ProductsPricingStoreCamerasCompareBlogSubscribe Get started → Book a Demo
HIPAA · Legal

Business Associate Agreement

TinyGuard is a HIPAA Business Associate. This agreement governs how we create, receive, maintain, and transmit Protected Health Information on behalf of your facility. Document version: 1.2 — May 2026.

Encryption
TLS 1.2+ in transit
AES-256 at rest for all ePHI including video segments.
Breach Window
60-day notification
Per 45 CFR 164.410(b). We aim for initial notice within 30 days where feasible.
Audit Retention
6 years minimum
All PHI access logs retained per 45 CFR 164.530(j). Full export on request.
Subcontractors
8 listed, status per row
Cloudflare, Neon, Anthropic, OpenAI, Google (Vertex AI), Stripe, Resend, Twilio. Downstream BAA status disclosed in §3.3. We do not transmit PHI to any subprocessor without an executed BAA in place — except Resend, which receives no PHI at all (notify-only email by design).
📋 How to get your signed BAA

Email del@tinyguard.co with your facility name and attorney contact. We return the executable BAA template within one business day. Founding Partners receive an executed BAA as part of their agreement package.

1. Purpose

TinyGuard LLC ("Business Associate") provides a cloud-based platform for facility management — video monitoring, attendance, care event logging, family communication, billing, EVV, and related services (the "Services"). Your facility ("Covered Entity") is a HIPAA Covered Entity.

In providing these Services, TinyGuard may create, receive, maintain, or transmit Protected Health Information ("PHI") on your behalf. This Agreement establishes the terms under which TinyGuard handles PHI in compliance with HIPAA, HITECH, and their implementing regulations at 45 CFR Parts 160 and 164.

2. PHI Categories

The following categories of PHI may be created, received, maintained, or transmitted by TinyGuard:

CategoryExamples
Health & care recordsMedication logs, immunization records, allergy info, dietary restrictions, special needs documentation
Incident & injury reportsAccident reports, injury documentation, behavioral incident records
Care event logsMeals, nap/sleep, diaper changes, daily care activities
Attendance recordsCheck-in/check-out times, guardian identity verification
Video recordingsOn-premises camera footage; cloud recordings when enabled
Daily reportsAI-generated care summaries shared with families
Messaging contentStaff-to-family communications regarding an individual's care
EVV recordsElectronic Visit Verification data for Medicaid-funded services

3. TinyGuard's Obligations

3.1 Permitted Uses

TinyGuard uses and discloses PHI only as permitted by this Agreement, as necessary to perform the Services, or as Required by Law. TinyGuard may use PHI for its proper management and administration only if the use is Required by Law or appropriate confidentiality assurances are obtained. TinyGuard may de-identify PHI per 45 CFR 164.514 and use de-identified data for product improvement and aggregate analytics.

3.2 Safeguards

TinyGuard implements administrative, physical, and technical safeguards that reasonably protect the confidentiality, integrity, and availability of ePHI per the HIPAA Security Rule (45 CFR Part 164, Subpart C), including:

  • Encryption: All PHI encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access controls: Role-based access with per-facility tenant isolation enforced on every database query.
  • Authentication: JWT-based auth with refresh-token rotation; reuse of a revoked token invalidates the entire family.
  • Audit logging: All PHI access logged with timestamps, user identity, and action taken.
  • On-premises video: Camera footage stays on your local network unless you opt into cloud recording.
  • Workforce training: TinyGuard personnel with PHI access receive HIPAA awareness training.

3.3 Subcontractors

TinyGuard ensures that any subcontractor creating, receiving, maintaining, or transmitting PHI on TinyGuard's behalf agrees to the same restrictions via written agreement per 45 CFR 164.502(e)(1)(ii) and 164.314(a)(2). The "BAA Status" column below is the operative representation; we will not transmit PHI to a subprocessor marked "In progress" without an executed BAA in place at the time of transmission.

