Last updated: June 1, 2026

Business Associate Agreement

This Business Associate Agreement ("BAA") is entered into between you, the Covered Entity or Business Associate ("Covered Entity"), and FairForge LLC, operating as stored.ge ("Business Associate"), and supplements the Terms of Service and Data Processing Agreement.

This BAA is required under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, "HIPAA Rules").

Contents

1. Definitions

Capitalized terms used but not defined in this BAA have the meanings assigned to them in the HIPAA Rules. For purposes of this BAA:

2. Permitted Uses and Disclosures of PHI

Business Associate may use or disclose PHI only as follows:

Business Associate shall not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted above.

3. Safeguards

Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, as required by 45 CFR §164.306 and §164.312. stored.ge provides the following safeguards:

3.1 Encryption at Rest

All stored objects are encrypted at rest using server-side encryption (SSE-S3) with AES-256-GCM. Key encapsulation uses ML-KEM-768, a post-quantum key encapsulation mechanism. Per-tenant encryption keys are derived and managed automatically.

3.2 Encryption in Transit

All data in transit is encrypted via TLS 1.2 or higher. HSTS headers are enforced on all connections. API endpoints are accessible only over HTTPS.

3.3 Access Controls

3.4 Integrity Controls

3.5 Audit Controls

stored.ge maintains audit logs for account access, API operations, and administrative actions. Event logging and webhook notifications are available for real-time monitoring of object operations.

4. Breach Notification

Business Associate shall comply with the breach notification requirements of 45 CFR §§164.400–414:

5. Subcontractors

Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate under this BAA, in accordance with 45 CFR §164.502(e)(1)(ii) and §164.308(b)(2).

6. Access to Records

7. Return or Destruction of PHI

Upon termination of this BAA or the underlying Terms of Service, Business Associate shall:

8. Term and Termination

Contact

For questions about this Business Associate Agreement or to execute a BAA for your organization: