Business Associate Agreement

This Business Associate Agreement ("Agreement") is entered into by and between Fax Pigeon LLC, an Illinois limited liability company ("Business Associate"), and the individual or entity that accepts this Agreement electronically through the Service ("Covered Entity").

This Agreement supplements and is incorporated into the Terms of Service published at faxpigeon.com/terms ("Terms"). Capitalized terms used but not defined in this Agreement have the meanings ascribed to them in the Terms or in the HIPAA Rules (as defined below).

By accepting this Agreement electronically through the Service, the individual accepting on behalf of Covered Entity represents and warrants that such individual has the authority to bind Covered Entity to the terms of this Agreement, has read this Agreement in its entirety, and agrees to be bound by its terms on behalf of Covered Entity.


1. Definitions

1.1 "Breach" has the meaning given to such term in 45 CFR § 164.402.

1.2 "Business Associate" means Fax Pigeon LLC.

1.3 "Covered Entity" means the individual or entity that accepts this Agreement and uses the Service.

1.3(a) "Covered Entity Name Change" means a change to Covered Entity's trade or operating name where the underlying legal entity that accepted this Agreement remains the same. Covered Entity may update its trade name through the Service settings. Such a change does not require new acceptance of this Agreement, does not alter the rights or obligations of either party, and does not affect the validity of the original acceptance record described in Section 7(i). The change is captured in the Service's audit log.

1.3(b) "Customer Data" means the fax documents and associated content that Covered Entity uploads to, transmits through, receives through, or generates in the Service, including Protected Health Information contained therein. De-identified information created under Section 4(j) is not Customer Data.

1.4 "Designated Record Set" has the meaning given to such term in 45 CFR § 164.501.

1.5 "Electronic Protected Health Information" or "ePHI" means Protected Health Information that is transmitted by or maintained in electronic media, as defined in 45 CFR § 160.103.

1.6 "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended from time to time, including amendments made by the Health Information Technology for Economic and Clinical Health Act ("HITECH Act").

1.7 "Individual" has the meaning given to such term in 45 CFR § 160.103 and includes a person who qualifies as a personal representative in accordance with 45 CFR § 164.502(g).

1.8 "Protected Health Information" or "PHI" means individually identifiable health information, as defined in 45 CFR § 160.103, that is within Covered Entity's data and to which Business Associate has access through the Service.

1.9 "Required by Law" has the meaning given to such term in 45 CFR § 164.103.

1.10 "Secretary" means the Secretary of the United States Department of Health and Human Services or the Secretary's designee.

1.11 "Security Incident" has the meaning given to such term in 45 CFR § 164.304.

1.12 "Service" means the cloud fax platform operated by Business Associate at faxpigeon.com and all associated features, functionality, and services.

1.13 "Subcontractor" has the meaning given to such term in 45 CFR § 160.103.

1.14 "Unsecured Protected Health Information" means Protected Health Information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in guidance issued under 42 U.S.C. § 17932(h)(2).


2. Scope

2.1 This Agreement applies to the extent that Covered Entity uses the Service to create, receive, maintain, or transmit PHI.

2.2 This Agreement does not apply to data that is outside the Service or that has not been submitted to or generated through the Service.

2.3 This Agreement does not apply to information that has been de-identified in accordance with 45 CFR § 164.514(a)-(c).


3. Obligations of Business Associate

(a) Use and Disclosure. Business Associate shall not use or disclose PHI except as permitted or required by this Agreement, the Terms, or as Required by Law.

(b) Safeguards. Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI, in compliance with Subpart C of 45 CFR Part 164 (the HIPAA Security Rule). Such safeguards include, without limitation:

  • Encryption of ePHI in transit using Transport Layer Security (TLS) version 1.2 or higher on every application connection;
  • Encryption of ePHI at rest using Advanced Encryption Standard (AES) with 256-bit keys;
  • Authentication and access controls, including automatic session termination after a period of inactivity;
  • Append-only audit logging of access to and actions upon ePHI;
  • Role-based access controls; and
  • Diagnostic and error logs are kept within Business Associate's HIPAA-covered cloud infrastructure, are designed and operated to minimize and exclude PHI, and are never transmitted to any error-monitoring or analytics system that is not covered by a business associate agreement.

