Legal · HIPAA
Business Associate Agreement
Standard terms — last revised August 2026
1. Scope
This Business Associate Agreement supplements the Terms of Service where AMP Telecom ("Business Associate") creates, receives, maintains, or transmits Protected Health Information ("PHI") on behalf of a customer that is a Covered Entity or Business Associate under HIPAA. PHI on the platform typically includes call recordings, transcripts, voicemail, SMS content, and caller identifiers.
2. Permitted uses and disclosures
We use and disclose PHI only as necessary to provide the service, as permitted by this agreement, or as required by law. AI processing of PHI (transcription, agent responses, CallScrub scoring) occurs solely to deliver features you have enabled, within US data centers, and PHI is never used to train models made available to other customers.
3. Safeguards
We maintain administrative, physical, and technical safeguards that reasonably and appropriately protect PHI, consistent with the HIPAA Security Rule: AES-256 encryption at rest, TLS/SRTP in transit, role-based access with audit logging, workforce training, and an annually tested incident response program.
4. Breach notification
We will notify you without unreasonable delay, and no later than 10 business days after discovery, of any breach of unsecured PHI, including the identity of affected individuals where known and the information required for your obligations under 45 CFR §164.404.
5. Subcontractors
Subcontractors that create, receive, maintain, or transmit PHI on our behalf (carrier partners, cloud infrastructure) are bound by written agreements imposing restrictions at least as protective as this BAA. A current subprocessor list is available on request.
6. Term and termination
This BAA terminates with your service agreement. Upon termination, we return or destroy PHI where feasible; where retention is required by law (e.g., call detail records), the protections of this BAA continue to apply for as long as the PHI is retained.