Table of contents
This BAA is not binding unless and until accepted by Customer through the Composio dashboard.
Upon acceptance, this Business Associate Agreement ("BAA") is entered into as of the Effective Date of the applicable Order Form, by and between the customer identified in the Order Form ("Covered Entity") and Sampark Inc. d/b/a Composio ("Business Associate").
This BAA supplements the Master Services Agreement between the parties ( the "Agreement") and governs Composio's obligations with respect to Protected Health Information (defined below) as defined under the HIPAA Standards (defined below). In the event of a conflict between this BAA and the Agreement, this BAA controls with respect to PHI.
Acceptance is available to Pro and Enterprise Developer customers on the billing page in the Composio developer dashboard.
1. DEFINITIONS
Capitalized terms not defined herein have the meanings assigned in the HIPAA Standards (45 C.F.R. Parts 160 and 164) or the Agreement.
1.1 "Breach" has the meaning set forth in 45 C.F.R. § 164.402.
1.2 "Business Associate" means Sampark Inc. d/b/a Composio, which creates, receives, maintains, or transmits PHI on behalf of the Covered Entity in connection with the Service.
1.3 "Covered Entity" means the Customer identified in the applicable Order Form, to the extent it is a Covered Entity that provides PHI to Composio under the Agreement.
1.4 "Designated Record Set" has the meaning set forth in 45 C.F.R. § 164.501.
1.5 "Electronic PHI (ePHI)" means PHI that is transmitted by or maintained in electronic media, as defined in 45 C.F.R. § 160.103.
1.6 "HIPAA Standards" means the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH), and the implementing regulations at 45 C.F.R. Parts 160 and 164, each as amended from time to time.
1.7 "Individual" means the person who is the subject of PHI and shall include a person who qualifies as a personal representative under 45 C.F.R. § 164.502(g).
1.8 “Protected Health Information” or "PHI" means Protected Health Information as defined in 45 C.F.R. § 160.103, limited to the information created, received, maintained, or transmitted by Composio on behalf of Customer in connection with the Service.
1.9 "Required by Law" has the meaning set forth in 45 C.F.R. § 164.103.
1.10 "Secretary" means the Secretary of the U.S. Department of Health and Human Services or the Secretary's designee.
1.11 "Security Incident" has the meaning in 45 C.F.R. § 164.304.
1.12 "Service" means the tool orchestration and integration services provided by Composio to Customer under the Agreement.
1.13 “Unsecured Protected Health Information” means Protected Health Information that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of technology or methodology specified by HHS in guidance and has the same meaning as the term “unsecured protected health information” as defined in 45 C.F.R. § 164.402.
2. OBLIGATIONS OF BUSINESS ASSOCIATE
2.1 Safeguards. Composio will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, as required by the HIPAA Standards, including the Security Rule at 45 C.F.R. Part 164, Subpart C. These safeguards include, at a minimum:
(a) encryption of ePHI at rest (AES-256) and in transit (TLS 1.2 or higher);
(b) role-based access control enforcing least-privilege principles;
(c) multi-factor authentication for all personnel and systems accessing ePHI;
(d) audit logging of all ePHI access events, including user identity, timestamp, action performed, and data elements accessed;
(e) security awareness training for all personnel with ePHI access;
(f) background checks on personnel with ePHI access;
(g) an incident response plan, tested at least annually; and
(h) vulnerability management and penetration testing performed at least annually.
2.2 Security Incident, Breach, and Unauthorized Use or Disclosure Reporting. Composio will notify Customer of: (a) any use or disclosure of PHI by Composio or any of its subcontractors that is not authorized by this BAA or otherwise permitted by the HIPAA Standards; (b) any Security Incident involving PHI; and (c) any Breach of Unsecured PHI, in each case to the extent required by applicable law.
(a) Notice of Unauthorized Use or Disclosure. Composio will notify Customer of any use or disclosure of PHI that is not authorized by this BAA or otherwise permitted by the HIPAA Standards without unreasonable delay and, in no event, later than five (5) business days after Composio discovers such unauthorized use or disclosure.
(b) Notice of Security Incident. Composio will notify Customer of any Security Incident involving PHI without unreasonable delay and, in no event, later than five (5) business days after Composio discovers such Security Incident. The Parties acknowledge that this notification obligation does not require Composio to report unsuccessful Security Incidents that do not result in unauthorized access, use, disclosure, modification, destruction of PHI, or interference with an information system, provided that Composio may satisfy its obligation to report such unsuccessful Security Incidents through periodic reports, summaries, or other mutually agreed-upon means.
