Healthcare data agreement

Health and patient data: our agreement for UK and US clients.

Version 2.0 · Last updated 23 September 2026

In short: most of our audits never need patient data, and we ask you not to send it. If an engagement does involve health data, we sign an agreement before we receive any. UK health and care organisations are covered by our data processing addendum with the extra terms in Part A. US covered entities under HIPAA sign the business associate agreement summarised in Part B.

Part A

UK health and care organisations

This part applies to dental practices, care providers, clinics and other UK organisations that handle health or care records.

What applies

Where we process personal data on your behalf, we act as your processor under Article 28 of the UK GDPR, on the terms of our data processing addendum. Health data is special category data under Article 9 of the UK GDPR, so we add the commitments below to any engagement that could involve it.

Keeping patient data out of scope

Our audits look at your systems, settings, policies and evidence, not at patient records. Please redact or leave out patient-identifiable information from anything you send us. If any reaches us by mistake, we will tell you, and we will delete or return it, as you choose.

If health data has to be shared

If something goes wrong

We will tell you without undue delay, and within 48 hours of becoming aware of a personal data breach affecting your data. That gives you time to meet the 72-hour deadline for reporting to the ICO and, where it applies to you, to report through the Data Security and Protection Toolkit.

At the end of the engagement

Within 30 days, and at your choice, we return the personal data we hold for you in a common format or delete it securely and confirm that in writing.

Part B

US covered entities: business associate agreement

Under HIPAA (45 CFR 164.502(e) and 164.504(e)), a covered entity that shares protected health information (PHI) with a business associate must have a written business associate agreement (BAA) in place first. This is a summary of the operative terms of our standard BAA. The signed BAA is a separate document executed alongside your engagement letter.

1. Parties

Covered Entity ("CE"): you, the US healthcare provider engaging Unavoidably Secure.

Business Associate ("BA"): Unavoidable Studio Ltd, a company registered in England and Wales (company number 17367981), trading as Unavoidably Secure, with its registered office in Leeds, United Kingdom.

2. Definitions

Terms in this BAA have the meanings given in the HIPAA Rules (45 CFR Parts 160 and 164) and the HITECH Act. In particular, "Breach", "Designated Record Set", "Individual", "Protected Health Information", "Required by Law", "Secretary", "Security Incident", "Unsecured Protected Health Information" and "Use" have the meanings given in 45 CFR 160.103 and 164.402.

3. Permitted uses and disclosures

BA may use or disclose PHI only:

4. Prohibited uses and disclosures

5. Safeguards

BA will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 CFR Part 164 for electronic PHI, to prevent use or disclosure of PHI other than as this BAA provides. These include:

6. Reporting

BA will report to CE without unreasonable delay, and in any event within 48 hours of discovery:

Routine unsuccessful attempts, such as port scans, pings and failed log-ins against accounts that do not exist, are not reported individually. BA will provide a summary of these on request.

7. Subcontractors and email

BA will ensure that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions and conditions that apply to BA (45 CFR 164.502(e)(1)(ii) and 164.308(b)(2)). Before any PHI is shared, BA will confirm in writing where it will be stored and which subcontractors, if any, will handle it.

BA does not send PHI by email. Our transactional email provider, Postmark, does not sign business associate agreements, so it is used only for notifications that contain no PHI, such as a message that a report is ready to collect.

8. Access, amendment and accounting

9. Access by the Secretary

BA will make its internal practices, books and records relating to PHI available to the Secretary of the US Department of Health and Human Services for the purpose of determining compliance with HIPAA.

10. Return or destruction of PHI

When the engagement ends, and at CE's choice, BA will either return all PHI in a common machine-readable format within 30 days, or destroy it and certify the destruction in writing. If return or destruction is not feasible, BA will extend the protections of this BAA to that PHI for as long as it holds it, and limit further use to the purposes that make return or destruction infeasible.

11. Term and termination

This BAA runs for the term of the engagement letter. Either party may end it on written notice for a material breach that is not put right within 30 days. On termination, section 10 applies.

12. State law

Where a US state law gives Individuals greater protection than HIPAA, for example on breach notification timelines or notice to a state Attorney General, BA will comply with that law for PHI about residents of that state.

13. Changes in the law

If HIPAA changes in a way that materially affects this BAA, the parties will negotiate in good faith to amend it. If they cannot agree within 60 days, either party may end it on written notice.

14. General

Signing

The signed agreement is a separate document. We send it with your details completed and signed by us, and it takes effect when you countersign. If you would like it in place before your first engagement, mention it when you request your audit and we will send it for signature within one business day.

Questions about this agreement: support@unavoidablysecure.com or 07749 941111 (+44 7749 941111 from the US).