HIPAA Business Associate Agreement
Effective Date: August 13, 2026
Version: 1.0
Operator: ARYX LLC (aryx.pro). The contracting party named on an Order Form controls for that transaction.
This HIPAA Business Associate Agreement ("BAA" or "Agreement") is entered into by and between ARYX LLC ("ARYX", "Business Associate") and the customer entity that has executed a Master Services Agreement, Order Form, or online subscription for the Services ("Customer", "Tenant", and, where it is a HIPAA covered entity or an upstream business associate, "Covered Entity"). ARYX and Customer are each a "Party" and together the "Parties".
This BAA supplements, and is incorporated by reference into, the agreement governing Customer's use of the ARYX platform (the "Underlying Agreement"). It governs the Parties' obligations with respect to Protected Health Information under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164 (the "HIPAA Rules"), as amended by the HITECH Act. Where a conflict exists between this BAA and the Underlying Agreement with respect to PHI, this BAA controls.
1. Scope and Applicability
1.1 ARYX operates a multi-tenant B2B SaaS platform for health-plan enrollment, administration, and billing, comprising EnrollFlow (member enrollment), ARYX CRM (member/lead relationship management for Tenant staff), ARYX Accounts (identity, SSO, org provisioning, and the subscription/billing engine), and supporting applications (collectively, the "Services").
1.2 EnrollFlow is the primary PHI system. It is the ARYX application designed to collect, store, and process Protected Health Information in the course of member enrollment. ARYX CRM and ARYX Accounts are designed to process member PII, tenant staff credentials, and financial/transaction data, and may incidentally receive PHI depending on Tenant configuration and Tenant-entered content. This BAA applies to all PHI that ARYX creates, receives, maintains, or transmits on behalf of Customer through any component of the Services.
1.3 This BAA does not apply to the payment-card data flow. Cardholder PAN and CVV are tokenized in-browser via Authorize.Net Accept.js (opaqueData) and never reach ARYX servers or database; ARYX stores only Authorize.Net CIM payment-profile tokens. That data flow is governed by the Underlying Agreement, the applicable Data Processing Addendum, and ARYX's PCI-DSS posture (see ARYX's refund and settlement standards (see also /legal/billing) and /legal/dpa), not by this BAA.
2. Definitions
2.1 Capitalized terms used but not defined in this BAA have the meanings assigned in the HIPAA Rules. The following terms apply:
- "Protected Health Information" or "PHI" means individually identifiable health information, as defined at 45 CFR 160.103, that ARYX creates, receives, maintains, or transmits for or on behalf of Customer through the Services. PHI includes Electronic Protected Health Information ("ePHI").
- "Breach", "Security Incident", "Required by Law", "Designated Record Set", "Subcontractor", "Unsecured PHI", and "Secretary" have the meanings given in 45 CFR Parts 160 and 164.
- "Authorized User" means an individual (Tenant staff, agent, or member/enrollee) whom Customer or its configuration permits to access the Services.
- "Member Data" means data pertaining to Customer's members/enrollees processed in the Services, which may include PHI and PII.
- "Processor" means Authorize.Net, the payment processor for CIM-based recurring charges.
- "Subprocessor" means a third party ARYX engages to process data in support of the Services. Where a Subprocessor creates, receives, maintains, or transmits PHI, it is a Subcontractor for purposes of the HIPAA Rules.
- "Services", "Customer"/"Tenant", and "ARYX" have the meanings given above.
3. Permitted Uses and Disclosures of PHI
3.1 Services performance. ARYX may use and disclose PHI only as necessary to perform the Services described in the Underlying Agreement — including enrollment processing, member administration, communications workflow, initiating and scheduling Processor payment activity, and support — and as otherwise permitted or required by this BAA or Required by Law.
3.2 Management and administration. ARYX may use PHI for the proper management and administration of ARYX and to carry out its legal responsibilities. ARYX may disclose PHI for such purposes only if the disclosure is Required by Law, or ARYX obtains reasonable written assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and the recipient notifies ARYX of any breach of confidentiality.
3.3 Data aggregation and de-identification. ARYX may use PHI to provide Data Aggregation services relating to the health care operations of Customer as permitted by 45 CFR 164.504(e)(2)(i)(B), and may de-identify PHI in accordance with 45 CFR 164.514(a)–(c). De-identified data is not PHI and is not subject to this BAA.