(c) Reporting and Breach Notification. Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, without unreasonable delay. Business Associate shall report to Covered Entity any Breach of Unsecured Protected Health Information of which Business Associate becomes aware, without unreasonable delay and in no event later than thirty (30) calendar days after discovery of the Breach. The notification shall include, to the extent reasonably available:

  • A description of the nature of the Breach, including the types of PHI involved;
  • The date of the Breach and the date of its discovery;
  • A description of the steps Business Associate has taken or will take to investigate the Breach, mitigate harm, and protect against further Breaches; and
  • Any other information that Covered Entity is required to include in its notification to affected Individuals under 45 CFR § 164.404(c).

The parties acknowledge that routine unsuccessful attempts at unauthorized access, use, disclosure, modification, or destruction of ePHI (including, but not limited to, pings, port scans, unsuccessful login attempts, denial-of-service attacks, and malware that does not result in unauthorized access) do not constitute Security Incidents or Breaches requiring individual notification under this Agreement, and this sentence serves as notice of such unsuccessful attempts. Business Associate shall report any successful Security Incident that results in unauthorized access to, use of, or disclosure of ePHI in accordance with this Section 3(c).

(d) Subcontractors. Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such PHI under this Agreement. Business Associate shall remain responsible for the acts and omissions of its Subcontractors to the same extent as if such acts or omissions were its own.

For the transmission of faxes, Business Associate uses a third-party telecommunications carrier. Business Associate operates its own fax transmission and reception systems and performs the fax protocol at both ends of every call. No fax document is handed to the carrier as a file in either direction: fax pages exist on the carrier's network only for the duration of a call, so the carrier holds no fax media to store. On that fact pattern of transient transmission without storage, Business Associate has determined that the carrier acts as a transmission conduit within the meaning of 45 CFR § 160.103 and is therefore not a Subcontractor under this Section 3(d). Business Associate maintains the durable record of each fax within its own HIPAA-covered cloud infrastructure at all times. If Business Associate's transmission arrangements ever change such that a carrier receives, stores, or retains fax media, Business Associate will engage that carrier as a Subcontractor subject to this Section 3(d).

For documents Covered Entity submits by email for faxing (Section 4(a)(i)), Business Associate uses an email-receiving service operated by Amazon Web Services, which receives the email over an encrypted connection and holds it, encrypted, only until Business Associate creates the fax, when it is deleted; any copy a fault leaves behind is removed by an automatic expiry rule within two (2) days of arrival. Amazon Web Services creates, receives, and maintains PHI on behalf of Business Associate for that purpose and is a Subcontractor under this Section 3(d), engaged under a business associate agreement between Business Associate and Amazon Web Services. Email that Business Associate sends to Covered Entity never contains PHI.

(e) Access to PHI. Business Associate shall make PHI maintained in the Service available to Covered Entity through the Service dashboard, in a form and format that reasonably enables Covered Entity to fulfill its obligations under 45 CFR § 164.524 (Individual right of access). Business Associate does not maintain a Designated Record Set on behalf of Covered Entity, and Covered Entity remains responsible under 45 CFR § 164.524 for responding to Individual access requests. Separately and as a service feature, Business Associate provides Covered Entity the export, access, and destruction capabilities described in Section 3(j); that service-feature access right is a contractual convenience provided by Business Associate and is distinct from, and does not enlarge, either party's obligations with respect to a Designated Record Set under 45 CFR § 164.524.

(f) Amendment of PHI. Business Associate shall make PHI available for amendment to the extent feasible through the Service, and shall incorporate any amendments to PHI as directed by Covered Entity, to the extent required by 45 CFR § 164.526. Fax documents stored in the Service are retained as transmitted and are not content-modifiable by Business Associate. If Covered Entity receives a request for amendment of PHI contained in fax documents, Covered Entity may contact Business Associate for assistance.

(g) Accounting of Disclosures. Business Associate shall maintain and make available to Covered Entity information required to provide an accounting of disclosures as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.528. Such information is maintained in the Service's audit log system.

(h) Compliance with Subpart E. To the extent that Business Associate carries out any obligation of Covered Entity under Subpart E of 45 CFR Part 164 (the HIPAA Privacy Rule), Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation.

(i) Availability to HHS. Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules, to the extent required by law.

