Business Associate Agreement
Version 2026-07.5
Company: Autonomy AI, LLC
Contact: [email protected]
This is the agreement a practice accepts during setup. The version above is recorded with the acceptance for the practice's HIPAA audit trail. It does not modify the Terms of Service or Privacy Policy.
Velyn Dental — Business Associate Agreement (Version 2026-07.5)
This Business Associate Agreement ("Agreement") supports the parties' compliance
with the HIPAA Privacy, Security, and Breach Notification Rules (45 CFR Parts 160
and 164) (the "HIPAA Rules"). Capitalized terms used but not defined here have
the meanings given in the HIPAA Rules. This Agreement is effective on the date
the Covered Entity accepts it through the Velyn service ("Effective Date").
1. Parties. This Agreement is between the dental practice (the "Covered Entity")
and Autonomy AI, LLC, operating Velyn ("Business Associate"), and governs
Protected Health Information (PHI) that Business Associate creates, receives,
maintains, or transmits on the Covered Entity's behalf while Velyn handles
phone-system calls, messaging, and scheduling for the Covered Entity.
2. Permitted uses and disclosures. Business Associate may use and disclose PHI
only (a) to provide the Velyn answering, messaging, and scheduling service,
(b) as the Covered Entity directs, (c) as Required by Law, and (d) for
Business Associate's proper management and administration or to carry out its
legal responsibilities. Business Associate may disclose PHI for the purposes
in (d) only if the disclosure is Required by Law or Business Associate
obtains reasonable assurances from the recipient that the PHI will remain
confidential, be used or further disclosed only as Required by Law or for the
purpose for which it was disclosed, and that the recipient will notify
Business Associate of any known breach of confidentiality. Business Associate
will not use or disclose PHI in a manner that would violate the Privacy Rule
if done by the Covered Entity.
3. Minimum necessary. Business Associate will limit its use and disclosure of,
and its requests for, PHI to the minimum necessary to accomplish the intended
purpose, consistent with 45 CFR 164.502(b) and 164.514(d).
4. Safeguards. Business Associate will use appropriate administrative, physical,
and technical safeguards, and will comply with the Security Rule (45 CFR Part
164, Subpart C) with respect to electronic PHI, to prevent use or disclosure
of PHI other than as provided for by this Agreement.
5. Reporting. Business Associate will report to the Covered Entity, without
unreasonable delay, (a) any use or disclosure of PHI not permitted by this
Agreement of which it becomes aware, (b) any Security Incident affecting
electronic PHI, and (c) any Breach of Unsecured PHI — and, for any Breach of
Unsecured PHI, in no event later than sixty (60) calendar days after
discovery of the Breach — consistent with 45 CFR 164.410, 164.314(a), and
164.504(e)(2)(ii)(C). The parties agree that this section serves as notice
of the routine occurrence of unsuccessful security incidents (e.g., scans,
pings, and failed access attempts), for which no additional report is
required.
6. Subcontractors. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b),
Business Associate will ensure that any subcontractor that creates, receives,
maintains, or transmits PHI on its behalf agrees in writing to restrictions
and conditions on that PHI at least as protective as those that apply to
Business Associate under this Agreement.
7. Individual rights. To the extent Business Associate maintains PHI in a
Designated Record Set, Business Associate will, within the time and manner
reasonably requested by the Covered Entity to meet its own obligations, (a)
make PHI available for access under 45 CFR 164.524, (b) make PHI available for
amendment and incorporate amendments under 45 CFR 164.526, and (c) maintain
and make available the information required for an accounting of disclosures
under 45 CFR 164.528.
8. Performance of Covered Entity obligations. To the extent Business Associate
agrees to carry out one or more of the Covered Entity's obligations under the
Privacy Rule (Subpart E of 45 CFR Part 164), Business Associate will comply
with the requirements of Subpart E that apply to the Covered Entity in the
performance of those obligations.
9. Availability to HHS. Business Associate will make its internal practices,
books, and records relating to the use and disclosure of PHI available to the
Secretary of the U.S. Department of Health and Human Services for purposes of
determining the Covered Entity's compliance with the HIPAA Rules.
10. Signer authority. The individual accepting this Agreement attests that they
are an authorized owner or administrator of the Covered Entity with authority
to bind it to this Agreement.
11. Workforce training. The Covered Entity attests that its workforce with
access to the Velyn service has received HIPAA privacy and security training
and that it does not share login credentials.
12. Scope of attestation. Velyn records the Covered Entity's attestations above;
Velyn does not audit, verify, or certify the Covered Entity's HIPAA
compliance program.
13. De-identification and product improvement. Business Associate may
de-identify PHI in accordance with 45 CFR 164.514(b). The Covered Entity
agrees that Business Associate may use such fully de-identified data for
product optimization, machine-learning training, and service improvement.
Data de-identified in accordance with 45 CFR 164.514(b) does not constitute
PHI and is not subject to this Agreement. Business Associate will not use
identifiable PHI to train machine-learning models.
