Try the new DeepSeek V4 Pro 0813 today. Frontier intelligence at a fraction of the cost. Here

Baseten Business Associate Agreement

About This Document; When This BAA Applies

This is Baseten's standard Business Associate Agreement ("BAA"). The Services are not intended for protected health information ("PHI") by default, and this BAA does not apply by default: it applies only where Baseten and the customer have executed it or incorporated it by reference in an Order Form or other written agreement between them. If the version you executed or incorporated differs from this page, that version governs. CUSTOMER MUST NOT SUBMIT PHI TO THE SERVICES UNLESS AND UNTIL THIS BAA IS IN EFFECT.

To execute this BAA, contact legal@baseten.co.

This Business Associate Agreement (this "BAA") supplements and forms part of the Baseten Terms and Conditions available at https://www.baseten.co/terms, or, where Baseten Labs, Inc. ("Baseten") and the customer ("Customer") have separately executed a master services agreement or other written agreement governing Customer's use of the Services, that executed agreement (in either case, the "Agreement"). This BAA is entered into by and between Baseten, a Delaware corporation with offices at 560 Davis St., Suite 250, San Francisco, CA 94111, and Customer (each a "Party" and together the "Parties"), and supplements the Agreement, including the DPA referenced therein. For purposes of HIPAA (as defined below), Customer is the "Covered Entity" (or an upstream "Business Associate"), and Baseten is the "Business Associate." Capitalized terms not defined in this BAA have the meanings set forth in the Agreement or, if applicable, the Data Processing Agreement in effect (the “DPA”), or, where not so defined, the meanings given by HIPAA. In the event of a conflict between this BAA and the Agreement or the DPA with respect to PHI, this BAA controls.

  1. Definitions

"Breach" has the meaning set forth in 45 CFR §164.402.

"Designated Record Set" has the meaning set forth in 45 CFR §164.501.

"Electronic PHI" or "ePHI" means PHI maintained in or transmitted by electronic media as defined in 45 CFR §160.103.

"HHS" means the U.S. Department of Health and Human Services.

"HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act"), and all regulations promulgated thereunder, including the Privacy Rule (45 CFR Part 160 and Part 164, Subparts A and E), the Security Rule (45 CFR Part 160 and Part 164, Subparts A and C), and the Breach Notification Rule (45 CFR Part 164, Subpart D).

"Individual" has the meaning set forth in 45 CFR §164.501 and includes a personal representative under 45 CFR §164.502(g).

"Protected Health Information" or "PHI" has the meaning set forth in 45 CFR §160.103, limited to information that Baseten creates, receives, maintains, or transmits from or on behalf of Customer in connection with the Services. PHI is a subset of Customer Personal Data and is treated as Customer Content under the Agreement.

"Required by Law" has the meaning set forth in 45 CFR §164.103.

"Security Incident" has the meaning set forth in 45 CFR §164.304, provided that, as further described in Section 4.2, the Parties acknowledge that Unsuccessful Security Incidents do not require individual notification.

"Subcontractor" has the meaning set forth in 45 CFR §160.103 and includes any Sub-Processor (as defined in the DPA) that creates, receives, maintains, or transmits PHI on behalf of Baseten.

"Unsecured PHI" has the meaning set forth in 45 CFR §164.402.

"Unsuccessful Security Incident" means an attempted but unsuccessful Security Incident of a type that occurs in the normal course of operating an internet-facing service, including pings and other broadcast attacks on Baseten's firewalls, port scans, unsuccessful log-on attempts, denials of service, and similar incidents that are detected and neutralized by Baseten's defensive controls without unauthorized access to PHI.

  1. Scope

This BAA applies to PHI that Baseten creates, receives, maintains, or transmits on behalf of Customer in connection with the Services. Customer is solely responsible for determining whether information it submits to the Services constitutes PHI and for configuring the Services consistent with HIPAA. Customer shall not submit PHI to the Services until this BAA is in effect, whether by mutual execution or by incorporation as described in the introduction to this BAA. This BAA is in addition to, and does not supersede, the DPA. To the extent PHI also constitutes Customer Personal Data, the DPA applies; to the extent of any conflict between this BAA and the DPA with respect to PHI, this BAA controls.

  1. Permitted Uses and Disclosures

  2. General. Baseten may use or disclose PHI only as reasonably necessary to provide the Services, as permitted or required by this BAA, or as Required by Law. Baseten will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Customer, except as permitted in Sections 3.2 and 3.3 below.

