ddsally

HIPAA BAA

Business Associate Agreement

About this document. This Business Associate Agreement governs how DDSALLY LLC creates, receives, maintains, or transmits Protected Health Information on behalf of your dental practice. By creating a DDSALLY account and checking the BAA acceptance box at signup, you electronically accept this BAA on behalf of your Practice; no separate signature is required. The Date of Acceptance and Version Accepted are recorded automatically in DDSALLY’s audit log.

DDSALLY LLC Business Associate Agreement

Version 1.2 · Updated June 14 2026

For Dental Practices, Dental Providers, Specialists, and Authorized Dental Office Users

Effective Date: The date on which the Practice or an authorized representative clicks “I Agree,” checks the acceptance box, creates an account, activates DDSALLY services, or otherwise electronically accepts this BAA.

Business Associate. DDSALLY LLC (“DDSALLY,” “we,” “us,” or “Business Associate”).

Covered Entity / Practice. The dental practice, dental provider, specialist, dental office, or HIPAA-covered dental entity that creates an account, subscribes to, accesses, or uses the DDSALLY platform.

Primary Agreement. This BAA is incorporated into DDSALLY’s Terms of Service, subscription agreement, order form, online account registration, or other agreement governing the use of DDSALLY services.

1. Electronic Acceptance

By checking the box stating that you agree to this BAA, clicking “I Agree,” creating a DDSALLY account, activating DDSALLY services, or using DDSALLY to send, receive, store, or manage Protected Health Information (“PHI”), you represent and agree that:

  • You are authorized to bind the Practice to this BAA.
  • The Practice is a Covered Entity or otherwise has HIPAA obligations with respect to PHI submitted through DDSALLY.
  • The Practice agrees to this BAA electronically.
  • The electronic acceptance of this BAA has the same legal effect as a handwritten signature.
  • The Practice will use DDSALLY only in accordance with HIPAA, this BAA, and DDSALLY’s Terms of Service. If you do not agree to this BAA, you must not use DDSALLY to create, receive, maintain, transmit, upload, send, or store PHI. DDSALLY may maintain electronic records showing the date, time, user, account, IP address, email address, version number, or other acceptance details associated with the Practice’s acceptance of this BAA.

2. Purpose of this BAA

DDSALLY provides a dental referral and communication platform that allows general dentists, dental specialists, dental offices, and authorized dental staff to securely communicate, coordinate referrals, exchange records, upload files, transmit images, send messages, and manage referral-related workflows. In providing these services, DDSALLY may create, receive, maintain, or transmit PHI on behalf of the Practice. This BAA governs how DDSALLY may use and disclose that PHI and how DDSALLY will protect it. This BAA is intended to satisfy the requirements of HIPAA, including the HIPAA Privacy Rule, Security Rule, Breach Notification Rule, and applicable HITECH requirements.

3. Definitions

Capitalized terms not defined in this BAA have the same meaning as under HIPAA.

  • “HIPAA” means the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations.
  • “PHI” means Protected Health Information, including electronic Protected Health Information, that DDSALLY creates, receives, maintains, or transmits on behalf of the Practice.
  • “Platform” or “Service” means the DDSALLY website, application, portal, software, referral system, secure messaging tools, file-storage functions, workflow tools, audit logs, support services, and related technology.
  • “Authorized Users” means dentists, specialists, employees, contractors, office managers, treatment coordinators, referral coordinators, dental assistants, hygienists, billing personnel, or other individuals authorized by the Practice to use DDSALLY.
  • “Patient-Submitted Data” means medical, dental, clinical, imaging, diagnostic, treatment, or other PHI submitted directly by a patient into DDSALLY.
  • “Subcontractor” means a third-party vendor or service provider that creates, receives, maintains, or transmits PHI on behalf of DDSALLY.

4. DDSALLY’s Role

DDSALLY acts as a Business Associate when it creates, receives, maintains, or transmits PHI on behalf of the Practice. DDSALLY is not a dental provider, treating provider, referral decision-maker, diagnostic service, payer, health plan, or healthcare clearinghouse. DDSALLY does not independently determine whether a patient should be referred, diagnosed, treated, contacted, accepted, scheduled, or managed. Those decisions remain the responsibility of the Practice and the participating dental providers.

5. Scope of DDSALLY Services

Covered Services; Excluded Services; HIPAA-Appropriate Configuration:

This BAA applies only to the DDSALLY Services, features, modules, support channels, integrations, and environments identified as covered for PHI in Exhibit A or otherwise expressly approved in writing by DDSALLY for HIPAA-appropriate use.

The Practice must not create, receive, maintain, transmit, upload, or store PHI through any DDSALLY feature, communication channel, beta feature, third-party integration, analytics tool, payment function, email support address, or other service that DDSALLY identifies as excluded, unsupported, or not approved for PHI.

DDSALLY may process, store, or transmit PHI using cloud, infrastructure, productivity, support, security, monitoring, or similar services only to the extent the applicable service is covered by an appropriate business associate agreement or other HIPAA-appropriate contractual arrangement and is configured for HIPAA-appropriate use.