14. Term and termination. This Agreement is effective on acceptance and
continues for as long as the Covered Entity subscribes to the Velyn
service; it terminates when that subscription terminates. The Covered
Entity may also terminate this Agreement if Business Associate materially
breaches it and fails to cure the breach within thirty (30) days after
receiving written notice of the breach. On termination, Business Associate
will return or destroy all PHI it maintains for the Covered Entity where
feasible; where return or destruction is not feasible, Business Associate
will extend the protections of this Agreement to that PHI and limit further
use and disclosure to the purposes that make return or destruction
infeasible. Business Associate shall ensure all subcontractors comply with
the return or destruction provisions of this Section.
15. Data return mechanics. The Covered Entity may request an export of its PHI
by written request delivered within thirty (30) days after termination.
Business Associate will deliver the export in a standard machine-readable
format (CSV or JSON). The parties agree that PHI residing in automated
database backups, disaster-recovery copies, and records Business Associate
retains to meet its six (6)-year federal retention obligations is not
feasible to return or destroy; Business Associate will keep those remaining
copies encrypted and access-restricted, extend the protections of this
Agreement to them, and make no further use or disclosure of them except as
Required by Law until they expire or are destroyed in the ordinary course.
16. Breach-response costs. Where a Breach of Unsecured PHI is caused entirely
by a failure of Business Associate's systems or personnel, Business
Associate will pay the resulting "Breach Costs," defined exclusively as:
(a) legally mandated notification letters to affected individuals, (b) up
to twelve (12) months of standard credit monitoring for affected patients
where legally required or reasonably necessary, and (c) regulatory fines
directly resulting from that Breach. Breach Costs do not include public
relations services, lost business or revenue, or forensic, crisis-
management, or consulting services not required by law. Business
Associate's obligation under this Section is subject to the limitation of
liability in Section 17.
17. Limitation of liability. Except as provided in this Section, each party's
total aggregate liability arising out of or relating to this Agreement is
capped at the fees paid by the Covered Entity to Business Associate for the
Velyn service in the twelve (12) months preceding the first event giving
rise to the liability. Solely for a Breach of Unsecured PHI caused entirely
by Business Associate, Business Associate's total aggregate liability is
instead capped at the greater of (a) three (3) times those trailing
twelve-month fees or (b) twenty-five thousand dollars ($25,000). To the
maximum extent permitted by law, neither party is liable for indirect,
incidental, consequential, special, exemplary, or punitive damages,
including lost profits or lost business, arising out of or relating to this
Agreement.
18. Indemnification. Each party will indemnify, defend, and hold harmless the
other from third-party claims to the extent arising from the indemnifying
party's own conduct: Business Associate indemnifies the Covered Entity for
third-party claims arising from Business Associate's gross negligence or a
Breach of Unsecured PHI caused entirely by Business Associate; the Covered
Entity indemnifies Business Associate for third-party claims arising from
the Covered Entity's misuse of the Velyn service or from false attestations
made under this Agreement. Each party's indemnification obligation is
subject to the limitation of liability in Section 17. To the maximum extent
permitted by law, each party waives any claim to multiple damages and
attorneys' fees under Massachusetts General Laws Chapter 93A arising out of
or relating to this Agreement.
19. Governing law and venue. This Agreement is governed by the laws of the
Commonwealth of Massachusetts, without regard to its conflict-of-laws
rules. The exclusive venue for any dispute arising out of or relating to
this Agreement is the state or federal courts sitting in Norfolk County,
Massachusetts (or the federal district embracing it), and each party
consents to personal jurisdiction there. This is the same governing law
and venue as the Velyn Terms of Service.
20. Order of precedence. In all matters concerning the use or disclosure of
PHI, and in all matters concerning liability arising out of or relating to
PHI — including the breach-response costs, limitation of liability, and
indemnification terms in Sections 16 through 18 — this Agreement controls
over the Velyn Terms of Service. In all other matters, the Terms of
Service control. Nothing in the Terms of Service enlarges either party's
liability under this Agreement beyond the limits in Section 17.
21. Amendment. The parties will amend this Agreement as necessary to comply
with changes to the HIPAA Rules or other applicable law. Business Associate
may publish an amended version of this Agreement for that purpose; the
amended version applies on the Covered Entity's acceptance, and each
acceptance is recorded with the version and hash of the text accepted. No
other amendment is effective unless in writing and agreed by both parties.
22. Notices. Notices under this Agreement must be in writing. Notices to the
Covered Entity may be delivered to the administrative email address on its
Velyn account. Notices to Business Associate must be delivered to the
support contact published on Velyn's legal pages, with a copy to Autonomy
AI, LLC via its registered agent in Pittsfield, Massachusetts. Notice is
effective on delivery.
23. No third-party beneficiaries. Nothing in this Agreement confers any right,
remedy, or claim on any person other than the Covered Entity and Business
Associate, including any patient or other individual whose PHI is subject
to this Agreement.
24. Survival and interpretation. Each party's obligations that by their nature
should survive termination — including the return-or-destroy provision and
Sections 15 through 20 — survive. Any ambiguity in this Agreement will be
resolved to permit the parties to comply with the HIPAA Rules.