When PolyQ Intake handles Protected Health Information (PHI) on behalf of a covered entity or another business associate, a signed BAA governs the arrangement. This page summarizes the proposed terms; talk to us before any PHI is sent.
Last updated · April 21, 2026Version · 2026.04 · 45 CFR §§ 164.502, 164.504, 164.314
Form
Standalone BAA, incorporated into the MSA by written agreement.
Parties
Covered Entity or upstream Business Associate ↔ Polyq.ai Inc.
Scope
PHI contained in interview audio, transcripts, summaries, documents and images uploaded by respondents during an interview, and derived records.
Without unreasonable delay and in no case later than 60 days from discovery
Availability
By written agreement, arranged before any PHI is sent
What we commit to
Use and disclosure limits. We use and disclose PHI only as permitted by the BAA and by your instructions, and as required by law. We do not sell PHI. We do not use PHI for marketing except as expressly authorized by the individual.
Safeguards. We maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI. These mirror the Security Rule at 45 CFR §§ 164.308, 164.310, 164.312, and 164.316.
Minimum necessary. Access to PHI is restricted to the smallest workforce reasonably required to operate the service. Engineering support access is time-boxed, MFA-gated, and logged.
Sub-contractor flow-down. Every sub-contractor that receives PHI is bound by a BAA at least as restrictive as the BAA between us and you. The list is published at polyq.ai/subprocessors.
Access, amendment, accounting. We will cooperate with you in responding to individuals’ requests for access, amendment, and accounting of disclosures under 45 CFR §§ 164.524, 164.526, and 164.528.
Breach notice. We will notify your designated Privacy Officer without unreasonable delay and in no case later than 60 calendar days from discovery of a Breach of Unsecured PHI. In practice, our target is within 72 hours of confirmation.
Return or destruction. On termination, we will return or destroy all PHI where feasible. Where destruction is not feasible, the obligations of this BAA continue for the retained copies.
HHS access. We make our internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance with HIPAA.
How PHI flows through the product
PHI arrives at two moments: (1) the client tells the Intake Manager something over voice, and (2) you read the transcript or summary in the dashboard. Between those points, PHI lives in three places — the voice platform sub-processor (during the call), our managed database (transcripts), and an object-storage bucket (audio). All three are encrypted at rest with AES-256 and in transit with TLS 1.2+. The specific sub-processors are listed on our Sub-processors page.
What the product does today: interview records are removed on the company-wide retention setting (90 days by default), cleanup removes provider segments and uploaded files before the interview record, administrative actions are written to an audit log you can export, and operator access is checked against company ownership on every request. Any safeguard you need beyond these — a shorter window for audio, restrictions on a sub-processor, or access reporting at the interview level — is agreed in writing in the signed BAA before any PHI is sent.
What we don’t do
We do not use PHI to train general-purpose AI models.
We do not disclose PHI to third parties except the sub-contractors listed at polyq.ai/subprocessors, each bound by a back-to-back BAA.
We do not retain PHI beyond the retention window configured on your account.
We do not market or sell PHI in any form.
Request a counter-signed BAA.
Reply with your organization’s legal name, NPI if applicable, and your Privacy Officer’s name and email. We’ll return the executed BAA within one business day.
Note. BAAs are available only on medical-tier or enterprise plans. Lower-tier plans are not provisioned to receive PHI; uploading or voicing PHI into a non-medical-tier Intake Manager is a violation of our Acceptable Use terms.