DDSALLY’s services include, but are not limited to:

  • Sending and receiving dental referrals.
  • Communication between general dentists and specialists.
  • Communication between general dentists.
  • Communication between dental specialists.
  • Communication between dental offices and authorized staff.
  • Uploading, storing, viewing, and transmitting referral-related files.
  • Sending clinical records, radiographs, photographs, CBCT images, MRI images, treatment notes, medical histories, dental histories, referral forms, consultation requests, reports, and other dental information.
  • Referral tracking and workflow management.
  • Secure messaging and care coordination.
  • Audit logging and activity tracking.
  • Technical support and account administration.
  • Security monitoring, backup, maintenance, and platform improvement.
  • Sending PHI to patients when directed by the Practice or an authorized dental provider.

6. Important Platform Limitation: Patients Cannot Directly Submit Medical Data

DDSALLY is designed primarily for dentist-to-dentist communication, general dentist-to-specialist communication, specialist-to-general dentist communication, specialist-to-specialist communication, dental office-to-dental office communication, and dental provider-to-patient communication when initiated by the Practice or authorized provider. DDSALLY is not designed to receive medical, dental, diagnostic, clinical, imaging, or other PHI directly from patients. The Practice must not instruct patients to upload, submit, message, or send PHI directly into DDSALLY unless DDSALLY has expressly enabled that feature in writing and provided the appropriate privacy, security, and workflow controls. DDSALLY may allow a Practice or authorized provider to send PHI to a patient. However, unless separately enabled in writing, patients may not send medical or dental data back into DDSALLY. If DDSALLY inadvertently receives Patient-Submitted Data, DDSALLY may notify the Practice and handle the information in accordance with this BAA, HIPAA, and DDSALLY’s applicable privacy and security procedures.

7. Permitted Uses and Disclosures by DDSALLY

7.1 Proper Management and Administration; Legal Responsibilities

DDSALLY may use PHI for DDSALLY’s proper management and administration and to carry out DDSALLY’s legal responsibilities, in each case only as permitted by HIPAA and this BAA.

DDSALLY may disclose PHI for DDSALLY’s proper management and administration or legal responsibilities only if the disclosure is Required by Law or DDSALLY obtains reasonable written assurances from the recipient that the recipient will: (a) maintain the confidentiality of the PHI; (b) use or further disclose the PHI only as Required by Law or for the purpose for which it was disclosed to the recipient; and (c) notify DDSALLY of any breach, security incident, or unauthorized use or disclosure involving the PHI of which the recipient becomes aware.

7.2 Covered Entity Obligations Performed by DDSALLY

To the extent DDSALLY agrees in writing to carry out any obligation of the Practice under the HIPAA Privacy Rule, DDSALLY will comply with the HIPAA requirements applicable to that obligation.

7.3 General Permitted Use DDSALLY may use and disclose PHI only as permitted by this BAA, DDSALLY’s Terms of Service, the Practice’s instructions, and HIPAA. Permitted purposes include:

  • To provide, operate, maintain, secure, support, troubleshoot, and improve the Platform;
  • To transmit referrals, messages, files, images, forms, clinical records, and related PHI between authorized dental providers and dental offices;
  • To send PHI to a patient at the direction of the Practice or authorized provider;
  • To maintain referral records, communication logs, audit logs, activity logs, and administrative records;
  • To provide customer support and technical support;
  • To perform backup, disaster recovery, security monitoring, vulnerability management, and system maintenance;
  • To carry out DDSALLY’s legal responsibilities;
  • For DDSALLY’s proper management and administration, as permitted by HIPAA;
  • To provide data aggregation services related to the Practice’s healthcare operations, if permitted by HIPAA;
  • To de-identify PHI in accordance with HIPAA;
  • As Required by Law. DDSALLY will not use or disclose PHI in a way that would violate HIPAA if done by the Practice, except as permitted for DDSALLY’s proper management, administration, legal responsibilities, or data aggregation.

8. Prohibited Uses and Disclosures

DDSALLY will not:

  • Use or disclose PHI except as permitted by this BAA, the Terms of Service, the Practice’s instructions, or applicable law;
  • Sell PHI;
  • Use PHI for marketing without required authorization;
  • Use PHI for advertising, retargeting, or unrelated commercial profiling;
  • Use PHI to identify, target, or contact patients outside the scope of DDSALLY services;
  • Use PHI to train generalized artificial intelligence or machine learning models unless separately authorized in writing and permitted by HIPAA;
  • Disclose PHI to unauthorized third parties;
  • Permit patients to directly submit PHI into DDSALLY unless DDSALLY has expressly enabled that function in writing;
  • Send PHI to payment processors, analytics tools, advertising tools, or support tools unless those vendors are authorized for PHI and covered by appropriate HIPAA compliant agreements;
  • Use PHI in a manner inconsistent with HIPAA.

9. Practice Responsibilities

Shared Responsibility; Customer Configuration and Use:

The Parties acknowledge that HIPAA compliance depends on both DDSALLY’s safeguards and the Practice’s configuration and use of the Platform. The Practice is responsible for using available administrative, technical, and workflow controls in a HIPAA-appropriate manner.