(c) Notice of Breach. Composio will notify Customer of any Breach of Unsecured PHI without unreasonable delay and in no event later than forty-eight (48) hours after discovery of the Breach. Such notice will comply with the requirements of 45 C.F.R. § 164.410 and will include, to the extent known at the time of notification: (i) a brief description of what happened, including the date of the Breach and the date of its discovery, if known; (ii) a description of the types of Unsecured PHI involved; (iii) identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, affected, or, if such identification is not reasonably possible at the time of notice, sufficient information to allow Customer to identify the affected Individuals; and (iv) a description of the steps Composio has taken or will take to investigate the Breach, mitigate harm, and prevent further Breaches.
(d) Continuing Notice. If Composio is unable to provide all information required under this Section within the applicable notification period, Composio will provide the information available at that time and will supplement its notice promptly as additional information becomes available.
(e) Cooperation. Composio will reasonably cooperate with Customer in investigating and responding to any Security Incident, Breach, or unauthorized use or disclosure of PHI, including by providing information reasonably necessary for Customer to comply with its obligations under the HIPAA Standards, including its obligations under 45 C.F.R. §§ 164.404 through 164.408. Composio will not notify any Individual, the media, or any governmental authority regarding a Breach involving Customer's PHI without Customer's prior written approval, unless such notification is Required by Law. Nothing in this Section will prevent Composio from making any notification that Composio is independently required to make by applicable law.
2.3 Subcontractors. Composio will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Composio agrees in writing to substantially the same restrictions and conditions that apply to Composio under this BAA, including implementing reasonable and appropriate safeguards to protect ePHI.
2.4 Offshore Restriction. No person physically located outside of the United States shall have access to PHI unless Customer provides prior written consent. Composio will not engage any subcontractor located outside of the United States to create, receive, maintain, or transmit PHI without Customer's prior written consent.
2.5 Audit Cooperation. Composio will make its internal practices, books, and records relating to PHI available to HHS for determining the Covered Entity's compliance with HIPAA.
2.6 Return and Destruction of PHI. Upon termination of the Agreement or this BAA, Composio will return or destroy all PHI in its possession within thirty (30) days. If return or destruction is infeasible (for example, PHI retained in encrypted backups), Composio will extend the protections of this BAA to such PHI for so long as Composio maintains such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible. Composio will certify destruction in writing upon Customer's request.
3. PERMITTED USES AND DISCLOSURES
3.1 General Limitation. Composio may use and disclose PHI solely as necessary to perform its obligations under the Agreement and to provide the Service, and only in compliance with the HIPAA Standards. Composio will not use or disclose PHI other than as permitted or required by this BAA or as Required by Law.
3.2 Minimum Necessary Standard. Composio will limit its use and disclosure of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.502(b) and 45 C.F.R. § 164.514(d).
3.3 Prohibited Uses. Composio will not use PHI for marketing, fundraising, sale, or any purpose not expressly authorized by this BAA or Required by Law.
3.4 Management and Administration. Composio may use PHI for proper management and administration of Composio or to carry out Composio's legal responsibilities, provided that: (a) the disclosure is Required by Law; or (b) Composio obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and the person notifies Composio of any instances of which it becomes aware in which the confidentiality of the information has been breached.
4. OBLIGATIONS OF COVERED ENTITY
4.1 Customer will notify Composio of any changes in, or revocation of, the permission by an Individual to use or disclose PHI, to the extent that such changes may affect Composio's use or disclosure of PHI.
4.2 Customer will notify Composio of any restriction on the use or disclosure of PHI that Customer has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent that such restriction may affect Composio's use or disclosure of PHI.
4.3 Customer will ensure that its use of the Service, and any instructions to Composio regarding PHI, comply with HIPAA and do not cause Composio to violate the HIPAA Standards.
4.4 Customer will obtain any consents or authorizations from Individuals as required by HIPAA before submitting PHI to the Service.
5. INDIVIDUAL RIGHTS
5.1 Access. To the extent Composio maintains PHI in a Designated Record Set, Composio will, within fifteen (15) business days of Customer's written request, make available to Customer (or, at Customer's direction, to an Individual) the PHI required for Customer to respond to a request for access under 45 C.F.R. § 164.524.
5.2 Amendment. To the extent Composio maintains PHI in a Designated Record Set, Composio will, within fifteen (15) business days of Customer's written request, make any amendments to PHI as directed by Customer pursuant to 45 C.F.R. § 164.526.
