Available lang sa Ingles ang dokumentong ito, at ang bersyong Ingles ang opisyal na teksto.

Business Associate Agreement

Effective date: [EFFECTIVE DATE, ON PUBLICATION]
Last updated: September 10, 2026
Version: baa-v2
Supersedes: baa-v1, which continues to govern a Firm that accepted it until that Firm accepts this version

NOT YET IN FORCE. This document is a draft. It must not be published, and must not be presented to any Firm for acceptance, until every bracketed PLACEHOLDER value in it is replaced and this notice is removed.

This Business Associate Agreement ("BAA") is entered into between Esqase, Inc. ("Esqase") and the law firm or organization that has accepted the Esqase Terms of Service and subscribes to the Professional plan ("Firm"). It forms part of the Terms of Service and governs Esqase's handling of Protected Health Information that the Firm stores in the Service.

The Firm is the Covered Entity or, where the Firm holds Protected Health Information as a business associate of one of its own clients, the Business Associate. Esqase is the Business Associate or, where the Firm is itself a business associate, the Subcontractor. Section 2 states how the roles are read.

Capitalized terms not defined in this BAA have the meanings given to them in the Terms of Service, including Account, Authorized User, Client Data, External User, Firm, Public-Facing Features, Service, Subscription, and User Content, or in 45 C.F.R. Parts 160 and 164.

1. Definitions

The following terms used in this BAA have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

In addition:

  • "Business Associate" has the meaning given to the term at 45 C.F.R. 160.103 and, in reference to a party to this BAA, means Esqase, except where Section 2.2 applies.
  • "Covered Entity" has the meaning given to the term at 45 C.F.R. 160.103 and, in reference to a party to this BAA, means the Firm, except where Section 2.2 applies.
  • "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act), and the regulations made under them.
  • "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164.
  • "PHI" means Protected Health Information that Esqase creates, receives, maintains, or transmits for or on behalf of the Firm through the Service. It is the subset of Client Data that is Protected Health Information, and it does not include information Esqase holds about the Firm and its Authorized Users as a controller of that information, which is governed by the Privacy Policy.
  • "Subprocessor" has the meaning given to it in the Data Processing Agreement and, where a Subprocessor creates, receives, maintains, or transmits PHI, it is also a Subcontractor for the purposes of the HIPAA Rules.

2. Application of This BAA

2.1 When It Applies

This BAA applies to PHI that the Firm submits to the Service while the Firm is on the Professional plan and has accepted this BAA in the Service. Until the Firm accepts this BAA, the Firm must not submit PHI to the Service. Esqase does not monitor Client Data for PHI, so the restriction in the preceding sentence is an obligation of the Firm rather than a control the Service enforces.

If the Firm moves from the Professional plan to the Standard plan, this BAA continues in force for PHI the Firm has already submitted, and Esqase continues to hold that PHI under this BAA until it is returned or destroyed under Section 6.3. The Firm keeps its personal injury records on the Standard plan and can export them at any time from its billing settings, but the module is hidden and the Firm must not submit further PHI to the Service until it accepts this BAA again on the Professional plan.

2.2 The Two Directions

A law firm may hold PHI in either of two capacities, and this BAA is written to work in both:

  • Where the Firm is a covered entity, or holds PHI as a hybrid entity or as part of an organized health care arrangement, the Firm is the Covered Entity and Esqase is its Business Associate.
  • Where the Firm holds PHI as a business associate of one of its own clients, the Firm is the Business Associate and Esqase is its Subcontractor. In that case, every reference in this BAA to "Covered Entity" is read as a reference to the Firm in its capacity as a business associate, and every obligation Esqase owes the Covered Entity is owed to the Firm, as 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2) require.

2.3 Where HIPAA Does Not Reach

A firm may hold health information that HIPAA does not cover, such as records obtained from a plaintiff client or produced in litigation. This BAA does not decide whether HIPAA applies to the Firm or to any record it holds; that determination is the Firm's. Where HIPAA does not apply, Esqase gives that information the same protections this BAA describes as a matter of contract, and the Data Processing Agreement continues to govern it.

2.4 No Determination of the Firm's Obligations

Esqase makes software for lawyers. Nothing in this BAA is legal advice, and nothing in it relieves the Firm of any obligation it owes under the HIPAA Rules, under its rules of professional conduct, or under an agreement with its own client.

