HIPAA · Legal

Business Associate Agreement

TinyGuard is a HIPAA Business Associate. This agreement governs how we create, receive, maintain, and transmit Protected Health Information on behalf of your facility. Document version: 1.2 — May 2026.

Encryption
TLS 1.2+ in transit
AES-256 at rest for all ePHI including video segments.
Breach Window
60-day notification
Per 45 CFR 164.410(b). We aim for initial notice within 30 days where feasible.
Audit Retention
6 years minimum
All PHI access logs retained per 45 CFR 164.530(j). Full export on request.
Subcontractors
8 listed, status per row
Cloudflare, Neon, Anthropic, OpenAI, Google (Gemini), Stripe, Resend, Twilio. Downstream BAA status disclosed in §3.3 — several in progress; we will not transmit PHI to a subprocessor without an executed BAA.
📋 How to get your signed BAA

Email del@tinyguard.co with your facility name and attorney contact. We return the executable BAA template within one business day. Founding Partners receive an executed BAA as part of their agreement package.

1. Purpose

TinyGuard LLC ("Business Associate") provides a cloud-based platform for facility management — video monitoring, attendance, care event logging, family communication, billing, EVV, and related services (the "Services"). Your facility ("Covered Entity") is a HIPAA Covered Entity.

In providing these Services, TinyGuard may create, receive, maintain, or transmit Protected Health Information ("PHI") on your behalf. This Agreement establishes the terms under which TinyGuard handles PHI in compliance with HIPAA, HITECH, and their implementing regulations at 45 CFR Parts 160 and 164.

2. PHI Categories

The following categories of PHI may be created, received, maintained, or transmitted by TinyGuard:

CategoryExamples
Health & care recordsMedication logs, immunization records, allergy info, dietary restrictions, special needs documentation
Incident & injury reportsAccident reports, injury documentation, behavioral incident records
Care event logsMeals, nap/sleep, diaper changes, daily care activities
Attendance recordsCheck-in/check-out times, guardian identity verification
Video recordingsOn-premises camera footage; cloud recordings when enabled
Daily reportsAI-generated care summaries shared with families
Messaging contentStaff-to-family communications regarding an individual's care
EVV recordsElectronic Visit Verification data for Medicaid-funded services

3. TinyGuard's Obligations

3.1 Permitted Uses

TinyGuard uses and discloses PHI only as permitted by this Agreement, as necessary to perform the Services, or as Required by Law. TinyGuard may use PHI for its proper management and administration only if the use is Required by Law or appropriate confidentiality assurances are obtained. TinyGuard may de-identify PHI per 45 CFR 164.514 and use de-identified data for product improvement and aggregate analytics.

3.2 Safeguards

TinyGuard implements administrative, physical, and technical safeguards that reasonably protect the confidentiality, integrity, and availability of ePHI per the HIPAA Security Rule (45 CFR Part 164, Subpart C), including:

3.3 Subcontractors

TinyGuard ensures that any subcontractor creating, receiving, maintaining, or transmitting PHI on TinyGuard's behalf agrees to the same restrictions via written agreement per 45 CFR 164.502(e)(1)(ii) and 164.314(a)(2). The "BAA Status" column below is the operative representation; we will not transmit PHI to a subprocessor marked "In progress" without an executed BAA in place at the time of transmission.

