Business Associate Agreement

v1.0First published: 15 October 2025Last updated: 14 January 2026Effective: 1 February 2026

This Business Associate Agreement (BAA) establishes the legal and operational framework under which NarraHealth Technologies Pvt. Ltd. processes Protected Health Information (PHI) on behalf of healthcare providers, hospitals, and covered entities.

Parties to This Agreement

Covered Entity (Provider)

A licensed healthcare provider (doctors, clinics, hospitals, labs, telemedicine platforms) that creates, receives, or transmits PHI.

Business Associate (Narra Healthcare)

NarraHealth Technologies Pvt. Ltd.: technology platform processing health data on behalf of Covered Entities.

What Narra Healthcare IS

  • A data processor/custodian
  • A technology platform
  • Responsible for security

What Narra Healthcare IS NOT

  • A healthcare provider
  • Responsible for clinical decisions
  • A medical device

Permitted Uses & Disclosures

Healthcare Coordination

Store and manage health records to enable patient access, provider access with consent, referrals, test result delivery, and clinical documentation.

ABDM/ABHA Integration

Link accounts to ABHA for nationwide health data exchange.

Patient controls:

  • Integration is optional
  • Patient can revoke access
  • Patient controls what data is shared

Business Operations

Permitted uses: system administration, security and fraud prevention, de-identified analytics, compliance and audit.

Restrictions: no identifying information in analytics; no marketing use; no sale of data.

Legal Compliance

Disclose only when legally required (court orders, regulatory requests, public health authorities). Narra Healthcare will notify Covered Entity of legal requests except where prohibited.

Prohibited Uses

Narra Healthcare WILL NOT:

  • Sell health data to third parties
  • Use health data for marketing or advertising
  • Share with insurance companies without consent
  • Share with employers
  • Share with pharmaceutical companies
  • Use for AI training without explicit consent
  • Share with data brokers
  • Use health data for discrimination
  • Rent or lease health data

Obligations of Narra Healthcare

  • Confidentiality: Treat all health data as confidential, limit disclosure, employees sign NDA
  • Data Security: AES-256 encryption, TLS 1.3, Google Cloud KMS, MFA, RBAC, background checks
  • Access Controls: MFA, granular permissions, 24/7 monitoring
  • Audit Logging: Complete trail retained 5+ years, available to Covered Entity
  • Data Integrity: Checksums, version control
  • Availability: 99.5% uptime, RTO < 4 hours
  • Breach Notification: Notify Covered Entity within 1 hour of critical breach; patients within 72 hours (DPDP Act)

Obligations of Providers

  • Have legal authority as a licensed healthcare provider
  • Obtain patient consent for processing
  • Comply with NABL/NABH/Medical Council standards
  • Inform patients that Narra Healthcare is used
  • Report suspected breaches to Narra Healthcare immediately
  • Cooperate with breach investigation

Security Safeguards

Technical

Encryption
AES-256 at rest, TLS 1.3 in transit, keys in AWS KMS and Google Cloud KMS
Access
MFA, RBAC, Least Privilege
Monitoring
IDS, Behavioral Analytics

Physical

Data centres
Delhi and Mumbai (AWS and GCP), 24/7 security, biometrics
Disaster recovery
Dedicated disaster recovery site

Administrative

Personnel
Background checks
Training
Annual security training
Incident response
Incident Response Plan
Risk management
Annual Risk Assessment

Sub-processors & Approved Vendors

Requirements for all sub-processors:

  • Must sign Data Processing Agreement
  • Maintain ISO 27001/SOC 2
  • Report breaches < 24 hours
  • Data residency in India for PHI

Approved sub-processors:

Vendor Purpose Location
Google Cloud Platform Cloud infrastructure Delhi & Mumbai
AWS Cloud redundancy Mumbai
Razorpay Payment processing India
Stripe Payments alternative US, data in India

Adding new sub-processors: 30-day notice to Covered Entity. Covered Entity may object or terminate.

Patient Rights & Access

Right to Access
Download full health history in PDF, CSV, JSON, HL7, FHIR within 30 days
Right to Correction
Inaccurate data corrected within 24 hours of provider verification
Right to Erasure
Permanent deletion within 30 days; legal records retained per law
Data Portability
PDF, CSV, JSON, HL7, FHIR
Right to Restrict
Limit uses, restrict sharing, pause analytics

Breach Notification & Management

Definition: Unauthorized access, disclosure, modification, loss, or corruption of health data.

Response timeline:

  • Immediate (< 1 hour): Detection, isolation, containment
  • Investigation (24 hours): Scope, impact, root cause
  • Notification (< 72 hours): Patients notified (DPDP Act requirement)

Notification parties:

  • Covered Entity within 1 hour (critical)
  • Patients within 72 hours
  • Regulators as required by law

Termination & Data Return

Termination methods:

  • By Covered Entity: Convenience, material breach, business decision (30 days notice)
  • By Narra Healthcare: Material breach, non-payment (30 days notice)

Data return options:

  • Download: Export all data (30-day window)
  • Deletion: Permanent deletion with certificate
  • Archive: Read-only retention (fee applies)

Liability & Contact

Liability: Limited to fees paid in prior 12 months. Minimum ₹1,00,000. Maximum ₹1,00,00,000.

Narra Healthcare indemnifies Covered Entity for: third-party claims of BAA breach, unauthorized disclosure, or negligence.

Covered Entity indemnifies Narra Healthcare for: lack of authorization, violation of healthcare laws, malpractice claims.

Governing law: Indian Law, Hyderabad courts. Dispute resolution: negotiation (15 days) → management escalation (30 days) → mediation (30 days) → arbitration.

BAA Questions
legal@narra.health
Breach Reports
security@narra.health
Data Subject Requests
dpo@narra.health