Without limiting Section 9, the Practice is responsible for: (a) configuring user roles, permissions, administrative accounts, message settings, file-sharing settings, retention settings, integrations, and notification settings appropriately; (b) using multi-factor authentication or other enhanced authentication controls where offered and appropriate; (c) reviewing audit logs and account activity where available; (d) limiting PHI to the minimum necessary for the intended purpose; (e) confirming recipient identity and authorization before transmitting PHI; and (f) ensuring that Authorized Users are trained to use DDSALLY in compliance with HIPAA and the Practice’s policies.

Security features identified for launch include TOTP multi-factor authentication; role-based multi-role permissions with a last-admin guard; user suspension/deactivation; password change requiring re-authentication; masked DOB/phone entry; encryption at rest using AWS KMS; encryption in transit using TLS; append-only audit logs written in the same transaction as the audited action; a configurable file-retention window; and an optional paid Archival Retention add-on. Not available at launch: SSO and message-level expiration beyond the retention lifecycle.

The Practice is responsible for its own HIPAA compliance and for the actions of its Authorized Users. The Practice will:

  • Use DDSALLY only for lawful and HIPAA-permitted purposes;
  • Authorize only appropriate workforce members and dental personnel to access DDSALLY;
  • Maintain accurate user access and promptly deactivate users who no longer need access;
  • Submit only PHI reasonably necessary for referral, treatment, communication, payment, operations, or other permitted purposes;
  • Confirm that each recipient is authorized to receive the PHI being sent;
  • Obtain any required patient consents, authorizations, acknowledgments, or permissions;
  • Maintain its own Notice of Privacy Practices and HIPAA policies;
  • Determine what information belongs in the Practice’s Designated Record Set;
  • Maintain clinical records as required by federal and state law;
  • Notify DDSALLY of any restrictions, revocations, confidential communication requests, or limitations that may affect DDSALLY’s use or disclosure of PHI;
  • Not instruct patients to send PHI directly to DDSALLY unless DDSALLY has expressly enabled that function in writing;
  • Not upload unnecessary PHI, payment card information, passwords, or unrelated sensitive information into DDSALLY.

10. Provider-to-Provider Referral Communications

DDSALLY may be used to transmit PHI from one dental provider or dental office to another dental provider or dental office for treatment, referral, consultation, care coordination, or related healthcare operations. The sending Practice is responsible for determining that the disclosure is permitted. The receiving Practice or provider is responsible for determining how received referral information is incorporated into its own clinical records, treatment records, referral records, or Designated Record Set. DDSALLY serves as the technology platform that facilitates the communication. DDSALLY does not independently verify the clinical accuracy, completeness, appropriateness, or legal sufficiency of the referral information.

11. Provider-to-Patient Communications

DDSALLY may allow a Practice or authorized provider to send PHI to a patient. When the Practice uses DDSALLY to send PHI to a patient, the Practice is responsible for:

  • Confirming the patient’s identity;
  • Confirming the patient’s correct email address, phone number, portal access, or other contact information;
  • Determining whether the communication is permitted;
  • Obtaining any required consent or authorization;
  • Determining whether the communication method is appropriate;
  • Ensuring that the content is accurate and appropriate;
  • Maintaining any required record of the communication. DDSALLY is not responsible for errors caused by incorrect patient contact information, wrong recipient selection, inaccurate PHI uploaded by the Practice, or misuse of the Platform by the Practice or its Authorized Users.

12. Minimum Necessary

DDSALLY will make reasonable efforts to use, disclose, or request only the minimum PHI necessary to accomplish the intended purpose, except where HIPAA does not require the minimum necessary standard, such as certain treatment-related disclosures. The Practice is responsible for limiting the PHI it submits to DDSALLY to what is reasonably necessary for the intended purpose.

13. Safeguards and Security Controls

DDSALLY will implement reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI and electronic PHI. DDSALLY’s safeguards may include:

  • Written HIPAA privacy and security policies;
  • Workforce privacy and security training;
  • Role-based access controls;
  • Unique user identification;
  • Authentication controls;
  • Administrative access controls;
  • Encryption of PHI in transit;
  • Encryption of PHI at rest where supported and appropriate;
  • Audit logs and activity logs;
  • Security monitoring;
  • Vulnerability management and patch management;
  • Backup and disaster recovery procedures;
  • Access review and user deactivation procedures;
  • Subcontractor review and vendor management;
  • Incident response procedures;
  • Periodic risk analysis and risk management activities.
  • DDSALLY will use commercially reasonable efforts to mitigate, to the extent practicable, any harmful effect known to DDSALLY from a use or disclosure of PHI not permitted by this BAA.

