← Back to Platform

Business Associate Agreement

AIZA-HexTyx AI Red Team Security Platform
Effective Date: July 28, 2026  ·  Last Updated: July 28, 2026

This Business Associate Agreement ("BAA") is entered into between FAVZ Group ("AIZA", "Business Associate") and the covered entity or business associate identified in a signed Order Form or Statement of Work ("Customer", "Covered Entity") and is incorporated into the Master Services Agreement or Terms of Service between the parties.

This BAA is required when Customer uses the AIZA-HexTyx platform to scan, test, or process AI systems that handle Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations.

1. Definitions

Capitalised terms used but not defined in this BAA shall have the meanings set forth in HIPAA, the HITECH Act, and their implementing regulations at 45 CFR Parts 160 and 164.

2. Scope and Applicability

2.1 When This BAA Applies

This BAA applies only when the Customer's use of the AIZA-HexTyx platform involves scanning or testing AI systems that process, store, or transmit PHI or ePHI. If Customer does not handle PHI in connection with the Services, this BAA is not required.

2.2 Activation

This BAA becomes effective upon written execution by both parties (including electronic signature) and remains in force for the duration of the underlying service agreement. Customers on Pro or Enterprise plans may request execution by contacting enterprise@aiza.ai.

2.3 Scan Data Clarification

AIZA does not intentionally collect, store, or process PHI as part of its scanning methodology. The HexTyx scan engine analyses AI system behaviour, prompt responses, and security posture — not patient data. However, if a Customer's AI system inadvertently surfaces PHI during a security scan (e.g., through data exfiltration testing), that data may briefly transit AIZA infrastructure. This BAA governs the handling of any such incidental PHI.

3. Permitted Uses and Disclosures by AIZA

AIZA may use or disclose PHI only as follows:

AIZA shall not use or disclose PHI in any manner that would violate the HIPAA Privacy Rule if done by the Covered Entity, except as otherwise permitted by this BAA.

4. AIZA's Obligations

4.1 Safeguards

AIZA shall implement and maintain appropriate administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any ePHI that AIZA creates, receives, maintains, or transmits on behalf of Customer, in accordance with 45 CFR Part 164, Subpart C (Security Rule).

Current safeguards include: AES-256 encryption at rest (Fernet/MultiFernet), TLS 1.3 in transit, HMAC-based pseudonymisation of identifiers, field-level encryption for sensitive scan data, DuoVault architecture separating identity from scan data, and access controls limiting PHI access to authorised personnel only.

4.2 Prohibition on Unauthorised Use

AIZA shall not use or disclose PHI other than as permitted or required by this BAA or as required by law.

4.3 Sub-contractors and Sub-processors

AIZA shall ensure that any sub-contractor or agent to whom it provides PHI agrees in writing to the same restrictions and conditions that apply to AIZA under this BAA. Current sub-processors with access to Customer data are listed at legal/sub-processors.

4.4 Access to PHI

Within 30 days of a written request by Customer, AIZA shall make available PHI in a Designated Record Set to Customer, or to an individual designated by Customer, to the extent necessary for Customer to fulfil its access obligations under 45 CFR § 164.524.

4.5 Amendment of PHI

Within 60 days of a written request by Customer, AIZA shall make available for amendment PHI in a Designated Record Set and shall incorporate any amendments in accordance with 45 CFR § 164.526.

4.6 Accounting of Disclosures

AIZA shall document and make available to Customer, within 60 days of a written request, information required for Customer to make an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.

4.7 Minimum Necessary

AIZA shall request, use, and disclose only the minimum amount of PHI necessary to accomplish the purpose of the use or disclosure, in accordance with the HIPAA minimum necessary standard at 45 CFR § 164.502(b).

5. Security Incident and Breach Notification

5.1 Security Incidents

AIZA shall report to Customer any Security Incident of which AIZA becomes aware without unreasonable delay. Attempted but unsuccessful Security Incidents (such as pings, port scans, unsuccessful log-on attempts, and similar events) are a regular occurrence and will be reported in aggregate in our quarterly security reports rather than individually.

5.2 Breach Notification

AIZA shall notify Customer of any Breach of Unsecured PHI without unreasonable delay and in no case later than 72 hours after AIZA discovers the Breach. Notification shall include, to the extent possible:

5.3 Breach Notification Responsibilities

As Covered Entity, Customer is responsible for notifying affected individuals, the Secretary of Health and Human Services, and (when applicable) the media, as required by 45 CFR §§ 164.404, 164.406, and 164.408. AIZA will cooperate fully with Customer in fulfilling these obligations.

6. Customer's Obligations

Customer shall:

7. Term and Termination

7.1 Term

This BAA is effective as of the date of execution and shall remain in effect until the underlying service agreement between the parties is terminated, unless earlier terminated as provided herein.

7.2 Termination for Cause

Either party may terminate this BAA effective immediately upon written notice if the other party has materially breached a provision of this BAA and has not cured the breach within 30 days of written notice of such breach.

7.3 Effect of Termination

Upon termination of this BAA, AIZA shall, if feasible, return or destroy all PHI received from, or created or received on behalf of, Customer. If return or destruction is not feasible, AIZA shall extend the protections of this BAA to the PHI and limit further use or disclosure to those purposes that make the return or destruction of the PHI infeasible. AIZA's standard data retention and deletion procedures are documented in the Privacy Policy.

8. Miscellaneous

8.1 Amendment

This BAA may be amended by AIZA upon 30 days' written notice to Customer if AIZA reasonably determines that an amendment is necessary to comply with applicable law or regulation. Material amendments otherwise require written consent of both parties.

8.2 Interpretation

This BAA shall be interpreted as broadly as necessary to implement and comply with HIPAA. Any ambiguity in this BAA shall be resolved in favour of a meaning that permits Customer to comply with HIPAA.

8.3 Survival

The respective rights and obligations of AIZA under Section 7.3 (Effect of Termination) shall survive the termination of this BAA.

8.4 No Agency

Nothing in this BAA shall be construed to create an employment, partnership, joint venture, or agency relationship between the parties.

8.5 Governing Law

This BAA shall be governed by the laws of Wyoming, USA, without regard to its conflict of law provisions, and subject to the dispute resolution provisions of the underlying service agreement.

8.6 Execution

Customers requiring a signed BAA should contact enterprise@aiza.ai. AIZA offers electronic signature via DocuSign. Execution of an Order Form that incorporates this BAA by reference constitutes acceptance of its terms.

9. Contact

All BAA-related inquiries, notices, and requests should be directed to:

Trust Center Privacy Terms Acceptable Use