Legal

Legal, Compliance & Regulatory Framework

GBSI operates with full transparency across all jurisdictions. Our complete legal documentation — governing platform usage, data protection, security, and compliance — is published here in its entirety.

This page contains the official legal text migrated from the GBSI legal documentation. The text has been preserved for completeness and formatted for improved readability.Source: https://corporate.lutinx.com/hipaa/

HIPAA Business Associate Agreement

Last updated: January 30, 2026

This Business Associate Agreement ("BAA") forms part of lutinx.com's Terms of Service or other agreement governing the use of lutinx.com's services ("Agreement") whether you are an existing customer who accepted the Agreement or a new customer accepting the Agreement now and shall only apply to you if you are using the enterprise tier subscription and have enabled the HIPAA compliance feature on the Platform. You acknowledge that you, on your own behalf as an individual or on behalf of your employer or its Authorized Affiliates (collectively, "Covered Entity" "you", "your" or the "Customer") have read and understood and agree to comply with this BAA, and are entering into a binding legal agreement with Lutin Technologies Ltd., the owner of lutinx.com ("lutinx.com", "us", "we", "our", or "Business Associate")."Authorized Affiliate" means any of Customer's affiliate(s) which is explicitly permitted to use the Services pursuant to the Agreement between Customer and lutinx.com, but has not signed its own agreement with lutinx.com and is not a "Customer" as defined under the Agreement. "Services" means the cloud-based work operating system platform ("Platform") and any other services provided to Customer by lutinx.com under the Agreement. To the extent that you are agreeing to this BAA in connection with your use of our Services on behalf of an entity that is a "business associate", as defined under HIPAA, of one or more HIPAA-covered entities and not itself a HIPAA-covered entity, lutinx.com acknowledges that it is functioning as a "subcontractor" hereunder as defined at 45 C.F.R. § 160.103 and that the term "Covered Entity" as used herein shall be considered contractual terminology and shall not imply that you are a covered entity as defined under HIPAA. Both parties shall be referred to as the "Parties" and each, a "Party".

In the course of providing the Services under the Agreement, the Business Associate may access, use, disclose, store, and/or process PHI on the Covered Entity's behalf. The BAA reflects the Parties' agreement with how the Business Associate uses and/or discloses the Covered Entity's Protected Health Information ("PHI") on behalf of the Covered Entity. Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement or as defined under the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations, as may be updated from time to time (collectively, "HIPAA"). You represent and warrant that you have, or you were granted, full authority to bind the Covered Entity to this BAA. If you cannot, or do not agree to, comply with, and be bound by, this BAA or do not have the authority to bind the Covered Entity, please do not provide us or give us access to PHI.

To sign a BAA with us, you can either (i) countersign the online version of this BAA posted at www.lutinx.com/hipaa, using the free version of CZone directly from your account. The signed copy will be provided directly to us. In the event of any conflict between certain provisions of this BAA and the provisions of the Agreement, the provisions of this BAA shall prevail.

The Parties agree to comply with the following provisions concerning any PHI that the Covered Entity provides to the Business Associate for the Business Associate to perform the Services.

1. Permitted Uses and Disclosures

The Business Associate may use and disclose PHI necessary to perform its obligations to the Covered Entity as set out in the Agreement or as otherwise permitted or required by Law under HIPAA, provided that the Business Associate shall not use or disclose PHI in a manner that would not be permitted if done by the Covered Entity. The Business Associate may also:

(a) use PHI (i) as necessary for its proper management and administration, or (ii) to carry out its legal responsibilities; and

(b) disclose PHI to third parties for the same purposes so long as (i) the disclosure is Required by Law or (ii) the Business Associate obtains satisfactory assurances from said third party that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed and that the third party will notify the Business Associate of any instances of which it is aware in which the confidentiality of the PHI has been breached.

Business Associate shall only use, disclose, and request the Minimum Necessary PHI to accomplish the purpose of the use, disclosure, or request.

2. Obligations of the Business Associate

(a) Limitation on Disclosure. The Business Associate agrees not to use or further disclose PHI other than as permitted under the Agreement or BAA, or as required by Law.

(b) Safeguards. The Business Associate agrees to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the PHI that it creates, receives, stores, maintains, or transmits on behalf of the Covered Entity according to this BAA and the Agreement, and shall prevent the use or disclosure of Covered Entity's PHI other than as provided for in this BAA, Agreement or as Required by Law.

(c) Mitigation. The Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by the Business Associate in violation of the requirements of the BAA.

(d) Use of Agents/Subcontractors. The Business Associate agrees to ensure that any agents, including a subcontractor, to whom the Business Associate provides PHI received from, or created or received by, the Business Associate on behalf of the Covered Entity, agree to restrictions and conditions for the use and disclosure of PHI that are no less restrictive than those that apply to the Business Associate under this BAA.

(e) Access to PHI. Within fifteen (15) days of receiving a written request from the Covered Entity or an Individual for a copy of PHI within a Designated Record Set, the Business Associate agrees to make the requested PHI available to the Covered Entity to enable the Covered Entity to respond to an Individual who seeks to inspect or copy his/her PHI. The Business Associate is required to comply with the Security Rule with respect to electronic PHI, including but not limited to making available upon written request copies of PHI in electronic format when PHI is stored electronically. Any disclosure of, or decision not to disclose, the PHI requested by an Individual, and compliance with the requirements applicable to an Individual's right to access PHI shall be the sole responsibility of the Covered Entity.