14. Reporting Unauthorized Uses, Disclosures, Security Incidents, and Breaches

DDSALLY will report to the Practice any unauthorized use or disclosure of PHI of which DDSALLY becomes aware. DDSALLY will notify the Practice of a Breach of Unsecured PHI without unreasonable delay and no later than seventy-two (72) hours after discovery, unless a different timeframe is required by law or agreed in writing. DDSALLY’s notice may include, to the extent known:

  • A brief description of what happened.
  • The date of the incident and the date of discovery, if known.
  • The types of PHI involved.
  • The Individuals affected or reasonably believed to be affected, if known.
  • Steps DDSALLY has taken or plans to take to investigate and mitigate harm.
  • Steps DDSALLY has taken or plans to take to reduce the risk of recurrence.
  • Information reasonably needed by the Practice to meet its breach notification obligations.
  • DDSALLY will also report successful Security Incidents involving electronic PHI without unreasonable delay. The Parties acknowledge that unsuccessful security events, such as routine scans, pings, unsuccessful login attempts, malware probes, firewall blocks, or similar events, may occur regularly. These unsuccessful events may be reported in a periodic or general manner unless required otherwise by law.

15. Subcontractors and Cloud Service Providers

DDSALLY remains responsible for the performance of its PHI-touching Subcontractors to the extent required by HIPAA and this BAA. DDSALLY will maintain, or make available through its website, account portal, onboarding materials, or upon reasonable request, a list of Subcontractors that DDSALLY reasonably expects may create, receive, maintain, or transmit PHI on behalf of DDSALLY.

DDSALLY may update its Subcontractors from time to time. DDSALLY will provide notice of material changes to PHI-touching Subcontractors by a commercially reasonable method, which may include notice through the Platform, email, account portal, website, or other method permitted by the Terms of Service. PHI-touching subcontractor list can be found on this URL:

DDSALLY may use third-party vendors, cloud service providers, hosting providers, infrastructure providers, support vendors, software vendors, security vendors, or other subcontractors to provide the Platform. DDSALLY will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of DDSALLY agrees in writing to substantially the same restrictions, conditions, and safeguards that apply to DDSALLY with respect to PHI. DDSALLY may use services such as Amazon Web Services, Google Workspace, or similar providers only to the extent that DDSALLY has appropriate agreements in place when PHI is involved and only to the extent that the applicable services are configured for HIPAA-appropriate use. DDSALLY may maintain a list of PHI-touching Subcontractors and may provide that list through its website, account portal, onboarding materials, or upon reasonable request.

16. Patient Rights Support

To the extent DDSALLY maintains PHI in a Designated Record Set on behalf of the Practice, DDSALLY will reasonably assist the Practice with HIPAA-required patient rights requests. This may include support for access to PHI, amendment of PHI, accounting of disclosures, restrictions on certain uses or disclosures where supported by the Platform, and confidential communication requests where supported by the Platform. If a patient contacts DDSALLY directly to request access, amendment, deletion, restriction, accounting, or other rights relating to PHI, DDSALLY may direct the patient to the Practice unless DDSALLY is required by law to respond directly. The Practice remains responsible for verifying the patient’s identity, determining whether to grant or deny the request, and responding to the patient as required by law.

17. Access, Amendment, and Accounting

DDSALLY will make PHI available to the Practice as reasonably necessary for the Practice to meet its HIPAA access obligations. DDSALLY will make PHI available for amendment and will incorporate amendments as directed by the Practice, to the extent the amendment is technically feasible within the Platform and required by HIPAA. DDSALLY will document disclosures of PHI made by DDSALLY as necessary for the Practice to respond to a patient’s request for an accounting of disclosures and will provide such information upon reasonable written request. The Parties acknowledge that certain disclosures, including many disclosures for treatment, payment, and healthcare operations, may be excluded from accounting requirements to the extent permitted by HIPAA.

18. Access by the U.S. Department of Health and Human Services

DDSALLY may make available reasonable security, privacy, or implementation materials describing HIPAA-relevant configuration, access-control, support, integration, retention, and prohibited-use practices for the Platform. The Practice is responsible for reviewing and following those materials to the extent applicable to the Practice’s use of DDSALLY. Visit DDSALLY’s for more information.

DDSALLY will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by DDSALLY on behalf of, the Practice available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining HIPAA compliance.

  1. Referral Records, File-Payload Retention, Deletion, and Lifecycle

DDSALLY is intended to operate as a referral communication and transfer platform, and not as the Practice’s primary system of record. Each Practice remains responsible for maintaining its own clinical, referral, legal, and record-retention records for referrals it sends, receives, reviews, or accepts.

DDSALLY may retain referral-related PHI as necessary to support treatment, referral history, audit logs, disclosure records, legal compliance, security, backup, dispute resolution, service administration, and record-retention obligations. Referral communications may involve more than one dental provider, specialist, dental office, or Practice. Information transmitted by one Practice may become part of another provider’s clinical, referral, or Designated Record Set.

If PHI is transmitted to a receiving dental provider or dental office through DDSALLY, DDSALLY may retain that PHI on behalf of the receiving provider or Practice, even if the sending Practice later terminates its account, withdraws the referral, or requests deletion. DDSALLY is not required to delete PHI if deletion would impair another provider’s clinical record, referral record, legal-retention obligation, audit record, disclosure record, professional responsibility, or ability to document treatment-related communications.

DDSALLY may operate an automated retention, deletion, and lifecycle process under which file payloads may be purged after applicable lifecycle events, subject to this BAA, the Terms of Service, any applicable legal-retention obligations, receiving-provider retention exceptions, and any Archival Retention add-on or configuration purchased or selected by the Practice.

