Legal · Felican AI Inc
Business Associate Agreement
Effective
This is the Business Associate Agreement (“BAA”) that each law firm signs in InjuryMcGee before uploading protected health information. It is written to meet the requirements of HIPAA, including 45 C.F.R. § 164.504(e) and § 164.314(a).
Version 2026-10-11. The version you sign is recorded with your workspace.
1. Parties and purpose
This BAA is between Felican AI Inc, 1001 South Main, Suite 700, Kalispell, MT 59901, (561) 264-7166 (“Business Associate”), and the law firm or other organization that subscribes to InjuryMcGee and signs this BAA in the Service (“Covered Entity”). It applies when, and to the extent that, Business Associate creates, receives, maintains or transmits Protected Health Information on behalf of Covered Entity in providing InjuryMcGee (the “Service”) under the Terms of Service (the “Underlying Agreement”).
Covered Entity may be a HIPAA covered entity, or a business associate of one, or may hold medical information under a client's authorization. The parties agree to treat all such information as Protected Health Information under this BAA either way.
2. Definitions
Capitalized terms used but not defined here have the meanings given in the HIPAA Rules (45 C.F.R. Parts 160 and 164), including “Breach”, “Designated Record Set”, “Individual”, “Required by Law”, “Secretary”, “Security Incident”, “Subcontractor” and “Unsecured Protected Health Information”.
- “HIPAA Rules” means the Privacy, Security, Breach Notification and Enforcement Rules at 45 C.F.R. Parts 160 and 164, as amended, including by the HITECH Act.
- “PHI” means Protected Health Information, including electronic PHI, that Business Associate creates, receives, maintains or transmits on behalf of Covered Entity.
3. Permitted uses and disclosures
Business Associate may use or disclose PHI only:
- To perform the Service for Covered Entity as described in the Underlying Agreement, including storing, organizing, classifying, extracting, summarizing and drafting from case documents at Covered Entity's direction.
- To send communications containing PHI only to recipients that an authorized user of Covered Entity has approved in the Service.
- As Required by Law.
- For Business Associate's proper management and administration or to carry out its legal responsibilities, provided that any disclosure for these purposes is Required by Law, or Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any instance in which the confidentiality of the PHI has been breached.
- To de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c), solely to operate and secure the Service.
Business Associate will not use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted in items 4 and 5 above. Business Associate will make reasonable efforts to use, disclose and request only the minimum necessary PHI. Business Associate will not sell PHI, use PHI for marketing, or use PHI to train machine-learning models.
4. Business Associate obligations
Business Associate will:
- Not use or disclose PHI other than as permitted or required by this BAA or as Required by Law.
- To the extent Business Associate carries out any of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in performing those obligations.
- Mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this BAA.
- Document disclosures of PHI as needed for Covered Entity to respond to a request for an accounting of disclosures.
5. Safeguards
Business Associate will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided by this BAA. These include:
- Storing documents containing PHI in Microsoft Azure Blob Storage, a HIPAA-eligible service covered by Microsoft's business associate agreement, encrypted at rest, with soft delete and versioning enabled.
- Processing PHI with AI and OCR services only on Microsoft Azure (Azure AI Foundry and Azure AI Document Intelligence) under Microsoft's business associate agreement.
- Encrypting PHI in transit using TLS.
- Logical separation of each customer's data, role-based access controls, and an append-only audit log.
- Limiting workforce access to PHI to personnel who need it to provide or support the Service, and training those personnel.
- Maintaining a written security risk analysis and risk management plan and reviewing them at least annually.
6. Reporting and breach notification
- Business Associate will report to Covered Entity any use or disclosure of PHI not provided for by this BAA, and any Breach of Unsecured PHI as required by 45 C.F.R. § 164.410, without unreasonable delay and in no case later than ten (10) business days after discovery.
- The report will include, to the extent known, the identity of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used or disclosed; a description of what happened, including the dates of the Breach and of discovery; the types of PHI involved; the steps Business Associate is taking to investigate, mitigate harm and protect against further Breaches; and any other information Covered Entity reasonably needs to notify Individuals, regulators or the media. Business Associate will supplement the report as further information becomes available.
