AIZA-HexTyx AI Red Team Security Platform
Effective Date: July 28, 2026 · Last Updated: July 28, 2026
This Business Associate Agreement ("BAA") is entered into between FAVZ Group ("AIZA", "Business Associate") and the covered entity or business associate identified in a signed Order Form or Statement of Work ("Customer", "Covered Entity") and is incorporated into the Master Services Agreement or Terms of Service between the parties.
This BAA is required when Customer uses the AIZA-HexTyx platform to scan, test, or process AI systems that handle Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations.
Capitalised terms used but not defined in this BAA shall have the meanings set forth in HIPAA, the HITECH Act, and their implementing regulations at 45 CFR Parts 160 and 164.
This BAA applies only when the Customer's use of the AIZA-HexTyx platform involves scanning or testing AI systems that process, store, or transmit PHI or ePHI. If Customer does not handle PHI in connection with the Services, this BAA is not required.
This BAA becomes effective upon written execution by both parties (including electronic signature) and remains in force for the duration of the underlying service agreement. Customers on Pro or Enterprise plans may request execution by contacting enterprise@aiza.ai.
AIZA does not intentionally collect, store, or process PHI as part of its scanning methodology. The HexTyx scan engine analyses AI system behaviour, prompt responses, and security posture — not patient data. However, if a Customer's AI system inadvertently surfaces PHI during a security scan (e.g., through data exfiltration testing), that data may briefly transit AIZA infrastructure. This BAA governs the handling of any such incidental PHI.
AIZA may use or disclose PHI only as follows:
AIZA shall not use or disclose PHI in any manner that would violate the HIPAA Privacy Rule if done by the Covered Entity, except as otherwise permitted by this BAA.
AIZA shall implement and maintain appropriate administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any ePHI that AIZA creates, receives, maintains, or transmits on behalf of Customer, in accordance with 45 CFR Part 164, Subpart C (Security Rule).
Current safeguards include: AES-256 encryption at rest (Fernet/MultiFernet), TLS 1.3 in transit, HMAC-based pseudonymisation of identifiers, field-level encryption for sensitive scan data, DuoVault architecture separating identity from scan data, and access controls limiting PHI access to authorised personnel only.
AIZA shall not use or disclose PHI other than as permitted or required by this BAA or as required by law.
AIZA shall ensure that any sub-contractor or agent to whom it provides PHI agrees in writing to the same restrictions and conditions that apply to AIZA under this BAA. Current sub-processors with access to Customer data are listed at legal/sub-processors.
Within 30 days of a written request by Customer, AIZA shall make available PHI in a Designated Record Set to Customer, or to an individual designated by Customer, to the extent necessary for Customer to fulfil its access obligations under 45 CFR § 164.524.
Within 60 days of a written request by Customer, AIZA shall make available for amendment PHI in a Designated Record Set and shall incorporate any amendments in accordance with 45 CFR § 164.526.
AIZA shall document and make available to Customer, within 60 days of a written request, information required for Customer to make an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.
AIZA shall request, use, and disclose only the minimum amount of PHI necessary to accomplish the purpose of the use or disclosure, in accordance with the HIPAA minimum necessary standard at 45 CFR § 164.502(b).
AIZA shall report to Customer any Security Incident of which AIZA becomes aware without unreasonable delay. Attempted but unsuccessful Security Incidents (such as pings, port scans, unsuccessful log-on attempts, and similar events) are a regular occurrence and will be reported in aggregate in our quarterly security reports rather than individually.
AIZA shall notify Customer of any Breach of Unsecured PHI without unreasonable delay and in no case later than 72 hours after AIZA discovers the Breach. Notification shall include, to the extent possible:
As Covered Entity, Customer is responsible for notifying affected individuals, the Secretary of Health and Human Services, and (when applicable) the media, as required by 45 CFR §§ 164.404, 164.406, and 164.408. AIZA will cooperate fully with Customer in fulfilling these obligations.
Customer shall:
This BAA is effective as of the date of execution and shall remain in effect until the underlying service agreement between the parties is terminated, unless earlier terminated as provided herein.
Either party may terminate this BAA effective immediately upon written notice if the other party has materially breached a provision of this BAA and has not cured the breach within 30 days of written notice of such breach.
Upon termination of this BAA, AIZA shall, if feasible, return or destroy all PHI received from, or created or received on behalf of, Customer. If return or destruction is not feasible, AIZA shall extend the protections of this BAA to the PHI and limit further use or disclosure to those purposes that make the return or destruction of the PHI infeasible. AIZA's standard data retention and deletion procedures are documented in the Privacy Policy.
This BAA may be amended by AIZA upon 30 days' written notice to Customer if AIZA reasonably determines that an amendment is necessary to comply with applicable law or regulation. Material amendments otherwise require written consent of both parties.
This BAA shall be interpreted as broadly as necessary to implement and comply with HIPAA. Any ambiguity in this BAA shall be resolved in favour of a meaning that permits Customer to comply with HIPAA.
The respective rights and obligations of AIZA under Section 7.3 (Effect of Termination) shall survive the termination of this BAA.
Nothing in this BAA shall be construed to create an employment, partnership, joint venture, or agency relationship between the parties.
This BAA shall be governed by the laws of Wyoming, USA, without regard to its conflict of law provisions, and subject to the dispute resolution provisions of the underlying service agreement.
Customers requiring a signed BAA should contact enterprise@aiza.ai. AIZA offers electronic signature via DocuSign. Execution of an Order Form that incorporates this BAA by reference constitutes acceptance of its terms.
All BAA-related inquiries, notices, and requests should be directed to: