# Business Associate Agreement

Version: 2.2, effective October 9, 2026 for new acceptances

Published October 9, 2026. Replaces Version 2.1, effective October 8, 2026. Version 2.2 changes Business Associate: the Polestar GRC business was assigned to Jonathan Prine, an individual doing business as Polestar GRC, who signs this BAA as Owner. Version 2.2 also replaces the assignment terms in Section 15.7, which now allow one further assignment, to an LLC of which Jonathan Prine is the sole member, only after at least thirty (30) days' Secure Notice and that company's signed assumption, with a right for Covered Entity to terminate before it takes effect; bars AI training on de-identified data (Section 2.4); names Amazon Web Services as the Subcontractor for AI features and states which files they send without redaction (Section 2.9); adds notice immediately following Discovery and a fifteen (15) day target for reports about California residents (Section 5.12); corrects the Part 2 lawful holder terms (Section 7.3); corrects the insurance statement (Section 11.5); and bars acceptance by a person who works for a referring organization (Section 17.4). This version applies to every acceptance made on or after October 9, 2026. A Covered Entity that accepted an earlier version stays on the version it accepted until it accepts this version (Section 13.5). For a customer that accepted an earlier version, Jonathan Prine became the Business Associate by assignment on the date stated in our notice of assignment. The assignment right in Section 15.7 applies to that customer only after an administrator accepts this version. Every earlier version is archived at polestargrc.com/legal/archive.

About this document. This Business Associate Agreement is the contract that governs Protected Health Information in the Polestar GRC Service. It is the written agreement that 45 C.F.R. 164.502(e)(2), 164.504(e), 164.308(b)(3), and 164.314(a) require between a covered entity and its business associate. It is written for covered entities: health care providers, health plans, and health care clearinghouses. If your organization is itself a business associate (for example a billing company, managed service provider, or software vendor serving covered entities), do not accept this document; accept the Subcontractor Business Associate Agreement instead. It becomes binding on both parties when your organization accepts it electronically as described in Section 17. Until it is in place, the Services do not accept new file uploads or the narrative text of incident and breach records in your workspace (Section 9(c)), and you must not place Protected Health Information in the Services by any other route. If your organization needs changes to this text, write to legal@polestargrc.com before accepting. We consider reasonable requests.

This Business Associate Agreement ("BAA") is entered into by and between:

- Covered Entity: [CUSTOMER LEGAL NAME] ("Covered Entity"), identified in the Services by its Polestar GRC organization account, as shown in the Execution Record. Business address: [CUSTOMER ADDRESS]. Notices to Covered Entity are delivered as described in Section 14, which does not depend on a mailing address being on file.
- Business Associate: Jonathan Prine, an individual doing business as Polestar GRC, 434 Kern St, Taft, CA 93268 ("Business Associate", "Polestar GRC" or "Polestar").

Effective Date. This BAA takes effect on the date Covered Entity accepts it electronically, as shown in the Execution Record appended to the executed copy. If Covered Entity accepted an earlier version of this BAA, this version replaces that version only as described in Section 13.

Relationship to the Agreement. This BAA supplements and is incorporated into the Polestar GRC Terms of Service, or any other written services agreement between the parties that expressly refers to this BAA (the "Agreement"). The Agreement describes the Services. This BAA governs how Business Associate handles Protected Health Information while providing the Services. If this BAA and the Agreement conflict about Protected Health Information, this BAA controls.

## 1. Definitions

1.1 HIPAA Rules means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, as amended, including by the HITECH Act and its implementing regulations.

1.2 Capitalized terms used but not defined in this BAA have the meanings given in the HIPAA Rules, including Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

1.3 Services means the Polestar GRC software-as-a-service platform and related support described in the Agreement, including during a free trial and during the Export Window.

1.4 Protected Health Information or PHI means Protected Health Information as defined at 45 C.F.R. 160.103, limited to the PHI that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity through the Services, including PHI that Covered Entity's users send to Business Associate's support channels. PHI includes Electronic PHI.

1.5 Discovery of a Breach has the meaning in 45 C.F.R. 164.410(a)(2): the first day on which the Breach is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate. A Breach is treated as known to Business Associate when it is known to any workforce member or agent of Business Associate other than the person who committed it.

1.6 Successful Security Incident means a Security Incident that results in unauthorized access to, or unauthorized acquisition, use, disclosure, modification, or destruction of, PHI, or interference with system operations in an information system that contains PHI. It excludes Unsuccessful Security Incidents.

1.7 Unsuccessful Security Incident means an attempted Security Incident that does not result in any of the outcomes listed in Section 1.6, such as pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, denial of service attacks that do not result in a server being taken offline, and malware that is blocked before execution.

1.8 Part 2 Record means a record, or information in a record, that identifies a patient as having or having had a substance use disorder and that is subject to 42 C.F.R. Part 2.

1.9 Business Day means Monday through Friday, excluding United States federal holidays.

1.10 Service End Date means the earliest of (a) the date the last paid subscription for Covered Entity's organization account ends without renewal, (b) the date a free trial ends without conversion to a paid subscription, and (c) the date the Agreement terminates.

1.11 Secure Notice means a notice delivered inside the Services to an authenticated administrator of Covered Entity's organization account, together with an email to the contacts in Section 14.1 that states that a notice is waiting and how to reach it, and that does not itself contain PHI.

## 2. Permitted and Required Uses and Disclosures

2.1 Services. Business Associate may use and disclose PHI only as necessary to provide, support, secure, and maintain the Services for Covered Entity as described in the Agreement and as Covered Entity directs through the Services, which consist of:

(a) storing and displaying the evidence files, incident and breach records, risk analysis answers, vendor and agreement records, and other documents that Covered Entity's users place in the Services, and producing the reports, exports, and audit packages that Covered Entity's users request from them;

(b) processing content through the AI features described in Section 2.9, when Covered Entity's users invoke them;

(c) giving access to Covered Entity's workspace to Business Associate's support and engineering personnel as described in Section 2.10;

(d) transmitting PHI to persons Covered Entity's users designate through a feature of the Services designed for that purpose, such as an auditor room or a shared export link;

(e) backing up, restoring, monitoring, and securing the systems that hold PHI; and

(f) returning and destroying PHI under Section 10.

Business Associate will not use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted by Sections 2.2 and 2.3.

2.2 Management and administration. Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only if (a) the disclosure is Required by Law, or (b) Business Associate first obtains reasonable written assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the recipient, and that the recipient will notify Business Associate of any instance of which it becomes aware in which the confidentiality of the PHI has been breached. This Section 2.2 implements 45 C.F.R. 164.504(e)(4).

2.3 Data Aggregation. Business Associate may use PHI to provide Data Aggregation services relating to the Health Care Operations of Covered Entity only if Covered Entity requests those services in writing. Business Associate does not offer Data Aggregation services as of the date of this version.

2.4 De-identification. Business Associate may de-identify PHI in accordance with 45 C.F.R. 164.514(a) through (c) only to produce aggregate statistics about the use and performance of the Services that do not identify Covered Entity. Information de-identified in that manner is no longer PHI. Business Associate will not attempt to re-identify de-identified information and will not disclose any re-identification code or mechanism. Business Associate will not use de-identified information derived from PHI to train, fine-tune, or evaluate any artificial intelligence or machine learning model, and will not sell or license it to any third party.

2.5 Required by Law. Business Associate may use or disclose PHI as Required by Law. Unless legally prohibited, Business Associate will notify Covered Entity before complying with a subpoena, court order, warrant, or other legal demand for PHI, and will give Covered Entity a reasonable opportunity to object or seek a protective order.

2.6 Prohibited uses and disclosures. Business Associate will not (a) sell PHI or receive remuneration in exchange for PHI, except as permitted by 45 C.F.R. 164.502(a)(5)(ii); (b) use or disclose PHI for marketing or fundraising; (c) use PHI to train, fine-tune, or improve any artificial intelligence or machine learning model, or permit any Subcontractor to do so; or (d) use or disclose PHI for any purpose not expressly permitted by this BAA.

2.7 Minimum necessary. Business Associate will request, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose, consistent with 45 C.F.R. 164.502(b) and 164.514(d), and will apply role-based access so that its workforce members can access only the PHI needed for their roles.

2.8 Obligations of Covered Entity performed by Business Associate. To the extent Business Associate carries out any obligation of Covered Entity under Subpart E of 45 C.F.R. Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation.

2.9 AI features. The Services include features that send content to a large language model operated by a third-party provider (the "AI Provider"). For every AI feature, Business Associate (a) sends content only to models hosted on Amazon Bedrock under Business Associate's business associate agreement with Amazon Web Services, which is a Subcontractor under Section 4; the model developer does not receive or have access to the content; (b) does not permit the AI Provider to retain content for training or to use it for any purpose other than returning a response; and (c) does not use the content to train any model, consistent with Section 2.6(c). The AI features work in two ways:

(i) Text features (the support chat assistant, policy drafting, and risk analysis answer suggestions) send text that Covered Entity's users type or that the Services assemble from Covered Entity's workspace. Before transmission Business Associate applies automated, pattern-based redaction to that text. As of the date of this version the redaction covers Social Security numbers, telephone numbers, dates of birth, labeled medical record numbers, and payment card numbers in all text features, and also email addresses, street addresses, and personal names in the support chat assistant. Redaction is not guaranteed to remove every identifier.

(ii) Document analysis features send a document or image that Covered Entity's user selects for analysis to the AI Provider. A PDF file or image is sent as uploaded, without redaction. A text file (plain text, CSV, JSON or HTML) is sent after redaction of the patterns that clause (i) lists for the support chat assistant.

Covered Entity agrees that its users will not enter patient-identifying information into text features, will use document analysis only on documents that Covered Entity is permitted to disclose to Business Associate under this BAA, and will not submit Part 2 Records to any AI feature (Section 7.4). The hosting platform and the model developer are named in the Polestar GRC Privacy Policy, and a change is subject to Section 4.2.

2.10 Support and engineering access. Business Associate's support and engineering personnel may access Covered Entity's workspace only (a) at the request of a user of Covered Entity's organization account, (b) to investigate a Security Incident, abuse, or a malfunction of the Services, or (c) as Required by Law. Each access session requires the person to record a reason before access begins, is limited to personnel whose role requires it, is recorded in Covered Entity's audit log with the person, reason, and time, and is visible to Covered Entity's administrators in the Services. Business Associate will not download or export Covered Entity's evidence files during a support session unless Covered Entity's user requested it or the access is under clause (b) or (c).

2.11 Support channels. Covered Entity will not send PHI to Business Associate by email or in support tickets unless Business Associate asks for specific information in order to resolve an issue. If PHI reaches Business Associate through a support channel, Business Associate will handle it under this BAA, will move it into Covered Entity's workspace or delete it once the issue is resolved, and will not keep it in support correspondence after the Service End Date except as Section 10.5 allows.

## 3. Safeguards

3.1 Security Rule. Business Associate will comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to Electronic PHI, and will use appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as provided by this BAA.