- Business Associate will report Security Incidents of which it becomes aware. The parties agree that this paragraph is notice of the ongoing existence of unsuccessful Security Incidents, such as pings, port scans, denied log-in attempts and blocked malware, for which no further notice is required unless they result in unauthorized access, use or disclosure of PHI.
- Unless the parties agree otherwise, Covered Entity is responsible for notifying affected Individuals, the Secretary and the media as the HIPAA Rules require.
7. Subcontractors
In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate under this BAA, including implementing reasonable and appropriate safeguards. Business Associate's current Subcontractors that handle PHI are listed in the HIPAA notice. Business Associate will give Covered Entity notice before adding a Subcontractor that handles PHI.
8. Access, amendment and accounting
- Access. To the extent Business Associate maintains PHI in a Designated Record Set, it will make that PHI available to Covered Entity within fifteen (15) days of a request, in the form and format requested where readily producible, so that Covered Entity can meet its obligations under 45 C.F.R. § 164.524. The Service's export features satisfy this obligation when they provide the requested PHI.
- Amendment. Business Associate will make amendments to PHI in a Designated Record Set as directed by Covered Entity under 45 C.F.R. § 164.526, or allow Covered Entity to make them in the Service, within fifteen (15) days of a request.
- Accounting. Business Associate will provide to Covered Entity, within fifteen (15) days of a request, the information needed for Covered Entity to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528.
- If an Individual asks Business Associate directly for access, amendment or an accounting, Business Associate will forward the request to Covered Entity within five (5) business days.
9. Access by HHS
Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules, and will notify Covered Entity of any such request unless prohibited by law.
10. Covered Entity obligations
- Covered Entity will notify Business Associate of any limitation in its notice of privacy practices, any restriction on use or disclosure it has agreed to, and any change or revocation of an Individual's authorization, to the extent it may affect Business Associate's use or disclosure of PHI.
- Covered Entity will not ask Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.
- Covered Entity is responsible for obtaining any authorizations or consents its obligations require, for the roles and permissions it gives its users, and for the recipients its users approve.
11. Term and termination
- This BAA takes effect when Covered Entity signs it in the Service and continues until all PHI is returned or destroyed under section 12.
- If Covered Entity determines that Business Associate has violated a material term of this BAA, Covered Entity may terminate the Underlying Agreement and this BAA if Business Associate does not cure the violation within thirty (30) days of written notice, or immediately if cure is not possible.
- If Business Associate determines that Covered Entity has violated a material term of this BAA, Business Associate may terminate on the same basis.
- This BAA terminates automatically when the Underlying Agreement terminates, subject to section 12.
12. Return or destruction of PHI
On termination, Business Associate will make PHI available to Covered Entity for export for thirty (30) days and will then destroy all PHI it and its Subcontractors maintain in any form, including in versioned and soft-deleted storage and backups as they expire on their normal schedule, which will not exceed ninety (90) days. Business Associate will retain no copies, except where return or destruction is infeasible; in that case Business Associate will notify Covered Entity of the conditions that make it infeasible, extend the protections of this BAA to that PHI, and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it retains the PHI. Business Associate will certify destruction in writing on request.
13. Miscellaneous
- Any ambiguity in this BAA will be resolved to permit compliance with the HIPAA Rules.
- The parties will amend this BAA as needed to comply with changes in the HIPAA Rules. Business Associate will publish updated versions here with a new version date and ask Covered Entity to sign them in the Service.
- If this BAA conflicts with the Underlying Agreement regarding PHI, this BAA controls.
- Sections 6, 9 and 12 survive termination.
- Nothing in this BAA confers any rights on any third party.
- This BAA is governed by federal law and, where not preempted, the laws of the State of Florida.
- Notices to Business Associate: Felican AI Inc, 1001 South Main, Suite 700, Kalispell, MT 59901; [email protected]; (561) 264-7166. Notices to Covered Entity go to the workspace owner's email address.
Draft pending legal review.