This Business Associate Agreement ("BAA") forms part of the Terms of Service between Smileline Technologies Ltd, company number 17408336, registered in England and Wales with its registered office at 1 Lyric Square, London, England, W6 0NB (the "Business Associate"), and the practice accepting it (the "Covered Entity" or "Practice"). It applies where the Practice is a covered entity under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164 (together, "HIPAA"), as amended by the HITECH Act.
Terms used but not defined here have the meanings given in HIPAA. "PHI" means Protected Health Information that Smileline creates, receives, maintains or transmits for or on behalf of the Practice.
1. Why this document exists
Smileline stores patient records, carries patient messages and telephone calls, records and transcribes those calls, and syncs clinical context from the Practice's practice management system. That makes Smileline a business associate. A covered entity may not disclose PHI to a business associate without satisfactory assurances in place, so this BAA is a precondition of a US practice using the Service — not an optional extra.
2. Permitted uses and disclosures
- Smileline may use and disclose PHI only to perform the Service, as this BAA permits, or as required by law.
- Smileline may use PHI for its own proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes only where the disclosure is required by law, or where Smileline obtains reasonable assurances from the recipient that it will be held confidentially, used only as permitted, and that the recipient will notify Smileline of any breach of its confidentiality.
- Smileline may de-identify PHI in accordance with 45 CFR 164.514(b) and may use the de-identified data, which is no longer PHI.
- Smileline will not use or disclose PHI in a way that would violate HIPAA if done by the Practice.
- Smileline will make reasonable efforts to use, disclose and request only the minimum necessary PHI to accomplish the purpose, as required by 45 CFR 164.502(b).
3. What Smileline will not do with PHI
- No advertising platforms. Smileline will not disclose PHI, or data derived from PHI, to any advertising or analytics platform that has not entered into a business associate agreement. Conversion upload to advertising platforms is switched off for US practices for this reason.
- No model training. Smileline will not use PHI to train, fine-tune or otherwise improve any artificial-intelligence model, and will not permit a sub-contractor to do so.
- No sale. Smileline will not sell PHI or receive remuneration in exchange for PHI.
4. Safeguards
Smileline will use appropriate administrative, physical and technical safeguards, and will comply with the HIPAA Security Rule at 45 CFR Part 164 Subpart C with respect to electronic PHI, to prevent use or disclosure of PHI other than as this BAA provides. The measures in section 6 of the Data Processing Agreement apply to PHI, together with encryption in transit and at rest, unique user identification, role-based access control, audit logging of access to patient records, and automatic session termination.
5. Sub-contractors
In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Smileline will ensure that every sub-contractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this BAA. The sub-processors listed in section 5 of the Data Processing Agreement apply, with these differences for US practices: the AI chat widget model provider is not engaged for US practices, and advertising platforms do not receive PHI. Where the Practice switches on the AI receptionist, the providers that carry, recognise and synthesise the speech of an AI-answered call and the model that conducts it (LiveKit Cloud in its US region, Cartesia, and OpenAI under zero-data-retention terms) are engaged under written assurances of the same standard; Smileline will not enable the AI receptionist for a US Practice until those assurances are in place.
6. Reporting
- Smileline will report to the Practice any use or disclosure of PHI not permitted by this BAA, any security incident, and any breach of unsecured PHI, without unreasonable delay and in any event within five business days of discovery — well inside the 60-day outer limit set by 45 CFR 164.410, so the Practice has time to meet its own notification deadlines.
- The report will include, to the extent known: the individuals affected, what happened, the types of PHI involved, what Smileline is doing to investigate and mitigate, and the information the Practice needs for its own notifications.
- Unsuccessful security incidents that result in no unauthorised access to PHI — routine scans, pings and failed log-in attempts — are reported in aggregate on request rather than individually.
7. Individual rights
- Smileline will make PHI in a designated record set available to the Practice so it can meet an individual's access request under 45 CFR 164.524, including in electronic form where requested.
- Smileline will make PHI available for amendment and incorporate amendments under 45 CFR 164.526.
- Smileline will maintain and make available the information required for an accounting of disclosures under 45 CFR 164.528.
- Where an individual contacts Smileline directly, Smileline will refer them to the Practice rather than acting on the request itself.
8. Access by the Secretary
Smileline will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of the US Department of Health and Human Services for purposes of determining the Practice's compliance with HIPAA.
9. Term and termination
- This BAA takes effect when the Practice accepts it and continues until all PHI is returned or destroyed.
- The Practice may terminate the Terms of Service if Smileline breaches a material term of this BAA and fails to cure it within 30 days of written notice.
- On termination, Smileline will return or destroy all PHI it still holds, including PHI held by sub-contractors, within 90 days. Where return or destruction is infeasible, Smileline will extend the protections of this BAA to that PHI and limit further use and disclosure to the reasons that make return or destruction infeasible, for as long as it retains the PHI.
10. Relationship to the other documents
Where this BAA conflicts with the Terms of Service or the Data Processing Agreement in respect of PHI, this BAA prevails. The parties agree to amend this BAA as necessary for each to comply with HIPAA. Any ambiguity is resolved to permit compliance with HIPAA.
11. Contact
Smileline Technologies Ltd · Company 17408336 · 1 Lyric Square, London, England, W6 0NB · privacy@smileline.io