Business Associate Addendum

Published: September 21, 2026

This Business Associate Addendum (“BAA”) constitutes an integral part of the Agreement by and between Inbenta and Customer, as each Party is identified in the relevant Order Form document(s) under which processing PHI is relevant. This BAA reflects the Parties’ agreement with regard to the Processing of PHI in accordance with the requirements of HIPAA.

This BAA is effective on the Effective Date of the TOS, and amends, supersedes and replaces any prior agreement relating to processing PHI that the Parties may have previously entered into. Capitalized terms used but not defined herein have the meaning provided in the TOS.

Background

Customer is either a “covered entity” or a “business associate” of a covered entity, as each is defined under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, as amended by the HITECH Act and the related regulations promulgated by HHS (collectively, “HIPAA”) and, as such, is required to comply with HIPAA’s provisions regarding the confidentiality and privacy of Protected Health Information;

The Parties have entered into the Agreement, under which Inbenta will provide Services to Customer that are specified therein that do not require access to or use of Protected Health Information, however Customer has determined there is a likelihood of Protected Health Information being included by third party Users of the Services;

To the extent Inbenta has access to Protected Health Information while providing Services pursuant to the Agreement, Inbenta will become a “business associate” of Customer;

Both Parties are committed to complying with all applicable United States federal and state laws governing the confidentiality and privacy of health information, including, but not limited to, the Privacy Rule; and,

Both Parties intend to protect the privacy and provide for the security of Protected Health Information disclosed to Inbenta pursuant to the terms of the Agreement, this BAA, HIPAA, and as otherwise Required By Law.

Statement of Agreement

NOW, THEREFORE, in consideration of the mutual covenants and conditions contained herein and subject to the continued provision of PHI under the Agreement, the Parties hereby agree as follows:

1. Definitions

For purposes of this BAA, the Parties give the following meaning to each of the terms in this Section 1, below. Any term used in this BAA but not otherwise defined herein, will have the meaning given to that term in the Agreement, HIPAA, the Privacy Rule or pertinent law.

a.Breach” means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule and which compromises the security or privacy of the PHI, as defined in 45 CFR §164.402.

b.CFR” shall mean the Code of Federal Regulations.

c.Data Aggregation” means, with respect to PHI created or received by Business Associate in its capacity as the “business associate” under HIPAA of Covered Entity, the combining of such PHI by Business Associate with the PHI received by Business Associate in its capacity as a business associate of one or more other “covered entity” under HIPAA, to permit data analyses that relate to the Health Care Operations (defined below) of the respective covered entities. The meaning of “data aggregation” in this BAA shall be consistent with the meaning given to that term in the Privacy Rule.

d.Designated Record Set” has the meaning given to such term under the Privacy Rule, including 45 CFR §164.501.B.

e.De-Identify” means to alter the PHI such that the resulting information meets the requirements described in 45 CFR §§164.514(a) and (b).

f.Electronic PHI” means any PHI maintained in or transmitted by electronic media as defined in 45 CFR §160.103.

g.Health Care Operations” has the meaning given to that term in 45 CFR §164.501.

h.HHS” means the U.S. Department of Health and Human Services.

i.HITECH Act” means the Health Information Technology for Economic and Clinical Health Act, enacted as part of the American Recovery and Reinvestment Act of 2009, Public Law 111-005.

j.Individual” has the same meaning given to that term in 45 CFR §§164.501 and 160.130 as to a person who qualifies as a personal representative in accordance with 45 CFR §164.502(g).

k.Privacy Rule” means that portion of HIPAA set forth in 45 CFR Part 160 and Part 164, Subparts A and E.

l.Protected Health Information” or “PHI” has the meaning given to the term “protected health information” in 45 CFR §§164.501 and 160.103, limited to the information created or received by Inbenta from or on behalf of Customer.

m.Required By Law” has the meaning given to it under HIPAA in 45 CFR § 164.103.

n.Security Incident” has the meaning given to it under HIPAA in 45 CFR § 164.304 as to the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.

o.Security Rule” means the Security Standards for the Protection of Electronic Health Information provided in 45 CFR Part 160 & Part 164, Subparts A and C.

p.Unsecured Protected Health Information” or “Unsecured PHI” means any Protected Health Information that is not rendered unusable, unreadable or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the HHS Secretary in the guidance issued pursuant to the HITECH Act and codified at 42 USC §17932(h).

