Legal · BAA
Business Associate Agreement
Effective Date: April 1, 2026
Parties
This Business Associate Agreement (“BAA”) is entered into between Rooted Maternal Wellness LLC d/b/a LactaRoute (“Business Associate” or “LactaRoute”), a technology platform operator, and the healthcare provider or practice (“Covered Entity”) that has registered for and uses the LactaRoute platform.
This BAA is incorporated into and made part of the LactaRoute Terms of Service. By activating or continuing to use a LactaRoute account, the Covered Entity agrees to this BAA.
1. Definitions
Terms used but not otherwise defined in this BAA have the meanings assigned to them in HIPAA, including 45 C.F.R. Parts 160 and 164.
- HIPAA means the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH, and implementing regulations.
- Protected Health Information (PHI) has the meaning given in 45 C.F.R. § 160.103.
- Electronic PHI (ePHI) means PHI that is created, received, maintained, or transmitted in electronic form.
- Services means the scheduling, clinical documentation, billing, and practice management features provided by LactaRoute.
2. Obligations of Business Associate
LactaRoute agrees to:
- Not use or disclose PHI except as permitted or required by this BAA or as required by law.
- Use appropriate safeguards, and comply with the HIPAA Security Rule with respect to ePHI, to prevent use or disclosure of PHI other than as permitted by this BAA.
- Report to the Covered Entity any use or disclosure of PHI not provided for by this BAA, including breaches of unsecured PHI as required by 45 C.F.R. § 164.410, without unreasonable delay and in no case later than 60 calendar days following discovery of a breach.
- Ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of LactaRoute agree to the same restrictions and conditions that apply to LactaRoute.
- Make available PHI in a designated record set to the Covered Entity as necessary to satisfy the Covered Entity's obligations under 45 C.F.R. § 164.524.
- Make its internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance with HIPAA.
- Upon termination of this BAA, return or destroy all PHI received from or created on behalf of the Covered Entity, if feasible, or extend the protections of this BAA to any retained PHI.
3. Permitted Uses and Disclosures
LactaRoute may use or disclose PHI:
- To provide the Services described in the Terms of Service, including scheduling, clinical charting, billing, and care coordination features.
- For LactaRoute's proper management and administration, provided any disclosure is required by law or LactaRoute obtains reasonable assurances that the recipient will hold the PHI confidentially.
- To provide data aggregation services relating to the health care operations of the Covered Entity.
- To de-identify PHI in accordance with 45 C.F.R. § 164.514, after which the resulting data is no longer PHI and not subject to this BAA.
4. Obligations of Covered Entity
The Covered Entity agrees to:
- Notify LactaRoute of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to abide by.
- Not request that LactaRoute use or disclose PHI in any manner that would not be permissible under HIPAA if done by the Covered Entity.
- Obtain any necessary authorizations from patients before using LactaRoute features that involve disclosures of PHI not otherwise permitted by HIPAA.
- Maintain an accurate and current list of authorized users of the Covered Entity's LactaRoute account.
5. Security Measures
LactaRoute implements and maintains commercially reasonable administrative, physical, and technical safeguards for ePHI, including:
- Encryption of ePHI at rest and in transit using industry-standard protocols (TLS 1.2+, AES-256).
- Role-based access controls limiting PHI access to authorized personnel.
- Regular security assessments and monitoring.
- Encrypted storage of sensitive credentials (API keys, Stripe keys) using AES-256-GCM.
- Hosting on AWS infrastructure with SOC 2 Type II certification.
6. Subcontractors
LactaRoute uses the following subcontractors (“Subprocessors”) that may create, receive, maintain, or transmit ePHI in connection with the Services:
- Amazon Web Services (AWS) — hosting, database, file storage, video visits (Amazon Chime), and last-resort audio transcription (Amazon Transcribe).
- Anthropic — the AI features: drafting visit notes, letters, and reports from transcripts and chart content; reading insurance-card photos; and translating speech during interpreted visits.
- Deepgram — transcription of visit audio for the AI scribe (the primary path), plus live captions and spoken interpretation.
- Groq — transcription of visit audio for the AI scribe (live segments).
- OpenAI (Whisper) — transcription of visit audio for the AI scribe (the fallback when Deepgram and Groq are unavailable).
- Stedi — insurance eligibility checks and insurance discovery: the client's name, date of birth, member ID, and, for discovery, address.
- Telnyx — Practice Phone calls and voicemail, faxes sent and received on LactaRoute fax numbers, and texts sent from LactaRoute's texting number.
- Resend — email LactaRoute sends on a practice's behalf when the practice has not connected its own mailbox, such as booking confirmations, intake links, and team notices.
- Google Maps Platform — address lookup and drive-time estimates for home visits: addresses only, never names or clinical information.
- Stripe — card payments: the client's name, email, the amount, and a short description such as “Lactation Consultation”.
AWS, Anthropic, Deepgram, Groq, and OpenAI operate under signed agreements consistent with the obligations set forth in this BAA. Stripe processes payment data under a data processing agreement.
When the Covered Entity connects its own account with one of the following services, LactaRoute sends that service what the connection needs, at the Covered Entity's direction, and the Covered Entity's own agreement with that service governs it: Spruce Health (texts), Office Ally (claims and remittance), Availity (eligibility), SRFax (fax), Square (payments), Google Calendar and Gmail (calendar events and email), Zoom (video visits), Google Analytics (visits to the embedded booking page, under the practice's own measurement ID), and the Covered Entity's own email server.
LactaRoute will notify the Covered Entity of any material changes to its Subprocessor list by updating this BAA. Continued use of the Service after such update constitutes acceptance.
7. Breach Notification
In the event of a breach of unsecured PHI, LactaRoute will:
- Notify the Covered Entity without unreasonable delay and in no case later than 60 calendar days following discovery of the breach, as required by 45 C.F.R. § 164.410.
- Include in such notification the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach, to the extent known.
- Provide any other information reasonably requested by the Covered Entity to enable it to fulfill its own breach notification obligations under 45 C.F.R. § 164.404.
- Cooperate with the Covered Entity in complying with applicable state breach notification laws, including the New Jersey Identity Theft Prevention Act (N.J.S.A. 56:11-44 et seq.).
8. Term and Termination
This BAA is effective as of the Effective Date and remains in effect until the Covered Entity's use of LactaRoute terminates. Either party may terminate this BAA upon 30 days written notice if the other party has materially breached any provision and failed to cure the breach within that period.
Upon termination, LactaRoute will, within 60 days, either return or destroy all PHI received from or created on behalf of the Covered Entity, to the extent feasible. To the extent return or destruction is not feasible, LactaRoute will extend the protections of this BAA to the PHI and limit further use and disclosure.
9. Limitation of Liability
To the maximum extent permitted by applicable law, LactaRoute's liability under this BAA shall not exceed the amount paid by the Covered Entity to LactaRoute in the twelve (12) months preceding the claim. LactaRoute shall not be liable for any indirect, incidental, special, or consequential damages arising from a breach of this BAA.
10. Governing Law
This BAA shall be governed by the laws of the State of New Jersey, without regard to its conflict of laws provisions, and applicable federal law including HIPAA.
11. Amendment
LactaRoute may amend this BAA to comply with changes in applicable law or regulation, including HIPAA, by providing 30 days written notice to the Covered Entity. Continued use of LactaRoute after the effective date of any amendment constitutes acceptance of the amended BAA.
12. Contact
Questions regarding this BAA should be directed to: info@rootedmaternalwellness.com