3.2 Specific controls. Without limiting Section 3.1, Business Associate maintains: encryption of PHI in transit (TLS 1.2 or higher) and at rest (AES-256); organization-scoped and role-based access controls enforced on every application procedure; multi-factor authentication available to all users, with organization-wide enforcement available to Covered Entity's administrators; brute-force lockouts; audit logging of access to PHI, protected so that application users, including Covered Entity's own administrators, cannot alter or delete entries; time-limited, signed download links for uploaded files; and a documented incident response plan tested at least annually.

3.3 Data location. Business Associate stores and processes PHI only in data centers located in the United States, and configures its Subcontractors, including the AI Provider, to process PHI only in the United States. Business Associate will not transfer PHI outside the United States without Covered Entity's prior written consent.

3.4 Risk analysis. Business Associate performs and documents an accurate and thorough assessment of risks to the confidentiality, integrity, and availability of Electronic PHI at least annually and after any material change to the Services, as required by 45 C.F.R. 164.308(a)(1)(ii)(A).

3.5 Workforce. Business Associate ensures that each workforce member with access to PHI is bound by written confidentiality obligations, completes privacy and security training before access and at least annually, and is subject to sanctions for violations of this BAA.

3.6 Documentation. Business Associate maintains the policies, procedures, and documentation required by 45 C.F.R. 164.316 and retains them for six (6) years from the later of their creation or the date they were last in effect.

3.7 Assurances. On Covered Entity's written request, not more than once in any twelve (12) month period unless following a Breach, Business Associate will provide a summary of its most recent risk analysis, a description of its security program, a completed security questionnaire of reasonable length, and copies of any third-party security assessments or certifications it holds. Covered Entity will treat this material as Business Associate's confidential information.

## 4. Subcontractors

4.1 Written agreements. Before any Subcontractor creates, receives, maintains, or transmits PHI on Business Associate's behalf, Business Associate will enter into a written agreement with that Subcontractor that meets the requirements of 45 C.F.R. 164.504(e) and 164.314(a) and imposes restrictions and conditions on the Subcontractor at least as restrictive as those that apply to Business Associate under this BAA, including compliance with the Security Rule with respect to Electronic PHI, as required by 45 C.F.R. 164.502(e)(1)(ii), 164.504(e)(2)(ii)(D), and 164.308(b)(2). Business Associate will not send PHI to a service provider that has not signed such an agreement, and configures service providers that have not (for example, its email delivery provider Twilio SendGrid, its SMS provider Twilio, and any error monitoring provider) so that PHI is not sent to them. Business Associate's emails and SMS messages state only that an item is waiting and how to reach it in the Services, and do not contain PHI or text that Covered Entity's users typed.

4.2 Current list and notice. The Polestar GRC Privacy Policy lists (a) each Subcontractor that may create, receive, maintain, or transmit PHI, and (b) each other service provider, with a statement of how Business Associate keeps PHI from reaching it. Business Associate will give Covered Entity at least thirty (30) days' notice by Secure Notice before a new Subcontractor accesses PHI. If Covered Entity objects on reasonable grounds related to the protection of PHI within that period and the parties cannot resolve the objection, Covered Entity may terminate the Agreement and this BAA on written notice and Business Associate will refund any prepaid fees for the period after termination. Business Associate may replace a Subcontractor without the thirty (30) day period where necessary to respond to a Security Incident or the Subcontractor's own failure, and will give notice as soon as practicable afterward.

4.3 Responsibility; pattern of violations. Business Associate remains responsible to Covered Entity for the acts and omissions of its Subcontractors with respect to PHI as if they were Business Associate's own, and will report to Covered Entity any Subcontractor Security Incident or impermissible use or disclosure under Section 5 as if it had occurred at Business Associate. If Business Associate knows of a pattern of activity or practice of a Subcontractor that constitutes a material breach or violation of the Subcontractor's obligations, Business Associate will take reasonable steps to cure the breach or end the violation and, if those steps are unsuccessful, will terminate the arrangement with that Subcontractor if feasible, as required by 45 C.F.R. 164.504(e)(1)(iii).

4.4 Annual confirmation. On Covered Entity's written request, not more than once in any twelve (12) month period, Business Associate will confirm in writing that each Subcontractor listed under Section 4.2(a) is under a written agreement meeting Section 4.1.

## 5. Reporting

5.1 Reportable Events. Each of the following is a "Reportable Event": (a) a Breach of Unsecured PHI; (b) any acquisition, access, use, or disclosure of PHI not permitted by this BAA, including one that Business Associate has not yet assessed under Section 5.3; and (c) a Successful Security Incident. A Reportable Event is discovered on the first day on which it is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate, determined in the same way as Section 1.5 provides for a Breach ("Discovery").

5.2 Initial notice. Business Associate will notify Covered Entity of a Reportable Event without unreasonable delay and in no case later than seven (7) calendar days after Discovery. Business Associate will not delay the initial notice to complete its investigation or its risk assessment. One notice may cover an event that falls under more than one part of Section 5.1. The initial notice will state the date of Discovery and will include, to the extent then known: a description of what happened, including the date of the event; the types of PHI involved; the identification of each Individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; the steps Individuals should take to protect themselves; what Business Associate is doing to investigate, mitigate harm, and prevent recurrence; and a contact for further questions. If the person who normally gives notices for Business Associate is unavailable, the initial notice may be given by a person Business Associate has designated for that purpose who has no access to PHI; such a notice may state only that Business Associate is investigating a possible Reportable Event, its date of Discovery, and that the details will follow under Section 5.3. A security alert or anomaly that Business Associate is investigating, and that has not yet given Business Associate reason to believe that PHI was or may have been accessed, acquired, used, disclosed, modified, or destroyed without authorization, is not by itself a Reportable Event. Business Associate will investigate such alerts promptly.