(j) Export, Access, and Destruction (Service-Feature Access Right). As a feature of the Service, and separate from the Designated Record Set allocation in Section 3(e), Business Associate provides Covered Entity the following capabilities with respect to PHI maintained in the Service: (i) Covered Entity may download individual fax documents through the Service at any time, on every account tier, and paid accounts may also generate a bulk export of their PHI and associated data through the Service; (ii) for paid accounts, Covered Entity may also request an administrator-assisted export from Business Associate, including after a subscription has ended, where Covered Entity is unable to access the Service, or where the volume of data exceeds what self-serve export can deliver; free evaluation accounts may likewise generate a bulk export of their records through the Service, and per-record download and the post-closure request process described in clause (iii) remain available in addition; (iii) after a subscription has ended, Covered Entity may request access to, an export of, or destruction of any PHI Business Associate still maintains, and Business Associate will verify the requester's identity before fulfilling any such request and will deliver any exported PHI only through a secure, time-limited link and never to an unverified requester; and (iv) Business Associate will not condition, delay, or deny export of, access to, return of, or destruction of PHI on the basis of any payment dispute. Where Covered Entity requests destruction of more than a single fax document under this Section or Section 6(c) (a selection of records, an account's whole set of records, a practice, or an account), the affected PHI is first scheduled for destruction and held for a seven (7) day recovery window, so that an accidental or premature deletion can be undone at Covered Entity's request. Deletion of a single fax document is performed immediately upon an explicit confirmation and cannot be undone. After that window closes, destruction is completed permanently as provided in Section 6(c)(iii).


4. Permitted Uses and Disclosures

(a) Service Operations. Business Associate may use or disclose PHI solely as necessary to perform the following services on behalf of Covered Entity:

(i) Transmitting outbound faxes, including documents Covered Entity submits by email to the Service's fax addresses, and receiving inbound faxes;

(ii) Storing fax documents and associated metadata;

(iii) Generating cover sheets incorporating Covered Entity's information;

(iv) Merging electronic signatures onto documents at Covered Entity's direction;

(v) Generating structured annotations from inbound fax content, including automated document-type classification, summarization, and metadata extraction, to help Covered Entity organize and review its incoming faxes, in each case for Covered Entity's own use and using the safeguards described in Section 3(b);

(vi) Generating delivery confirmation records and proof-of-delivery certificates;

(vii) Maintaining contact records associated with Covered Entity's account;

(viii) Maintaining audit logs for compliance and security purposes; and

(ix) Any other function necessary for the operation of the Service as described in the Terms.

(b) Required by Law. Business Associate may use or disclose PHI as Required by Law.

(c) Minimum Necessary. Business Associate agrees to limit its use and disclosure of PHI to the minimum necessary to accomplish the intended purpose of such use or disclosure, consistent with 45 CFR § 164.502(b).

(d) Consistency with Covered Entity's Obligations. Business Associate shall not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as expressly permitted by this Agreement.

(e) Proper Management and Administration. Business Associate may use PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate.

(f) Disclosure for Management and Administration. Business Associate may disclose PHI for the proper management and administration of Business Associate, provided that (i) such disclosure is Required by Law, or (ii) Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and that the person will notify Business Associate of any instances of which it is aware that the confidentiality of the information has been breached.

(g) Prohibition on Sale of PHI. Business Associate shall not directly or indirectly receive remuneration in exchange for PHI, except as permitted by 45 CFR § 164.502(a)(5)(ii).

(h) Prohibition on Marketing Use. Business Associate shall not use or disclose PHI for marketing purposes as defined by 45 CFR § 164.501.

(i) Prohibition on Training Use. Business Associate does not use identifiable Protected Health Information to train, improve, or develop any machine-learning or artificial-intelligence model, and does not permit any Subcontractor or service provider to use it for that purpose. Automated document analysis, as described in Section 4(a)(v), processes fax content solely to generate classifications and summaries for Covered Entity's use, using the safeguards described in Section 3(b). Nothing in this Section limits Business Associate's creation or use of de-identified information as permitted by Section 4(j) and Section 2.3.

(j) De-Identification. Business Associate may use Protected Health Information to create de-identified information pursuant to 45 CFR § 164.502(d) and § 164.514(a)-(c), including by the Safe Harbor method of § 164.514(b)(2) and the Expert Determination method of § 164.514(b)(1). The creation of de-identified information is a permitted use under this Agreement. Information so de-identified is no longer Protected Health Information and, as provided in Section 2.3, is not subject to this Agreement.

