Ageless Health & Aesthetics and SkyBreak Labs LLC
Made on the date of last signature between Ageless Health & Aesthetics , a and a HIPAA covered entity ("Client"), and SkyBreak Labs LLC, a Florida limited liability company ("Provider"). It accompanies the Master Services Agreement between the parties, which requires it before any patient data moves.
1.1 PHI, Breach, Security Incident, Designated Record Set, Required by Law, Subcontractor, Unsecured PHI and Secretary carry their 45 CFR Parts 160 and 164 meanings (the "HIPAA Rules"), PHI here covering anyone who enquires about, seeks, schedules, receives or declines care from Client, and any hash of an identifier. Designated System: a system listed in Appendix A. Sensitive Category: as the MSA defines it, here Men's sexual health and sexual function. Hormone and testosterone therapy, for any gender. Peptide therapy where it is offered for sexual function or hormonal effect.
1.2 Practice Platform: the account Client holds with Client's own vendor (the "Platform Vendor"), where Provider builds Client's booking, contact and patient communication workflows under access Client grants and may revoke at will. Provider neither owns nor provisions it.
2.1 45 CFR 164.502(b). Provider may receive only contact identifiers and status, appointment or transaction date, status, location, neutral scheduling label, case value, record identifiers and, from the Voice Agent, the caller's stated reason for calling with recording and transcript. Never: diagnosis, condition, symptom, procedure or service line, medication, lab result, clinical note, insurance detail, or anything on substance use disorder, reproductive health, behavioral health or a minor. Adding a field takes a signed amendment.
2.2 Where Client's grant exposes anything outside 2.1, Provider will not open, extract, copy or use it and will ask Client to narrow the permissions. PHI arriving outside 2.1 is quarantined, reported within one business day and destroyed on Client's instruction.
2.3 Exports move by None required as at the Effective Date: no export of Protected Health Information leaves the Practice Platform, and Provider's work on PHI is performed inside it under Client-granted access. Before any export becomes necessary, the transfer mechanism is named here in writing and covered under section 6. Protected Health Information never moves by email, consumer file-sharing services, or removable media.. No PHI moves before this BAA is executed and section 6 satisfied.
PHI reaches Provider only by routes (a) to (e), only as far as the Services require and only in 2.1 fields. Route (f) carries no PHI at all. Client's instruction does not widen this section.
(a) Suppression Export of Client's patient contacts, to keep patients, unsubscribes and do-not-contact requests out of campaigns aimed at people who were never patients, the check running inside Provider's own infrastructure.
(b) Matchback Export of closed appointments and transactions, compared against marketing records for Client's monthly SkyBreak Report and cost per showed appointment, as health care operations (45 CFR 164.501, 164.506), on one-way hashes, keeping aggregates only.
(c) The Voice Agent, answering patient calls and messages, capturing contact details and the stated reason for calling, booking, rescheduling and routing to staff, as appointment scheduling and care coordination. Recordings and transcripts are PHI, kept 90 days, reaching only Client's booking record.
(d) Provider's granted access to the Practice Platform, to run Client's records, calendars, inbox, pipeline stages, follow-up and user administration so far as that grant permits, as health care operations and business management, not a permission to use what accumulates there. Within it Provider may send operational messages (confirmations, reminders, no-show follow-up, care instructions Client authors, missed-call text-back, review requests) as treatment and care coordination, and reactivation, recall and retention campaigns to Client's own patients on section 4's conditions.
(e) Provider may also use and disclose PHI for its own management, administration and legal responsibilities (45 CFR 164.504(e)(4)) and as Required by Law, disclosing only what the law compels or to a recipient who agrees in writing to hold it confidentially, use it only as provided and report any breach to Provider, and telling Client within one business day.
(f) Website visitor identification, advertising and analytics, on every page including a Sensitive Category page. Provider may resolve an anonymous visit to a contact identity and use it for Client's own marketing follow-up and advertising audiences, which from a Sensitive Category page means ordinary page-view retargeting the identity itself never reaches, and may operate advertising and analytics tags on such a page. This is not a route by which PHI reaches Provider: it runs on anonymous traffic and creates Personal Data under the Data Processing Agreement, not PHI, and leaves section 6 unchanged. On such a page it runs only inside the containment rule in MSA 5.2 and DPA 3.2.4, a term of this BAA, and two of those controls condition it: the address of the page is masked and its title replaced with a generic value before either leaves that page, so no third party, an analytics service included, receives the real value, and Provider will not operate resolution, advertising or analytics there without it; and a resolved identity stays inside Client's systems and the Provider systems bound to that rule.
A communication from Client to Client's own patients about health-related services Client itself provides is not marketing under 45 CFR 164.501: it is health care operations under 164.506(a) and needs no 164.508 authorization. If a third party whose product is described pays for one it becomes marketing, and Provider will not send it without each recipient's prior 164.508 authorization. Client is sender of record. No campaign names a price or offer, is segmented on a condition, diagnosis, medication or service line, or is sent only to a Sensitive Category service line, and opt-outs apply everywhere within one business day. Those limits apply equally to a campaign to a person identified under 3(f), which is written to be unremarkable if the resolution landed on the wrong member of a household.