5.3 Accounting of Disclosures. Composio will document disclosures of PHI and information related to such disclosures as would be required for Customer to respond to a request by an Individual for an accounting of disclosures under 45 C.F.R. § 164.528. Composio will provide such information to Customer within thirty (30) days of Customer's written request.
6. TERM AND TERMINATION
6.1 Term. This BAA is effective as of the Effective Date specified in the applicable Order Form and continues until the earlier of: (a) the termination or expiration of the Agreement; or (b) all PHI created, received, maintained, or transmitted by Composio on behalf of Customer is returned or destroyed in accordance with Section 2.6.
6.2 Termination for Cause. Either Party may terminate this BAA and the Agreement if the other Party materially breaches any provision of this BAA and fails to cure such breach within thirty (30) days of receiving written notice of the breach. If cure of the breach is not reasonably possible, the non-breaching Party may terminate immediately upon written notice. If Customer determines that termination of this BAA is not feasible, Customer will report the breach or violation to the Secretary as required by 45 C.F.R. § 164.504(e). If Composio determines that termination of this BAA is not feasible, Composio may report the breach or violation to the Secretary to the extent required or permitted by applicable law.
6.3 Effect of Termination. Upon termination of this BAA for any reason, Composio will return or destroy PHI in accordance with Section 2.6. The following Sections survive termination: 2.2, 2.5, 2.6, 6.3, 7, and 8.
7. LIABILITY AND INDEMNIFICATION
7.1 Liability Cap. Composio's total aggregate liability for all claims arising under or in connection with this BAA (including, without limitation, breach notification costs, regulatory fines attributable to Composio's breach, credit monitoring costs, and indemnification obligations under Section 7.2) shall not exceed three times (3x) the annual fees paid or payable by Customer under the applicable Order Form in the twelve (12) months preceding the first event giving rise to liability. This liability cap is specific to this BAA; the Agreement's general liability cap applies to all other claims.
7.2 Indemnification. Composio will indemnify and hold harmless Customer from and against direct costs reasonably incurred as a result of Composio's Breach of Unsecured PHI in violation of this BAA, including:
(i) notification costs to affected Individuals required by applicable law;
(ii) credit monitoring services for affected Individuals (for a period not to exceed twelve (12) months);
(iii) regulatory fines and penalties directly resulting from Composio's Breach of Unsecured PHI; and
(iv) reasonable attorneys' fees incurred in connection with items (i) through (iii).
All indemnification obligations under this Section 7.2 are subject to the liability cap set forth in Section 7.1.
7.3 Exclusions. Composio will not be liable for, and will have no indemnification obligation with respect to, any Breach or Security Incident resulting from: (a) Customer's instructions that violate HIPAA; (b) Customer's failure to properly configure the Service in accordance with Composio's documentation; or (c) events outside of Composio's reasonable control.
8. MISCELLANEOUS
8.1 Insurance. Composio will maintain during the Term, and for a period of three (3) years following termination, insurance coverage meeting or exceeding the following minimums: (a) Technology Errors & Omissions / Cyber Liability insurance with limits of not less than $500,000 per claim and $1,000,000 in the aggregate; and (b) Commercial General Liability insurance with limits of not less than $500,000 per occurrence and $1,000,000 in the aggregate. Certificates of insurance will be provided upon Customer's request.
8.2 Interpretation. Any ambiguity in this BAA shall be resolved in favor of a meaning that permits compliance with the HIPAA Standards.
8.3 Regulatory Amendments. If any provision of the HIPAA Standards is amended in a manner that requires modification of this BAA, the Parties will negotiate in good faith to amend this BAA accordingly. If the Parties cannot reach agreement within sixty (60) days of the effective date of the amendment, either Party may terminate this BAA upon thirty (30) days' written notice.
8.4 No Third-Party Beneficiaries. This BAA does not create any rights in any third party, and no third party shall have any right to enforce any provision of this BAA.
8.5 Governing Law. This BAA is governed by the law specified in the Agreement. If the Agreement is silent on governing law, this BAA shall be governed by the laws of the State of California without regard to its conflict-of-laws provisions.
8.6 Notices. Security Incident and Breach notifications to Customer shall be sent to the contact designated in the applicable Order Form and via email to Customer's designated privacy or security contact. Notices to Composio shall be sent to security@composio.dev.
Last updated August 28, 2026