2. Use and Disclosure of PHI

a. Except as otherwise provided in this BAA, Inbenta may access, use, disclose, modify or destroy PHI as reasonably necessary to provide the Services described in the Agreement to Customer, and to undertake other activities of Inbenta permitted or required of Inbenta by the Agreement, this BAA, or as otherwise Required By Law.

b. Except as otherwise limited by this BAA or federal or state law, Customer authorizes Inbenta to use the PHI in its possession for the proper management and administration of Inbenta’s business and to carry out its legal responsibilities. Inbenta may disclose PHI for its proper management and administration, provided that (i) the disclosures are Required By Law; or (ii) Inbenta obtains, in writing, prior to making any disclosure to a third party reasonable assurances from this third party that the PHI will be held confidential as provided under this BAA and used or further disclosed only as Required By Law or for the purpose for which it was disclosed to this third party.

c. Inbenta will not use or disclose PHI in a manner other than as provided in this BAA, as permitted under the Privacy Rule, or as Required By Law. Inbenta may use or disclose PHI, to the extent practicable, as a limited data set or limited to the reasonably necessary amount of PHI to carry out the intended purpose of the use or disclosure, in accordance with the requirements of HIPAA, including Section 13405(b) of the HITECH Act (codified at 42 USC §17935(b)) and any of the act’s implementing regulations adopted by HHS, for each use or disclosure of PHI.

d. Upon request, Inbenta will make available to Customer any of Customer’s PHI that Inbenta or any of its agents or subcontractors have in their possession, subject to the provisions of this BAA.

e. Inbenta may use PHI to report violations of law to appropriate U.S. federal and state authorities, consistent with 45 CFR §164.502(j)(1).

3. Safeguards Against Misuse of PHI

As are reasonable in light of the nature of the Services, Inbenta will use appropriate safeguards designed to prevent the unauthorized use or disclosure of PHI provided during Customer’s use of the Services, and Inbenta agrees to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI that it creates, receives, maintains or transmits on behalf of Customer. Inbenta agrees to take reasonable steps, including providing training to its employees to comply with this BAA and that are designed to prevent actions or omissions of its employees or agents from causing Inbenta to breach the terms of this BAA.

4. Reporting Disclosures of PHI and Security Incidents

Inbenta will report to Customer in writing (including by email) any use or disclosure of PHI not provided for by this BAA or the Agreement of which it becomes aware and Inbenta agrees to report to Customer any Security Incident actually affecting electronic PHI of Customer of which it becomes aware. Inbenta agrees to report any such event without unreasonable delay and in no case later than 60 calendar days after confirmation of the event.

5. Reporting Breaches of Unsecured PHI

Inbenta will inform Customer in writing (including by email) promptly upon the discovery of any Breach of Unsecured PHI in accordance with the requirements set forth in 45 CFR §164.410. To the extent feasible, such information shall include the identification of each Individual whose Protected Health Information has been, or is reasonably believed by Inbenta to have been improperly accessed, acquired, or disclosed.

6. Mitigation of Disclosures of PHI

Inbenta will take reasonable measures to mitigate, to the extent practicable, potential risks reasonably likely to result in a harmful effect that is known to Inbenta of any use or disclosure of PHI by Inbenta or its agents or subcontractors in violation of the requirements of this BAA.

7. Agreements with Agents or Subcontractors

Inbenta will take appropriate measures designed to ensure that any agents or subcontractors used by Inbenta to perform its obligations under the Agreement that require access to PHI are bound by written obligations that provide materially the same level of protection for PHI as this BAA. To the extent that Inbenta uses agents or subcontractors in its performance of obligations hereunder, Inbenta will remain responsible for their performance as if performed by Inbenta.

