Who this is between
This Business Associate Agreement is between [Legal entity], which operates Bronwin, and the licensed provider or organization accepting it. It takes effect when you accept it at registration and governs all Protected Health Information we create, receive, maintain or transmit on your behalf.
We sign it on every plan, including the free one. There is no version of Bronwin that runs without it.
Capitalized terms not defined here carry the meaning given in 45 CFR Parts 160 and 164. Three terms are ours:
- Content — the events, severities, notes, board and legend created in the app. All of it reaches us encrypted under keys generated on your device and your patient’s.
- Service Metadata — everything else we hold: your account, the connection rows, key material sealed to your devices, and the hour a record arrived.
- Connection — one provider-to-patient relationship. It is the unit of encryption, and each has its own keys.
What we may do with it
We use and disclose Protected Health Information only:
- to provide, maintain and support the service you have contracted for;
- as Required by Law;
- for our own proper management and administration, or to carry out our legal responsibilities — and where that means disclosing it, only if the disclosure is Required by Law or the recipient agrees in writing to hold it confidentially, use it only as furnished, and tell us of any breach (45 CFR §164.504(e)(4)).
We will not:
- sell it, or use or disclose it for marketing or fundraising (§164.502(a)(5)(ii));
- de-identify it or build any derived dataset from it;
- use it to train machine-learning models;
- use or disclose it in any way that would violate Subpart E of Part 164 if you did it, except as §164.504(e)(2)(i)(A) permits for our management and administration.
Data aggregation services under §164.504(e)(2)(i)(B) are not offered, and could not be. Every connection has its own keys and we hold none of them. There is no view across your caseload for us to build, and building one would require a key we deliberately do not have.
How it is protected
We will use appropriate safeguards and comply with Subpart C of Part 164 with respect to electronic Protected Health Information, as §164.314(a)(2)(i)(A) requires. Specifically:
- Content is encrypted on the device before it is sent, under keys held in hardware-backed key storage on your phone and your patient’s. We hold no copy and no mechanism to derive, escrow or recover one.
- All transport is TLS. The server moves sealed blobs and performs no cryptography over your content.
- A written Security Rule risk analysis under §164.308(a)(1)(ii)(A), workforce training, a sanction policy, an incident response plan and a contingency plan, each reviewed at least annually.
- Access controls and audit controls recording which device read which connection and when. Audit records cover access, never Content.
- Verification of your NPI against NPPES at registration.
What we tell you, and when
We will report to you any use or disclosure not permitted by this agreement, any Security Incident we become aware of, and any Breach of Unsecured Protected Health Information — in each case without unreasonable delay and no later than five business days after discovery. The report will carry what §164.410(c) requires, to the extent we have it.
Unsuccessful Security Incidents — scans, pings, failed logins, the ordinary background noise of running a server — are reported in aggregate on request rather than one at a time.
On encryption and breach. Content is encrypted in a manner consistent with NIST SP 800-111 under keys we have never possessed, which is the standard the Breach Notification Rule uses to decide whether Protected Health Information is unsecured. An incident involving Content may therefore not be a Breach requiring notification at all. We will tell you about it regardless, and we will tell you exactly what was and was not covered by encryption, so the determination is yours to make.
Who else touches it
We may use subcontractors, and each one that creates, receives, maintains or transmits Protected Health Information on our behalf is bound in writing to restrictions at least as strict as these, as §164.502(e)(1)(ii) requires. The current list:
| Who | What they do | What reaches them |
|---|---|---|
| [Hosting provider] | Runs the sync server and its backups | Ciphertext, provider account rows, sealed key material, and the hour a record arrived. No key that opens any of it. |
| [Payment processor] | Subscription billing on the Solo and Group plans | Your name, email and card details. Nothing from any patient connection, and we never see or store a card number. |
| Netlify | Hosts bronwin.xyz | Requests to this website. Nothing from the app, which does not talk to it. |
| Cloudflare | The anti-spam check on the early access form | The challenge itself and the IP address that solved it. |
| Google Fonts | Serves the typefaces on this website | The IP address and browser of anyone who loads a page here. |
| Schoodic Mailer | Delivers the early access form to our inbox | The name, work email and three answers on that form. |
We will give you at least 30 days’ notice by email before adding a subcontractor that would handle Protected Health Information, and you may terminate rather than accept it.
