activated by Behery Dental staff, manual invoicing with a secure payment link (no card is stored), and per-case overage billing for usage beyond a plan's included volume. Behery Dental does not use PHI to determine or process that billing: billing is based on case and order counts, not on the content of any PHI.
b) As required by law. Behery Dental may use or disclose PHI as required by applicable law, including HIPAA.
c) For Business Associate's operations. Behery Dental may use PHI for its own proper management and administration, or to carry out its legal responsibilities, provided that disclosures are required by law or Behery Dental obtains reasonable assurances from the recipient that the PHI will be kept confidential.
d) No other uses or disclosures. Behery Dental will not use or disclose PHI in any manner not permitted by this BAA or HIPAA.
3Obligations of Business Associate
Behery Dental agrees to:
a) Not use or disclose PHI other than as permitted or required by this BAA or applicable law.
b) Implement safeguards. Use appropriate administrative, physical and technical safeguards to protect the confidentiality, integrity and availability of ePHI, in accordance with the HIPAA Security Rule (45 CFR Part 164, Subpart C).
c) Report breaches and security incidents. Notify the Covered Entity of: any Breach of Unsecured PHI within 30 days of discovery, including the information required by 45 CFR §164.410; and any Security Incident of which Behery Dental becomes aware, including attempted but unsuccessful incidents, in accordance with 45 CFR §164.314(a)(2)(i)(C). Reports should be directed to [email protected] or to the contact provided by the Covered Entity.
d) Sub-processors and subcontractors. Ensure that any subcontractor or sub-processor that creates, receives, maintains or transmits PHI on behalf of Behery Dental agrees to the same restrictions and conditions as apply to Behery Dental under this BAA. See §4 for disclosure of current PHI-accessing sub-processors.
e) Access and amendment. Provide access to PHI in a Designated Record Set to the Covered Entity or, as directed, to the individual, in accordance with 45 CFR §164.524. Accommodate requests to amend PHI in accordance with 45 CFR §164.526.
f) Accounting of disclosures. Make available the information required for the Covered Entity to provide an accounting of disclosures in accordance with 45 CFR §164.528.
g) Compliance assistance. Make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with HIPAA.
h) Minimum necessary. Use, disclose or request only the minimum PHI necessary to accomplish the intended purpose.
i) No sale of PHI. Behery Dental will not directly or indirectly receive remuneration in exchange for PHI, except as permitted under HIPAA.
j) No AI processing of PHI. The platform does not currently include any artificial-intelligence or machine-learning feature that processes case data, and Behery Dental does not use identifiable PHI to train artificial intelligence or machine learning models. If an AI-assisted feature is introduced in the future, this BAA will be updated first to disclose the relevant sub-processor under §4 before that feature is enabled for any Covered Entity.
4Sub-processors with Access to PHI
The following Behery Dental sub-processors may have access to PHI in the course of providing platform services. Behery Dental maintains appropriate agreements with each. Billing for Behery Dental's services (subscription and per-case overage charges) is invoiced directly to the Covered Entity and paid via a secure payment link; that billing process is based on case and order counts, not on PHI, so no payment-related sub-processor is listed in this table:
| Sub-processor | Role | PHI Access |
|---|---|---|
| Supabase, Inc. | Database, authentication, and case-file storage (a private, access-controlled storage bucket) | Yes. The case record, treatment plans, case-thread messages, and any case files the clinic or Behery Dental's team upload are stored on Supabase infrastructure. Encrypted at rest and in transit; access to a case's files is restricted by policy to the clinic's own team members (owner, admin, or member roles) and authorized Behery Dental staff. |
| Resend | Transactional email delivery (case status-change notices, new-message notices, invoice notices, team invites) | Limited. Case-status and new-message emails include the case's patient reference and, for new-message notices, a short preview (up to 140 characters) of the message text — which may constitute PHI depending on what a Covered Entity's staff enter into the case record or a message. Resend does not receive uploaded case files. |
Behery Dental will maintain and make available an up-to-date list of sub-processors upon written request to [email protected], and will notify Covered Entities before adding a new sub-processor with access to PHI.
5Obligations of the Covered Entity
The Covered Entity agrees to:
a) Notify Behery Dental of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to in accordance with 45 CFR §164.522, to the extent such restriction may affect Behery Dental's use or disclosure of PHI.
b) Notify Behery Dental of any changes in or revocation of consent or authorization of individuals to use or disclose PHI, to the extent this affects Behery Dental's permitted uses and disclosures.
c) Not request Behery Dental to use or disclose PHI in any manner that would not be permissible under HIPAA if done by the Covered Entity.
d) Obtain all required patient authorizations and consents before uploading PHI to the Behery Dental platform.
e) Implement appropriate access controls for its own users of the Behery Dental platform and ensure that only authorized personnel upload or access PHI.
f) Use an opaque patient reference (e.g., a case number or initials) in the platform's patient-reference field — which is the field the platform is designed to hold, not the patient's full legal name — and avoid entering the patient's full name or other direct identifiers into case notes or case-thread messages where not clinically necessary, to minimize PHI exposure on the platform. Where a Covered Entity needs to maintain a complete patient record, it should do so in its own practice-management or electronic-health-record system rather than on the platform.
6Term and Termination
a) Term. This BAA is effective upon the Covered Entity's acceptance of the Behery Dental Terms of Service or DPA, and remains in effect for the duration of the service relationship.
b) Termination for cause. Either party may terminate this BAA immediately if the other party materially breaches a HIPAA obligation and fails to cure the breach within 30 days of written notice.
c) Obligations on termination. Upon termination, Behery Dental will, at the direction of the Covered Entity, return or destroy all PHI received from or created on behalf of the Covered Entity, to the extent feasible. Where return or destruction is not feasible (for example, PHI held in backup systems), Behery Dental will extend the protections of this BAA to such PHI for as long as it is retained, and will limit further uses and disclosures to those purposes that make the return or destruction infeasible.
d) Data deletion. PHI deletion requests are fulfilled via a managed process within 30 days of written request to [email protected]. Payment and audit records may be retained in pseudonymized form to meet legal and regulatory obligations.
7Amendments
Behery Dental may amend this BAA from time to time to remain compliant with HIPAA and other applicable law. Material changes will be communicated to Covered Entities with reasonable advance notice. Continued use of the platform following notice of an amendment constitutes acceptance.
8Miscellaneous
a) Regulatory references. Any reference to a HIPAA regulation includes any amendments or successor provisions.
b) No third-party beneficiaries. This BAA is for the benefit of the parties only and does not create rights in any third party, including any patient.
c) Relationship to DPA. Where this BAA conflicts with the Behery Dental DPA on matters relating to PHI, this BAA governs. In all other respects the DPA applies.
d) Governing law. This BAA is governed by the laws of [TO BE DETERMINED], subject to applicable federal law including HIPAA.
e) Entire agreement. This BAA, together with the Behery Dental DPA and Terms of Service, constitutes the entire agreement between the parties with respect to HIPAA compliance.
f) Severability. If any provision of this BAA is found unenforceable, the remaining provisions continue in full force.
9Contact
To exercise rights under this BAA, report a Security Incident or Breach, or request a list of AI sub-processors:
Email: [email protected]
Company: Behery Dental
Questions about this BAA?
Contact us through the early access form and our team will follow up directly.