3. Permitted Uses and Disclosures by Esqase

3.1 Permitted Purposes

Esqase may use and disclose PHI only:

  • as necessary to perform the services set out in the Terms of Service and as instructed by the Firm through its configuration of, and its Authorized Users' actions in, the Service;
  • as Required By Law; and
  • for the proper management and administration of Esqase, and to carry out Esqase's legal responsibilities, as described in Section 3.3.

3.2 Limits

Esqase will not use or disclose PHI other than as permitted or required by this BAA or as Required By Law, and will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Covered Entity, except for the uses and disclosures described in Section 3.3.

Esqase will not:

  • sell PHI, or use or disclose PHI for marketing or fundraising, within the meaning of 45 C.F.R. 164.501, 164.508(a)(3), and 164.514(f);
  • use or disclose PHI to train, fine-tune, or improve any artificial intelligence or machine learning model, its own or a third party's. Esqase's agreement with its artificial intelligence provider prohibits that provider from doing so, as Section 5.8 of the Terms of Service and Section 2.5 of the Data Processing Agreement also record. Section 3.6 describes that processing;
  • de-identify PHI, or create a limited data set from PHI, except on the Firm's written instruction and in accordance with 45 C.F.R. 164.514; or
  • provide Data Aggregation services relating to the health care operations of the Covered Entity.

Esqase may use PHI for its own proper management and administration and to carry out its legal responsibilities. Esqase may disclose PHI for those purposes only where the disclosure is Required By Law, or where Esqase obtains reasonable assurances in writing from the person to whom it discloses the PHI that the information will be held confidentially and used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and that the person will notify Esqase of any instance of which it becomes aware in which the confidentiality of the information has been breached.

3.4 Minimum Necessary

Esqase will limit its requests for, uses of, and disclosures of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. 164.502(b) and 164.514(d) and with the Firm's minimum necessary policies and procedures as the Firm makes them known to Esqase. Access to PHI within Esqase is restricted to personnel who need it to provide, support, or secure the Service.

3.5 Confidentiality and Privilege

PHI in the Service may also be privileged or otherwise protected from disclosure. Esqase treats Client Data as confidential, as Section 5.4 of the Terms of Service provides. Esqase's access to PHI as a service provider is not intended by either party to waive any attorney-client privilege, work product protection, or other protection, and Esqase will not assert or waive any such protection on the Firm's behalf.

3.6 Artificial Intelligence Processing

The Service can use Google's Vertex AI to make records findable. Two things happen, and they are not the same:

  • Document indexing. Where the Firm turns this on, the contents of documents the Firm uploads to or writes in the Service, which may include PHI, are sent to a Google Gemini model on Vertex AI, which returns a short description and keywords that Esqase stores with the document and uses for search. This is off by default for a Firm that accepts this BAA. Accepting this BAA switches it off for the whole Firm, and a Firm Owner must turn it back on deliberately in the Service's settings. A personal injury case carries a second switch of its own, which also starts off, so a document on a personal injury matter is sent only when both are on. Turning a switch off stops documents added or updated after that point from being sent; it does not delete output already stored.
  • Search embeddings. Text drawn from records, and the search terms an Authorized User types, are sent to a Google text embedding model on Vertex AI, which returns the numeric representations that make search work. This processing is required for search to function and is not covered by the switch described above. A Firm that does not want PHI processed this way should not put PHI in a searchable record.

Google is Esqase's Subcontractor for both, and Esqase holds this processing under the Google Cloud HIPAA Business Associate Agreement named in Section 4.4. Both models are called in a Google Cloud region chosen from the country recorded in the Firm's settings: Google's European region for a Firm in the European Economic Area or the United Kingdom, Google's Australian region for a Firm in Australia or New Zealand, and the United States for every other Firm, including a Firm in the United States. The Firm's records themselves are stored in the United States; for a Firm in one of the two other regions, the text sent to a model and the model's response are processed in that region. Neither model is used to train, fine-tune, or improve any model, as Section 3.2 provides, and no decision about any Individual is made by these models.

4. Obligations of Esqase

Esqase agrees to:

4.1 Safeguards

Use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to Electronic Protected Health Information, to prevent the use or disclosure of PHI other than as provided for by this BAA. The administrative, physical, and technical safeguards Esqase implements are described in Schedule 1 and in Section 5.1 of the Data Processing Agreement.

4.2 Reporting of Security Incidents and Breaches

Report to the Firm any use or disclosure of PHI not provided for by this BAA of which Esqase becomes aware, any Security Incident of which it becomes aware, and any Breach of Unsecured Protected Health Information as required by 45 C.F.R. 164.410.