The lifecycle process may include purge events after the receiving provider or Practice has downloaded the file payload, after the receiving provider or Practice has been notified and an applicable grace period has passed, after sender withdrawal and any applicable grace period, or following subscription lapse, nonpayment, account termination, or service interruption as described elsewhere in this BAA or the Terms of Service.

DDSALLY will use a receiver-not-stranded rule when applying payload-deletion processes. An uploader’s file payload should be purged only when the receiving provider or Practice has already downloaded it, has been given notice and a reasonable opportunity to retrieve it, or has provided a logged acknowledgment, force-download confirmation, or equivalent confirmation where applicable. DDSALLY may implement technical safeguards, notices, grace periods, logs, or other workflow controls to reduce the risk that a receiving provider is deprived of access to referral-related PHI needed for treatment, documentation, or professional obligations.

File-payload deletion and audit-record retention are separate processes. Audit logs, disclosure records, activity records, security logs, transmission records, and other administrative records may be retained after file payloads are purged. DDSALLY expects audit and disclosure-related records to be retained for approximately seven (7) years, or for such longer or shorter period as may be required by applicable law, policy, contractual obligation, security needs, or legal-preservation requirements.

Practices may purchase, enable, or configure an Archival Retention add-on or similar retention feature that extends the retention window for certain file payloads or referral records. Retention periods may therefore vary by subscription plan, add-on, configuration, referral status, receiving-provider need, legal-retention requirement, or other applicable exception (For additional information, refer to Sections 22 and 23).

If return or destruction of PHI is not feasible, DDSALLY will continue to protect the PHI in accordance with this BAA and will limit further uses and disclosures to those purposes that make return or destruction infeasible. Because dental and healthcare record-retention periods vary by state, provider type, record type, payer requirement, and applicable law, each Practice should consult qualified legal counsel regarding its own record-retention obligations.

20. De-Identified Information

DDSALLY may de-identify PHI in accordance with HIPAA. Once information has been properly de-identified under HIPAA, it is no longer PHI and may be used by DDSALLY for lawful purposes, including analytics, product improvement, security, reliability, research, benchmarking, and business operations. DDSALLY will not attempt to re-identify de-identified information except as permitted by HIPAA.

21. Artificial Intelligence and Analytics

DDSALLY will not use identifiable PHI to train generalized artificial intelligence models, machine learning systems, diagnostic models, advertising systems, or unrelated analytics tools unless the Practice separately authorizes such use in writing and the use is permitted by HIPAA. DDSALLY may use de-identified data, technical metadata, operational data, and usage analytics to improve security, reliability, usability, and Platform performance, provided such use complies with HIPAA and this BAA. DDSALLY’s AI-assisted referral report generation is a current covered DDSALLY Service approved for PHI when provided through Amazon Bedrock under DDSALLY’s AWS BAA and Healthcare addendum, as listed in Exhibit A. DDSALLY will not send PHI directly to a third-party AI provider outside the approved covered service path unless an appropriate BAA, zero-retention or equivalent HIPAA-appropriate arrangement, and any required customer authorization are in place before PHI is sent.

22. Term and Termination

This BAA begins when the Practice electronically accepts it and remains in effect for as long as DDSALLY creates, receives, maintains, or transmits PHI on behalf of the Practice.

This BAA will terminate when the Practice’s DDSALLY account, subscription, or Services Agreement terminates, except for provisions that must survive termination, including confidentiality, breach cooperation, retention, return or destruction of PHI, access to records, audit and disclosure-record retention, indemnification, limitation of liability, and continued protection of retained PHI.

If either Party materially breaches this BAA, the non-breaching Party may provide written notice and a reasonable opportunity to cure. If the breach is not cured within thirty (30) days, or if cure is not reasonably possible, the non-breaching Party may terminate the affected Services or this BAA, as permitted by law and the Terms of Service.

Following interruption, suspension, non-payment, subscription lapse, account termination, or termination of paid Services, DDSALLY may provide notice to the Practice and a retrieval or reactivation window of not less than thirty (30) days. During that window, the Practice may retrieve applicable file payloads or reactivate access, subject to the Terms of Service, security requirements, payment requirements, account-status requirements, and any technical limitations.

After the applicable retrieval or reactivation window has expired, DDSALLY may purge file payloads uploaded by the Practice, subject to this BAA, the Terms of Service, the receiver-retention exceptions, legal-retention exceptions, and continued-protection obligations described in Sections 19 and 23.

Reactivation within the applicable retrieval or reactivation window may restore access to the affected Services or file payloads, subject to the Terms of Service, security requirements, payment status, account configuration, and any technical limitations. DDSALLY does not guarantee that all file payloads, metadata, configurations, or service functionality can be restored after suspension, lapse, termination, or expiration of any retrieval window.

Audit logs, disclosure records, activity records, security logs, and other administrative records may be retained after file payloads are purged. DDSALLY expects audit- and disclosure-related records to be retained for approximately seven (7) years, or for such longer or shorter period as may be required by applicable law, policy, contractual obligation, security needs, or legal preservation requirements.

