HIPAA Business Associate Addendum
Effective August 28, 2026
Version 2026-08-28
This Business Associate Addendum (“BAA”) supplements the agreement governing Customer’s use of Leap’s Services (the “Underlying Agreement”) between the Customer identified in the Activation Record and Leap Intelligence, LLC, a Delaware limited liability company (“Leap”). Customer is the covered entity or business associate, as identified in that record, and Leap is the business associate.
Acceptance and activation. This BAA does not become effective merely because someone visits this page, accepts Leap’s general Terms, or uses a non-HIPAA Service. It becomes effective only when an authorized Customer representative affirmatively accepts this identified version in a Leap order form or electronic HIPAA activation flow and Leap confirms activation. That retrievable electronic record identifies the Customer, its covered role, acceptance and effective dates, covered locations or lines, retention selections, notice contacts, and other approved configuration (the “Activation Record”). PHI may be processed only after both acceptance and technical activation. Neither one alone establishes compliance.
1.Definitions and Scope
Capitalized terms not defined here have the meanings assigned by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended, including HITECH (“HIPAA”). “PHI” means Protected Health Information created, received, maintained, or transmitted by Leap for or on behalf of Customer. “Electronic PHI” or “ePHI” means PHI maintained or transmitted electronically.
This BAA applies only to PHI processed through the Services, locations, lines, providers, retention periods, recipients, and other configurations identified in the Activation Record (“HIPAA Services”). It does not authorize PHI in any other Leap service or configuration.
2.Permitted Uses and Disclosures
Leap may use and disclose PHI only as necessary to perform the Underlying Agreement and Activation Record, as permitted by this BAA, or as Required by Law. Leap shall not use or disclose PHI in a manner that would violate HIPAA if performed by Customer, except as expressly permitted for a business associate.
2.1Management and Administration
Leap may use PHI for its proper management and administration or to carry out its legal responsibilities. It may disclose PHI for those purposes only if Required by Law or after obtaining reasonable written assurances that the recipient will keep it confidential, use or disclose it only for the required or stated purpose, and notify Leap of a confidentiality breach.
2.2Minimum Necessary
Leap shall limit uses, disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose, except where HIPAA provides otherwise. Customer shall provide only the PHI reasonably necessary for the HIPAA Services.
2.3Prohibited Uses
Leap shall not sell PHI; use PHI for targeted advertising; use PHI to train a shared or public model; allow a model provider to use PHI for its own model training; or use PHI for unrelated product development, except with Customer’s express written authorization and only if permitted by law.
2.4De-identification and Aggregation
Leap may de-identify PHI under 45 C.F.R. § 164.514 only when the Activation Record expressly authorizes it. Data aggregation involving PHI also requires Customer’s express written authorization. Properly de-identified information is not PHI and may be retained and used subject to applicable law and the Underlying Agreement.
2.5No Clinical Reliance
HIPAA Services support administrative communications and workflows. They do not provide medical diagnosis, clinical advice, emergency services, or a substitute for licensed professional judgment. Customer remains responsible for clinical decisions, triage protocols, emergency procedures, and reasonable alternative urgent communication channels.
3.Safeguards
Leap shall comply with the applicable provisions of the HIPAA Security Rule for ePHI and maintain reasonable and appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI.
- Controls include, as appropriate to risk, authentication, least privilege, audit controls, transmission security, encryption, change and vulnerability management, backups, workforce training, incident response, and periodic risk analysis and management.
- Workforce access is limited to personnel who need PHI to provide or support HIPAA Services and who are bound by confidentiality duties.
- Leap maintains audit records reasonably sufficient to identify access to protected call content, transcripts, recordings, messages, contacts, exports, and sharing features.
- PHI may flow only through approved providers and locations. Leap shall not transfer it to an unapproved AI gateway, model provider, analytics service, or logging destination.
