Business Associate Agreement

v1.1First published: 15 October 2025Last updated: 1 September 2026Effective: 1 October 2026

This Business Associate Agreement (BAA) establishes the legal and operational framework under which Narra Technologies Private Limited processes Protected Health Information (PHI) on behalf of healthcare providers, hospitals, and covered entities. It applies to healthcare deployments only. Commerce deployments of Narra do not process PHI and do not require a BAA.

Scope: When This Agreement Applies

This BAA applies only where Narra processes Protected Health Information on behalf of a healthcare organisation. Read this section before anything else.

This agreement applies to you if

  • You are a healthcare provider, hospital, clinic, diagnostic centre, laboratory, pharmacy, or telemedicine platform, and
  • You store, transmit, or process patient health data in Narra.

This agreement does not apply to you if

  • You run a commerce deployment of Narra, for example grossDule, storeDule, or webDule. Those products handle catalogue, inventory, order, and customer data. They do not process Protected Health Information, and no BAA is required or offered for them. Your relationship is governed by the Terms of Service and the Data Processing Agreement.
  • You use Narra only for administrative functions with no patient data.

If a commerce customer has been shown this document from a product footer, it is for reference only. Nothing in it applies to a deployment that holds no PHI.

Parties to This Agreement

Covered Entity (Provider)

A licensed healthcare provider (doctors, clinics, hospitals, labs, telemedicine platforms) that creates, receives, maintains, or transmits PHI.

Business Associate (Narra)

Narra Technologies Private Limited, a company incorporated in India with its registered office in Hyderabad, Telangana: a technology platform processing health data on behalf of Covered Entities.

What Narra IS

  • A data processor and custodian
  • A technology platform
  • Responsible for the security of the PHI in its systems

What Narra IS NOT

  • A healthcare provider
  • Responsible for clinical decisions
  • A medical device

Permitted Uses & Disclosures

Narra may use and disclose PHI only as permitted by this agreement, as required by law, or as otherwise instructed in writing by the Covered Entity. Any use or disclosure not permitted here is prohibited.

Minimum necessary

Narra requests, uses, and discloses only the minimum amount of PHI necessary to accomplish the purpose of the use, disclosure, or request, consistent with 45 CFR 164.502(b) and 164.514(d).

Healthcare Coordination

Store and manage health records to enable patient access, provider access with consent, referrals, test result delivery, and clinical documentation.

National health network integration

Where a national health record network is available, accounts may be linked with patient consent so that health data can be exchanged across that network. India's ABDM, and the ABHA identifier it issues, are one such network.

Patient controls:

  • Integration is optional
  • The patient can revoke access
  • The patient controls what data is shared

Business Operations

Permitted uses: system administration, security and fraud prevention, de-identified analytics, and compliance and audit, in each case for the proper management and administration of Narra or to carry out its legal responsibilities, as permitted by 45 CFR 164.504(e)(4).

Restrictions: no identifying information in analytics; no marketing use; no sale of PHI. De-identification, where performed, follows the Safe Harbor method at 45 CFR 164.514(b)(2), or an expert determination under 164.514(b)(1).

Legal Compliance

Disclose only when required by law (court orders, regulatory requests, public health authorities). Narra will notify the Covered Entity of legal requests except where prohibited, and where it discloses PHI to a third party as required by law it obtains reasonable assurances of confidentiality and of notice of any further compelled disclosure.

Prohibited Uses

Narra WILL NOT:

  • Sell health data to third parties
  • Use health data for marketing or advertising
  • Share with insurance companies without consent
  • Share with employers
  • Share with pharmaceutical companies
  • Use PHI to train, fine-tune, or evaluate machine-learning models without the Covered Entity's explicit written consent. The same prohibition appears in our Terms of Service and Privacy Policy, so the three documents agree.
  • Share with data brokers
  • Use health data for discrimination
  • Rent or lease health data
  • Use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by the Covered Entity, except as permitted at 45 CFR 164.504(e)(4)

Obligations of Narra

  • Confidentiality: Treat all health data as confidential, limit disclosure, employees sign NDA
  • Data Security: AES-256 encryption, TLS 1.3, Google Cloud KMS, MFA, RBAC, background checks. Administrative, physical, and technical safeguards that reasonably and appropriately protect electronic PHI, as required by the HIPAA Security Rule at 45 CFR 164.308, 164.310, 164.312, and 164.316.
  • Access Controls: MFA, granular permissions, 24/7 monitoring
  • Audit Logging: Complete trail retained 5 years, or the longer period required by applicable law, and available to the Covered Entity
  • Data Integrity: Checksums, version control
  • Availability: 99.5% uptime, RTO < 4 hours
  • Breach Notification: Notify the Covered Entity without unreasonable delay and in any event within 24 hours of discovery, and within 1 hour for a breach assessed as critical. See the Breach Notification section for the full timetable.
  • Mitigation: Mitigate, to the extent practicable, any harmful effect known to Narra of a use or disclosure of PHI in violation of this agreement (45 CFR 164.530(f)).
  • Access to books and records: Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the US Department of Health and Human Services for purposes of determining the Covered Entity's compliance with the HIPAA Privacy Rule (45 CFR 164.504(e)(2)(ii)(I)).