(k) De-Identified Information; Ownership and Re-Identification. Information de-identified under Section 4(j) in accordance with 45 CFR § 164.514 is not Customer Data and is not Covered Entity's Protected Health Information. Business Associate uses de-identified information solely to operate, analyze, improve, and develop the Service, and does not sell, license, or otherwise disclose it to any third party. Any re-identification code or mechanism Business Associate may maintain in accordance with 45 CFR § 164.514(c) is retained by Business Associate alone, is kept confidential, and is used for no other purpose; any information Business Associate re-identifies is again Protected Health Information subject to this Agreement, as provided in 45 CFR § 164.502(d)(2)(ii). Business Associate retains all intellectual-property rights in de-identified and aggregated data, and such rights survive termination of this Agreement and any return or destruction of the underlying Protected Health Information.

5. Obligations of Covered Entity

(a) Covered Entity shall not request that Business Associate use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as expressly permitted by this Agreement.

(b) Covered Entity shall notify Business Associate of any restrictions on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR § 164.522, to the extent that such restrictions may affect Business Associate's use or disclosure of PHI.

(c) Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.

(d) Covered Entity controls and is solely responsible for the accuracy of recipient fax numbers and for directing each transmission to the intended recipient. Because Business Associate transmits faxes to the numbers Covered Entity provides, Business Associate is not responsible for any disclosure of PHI that results from a transmission Covered Entity directs to an incorrect fax number.

(e) Covered Entity is responsible for determining whether its use of the Service, including the automated document analysis features described in Section 4(a)(v), is consistent with Covered Entity's own HIPAA policies and procedures. Business Associate provides the technical capabilities of the Service; Covered Entity is responsible for determining the lawfulness of its own use of those capabilities.

(f) The Service processes all fax documents uniformly regardless of content. Covered Entity is solely responsible for compliance with any laws or regulations imposing requirements beyond HIPAA with respect to specific categories of health information transmitted through the Service, including but not limited to 42 CFR Part 2.

(g) Records Retention; Export Before Deletion. Covered Entity is solely responsible for determining and satisfying its own medical-record and legal retention obligations, and Business Associate is not the system of record for those duties. Because Covered Entity's records remain available to export at any time, Covered Entity is encouraged to export its data before requesting deletion, and Covered Entity should note that its state law may require records to be retained for a minimum period.

(h) Email to Fax. When Covered Entity's workforce submits a document for faxing by email, the email travels through Covered Entity's own email provider before it reaches Business Associate. Business Associate receives it over an encrypted connection and treats it as PHI from arrival. The leg before Business Associate's door is Covered Entity's: Covered Entity is responsible for sending PHI by email only from an email service it has covered with its own business associate agreement, or for submitting the document through the Service instead.


6. Term and Termination

(a) Term. This Agreement is effective upon Covered Entity's electronic acceptance and shall remain in effect for the duration of Covered Entity's account with Business Associate.

(a)(i) Continuity of Coverage. The acceptance of this Agreement recorded for a subscribing entity remains in force for that entity for the duration of the entity's account, including across: (A) changes to the entity's subscription plan; (B) changes to the entity's billing cycle; (C) changes to the entity's trade or operating name, provided the underlying legal entity that accepted this Agreement remains the same; and (D) periods of subscription inactivity during which the entity remains a registered user of the Service. Where Covered Entity establishes a separate practice through the Service, a distinct acceptance of this Agreement is recorded for that organization, naming the organization as the Covered Entity, and the personal acceptance previously recorded for the Owner remains in force without lapse. The acceptance recorded under this Agreement is bound to the identity of the party that accepted it (the Covered Entity, acting through the natural person designated as its Owner), and remains bound to that identity notwithstanding any change in the Covered Entity's subscription plan or billing cycle; a plan change does not terminate, re-paper, or require re-acceptance of this Agreement, and the original acceptance record described in Section 7(i) continues to govern. For any updated version of this Agreement, Business Associate will provide the notice described in Section 7(b), and Covered Entity's continued use of the Service after the effective date constitutes acceptance of the updated version.

(a)(ii) Survival After Subscription End; Deletion Destroys. This Agreement remains in effect for so long as Business Associate creates, receives, maintains, or transmits Protected Health Information on behalf of Covered Entity, notwithstanding suspension, downgrade, cancellation, or non-renewal of the underlying subscription. After a subscription ends, Business Associate retains Protected Health Information on an indefinite basis solely to (i) preserve Covered Entity's historical records for later retrieval, (ii) comply with Covered Entity's documented retention or legal-hold instructions, and (iii) satisfy applicable law, and for no other purpose, until Covered Entity requests its return or destruction under Section 6(c). Deletion of the account is a request for the destruction of all of the account's Protected Health Information: it immediately revokes Covered Entity's access credentials, active sessions, and ability to log in, and destruction is carried out as provided in Section 6(c)(iii), including the seven (7) day recovery window.