8. Audit Report

To the extent Required By Law, and subject to all applicable legal privileges, Inbenta shall, upon written request, make available its internal practices, books, agreements, records, and policies and procedures relating to the use and disclosure of PHI to the Secretary of the Department of Health and Human Services (the “Secretary”) for the purpose of the Secretary determining Customer’s and Inbenta’s compliance with HIPAA and this BAA.

9. Access to PHI by Individuals

a. Upon request, Business Associate agrees to furnish Covered Entity with copies of the PHI maintained by Business Associate in a Designated Record Set in the time and manner designated by Covered Entity to enable Covered Entity to respond to an Individual’s request for access to PHI under 45 CFR §164.524.

b. In the event any Individual or personal representative requests access to the Individual’s PHI directly from Business Associate, Business Associate will forward that request to Covered Entity without unreasonable delay. Any disclosure of, or decision not to disclose, the PHI requested by an Individual or a personal representative and compliance with the requirements applicable to an Individual’s right to obtain access to PHI shall be the sole responsibility of Covered Entity.

10. Amendment of PHI

a. Upon request and instruction from Covered Entity, Business Associate will amend PHI or a record about an Individual in a Designated Record Set that is maintained by, or otherwise within the possession of, Business Associate as directed by Covered Entity in accordance with procedures established by 45 CFR §164.526. Any request by Covered Entity to amend such information will be completed by Business Associate without unreasonable delay.

b. In the event that any Individual requests that Business Associate amend such Individual’s PHI or record in a Designated Record Set, Business Associate will forward that request to Covered Entity without unreasonable delay. Any amendment of, or decision not to amend, the PHI or record as requested by an Individual and compliance with the requirements applicable to an Individual’s right to request an amendment of PHI will be the sole responsibility of Covered Entity.

11. Accounting of Disclosures

a. Inbenta will document any disclosures of PHI made by it to account for such disclosures as required by 45 CFR §164.528(a). Inbenta also will make available information related to such disclosures as would be required for Customer to respond to a request for an accounting of disclosures in accordance with 45 CFR §164.528. At a minimum, Inbenta will furnish Customer the following with respect to any covered disclosures by Inbenta: (i) the date of disclosure of PHI; (ii) the name of the entity or person who received PHI, and, if known, the address of such entity or person; (iii) a brief description of the PHI disclosed; and (iv) a brief statement of the purpose of the disclosure which includes the basis for such disclosure.

b. Inbenta will furnish to Customer information collected in accordance with this Section without unreasonable delay after receiving a written request from Customer, to permit Customer to make an accounting of disclosures as required by 45 CFR §164.528, or if Customer elects to provide an Individual with a list of its business associates, Inbenta will provide an accounting of its disclosures of PHI upon request of the Individual, if and to the extent that such accounting is required under the HITECH Act or under HHS regulations adopted in connection with the HITECH Act.

c. In the event an Individual delivers the initial written notice for an accounting directly to Inbenta in relation to such Individual’s PHI stored by Inbenta, Inbenta will forward such request to Customer without unreasonable delay.

12. Availability of Books and Records

Business Associate will make available its internal practices, books, agreements, records, and policies and procedures relating to the use and disclosure of PHI, upon written request, to the Secretary of HHS for purposes of determining Covered Entity’s and Business Associate’s compliance with HIPAA, and this BAA.

13. Responsibilities of Customer

With regard to the use or disclosure of Protected Health Information by Inbenta, Customer agrees that it will:

a. Not include in its notice of privacy practices any limitation that limits Inbenta’s permitted or required uses or disclosures of PHI under this BAA, unless such a limit is required by law. If Customer is required by law to include such a limitation in its notice of privacy practices, Customer shall promptly notify Inbenta of any such limitation, to the extent that such limitation may affect Inbenta’s use or disclosure of PHI.

b. Notify Inbenta of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such changes may affect Inbenta’s use or disclosure of PHI.

c. Not agree to any request for a restriction that limits Inbenta’s permitted or required uses or disclosures of PHI under this BAA, or delivery of the Services, unless it is Required By Law. If Customer is required by law to agree to such a restriction, Customer shall promptly notify Inbenta of any such restriction.