Absolute, overriding sections 3, 4 and 6, and not subject to Client's instruction. Provider will never: (a) use PHI, or any hash of it, to build, seed, enrich, score, target, exclude within or measure any advertising audience, lookalike or match list, to train any model beyond configuring Client's own agent, or to enrich another client's data, nor build any audience or lookalike from Sensitive Category page traffic identifiable by condition; (b) make PHI available in any form, including hashed, to any advertising, analytics, data-broker, identity-resolution, enrichment or list service, or merge it with anonymous-visitor data, including data resolved under 3(f), apart from the read-only comparisons in 3(a) and 3(b), which emit no PHI; (c) sell PHI, or disclose it for remuneration from or on behalf of the recipient, a sale under 45 CFR 164.502(a)(5)(ii); (d) disclose PHI outside the Designated Systems in Appendix A, or an identity resolved under 3(f) from a Sensitive Category page outside Client's own systems and the Provider systems bound to the containment rule, which never include an advertising platform or an analytics service whatever tags Provider is permitted to run there, or send any identifier to an advertising, analytics or measurement platform together with a condition, diagnosis, symptom, medication, procedure or service line, in any event, parameter, address, page title, audience name or custom conversion; (e) send a marketing text or place a marketing call to a person identified under 3(f) absent that person's own documented prior consent, whatever the opportunity; (f) send a person identified under 3(f) from a Sensitive Category page any message that references, implies or is tailored to the page or subject they viewed. Such messages carry ordinary clinic content only, chosen without reference to the resolving page, so that a message reaching another member of the household discloses nothing; or (g) use or further disclose PHI other than as this BAA permits or as Required by Law, or in any way that would violate Subpart E of 45 CFR Part 164 if done by Client (45 CFR 164.504(e)(2)(i), (e)(2)(ii)(A)).
6.1 Provider will use appropriate safeguards and comply, where applicable, with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure other than as this BAA provides (45 CFR 164.504(e)(2)(ii)(B)): access named-account and MFA-protected, transfers encrypted. PHI may exist only in a Designated System listed in Appendix A, including any device on which an export is opened.
6.2 A system is listed only where a current executed business associate agreement covers it and any HIPAA-eligible plan its operator requires is enabled. For the Practice Platform that agreement is between Client and the Platform Vendor, because the account is Client's, and Provider will confirm it is executed before placing PHI there. Every other Designated System is Provider's paper. If a capability needs an unlisted system, or a listed one's agreement lapses, Provider suspends the affected service and tells Client within one business day rather than moving data.
7.1 In accordance with 45 CFR 164.502(e)(1)(ii), Provider will ensure that any Subcontractor that creates, receives, maintains or transmits PHI on Provider's behalf first agrees in writing to the same restrictions and conditions that apply to Provider here, including section 5 (45 CFR 164.504(e)(5)). On learning of a material breach by one, Provider will cure or end it, otherwise terminate that Subcontractor's access, and tell Client.
7.2 The Platform Vendor is Client's own business associate, not Provider's Subcontractor: 7.1 does not reach it and 6.2 governs instead. Provider will tell Client anything it learns that vendor is doing that would breach its obligations to Client.
8.1 Provider will report any use or disclosure of PHI not provided for by this BAA of which it becomes aware, and any Security Incident, within 72 hours of becoming aware.
8.2 Provider will notify Client of a Breach of Unsecured PHI within 72 hours of discovery, shorter than the 60 days 45 CFR 164.410 allows. Discovery is the first day the Breach is known, or by reasonable diligence would have been known, to anyone in Provider's workforce or any Subcontractor other than the person committing it.
8.3 The notice identifies each individual whose Unsecured PHI was, or is reasonably believed to have been, involved and states what happened, when, when discovered, the types of PHI and Provider's remediation, with anything further Client needs for 45 CFR 164.404 to 164.408 as it becomes available. Provider mitigates any harmful effect known to it; Client makes every notification.
9.1 Within ten business days of Client's request Provider will make PHI it maintains in a Designated Record Set available to Client or, at Client's direction, the individual (45 CFR 164.524); make it available for amendment and incorporate any amendment Client directs (164.526); and provide the information required for an accounting of disclosures (164.528).
9.2 To the extent Provider carries out an obligation of Client under Subpart E of 45 CFR Part 164, Provider complies with the requirements of that Subpart that apply to Client in performing it, including any restriction Client agrees under 164.522.
9.3 Provider makes its internal practices, books and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Client available to the Secretary for determining Client's compliance with HIPAA. Individuals contacting Provider are referred to Client.
10.1 This BAA runs from the date of last signature until all PHI is returned or destroyed under 10.2. Client may terminate immediately if Client determines Provider has violated a material term (45 CFR 164.504(e)(2)(iii)); a cure period is Client's to grant, never a precondition.
10.2 On termination, within 30 days, Provider returns or destroys all such PHI it still maintains in any form, retains no copies and requires the same of its Subcontractors. Where that is not feasible, Provider tells Client what and why, limits further use and disclosure to the purposes making return or destruction infeasible, and extends this BAA's protections to that PHI while held (45 CFR 164.504(e)(2)(ii)(J)).
10.3 Sections 3(e), 5, 8, 9.3 and 10 survive.
On PHI this BAA controls over the MSA and reduces no protection either gives; liability and caps are the MSA's. Ambiguity resolves toward compliance with the HIPAA Rules. Amendment is in writing signed by both, and Florida law governs except where federal law controls. CAN-SPAM, the TCPA and state telemarketing and call-recording laws apply independently.
The only systems PHI may exist in under section 6, as at August 7, 2026. Everything unlisted is excluded, as a term of this BAA.
Ageless Health & Aesthetics · Signature: ______________________ Date: _________ · Name: Ryan Ramos, MD, FACS · Title:
SkyBreak Labs LLC · Signature: ______________________ Date: _________ · Name: ______________________ · Title: ______________________
Notices to team@ageless-orlando.com and hello@skybreaklabs.com.