(f) Amendment of PHI. Within fifteen (15) days of receiving a written request from the Covered Entity to make an amendment to PHI within a Designated Record Set, the Business Associate will make such amendment and will inform the Covered Entity that an amendment has been made. If the Business Associate receives an amendment request directly from an Individual, the Business Associate shall notify the Covered Entity of the request within fifteen (15) days of receiving a written request from the Individual.

(g) Accounting of Certain Disclosures. Within thirty (30) days of receiving a written request from the Covered Entity for an accounting of disclosures of PHI about an Individual, the Business Associate shall provide to the Covered Entity a listing of the persons or entities to which the Business Associate has disclosed PHI about the Individual within the prior six (6) years, along with the dates of, reasons for, and brief descriptions of the disclosures to enable the Covered Entity to respond to an Individual seeking an accounting of the disclosures of the Individual's PHI in accordance with 45 C.F.R. § 164.528.

(h) Access to Books and Records. The Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI received from, created by, or received by the Business Associate on behalf of the Covered Entity available upon request to the Secretary of the U.S. Department of Health and Human Services so that it may evaluate the Covered Entity's compliance with the Privacy Rule.

(i) Obligations of Business Associate Upon Termination. The Business Associate shall, upon termination or expiration of this BAA, if feasible, return or allow the Covered Entity to destroy all PHI received from, processed by, or received by the Business Associate on behalf of the Covered Entity, that the Business Associate still maintains in any form in connection with this BAA and the Agreement through a deletion option provided by Business Associate in the Platform and retain no copies of such PHI except as otherwise outlined in Section 5(b) of this BAA or the Agreement. If such return or destruction is not feasible as determined by the Business Associate, the Business Associate will extend the protections of this BAA to the PHI and limit further uses and disclosures to those purposes that make the return or destruction of the PHI infeasible.

(j) Reporting of Security Incident. The Business Associate shall report to the Covered Entity any Security Incident of which it becomes aware. Under 45 C.F.R. § 164.304, a Security Incident is defined as the attempted or successful unauthorized access, use, disclosure, or destruction of information or interference with system operations in an information system. Notwithstanding the foregoing, the Parties acknowledge and agree that this Section constitutes notice by the Business Associate to the Covered Entity of the ongoing existence and occurrence of attempted but Unsuccessful Security Incidents (as defined below) for which no additional notice to the Covered Entity is required. "Unsuccessful Security Incidents" means, without limitation, pings and other broadcast attacks on the Business Associate's firewall, port scans, unsuccessful log-on attempts, denials of service and any combination of the above, so long as no such incident results in unauthorized access, use or disclosure of PHI.

3. Obligations of the Covered Entity

The Covered Entity shall:

  • Notify the Business Associate of any limitation(s) in its notice of privacy practices, if such limitation(s) may affect the Business Associate's use or disclosure of PHI;
  • Notify the Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, if such changes may affect the Business Associate's use or disclosure of PHI;
  • Notify the Business Associate of any restriction to the use or disclosure of PHI that the Covered Entity has agreed to in accordance with HIPAA Privacy Rule, if such restriction may affect the Business Associate's use or disclosure of PHI;
  • Not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule or this BAA if done by the Covered Entity.

4. Permissible Requests by Covered Entity

The Covered Entity shall not request the Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by the Covered Entity.

5. Term and Termination

(a) Term. The term of this BAA shall be effective as of the Effective Date, and shall terminate when all of the PHI provided by the Covered Entity to the Business Associate, or created or received by the Business Associate on behalf of the Covered Entity, is destroyed or returned to the Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information in accordance with this BAA.

(b) Termination for Cause. Upon the Covered Entity's knowledge of a material breach by the Business Associate, the Covered Entity shall either: (i) provide an opportunity for the Business Associate to cure the breach or end the violation within the timeframe specified by the Covered Entity, and terminate this BAA and the Agreement if the Business Associate does not cure the breach or end the violation within the agreed timeframe; or (ii) immediately terminate this BAA and the Agreement if cure is not possible.

(c) Effect of Termination. Upon termination of this BAA for any reason, the Business Associate shall return or destroy all PHI received from the Covered Entity, or created or maintained by the Business Associate on behalf of the Covered Entity, and shall not retain copies of such information once the BAA is terminated.

6. Miscellaneous

(a) Amendment. The Parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for the Covered Entity or the Business Associate to comply with the requirements of HIPAA, and any other applicable law.

(b) Regulatory References. A reference in this BAA to a section in HIPAA means the section as in effect or as amended.

(c) Interpretation. Any ambiguity in this BAA shall be interpreted to permit compliance with HIPAA.

(d) No Third Party Beneficiaries. Nothing express or implied in this BAA is intended to confer, nor shall anything herein confer, upon any person other than the Parties any rights, remedies, obligations, or liabilities whatsoever.

Contact

For HIPAA-related inquiries or BAA execution:

Company: Lutin Technologies Ltd.
Email: legal@lutinx.com
Subject: "HIPAA / BAA Request"

Legal Department

For questions related to this document, contact our legal team.

Contact Legal