d. Not request or cause Inbenta to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Customer, or in any way that does not conform to the Services.

e. Implement and use appropriate privacy and security safeguards designed to prevent unauthorized use or disclosure of PHI, and to implement and use administrative, physical, and technical safeguards in order to reasonably and appropriately protect PHI in compliance with HIPAA and this BAA and as otherwise required under the Security Rule. In particular, Customer shall encrypt all PHI stored in or transmitted using the Services in accordance with the Secretary of HHS’s document entitled “Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals”, available online at https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html, as it may be updated from time to time, and as may be made available on any successor or related site designated by HHS. To the extent that Customer chooses to use the Services to transmit PHI without encryption, Customer is responsible for documenting under the Security Rule that encryption is not reasonable and appropriate for such communications and implementing any equivalent alternative measures if reasonable and appropriate. Customer acknowledges and agrees that Inbenta has no obligation to protect PHI under this BAA to the extent that Customer creates, receives, maintains, or transmits PHI outside of the Services.

f. Warrant for each delivery of PHI that it has obtained any necessary authorizations, consents, and other permissions that may be required under applicable law prior to disclosing or uploading any data, including without limitation PHI, in relation to the Services.

14. Data Ownership

This BAA will in no way alter that data ownership provisions agreed to in the Agreement.

15. Term and Termination

a. This BAA will terminate on the earlier of (i) a permitted termination in accordance with this Section 15, or (ii) the expiration or termination of the Agreement under which Customer has access to the Services.

b. Customer may terminate immediately this BAA if it is determined that Inbenta has breached a material term of this BAA and Inbenta has failed to cure that material breach, to Customer’s reasonable satisfaction, within 30 days after written notice from Customer. Customer may report the problem to the Secretary of HHS if Required By Law, subject to all applicable legal privileges.

c. Subject to the section in the Agreement regarding Suspension, if Inbenta determines that Customer has breached a material term of this BAA, then Inbenta will provide Customer with written notice of the existence of the breach and shall provide Customer with 30 days to cure the breach. Customer’s failure to cure the breach within the 30-day period will be grounds for immediate termination of the Agreement or this BAA by Inbenta. Inbenta may report the breach to HHS, subject to all applicable legal privileges.

d. After termination of the Agreement or this BAA for any reason, all PHI maintained by Inbenta will be deleted from the Services in accordance with terms relating to Customer Data in the Agreement. Inbenta will extend the protections of this BAA to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for as long as Inbenta maintains such PHI. The Parties understand that this Section 15.D. will survive any termination of this BAA.

16. Effect of BAA

This BAA is a part of and subject to the terms of the Agreement. This BAA, together with the Agreement as amended by this BAA, (i) is intended by the Parties as a final, complete and exclusive expression of the terms of their agreement and (ii) supersedes all prior agreements and understandings (whether oral or written) between the Parties with respect to the subject matter hereof. The provisions of this BAA override and control any conflicting provision of the Agreement; however, except as expressly modified or amended under this BAA as to PHI, the terms of the Agreement remain in full force and effect.

17. Amendments to Comply with Law

The Parties acknowledge that federal and state laws relating to data security and privacy of health information are rapidly evolving and that amendment of this BAA may be required to provide for procedures to ensure compliance with such developments. The Parties specifically agree to take such action as is necessary to implement the standards and requirements of HIPAA. Upon the request of either Party, the other Party agrees to promptly enter into negotiations concerning the terms of an amendment to this BAA embodying written assurances consistent with the standards and requirements of HIPAA or other applicable laws. Either Party may terminate this BAA upon thirty (30) days prior written notice in the event that the other Party: (i) does not promptly enter into negotiations to amend this BAA when requested pursuant to this Section 16; or (ii) does not enter into an amendment to this BAA providing assurances regarding the safeguarding of PHI sufficient to satisfy the standards and requirements of HIPAA.

18. Interpretation

This BAA and the Agreement shall be interpreted as broadly as necessary to implement and comply with HIPAA. The Parties agree that any ambiguity in this BAA shall be resolved in favor of a meaning that complies, and is consistent, with HIPAA.