VaultMailVaultMail

Business Associate Agreement

v1.3

Effective: 2026-07-27 · Between Spriggan AI, Inc. and you, the Covered Entity.

BUSINESS ASSOCIATE AGREEMENT

VaultMail — Spriggan AI, Inc.

Recitals

This Business Associate Agreement ("BAA") is entered into by and between Spriggan AI, Inc. ("Business Associate" or "VaultMail") and the entity or individual accepting this BAA ("Covered Entity" or "Customer"). Customer uses VaultMail, an encrypted file sharing and email encryption service operated by Spriggan AI, Inc. In connection with Customer's use of VaultMail, Business Associate may create, receive, maintain, or transmit Protected Health Information ("PHI") on behalf of Customer. The Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), and its implementing regulations at 45 CFR Parts 160 and 164 (the "HIPAA Rules") require that Covered Entities obtain satisfactory assurances from their Business Associates that PHI will be appropriately safeguarded. This BAA sets forth the terms and conditions pursuant to which PHI will be handled by Business Associate in connection with the VaultMail service.

1. Definitions

Capitalized terms used but not otherwise defined in this BAA have the meanings set forth in the HIPAA Rules. For purposes of this BAA: (a) "Breach" has the meaning set forth in 45 CFR § 164.402. (b) "Designated Record Set" has the meaning set forth in 45 CFR § 164.501. (c) "Electronic Protected Health Information" or "ePHI" means PHI that is transmitted by or maintained in electronic media, as defined in 45 CFR § 160.103. (d) "Protected Health Information" or "PHI" means individually identifiable health information, as defined in 45 CFR § 160.103, that is created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity through the VaultMail service. For the avoidance of doubt, PHI includes ePHI. (e) "Security Incident" has the meaning set forth in 45 CFR § 164.304. (f) "Service" means the VaultMail encrypted file sharing and email encryption service, including web application, Chrome extension, and associated APIs operated by Business Associate. (g) "Subcontractor" means a person or entity to whom Business Associate delegates a function, activity, or service involving the creation, receipt, maintenance, or transmission of PHI.

2. Obligations of Business Associate

(a) Permitted Uses and Disclosures. Business Associate shall not use or disclose PHI except as permitted or required by this BAA, as necessary to perform the Service for Covered Entity, or as Required by Law. (b) Safeguards. Business Associate shall use appropriate administrative, physical, and technical safeguards to prevent the use or disclosure of PHI other than as provided for by this BAA, consistent with the requirements of Subpart C of 45 CFR Part 164. (c) Reporting. Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which Business Associate becomes aware. Business Associate shall report any Security Incident of which Business Associate becomes aware. Business Associate shall report any Breach of Unsecured PHI in accordance with 45 CFR § 164.410. (d) Breach Notification Timing. Business Associate shall provide notification to Covered Entity of a Breach without unreasonable delay, and in no event later than thirty (30) calendar days after discovery of the Breach. Notification shall include, to the extent available: (i) the identification of each individual whose Unsecured PHI has been, or is reasonably believed to have been, breached; (ii) a description of the type of Unsecured PHI involved; (iii) recommended steps for individuals to protect themselves; (iv) a description of what Business Associate is doing to investigate the Breach, mitigate harm, and prevent future Breaches; and (v) contact procedures for individuals to ask questions. (e) Subcontractors. Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions and conditions that apply to Business Associate under this BAA, in accordance with 45 CFR § 164.502(e)(1)(ii) and § 164.308(b)(2). Business Associate's current Subcontractors for the Service are: Google Cloud Platform (compute, storage, key management) and authentication identity providers (Google, Microsoft). (f) Access. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.524. (g) Amendment. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make PHI available for amendment and incorporate amendments to PHI as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.526. (h) Accounting. Business Associate shall make information available as required for Covered Entity to satisfy its obligations to provide an accounting of disclosures under 45 CFR § 164.528. Business Associate maintains an audit log of all access to encrypted objects, which serves as the basis for accounting of disclosures. (i) Government Access. Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Rules. (j) Minimum Necessary. Business Associate shall limit its use, disclosure, or request of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 CFR § 164.502(b).

