Orithos provides a standard Business Associate Agreement (BAA) for customers subject to HIPAA. The BAA covers the use and disclosure of Protected Health Information (PHI) by Orithos on behalf of covered entities and business associates.
Key Provisions
- PHI Handling: All PHI is encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). Orithos does not store PHI beyond the retention period configured in your org settings.
- Permitted Uses: Orithos may use PHI only to provide the AI security scanning service as defined in the Master Subscription Agreement.
- Breach Notification: Orithos will notify the customer within 72 hours of becoming aware of a breach involving PHI.
- Subprocessors: Orithos engages AWS (US-East-1), Anthropic, and OpenAI as subprocessors. A full list is available upon request.
- Audit Rights: Our SOC 2 Type II program is in progress; the report will be made available under NDA once issued. On-site audits are subject to mutual agreement and 30-day notice.
- Data Deletion: Upon termination, Orithos deletes all customer PHI within 30 days. A certificate of destruction is provided.
Download
The standard BAA is available as a PDF.Download BAA (PDF) →
Need a custom BAA? Contact [email protected].