Version 1.0 · Effective August 10, 2026

Sanasign Business Associate Agreement

Effective date: August 10, 2026

This Business Associate Agreement (this "BAA") is entered into between Sanasign, Inc. ("Business Associate") and the Organization accepting the Sanasign Healthcare Provider User Agreement (the "Underlying Agreement"), acting as a covered entity or as a business associate of a covered entity ("Customer"). This BAA is Exhibit A to, is incorporated into, and takes effect simultaneously with the Underlying Agreement upon Customer's acceptance. Customer and Business Associate are each a "Party."

Background. In providing the services described in the Underlying Agreement (the "Services"), Business Associate will create, receive, maintain, and transmit Protected Health Information from or on behalf of Customer. The Parties intend to comply with the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended, including by the HITECH Act and the Omnibus Final Rule (collectively, "HIPAA"), including 45 C.F.R. §§ 164.314(a), 164.502(e), and 164.504(e).

1. Definitions

Capitalized terms not defined in this BAA have the meanings given in HIPAA. References to C.F.R. sections mean those sections as in effect or amended.

1.1 "Breach," "Designated Record Set," "Individual," "Protected Health Information" ("PHI"), "Required by Law," "Secretary," "Security Incident," "Subcontractor," and "Unsecured PHI" have the meanings given in 45 C.F.R. Parts 160 and 164, with PHI limited to information created, received, maintained, or transmitted by Business Associate from or on behalf of Customer.

1.2 "Unsuccessful Security Incident" means an attempted but unsuccessful Security Incident, including pings and other broadcast attacks on firewalls, port scans, unsuccessful log-on attempts, denials of service, and similar routine events, in each case that does not result in unauthorized access to, or acquisition, use, or disclosure of, PHI.

2. Permitted Uses and Disclosures

2.1 To Provide the Services. Business Associate may use and disclose PHI to perform the Services for and on behalf of Customer as described in the Underlying Agreement — including creating, routing, displaying, and transmitting Documents to the recipients Customer designates, capturing signatures, maintaining audit trails, and generating Completion Packages — provided that such use or disclosure would not violate the Privacy Rule if done by Customer. Customer acknowledges that directing transmission of a Document to a recipient constitutes Customer's instruction to disclose the PHI in that Document to that recipient, and that Business Associate has no control over, and no responsibility for, the recipient's subsequent uses and disclosures.

2.2 Management and Administration. Business Associate may use PHI for its proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes if the disclosure is Required by Law or Business Associate obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of its confidentiality of which it becomes aware.

2.3 Data Aggregation. Business Associate may use and disclose PHI to provide data aggregation services relating to Customer's health care operations as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).

2.4 De-Identification. Business Associate may create de-identified information from PHI in accordance with 45 C.F.R. § 164.514(a)–(b), and may use and disclose such de-identified information to operate, evaluate, and improve its services (including developing and training automated features) and to produce aggregated benchmarks and statistics, in each case subject to the limitations in the Underlying Agreement, including the prohibition on the sale of identifiable data. Business Associate will not attempt to re-identify de-identified information.

2.5 Reporting Violations. Business Associate may use PHI to report violations of law to appropriate federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1).

2.6 Minimum Necessary. Business Associate will limit its uses, disclosures, and requests of PHI, to the extent practicable, to a limited data set or the minimum necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.514(d) and 42 U.S.C. § 17935(b).

2.7 No Other Uses. Business Associate will not use or disclose PHI other than as permitted or required by this BAA, the Underlying Agreement, or as Required by Law, and will not receive remuneration in exchange for PHI except as permitted by HIPAA.

3. Obligations of Business Associate

3.1 Safeguards. Business Associate will use appropriate safeguards to prevent use or disclosure of PHI other than as provided by this BAA, and will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI as required by the Security Rule, and will otherwise comply with the Security Rule with respect to electronic PHI. Business Associate will train its workforce members with access to PHI on their obligations.

3.2 Reporting. Business Associate will report to Customer: (a) any use or disclosure of PHI not provided for by this BAA of which it becomes aware; (b) any Security Incident of which it becomes aware, other than Unsuccessful Security Incidents; and (c) any Breach of Unsecured PHI as required by 45 C.F.R. § 164.410 — in each case without unreasonable delay, and in no event more than thirty (30) calendar days after discovery. This Section constitutes notice, and no further notice will be given, of the ongoing occurrence of Unsuccessful Security Incidents; reports regarding them are available on request. Breach notifications will include, to the extent known: the identity of each Individual whose Unsecured PHI was or is reasonably believed to have been involved; a description of what happened, the dates of the Breach and its discovery, and the types of information involved; steps Individuals should take to protect themselves; what Business Associate is doing to investigate, mitigate, and prevent recurrence; and the other particulars Customer needs for its notifications under 45 C.F.R. § 164.404.

3.3 Notification Cost Reimbursement. For a Breach of Unsecured PHI caused by Business Associate's violation of this BAA, Business Associate will reimburse Customer's reasonable, documented costs of providing the notifications required of Customer by 45 C.F.R. Part 164, Subpart D as a result of that Breach. This reimbursement obligation is subject to the limitation of liability in the Underlying Agreement.

3.4 Mitigation. Business Associate will take reasonable measures to mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this BAA.

3.5 Subcontractors. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions substantially the same as those that apply to Business Associate under this BAA, including implementation of reasonable and appropriate safeguards for electronic PHI. Other users and organizations on the Services are not Business Associate's Subcontractors.