If return or destruction of PHI is not feasible following termination, DDSALLY will continue to protect the PHI in accordance with this BAA and will limit further uses and disclosures to those purposes for which return or destruction is infeasible.

23. Return or Destruction of PHI

Subject to the Terms of Service, applicable law, security requirements, and any reasonable technical limitations, DDSALLY will make PHI maintained by DDSALLY on behalf of the Practice reasonably available for retrieval or export upon termination or upon the Practice’s reasonable request, where feasible.

DDSALLY is not required to provide PHI in a manner that compromises security, violates the rights or legal obligations of another Practice or provider, discloses PHI to an unauthorized recipient, or requires DDSALLY to delete or alter PHI that must be retained under Section 19 or Section 23.

Where an export is provided, DDSALLY will make available (i) files, images (including DICOM and Carestream .rvg), reports, and attachments in their original formats, and (ii) referral records and status, messages, referral metadata, and an extract of audit-log entries relating to the Practice in a structured, machine-readable format (CSV or JSON), and/or a human-readable summary where appropriate. Self-service download of individual files, images, and reports is available within the Platform; bulk and structured exports are provided on a support-assisted basis upon the Practice's reasonable request. Self-service export of the Practice’s audit log as a date-ranged CSV is also available to Practice administrators from within the Platform. Retrieval window. The Practice may retrieve or request an export for a period of not less than thirty (30) days following termination or service interruption, consistent with the deletion timeline in Section 19; reactivation within that window restores access. Exports are delivered only to an authorized representative of the Practice through a secure method and exclude PHI that another Practice or provider is entitled to retain under Sections 19 and 23. DDSALLY may retain its own audit and disclosure records as required by law (approximately seven years), independent of any export.

Upon termination, DDSALLY will return or destroy PHI received from, or created, received, maintained, or transmitted on behalf of, the Practice, if feasible. Return or destruction may not be feasible where PHI:

  • Is part of another provider’s referral or clinical record;
  • Must be retained for legal, regulatory, audit, backup, security, litigation, or compliance purposes;
  • Exists in routine backup or disaster recovery systems;
  • Must be retained to protect DDSALLY’s legal rights or comply with law;
  • Is required by a receiving Practice or provider for record-retention purposes. If return or destruction is not feasible, DDSALLY will continue to protect the PHI under this BAA and will limit further uses and disclosures to the purposes that make return or destruction infeasible.

24. Indemnification

Subject to DDSALLY’s Terms of Service and applicable law, DDSALLY will be responsible for third-party claims, damages, penalties, liabilities, costs, or reasonable attorneys’ fees to the extent caused by DDSALLY’s material breach of this BAA, violation of HIPAA, or unauthorized use or disclosure of PHI caused by DDSALLY. Subject to DDSALLY’s Terms of Service and applicable law, the Practice will be responsible for third-party claims, damages, penalties, liabilities, costs, or reasonable attorneys’ fees to the extent caused by the Practice’s misuse of DDSALLY, unauthorized disclosure of PHI, failure to obtain required patient permissions, incorrect recipient selection, inaccurate contact information, unlawful instructions, or HIPAA violation caused by the Practice or its Authorized Users.

25. Limitation of Liability

Any limitation of liability, exclusion of damages, or allocation of risk in DDSALLY’s Terms of Service applies to this BAA to the extent permitted by law. Nothing in this BAA is intended to limit either Party’s obligation to comply with HIPAA.

26. Notices

DDSALLY may provide notices under this BAA by email, through the Platform, through the Practice’s account, by mail, or through another method permitted by the Terms of Service. DDSALLY Notice Contact. DDSALLY LLC, Attn: Privacy Officer, privacy@ddsally.com. Address: 1601 N. Sepulveda Blvd, #398, Manhattan Beach, CA 90266, USA. Practice Notice Contact. The email address, account owner, administrator, mailing address, or other notice contact provided by the Practice during account registration or updated in the Practice’s DDSALLY account. The Practice is responsible for keeping its notice information up to date.

27. Updates to this BAA

DDSALLY may update this BAA from time to time to reflect changes in law, regulation, technology, services, security practices, or business operations. If DDSALLY makes material changes, DDSALLY may provide notice through the Platform, by email, or through another reasonable method. Continued use of DDSALLY after the effective date of an updated BAA may constitute acceptance of the updated BAA, unless a separate written agreement states otherwise.

If the Practice does not agree to an updated BAA, the Practice must stop using DDSALLY for PHI and may terminate its account in accordance with the Terms of Service.

28. Relationship to Terms of Service

This BAA is incorporated into and forms part of DDSALLY’s Terms of Service or other applicable Services Agreement. If this BAA conflicts with DDSALLY’s Terms of Service regarding PHI, HIPAA, privacy, or security obligations, this BAA controls only with respect to PHI and HIPAA-related obligations. All other terms of the Terms of Service remain in effect.

29. Miscellaneous

No Third-Party Beneficiaries. This BAA does not create rights for any third party, including any patient, except as required by law.

