BUSINESS ASSOCIATE AGREEMENT

Pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA),
the Health Information Technology for Economic and Clinical Health Act (HITECH),
and 45 CFR Parts 160 and 164

Effective Date: _______________

This Business Associate Agreement ("Agreement") is entered into by and between:

Covered Entity: _______________________________________ ("Covered Entity")

Business Associate: Bonis Systems LLC, d/b/a HealthAgent ("Business Associate")

Address: San Antonio, Texas

UEI: R2BPJDC5CBA3

1. DEFINITIONS

All capitalized terms used but not otherwise defined herein shall have the meanings assigned to them in HIPAA, HITECH, and the HIPAA Privacy, Security, and Breach Notification Rules at 45 CFR Parts 160 and 164.

"Protected Health Information" (PHI) means individually identifiable health information transmitted or maintained in any form or medium, as defined in 45 CFR 160.103.

"Electronic Protected Health Information" (ePHI) means PHI that is transmitted or maintained in electronic media.

"Services" means the AI-powered healthcare navigation, caregiver management, portal synchronization, and related services provided by Business Associate through the HealthAgent platform (healthagentcare.com).

2. OBLIGATIONS OF BUSINESS ASSOCIATE

Business Associate agrees to:

(a) Not use or disclose PHI other than as permitted or required by this Agreement or as required by law.

(b) Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, including but not limited to:

— AES-256-GCM encryption of ePHI at rest

— TLS 1.3 encryption of ePHI in transit

— Multi-factor authentication (TOTP + SMS + backup codes)

— Knox Blockchain immutable audit trail (SHA-256 hash chain)

— PHI Scrubber removing all 18 HIPAA Safe Harbor identifiers at system boundaries

— Role-based access controls (patient, caregiver, administrator)

— Google Cloud Platform hosting with signed Google BAA

(c) Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including breaches of Unsecured PHI as required by 45 CFR 164.410.

(d) Report any Security Incident of which it becomes aware to Covered Entity within 24 hours of discovery.

(e) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions and conditions.

(f) Make available PHI in a Designated Record Set to Covered Entity or, as directed, to an Individual, as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524.

(g) Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance.

(h) Document and make available information required to provide an accounting of disclosures in accordance with 45 CFR 164.528. Business Associate maintains this accounting via the Knox Blockchain audit trail.

(i) To the extent Business Associate carries out any of Covered Entity's obligations under the HIPAA Privacy Rule, comply with the requirements that apply to Covered Entity.

3. PERMITTED USES AND DISCLOSURES

Business Associate may use or disclose PHI only for the following purposes:

(a) To perform the Services described in the underlying service agreement between the parties.

(b) For the proper management and administration of Business Associate, provided that disclosures are Required by Law or Business Associate obtains reasonable assurances from the recipient.

(c) To provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted by 45 CFR 164.504(e)(2)(i)(B).

(d) To de-identify PHI in accordance with 45 CFR 164.514(a)-(c). Business Associate employs the Safe Harbor Method (removal of 18 identifiers) via its automated PHI Scrubber.

4. OBLIGATIONS OF COVERED ENTITY

Covered Entity agrees to:

(a) Notify Business Associate of any limitations in its notice of privacy practices that may affect Business Associate's use or disclosure of PHI.

(b) Notify Business Associate of any changes in, or revocation of, an Individual's permission to use or disclose PHI.

(c) Notify Business Associate of any restrictions on the use or disclosure of PHI agreed to by Covered Entity pursuant to 45 CFR 164.522.

5. BREACH NOTIFICATION

Business Associate shall, following discovery of a Breach of Unsecured PHI, notify Covered Entity without unreasonable delay and no later than 30 calendar days after discovery. Notification shall include:

— Identification of each Individual whose PHI has been or is reasonably believed to have been accessed, acquired, used, or disclosed

— A description of the nature of the Breach

— Steps taken to investigate and mitigate the Breach

— Contact information for further inquiries

Business Associate maintains automated breach detection, 4-factor risk assessment, and state-specific breach notification law compliance for all 50 states via its breach notification engine.

6. TERM AND TERMINATION

(a) Term. This Agreement shall be effective as of the Effective Date and shall remain in effect for the duration of the underlying service agreement, unless earlier terminated as provided herein.

(b) Termination for Cause. Either party may terminate this Agreement if the other party materially breaches any provision and fails to cure within 30 days of written notice.

(c) Effect of Termination. Upon termination, Business Associate shall return or destroy all PHI received from or created on behalf of Covered Entity, if feasible. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible.

7. SECURITY STANDARDS

Business Associate represents and warrants that its HealthAgent platform implements the following security measures, verified by automated compliance assessment (Knox Blockchain Security):

— NIST SP 800-171 Rev 2 compliance (30+ requirements tracked)

— CMMC Level 2 readiness (14 domains, 110 practices)

— FedRAMP-aligned controls (Google Cloud Platform P-ATO High)

— Section 889 supply chain compliance (FAR 52.204-25)

— 42 CFR Part 2 substance abuse record protections

— Section 508 accessibility (WCAG 2.1 AA)

— Knox Blockchain immutable audit trail with tamper detection

— 259 automated tests passing continuously

8. MISCELLANEOUS

(a) Regulatory References. Any reference to a regulatory provision shall be deemed to be a reference to the provision as amended from time to time.

(b) Amendment. This Agreement may not be modified except by written agreement signed by both parties.

(c) Survival. The obligations of Business Associate under Sections 2, 5, and 6(c) shall survive termination of this Agreement.

(d) Governing Law. This Agreement shall be governed by federal law, including HIPAA, HITECH, and applicable regulations.

(e) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that complies with HIPAA and HITECH.

9. SIGNATURES

COVERED ENTITY:

Authorized Signature

Printed Name & Title

Date

BUSINESS ASSOCIATE:

Bonis Systems LLC

Jonis Fields, Founder & CEO

Date

UEI: R2BPJDC5CBA3
healthagentcare.com