SubcontractorServicePHI ScopeBAA Status
Cloudflare, Inc.Edge compute (Workers), R2 object storage, Cloudflare Tunnel, Cloudflare Calls SFUAll ePHI stored/processed on Cloudflare infrastructure.In progress — Cloudflare BAA available on Enterprise plan; required before first HIPAA-regulated facility goes live.
Neon, Inc.Serverless PostgreSQL — primary system of recordAll platform data. Tenant isolation via Row-Level Security (PostgreSQL RLS, FORCE on every facility-scoped table).In progress — required before first HIPAA-regulated facility goes live.
Stripe, Inc.Subscription + tuition payment processingBilling identifiers and payment methods only. No clinical PHI.Available; PHI handling is limited to non-clinical billing identifiers.
Resend, Inc.Transactional emailEmail addresses only; notify-only "log in to view" messages. No PHI (no care content, names, or clinical detail) in email payloads.No BAA — Resend does not sign HIPAA BAAs. Compliance is achieved by design: PHI is excluded from all email payloads (notify-only deep links), so no PHI is transmitted to Resend.
Anthropic, PBCClaude API — care summaries, daily reports, observation analysisCare summaries, incident analyses, and other AI content may contain child or resident names and care events. Zero Data Retention available on commercial enterprise terms.In progress — Anthropic offers BAA; required before any PHI traverses this provider in production.
OpenAI, L.L.C.Secondary AI provider for the same care-summary, daily-report, and observation flows when configured by TinyGuardSame PHI categories as Anthropic. Only one AI provider serves a given request.Available — OpenAI Healthcare BAA executed 2026-07-03; Zero Data Retention confirmed implemented by OpenAI for our organization on 2026-07-03. Under OpenAI's 2026-07-09 provisioning update, the BAA's Modified Retention safeguard may operate as Zero Data Retention or "Eyes Off" (content excluded from human review). PHI uses HIPAA-eligible endpoints only and is bound to the BAA organization.
Google LLC (Vertex AI)Tertiary AI provider for the same care-summary, daily-report, observation, and support-chat flows when configured by TinyGuardSame PHI categories as Anthropic. Only one AI provider serves a given request.Available — Google Cloud BAA accepted 2026-06-05 covering Vertex AI (a HIPAA-eligible service). PHI is routed only to BAA-covered providers (Google Vertex AI and OpenAI). Google retains limited abuse-monitoring logs under its BAA-covered Cloud terms; the public Gemini (AI Studio) API, which does not sign BAAs, is never used for PHI.
Twilio, Inc.SMS notificationsPhone numbers + limited message text (e.g., pickup alerts).In progress — required before first HIPAA-regulated facility goes live.

TinyGuard provides 30 days' notice of material changes to this subcontractor list.

No biometrics, ever — locked as a standalone covenant in MSA §3 and reaffirmed in this BAA. No subprocessor receives video frames for biometric derivation; none of the AI providers above process biometric data on TinyGuard's behalf. See the full No-Biometrics Covenant and the broader Legal Stack v1.0 covenants page for the architectural commitments paired with this BAA.

3.4 Individual Rights

TinyGuard makes PHI available to Covered Entity to satisfy individuals' access rights (45 CFR 164.524), amendment rights (45 CFR 164.526), and accounting of disclosures (45 CFR 164.528). Facility administrators can export individual records through the platform at any time.

3.5 Minimum Necessary

TinyGuard limits its use, disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose per 45 CFR 164.502(b) and 164.514(d).

3.6 Data Retention

TinyGuard retains PHI for the duration of the Services agreement and, unless earlier destruction is requested, for a minimum of six (6) years from the date of creation or last effective date — consistent with 45 CFR 164.530(j). Video recordings follow the retention schedule you select within the platform (default: 30 days for cloud recordings; local recordings subject to device capacity).

4. Your Facility's Obligations

  • Obtain all consents or authorizations required under applicable law before providing PHI to TinyGuard.
  • Notify TinyGuard of any restrictions on PHI use or disclosure agreed to with individuals.
  • Manage user access and permissions within the platform for your staff.
  • Ensure your own use of the platform complies with HIPAA and applicable state law.
  • Maintain physical security of on-premises Raspberry Pi devices and your network infrastructure.

By granting TinyGuard the right to use anonymized camera footage under the Services agreement, your facility warrants that it has obtained all required consents from families, guardians, and residents under applicable law (including COPPA for children under 13 and applicable elder care statutes) before granting those rights.

5. Breach Notification

5.1 Timeline

TinyGuard notifies Covered Entity of a confirmed Breach of Unsecured PHI within 60 calendar days of discovery per 45 CFR 164.410(b). We aim to provide initial notification within 30 days where feasible.

5.2 Notification Contents

Notification includes: the nature of the Breach, types of PHI involved, identity of affected individuals (to the extent known), what TinyGuard is doing to investigate and mitigate, and contact information for our privacy contact: Gerald Delane Peck, del@tinyguard.co.

5.3 Cooperation

TinyGuard cooperates with Covered Entity in meeting HHS notification obligations under 45 CFR 164.404 and 164.408. Routine unsuccessful access attempts (port scans, failed logins) are not reportable Security Incidents; summary information is available on request.

6. Term and Termination

This Agreement runs concurrent with the underlying Services agreement. Either Party may terminate for material breach uncured within 30 calendar days of written notice.

On termination, TinyGuard returns or destroys all PHI at Covered Entity's election, including PHI held by subcontractors, unless retention is Required by Law. TinyGuard provides a full data export (CSV/JSON) within 30 days of written request before destruction. Obligations under this section survive termination.

7. General Provisions

  • Regulatory references: All references to HIPAA/HITECH mean those provisions as currently in effect or amended.
  • Amendment: Parties amend this Agreement as necessary to comply with regulatory changes. Amendments must be in writing and signed by both Parties.
  • Governing law: Federal law (HIPAA/HITECH) governs. To the extent state law applies: State of Oregon, without regard to conflict-of-laws principles.
  • No third-party beneficiaries: Nothing in this Agreement confers rights on any person other than the Parties.
  • Entire agreement: This Agreement, together with the Services agreement, constitutes the entire understanding between the Parties regarding PHI handling.
Ready to sign?

Email us. BAA back the same day.

Send your facility name and attorney contact. We return the executable template within one business day.