Skip to content

Business Associate Agreement

Version 2026-07.5

Company: Autonomy AI, LLC

Contact: [email protected]

This is the agreement a practice accepts during setup. The version above is recorded with the acceptance for the practice's HIPAA audit trail. It does not modify the Terms of Service or Privacy Policy.

Velyn Dental — Business Associate Agreement (Version 2026-07.5) This Business Associate Agreement ("Agreement") supports the parties' compliance with the HIPAA Privacy, Security, and Breach Notification Rules (45 CFR Parts 160 and 164) (the "HIPAA Rules"). Capitalized terms used but not defined here have the meanings given in the HIPAA Rules. This Agreement is effective on the date the Covered Entity accepts it through the Velyn service ("Effective Date"). 1. Parties. This Agreement is between the dental practice (the "Covered Entity") and Autonomy AI, LLC, operating Velyn ("Business Associate"), and governs Protected Health Information (PHI) that Business Associate creates, receives, maintains, or transmits on the Covered Entity's behalf while Velyn handles phone-system calls, messaging, and scheduling for the Covered Entity. 2. Permitted uses and disclosures. Business Associate may use and disclose PHI only (a) to provide the Velyn answering, messaging, and scheduling service, (b) as the Covered Entity directs, (c) as Required by Law, and (d) for Business Associate's proper management and administration or to carry out its legal responsibilities. Business Associate may disclose PHI for the purposes in (d) only if the disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential, be used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any known breach of confidentiality. Business Associate will not use or disclose PHI in a manner that would violate the Privacy Rule if done by the Covered Entity. 3. Minimum necessary. Business Associate will limit its use and disclosure of, and its requests for, PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 CFR 164.502(b) and 164.514(d). 4. Safeguards. Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with the Security Rule (45 CFR Part 164, Subpart C) with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. 5. Reporting. Business Associate will report to the Covered Entity, without unreasonable delay, (a) any use or disclosure of PHI not permitted by this Agreement of which it becomes aware, (b) any Security Incident affecting electronic PHI, and (c) any Breach of Unsecured PHI — and, for any Breach of Unsecured PHI, in no event later than sixty (60) calendar days after discovery of the Breach — consistent with 45 CFR 164.410, 164.314(a), and 164.504(e)(2)(ii)(C). The parties agree that this section serves as notice of the routine occurrence of unsuccessful security incidents (e.g., scans, pings, and failed access attempts), for which no additional report is required. 6. Subcontractors. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b), Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions on that PHI at least as protective as those that apply to Business Associate under this Agreement. 7. Individual rights. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will, within the time and manner reasonably requested by the Covered Entity to meet its own obligations, (a) make PHI available for access under 45 CFR 164.524, (b) make PHI available for amendment and incorporate amendments under 45 CFR 164.526, and (c) maintain and make available the information required for an accounting of disclosures under 45 CFR 164.528. 8. Performance of Covered Entity obligations. To the extent Business Associate agrees to carry out one or more of the Covered Entity's obligations under the Privacy Rule (Subpart E of 45 CFR Part 164), Business Associate will comply with the requirements of Subpart E that apply to the Covered Entity in the performance of those obligations. 9. Availability to HHS. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining the Covered Entity's compliance with the HIPAA Rules. 10. Signer authority. The individual accepting this Agreement attests that they are an authorized owner or administrator of the Covered Entity with authority to bind it to this Agreement. 11. Workforce training. The Covered Entity attests that its workforce with access to the Velyn service has received HIPAA privacy and security training and that it does not share login credentials. 12. Scope of attestation. Velyn records the Covered Entity's attestations above; Velyn does not audit, verify, or certify the Covered Entity's HIPAA compliance program. 13. De-identification and product improvement. Business Associate may de-identify PHI in accordance with 45 CFR 164.514(b). The Covered Entity agrees that Business Associate may use such fully de-identified data for product optimization, machine-learning training, and service improvement. Data de-identified in accordance with 45 CFR 164.514(b) does not constitute PHI and is not subject to this Agreement. Business Associate will not use identifiable PHI to train machine-learning models. 14. Term and termination. This Agreement is effective on acceptance and continues for as long as the Covered Entity subscribes to the Velyn service; it terminates when that subscription terminates. The Covered Entity may also terminate this Agreement if Business Associate materially breaches it and fails to cure the breach within thirty (30) days after receiving written notice of the breach. On termination, Business Associate will return or destroy all PHI it maintains for the Covered Entity where feasible; where return or destruction is not feasible, Business Associate will extend the protections of this Agreement to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible. Business Associate shall ensure all subcontractors comply with the return or destruction provisions of this Section. 