  3. Management and Administration. Baseten may use PHI for the proper management and administration of Baseten and to carry out its legal responsibilities, and may disclose PHI for such purposes only if: (a) the disclosure is Required by Law; or (b) Baseten obtains reasonable written assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose disclosed, and the recipient will notify Baseten of any breach of confidentiality.

  4. Minimum Necessary; De-Identification. Baseten will, to the extent practicable, use, disclose, and request only the minimum amount of PHI necessary to carry out the intended purpose, consistent with Section 13405(b) of the HITECH Act (codified at 42 USC §17935(b)). Baseten may de-identify PHI in accordance with 45 CFR §164.514(a)-(c), and de-identified information is not PHI and is not subject to this BAA.

  5. No Training on PHI. For the avoidance of doubt and consistent with the terms of the Agreement, Baseten will not use PHI to train, fine-tune, develop, or otherwise improve any machine learning or artificial intelligence model, whether for Baseten's own use or for the benefit of any third party.

  6. Reporting Violations of Law. Baseten may use or disclose PHI to report violations of law to appropriate federal or state authorities consistent with 45 CFR §164.502(j)(1).

  7. Safeguards and Reporting

  8. Safeguards. Baseten will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of Customer, consistent with the Security Rule and the Security Practices (available at [https://www.baseten.co/legal/security-practices]). The Security Practices govern the substance of Baseten's technical and organizational measures; this BAA does not impose obligations in excess of, or inconsistent with, those measures.

  9. Reporting Security Incidents. Baseten will report to Customer in writing any successful Security Incident affecting ePHI of Customer of which Baseten becomes aware, without undue delay and in any event within forty-eight (48) hours of Baseten's confirmation of the Security Incident (or, if the Parties have entered into a DPA and that DPA prescribes a shorter timeframe, within such shorter timeframe). The Parties acknowledge that Unsuccessful Security Incidents are reported, if at all, on an aggregated basis as part of Baseten's standard security reporting, and individual notification of Unsuccessful Security Incidents is not required.

  10. Breach Notification. Baseten will notify Customer of any Breach of Unsecured PHI in accordance with 45 CFR §164.410 without undue delay and in any event within forty-eight (48) hours of Baseten's confirmation of the Breach (or, if the Parties have entered into a DPA and that DPA prescribes a shorter timeframe, within such shorter timeframe), and in no case later than the timeframes required by 45 CFR §164.410. To the extent Customer reasonably incurs costs in complying with the Breach Notification Rule (Subpart D of 45 CFR Part 164) as a direct and proximate result of a Breach committed by Baseten, such costs are subject to the limitations and caps set forth in the Agreement.

  11. Mitigation. Baseten will take reasonable measures to mitigate, to the extent practicable, any harmful effect of which it becomes aware of any use or disclosure of PHI by Baseten or its Subcontractors in violation of this BAA.

  12. Subcontractors

In accordance with 45 CFR §§164.502(e)(1)(ii) and 164.308(b)(2), Baseten will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Baseten agrees in writing to restrictions and conditions at least as protective as those imposed on Baseten by this BAA and the Security Rule. Subcontractor engagement and Customer's notification and objection rights are governed by the terms in the DPA, which are incorporated by reference and applies equally to Subcontractors that handle PHI. If the Parties have not entered into a DPA, Baseten will: (a) maintain a list of Subcontractors that handle PHI, available on request; (b) provide Customer with at least thirty (30) days' advance written notice of any new Subcontractor that will handle PHI; and (c) afford Customer the right to object to a new Subcontractor on reasonable data protection grounds, with the Parties working in good faith to resolve any such objection (and, failing resolution, Customer may terminate the affected portion of the Services upon notice).

  1. Individual Rights

  2. Access. Within ten (10) business days of a written request from Customer, Baseten will make available to Customer (or, if directed by Customer, to the Individual) any PHI in a Designated Record Set maintained by Baseten as reasonably necessary to enable Customer to respond to an Individual's request for access under 45 CFR §164.524.

  3. Amendment. Within fifteen (15) business days of a written request and instruction from Customer, Baseten will amend PHI in a Designated Record Set maintained by Baseten as directed by Customer in accordance with 45 CFR §164.526.