Individual rights
Because we cannot decrypt Content, the copy that can answer a request from an individual is the one on your device, not the one on our servers.
- Access, §164.524. Content in a Designated Record Set is available to you in the app, and any date range exports to PDF with the legend included. On request we will also hand over the ciphertext and Service Metadata we hold for a connection, within ten business days.
- Amendment, §164.526. We will make Protected Health Information available for amendment and incorporate amendments as you direct. Records are append-only: an amendment is a new record superseding the earlier one, and the history keeps both.
- Accounting of disclosures, §164.528. We will document disclosures and give you what you need to answer a request within ten business days. We make no disclosures of Content, because we cannot read it; what we can account for is Service Metadata.
- The Secretary, §164.504(e)(2)(ii)(I). We will make our internal practices, books and records available to the Secretary of Health and Human Services for determining your compliance.
What you attest to
- Every person you connect is your current patient and is 18 or older. We have no way to verify either and do not try; your attestation and its timestamp are recorded on the connection.
- Whether your practice is subject to 42 CFR Part 2. You tell us at registration and you tell us if it changes.
- You will not put Protected Health Information anywhere it does not belong — your account profile, support email, or any form on bronwin.xyz. None of those are encrypted the way the app is, and the website form is delivered by a vendor who is not a Business Associate.
- You have whatever consent or authorization your own obligations require before you connect a patient.
- You will tell us of any restriction agreed under §164.522, or any revoked authorization, to the extent it changes what we may do.
- You will not ask us to use or disclose Protected Health Information in a way that would violate Subpart E if you did it yourself.
This is not your medical record
Bronwin is a patient-owned self-monitoring aid. It is not an electronic health record and not a system of record. Content that is clinically relevant belongs in your own record system; the PDF export exists so that path is a sanctioned one rather than a screenshot.
Record retention obligations of six to ten years or more run to you, not to us. The architecture that makes the rest of this agreement true is the same one that means we cannot restore what a lost device destroys: if you lose your only enrolled device and have not kept your recovery phrase, the histories go with it, and there is nothing on our servers that could bring them back.
42 CFR Part 2
If you tell us your practice is a Part 2 program, then for records covered by it:
- Part 2 protects patient identity itself, not only diagnosis and treatment. We hold no patient identity at all — no name, no email, no phone, and no way to work out which of your patients a connection belongs to.
- We will not use or disclose Part 2 records except as Part 2 permits, and will resist in any judicial proceeding an attempt to compel disclosure without a court order meeting §2.64 or §2.65.
- Exports carry the redisclosure notice §2.32 requires.
- Under the 2024 Final Rule, HIPAA’s Breach Notification Rule now applies to Part 2 records, and the reporting terms above apply to them unchanged.
Term, and what happens at the end of it
- This agreement runs until your account closes or it is terminated.
- Either of us may terminate for cause if the other materially breaches it and does not cure within 30 days of written notice.
- §164.504(e)(2)(ii)(J) asks for return or destruction of Protected Health Information at termination. We cannot return Content in usable form, having no key — the usable copy is already on your device, and you should export before you close the account. What we can do is destroy, and do: ciphertext, connection rows, sealed key material and roster ciphertext are deleted within 30 days of termination, and are gone from backups within 35 days.
- Service Metadata we are required to keep for legal or accounting reasons survives termination, and every protection in this agreement continues to apply to it for as long as we hold it.
- The sections on permitted use, safeguards, reporting, individual rights and this one survive termination.
General
- Nothing here creates rights in any third party.
- We may amend this agreement to keep it compliant with changes in law. Material changes are emailed to you at least 30 days before they take effect, and every version is retained; your account records which one you accepted and when.
- References to a regulation mean that section as amended from time to time.
- Any ambiguity is resolved in favor of the reading that complies with HIPAA and, where applicable, 42 CFR Part 2.
- Governed by the laws of [State].
- Notices go to [Legal entity], [Notice address], and to legal@bronwin.xyz.