Business Associate Agreement
Last updated: June 17, 2026
Effective date: June 17, 2026
This Business Associate Agreement (“BAA” or “Agreement”) is entered into between CREBRAL AI, LLC, a Florida limited liability company operating under the trade name Crebral Health (“Business Associate”), and the practitioner, clinic, or organization that accepts this BAA (“Covered Entity”). It governs Business Associate’s handling of Protected Health Information (“PHI”) and is incorporated by reference into, and forms part of, the Crebral Health Terms of Service. This BAA is required by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively, “HIPAA”).
A FULLY EXECUTED BAA IS REQUIRED BEFORE ANY PROTECTED HEALTH INFORMATION IS UPLOADED TO OR PROCESSED THROUGH THE PLATFORM. UPLOADING PHI WITHOUT AN EXECUTED BAA IN PLACE IS A MATERIAL BREACH OF THE TERMS OF SERVICE AND IS STRICTLY PROHIBITED.
Where the Covered Entity is not a HIPAA-covered entity (and therefore HIPAA does not apply), this BAA does not take effect; patient data is instead governed by the Terms of Service and Privacy Policy.
1. Background and Purpose
Covered Entity is a HIPAA Covered Entity or a Business Associate of a Covered Entity that has engaged Crebral Health to provide software-as-a-service tools for biomarker analysis, biological-age clock interpretation, AI-generated longevity program drafting, and clinic workflow management (the “Services”). In performing the Services, Crebral Health may create, receive, maintain, or transmit PHI on behalf of Covered Entity and therefore acts as a “Business Associate” as that term is defined under HIPAA. The parties enter into this Agreement to satisfy the requirements of 45 C.F.R. §§ 164.502(e) and 164.504(e) and to permit Covered Entity to comply with its obligations under HIPAA.
2. Definitions
Capitalized terms used but not defined in this Agreement have the meanings given to them under HIPAA, including the Privacy Rule, the Security Rule, the Breach Notification Rule, and the HITECH Act. For convenience:
- “HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164.
- “Protected Health Information” (“PHI”) has the meaning at 45 C.F.R. § 160.103, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity. “Electronic PHI” (“ePHI”) means PHI in electronic form.
- “Breach,” “Security Incident,” “Required By Law,” “Subcontractor,” “Use,” and “Disclosure” have the meanings given under the HIPAA Rules.
- “Covered Entity” and “Business Associate” have the meanings at 45 C.F.R. § 160.103 and refer to the parties to this Agreement, respectively.
3. Permitted Uses and Disclosures by Business Associate
Except as otherwise limited by this Agreement, Business Associate may Use and Disclose PHI only as follows:
- to perform the Services and to carry out Covered Entity’s obligations, as permitted or required by this Agreement, the Terms of Service, or as Required By Law;
- for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any Disclosure for such purposes is either Required By Law or made under written assurances of confidentiality and a duty to report any breach of confidentiality, consistent with 45 C.F.R. § 164.504(e)(4);
- to provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B); and
- to de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c) (Safe Harbor or Expert Determination), where and to the extent permitted by Covered Entity in writing; de-identified data is not PHI and is not subject to this Agreement.
BUSINESS ASSOCIATE WILL NOT USE OR DISCLOSE PHI IN ANY MANNER THAT WOULD VIOLATE HIPAA IF DONE BY COVERED ENTITY, EXCEPT AS PERMITTED UNDER 45 C.F.R. § 164.504(e)(4) FOR BUSINESS ASSOCIATE’S OWN MANAGEMENT AND ADMINISTRATION AS DESCRIBED ABOVE.
Business Associate will not Use or Disclose PHI for marketing, sale of PHI, or to train, fine-tune, or improve any artificial intelligence or machine-learning model, except with the separate written authorization of Covered Entity and any required individual authorization, and only using data de-identified in accordance with 45 C.F.R. § 164.514. Business Associate will limit its Uses, Disclosures of, and requests for PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b).