4.Subcontractors
Before a Subcontractor creates, receives, maintains, or transmits PHI for Leap, Leap shall obtain a written agreement requiring substantially the same restrictions, conditions, and safeguards that apply under this BAA. Leap shall maintain a current register of material PHI Subcontractors and provide it on reasonable request, subject to confidentiality and security restrictions.
Leap may update infrastructure and Subcontractors without Customer consent when the replacement is contractually and technically approved for PHI and does not materially reduce protection. Customer may request the register and, no more than once in twelve months, a confidential written summary of Leap’s latest security risk analysis or independent assessment. This BAA does not grant access to Leap’s systems, facilities, source code, or another customer’s data and does not limit the Secretary of HHS’s rights.
5.Data Handling
Recordings, transcripts, messages, and related call data may be retained for the period selected in the Activation Record. HIPAA does not require zero retention, but retention must be justified, secured, and no longer than reasonably necessary for the approved purpose or a legal obligation. Compliance and audit documentation may be retained for the period required by 45 C.F.R. § 164.316.
Leap shall require authorization before presenting PHI and shall use expiring or otherwise protected links for recordings and logs where supported. An expiring URL is not a substitute for application authorization and must not be treated as a permanent public link.
6.Reporting and Incident Response
Leap shall report a use or disclosure of PHI not permitted by this BAA of which it becomes aware, including a Breach of Unsecured PHI, without unreasonable delay and no later than ten calendar days after discovery. Leap shall report successful Security Incidents involving Customer PHI without unreasonable delay. This paragraph gives notice of routine unsuccessful attempts that do not result in unauthorized access, use, disclosure, modification, destruction, or interference.
To the extent known, notice will describe the event, discovery and occurrence dates, categories of PHI, affected Individuals, containment and mitigation, and a follow-up contact. Leap may supplement notice as facts become available. A notice is not an admission of fault or an automatic determination that a reportable Breach occurred.
Leap shall reasonably cooperate with Customer’s investigation, risk assessment, legally required notices, mitigation, and remediation. As between the parties, Customer determines and makes legally required notices to Individuals, HHS, or the media unless the parties agree otherwise in writing.
7.Regulators and Mitigation
Leap shall make its internal practices, books, and records relating to PHI received from, or created or received on behalf of, Customer available to the Secretary of HHS for purposes of determining HIPAA compliance. Leap shall mitigate, to the extent practicable, harmful effects known to Leap arising from a use or disclosure by Leap or its Subcontractors in violation of this BAA.
8.Individual Rights
To the extent Leap maintains PHI in a Designated Record Set, Leap shall make it available to Customer as reasonably necessary for Customer to satisfy 45 C.F.R. § 164.524 and, unless a shorter period is recorded, respond within ten business days. On Customer’s written direction, Leap shall support amendment under 45 C.F.R. § 164.526 to the extent technically within Leap’s control.
Leap shall document disclosures and provide information reasonably necessary for an accounting under 45 C.F.R. § 164.528. Direct requests from an Individual will be forwarded to Customer, and Leap will not make the substantive determination unless Required by Law or directed by Customer. When Leap performs a delegated Privacy Rule duty, it shall comply with the requirements applicable to Customer in performing that duty.
Routine assistance is included. Leap may charge reasonable, pre-agreed fees for materially extraordinary assistance, including non-standard bulk exports, repeated questionnaires, litigation support, or regulatory-investigation support beyond Leap’s own duties.
9.Customer Obligations
- Customer shall provide lawful instructions and represents that it has authority and required permissions to provide PHI to Leap.
- Customer shall notify Leap of relevant limitations in its privacy notice, authorization changes, revocations, and agreed restrictions.
- Customer shall manage users, roles, recipients, devices, and credentials and promptly remove unnecessary access.
- Customer is responsible for required recording, messaging, telemarketing, emergency, and professional-practice notices and consents.
- Customer’s Activation Record selections are its instructions and minimum-necessary determination for recordings, retention, notifications, recipients, integrations, and intake fields.