(b) Termination for Cause. Either party may terminate this Agreement if the other party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) days after receiving written notice of the breach. Covered Entity may cancel its subscription at any time through the Service, after which Business Associate retains Protected Health Information as provided in Section 6(a)(ii), or may delete its account, which is a request for destruction carried out under Section 6(c)(iii). Non-payment, billing suspension, or any payment dispute shall not trigger a lockout of Covered Entity's access to, export of, return of, or destruction of stored Protected Health Information; only the sending of faxes may be suspended for non-payment.

(c) Obligations Upon Termination. Upon termination of Covered Entity's account, Business Associate shall:

(i) For free evaluation accounts not deleted by Covered Entity: retain PHI in a read-only state, accessible solely to Covered Entity, on an indefinite basis until Covered Entity requests its return or destruction, solely for the archival, retrieval, legal-hold, and compliance purposes stated in Section 6(a)(ii), and subject to the safeguards of Section 3(b); Business Associate does not destroy free-evaluation PHI on any fixed schedule;

(ii) For paid accounts canceled but not deleted: retain PHI in a read-only state, accessible solely to Covered Entity, on an indefinite basis so that Covered Entity may retrieve its historical records, there is no automatic deletion and no fixed retention period after cancellation, until Covered Entity requests its return or destruction. Such retained PHI is held solely for the archival, retrieval, legal-hold, and compliance purposes stated in Section 6(a)(ii), and for no other purpose, subject to the safeguards of Section 3(b). Covered Entity may export or request destruction of its records at any time. Non-PHI metadata may be retained for legal compliance purposes;

(ii)(A) For practices with members other than the Owner whose subscription has ended without account deletion (by cancellation, by an immediate end, or otherwise): PHI stored under that practice shall be retained on an indefinite basis in a read-only state, accessible solely to the natural person who is the practice's Owner at the moment the subscription ends, solely for the archival, retrieval, legal-hold, and compliance purposes stated in Section 6(a)(ii), and for no other purpose. The archive is provided as a continuing-access convenience to enable Owner-managed record retrieval. Such retained PHI shall remain subject to the safeguards described in Section 3(b). The Owner may export or direct Business Associate to destroy such retained PHI at any time, and destruction shall occur upon (1) explicit account deletion by the Owner; or (2) explicit request for destruction submitted by the Owner to Business Associate. Workforce members of the practice do not retain access to such retained PHI through the Service following their removal;

(iii) Upon Covered Entity's request for return or destruction of PHI, whether a request to destroy specific records, a request to destroy all of an account's data, deletion of the account itself, or a request submitted to Business Associate, return or destroy the PHI within the scope of that request, if feasible, as provided in the remainder of this Section; where return or destruction is not feasible, extend the protections of this Agreement to such PHI and limit further use and disclosure to those purposes that make return or destruction infeasible. The scope of a destruction request is fixed at the time the request is made and comprises only the Protected Health Information identified in that request; Protected Health Information created after a request is made is not within that request and is not destroyed by it. Upon a request for destruction of more than a single fax document, the Protected Health Information within the scope of the request is scheduled for destruction and held for a seven (7) day recovery window, during which the deletion may be undone at Covered Entity's request, whether by the Owner or by Business Associate acting on the Owner's behalf; destruction of a single fax document is performed immediately upon an explicit confirmation and cannot be undone. After the recovery window closes, Business Associate permanently destroys the live, production copy of the Protected Health Information within the scope of the request, and the record is rendered beyond use. Any residual copies that persist in Business Associate's short-term, disaster-recovery backups are not used or restored for any purpose other than disaster recovery and age out of those backups automatically within ninety (90) days. A record of the fact of destruction is retained in the audit log. Following such a request, Business Associate shall not thereafter create new de-identified information from the specific Protected Health Information subject to that request. Business Associate shall not condition, delay, or deny return, destruction, or Covered Entity's access to PHI on the basis of any payment dispute;

(iv) Continue to apply appropriate safeguards to any PHI retained pursuant to this Section 6(c) for the duration of such retention;

(v) Not use retained PHI for any purpose other than the purposes for which such retention is authorized under this Section 6(c), except that Business Associate may use retained PHI to create de-identified information as permitted by Section 4(j), subject to the limitation in Section 6(c)(iii) for Protected Health Information that is subject to a request for return or destruction; and

(vi) Destroy retained PHI when retention is no longer necessary to fulfill the purposes described in this Section 6(c).