Esqase will make that report without unreasonable delay and in no case later than five (5) business days after discovery. An event is discovered on the first day on which it is known to Esqase, or by exercising reasonable diligence would have been known to Esqase, as 45 C.F.R. 164.410(a)(2) provides. Esqase will not delay the initial report in order to complete its investigation, and will provide the remaining information as it becomes available.

The report will include, to the extent known at the time: the nature of the event; the date it occurred and the date it was discovered; the categories and approximate number of Individuals affected and the identification of each Individual whose Unsecured Protected Health Information has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; the categories and approximate volume of PHI involved; the likely consequences; and the steps Esqase has taken or proposes to take to investigate the event, to mitigate its harmful effects, and to protect against recurrence.

Unsuccessful attempts that do not compromise the security of PHI, such as pings and other broadcast attacks on a firewall, port scans, unsuccessful log-in attempts, and denial-of-service attacks that do not result in access to PHI, are not individually reportable. The parties agree that this paragraph is notice of those attempts, and Esqase will provide a summary of them on the Firm's reasonable written request.

A report under this Section is not an acknowledgement by Esqase of fault or liability. The Firm remains responsible for determining whether an event is a Breach requiring notification and for making any notification to Individuals, to the Secretary, or to the media. Esqase will not make a notification on the Firm's behalf unless the Firm instructs it to in writing.

4.3 Mitigation

Mitigate, to the extent practicable, any harmful effect known to Esqase of a use or disclosure of PHI by Esqase in violation of this BAA.

4.4 Subcontractors

In accordance with 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Esqase agrees in writing to the same restrictions, conditions, and requirements that apply to Esqase with respect to that PHI.

The only Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Esqase is Google LLC. From the Effective date stated above, Google provides the database (Cloud SQL for PostgreSQL), the file storage (Cloud Storage), the application runtime (Cloud Run), the background job runtime (Cloud Functions), the secret store (Secret Manager), the network perimeter every request passes through (Cloud Load Balancing, Cloud Armor, and Cloud CDN, which is configured to cache static assets only and never an authenticated response), the log store (Cloud Logging), the sign-in service (Identity Platform), and the artificial intelligence models described in Section 3.6 (Vertex AI). Esqase holds PHI on those services under the Google Cloud HIPAA Business Associate Agreement, which must be executed and in force before this BAA is offered to any Firm. Firebase Data Connect is not used at all. Firebase App Hosting serves only Esqase's public marketing and documentation website at esqase.com, which holds no Client Data and no PHI; no part of the Service that holds or transmits PHI runs on it.

Three further Google services are used in a way that keeps PHI out of them. Firestore carries the real-time signals that tell an open page that something it is showing has changed, which are identifiers and timestamps and no record content. Firebase Cloud Messaging delivers push notifications, which for a Firm that has accepted this BAA carry no record content, as Schedule 1 describes. Firebase App Check verifies that a request comes from a genuine Esqase application and receives no record content.

Esqase's other vendors do not receive PHI. Stripe receives Subscription billing data about the Firm itself and no Client Data. Resend delivers the Service's outbound email; for a Firm that has accepted this BAA, the push and notification email channels carry no record content, as Schedule 1 describes. PostHog receives product analytics that carry no record content and no session replay, as Schedule 1 describes. Esqase's current Subprocessors, with the purpose and location of each, are listed at esqase.com/subprocessors.

Esqase will give the Firm at least 14 days' prior written notice by email before engaging a new Subcontractor that will process PHI, on the terms set out in Section 6.3 of the Data Processing Agreement, which include the Firm's right to object and, where the objection cannot be resolved, to terminate. Esqase remains liable to the Firm for the performance of each Subcontractor's obligations under this Section, subject to Section 7.6.

4.5 Access

Make PHI in a Designated Record Set available to the Firm as necessary to satisfy the Firm's obligations under 45 C.F.R. 164.524. Authorized Users can read and retrieve the Firm's records directly in the Service at any time, and can download documents and other files individually. The Firm Owner can additionally export the Firm's records as a machine-readable file from the billing settings; Section 18.5 of the Terms of Service states what that export covers and the limits on it. Where a request cannot be satisfied that way, Esqase will provide the PHI to the Firm within 10 business days of the Firm's written request, in a structured, commonly used, and machine-readable format. If Esqase receives a request for access directly from an Individual, it will forward the request to the Firm and will not respond to it, unless the Firm instructs it to in writing.