Assignment: DDSALLY may assign this BAA in connection with a merger, acquisition, reorganization, sale of assets, transfer of the Platform, or other business transaction, provided that the successor assumes DDSALLY’s obligations regarding PHI. The Practice may not assign this BAA except as permitted by the Terms of Service or with DDSALLY’s written consent.

Severability: If any provision of this BAA is found invalid or unenforceable, the remaining provisions will remain in effect to the fullest extent permitted by law.

Governing Law: This BAA is governed by HIPAA and other applicable federal law. To the extent state law applies and is not preempted by HIPAA, this BAA is governed by the law stated in DDSALLY’s Terms of Service. If the Terms of Service do not identify governing law, the governing law shall be the law of the state where DDSALLY LLC is organized, unless otherwise required by law.

Entire Agreement Regarding PHI: This BAA, together with DDSALLY’s Terms of Service and any applicable subscription agreement or order form, is the complete agreement between DDSALLY and the Practice regarding the use, disclosure, protection, and handling of PHI.

Exhibit A — Covered Services, Excluded Services, Configuration Requirements, and PHI-Touching Subcontractors

This Exhibit A identifies the DDSALLY services and channels approved for PHI, the services and channels excluded or unsupported for PHI, the Practice configuration responsibilities, and current PHI-touching vendors/cloud services.

A. Covered DDSALLY Services Approved for PHI

  • Referral creation and provider-to-provider referral messaging.
  • File upload, storage, and transfer, including radiographs, photographs, CBCT/DICOM and Carestream .rvg images, treatment notes, medical/dental histories, referral forms, and reports.
  • In-app DICOM/imaging viewer, with PHI rendered client-side from encrypted storage.
  • Secure referral chat among authorized, non-suspended users of both the sending and receiving practices.
  • Provider-to-patient outbound delivery of PHI, initiated by the Practice.
  • AI-assisted referral report generation through Amazon Bedrock as a live/current covered feature, subject to the restrictions in Section 21.
  • Transactional email notifications via AWS SES, which may include limited identifiers.
  • Audit logging and referral activity tracking.
  • Account administration and PHI-approved technical support.

B. Excluded or Unsupported for PHI

  • Marketing/outreach email, including Outreach and Broadcast sends, and the associated public asset store (S3 bucket ddsally-public-assets). These are non-PHI by design and kept separate from the PHI file store dental-referral-files-prod.
  • Stripe billing and payment fields. These are for billing/account data only; PHI must not be entered.
  • General or unauthenticated support email and the public marketing website and its forms.
  • Any beta or unreleased feature not expressly approved for PHI in writing.
  • Any support, analytics, advertising, payment, or other third-party tool not approved for PHI and not covered by an appropriate HIPAA-compliant arrangement.

C. Required / Recommended Customer Configuration

  • Enable TOTP multi-factor authentication for all users.
  • Assign least-privilege roles through the multi-role/RBAC system; keep at least one administrator because a last-admin guard is enforced.
  • Promptly suspend or deactivate users who no longer need access.
  • Verify the recipient Practice/provider before sending PHI and limit uploads to the minimum necessary.
  • Review audit/activity logs where available.
  • Do not upload payment-card data, passwords, or unrelated sensitive data.
  • Single sign-on (SSO) is not available at launch.

D. PHI-Touching Subcontractors / Cloud Services

The following table reflects current operational information.

VendorService(s)Role re: PHIBAA / status
Amazon Web Services (account 742558702242, us-west-2)ECS Fargate (compute); RDS PostgreSQL (referral data, audit log); S3 dental-referral-files-prod (files & imaging); DynamoDB (chat); Cognito (auth/identity); Amazon Bedrock (AI report generation); SES (transactional email); KMS (encryption keys); CloudWatch (logs); EventBridge (retention scheduling).Creates / receives / maintains / transmits PHI.AWS BAA + Healthcare addendum — in effect.
StripeSubscription billing, payment methods, invoices, storage/archival add-ons.Billing & account data only — NOT approved for PHI.N/A for PHI (billing only); Section 8 prohibits sending PHI.
Google WorkspaceEmail for support@, noreply@, postmaster@ ddsally.com.May receive PHI if a Practice emails PHI to these addresses.BAA — in effect.
Anthropic (direct API)Website help/support assistant, which calls the Anthropic API directly (separate from Amazon Bedrock).Designed not to receive PHI — instructed to refuse patient information and persists nothing. PHI-bearing AI runs via Bedrock, not here.No PHI by design; no BAA required for current use. Standing safeguard: if PHI is ever sent directly, a BAA / zero-retention or equivalent HIPAA-appropriate arrangement is required first.

Exhibit B — Optional Customer-Specific Instructions or Restrictions

[Exhibit B is designed to capture any customer-specific terms accepted by DDSALLY in writing. If no customer-specific terms are agreed, the default language below should apply.