(d) Survival. The obligations of Business Associate under Sections 3(b) (Safeguards), 3(c) (Breach Notification), 3(g) (Accounting of Disclosures), 3(i) (Availability to HHS), 4(j) (De-Identification), 4(k) (De-Identified Information; Ownership and Re-Identification), and this Section 6 shall survive the termination or expiration of this Agreement to the extent that Business Associate retains any PHI or any de-identified information derived from it.

(e) Survival of De-Identified Information. Destruction or return of Protected Health Information under this Section does not require the destruction of de-identified information previously and lawfully derived from it in accordance with Section 4(j). De-identified information survives termination of this Agreement and any return or destruction of the underlying Protected Health Information.

(f) No Access Lockout for Non-Payment. Non-payment, billing suspension, or any payment dispute shall not trigger a lockout of Covered Entity's access to, export of, return of, or destruction of stored Protected Health Information; only the sending of faxes may be suspended for non-payment.


7. Miscellaneous

(a) Regulatory References. Any reference in this Agreement to a section of the HIPAA Rules means the section as in effect or as amended from time to time, and for which compliance is required.

(b) Amendment. Business Associate may update this Agreement from time to time to comply with changes in the HIPAA Rules or for other lawful purposes. Material changes will be communicated by email at least thirty (30) days before the effective date of the revised Agreement. Covered Entity's continued use of the Service after the effective date of any update constitutes acceptance of the updated Agreement. A change in Covered Entity's subscription plan is not, by itself, a material amendment of this Agreement and does not require new acceptance, as provided in Section 6(a)(i).

(c) Interpretation. Any ambiguity in this Agreement shall be resolved to permit Business Associate and Covered Entity to comply with the HIPAA Rules.

(d) Conflict. In the event of any conflict between the provisions of this Agreement and the Terms with respect to the use, disclosure, protection, or handling of PHI, the provisions of this Agreement shall control.

(e) Governing Law. This Agreement shall be governed by the laws of the State of Illinois, without regard to conflict of law principles, except to the extent preempted by the HIPAA Rules or other applicable federal law.

(f) No Third-Party Beneficiaries. Nothing in this Agreement confers any right, remedy, or claim upon any person or entity other than Business Associate and Covered Entity.

(g) Entire Agreement. This Agreement, together with the Terms and the Privacy Policy, constitutes the entire agreement between Business Associate and Covered Entity with respect to the subject matter hereof and supersedes all prior oral and written agreements, understandings, and communications regarding such subject matter.

(h) Dispute Resolution. Any dispute arising out of or relating to this Agreement shall be resolved in accordance with the dispute resolution provisions set forth in Section 16 of the Terms of Service, which are incorporated herein by reference for this purpose. The dispute definition in Section 16.1 of the Terms expressly includes disputes arising out of or relating to this Agreement.

(i) Acceptance Record. Business Associate records the following information upon Covered Entity's acceptance of this Agreement: the name and professional title of the individual accepting on behalf of Covered Entity, the name of the Covered Entity, the version of this Agreement accepted, a timestamp of the acceptance, the account identifier, and the IP address from which the acceptance was submitted. This acceptance record is maintained as part of Covered Entity's account for evidentiary and compliance purposes.

(j) Encrypted Data and Breach Determination. The parties acknowledge that a breach of data that has been encrypted in a manner that renders PHI unusable, unreadable, or indecipherable to unauthorized persons, where the encryption key has not been compromised, may not constitute a Breach of Unsecured Protected Health Information requiring notification under this Agreement, consistent with the breach notification guidance issued by the Secretary pursuant to 42 U.S.C. § 17932(h)(2). Business Associate maintains encryption of ePHI at rest using AES-256 and, on every application connection, in transit using TLS 1.2 or higher. Fax transmission itself takes place over telephone networks, including the network segment between Business Associate's transmission systems and the carrier; fax content exists on those networks only for the duration of a call, is not TLS-encapsulated there, and no fax document is handed to the carrier to store. This Section does not relieve either party of any obligation to conduct a risk assessment to determine whether a Breach has occurred, as required by 45 CFR § 164.402.


8. Contact

Business Associate: Fax Pigeon LLC 211 W. Wacker Drive, Ste 120, PMB 2449, Chicago, Illinois 60606

[email protected]


© 2026 Fax Pigeon LLC. All rights reserved.