3. Obligations of Covered Entity

(a) Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as expressly permitted under this BAA. (b) Covered Entity shall be responsible for implementing appropriate safeguards within its own environment, including but not limited to: (i) obtaining any required patient authorizations or consents; (ii) maintaining the security of its own devices and accounts used to access the Service; (iii) determining what data constitutes PHI; and (iv) ensuring its workforce members are trained on HIPAA requirements. (c) Covered Entity shall notify Business Associate of any restrictions on the use or disclosure of PHI to which Covered Entity has agreed in accordance with 45 CFR § 164.522, to the extent that such restrictions affect Business Associate's use or disclosure of PHI. (d) Covered Entity shall not provide Business Associate with PHI that Covered Entity does not have the authority or right to disclose to Business Associate. (e) Covered Entity acknowledges that Business Associate provides an encryption and access control service. Business Associate encrypts content provided by Covered Entity and controls access based on policies set by Covered Entity. Business Associate does not review, interpret, or make clinical decisions based on the content of encrypted objects. (f) Content Retention. Business Associate cryptographically destroys encrypted content (file and message payloads and their wrapped encryption keys) thirty (30) days after the content is created, or sooner if Covered Entity sets a shorter expiration. The associated audit-log entries for that object (access, grant, denial, revocation, and deletion events) are NOT deleted at thirty (30) days; they are retained as part of the accounting of disclosures for a minimum of six (6) years per 45 CFR § 164.530(j) before the underlying record is finally purged. Business Associate retains operational compliance documentation required by 45 CFR § 164.530(j) (including written policies and procedures, risk assessments, breach-notification records, and signed BAA acceptance records) for six (6) years from the date of creation or the date the record was last in effect, whichever is later. Covered Entity acknowledges and agrees that the Service is a transport and access-control tool, not a system of record, and that Covered Entity is solely responsible for retaining any PHI needed to satisfy its own legal, regulatory, or professional records-retention obligations (including state medical-records-retention laws). Business Associate will preserve content that is subject to a legal hold or preservation order of which it has received written notice, notwithstanding the thirty (30)-day deletion schedule. (g) Sender-Initiated Permanent Deletion. The Service allows Covered Entity (as sender) to permanently delete an encrypted object's payload at any time before its scheduled expiration. When Covered Entity deletes an object, Business Associate destroys the object's wrapped encryption key and erases the encrypted payload (the encrypted file bytes held in object storage and/or the inline ciphertext). Because the encryption key is destroyed, the content becomes cryptographically unrecoverable — including from any residual copies that may exist in operational backups, which are unreadable without the key and are purged in the ordinary course within the applicable backup-retention period. This cryptographic erasure is consistent with the media-sanitization guidance of NIST Special Publication 800-88. The object's audit-log record (recipients, access events, and the deletion event itself) is intentionally retained as part of the accounting of disclosures and is unaffected by this deletion. Deletion is irreversible: Business Associate cannot restore deleted content, and Covered Entity is solely responsible for retaining any PHI it is independently required to keep.

4. Technical Safeguards

Business Associate implements the following technical safeguards in accordance with 45 CFR § 164.312: (a) Access Control (§164.312(a)(1)): Recipient allowlists enforced server-side. Only email addresses designated by the sender may decrypt content. (b) Unique User Identification (§164.312(a)(2)(i)): All users authenticated via OAuth (Google, Microsoft) or verified email. No shared accounts. (c) Automatic Logoff (§164.312(a)(2)(iii)): Sessions expire after 15 minutes of inactivity. Re-authentication required. (d) Encryption and Decryption (§164.312(a)(2)(iv)): AES-256-GCM encryption with per-object data encryption keys (DEKs), wrapped by per-user key encryption keys (KEKs). (e) Audit Controls (§164.312(b)): Immutable audit log records every encryption, decryption, access, grant, denial, and revocation event with timestamps, IP addresses, and user identifiers. (f) Integrity (§164.312(c)(1)): AES-GCM authentication tags detect any modification to encrypted content. (g) Transmission Security (§164.312(e)(1)): TLS 1.3 enforced on all connections. HSTS preloaded. (h) Infrastructure: The Service runs on Google Cloud Platform under a signed Google Cloud Business Associate Agreement. All GCP services used are HIPAA-eligible.

5. Term and Termination

(a) Term. This BAA takes effect on the date of acceptance by Covered Entity and remains in effect for as long as Covered Entity maintains an active VaultMail account, unless earlier terminated as provided herein. (b) Termination for Cause. Either party may terminate this BAA if the other party materially breaches any provision of this BAA and fails to cure such breach within thirty (30) days after receiving written notice of the breach. (c) Effect of Termination. Upon termination of this BAA, Business Associate shall, at Covered Entity's election, return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity. If return or destruction is infeasible, Business Associate shall extend the protections of this BAA to the PHI retained and limit further uses and disclosures to those purposes that make return or destruction infeasible. Audit log records may be retained for up to six (6) years as required by HIPAA §164.530(j). (d) Automatic Termination. This BAA shall automatically terminate if Covered Entity's VaultMail account is terminated or deleted.