5.3 Risk assessment and full report. Business Associate will treat each event under Section 5.1(b) as a presumed Breach unless it documents a risk assessment under 45 C.F.R. 164.402 showing a low probability that the PHI has been compromised. No later than thirty (30) calendar days after Discovery, or sooner where reasonably necessary for Covered Entity to meet a shorter deadline that Covered Entity identifies under Section 5.12, Business Associate will deliver a written report that includes its risk assessment and the information described in 45 C.F.R. 164.404(c) and 164.410(c), and will supplement it promptly as more information becomes available. An event that the risk assessment shows is not a Breach remains reportable under this Section 5. Covered Entity makes the final determination whether notification to Individuals, the Secretary, or the media is required for its own obligations under 45 C.F.R. 164.404 through 164.408, and Business Associate will provide the information and cooperation reasonably needed for those notifications.

5.4 Outer limits. The seven (7) day and thirty (30) day periods in this Section 5 are outer limits, not targets. They do not extend any shorter period that applicable law requires of Business Associate, including state laws that require a person that maintains data it does not own to notify the owner immediately or within a fixed number of days, and they do not extend the sixty (60) calendar day limit in 45 C.F.R. 164.410(b). Section 5.7 (law enforcement delay) applies to every period in this Section 5.

5.5 Unsuccessful Security Incidents. The parties acknowledge that this Section 5.5 constitutes notice by Business Associate of the ongoing occurrence of Unsuccessful Security Incidents. No further notice of Unsuccessful Security Incidents is required. On written request, not more than quarterly, Business Associate will provide a summary of Unsuccessful Security Incidents affecting systems that hold Covered Entity's PHI.

5.6 Contingency plan activation. Business Associate will notify Covered Entity within twenty-four (24) hours after activating its contingency plan (for example, restoring from backup or failing over to alternate infrastructure) where the activation affects the availability or integrity of Covered Entity's PHI.

5.7 Law enforcement delay. If a law enforcement official states to Business Associate that a notification would impede a criminal investigation or damage national security, Business Associate may delay the notice as permitted by 45 C.F.R. 164.412 and will document the statement and notify Covered Entity as soon as the delay ends.

5.8 Mitigation. Business Associate will mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI by Business Associate or its Subcontractors in violation of this BAA.

5.9 Costs of notification. To the extent a Breach is caused by Business Associate's or its Subcontractors' breach of this BAA, Business Associate will reimburse Covered Entity's reasonable, documented, out-of-pocket costs of the notifications to Individuals, the Secretary, the media, and state regulators that the HIPAA Rules or applicable state law require, subject to Section 11.

5.10 Independent contractor; Discovery date. Business Associate is an independent contractor and not an agent of Covered Entity. Business Associate controls the manner and means of performing the Services, and Covered Entity directs only the result through the features of the Services. Neither party intends that Business Associate's knowledge of a Breach be imputed to Covered Entity under 45 C.F.R. 164.404(a)(2). Because that question is determined under the Federal common law of agency and not by this BAA, Covered Entity should treat Business Associate's date of Discovery as a possible start of Covered Entity's own notification period until Covered Entity has concluded otherwise, and Business Associate's seven (7) day notice period under Section 5.2 is designed to keep the difference between the two dates small. Each notice under Section 5.2 will state Business Associate's date of Discovery.

5.11 How reports are delivered. Business Associate delivers reports under this Section 5 by Secure Notice to the Privacy Officer and Security Officer contacts recorded in Covered Entity's organization settings and to the organization account owner. The email part of a Secure Notice states that a report is waiting, its date, and how to reach it, and does not contain the identity of any Individual or other PHI. If Covered Entity cannot reach the report in the Services, Business Associate will deliver it by another method that protects PHI, such as an encrypted file or a telephone call, as Covered Entity reasonably requests. Business Associate will ask the recipient to confirm receipt of each report. Covered Entity is responsible for keeping those contacts current. If no Privacy Officer or Security Officer is recorded, notice to the account owner is sufficient.

5.12 Shorter deadlines under state law. Some state laws require Covered Entity to notify patients or regulators sooner than the HIPAA Rules require (for example, Cal. Health and Safety Code 1280.15 requires a licensed clinic, health facility, home health agency, or hospice to report unauthorized access to medical information within fifteen (15) business days after detection). Covered Entity may identify such a deadline to Business Associate in writing or in its organization settings, and Business Associate will then deliver the information Covered Entity needs early enough for Covered Entity to meet it, using reasonable efforts where the deadline is shorter than the periods in Sections 5.2 and 5.3. Where Business Associate maintains computerized personal information that it does not own, its notice under this Section 5 is also its notice to Covered Entity under Cal. Civ. Code 1798.82(b) and similar state laws, and Business Associate will give it immediately following Discovery, and in any case within the period in Section 5.2. Where Business Associate knows that the affected PHI concerns residents of California, Business Associate will use reasonable efforts to deliver the report under Section 5.3 within fifteen (15) calendar days after Discovery, so that Covered Entity, as the owner of the information, can meet Cal. Civ. Code 1798.82(a)(2) and, where it applies, Cal. Health and Safety Code 1280.15(b).

## 6. Individual Rights

6.1 Designated Record Set. The Services are a compliance documentation platform. They are not designed to serve as Covered Entity's medical record or other Designated Record Set, and Covered Entity agrees not to use them as one. The remainder of this Section 6 applies to the extent Business Associate nonetheless maintains PHI in a Designated Record Set on behalf of Covered Entity.

