BAA

Business Associate Agreement

Our HIPAA agreement covering how we handle Protected Health Information as a Business Associate of your practice.

Last UpdatedMay 14, 2026
Effective DateMay 14, 2026

Business Associate

Kaila AI

support@hellokaila.com

Covered Entity

Customer

The subscribing dental practice

This Business Associate Agreement ("BAA") is entered into between Kaila ("Business Associate") and the Customer ("Covered Entity") in accordance with HIPAA and HITECH. This BAA governs the handling of Protected Health Information by Kaila on behalf of the Customer.

1.Definitions

"Protected Health Information" (PHI) has the meaning set forth in 45 C.F.R. § 160.103, limited to information Kaila creates, receives, maintains, or transmits on behalf of the Covered Entity.

"Business Associate Services" means the AI-powered dental documentation, transcription, note generation, and related services provided by Kaila under the Master Subscription Agreement.

"Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system containing PHI.

2.Permitted Uses and Disclosures

Kaila may use and disclose PHI only as permitted or required by this BAA or as required by law. Specifically, Kaila may:

  • Use and disclose PHI as necessary to perform the Business Associate Services
  • Use PHI for the proper management and administration of Kaila's business
  • Use PHI to report violations of law to appropriate authorities
  • De-identify PHI in accordance with 45 C.F.R. § 164.514(b) for service improvement purposes

3.Prohibited Uses and Disclosures

Kaila will not:

  • Use or disclose PHI for any purpose not permitted by this BAA or applicable law
  • Use PHI for marketing or commercial purposes without authorization
  • Sell PHI without written authorization from the Covered Entity
  • Use PHI to train AI models without complete de-identification

4.Safeguards

Kaila will implement and maintain appropriate administrative, physical, and technical safeguards to protect PHI, including:

  • AES-256 encryption at rest via AWS KMS with automatic key rotation every 365 days
  • SSL/TLS encryption in transit on all connections
  • Hardware Security Modules (HSMs) for master key protection
  • Multi-factor authentication and role-based access controls
  • MITE NLP de-identification processing before any secondary use
  • Dedicated GPU transcription servers that do not persist session data
  • Full audit logging of all PHI access, modification, and deletion events

5.Subcontractors

Kaila will ensure that any subcontractors who create, receive, maintain, or transmit PHI on Kaila's behalf agree to restrictions and conditions at least as stringent as those in this BAA. Kaila maintains Business Associate Agreements with all covered subcontractors, including AWS and Google Cloud for infrastructure services.

6.Breach Notification

Kaila will notify the Covered Entity of a Breach of Unsecured PHI:

  • Initial notification within one (1) business day of confirming a breach, with the nature, scope, and containment steps
  • Full breach assessment completed within 10 calendar days
  • Formal HIPAA breach notification within 60 calendar days if the breach qualifies
  • Post-incident report archived for six (6) years

7.Individual Rights

To the extent Kaila maintains PHI in a Designated Record Set, Kaila will cooperate with the Covered Entity to:

  • Provide individuals with access to their PHI upon request
  • Amend PHI upon direction of the Covered Entity
  • Provide an accounting of disclosures as required by HIPAA
  • Restrict uses and disclosures as directed by the Covered Entity

8.Data Retention and Destruction

Active PHI records are retained for a minimum of 90 days. Upon termination of the Agreement, all PHI will be securely destroyed within 30 days using the following methods:

  • DynamoDB records removed via confirmed delete operations with deletion logs
  • Local and client-side caches wiped with multi-pass overwrite
  • Encryption keys for anonymized data revoked to render residual ciphertext undecryptable
  • All destruction actions timestamped in an append-only audit log

Written certification of destruction is available upon request.

9.Audit Rights

Kaila will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA, as required by 45 C.F.R. § 164.504(e)(2)(ii)(I).

10.Term and Termination

This BAA is effective upon Customer's execution of the Master Subscription Agreement and remains in effect until the Agreement terminates or expires. Either party may terminate this BAA if the other materially breaches its obligations and fails to cure within 30 days of written notice.

In the event of a breach by Kaila that cannot be cured, Covered Entity may immediately terminate the Agreement and this BAA.

11.Survival

The obligations of confidentiality and data protection in this BAA survive termination of the Agreement for as long as Kaila retains PHI and until all PHI is destroyed or returned in accordance with Section 8.

12.Contact

For HIPAA and BAA-related inquiries, contact support@hellokaila.com with subject line: BAA Inquiry.

Official Documentation Notice

The signed version of this agreement executed upon joining Kaila Voice is your official, legally binding document. The online version above is provided for reference and convenience only. In the event of any conflict or discrepancy between the online version and your signed agreement, the signed agreement controls.

Any updates, amendments, or modifications to your agreement will be provided in writing and must be signed or acknowledged by both parties to be effective. Unilateral changes published to this page do not modify your signed agreement.

Questions about your specific agreement? support@hellokaila.com