Finerified
  • How it works
  • Practices
  • Lenders
  • Free tools
  • Pricing
  • Contact
Lender portalSign inStart free →
← Legal
FinVerified, Inc.

Business Associate Agreement

Effective Date: June 22, 2026Last Updated: June 30, 2026

1. Purpose and Applicability

This Business Associate Agreement ("BAA") is entered into between FinVerified, Inc. ("Business Associate") and the dental practice, DSO, or healthcare organisation ("Covered Entity") that accesses the FinVerified Platform. This BAA is incorporated by reference into the Provider Service Agreement and governs the handling of Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the HITECH Act.

2. Definitions

Terms used but not defined in this BAA shall have the meanings ascribed to them in 45 C.F.R. Parts 160 and 164 (the HIPAA Rules). "Protected Health Information" or "PHI" means any individually identifiable health information transmitted or maintained by FinVerified on behalf of the Covered Entity.

3. Permitted Uses and Disclosures

FinVerified may use or disclose PHI only as necessary to perform the services described in the Provider Service Agreement, or as required by law. FinVerified shall not use or disclose PHI in a manner that would violate the requirements of the HIPAA Rules if done by the Covered Entity.

Important: FinVerified's diagnostic and scoring systems do not store or process PHI. Patient-level data within the Platform is identified only by anonymised session tokens (UUIDs). The BAA applies to any PHI that may be incidentally transmitted to FinVerified through evidence vault uploads or support communications.

4. Safeguards

FinVerified shall implement appropriate administrative, physical, and technical safeguards to prevent unauthorised use or disclosure of PHI, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Access controls limiting PHI access to authorised personnel only
  • Audit logging of all access to systems that may contain PHI
  • Annual security risk assessments
  • Employee HIPAA training requirements

5. Breach Notification

FinVerified shall notify the Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery of a Breach of Unsecured PHI. Notification shall include the information required by 45 C.F.R. § 164.410.

6. Subcontractors

FinVerified shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of FinVerified agrees to restrictions and conditions at least as stringent as those in this BAA. FinVerified maintains BAAs with all approved vendors that may access PHI, including AWS (cloud infrastructure) and Anthropic (AI services).

7. Individual Rights

To the extent FinVerified maintains a Designated Record Set on behalf of the Covered Entity, FinVerified shall make PHI available to the Covered Entity as necessary to fulfil the Covered Entity's obligations to provide individuals access to their PHI under 45 C.F.R. § 164.524.

8. Term and Termination

This BAA remains in effect for the duration of the Provider Service Agreement. Upon termination, FinVerified shall, at the Covered Entity's election, return or destroy all PHI it maintains in any form. Where return or destruction is not feasible, FinVerified shall extend the protections of this BAA to the PHI and limit further uses and disclosures.

9. Contact

For HIPAA-related enquiries or breach reporting, contact:

FinVerified Privacy Officer

privacy@finverified.ai

Finerified

The compliance, conversion, and fraud-prevention layer for the patient payment pathway. Payment Pathway Compliance™.

SOC 2 Type I in progress · HIPAA

Platform

How it worksFree toolsPricingCompliance check

Who it's for

Practices & DSOsLendersBecome a partner →

Get started

Practice sign inLender portalStart free trialFree assessmentContact us

© 2026 FinVerified, Inc. · Payment Pathway Compliance™

  • Privacy Policy
  • ·Terms of Service
  • ·SMS Terms
  • ·Patient Terms
  • ·HIPAA Notice
  • ·Provider Agreement
  • ·Lender Agreement
  • ·Cookie Policy
  • ·Acceptable Use
  • ·Subprocessors