6.2 Access. Within ten (10) Business Days after Covered Entity's written request, Business Associate will make PHI in a Designated Record Set available to Covered Entity in the form and format requested if readily producible, or otherwise in a readable electronic form, so that Covered Entity can meet its obligations under 45 C.F.R. 164.524. Covered Entity may also use the Services' export features for this purpose at any time.

6.3 Amendment. Within ten (10) Business Days after Covered Entity's written request, Business Associate will make PHI in a Designated Record Set available for amendment and will incorporate any amendment Covered Entity directs, in accordance with 45 C.F.R. 164.526.

6.4 Accounting of disclosures. Business Associate will document each disclosure of PHI that would be required to be included in an accounting under 45 C.F.R. 164.528, including the date, the recipient, a brief description of the PHI, and the purpose, and will retain that documentation for six (6) years. Within ten (10) Business Days after Covered Entity's written request, Business Associate will provide the information needed for Covered Entity to respond to an Individual's request for an accounting. Disclosures that Covered Entity's own users make through features of the Services (for example, sharing an audit room) are Covered Entity's disclosures, and the Services' audit log records them for Covered Entity's use.

6.5 Restrictions and confidential communications. Covered Entity will notify Business Associate in writing of any restriction on use or disclosure of PHI that Covered Entity has agreed to under 45 C.F.R. 164.522 and that affects Business Associate's handling of PHI, and Business Associate will comply with the restriction to the extent it applies to the Services.

6.6 Requests received directly. If an Individual contacts Business Associate directly to exercise a right under Subpart E, Business Associate will forward the request to Covered Entity within five (5) Business Days and will not respond substantively except as Covered Entity directs or as Required by Law.

## 7. Part 2 Records

7.1 Not designed for Part 2 Records. The Services are not designed to store Part 2 Records. Covered Entity will not upload Part 2 Records except where strictly necessary as compliance evidence, and will redact patient identifying information from such records wherever possible before upload.

7.2 Qualified service organization terms. If Covered Entity is a Part 2 program and discloses Part 2 Records to Business Associate, then with respect to those records Business Associate acknowledges and agrees that, in receiving, storing, processing, or otherwise dealing with any Part 2 Records, it is fully bound by 42 C.F.R. Part 2; that it will, if necessary, resist in judicial proceedings any efforts to obtain access to patient identifying information related to substance use disorder diagnosis, treatment, or referral for treatment except as permitted by 42 C.F.R. Part 2; that it will not use or disclose Part 2 Records in any civil, criminal, administrative, or legislative investigation or proceeding against the patient except as permitted by 42 C.F.R. Part 2; and that it will not redisclose Part 2 Records except as permitted by 42 C.F.R. Part 2 and this BAA. The parties intend this Section 7.2 to satisfy the written agreement requirement for a qualified service organization in the definition at 42 C.F.R. 2.11.

7.3 Lawful holder disclosures. If Covered Entity is not a Part 2 program but is a lawful holder of Part 2 Records and discloses them to Business Associate, Business Associate agrees, in addition to its obligations under the HIPAA Rules, that it is fully bound by 42 C.F.R. Part 2 upon receipt of the patient identifying information; that it will implement appropriate safeguards to prevent unauthorized uses and disclosures; that it will report any unauthorized use, disclosure, or breach of patient identifying information to Covered Entity under Section 5; that it will not further disclose the information except to its own contract agents helping it perform this BAA and only as 42 C.F.R. Part 2 permits; and that any permitted further disclosure will carry the notice required by 42 C.F.R. 2.32.

7.4 AI features. Covered Entity will not submit Part 2 Records to AI features of the Services.

7.5 Breach notification for Part 2 Records. A Breach involving Part 2 Records is reported under Section 5, and Business Associate will cooperate with Covered Entity's obligations under 42 C.F.R. 2.16 and 45 C.F.R. 164.400 through 164.414.

7.6 Covered Entity responsibilities. Covered Entity is responsible for obtaining any patient consent required by 42 C.F.R. 2.31 before disclosing Part 2 Records to Business Associate, for including any notice required by 42 C.F.R. 2.32, and for identifying records as Part 2 Records when uploading them where the Services provide a means to do so.

## 8. Access by the Secretary

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary for purposes of determining Covered Entity's and Business Associate's compliance with the HIPAA Rules. Unless prohibited by law, Business Associate will promptly notify Covered Entity of any such request.

## 9. Covered Entity Obligations

Covered Entity will:

(a) not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted by Sections 2.2 and 2.3;

(b) notify Business Associate in writing of any limitation in Covered Entity's notice of privacy practices under 45 C.F.R. 164.520, any change in or revocation of an Individual's permission to use or disclose PHI, and any restriction agreed to under 45 C.F.R. 164.522, in each case to the extent the limitation, change, revocation, or restriction may affect Business Associate's use or disclosure of PHI;

(c) have the authority under the HIPAA Rules to disclose to Business Associate any PHI it uploads to the Services, not upload PHI before this BAA is in effect, and upload PHI only within features designed to hold it (evidence uploads, incident and breach records, and document storage) and only to the extent reasonably necessary for compliance documentation. Until this BAA has been accepted under Section 17, the Services refuse new file uploads and the narrative text of incident and breach records in Covered Entity's workspace, give incident records a title made from their date and category, and offer acceptance in the same dialog; they never block viewing, downloading (including audit package and evidence ZIP files), or deleting what is already stored. Covered Entity will not place PHI in the Services by any other route, or in fields that block does not cover, before this BAA is in effect;

(d) use AI features only as Section 2.9 permits, and not upload Part 2 Records except as permitted by Section 7;

(e) manage its own users' access to the Services, including removing users who leave its workforce, give administrator rights only to persons it has authorized to act for it, and keep its Privacy Officer, Security Officer, and account owner contacts current;

(f) where a Polestar partner created or manages Covered Entity's organization account, understand that the partner is not a party to this BAA, cannot accept it for Covered Entity (Section 17.4), that partner staff have access to Covered Entity's PHI only if Covered Entity invites them, and that if Covered Entity invites them Covered Entity is responsible for having its own business associate agreement with the partner; and

(g) comply with the HIPAA Rules and applicable state law in its own use of the Services and the PHI stored in them.

