Meta16Labs
Trust

Business associate agreement

Our commitments when handling protected health information on behalf of a covered entity.

Permitted use

Protected health information is used solely to deliver the contracted services, and for no independent purpose of our own.

Safeguards

Administrative, physical and technical safeguards aligned to ISO 27001 controls, with access limited to personnel who require it to deliver the service.

Subcontractors

Any subcontractor with access to protected health information is bound by equivalent written obligations before access is granted.

Individual rights

We support the covered entity in responding to access, amendment and accounting-of-disclosure requests within agreed timelines.

Incident reporting

Security incidents involving protected health information are reported to the covered entity promptly, with the information needed for their own notification obligations.

Return or destruction

On termination, protected health information is returned or securely destroyed, with written confirmation, except where retention is legally required.

This page summarises our operating commitments. The governing terms are those in the executed agreement with your institution.