RONUS

Effective August 16, 2026

Business Associate Agreement (BAA)

This Business Associate Agreement ("BAA") forms part of the agreement between RUFUS TECH LLC ("RONUS", the Business Associate) and the Client acting as Covered Entity under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). It complies with 45 CFR §164.504(e). It applies to U.S. clients in sectors that handle Protected Health Information (PHI): dental clinics, aesthetic centers with medical staff, and other healthcare providers. Without a signed BAA, RONUS will not process PHI on behalf of the Client.

1. Definitions

Capitalized terms not defined here have the meaning given to them in the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule (45 CFR Parts 160 and 164). For purposes of this BAA:

  • "PHI" (Protected Health Information): individually identifiable health information, as defined in 45 CFR §160.103, created, received, maintained, or transmitted by RONUS on behalf of the Client.
  • "ePHI" (Electronic PHI): PHI transmitted or maintained in electronic form.
  • "Covered Entity": the Client, when it is a healthcare provider subject to HIPAA.
  • "Business Associate": RONUS, when processing PHI on behalf of the Client.
  • "Security Incident": the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
  • "Breach": the unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy, as defined in 45 CFR §164.402.
  • "Subcontractor": any person or entity to whom RONUS delegates, in whole or in part, a function involving the processing of PHI.

2. Permitted Uses and Disclosures of PHI

RONUS will use or disclose PHI only:

  • To provide the Services to the Client, in accordance with the service agreement.
  • For RONUS's own proper management and administration, or to carry out RONUS's legal responsibilities, provided that the disclosure is required by law, or RONUS obtains reasonable assurances from the recipient that the information will be held confidential and used or disclosed only as required by law or for the purpose for which it was disclosed, and that the recipient will notify RONUS of any instances of which it becomes aware in which the confidentiality has been breached.
  • To provide Data Aggregation Services relating to the healthcare operations of the Client, to the extent the Client has requested.
  • As required by law.

3. Obligations of the Business Associate

RONUS agrees to:

  • Not use or disclose PHI other than as permitted or required by this BAA or by law.
  • Implement and maintain reasonable and appropriate administrative, physical, and technical safeguards that protect the confidentiality, integrity, and availability of ePHI that RONUS creates, receives, maintains, or transmits on behalf of the Client, in accordance with the Security Rule (45 CFR §§164.308, 164.310, 164.312, and 164.316).
  • Report to the Client any use or disclosure of PHI not provided for by this BAA of which RONUS becomes aware, including Breaches of unsecured PHI under 45 CFR §164.410.
  • Report to the Client any Security Incident of which RONUS becomes aware.
  • Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of RONUS agrees in writing to the same restrictions, conditions, and requirements that apply to RONUS under this BAA, by means of an equivalent BAA.
  • Make PHI available to the Client to enable the Client to comply with an individual's right of access under 45 CFR §164.524.
  • Make PHI available to the Client for amendment under 45 CFR §164.526, and incorporate amendments as instructed by the Client.
  • Maintain and make available to the Client the information required for the Client to provide an accounting of disclosures under 45 CFR §164.528.
  • Comply with the applicable requirements of the Privacy Rule to the extent RONUS carries out an obligation of the Client.
  • Make available to the Client and to the Secretary of Health and Human Services ("HHS") its internal practices, books, and records relating to the use and disclosure of PHI for purposes of determining the Client's compliance with the Privacy Rule.

4. Breach and Incident notification

RONUS will notify the Client of any Breach of unsecured PHI without unreasonable delay and in any event within 30 calendar days of discovery, in accordance with 45 CFR §164.410. RONUS will endeavor to notify within 72 hours of discovery where reasonably practicable.

The notification will include, to the extent available: identification of each individual whose PHI has been, or is reasonably believed to have been, the subject of the Breach; description of what happened, dates, type of PHI involved, steps taken, and recommended actions.

Minor Security Incidents (unsuccessful access attempts, pings, routine scans, and the like) are reported in periodic aggregate form.

5. Subcontractors

RONUS will enter into equivalent BAAs with any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of RONUS, in accordance with 45 CFR §164.502(e)(1)(ii) and §164.308(b)(2).

The complete, current list of Subcontractors is published at ronus.tech/subprocessors. Of those, the ones that may handle PHI depending on the contracted configuration are: Supabase (database and files), OpenAI (language models), Twilio (WhatsApp and SMS), Stripe (payments), Vercel and Cloudflare (hosting and access) and Hetzner (the virtual private server, Germany). VAPI will be added once the voice channel is activated; it is announced on the public list and does not process data yet. RONUS maintains a written agreement with each of them imposing, at a minimum, the same obligations this BAA imposes on RONUS.

6. Term and termination

This BAA takes effect on the date of signature by the parties and remains in force while RONUS provides the Service to the Client.

The Client may terminate this BAA and the service agreement if it determines, in its reasonable judgment, that RONUS has materially breached this BAA and has failed to cure the breach within a reasonable period, no less than 30 days, from written notice.

If termination of this BAA is not reasonably possible, the Client may report the breach to the Secretary of HHS.

7. Return or destruction of PHI upon termination

Upon termination of this BAA, RONUS will return to the Client or destroy all PHI received from the Client, or created, maintained, or received by RONUS on behalf of the Client, that RONUS still maintains in any form. RONUS will retain no copies of the PHI.

If returning or destroying the PHI is not reasonably possible, RONUS will extend the protections of this BAA to that PHI and limit further uses and disclosures of that PHI to the purposes that make its return or destruction infeasible, for so long as RONUS maintains it.

8. Miscellaneous

Any ambiguity in this BAA will be resolved in favor of an interpretation that permits the Client to comply with HIPAA.

References in this BAA to a section of the HIPAA regulations shall be deemed to refer to the section as in effect or as amended from time to time.

The parties agree to take such actions as are necessary to amend this BAA from time to time as is necessary to maintain compliance with HIPAA, HITECH, and implementing regulations.

If any provision is held invalid, the rest will remain in full force. Provisions that by their nature should survive termination (Breach notification, return/destruction, survival of obligations over PHI not returned) shall survive.

9. Governing law, language, and interpretation

This BAA is governed by applicable U.S. federal laws (HIPAA, HITECH, and implementing regulations). For matters not covered by federal law, the laws of the State of South Carolina apply.

This BAA is published in Spanish and English. In the event of discrepancy between versions, the English version shall prevail, as HIPAA is U.S. federal law in English and the U.S. is the primary jurisdiction of the BAA.

Any question about this BAA may be directed to privacy@ronus.tech.