## 10. Term and Termination

10.1 Term. This BAA takes effect on the Effective Date and remains in effect until the later of (a) termination or expiration of the Agreement, and (b) the date Business Associate has returned or destroyed all PHI as provided in Section 10.4 or has documented that return or destruction is infeasible under Section 10.5.

10.2 Termination for cause by Covered Entity. If Covered Entity determines that Business Associate has violated a material term of this BAA, Covered Entity may terminate this BAA and the Agreement, as 45 C.F.R. 164.504(e)(2)(iii) requires. Covered Entity will give Business Associate written notice describing the violation and a reasonable period to cure that Covered Entity specifies, which will be at least ten (10) Business Days unless Covered Entity reasonably determines that cure is not possible or that the violation creates an ongoing risk to PHI, in which case Covered Entity may terminate immediately on written notice. Business Associate will refund any prepaid fees for the period after a termination under this Section 10.2. Nothing in this BAA limits Covered Entity's obligations under 45 C.F.R. 164.504(e)(1)(ii).

10.3 Termination for cause by Business Associate. If Business Associate determines that Covered Entity has violated a material term of this BAA, including by uploading PHI in a manner that breaches Section 9 and that materially increases risk to PHI, Business Associate may give Covered Entity written notice describing the violation and may suspend the affected features or terminate this BAA and the Agreement if Covered Entity does not cure within thirty (30) days after the notice.

10.4 Return or destruction. For thirty (30) days after the Service End Date (the "Export Window"), Covered Entity may export its PHI using the Services' export features, and may instead request return of PHI in a commonly used electronic format before the Export Window ends. After the Export Window, Business Associate will destroy all PHI it maintains on behalf of Covered Entity, wherever stored, including database records, uploaded files and their stored versions in object storage, generated reports and exports, support correspondence, and PHI held by Subcontractors, using methods consistent with NIST Special Publication 800-88, and will retain no copies, except as provided in Section 10.5. Destruction of PHI in production systems will be complete within thirty (30) days after the Export Window, and destruction of PHI in encrypted backups and in prior stored versions of files will be complete within ninety (90) days after the Export Window as those copies reach the end of their retention. Business Associate will send a written certification of destruction to the account owner's email address when production destruction is complete and again when backup destruction is complete, and will provide a further certification on request.

10.5 Infeasibility. If return or destruction of specific PHI is infeasible, Business Associate will notify Covered Entity of the conditions that make it infeasible, extend the protections of this BAA to that PHI, limit further uses and disclosures to the purposes that make return or destruction infeasible, and destroy the PHI when those purposes end. The parties agree that return or destruction is infeasible only for (a) audit log entries that Business Associate retains for six (6) years as documentation under 45 C.F.R. 164.316(b)(2), which record the identity of the user, the action taken, the type and identifier of the record affected, the network address, and the time, together with any PHI embedded in those entries (for example in a file name or record title), which Business Associate will destroy when the six (6) year retention period ends, and (b) PHI subject to a litigation hold or legal preservation obligation, which Business Associate will destroy when the hold ends.

10.6 Suspension. Suspension of the Services under the Agreement does not suspend Business Associate's obligations under this BAA. During a suspension, Business Associate will continue to safeguard PHI and, where the suspension is not for Covered Entity's violation of this BAA or a security threat, will preserve Covered Entity's ability to export PHI.

10.7 Survival. Sections 2, 3, 5, 6, 7, 8, 10.4, 10.5, 11, 12, and 15 survive termination of this BAA for as long as Business Associate or any Subcontractor retains PHI, and Sections 11 and 12 survive indefinitely.

10.8 Retained workspaces and lapsed trials. If, before the Export Window ends, Covered Entity's account owner directs Business Associate in the Services to keep the workspace instead of deleting it, or Covered Entity starts a new subscription, the schedule in Section 10.4 stops and this BAA continues to apply to the PHI. A workspace kept at Covered Entity's direction without a subscription is read-only, and Business Associate may restart the Section 10.4 schedule on thirty (30) days' Secure Notice if the workspace remains without a subscription for twelve (12) months. A lapsed free trial cannot be kept this way: where the Service End Date is the end of a free trial under Section 1.10(b) and no subscription starts, destruction of PHI in production systems will be complete no later than sixty (60) days after the trial ended, and destruction in backups follows Section 10.4.

## 11. Liability, Indemnification, and Insurance

11.1 Relationship to the Agreement. The limitations and exclusions of liability in the Agreement apply to this BAA except as modified in this Section 11. This Section 11 governs liability relating to PHI.

11.2 Direct damages. The following are direct damages, and not consequential or indirect damages, when they are caused by a party's breach of this BAA: the reasonable, documented costs of investigating a Breach, including forensic services; the costs of notifying Individuals, the Secretary, the media, and state regulators as required by law; the cost of call center and credit monitoring or identity protection services where required by law or reasonably necessary to mitigate harm to Individuals; and, to the extent recovery is permitted by applicable law, civil monetary penalties or settlement amounts that a government authority imposes on the non-breaching party and that are attributable to the breaching party's breach of this BAA.