Customer shall not submit records subject to 42 C.F.R. Part 2, psychotherapy notes, or another specially restricted category (“Excluded Data”) unless a written amendment expressly authorizes the category and required controls are active. If Leap becomes aware of prohibited Excluded Data, Leap shall continue to safeguard it, notify Customer, and follow lawful deletion or handling instructions.
10.Liability and Risk Allocation
This BAA is subject to the liability exclusions and limitations in the Underlying Agreement. All amounts arising from this BAA count toward the same aggregate liability cap; nothing here increases that cap. To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages or lost profits, revenue, or goodwill arising from this BAA.
If a Breach of Unsecured PHI is caused by Leap’s violation of this BAA, Leap shall reimburse Customer’s reasonable, documented, out-of-pocket costs of notices legally required by the Breach Notification Rule, subject to the liability cap. Leap is not responsible for optional credit monitoring or costs caused by Customer’s unlawful data or instructions, configuration choices, users or recipients, credential compromise not caused by Leap, missing notices or consents, onward disclosures, or continued use after Leap recommends a security-relevant change that Customer declines.
Leap’s obligations concern its own role as a business associate. Leap does not provide legal advice or warrant that Customer’s policies, configurations, or overall compliance program satisfy HIPAA or other law. Leap shall maintain commercially reasonable insurance, including cyber-liability coverage, appropriate to its role.
11.Term, Termination, and Suspension
This BAA begins on the effective date in the Activation Record and continues until the later of termination of the Underlying Agreement or completion of surviving duties. A party that knows of the other’s material breach shall give written notice and thirty days to cure, unless immediate action is required by law or serious security risk.
Leap may suspend PHI processing and place affected Services into a safe non-PHI mode if this BAA is not effective or terminates, Customer materially breaches it, or a required downstream agreement or safeguard lapses. Leap shall give notice as promptly as reasonably practicable and restore the service when a compliant path is available.
Upon termination, Leap shall return or destroy Customer PHI at Customer’s written election and to the extent feasible within thirty days. Encrypted backups may be destroyed on Leap’s standard purge cycle and remain protected until purged. If return or destruction is infeasible, Leap shall explain why, continue protecting retained PHI, and limit use and disclosure to the purpose requiring retention.
12.General
The parties shall reasonably amend this BAA as necessary for changes to applicable law. Ambiguities shall be resolved to permit HIPAA compliance. This BAA controls over conflicting Underlying Agreement terms concerning PHI; otherwise the Underlying Agreement governs, including governing law, disputes, warranties, indemnity, and liability.
This BAA creates no third-party beneficiary, agency, partnership, or fiduciary relationship. It may be assigned only with a permitted assignment of the Underlying Agreement, and an assignee continuing HIPAA Services must assume the applicable duties in writing. Electronic acceptance and signatures are valid counterparts.
Formal notices use the notice method in the Underlying Agreement and the privacy and security contacts in the Activation Record. This BAA and that record are the entire agreement concerning PHI and supersede marketing statements, questionnaires, and product-interface claims. Amendments and waivers must be in a writing accepted by authorized representatives of both parties.
13.Activation Record
The electronic Activation Record is part of this BAA and must include the following before production PHI processing begins:
- Customer legal entity and covered-entity or business-associate role;
- authorized representative, acceptance timestamp, and BAA version;
- covered practices, locations, lines, services, and expected PHI;
- recording choice and notice, transcript and recording retention;
- secure playback, notification mode, recipients, and contacts;
- de-identification authorization and any additional restrictions;
- technical validation of approved providers, routing, access, logging, retention, and absence of unapproved fallback; and
- Leap activation confirmation and timestamp.
Customer’s selections are its instructions and minimum-necessary determination. Leap will not activate HIPAA Services until the acceptance and configuration record is complete and technical validation succeeds.
Questions or formal requests concerning this BAA may be sent to Engineering@GetLeapAI.com. Customers should have healthcare counsel review this standard form and their Activation Record before accepting it.