  4. Accounting of Disclosures. Baseten will document disclosures of PHI as required by 45 CFR §164.528(a) and, within ten (10) business days of a written request from Customer, will make such documentation available to Customer to enable Customer to respond to an Individual's request for an accounting of disclosures.

  5. Routing Individual Requests. If Baseten receives a request directly from an Individual (or personal representative) under Sections 6.1, 6.2, or 6.3 above, Baseten will, within ten (10) business days, forward the request to Customer. Customer is solely responsible for responding to Individual requests; Baseten has no obligation to respond directly to any Individual.

  6. HHS Secretary Access

Baseten will make its internal practices, books, records, and policies and procedures relating to the use and disclosure of PHI received from, or created or received by Baseten on behalf of, Customer available to the Secretary of HHS for purposes of the Secretary determining Customer's or Baseten's compliance with HIPAA, in each case subject to applicable attorney-client and other legal privileges.

  1. Customer Responsibilities

Customer will: (a) notify Baseten of any limitations in Customer's notice of privacy practices under 45 CFR §164.520 to the extent that such limitation may affect Baseten's use or disclosure of PHI; (b) notify Baseten of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent such changes may affect Baseten's use or disclosure of PHI; (c) notify Baseten of any restriction on the use or disclosure of PHI to which Customer has agreed under 45 CFR §164.522, to the extent such restriction may affect Baseten's use or disclosure of PHI; (d) not request Baseten to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Customer; and (e) be solely responsible for obtaining and maintaining all consents, authorizations, and notices required under HIPAA in connection with Customer's submission of PHI to the Services.

  1. Data Ownership

Baseten's processing of PHI under this BAA does not confer on Baseten any ownership rights in, or license to, the PHI beyond those rights granted in the Agreement and the DPA. PHI remains Customer Content under the Agreement.

  1. Term and Termination

  2. Term. This BAA is effective upon the earlier of mutual execution of this BAA or the date this BAA is incorporated by cross-reference in the applicable Order Form or other written agreement between the Parties, and continues until the earlier of (a) termination of the Agreement, or (b) termination of this BAA in accordance with Section 10.2 below. Termination of this BAA terminates Customer's right to submit PHI to the Services but does not terminate the Agreement.

  3. Termination for Material Breach. Either Party may terminate this BAA, effective upon written notice, if the other Party materially breaches this BAA and fails to cure such breach within thirty (30) days of written notice from the non-breaching Party. If cure is not feasible, the non-breaching Party may terminate this BAA immediately.

  4. Return or Destruction; Survival. Upon termination of this BAA for any reason, Baseten will, at Customer's election, return or destroy all PHI in its possession and will not retain copies, except to the extent return or destruction is not feasible (including, without limitation, PHI retained in routine backups or required to be retained by law). With respect to PHI that Baseten cannot feasibly return or destroy, Baseten will extend the protections of this BAA to such retained PHI and will limit further use and disclosure to the purposes that make return or destruction infeasible, for so long as Baseten retains such PHI. This Section 10.3 survives termination.

  5. Precedence; Effect of BAA

This BAA is part of and subject to the Agreement, except that to the extent any term of this BAA conflicts with the Agreement or the DPA with respect to PHI, this BAA controls. With respect to Customer Personal Data that is not PHI, the DPA controls. Except as expressly stated in this BAA or as Required by Law, this BAA does not create any rights in favor of any third party. Baseten's aggregate liability for claims arising under or relating to this BAA is governed by the limitations and caps set forth in the Agreement.

  1. Regulatory References; HITECH Act

References in this BAA to sections of HIPAA mean those sections as in effect or as amended. The Parties agree to comply with applicable provisions of the HITECH Act and to negotiate in good faith to modify this BAA as reasonably necessary to comply with changes in HIPAA, the HITECH Act, or related regulations. If the Parties are unable to reach agreement on such modifications, either Party may terminate this BAA upon thirty (30) days' prior written notice to the other Party.

  1. Notices

Notices under this BAA will be delivered in accordance with the notice provisions of the Agreement. For notices to Baseten relating to PHI, Security Incidents, or Breaches, Customer may also notify Baseten at security@baseten.co.

  1. Counterparts; Electronic Signatures

This BAA may be executed in counterparts, each of which constitutes an original and all of which together constitute one instrument. Signatures delivered by electronic means (including DocuSign or comparable e-signature platforms) have the same effect as original signatures.


To execute this BAA or ask questions, contact legal@baseten.co.

Baseten Business Associate Agreement