3.4 Minimum Necessary. ARYX will, when using or disclosing PHI or requesting PHI from Customer, make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 CFR 164.502(b) and 164.514(d). Multi-tenant isolation is enforced in Postgres via Row-Level Security (RLS), org-scoped, so that PHI of one Tenant is not accessible to another Tenant.
4. Prohibition on Other Use or Disclosure
4.1 ARYX will not use or disclose PHI other than as permitted or required by this BAA, the Underlying Agreement, or as Required by Law.
4.2 ARYX will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Customer, except for the management, administration, and legal-responsibility purposes and Data Aggregation services set out in Section 3.
4.3 ARYX will not sell PHI and will not use or disclose PHI for marketing, fundraising, or the creation of de-identified datasets for resale, except as expressly authorized in writing by Customer and permitted by the HIPAA Rules.
5. Safeguards
5.1 ARYX will implement and maintain administrative, physical, and technical safeguards, and comply with the applicable requirements of the HIPAA Security Rule (45 CFR Part 164, Subpart C) with respect to ePHI, reasonably designed to prevent use or disclosure of PHI other than as provided by this BAA. These safeguards are described in ARYX's information security program (see ARYX's information security program) and include, at minimum:
- Technical: encryption of ePHI in transit (TLS) and at rest; org-scoped Postgres Row-Level Security enforcing Tenant isolation; SSO and role-based access control via ARYX Accounts; least-privilege access; audit logging; and secrets management.
- Administrative: access provisioning and de-provisioning, workforce security and training, risk assessment, and a documented incident-response process (see ARYX's incident response commitments).
- Physical: reliance on the physical and environmental controls of ARYX's infrastructure Subprocessors (Supabase and Vercel), which maintain independently attested facility controls.
5.2 ARYX will ensure that any agent or Subcontractor that creates, receives, maintains, or transmits ePHI on ARYX's behalf agrees in writing to implement reasonable and appropriate safeguards, as set out in Section 8.
6. Reporting of Security Incidents and Breaches
6.1 Security Incidents. ARYX will report to Customer any Security Incident of which it becomes aware, in accordance with the timelines and process in ARYX's incident response commitments. Consistent with 45 CFR 164.308(a)(6), the Parties acknowledge that routine, unsuccessful attempts (e.g., pings, port scans, blocked access attempts, and similar events that do not result in unauthorized access to or acquisition of PHI) are hereby reported on an ongoing aggregate basis and do not require individual notice.
6.2 Breach of Unsecured PHI. ARYX will notify Customer of any Breach of Unsecured PHI without unreasonable delay and in no case later than sixty (60) calendar days after Discovery of the Breach, and ARYX will use commercially reasonable efforts to provide initial notice within forty-eight (48) to seventy-two (72) hours of Discovery. A Breach is treated as Discovered as of the first day on which it is known, or by exercising reasonable diligence would have been known, to ARYX.
6.3 Content of Breach notification. To the extent known, ARYX's notice will include: (a) a description of what happened, including the date of the Breach and date of Discovery; (b) the types of PHI involved (e.g., names, dates of birth, member identifiers, enrollment or health data); (c) the identity of each individual whose Unsecured PHI was or is reasonably believed to have been accessed, acquired, used, or disclosed; (d) the steps ARYX has taken or will take to investigate, mitigate harm, and prevent recurrence; and (e) a point of contact. ARYX will supplement its notice as additional information becomes available.
6.4 Cooperation. ARYX will reasonably cooperate with Customer's own Breach-notification obligations under 45 CFR 164.404–164.410. As between the Parties, Customer is responsible for notifying affected individuals, the Secretary, and the media where required, unless the Parties agree in writing that ARYX will do so on Customer's behalf.
7. Individual Rights
7.1 Access (45 CFR 164.524). To the extent ARYX maintains PHI in a Designated Record Set, ARYX will, within ten (10) business days of Customer's request, make such PHI available to Customer (or, where directed, to the individual) so that Customer can meet its access obligations. EnrollFlow provides the primary record set for enrollment PHI.
7.2 Amendment (45 CFR 164.526). ARYX will make PHI in a Designated Record Set available for amendment and will incorporate amendments directed by Customer within ten (10) business days of Customer's request.
7.3 Accounting of Disclosures (45 CFR 164.528). ARYX will document disclosures of PHI and information related to such disclosures as required for Customer to respond to an accounting request, and will provide such information to Customer within ten (10) business days of request. ARYX's audit logging is designed to support this obligation.
7.4 Requests directed to ARYX. If an individual submits an access, amendment, or accounting request directly to ARYX, ARYX will, within a reasonable time, forward the request to Customer and will not respond directly except as directed by Customer or Required by Law.