4.6 Amendment

Make any amendment to PHI in a Designated Record Set as directed by, or agreed to by, the Firm pursuant to 45 C.F.R. 164.526, or take other measures as necessary to satisfy the Firm's obligations under that section. Authorized Users can amend the Firm's records directly in the Service. Where an amendment cannot be made that way, Esqase will act on the Firm's written direction within 10 business days. If Esqase receives a request for amendment directly from an Individual, it will forward the request to the Firm and will not act on it, unless the Firm instructs it to in writing.

4.7 Accounting of Disclosures

Maintain and make available to the Firm the information required to provide an accounting of disclosures as necessary to satisfy the Firm's obligations under 45 C.F.R. 164.528. Esqase keeps an audit log of access to and modification of records in the Service, recording the identity of the actor, the action, and the time. Esqase will provide the information within 10 business days of the Firm's written request. If Esqase receives a request for an accounting directly from an Individual, it will forward the request to the Firm and will not respond to it, unless the Firm instructs it to in writing.

4.8 The Firm's Obligations Carried Out by Esqase

To the extent Esqase is to carry out one or more of the Firm's obligations under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to the Covered Entity in the performance of those obligations.

4.9 Availability of Books and Records to the Secretary

Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining the Firm's compliance with the HIPAA Rules. Esqase will notify the Firm of a request under this Section before responding to it, unless notice is prohibited by law. Disclosure to the Secretary under this Section is not a breach of Esqase's confidentiality obligations.

4.10 Government and Law Enforcement Demands

Handle a subpoena, court order, warrant, or other legally binding demand for PHI as Section 18 of the Data Processing Agreement provides, including notifying the Firm before disclosing anything unless notice is prohibited by law, challenging the demand where there is a reasonable basis to consider it unlawful, disclosing only the minimum it is legally compelled to disclose, and referring the requesting authority to the Firm where it is able to do so.

5. Obligations of the Firm

5.1 Notices, Permissions, and Restrictions

The Firm will notify Esqase of any limitation in its notice of privacy practices under 45 C.F.R. 164.520, of any change in or revocation of an Individual's permission to use or disclose that Individual's PHI, and of any restriction on the use or disclosure of PHI that the Firm has agreed to or is required to abide by under 45 C.F.R. 164.522, in each case to the extent the limitation, change, revocation, or restriction may affect Esqase's use or disclosure of PHI. Esqase gives effect to a restriction of that kind only from the date the Firm notifies it in writing at legal@esqase.com, and only to the extent the Service can give effect to it.

5.2 Permissible Requests

The Firm will not request Esqase to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by the Covered Entity, except where Section 3.3 permits the use or disclosure.

5.3 Configuration and Use of the Service

The Firm decides which Authorized Users and External Users may access which records, including through document sharing, eSignature requests, booking pages, intake forms, and payment pages. Esqase acts on those configuration choices as instructions from the Firm. The Firm is responsible for the accuracy, quality, and legality of the PHI it submits, for having authority to submit it, and for configuring the Service so that PHI is disclosed only to the people the Firm intends. Section 17 of the Data Processing Agreement states the same responsibility for personal data generally.

The Firm is responsible for the security of its own accounts. Esqase requires two-factor authentication for every member of a Firm that has accepted this BAA, as Schedule 1 describes.

6. Term and Termination

6.1 Term

This BAA takes effect on the date the Firm accepts it in the Service and remains in effect until all PHI is returned or destroyed in accordance with Section 6.3, or until it terminates under Section 6.2.

6.2 Termination for Cause

The Firm may terminate this BAA and the Subscription if it determines that Esqase has violated a material term of this BAA and Esqase has not cured the violation within 30 days of written notice at legal@esqase.com. If cure is not possible, the Firm may terminate immediately. Termination of the Subscription terminates this BAA, subject to Section 6.3 and Section 6.4.

Esqase may terminate this BAA on 30 days' written notice if the Firm violates a material term of it and does not cure the violation within that period, or immediately where required to prevent a violation of the HIPAA Rules.

6.3 Return or Destruction of PHI on Termination

On termination of this BAA for any reason, Esqase will return to the Firm, or at the Firm's election destroy, all PHI that Esqase or its Subcontractors still maintain in any form, except as this Section provides. This is what happens, and when.