3.6 Access. Business Associate will make PHI in a Designated Record Set available to Customer as necessary for Customer to meet its obligations under 45 C.F.R. § 164.524, within ten (10) business days of written request, including by making the Services and export functions available. If an Individual requests access directly from Business Associate, Business Associate will forward the request to Customer within ten (10) business days; responding to the Individual is Customer's sole responsibility.

3.7 Amendment. Business Associate will incorporate amendments to PHI in a Designated Record Set as directed or agreed by Customer pursuant to 45 C.F.R. § 164.526, within fifteen (15) business days of written request, including by making the Services available for Customer to make the amendment. If an Individual requests amendment directly from Business Associate, Business Associate will forward the request to Customer within ten (10) business days; responding is Customer's sole responsibility.

3.8 Accounting of Disclosures. Business Associate will document disclosures of PHI, and information related to them, as would be required for Customer to respond to a request for an accounting under 45 C.F.R. § 164.528 — including the date, the recipient's name and (if known) address, a brief description of the PHI, and the purpose — and will provide that information to Customer within twenty (20) business days of written request. If an Individual requests an accounting directly from Business Associate, Business Associate will forward the request to Customer within ten (10) business days.

3.9 Designated Record Set Scope. The Parties acknowledge that Customer's Designated Record Set within the Services consists of Documents transmitted for signature, executed Documents, and Completion Packages. Documents in unsent draft status that have not been transmitted to any recipient are working drafts and are not part of the Designated Record Set until sent.

3.10 Carrying Out Customer Obligations. To the extent Business Associate is to carry out one or more of Customer's obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Customer in the performance of those obligations.

3.11 Governmental Access. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA.

4. Obligations of Customer

4.1 Notices Affecting Use. Customer will notify Business Associate, at least fifteen (15) days before the effective date where practicable, of: (a) any limitation in Customer's notice of privacy practices under 45 C.F.R. § 164.520; (b) any change in or revocation of an Individual's permission to use or disclose PHI; and (c) any restriction on use or disclosure of PHI that Customer has agreed to under 45 C.F.R. § 164.522 — in each case to the extent it may affect Business Associate's use or disclosure of PHI. Customer will not agree to any restriction that materially impairs Business Associate's ability to perform the Services without the Parties' mutual written agreement on any necessary modifications.

4.2 Consents and Authorizations. Customer is responsible for obtaining any consent or authorization required by HIPAA or other applicable law before submitting PHI to the Services or directing its disclosure to any recipient, including consents required for specially protected information.

4.3 Permissible Requests. Customer will not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Customer, except as permitted for data aggregation and Business Associate's management and administration.

5. Term and Termination

5.1 Term. This BAA takes effect on acceptance of the Underlying Agreement and continues until all PHI is returned or destroyed, or protections are extended under Section 5.3.

5.2 Termination for Cause. On a Party's knowledge of a material breach of this BAA by the other Party, the non-breaching Party will give written notice describing the breach and a cure period of thirty (30) days. If the breach is not cured within that period, the non-breaching Party may terminate this BAA and the Underlying Agreement; if cure is not possible, the non-breaching Party may terminate immediately on written notice.

5.3 Effect of Termination. Following termination of the Underlying Agreement and the expiration of the sixty (60)-day data export window provided there, Business Associate will return or destroy all PHI received from or created or received on behalf of Customer, retaining no copies, including PHI held by its Subcontractors. If return or destruction is infeasible — including where retention is Required by Law or where PHI resides in routine backups pending scheduled destruction — Business Associate will notify Customer of the conditions making it infeasible, extend the protections of this BAA to the retained PHI, limit further uses and disclosures to the purposes that make return or destruction infeasible, and destroy the PHI when feasibility permits. Customer acknowledges that where Business Associate provides services to other organizations that lawfully hold copies of the same Documents (including a counterparty to a transmitted Document), Business Associate will continue to make those copies available to those organizations under its agreements with them.

6. Miscellaneous

6.1 Interpretation. Any ambiguity in this BAA will be resolved to permit the Parties to comply with HIPAA. A reference to a section of HIPAA means that section as in effect or amended.

6.2 Conflict. As to PHI, this BAA controls over any conflicting term of the Underlying Agreement, except that the limitation of liability in the Underlying Agreement applies to this BAA, including Section 3.3.

6.3 Amendment. The Parties will amend this BAA as necessary to comply with changes to HIPAA. Business Associate may amend this BAA on thirty (30) days' written notice to the extent necessary for compliance with law; if Customer reasonably objects that an amendment materially and adversely affects it beyond what compliance requires, and the Parties cannot agree within thirty (30) days, either Party may terminate the Underlying Agreement on written notice.

6.4 No Third-Party Beneficiaries. Nothing in this BAA confers any right or remedy on any person other than the Parties and their permitted successors and assigns.

6.5 Survival. Sections 3.3, 5.3, and 6 survive termination.

6.6 Notices. Notices under this BAA: to Business Associate, [email protected] or Sanasign, Inc., Attn: Privacy, at Sanasign's principal business address as published on the Site or on file with the California Secretary of State; to Customer, the notice address or account email under the Underlying Agreement.

6.7 Governing Law. This BAA is governed by the law governing the Underlying Agreement, and disputes under it are resolved as the Underlying Agreement provides.