Business Associate Agreement
Last updated June 23, 2026
Hearing care is healthcare, and the records in MintClinic are protected health information (PHI) under HIPAA. When your clinic uses MintClinic, your clinic is the Covered Entity and Mintpath is your Business Associate. A signed Business Associate Agreement (BAA) is completed before any workspace may be used with PHI and governs how we handle that information. This page summarizes its key terms.
Permitted uses of PHI
We use and disclose PHI only to provide and support the MintClinic service for your clinic, as permitted by the BAA and required by law. We never sell PHI and never use it for advertising or our own purposes.
Safeguards
- Technical: per-tenant row-level isolation, TLS with verified certificates in transit, AES-256 encryption at rest, multi-factor authentication, and least-privilege access.
- Administrative: access reviews, secrets management, and an immutable, hash-linked audit log of access to clinical records.
- Physical: PHI is hosted with infrastructure providers that maintain SOC 2 / ISO 27001-aligned physical controls.
Subcontractors
We require any subcontractor that handles PHI on our behalf to agree in writing to restrictions and conditions at least as protective as those in our BAA.
Breach notification
We will report any use or disclosure not permitted by the BAA, and any breach of unsecured PHI, to your clinic without unreasonable delay and as required by HIPAA, with the information needed for your clinic to meet its notification obligations.
Access, amendment, and accounting
We will make PHI available so your clinic can meet its HIPAA obligations to provide individuals access to their records, to amend records, and to account for disclosures.
Return or destruction on termination
On termination of your account, we will, at your clinic’s direction, return or securely destroy the PHI we maintain, except where retention is required by law.
How to execute a BAA
A countersigned BAA is provided as part of onboarding for any workspace approved to handle PHI, including approved pilot accounts. To request a copy, review redlines, or use your own paper, contact baa@mintpath.ai.
HIPAA references
This BAA is designed to satisfy the requirements of 45 C.F.R. §§ 164.502(e), 164.504(e), and the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C).
This page summarizes our standard BAA for transparency and is not itself the agreement or legal advice. The executed BAA between your clinic and Mintpath controls and prevails over this summary.