SubcontractorServicePHI ScopeBAA Status
Cloudflare, Inc.Edge compute (Workers), R2 object storage, Cloudflare Tunnel, Cloudflare Calls SFUAll ePHI stored/processed on Cloudflare infrastructure.In progress — Cloudflare BAA available on Enterprise plan; required before first HIPAA-regulated facility goes live.
Neon, Inc.Serverless PostgreSQL — primary system of recordAll platform data. Tenant isolation via Row-Level Security (PostgreSQL RLS, FORCE on every facility-scoped table).In progress — required before first HIPAA-regulated facility goes live.
Stripe, Inc.Subscription + tuition payment processingBilling identifiers and payment methods only. No clinical PHI.Available; PHI handling is limited to non-clinical billing identifiers.
Resend, Inc.Transactional emailEmail addresses + message content (daily reports, billing).In progress — required before first HIPAA-regulated facility goes live.
Anthropic, PBCClaude API — care summaries, daily reports, observation analysisCare summaries, incident analyses, and other AI content may contain child or resident names and care events. Zero Data Retention available on commercial enterprise terms.In progress — Anthropic offers BAA; required before any PHI traverses this provider in production.
OpenAI, L.L.C.Secondary AI provider for the same care-summary, daily-report, and observation flows when configured by TinyGuardSame PHI categories as Anthropic. Only one AI provider serves a given request.In progress — OpenAI Healthcare BAA via direct sales engagement; required before any PHI traverses this provider in production.
Google LLC (Gemini API)Tertiary AI provider for the same care-summary, daily-report, observation, and support-chat flows when configured by TinyGuardSame PHI categories as Anthropic. Only one AI provider serves a given request.In progress — Google Vertex AI BAA via Google Cloud Healthcare; the public Gemini API does not sign BAAs. TinyGuard will route PHI to Vertex AI only, never to the public Gemini API, once contracted.
Twilio, Inc.SMS notificationsPhone numbers + limited message text (e.g., pickup alerts).In progress — required before first HIPAA-regulated facility goes live.

TinyGuard provides 30 days' notice of material changes to this subcontractor list.

No biometrics, ever — locked as a standalone covenant in MSA §3 and reaffirmed in this BAA. No subprocessor receives video frames for biometric derivation; none of the AI providers above process biometric data on TinyGuard's behalf. See the full No-Biometrics Covenant and the broader Legal Stack v1.0 covenants page for the architectural commitments paired with this BAA.

3.4 Individual Rights

TinyGuard makes PHI available to Covered Entity to satisfy individuals' access rights (45 CFR 164.524), amendment rights (45 CFR 164.526), and accounting of disclosures (45 CFR 164.528). Facility administrators can export individual records through the platform at any time.

3.5 Minimum Necessary

TinyGuard limits its use, disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose per 45 CFR 164.502(b) and 164.514(d).

3.6 Data Retention

TinyGuard retains PHI for the duration of the Services agreement and, unless earlier destruction is requested, for a minimum of six (6) years from the date of creation or last effective date — consistent with 45 CFR 164.530(j). Video recordings follow the retention schedule you select within the platform (default: 30 days for cloud recordings; local recordings subject to device capacity).

4. Your Facility's Obligations

By granting TinyGuard the right to use anonymized camera footage under the Services agreement, your facility warrants that it has obtained all required consents from families, guardians, and residents under applicable law (including COPPA for children under 13 and applicable elder care statutes) before granting those rights.

5. Breach Notification

5.1 Timeline

TinyGuard notifies Covered Entity of a confirmed Breach of Unsecured PHI within 60 calendar days of discovery per 45 CFR 164.410(b). We aim to provide initial notification within 30 days where feasible.

5.2 Notification Contents

Notification includes: the nature of the Breach, types of PHI involved, identity of affected individuals (to the extent known), what TinyGuard is doing to investigate and mitigate, and contact information for our privacy contact: Gerald Delane Peck, del@tinyguard.co.

5.3 Cooperation

TinyGuard cooperates with Covered Entity in meeting HHS notification obligations under 45 CFR 164.404 and 164.408. Routine unsuccessful access attempts (port scans, failed logins) are not reportable Security Incidents; summary information is available on request.

6. Term and Termination

This Agreement runs concurrent with the underlying Services agreement. Either Party may terminate for material breach uncured within 30 calendar days of written notice.

On termination, TinyGuard returns or destroys all PHI at Covered Entity's election, including PHI held by subcontractors, unless retention is Required by Law. TinyGuard provides a full data export (CSV/JSON) within 30 days of written request before destruction. Obligations under this section survive termination.

7. General Provisions

Ready to sign?

Email us. BAA back the same day.

Send your facility name and attorney contact. We return the executable template within one business day.