United States users · Legal notice · effective September 25, 2026

US HIPAA Addendum

Health Insurance Portability and Accountability Act safeguards covering Protected Health Information and Business Associate commitments.

This HIPAA Addendum (this “BAA”) applies to United States users of Invozaa and governs the processing of Protected Health Information (“PHI”) as defined in the US Health Insurance Portability and Accountability Act of 1996, Public Law 104–191 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”), and all implementing regulations at 45 CFR Parts 160 and 164, as amended (collectively the “HIPAA Rules”).


For the purposes of the HIPAA Rules, if you are a Covered Entity (health plan, health care clearinghouse, or health care provider who transmits health information in electronic form in connection with a transaction for which the Secretary of HHS has adopted a standard) or a Business Associate of a Covered Entity, this Addendum documents Invozaa’s obligations as a Business Associate when your account is flagged for HIPAA processing on written request. Unmarked consumer accounts that do not submit PHI are outside the scope of this BAA.


1. Permitted uses and disclosures of PHI by Business Associate (164.502 / 164.504)
Invozaa (the “Business Associate”) may use or disclose PHI only as permitted or required by this Addendum, by the underlying Business Associate Agreement with the Covered Entity, or as Required By Law. Specifically, the Business Associate may:
(a) Use or disclose PHI for the proper management and administration of the Business Associate (§164.502(e)(1)), provided that the Business Associate obtains assurances of confidentiality from any third-party agent to whom PHI is disclosed;
(b) Use or disclose PHI for the data aggregation services and to perform analytics on de-identified PHI consistent with §164.502(d);
(c) Use or disclose PHI as Required By Law, including valid court orders, subpoenas, and compelled civil investigative demands.


2. Minimum necessary standard (164.502(b))
Invozaa applies the HIPAA minimum necessary principle across all PHI processing: only PHI necessary to generate, store, and deliver the requested invoice/receipt artefacts is ever ingested into our system; employees access PHI only on a strict need-to-know basis; PHI redaction APIs automatically remove patient identifiers from customer support tooling unless an explicit exception is approved by the Privacy Officer.


3. De-identification standard
PHI that has been de-identified in accordance with §164.514(b) (Expert Determination / Safe Harbor removal of all 18 specified identifiers) is no longer considered PHI under the HIPAA Rules, and Invozaa may use and disclose such de-identified information without restriction for product-improvement analytics, with the caveat that we do not attempt to re-identify any such dataset.


4. Individual rights (164.524, 164.526, 164.528, 164.522)
Upon written request from the Covered Entity, Invozaa will provide or assist in providing:
- Right of access (§164.524): make PHI held in a Designated Record Set available for inspection and obtain a copy within 30 calendar days;
- Right to amendment (§164.526): accept or deny an amendment request in writing within 60 days, append any accepted amendment to the affected Designated Record Set;
- Right to an accounting of disclosures (§164.528): account for disclosures of PHI made by Business Associate in the 6 years prior to the request, consistent with §164.528 exceptions;
- Right to request restrictions (§164.522): honour any agreed restrictions to uses and disclosures of PHI.


5. Breach notification rule (164 Subpart D)
Invozaa will, without unreasonable delay and in no case later than 60 calendar days from the date of discovery of a Breach of Unsecured PHI as defined at §164.402, notify the Covered Entity in writing of the date of discovery, a brief description of the PHI involved, the number of affected individuals (or a reasonable estimate), any known risk of harm, any steps taken to mitigate, and the identity and contact information of the individual(s) at Business Associate to contact for follow-up.


Invozaa will cooperate fully with the Covered Entity in the Covered Entity’s own notifications to HHS OCR and to affected individuals, media, and substitute decision-makers, consistent with §164.404–§164.408.


6. BAAs with subcontractors and Omnibus Rule
Invozaa obtains and maintains compliant written Business Associate Agreements with every subcontractor or downstream sub-processor that has, or may have, access to PHI. All agreements satisfy the Omnibus Rule (78 FR 5565, Jan 25, 2013) requirements including downstream flow-down of all Security Rule and Breach Notification obligations, joint and several liability for breaches caused by subcontractors, and termination-for-cause provisions.


7. Security rule — administrative, physical, technical safeguards
Administrative: designated Privacy Officer + Security Officer roles; annual documented risk analysis; Sanction Policy for workforce members who fail to comply; formal information access management with role-based permissions; periodic security-aware workforce training (documented with attendance & attestations); Incident Response and Data Breach Response runbooks reviewed quarterly.
Physical: data centres with SSAE 18 SOC 2 Type II audits, 24/7 on-site security, biometric access, CCTV, cage-based cabinet locks, documented media disposal (disk degauss or cryptographic-shred workflow), and visitor access logs.
Technical: access control with unique user IDs + role-based authorisation + automatic logoff; audit controls with 12-month tamper-evident access logs, including all read/write/delete actions on PHI; integrity controls with cryptographic hashes of PHI payloads to detect unauthorised modification; transmission security with TLS 1.2+ for all in-transit PHI + AES-256-GCM encryption of PHI at rest with separate keys rotated on a 90-day schedule; vulnerability-scan cadence of weekly plus continuous SAST/DAST; two-factor authentication required for every PHI-accessible employee workstation and administrator account.


8. Business Associate contact for privacy
Send any BAA requests, PHI access requests, Breach notifications, DPIA requests, or Privacy Officer correspondence to:
support@invozaa.com (marked for the attention of the HIPAA Privacy Officer / HIPAA Security Officer).