B.1 Default Customer-Specific Restrictions

  • No customer-specific restriction applies unless accepted by DDSALLY in a signed writing, electronic order form, administrative configuration, or other written amendment approved by DDSALLY.
  • The Practice must not instruct DDSALLY to use or disclose PHI in a manner that would violate HIPAA or other applicable law if performed by the Practice.
  • The Practice must notify DDSALLY in writing of any patient-specific restriction, revocation, confidential communication request, or legal limitation that DDSALLY is expected to follow. DDSALLY is required to follow such restriction only to the extent DDSALLY has agreed in writing and the Platform can technically support it.
  • State-law or payer-specific retention duties remain the Practice’s responsibility unless DDSALLY expressly agrees in writing to a specific retention configuration or Archival Retention add-on.

B.2 Platform Data-Flow Summary

DDSALLY is a referral transfer layer and Business Associate that transmits and temporarily maintains PHI between practices. The practices remain the systems of record. A typical flow is: a sending Practice uploads referral data, clinical notes, and imaging, including DICOM and Carestream .rvg radiographs; DDSALLY stores it encrypted and notifies the receiving Practice; authorized, non-suspended users of both practices access it through the web app and in-app DICOM viewer and exchange secure messages; the Platform may generate an AI-assisted referral report from the referral through the approved covered service path; and file payloads are purged on a retention lifecycle. All compute and primary storage are intended to operate in AWS us-west-2 under an AWS BAA and Healthcare addendum.

B.3 Security and Configuration Terms

  • Security controls available at launch include TOTP MFA; role-based multi-role permissions with a last-admin guard; user suspension/deactivation; password change requiring re-authentication; masked DOB/phone entry; encryption at rest using AWS KMS; encryption in transit using TLS; append-only audit logs written in the same transaction as the audited action; a configurable file-retention window; and an optional paid Archival Retention add-on.
  • Features not available at launch include SSO and message-level expiration beyond the retention lifecycle.
  • The Practice is responsible for using available configuration controls in a HIPAA-appropriate manner and for limiting access to Authorized Users only.

B.4 Retention, Deletion, and Service Interruption

  • DDSALLY is a transfer layer, not the Practice’s primary system of record. The receiving Practice is responsible for its own system-of-record obligations for referrals it receives.
  • File payloads may be purged after the receiver has downloaded them or been notified, plus a grace period; after sender withdrawal, plus any applicable grace period; and after subscription lapse or service interruption following the retrieval/reactivation window described in Section 22.
  • Receiver-not-stranded rule: an uploader’s payload is purged only where the receiver has already downloaded it, been given notice and reasonable opportunity to retrieve it, or provided a logged acknowledgment, force-download confirmation, or equivalent confirmation where applicable.
  • Audit records are retained separately from file payloads. Audit, disclosure, activity, security, and administrative records may be retained for approximately seven (7) years, or another period required by law, policy, contract, security need, or legal preservation.
  • After dunning is exhausted or a subscription lapses, DDSALLY may notify the Practice and provide an approximately thirty (30) day window to download or reactivate access. After that window, Practice’s uploaded file payloads may be purged, while audit records may be retained. Reactivation within the window may restore access, subject to technical and account-status limitations.
  • The Archival Retention add-on may extend the retention window for certain file payloads or referral records. Retention periods may vary by plan, add-on, configuration, referral status, receiving-provider need, legal-retention requirement, or other applicable exception.

B.5 Export on Termination

  • Upon termination or reasonable request, DDSALLY will make PHI reasonably available for retrieval or export where feasible and consistent with security requirements, legal obligations, receiver-retention exceptions, and technical limitations.
  • Expected export materials may include files, imaging, reports, attachments, referral records and status, messages, referral metadata, and relevant audit-log extracts in original formats and/or CSV, JSON, or human-readable summaries where appropriate.
  • Exports are delivered only to an authorized representative of the Practice through a secure method and exclude PHI that another Practice or provider is entitled to retain.

B.6 AI Feature Terms

  • AI-assisted referral report generation is a live/current covered feature, not merely a future feature. DDSALLY generates referral reports from PHI using Amazon Bedrock under the AWS BAA and Healthcare addendum, subject to Section 21.
  • DDSALLY will not use identifiable PHI to train generalized models unless separately authorized in writing and permitted by HIPAA.
  • The direct Anthropic API website help assistant is designed not to receive PHI and is separate from Bedrock. If DDSALLY changes any AI path so that PHI is sent directly to a third-party AI provider, DDSALLY must have an appropriate BAA, zero-retention, or equivalent HIPAA-appropriate arrangement and any required customer authorization before PHI is sent.

B.7 Customer-Specific Terms Accepted by DDSALLY

None.

Electronic Acceptance Statement

By checking the box below, clicking “I Agree,” creating an account, activating DDSALLY services, or using DDSALLY to send, receive, maintain, transmit, upload, store, or manage PHI, I acknowledge and agree that:

  • I am authorized to accept this Business Associate Agreement on behalf of the Practice;
  • I have read and understand this Business Associate Agreement;
  • The Practice agrees to be legally bound by this Business Associate Agreement;
  • The Practice agrees that electronic acceptance has the same legal effect as a handwritten signature;
  • The Practice will use DDSALLY in compliance with HIPAA, this BAA, and DDSALLY’s Terms of Service.

The Date of Electronic Acceptance and the Version Accepted are automatically recorded by DDSALLY at the moment of acceptance, along with the accepting user’s account, email address, and IP address.