  • On termination, records are marked deleted rather than erased. Deleting a Firm ends its Subscription and marks the Firm and its records deleted. They are not visible in the Service and are not processed for any purpose other than restoring them.
  • A 30-day recovery window. PHI is retained for 30 days after the Account is terminated so that the Firm can recover it, as Section 12.2 of the Data Processing Agreement provides. Before termination, and during that window, the Firm may export its records as Section 4.5 describes.
  • Then the primary stores are purged. At the end of that window Esqase deletes or anonymizes PHI in the database and the file storage. On the Firm's written request Esqase will act sooner, and will confirm in writing when it has done so.
  • Backups expire on the platform's own schedule. Backup copies of the database and the file storage are made and expired by the underlying Google Cloud services. They cannot be edited or selectively purged, and PHI in them is deleted when the backup that holds it expires. Section 12.2 of the Data Processing Agreement states the outer bound of 90 days.
  • The audit trail is kept. The audit log described in Schedule 1 is append-only: a database trigger refuses any deletion, and it is retained for at least six years as 45 C.F.R. 164.316(b)(2)(i) requires. It records who did what, when, and to which record, and an entry may include an identifier or a name. It is not returned or destroyed on termination, and the paragraph below governs it.

Where return or destruction is infeasible. Where Esqase determines that returning or destroying PHI is infeasible, Esqase will notify the Firm in writing of the conditions that make it infeasible. Those conditions include the append-only audit trail described above, PHI held in backup media that cannot be selectively purged before the backup expires, PHI Esqase is required to retain by applicable law, and PHI subject to a legal hold. For as long as Esqase retains that PHI, Esqase will:

  • extend the protections of this BAA to it;
  • limit further uses and disclosures of it to those purposes that make its return or destruction infeasible;
  • continue to apply the safeguards in Section 4.1 and Subpart C of 45 C.F.R. Part 164 to it;
  • keep it isolated from further processing; and
  • return or destroy it as soon as the conditions that made return or destruction infeasible no longer apply.

6.4 Survival

Esqase's obligations under Section 6.3, and the parties' obligations under Sections 3.2, 3.5, 4.1, 4.2, 4.9, and 7, survive the termination of this BAA for as long as Esqase retains PHI and for as long thereafter as is necessary to give them effect.

7. Miscellaneous

7.1 Regulatory References

A reference in this BAA to a section of the HIPAA Rules means the section as in effect or as amended, and a reference to a statute or regulation includes any successor provision.

7.2 Amendment

The parties will take such action as is necessary to amend this BAA from time to time as is necessary for compliance with the requirements of the HIPAA Rules and any other applicable law. Esqase may otherwise update this BAA where the change is required by law, reflects a change to the Service, or updates the Subprocessor list referred to in Section 4.4. Esqase will post the updated BAA at esqase.com/business-associate-agreement, revise the version identifier and the Last updated date, and, where a change materially reduces the protections in this BAA, notify the Firm by email at least 14 days before it takes effect. A Firm that does not accept a material change may terminate under Section 6.2. No change to this BAA reduces a protection the HIPAA Rules require.

7.3 Interpretation

Any ambiguity in this BAA is resolved to permit compliance with the HIPAA Rules. Section headings are for convenience and do not affect interpretation.

7.4 No Third-Party Beneficiaries

Nothing in this BAA is intended to confer, and nothing in it confers, any right, remedy, obligation, or liability on any person other than the Firm and Esqase and their respective successors and permitted assigns. This BAA does not create any right in an Individual, and it does not create a private right of action under the HIPAA Rules.

7.5 Precedence

Where this BAA conflicts with the Terms of Service or the Data Processing Agreement with respect to PHI, this BAA prevails. In all other respects those agreements govern, and this BAA is read together with them. This BAA does not vary the Data Processing Agreement with respect to personal data that is not PHI.

Esqase offers one country-specific agreement to a Firm: this BAA, or the data processing agreement we publish for a Firm's country, available from esqase.com/legal, according to the country recorded in the Firm's settings. If a Firm has accepted both, the one that matches the Firm's currently registered country governs, and the other has no effect for as long as that remains the registered country.

7.6 Limitation of Liability

Each party's liability under this BAA is subject to the limitations set out in Section 16 of the Terms of Service, except to the extent applicable law does not permit those limitations to apply.

7.7 Governing Law

This BAA is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles, and disputes arising out of or relating to it are resolved as provided in Section 19 of the Terms of Service. Nothing in this Section limits the authority of the Secretary under the HIPAA Rules.

7.8 Acceptance

This BAA is entered into when a person authorized to bind the Firm accepts it in the Service. Esqase records the acceptance, the version accepted, the name and title of the person who accepted it, and the date and time. A Firm that requires a countersigned copy may request one at legal@esqase.com; a countersigned copy records the same terms and does not vary them.

