Skip to main content

LEGAL & PRIVACY

Business Associate Agreement

How Mamavi handles protected health information on behalf of the practices, doulas and midwives who use the Care Provider Portal — and how to put a signed BAA in place.

Effective

What this page is, and what it is not

A Business Associate Agreement is a contract required by the HIPAA Privacy Rule whenever a covered entity lets a vendor create, receive, maintain or transmit protected health information on its behalf. It has to be signed by both parties. A published web page cannot do that job.

So this page is not itself a signed agreement, and reading it does not create one. It exists to tell you, before you go any further, exactly what Mamavi commits to as a business associate — and to give you a way to execute the real document.

When HIPAA applies to Mamavi

HIPAA regulates covered entities — most health-care providers, health plans and clearing houses — and the business associates who handle protected health information for them. It does not regulate an individual keeping notes about their own pregnancy.

That distinction matters here. When a parent uses the Mamavi app for themselves, we are handling their own data at their direction: HIPAA generally does not apply, and our Privacy Policy is the document that governs.

When a doula, midwife, OB-GYN or practice uses the Care Provider Portal to manage clients, that professional may be a covered entity, and Mamavi is then handling protected health information on their behalf. That is the relationship a BAA covers.

What our BAA commits us to

The agreement we offer follows the required elements of 45 CFR §164.504(e). In summary, Mamavi Health, Inc. agrees to:

  • Use and disclose protected health information only as the agreement permits, as the covered entity directs, or as required by law.
  • Apply the administrative, physical and technical safeguards of the HIPAA Security Rule to any electronic protected health information we hold.
  • Report to the covered entity any use or disclosure not provided for by the agreement, including any security incident or breach.
  • Bind every subcontractor that touches protected health information to the same restrictions and conditions.
  • Make protected health information available so the covered entity can meet an individual’s right of access, amendment and accounting of disclosures.
  • Make our internal practices, books and records available to the Secretary of Health and Human Services for compliance review.
  • Return or destroy all protected health information at the end of the agreement, where that is feasible, and extend the protections to anything that cannot be returned or destroyed.

The safeguards behind those commitments

The commitments above are backed by concrete engineering, not just contract language. Data is encrypted in transit with TLS and at rest by our hosting providers. Passwords are hashed with bcrypt and never stored in plain text.

Every API request is authenticated with a signed token and then authorised against the specific household it touches — a provider cannot read a client they are not connected to, even by guessing an identifier. Provider exports additionally require recorded client consent, and every export is logged.

Our API does not include request contents in its error responses.

Breach notification

If we discover a breach of unsecured protected health information, we will notify the affected covered entity without unreasonable delay and no later than 60 days after discovery, as the Breach Notification Rule requires.

The notice will identify the individuals affected so far as we know them, describe what happened and when, say what information was involved, and set out what we are doing about it. We will cooperate with the covered entity’s own notification obligations.

Subcontractors

Mamavi uses a small number of vendors to run the service — managed database hosting, media storage, transactional email, AI inference and payment processing. Any of them that creates, receives, maintains or transmits protected health information on our behalf is a subcontractor under the agreement.

We contract with each of those subcontractors on terms at least as protective as the ones we give you, and we remain responsible to you for what they do. We will tell you who they are on request.

Term, termination and return of data

The agreement runs for as long as Mamavi holds protected health information for you. Either party may terminate it if the other materially breaches it and does not cure the breach within a reasonable period.

On termination we will return or destroy the protected health information we hold for you. Where that is not feasible — for instance, within an encrypted backup awaiting its normal expiry — we will extend the agreement’s protections to it and limit further use to whatever makes return or destruction infeasible.

How to execute a BAA with us

Write to hello@mamavihealth.com with your practice name, the name and title of the person authorised to sign, and the professional role you are registering under. We will send you the executable agreement.

Do not upload client information into the Care Provider Portal before the agreement is in place if your organisation requires one first. If you are unsure whether you need a BAA, that is a question for your own compliance advisor, not for us.

If you are a parent, not a practice

You almost certainly do not need a BAA. HIPAA regulates the professionals and organisations who treat you, not you as an individual. The document that governs your own pregnancy and postpartum data in Mamavi is our Privacy Policy — that is the one worth reading.

Contact us

BAA requests and compliance questions: hello@mamavihealth.comMamavi Health, Inc.