Last updated: June 1, 2026
Business Associate Agreement
This Business Associate Agreement ("BAA") is entered into between you, the Covered Entity or Business Associate ("Covered Entity"), and FairForge LLC, operating as stored.ge ("Business Associate"), and supplements the Terms of Service and Data Processing Agreement.
This BAA is required under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, "HIPAA Rules").
Contents
- Definitions
- Permitted Uses and Disclosures of PHI
- Safeguards
- Breach Notification
- Subcontractors
- Access to Records
- Return or Destruction of PHI
- Term and Termination
- Contact
1. Definitions
Capitalized terms used but not defined in this BAA have the meanings assigned to them in the HIPAA Rules. For purposes of this BAA:
- Covered Entity means the customer who is subject to HIPAA and enters into this BAA in connection with the use of stored.ge services.
- Business Associate means FairForge LLC, operating as stored.ge, which creates, receives, maintains, or transmits Protected Health Information on behalf of the Covered Entity.
- Protected Health Information (PHI) means individually identifiable health information as defined in 45 CFR §160.103, including electronic PHI (ePHI).
- Electronic Protected Health Information (ePHI) means PHI that is transmitted by or maintained in electronic media, as defined in 45 CFR §160.103.
- Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule which compromises the security or privacy of the PHI, as defined in 45 CFR §164.402.
- Security Incident means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system, as defined in 45 CFR §164.304.
2. Permitted Uses and Disclosures of PHI
Business Associate may use or disclose PHI only as follows:
- Service performance: As necessary to perform obligations under the Terms of Service, including storage, retrieval, and delivery of objects via the S3-compatible API.
- Management and administration: For Business Associate's proper management and administration, or to carry out legal responsibilities, provided that any disclosure is required by law or Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially.
- As required by law: As required by applicable federal, state, or local law, provided that Business Associate will notify Covered Entity of such requirement where permitted.
Business Associate shall not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted above.
3. Safeguards
Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, as required by 45 CFR §164.306 and §164.312. stored.ge provides the following safeguards:
3.1 Encryption at Rest
All stored objects are encrypted at rest using server-side encryption (SSE-S3) with AES-256-GCM. Key encapsulation uses ML-KEM-768, a post-quantum key encapsulation mechanism. Per-tenant encryption keys are derived and managed automatically.
3.2 Encryption in Transit
All data in transit is encrypted via TLS 1.2 or higher. HSTS headers are enforced on all connections. API endpoints are accessible only over HTTPS.
3.3 Access Controls
- Unique user identification: Each tenant receives unique access credentials. Scoped API keys provide granular, per-bucket, per-operation access control.
- Two-factor authentication: TOTP-based two-factor authentication is available for all accounts and enforced for administrative access.
- Automatic logoff: Dashboard sessions expire after 24 hours of inactivity, with hourly session cleanup.
- Emergency access: Administrators can reset two-factor authentication and manage account status for emergency access procedures.
3.4 Integrity Controls
- ETag (MD5) verification computed on every upload to ensure data integrity.
- Object Lock (WORM) support for immutable retention of records.
- MFA Delete enforcement prevents unauthorized deletion of versioned objects.
3.5 Audit Controls
stored.ge maintains audit logs for account access, API operations, and administrative actions. Event logging and webhook notifications are available for real-time monitoring of object operations.
4. Breach Notification
Business Associate shall comply with the breach notification requirements of 45 CFR §§164.400–414:
- Discovery and notification: Business Associate shall report to Covered Entity any Breach of Unsecured PHI without unreasonable delay, and in no case later than 72 hours after discovery of the Breach.
- Content of notification: Notification shall include, to the extent available: (a) identification of each individual whose PHI has been or is reasonably believed to have been affected; (b) a description of the type of PHI involved; (c) a description of what Business Associate is doing to investigate, mitigate, and prevent recurrence; (d) contact information for questions.
- Cooperation: Business Associate shall cooperate with Covered Entity in meeting Covered Entity's obligations to notify affected individuals and the Secretary of the U.S. Department of Health and Human Services ("HHS").
- Security incidents: Business Associate shall report to Covered Entity any Security Incident of which it becomes aware. Reports of unsuccessful Security Incidents (e.g., pings, port scans, failed login attempts) may be provided in summary or aggregate form.
5. Subcontractors
Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate under this BAA, in accordance with 45 CFR §164.502(e)(1)(ii) and §164.308(b)(2).
6. Access to Records
- Individual access: Business Associate shall make PHI maintained in Designated Record Sets available to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR §164.524. stored.ge's S3-compatible API provides direct access to all stored objects.
- Amendment: Business Associate shall make PHI available for amendment and incorporate any amendments to PHI as directed by Covered Entity, pursuant to 45 CFR §164.526.
- Accounting of disclosures: Business Associate shall make information available to Covered Entity as required to provide an accounting of disclosures under 45 CFR §164.528.
- HHS access: Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining Covered Entity's compliance with the HIPAA Rules.
7. Return or Destruction of PHI
Upon termination of this BAA or the underlying Terms of Service, Business Associate shall:
- Return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, if feasible.
- If return or destruction is not feasible, extend the protections of this BAA to the PHI retained and limit further uses and disclosures to those purposes that make return or destruction infeasible.
- Account deletion follows the process described in our Terms of Service: a 30-day grace period followed by permanent data destruction.
8. Term and Termination
- Term: This BAA is effective upon execution by both parties and remains in effect for the duration of the underlying Terms of Service, unless terminated earlier as provided herein.
- Termination for cause: Either party may terminate this BAA if the other party materially breaches any provision and fails to cure the breach within 30 days of written notice.
- Effect of termination: The obligations of Business Associate under Section 7 (Return or Destruction of PHI) shall survive termination.
- Regulatory changes: The parties agree to negotiate in good faith any amendments to this BAA necessary to comply with changes to the HIPAA Rules or other applicable law.
Contact
For questions about this Business Associate Agreement or to execute a BAA for your organization:
- Email: compliance@stored.ge
- Entity: FairForge LLC
- Jurisdiction: State of Utah, United States