Subcontractors & Flow-Down

Narra may engage subcontractors that create, receive, maintain, or transmit PHI on its behalf only where it has first obtained written assurances, in a binding agreement, that the subcontractor agrees to the same restrictions, conditions, and requirements that apply to Narra under this BAA with respect to that PHI. This gives effect to 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2).

Each subcontractor agreement must

  • Restrict use and disclosure of PHI to the purposes for which the subcontractor was engaged
  • Require implementation of safeguards at least equivalent to those in this BAA
  • Require the subcontractor to report a breach or unauthorised use or disclosure to Narra within 24 hours of discovery
  • Flow the same obligations down to any further subcontractor
  • Require return or destruction of PHI at the end of the engagement
  • Give Narra audit and information rights that it can exercise on the Covered Entity's behalf

Narra remains fully liable to the Covered Entity for the acts and omissions of its subcontractors in relation to PHI.

Obligations of the Covered Entity

  • Have legal authority as a licensed healthcare provider
  • Obtain patient consent, or another lawful basis, for the processing
  • Comply with applicable clinical and accreditation standards, including NABL, NABH, and Medical Council standards where they apply
  • Inform patients that Narra is used to process their data
  • Notify Narra of any limitation in its notice of privacy practices, of any change to or revocation of a patient's permission, and of any restriction on the use or disclosure of PHI that it has agreed to, to the extent any of these affect Narra's permitted uses (45 CFR 164.504(e)(1)(iii))
  • Not ask Narra to use or disclose PHI in a way that would be impermissible if done by the Covered Entity itself
  • Report suspected breaches to Narra immediately
  • Cooperate with breach investigation

Security Safeguards

Technical

Encryption
AES-256 at rest, TLS 1.3 in transit, keys held in Google Cloud KMS
Access
MFA, RBAC, least privilege
Monitoring
Intrusion detection and behavioural analytics

Physical

Data centres
Google Cloud data centres in the residency region for the deployment, which is asia-south1 (Mumbai, India) today, with 24/7 security personnel and biometric access control
Disaster recovery
Encrypted backups replicated to a second location within the residency region, with tested restore procedures

Administrative

Personnel
Background checks and written confidentiality obligations
Training
Annual security and privacy training
Incident response
Documented incident response plan, exercised quarterly
Risk management
Annual risk assessment, as required by 45 CFR 164.308(a)(1)(ii)(A)

Our current certification status, stated plainly, is in the Data Security Statement.

Sub-processors & Approved Vendors

Requirements for all sub-processors that touch PHI:

  • Must sign a written agreement with the flow-down terms in the Subcontractors & Flow-Down section
  • Must maintain ISO/IEC 27001 certification or an equivalent independently assessed control framework
  • Must report breaches to Narra within 24 hours of discovery
  • Must keep PHI within the agreed residency region

Approved sub-processors that may process PHI:

Vendor Purpose Processing region
Google Cloud Platform Application hosting, compute, storage, key management, logging asia-south1 (Mumbai, India)
Firebase (Google) Authentication and static hosting. Holds account identifiers, not clinical records. Google Cloud region for the project
MongoDB Atlas Managed application database Google Cloud asia-south1 (Mumbai, India)

Payment processors do not receive PHI. Razorpay and Stripe process billing data only. They are listed, with their regions, in the sub-processor table in the Data Processing Agreement, which is the single authoritative list for the whole corpus.

Not used: Narra does not currently use Amazon Web Services. Earlier versions of this document listed AWS as a sub-processor and as a key store. That was inaccurate and has been corrected.

Adding new sub-processors: at least 30 days written notice to the Covered Entity, which may object on reasonable grounds or terminate the affected services without penalty. The full procedure, including how to subscribe to change notices, is in the Sub-processors section of the Data Processing Agreement.

Patient Rights & Access

Narra supports the Covered Entity in meeting its obligations to individuals. Where a patient contacts Narra directly, Narra routes the request to the Covered Entity rather than answering it.

Right of access (45 CFR 164.524)
Narra makes PHI in a designated record set available to the Covered Entity, or at its direction to the individual, so that access can be granted within 30 days. Download in PDF, CSV, JSON, HL7, or FHIR.
Right to amendment (45 CFR 164.526)
Narra makes PHI available for amendment and incorporates any amendment the Covered Entity directs, maintaining version history. Corrections are applied within 24 hours of provider verification.
Accounting of disclosures (45 CFR 164.528)
Narra maintains, and makes available to the Covered Entity, the information required to give an individual an accounting of disclosures of their PHI, covering the six years before the request.
Right to erasure
Permanent deletion within 30 days of instruction; records required by law are retained for the required period.
Data Portability
PDF, CSV, JSON, HL7, FHIR
Right to Restrict
Limit uses, restrict sharing, pause analytics

Breach Notification & Management

Definition: unauthorized access, disclosure, modification, loss, or corruption of health data. Where HIPAA applies, "Breach" has the meaning given at 45 CFR 164.402, including the risk assessment in that definition. This wording is the same in the Terms of Service, Privacy Policy, and Data Processing Agreement.

Response timeline:

  • Detection, isolation, containment: without undue delay, and in any event within 1 hour of detection
  • Investigation (24 hours): scope, impact, root cause
  • Notification: as set out below

Notification parties and deadlines:

Covered Entity
Without unreasonable delay and in any event within 24 hours of discovery; within 1 hour where the breach is assessed as critical. This satisfies 45 CFR 164.410. The report identifies each individual whose PHI was or is reasonably believed to have been affected, and includes the information the Covered Entity needs to make its own notifications.
Individuals, where HIPAA applies
The Covered Entity notifies affected individuals without unreasonable delay and no later than 60 calendar days from discovery (45 CFR 164.404). Narra provides the content and support required.
US Department of Health and Human Services
The Covered Entity notifies the Secretary under 45 CFR 164.408. Where a breach affects 500 or more individuals, notice to the Secretary and to prominent media serving the state or jurisdiction is contemporaneous with individual notice (45 CFR 164.406). Smaller breaches are logged and reported annually.
Individuals and regulators under GDPR and India's DPDP Act
Within 72 hours, as set out in the Data Processing Agreement and the Privacy Policy.

Termination & Return or Destruction of PHI

Termination methods:

  • By the Covered Entity: convenience, material breach, or business decision, on 30 days notice
  • By Narra: material breach or non-payment, on 30 days notice
  • For cause: either party may terminate immediately if the other materially breaches this BAA and does not cure the breach within 30 days of written notice, as contemplated by 45 CFR 164.504(e)(2)(iii)

Return or destruction

On termination, Narra returns or destroys all PHI it received from, or created or received on behalf of, the Covered Entity, and retains no copies. This is the required outcome under 45 CFR 164.504(e)(2)(ii)(J), and it is not optional.

  1. Export window: the Covered Entity has 30 days to export all data in PDF, CSV, JSON, HL7, or FHIR.
  2. Return or destruction: at the end of that window Narra returns the data to the Covered Entity, or destroys it, at the Covered Entity's election. Destruction uses overwrite, crypto-erase, or physical destruction of decommissioned media. A certificate of destruction is provided at no charge.
  3. Where return or destruction is infeasible: Narra notifies the Covered Entity of the conditions that make it infeasible, extends the protections of this BAA to that PHI, and limits further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it retains the PHI. This is the only permitted alternative.

An optional read-only Archive service is available as a separate paid subscription, but only where the Covered Entity affirmatively elects it in writing. It is a form of continued processing under this BAA, not a substitute for return or destruction, and it is never applied by default.

How to Execute This Agreement

This page is the standard form of the agreement. It becomes binding when it is executed by both parties. It is not executed by browsing this page.

To execute

  1. Email legal@narrahealthcare.com with the subject "BAA execution request".
  2. We return a counterpart of this agreement with a schedule for the party details below.
  3. Both parties sign. The agreement may be executed in counterparts, and by electronic signature, each of which is an original and which together form one agreement.

Details completed on execution

  • Covered Entity legal name, registration or licence number, and registered address
  • Covered Entity authorised signatory: name, title, and privacy contact
  • Narra signatory: name and title
  • Effective date of this BAA between the parties, which may differ from the effective date shown at the top of this page
  • The Narra products and environments in scope
  • Any residency, retention, or liability terms agreed in the Order Form, which take precedence over this BAA

Until a counterpart is executed, this page is published for review only and creates no obligations on either party.

Liability & Contact

Liability

Narra's total aggregate liability under this BAA is subject to, and forms part of, the single liability cap stated in the Terms of Service. This BAA does not create a separate cap and does not raise the cap in the Terms. There is no minimum liability floor.

The cap is the lesser of the fees paid to Narra in the 12 months preceding the claim, or ₹100,000 or its equivalent in the Covered Entity's billing currency. A different cap applies only where expressly stated in an Order Form or signed master agreement, which takes precedence. The cap does not apply to gross negligence, wilful misconduct, fraud, death or personal injury caused by negligence, or any liability that cannot be limited by law.

Narra indemnifies the Covered Entity for: third-party claims arising from Narra's breach of this BAA, unauthorized disclosure by Narra, or Narra's negligence.

The Covered Entity indemnifies Narra for: lack of authorization, violation of healthcare laws by the Covered Entity, and malpractice claims.

Governing law and venue

The laws of India, and the exclusive jurisdiction of the courts in Hyderabad, Telangana, India. These are the same governing law and venue as the Terms of Service, which govern the whole relationship unless an Order Form states otherwise. Dispute resolution: negotiation (15 days), then management escalation (30 days), then mediation (30 days), then arbitration seated in Hyderabad, Telangana.

Entity
Narra Technologies Private Limited, Hyderabad, Telangana, India
BAA questions and execution
legal@narrahealthcare.com
Breach Reports
security@narrahealthcare.com
Data Subject Requests and the Data Protection Officer
dpo@narrahealthcare.com
Phone
+91 93999 12340