15. Data return mechanics. The Covered Entity may request an export of its PHI by written request delivered within thirty (30) days after termination. Business Associate will deliver the export in a standard machine-readable format (CSV or JSON). The parties agree that PHI residing in automated database backups, disaster-recovery copies, and records Business Associate retains to meet its six (6)-year federal retention obligations is not feasible to return or destroy; Business Associate will keep those remaining copies encrypted and access-restricted, extend the protections of this Agreement to them, and make no further use or disclosure of them except as Required by Law until they expire or are destroyed in the ordinary course. 16. Breach-response costs. Where a Breach of Unsecured PHI is caused entirely by a failure of Business Associate's systems or personnel, Business Associate will pay the resulting "Breach Costs," defined exclusively as: (a) legally mandated notification letters to affected individuals, (b) up to twelve (12) months of standard credit monitoring for affected patients where legally required or reasonably necessary, and (c) regulatory fines directly resulting from that Breach. Breach Costs do not include public relations services, lost business or revenue, or forensic, crisis- management, or consulting services not required by law. Business Associate's obligation under this Section is subject to the limitation of liability in Section 17. 17. Limitation of liability. Except as provided in this Section, each party's total aggregate liability arising out of or relating to this Agreement is capped at the fees paid by the Covered Entity to Business Associate for the Velyn service in the twelve (12) months preceding the first event giving rise to the liability. Solely for a Breach of Unsecured PHI caused entirely by Business Associate, Business Associate's total aggregate liability is instead capped at the greater of (a) three (3) times those trailing twelve-month fees or (b) twenty-five thousand dollars ($25,000). To the maximum extent permitted by law, neither party is liable for indirect, incidental, consequential, special, exemplary, or punitive damages, including lost profits or lost business, arising out of or relating to this Agreement. 18. Indemnification. Each party will indemnify, defend, and hold harmless the other from third-party claims to the extent arising from the indemnifying party's own conduct: Business Associate indemnifies the Covered Entity for third-party claims arising from Business Associate's gross negligence or a Breach of Unsecured PHI caused entirely by Business Associate; the Covered Entity indemnifies Business Associate for third-party claims arising from the Covered Entity's misuse of the Velyn service or from false attestations made under this Agreement. Each party's indemnification obligation is subject to the limitation of liability in Section 17. To the maximum extent permitted by law, each party waives any claim to multiple damages and attorneys' fees under Massachusetts General Laws Chapter 93A arising out of or relating to this Agreement. 19. Governing law and venue. This Agreement is governed by the laws of the Commonwealth of Massachusetts, without regard to its conflict-of-laws rules. The exclusive venue for any dispute arising out of or relating to this Agreement is the state or federal courts sitting in Norfolk County, Massachusetts (or the federal district embracing it), and each party consents to personal jurisdiction there. This is the same governing law and venue as the Velyn Terms of Service. 20. Order of precedence. In all matters concerning the use or disclosure of PHI, and in all matters concerning liability arising out of or relating to PHI — including the breach-response costs, limitation of liability, and indemnification terms in Sections 16 through 18 — this Agreement controls over the Velyn Terms of Service. In all other matters, the Terms of Service control. Nothing in the Terms of Service enlarges either party's liability under this Agreement beyond the limits in Section 17. 21. Amendment. The parties will amend this Agreement as necessary to comply with changes to the HIPAA Rules or other applicable law. Business Associate may publish an amended version of this Agreement for that purpose; the amended version applies on the Covered Entity's acceptance, and each acceptance is recorded with the version and hash of the text accepted. No other amendment is effective unless in writing and agreed by both parties. 22. Notices. Notices under this Agreement must be in writing. Notices to the Covered Entity may be delivered to the administrative email address on its Velyn account. Notices to Business Associate must be delivered to the support contact published on Velyn's legal pages, with a copy to Autonomy AI, LLC via its registered agent in Pittsfield, Massachusetts. Notice is effective on delivery. 23. No third-party beneficiaries. Nothing in this Agreement confers any right, remedy, or claim on any person other than the Covered Entity and Business Associate, including any patient or other individual whose PHI is subject to this Agreement. 24. Survival and interpretation. Each party's obligations that by their nature should survive termination — including the return-or-destroy provision and Sections 15 through 20 — survive. Any ambiguity in this Agreement will be resolved to permit the parties to comply with the HIPAA Rules.