11.3 Indemnification. Each party (the "Indemnifying Party") will defend the other party and its officers, directors, and employees against any third-party claim, and any investigation or enforcement action by a government authority, arising from the Indemnifying Party's or its Subcontractors' breach of this BAA or violation of the HIPAA Rules, and will pay the resulting damages, penalties, settlements, and reasonable attorneys' fees, in each case to the extent permitted by applicable law. The indemnified party will give prompt notice of the claim, allow the Indemnifying Party to control the defense and settlement (provided no settlement admits fault on the indemnified party's behalf or imposes obligations on it without its consent), and cooperate reasonably.

11.4 BAA liability cap. Each party's total aggregate liability arising out of or relating to this BAA, including under Sections 5.9, 11.2, and 11.3, will not exceed the greater of (a) two (2) times the fees paid or payable by Covered Entity under the Agreement in the twelve (12) months before the event giving rise to liability, or (b) fifty thousand U.S. dollars ($50,000), which becomes one hundred thousand U.S. dollars ($100,000) for an event that occurs on a date when the cyber liability insurance stated in Section 11.5 has an aggregate limit of two million U.S. dollars ($2,000,000) or more. This cap is separate from and in addition to the general liability cap in the Agreement. Nothing in this Section 11 limits liability for a party's gross negligence, willful misconduct, or fraud, or liability that cannot be limited under applicable law.

11.5 Insurance. Business Associate will state in this Section 11.5 the insurance it carries, will keep that statement accurate, and will provide a certificate of insurance on request. As of the date of this version, Business Associate does not carry commercial general liability, cyber liability, or technology errors and omissions insurance in its own name, and this BAA does not promise that it does. Business Associate will give Covered Entity Secure Notice within thirty (30) days after it binds any of those coverages, stating the type of coverage and its limits.

## 12. Governing Law

This BAA is governed by the laws of the State of California and applicable federal law, without regard to conflict-of-laws rules, and the venue and dispute resolution provisions of the Agreement (in the Terms of Service, Sections 22 and 23) apply to disputes under it. The parties will interpret this BAA so as to comply with the HIPAA Rules. Nothing in this BAA prevents either party from complying with a state law that is more stringent than the HIPAA Rules and that applies to Covered Entity's PHI, including Cal. Civ. Code 56 et seq. (the Confidentiality of Medical Information Act) where it applies, and the parties will cooperate so that each can meet those state law obligations.

## 13. Amendments and Versions

13.1 Changes in law. The parties will amend this BAA as necessary to comply with changes in the HIPAA Rules or other applicable law. Business Associate may make an amendment that is required by a change in law by publishing a new version and giving Covered Entity Secure Notice that identifies the change, and the new version takes effect on the compliance date of the change in law or thirty (30) days after notice, whichever is later, unless the law requires an earlier date.

13.2 Other updates. Business Associate may publish a new version of this BAA from time to time. Business Associate will give Covered Entity at least thirty (30) days' Secure Notice before a new version takes effect, with a summary of the changes and a comparison against the version Covered Entity last accepted. A new version that changes Section 2, 4, 5, 7, 10, or 11, or that reduces Business Associate's obligations or expands its permitted uses and disclosures of PHI in any other Section, takes effect for Covered Entity only when an authorized representative of Covered Entity accepts it under Section 17, and until then the version Covered Entity last accepted remains in effect. Any other new version takes effect on the stated effective date unless Covered Entity declines it in the Services before that date, in which case the version Covered Entity last accepted remains in effect.

13.3 Records of versions. Each version of this BAA is identified by a unique version number and a SHA-256 fingerprint of its published text. Business Associate will not change the published text of a version without assigning a new version number. Business Associate keeps every published version available at polestargrc.com/legal and on request. The executed copy of each version Covered Entity accepts, with its Execution Record, is retained in Covered Entity's BAA Tracker, and the person who accepted it is emailed a link to it.

13.4 Negotiated terms. A written amendment signed by both parties, including by electronic signature, prevails over this published text for the parties who signed it.

13.5 Earlier versions. A version of this BAA that Covered Entity accepted before the effective date of this version, including any text published as a draft, remains in effect for Covered Entity until Covered Entity accepts this version or the Agreement terminates. Business Associate will ask Covered Entity to accept this version in the Services at its next sign-in or renewal. In particular, a Covered Entity that accepted Version 2.0 keeps the seventy-two (72) hour reporting periods in Section 5 of Version 2.0 until it accepts this version, and Business Associate will work to those periods for that Covered Entity until then.

## 14. Notices

14.1 To Covered Entity. Business Associate gives notices under this BAA by Secure Notice to the Privacy Officer and Security Officer contacts recorded in Covered Entity's organization settings and to the organization account owner. A notice that does not contain PHI (for example a notice of a new version under Section 13) may be given entirely by email. Notice is effective when sent, unless Business Associate receives an automated delivery failure, in which case Business Associate will attempt delivery to another administrator on the account and notice is effective when that delivery is sent. No mailing address is required.

14.2 To Business Associate. Covered Entity gives notices under this BAA by email to legal@polestargrc.com, and for Security Incidents also through the in-product incident report, with a copy by mail to Polestar GRC, Attn: Jonathan Prine, 434 Kern St, Taft, CA 93268 for notices of breach or termination. Covered Entity will not include PHI in an email notice. Notice is effective when received.

## 15. Miscellaneous

15.1 Regulatory references. A reference to a section of the HIPAA Rules or 42 C.F.R. Part 2 means that section as in effect or as amended.