8. Subcontractors and Subprocessor Flow-Down
8.1 In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ARYX will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on ARYX's behalf agrees in writing to restrictions and conditions on PHI that are at least as restrictive as those that apply to ARYX under this BAA, by executing a business associate agreement with ARYX.
8.2 The current Subprocessors that may process PHI in support of the Services, and for which flow-down BAAs are required, include Supabase (database, authentication, storage — the primary PHI store for EnrollFlow), Vercel (application hosting), and Resend (transactional email, where PHI is included in message content). GoTo (SMS/voice) and Authorize.Net (payments) are engaged as Subprocessors under the Underlying Agreement; a flow-down BAA is required for GoTo to the extent PHI is transmitted in communications content. The authoritative, maintained list is in /legal/subprocessors.
8.3 ARYX remains liable to Customer for the acts and omissions of its Subcontractors with respect to PHI to the same extent as if performed by ARYX. ARYX will notify Customer of intended additions or replacements of PHI-processing Subprocessors in accordance with the notice mechanism in the DPA, and Customer may object on reasonable data-protection grounds.
9. Availability of Records to HHS
9.1 ARYX will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by ARYX on behalf of, Customer available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Customer's compliance with the HIPAA Rules, subject to applicable attorney-client privilege and confidentiality protections. Disclosure to the Secretary does not waive any privilege.
10. Obligations of Customer
10.1 Customer will notify ARYX of any limitation(s) in Customer's Notice of Privacy Practices, any changes to or revocation of an individual's authorization, and any restriction on the use or disclosure of PHI that Customer has agreed to or is required to abide by, to the extent such limitation, change, revocation, or restriction may affect ARYX's use or disclosure of PHI.
10.2 Customer will not request that ARYX use or disclose PHI in any manner that would not be permitted under the HIPAA Rules if done by Customer, except as permitted under Section 3 (management, administration, legal responsibilities, and Data Aggregation).
10.3 Customer is responsible for configuring the Services (including RLS-scoped access, role assignments, and communication templates) so that PHI is collected and disclosed consistent with Minimum Necessary and Customer's own HIPAA obligations.
11. Term and Termination
11.1 Term. This BAA is effective as of the Effective Date and continues until the later of termination of the Underlying Agreement or the date on which all PHI is returned or destroyed in accordance with Section 12.
11.2 Termination for cause. If Customer determines that ARYX has materially breached this BAA, Customer may: (a) provide ARYX a reasonable opportunity to cure, not to exceed thirty (30) days; (b) if cure is not effected, terminate the Underlying Agreement and this BAA; or (c) if neither cure nor termination is feasible, report the violation to the Secretary. ARYX has reciprocal cure and termination rights for Customer's material breach.
12. Return or Destruction of PHI at Termination
12.1 Upon termination of this BAA, ARYX will, if feasible, return to Customer or securely destroy all PHI that ARYX (and its Subcontractors) maintains in any form, and retain no copies, in accordance with ARYX's data ownership and retention terms.
12.2 Where return or destruction is infeasible (including where PHI is retained in immutable backups or as Required by Law), ARYX will extend the protections of this BAA to such PHI and limit further use or disclosure to those purposes that make return or destruction infeasible, for so long as ARYX retains the PHI. Backup media containing PHI is destroyed on its ordinary rotation schedule of not more than ninety (90) days after termination.
12.3 ARYX will provide Customer written certification of return or destruction upon request. Customer is responsible for exporting its own Member Data prior to termination via the Services' export functionality.
13. Miscellaneous
13.1 Interpretation. Ambiguities are resolved to permit compliance with the HIPAA Rules. This BAA is construed to give effect to 45 CFR 164.504(e).
13.2 Amendment. The Parties will amend this BAA as necessary to comply with changes to the HIPAA Rules or other applicable law.
13.3 No third-party beneficiaries. Nothing in this BAA confers rights on any person other than the Parties, except as expressly provided by the HIPAA Rules.
13.4 Governing law. This BAA is governed by the laws of the United States, with venue in the courts designated on the applicable Order Form, except where preempted by federal law. Notices are sent to the notice address designated on the applicable Order Form; HIPAA/privacy matters to legal@aryx.pro and security matters to legal@aryx.pro.
13.5 Survival. Sections 9, 12, and any provision necessary for the protection of PHI survive termination.
Questions about this document? Contact legal@aryx.pro. Related: all legal documents · Privacy Policy · Terms of Service.