Business Associate Agreement
Effective date: October 6, 2026 · Service: CIAG Quantum LENS
Status: this Business Associate Agreement ("BAA") is published and available to accept, but CIAG does not yet have Modified Retention active on its underlying OpenAI account (see Section 2.2). Until CIAG confirms that condition is met, the Eligible Service described in Section 2 is not yet available, and no Protected Health Information should be submitted through the Service. CIAG will update this notice when that condition is satisfied. This document has not been reviewed by a licensed attorney.
This Business Associate Agreement is entered into by CIAG Global, LLC, a Minnesota limited liability company ("Company," "we," "us"), and the customer accepting this BAA in connection with its use of the CIAG Quantum LENS document-extraction service ("Customer," "you"). This BAA supplements, and is incorporated into, our Terms of Service (the "Terms"); together they form the agreement between Company and Customer regarding Protected Health Information. Capitalized terms used but not defined here have the meaning given in the Terms or under HIPAA.
1. Background
- Company provides Customer access to the Service, through which Customer may submit documents that create, receive, transmit, or contain Protected Health Information ("PHI," as defined under HIPAA, limited to information Company receives from Customer). For purposes of this BAA, Customer is either a Covered Entity or a Business Associate of its own upstream customers or patients, and Company is a Business Associate of Customer.
- Company performs the extraction itself using a third-party AI subcontractor (currently, OpenAI) under a separate Business Associate Agreement between Company and that subcontractor covering the specific API services Company uses to provide the Service (see Section 4).
2. Eligible Service and Scope
- Eligible Service. PHI may be submitted to Company only through the document-extraction functionality of the Service (currently, the
/api/lens/extract endpoint and its browser interface at /lens), and only once Company has confirmed the condition in Section 2.2 is satisfied. No other Company service, feature, or communication channel (including support email, sales calls, or any beta or preview feature) is covered by this BAA, and Customer agrees not to transmit PHI to Company through any channel other than the Eligible Service.
- Condition precedent. Company's ability to lawfully process PHI depends on Company's own underlying agreement with its AI subcontractor, including that subcontractor's Modified Retention (or equivalent reduced-retention) feature being active on the account the Service uses. This BAA is effective on acceptance for purposes of establishing the parties' rights and obligations, but Customer agrees not to submit PHI until Company has posted notice on this page, or otherwise notified Customer directly, that this condition is met.
- Minimum necessary. The parties acknowledge that all PHI transmitted to Company through the Eligible Service is the minimum necessary for Company to perform the extraction Customer has requested.
3. Permitted Uses and Disclosures
- Company may use and disclose PHI only (i) to perform the Service as directed by Customer, (ii) as permitted or required by this BAA, (iii) as Required by Law, and (iv) for Company's proper management and administration, provided any further disclosure is either Required by Law or made under reasonable assurances of confidentiality consistent with this BAA. Company will not use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Customer, except as this BAA permits.
- Company is not intended to, and does not, carry out any of Customer's own obligations under the HIPAA Privacy Rule.
4. Subcontractors
Company's AI processing subcontractor for the Eligible Service is OpenAI. Company has entered into its own Business Associate Agreement with OpenAI covering the API services the Eligible Service relies on, requiring OpenAI to protect PHI under restrictions and conditions at least as stringent as those in this BAA. Company will not add or change a subcontractor that creates, receives, maintains, or transmits PHI on Company's behalf without ensuring that subcontractor agrees to the same restrictions that apply to Company here. If Company learns of a pattern of activity that constitutes a material breach of a subcontractor's obligations with respect to PHI, Company will take reasonable steps to cure the breach, end the violation, or terminate the relationship.
5. Safeguards and Reporting
- Safeguards. Company uses appropriate administrative, technical, and physical safeguards to prevent use or disclosure of PHI other than as this BAA provides. By design, the Service does not write uploaded documents to disk and does not store documents or extraction results in Company's database — each document is processed in memory and discarded once the result is returned. Company treats this as a safeguard, not a substitute for the other protections in this BAA.