4. Obligations of Business Associate
Business Associate agrees to:
- Limit use and disclosure: not Use or Disclose PHI other than as permitted or required by this Agreement or as Required By Law;
- Safeguards: use appropriate administrative, physical, and technical safeguards, and comply with the Security Rule (45 C.F.R. Part 164, Subpart C) with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided by this Agreement, including encryption of ePHI in transit and at rest and role-based access controls;
- Report unauthorized use or disclosure: report to Covered Entity any Use or Disclosure of PHI not permitted by this Agreement of which it becomes aware, and any Security Incident, without unreasonable delay;
- Breach notification: notify Covered Entity of any Breach of Unsecured PHI in accordance with 45 C.F.R. § 164.410, without unreasonable delay and no later than five (5) business days after Discovery, including, to the extent then known, the identification of each individual affected and the information required for Covered Entity to meet its own breach-notification obligations;
- Subcontractors (flow-down): in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement;
- Access (§ 164.524): make PHI in a Designated Record Set available to Covered Entity (or, as directed, to the individual) as necessary for Covered Entity to respond to an individual’s request for access;
- Amendment (§ 164.526): make PHI in a Designated Record Set available for amendment and incorporate any amendments as directed by Covered Entity;
- Accounting of disclosures (§ 164.528): document and make available the information required for Covered Entity to provide an accounting of disclosures of PHI;
- Availability to HHS: make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the U.S. Department of Health and Human Services (“HHS”) for purposes of determining Covered Entity’s compliance with HIPAA;
- Covered Entity obligations: to the extent Business Associate is to carry out any of Covered Entity’s obligations under the Privacy Rule, comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of those obligations; and
- Mitigation: mitigate, to the extent practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI in violation of this Agreement.
5. Obligations of Covered Entity
Covered Entity agrees to:
- obtain any consents, authorizations, or permissions, and provide any notices (including its Notice of Privacy Practices), that may be required for Business Associate to Use and Disclose PHI to perform the Services, and represent that it has the authority to provide the PHI it submits to the Platform;
- notify Business Associate of any limitation in its Notice of Privacy Practices, of any changes in, or revocation of, an individual’s permission to Use or Disclose PHI, and of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent any of these may affect Business Associate’s Use or Disclosure of PHI;
- not request or direct Business Associate to Use or Disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except as expressly permitted under Section 3 (Business Associate’s management and administration, data aggregation, or de-identification); and
- configure and use the Platform in accordance with the documentation, including by not transmitting PHI through channels not designated for PHI and by managing user access within its organization.
6. Security of Electronic PHI
With respect to ePHI that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity, Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI, as required by the Security Rule (45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316). Business Associate maintains a written information-security program, encrypts ePHI in transit and at rest, enforces access controls and audit logging, and conducts periodic risk assessments. A current description of Business Associate’s subprocessors is available at crebral.ai/subprocessors.
7. Term and Termination
- Term: This Agreement is effective on the date Covered Entity accepts it (or as of the date PHI is first provided to Business Associate, whichever is earlier) and remains in effect until all PHI is returned or destroyed or, if return or destruction is infeasible, until the protections of this Agreement are extended to such PHI as described below.
- Termination for cause: If Business Associate materially breaches this Agreement, Covered Entity may provide an opportunity to cure within thirty (30) days, and may terminate the Agreement and the Services if Business Associate does not cure the breach within that period. Either party may terminate as provided in the Terms of Service.
- Effect of termination: Upon termination, Business Associate will, if feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity that Business Associate maintains, and retain no copies. Covered Entity may export its data through the Platform prior to termination. Where return or destruction is infeasible, Business Associate will extend the protections of this Agreement to such PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible, for so long as Business Associate retains the PHI.
8. Miscellaneous
- Regulatory references: A reference to a section of the HIPAA Rules means the section as in effect or as amended, and for which compliance is required.
- Amendment: The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPAA Rules. Business Associate may update this Agreement to maintain compliance with applicable law on notice to Covered Entity.
- Interpretation: Any ambiguity in this Agreement will be resolved to permit the parties to comply with the HIPAA Rules. In the event of a conflict between this Agreement and the Terms of Service with respect to the subject matter of PHI, this Agreement controls.
- No third-party beneficiaries: Nothing in this Agreement confers any rights on any person other than the parties, except as expressly provided under HIPAA.
- Survival: Section 7 (Effect of termination), Section 4 (to the extent applicable to retained PHI), and the indemnification and limitation-of-liability provisions of the Terms of Service survive termination.
- Governing law: This Agreement is governed by the laws of the State of Florida and, where applicable, the federal HIPAA Rules, without regard to conflict-of-law principles.
9. How This BAA Is Executed
This BAA is offered to Covered Entity as part of account onboarding and is incorporated by reference into the Terms of Service. Covered Entity may execute this BAA by (a) accepting it electronically (clickwrap) during onboarding, or (b) requesting a countersigned copy from Business Associate. A countersigned copy is available on request to the contact below. PHI must not be uploaded to or processed through the Platform until this BAA has been executed and is in effect.
10. Contact
To request an executed copy of this BAA, to report a Breach or Security Incident, or for any questions regarding this Agreement, contact:
Email: team@Crebral.ai
Mailing Address: CREBRAL AI, LLC, 1925 Trade Center Way, Suite 2, Naples, FL 34109