6. Limitation of Liability

(a) TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL BUSINESS ASSOCIATE BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO THIS BAA, REGARDLESS OF THE FORM OF ACTION AND WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, EVEN IF BUSINESS ASSOCIATE HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. (b) TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, BUSINESS ASSOCIATE'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS BAA SHALL NOT EXCEED THE GREATER OF: (I) THE TOTAL FEES PAID BY COVERED ENTITY TO BUSINESS ASSOCIATE DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (II) ONE HUNDRED U.S. DOLLARS (USD $100). (c) The limitations in this Section 6 shall not apply to: (i) Business Associate's breach of its confidentiality obligations; or (ii) either party's indemnification obligations under Section 7. (d) COVERED ENTITY ACKNOWLEDGES THAT THE SERVICE IS PROVIDED PRIMARILY AS AN ENCRYPTION AND ACCESS CONTROL TOOL. BUSINESS ASSOCIATE DOES NOT GUARANTEE THAT THE SERVICE WILL PREVENT ALL UNAUTHORIZED ACCESS TO PHI, AND COVERED ENTITY IS RESPONSIBLE FOR EVALUATING WHETHER THE SERVICE IS APPROPRIATE FOR ITS PARTICULAR COMPLIANCE NEEDS.

7. Indemnification

(a) Covered Entity shall indemnify, defend, and hold harmless Business Associate, its officers, directors, employees, and agents from and against any and all claims, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (i) Covered Entity's breach of this BAA; (ii) Covered Entity's failure to comply with applicable HIPAA Rules; (iii) Covered Entity's use of the Service in a manner not permitted by this BAA or the VaultMail Terms of Service; or (iv) any claim by a third party (including any individual whose PHI is at issue) arising from Covered Entity's acts or omissions. (b) Business Associate shall indemnify, defend, and hold harmless Covered Entity from and against any and all claims, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising directly from Business Associate's material breach of this BAA, subject to the limitations set forth in Section 6.

8. Disclaimer of Warranties

EXCEPT AS EXPRESSLY SET FORTH IN THIS BAA, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE." BUSINESS ASSOCIATE MAKES NO WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, OR NON-INFRINGEMENT. BUSINESS ASSOCIATE DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR COMPLETELY SECURE. COVERED ENTITY IS SOLELY RESPONSIBLE FOR DETERMINING WHETHER THE SERVICE MEETS ITS REGULATORY AND COMPLIANCE REQUIREMENTS.

9. General Provisions

(a) Regulatory References. Any reference in this BAA to a section of the HIPAA Rules means the section as in effect or as amended. (b) Amendment. The parties agree to amend this BAA as necessary to comply with the requirements of the HIPAA Rules or any other applicable law. Business Associate may update this BAA by posting a revised version at vaultmailapp.com/baa. Material changes will be communicated to Covered Entity via the email address on file at least thirty (30) days before taking effect. (c) Interpretation. Any ambiguity in this BAA shall be interpreted to permit compliance with the HIPAA Rules. (d) Governing Law. This BAA shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of laws principles. (e) Entire Agreement. This BAA, together with the VaultMail Terms of Service and Privacy Policy, constitutes the entire agreement between the parties regarding the subject matter hereof and supersedes all prior agreements, understandings, and communications, whether written or oral, regarding such subject matter. (f) Severability. If any provision of this BAA is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect. (g) Survival. Sections 6 (Limitation of Liability), 7 (Indemnification), 8 (Disclaimer of Warranties), and 9 (General Provisions) shall survive termination of this BAA. (h) No Third-Party Beneficiaries. This BAA is between Business Associate and Covered Entity. No third party has any rights under this BAA, except as required by the HIPAA Rules. (i) Electronic Acceptance. Covered Entity accepts this BAA by clicking "I Accept" or a similar mechanism within the VaultMail service. Electronic acceptance constitutes Covered Entity's legally binding signature. Business Associate records the date, time, IP address, and user agent of acceptance for audit purposes.

This BAA is provided for informational purposes and is not a substitute for legal advice. We recommend consulting with a healthcare attorney to ensure this agreement meets your organization’s specific compliance needs.

Questions? Contact support@spriggan.ai