Platform Terms of Use - Scribe & Clinician Assistant

This Business Associate Agreement (“BAA”) is entered into between Notiro Corp. (“Business Associate”) and the healthcare provider, healthcare organization, or other HIPAA Covered Entity accepting this Agreement (“Covered Entity”).

By clicking “I Agree,” accessing, or using Notiro’s services to process Protected Health Information (“PHI”), Covered Entity agrees to the terms of this BAA.

1. Purpose

Notiro provides AI-powered clinical documentation, transcription, and workflow support services that may involve the creation, receipt, maintenance, transmission, or processing of PHI on behalf of Covered Entity.

This BAA is intended to satisfy the requirements of:

  • HIPAA
  • HITECH Act
  • Applicable federal and state healthcare privacy laws

2. Definitions

Terms not otherwise defined herein shall have the meanings assigned under HIPAA. Including:

  • Protected Health Information (PHI)
  • Breach
  • Security Incident
  • Covered Entity
  • Business Associate
  • Unsecured PHI

3. Permitted Uses and Disclosures

Notiro may use and disclose PHI solely to:

  • Provide the Services
  • Generate clinical documentation
  • Perform transcription services
  • Support authorized integrations
  • Maintain platform security
  • Conduct customer support
  • Fulfill legal obligations

Notiro shall not sell PHI.

Notiro shall not use PHI for advertising purposes.

Notiro shall not use PHI to train general-purpose or publicly available AI models.

4. Safeguards

Notiro shall implement reasonable and appropriate administrative, technical, and physical safeguards including:

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest
  • Role-based access controls
  • Multi-factor authentication
  • Audit logging
  • Security monitoring
  • Vulnerability management
  • Incident response procedures

5. Subprocessors

Notiro may engage subcontractors and service providers.

Notiro shall ensure all subcontractors with access to PHI are bound by written agreements requiring protections at least as protective as this BAA.

6. Reporting

Notiro shall notify Covered Entity without unreasonable delay and no later than thirty (30) calendar days after discovery of:

  • A Breach of Unsecured PHI
  • Unauthorized use or disclosure of PHI
  • Material Security Incidents involving PHI

Notifications shall include information reasonably available at the time.

7. Access and Amendment

Upon written request, Notiro shall provide reasonable assistance necessary for Covered Entity to:

  • Access PHI
  • Amend PHI
  • Respond to accounting-of-disclosure requests

To the extent required by HIPAA.

8. Data Retention and Deletion

Notiro shall retain PHI only as necessary:

  • To provide the Services
  • To satisfy contractual obligations
  • To comply with applicable law

Upon termination:

  • Covered Entity may export its data within thirty (30) days.
  • Following the export period, Notiro shall securely delete PHI unless retention is legally required.

9. Customer Responsibilities

Covered Entity is solely responsible for:

  • Obtaining required patient consents
  • Complying with recording laws
  • Determining whether recordings may occur
  • Reviewing all AI-generated documentation
  • Ensuring clinical accuracy

10. Artificial Intelligence

Notiro provides AI-assisted documentation tools. Covered Entity acknowledges:

  • AI-generated outputs are assistive only.
  • Notiro does not provide medical advice.
  • Healthcare professionals remain solely responsible for:
    • Clinical decisions
    • Diagnoses
    • Treatment plans
    • Billing and coding submissions
    • Final documentation approval

11. Audit Rights

Upon reasonable written request and subject to confidentiality restrictions, Notiro may provide documentation reasonably necessary to demonstrate compliance with HIPAA obligations.

12. Termination

This BAA remains effective until:

  • Services are terminated; and
  • All PHI has been returned or securely deleted.

Either party may terminate this BAA upon material breach if the breach is not cured within thirty (30) days after notice.

13. Survival

The obligations relating to PHI protection shall survive termination for as long as PHI is retained.

14. Order of Precedence

In the event of a conflict between this BAA and any other agreement between the parties, this BAA shall control with respect to PHI.

15. Electronic Acceptance

The parties agree that electronic acceptance, including clicking “I Agree,” checking an acceptance box, or using the Services after presentation of this BAA, constitutes a legally binding signature.

16. Contact Us

If you have any questions or concerns about these Terms, please contact us at [email protected]