15.2 Interpretation. Any ambiguity in this BAA will be resolved to permit compliance with the HIPAA Rules. Headings are for convenience only.

15.3 No third-party beneficiaries. Nothing in this BAA confers any right, remedy, or claim on any person other than the parties, including any Individual whose PHI is held in the Services.

15.4 Independent contractors. The parties are independent contractors. This BAA does not create a partnership, joint venture, or agency relationship.

15.5 Severability. If any provision of this BAA is held unenforceable, the remaining provisions remain in effect and the unenforceable provision will be modified to the minimum extent needed to make it enforceable and consistent with the HIPAA Rules.

15.6 Entire agreement. This BAA and the Agreement are the entire agreement between the parties about PHI and supersede any prior business associate agreement between them covering the Services, subject to Section 13.5.

15.7 Assignment. Neither party may assign this BAA except together with a permitted assignment of the Agreement. Any permitted assignee of Business Associate must assume this BAA in writing, and Business Associate will give Covered Entity Secure Notice of the assignment. In addition, Business Associate may assign this BAA, together with the Agreement, to Polestar GRC, LLC, a limited liability company of which Jonathan Prine is the sole member (the "LLC"), without Covered Entity's consent, on these terms. (a) Business Associate will give Covered Entity at least thirty (30) days' Secure Notice before the assignment takes effect, stating the LLC's exact legal name, its state of organization and entity number, and the effective date. (b) Before the effective date, the LLC will assume this BAA and the Agreement in a writing signed for the LLC, and will have in place the written agreements Section 4.1 requires with each Subcontractor. (c) On the effective date, the Services will give Covered Entity an updated executed copy of this BAA naming the LLC. (d) The Services, the locations where PHI is stored and the Subcontractors will not change because of the assignment. (e) Covered Entity may terminate the Agreement and this BAA by written notice before the effective date and receive a refund of prepaid fees for the period after termination. (f) Jonathan Prine remains responsible for obligations that arose before the effective date.

15.8 Electronic records and signatures. The parties agree that this BAA is a written contract for purposes of 45 C.F.R. 164.502(e)(2), 164.504(e), 164.308(b)(3), and 164.314(a), that it may be executed by electronic signature and electronic acceptance under the federal Electronic Signatures in Global and National Commerce Act (15 U.S.C. 7001 et seq.) and the applicable state Uniform Electronic Transactions Act (in California, Cal. Civ. Code 1633.1 et seq.), and that an electronic copy of this BAA with its Execution Record is admissible as an original.

## 16. Execution by Business Associate

Business Associate has executed this BAA by the electronic signature of Jonathan Prine, an individual doing business as Polestar GRC, who adopted the typed signature below with the intent to sign each published version of this BAA, including this version. That signature applies to every copy of this version accepted by a customer under Section 17. The published text of this version carries the SHA-256 fingerprint stated in the Execution Record. A countersigned copy of a customer's executed copy is available on request from legal@polestargrc.com.

Polestar GRC, by Jonathan Prine, Owner

Electronically signed on October 9, 2026 for Version 2.2.

## 17. Acceptance by Covered Entity

17.1 How Covered Entity accepts. Covered Entity accepts this BAA when an individual who is an administrator of Covered Entity's organization account, and who is an owner, officer, or employee of Covered Entity or a person Covered Entity has authorized in writing to sign agreements for it, enters Covered Entity's legal name, his or her own name and title, confirms that authority, and selects the acceptance control in the Services, in the BAA Tracker or in the dialog the Services show when an upload is blocked under Section 9(c). Acceptance happens only in the Services.

17.2 Execution Record. Business Associate records the acceptance in an Execution Record that states the legal name of Covered Entity as entered by the person who accepted, Covered Entity's organization account (its name and account number), the person who accepted, that person's title and account email address, the confirmation of authority, the date and time of acceptance (UTC), the network address and browser from which acceptance was made, the method of acceptance (in the Services), the version accepted, and the SHA-256 fingerprint of the published text that was displayed to the person who accepted.

17.3 Copies. The Execution Record is appended to the executed copy. Business Associate keeps the executed copy as a PDF in Covered Entity's BAA Tracker, where Covered Entity's administrators can download it, and emails the person who accepted and the account owner a link to it; the email contains no PHI. Business Associate will keep its own copy for six (6) years after this BAA ends and will provide it to Covered Entity on request during that time, including after the workspace is deleted. Covered Entity may request a countersigned PDF of the executed copy from legal@polestargrc.com at any time.

17.4 Partner-managed and referred accounts. No person who works for a Polestar partner and not for Covered Entity, and no person whose access to Covered Entity's organization account comes through a Polestar partner, may accept this BAA for Covered Entity, and the Services refuse such an acceptance. No person who works for an organization that referred Covered Entity to Polestar, and not for Covered Entity, may accept this BAA for Covered Entity.

17.5 Effect. Covered Entity agrees that its acceptance under this Section 17 is its signature on this BAA.

## Signatures

Covered Entity: [CUSTOMER LEGAL NAME]

Accepted electronically as described in Section 17. The Execution Record below forms part of this BAA.

---

Earlier versions of this Business Associate Agreement: [Version 2.1, effective October 8, 2026](https://polestargrc.com/legal/archive/hipaa-baa-v2.1), [Version 2.0, effective October 1, 2026](https://polestargrc.com/legal/archive/hipaa-baa-v2.0) and [Version 2.0, draft dated August 1, 2026, offered from September 21, 2026 to October 1, 2026](https://polestargrc.com/legal/archive/hipaa-baa-v2.0-2026-08-01). Every version of our legal documents is listed at [polestargrc.com/legal/archive](https://polestargrc.com/legal/archive).