- Reporting. Company will report to Customer, promptly after discovery: (i) any use or disclosure of PHI not permitted by this BAA; (ii) any Breach of Unsecured PHI as defined by HIPAA; and (iii) any Security Incident of which Company becomes aware. Company will reasonably cooperate with Customer in responding to such an event and will supplement an initial report with additional information as it becomes available. The parties agree notice is deemed given for Unsuccessful Security Incidents (routine, non-compromising events such as pings or failed login attempts) without a separate report for each occurrence.
- Mitigation. Company will take reasonable steps to mitigate, to the extent practicable, any harmful effects known to Company from a use or disclosure of PHI in violation of this BAA.
6. Access, Amendment, and Accounting of Disclosures
Company does not maintain PHI as a designated record set on Customer's behalf — by design, Company does not retain documents or extraction results after a request completes. If Company receives a request for access or amendment of PHI under 45 C.F.R. § 164.524 or § 164.526, Company's sole obligation is to promptly forward the request to Customer. If Company discloses PHI in a manner required to be included in an accounting under 45 C.F.R. § 164.528, Company will maintain and, within ten (10) business days of Customer's request, provide the information Customer would need to respond to an individual's accounting request.
7. Availability of Books and Records
Company will make its relevant HIPAA policies, books, and records available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
8. Customer's Responsibilities
- Customer represents and warrants that it has obtained, and will maintain, all permissions, authorizations, and consents necessary for Company to receive, process, and return PHI as this BAA contemplates, and will notify Company of any change in or revocation of such permission that affects Company's use or disclosure of PHI.
- Customer will ensure that no limitation in its own notice of privacy practices, and no restriction it has agreed to under 45 C.F.R. § 164.522, affects Company's use or disclosure of PHI under this BAA.
- Customer will not ask Company to use or disclose PHI in a manner that would not be permissible under the HIPAA Privacy Rule if done by Customer directly.
- Customer is solely responsible for the accuracy and completeness of documents it submits, for verifying extraction output before relying on it for any clinical, billing, or other purpose, and for ensuring that only personnel qualified and authorized to handle PHI submit documents through the Service or rely on its output.
- If Customer discloses output from the Service to its own patients, customers, or other downstream parties, Customer will have its own written agreement with that party covering their use of the output, consistent with applicable law, and will disclose to them any limitations associated with AI-generated extraction output.
- Customer will train its own personnel who use the Service on their obligations with respect to PHI, and will take reasonable steps to mitigate any harmful effects known to Customer from its own breach of this BAA.
9. Healthcare-Specific Disclaimers
The service and its output are not a substitute for the judgment of a properly trained and licensed professional. extraction results are generated automatically and may contain errors, omissions, or misinterpretations, including on multi-page, handwritten, or poorly scanned documents. company is not responsible for any diagnosis, course of treatment, billing, coding, or claims decision made in reliance on service output, and the service is not intended to function as a medical device.
10. Term and Termination
- Term. This BAA begins on the date Customer accepts it and continues until terminated as set out here, or until the Terms terminate, whichever occurs first.
- Termination for breach. Either party may terminate this BAA, and the underlying Terms, if the other party has materially breached this BAA and fails to cure that breach within thirty (30) days of written notice.
- Effect of termination. On termination or expiration, Customer will stop transmitting PHI to Company. Because the Service does not retain documents or extraction results beyond the time needed to process and return a single request, there is no PHI retained by Company to return or destroy as of the date of this BAA; if that changes, Company will update this section accordingly.
11. Limitation of Liability
Except for a breach of Section 2 (Eligible Service and Scope) or Section 9 (Healthcare-Specific Disclaimers), this BAA is subject to the limitation of liability set out in the Terms.
12. General
This BAA is incorporated into, and governed by the same governing-law and dispute-resolution provisions as, the Terms. In the event of a conflict between this BAA and the Terms regarding the handling of PHI, this BAA controls. Company may update this BAA by posting a revised version on this page and updating the effective date; if an update materially affects Customer's rights or obligations, Company will provide at least thirty (30) days' notice before it takes effect, except where a shorter period is necessary to comply with applicable law.
13. Contact
CIAG Global, LLC, a Minnesota limited liability company
Contact: will@ciag-global.com
Address: 330 S Second Ave, Suite 200 1900, Minneapolis, MN 55401