8. Contact

For questions about this BAA, to give a notice under it, or to request a countersigned copy, contact:

Esqase, Inc.
Attention: Privacy and Security
2810 N Church St STE 89268
Wilmington, DE 19802, United States
legal@esqase.com

Esqase's designated privacy contact is Kristoffer Bello, its Security Officer, reachable at the address above. Esqase acknowledges a notice under this BAA within five business days.

Schedule 1. Safeguards Esqase Implements

These are the safeguards Esqase maintains under Section 4.1, stated against the standards of Subpart C of 45 C.F.R. Part 164. Each one is in force in the Service on the Effective date stated above, and this Schedule describes the platform as it operates from that date. Esqase may update them from time to time, provided that an update does not materially reduce the overall level of protection.

Access management. Access is role based. Every record carries the identity of the Firm that owns it. Row level security is enabled and forced on every table in the database, and the application connects as a role that cannot bypass it, so a read or a write outside the Firms the acting user belongs to fails at the data layer rather than in the interface. A write is checked in the database itself, on every statement, against the acting user's membership of that Firm and the permissions of that user's role, so a write the role does not allow fails the same way. Access to PHI within Esqase is restricted as Section 3.4 describes.

Database least privilege. Each application service connects to the database as its own identity, authenticated by the cloud platform rather than by a password; no database password exists in Esqase's systems. Those identities are members of one of four database roles: one that owns the schema and is used only to apply changes to it, one for the web applications, one for background jobs, and one that can only read. None of the four can bypass row level security or act as a database superuser, and the application refuses to open a connection whose role could. Every connection carries a statement timeout, an idle-transaction timeout, and a lock timeout, so no query can hold a connection or a lock open indefinitely.

Authentication. Sign-in is by email and password with email verification, and by two-factor authentication using an authenticator app or an emailed one-time code, with single-use recovery codes. Two-factor authentication is required for every member of a Firm that has accepted this BAA: a member who has not enrolled is sent to enrolment and cannot use the application until enrolment is complete. A Firm Owner cannot switch the requirement off while this BAA is in force.

Session limits. Sessions are verified on the server on every request and last at most 12 hours. A session on the firm dashboard or the client portal ends after 1 hour without activity, and a session on Esqase's internal staff console ends after 30 minutes.

Transmission security. All traffic between clients and servers uses TLS, and every Esqase application sends HTTP Strict Transport Security, so a browser will not fall back to an unencrypted connection. Requests to the Esqase applications reach them only through Google Cloud's global load balancer, which terminates TLS and applies Google Cloud Armor's protections against attack and automated abuse; the application services accept no connection from the public internet. A small number of background endpoints sit outside the load balancer. One of them, the billing provider's webhook, is reachable from the public internet, carries no PHI, and verifies the provider's cryptographic signature on every request before it is processed.

Encryption at rest. The database and the file storage are encrypted at rest with keys managed by the underlying cloud platform. Two-factor authentication seeds and document share tokens are additionally encrypted by Esqase at the application layer, with AES-256-GCM, before they are stored.

Key management. Esqase's platform secrets and signing keys are held in Google Secret Manager, separately from the data they protect.

Audit controls. Every create, update, delete, and restore of a record is written to a single append-only audit log in the same database transaction as the change, with the identity of the actor, the time, the action, and the record. Opening and downloading a record are recorded the same way. A database trigger refuses every attempt to delete an audit row and every attempt to change one, except for five columns that record which identity and which matter an existing row belongs to and that cannot change what the row says happened. Audit records are retained for at least six years, as 45 C.F.R. 164.316(b)(2)(i) requires. Changes to the database schema and to database roles are recorded by the database engine itself, and those records, together with the platform's own data-access logs, are written to a separate log store retained for seven years.

Vulnerability management. Esqase's software dependencies are scanned weekly for updates, and updates are applied through the ordinary change process.

Analytics. Session replay is not enabled in any Esqase application. PostHog is the only analytics processor, and no Esqase application loads Google Analytics. Esqase's product analytics carry record identifiers and never record content: no client name, no matter title, no document name or contents, no note or message text, no search term, and no amount.

Notification content. For a Firm that has accepted this BAA, outbound push notifications and notification emails carry no record content: no client, matter, document, or provider names. That control covers those two channels. Email the Firm itself sends to its own client through the Service, such as a shared document invitation or an invoice reminder, carries the content the Firm puts in it.

Physical safeguards. Production infrastructure runs in Google Cloud data centers, which operate their own physical and environmental controls.

Isang plataporma para sa buong praktis ninyo