תנאי עיבוד מידע
תנאים אלה חלים בין המטפל/ת המאשר/ת אותם ביישומון MindStack ("המטפל") לבין MindStack ("מיינדסטאק"), ונכנסים לתוקף ברגע האישור.
1. רקע והגדרות
(א) המטפל מנהל מאגר מידע על מטופליו, והוא בעל השליטה במאגר כמשמעותו בחוק הגנת הפרטיות, התשמ"א-1981, כפי שתוקן ("החוק").
(ב) מיינדסטאק מעבדת את המידע עבור המטפל ומטעמו בלבד, והיא "מחזיק" כמשמעותו בחוק. תקנות הגנת הפרטיות (אבטחת מידע), התשע"ז-2017 ("תקנות אבטחת מידע") חלות על מיינדסטאק במישרין.
(ג) "המידע" הוא כל מידע על מטופלי המטפל המעובד בשירות: הקלטות פגישות, תמלילים, סיכומים שנוצרו בידי בינה מלאכותית, פרטי מטופלים (שם, תאריך לידה, פרטי קשר), אבחנה, רמת סיכון, הערות המטפל, ונתוני פגישות וחיובים.
2. מטרת העיבוד והיקפו
(א) מיינדסטאק תעבד את המידע אך ורק לשם אספקת השירות למטפל: הקלטה, תמלול, סיכום, ניהול מטופלים ופגישות, הפקת חשבוניות וצ'אט מקצועי על מטופלי המטפל.
(ב) מיינדסטאק לא תשתמש במידע לכל מטרה אחרת: לא תמכור אותו, לא תשתמש בו לפרסום, ולא תאמן עליו מודלים של בינה מלאכותית.
(ג) העיבוד נמשך כל עוד חשבון המטפל פעיל, בכפוף למחיקות שהמטפל מבצע בשירות.
3. אבטחת מידע
(א) מאגר המידע מסווג ברמת האבטחה הבינונית לפי תקנות אבטחת מידע, ומיינדסטאק מקיימת את חובות רמה זו, ובכלל זה: נוהל אבטחה כתוב ומחייב, מסמך הגדרות מאגר, הצפנת המידע בתעבורה ובאחסון, הרשאות גישה מצומצמות ואישיות, תיעוד אוטומטי של גישה למערכות ושמירתו, וסקירה שוטפת של התיעוד.
(ב) הגישה למידע ניתנת רק למי שחתום על נוהל האבטחה וחב בחובת סודיות, ובהיקף הנדרש לתפקידו בלבד.
4. מעבדי משנה והעברת מידע אל מחוץ לישראל
(א) מיינדסטאק נעזרת בספקי משנה לאחסון, לתמלול ולסיכום. כל ספק משנה שמעבד את המידע קשור בהתחייבויות כתובות שאינן מקלות מאלה שבתנאים אלה.
(ב) העיבוד מתבצע בשרתים באיחוד האירופי, והעברת המידע נעשית בהתאם לתקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001.
(ג) מיינדסטאק לא תעביר את המידע לגורם נוסף אלא לפי תנאים אלה או בהסכמת המטפל בכתב.
5. אירועי אבטחה
(א) מיינדסטאק תודיע למטפל ללא דיחוי על אירוע אבטחה חמור הנוגע למידע מטופליו (שימוש במידע בלא הרשאה או פגיעה בשלמותו), ותמסור לו את הפרטים הדרושים למילוי חובותיו.
(ב) מיינדסטאק תדווח לרשות להגנת הפרטיות על אירועים כנדרש בתקנה 11 לתקנות אבטחת מידע, ותתעד כל אירוע אבטחה.
6. פיקוח ושקיפות
לפי בקשת המטפל, ולא יותר מאחת לשנה, תמסור מיינדסטאק דין וחשבון על אופן קיום חובותיה לפי תנאים אלה ולפי תקנות אבטחת מידע.
7. זכויות מטופלים
חובות היידוע, ההסכמה, העיון והתיקון כלפי המטופלים חלות על המטפל כבעל השליטה במאגר. מיינדסטאק מעמידה לרשות המטפל את הכלים למילוין: עיון במידע, תיקונו ומחיקתו בתוך היישומון.
8. סיום ההתקשרות
עם סגירת חשבון המטפל יימחק המידע שמיינדסטאק מחזיקה עבורו. מחיקת מטופל או פגישה בתוך היישומון מוחקת את המידע הנוגע להם.
9. כללי
(א) תנאים אלה והסכם השותף העסקי (Business Associate Agreement) שבהמשך המסמך מאושרים יחד, באישור אחד. הנוסח העברי הוא המחייב לעניין הדין הישראלי; הנוסח האנגלי של הסכם השותף העסקי הוא המחייב לעניין דרישות HIPAA.
(ב) מיינדסטאק רשאית לפרסם נוסח מעודכן; נוסח מעודכן יחול על המטפל רק עם אישורו.
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement ("Agreement") is entered into between the therapist accepting this Agreement in the MindStack application ("Covered Entity") and MindStack ("Business Associate"), and takes effect at the moment of acceptance (the "Effective Date").
Covered Entity is a health care provider that may be subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"). Business Associate provides session recording, transcription, AI-assisted summarization, scheduling, and related practice-management services (the "Services"), and in doing so creates, receives, maintains, and transmits Protected Health Information on behalf of Covered Entity. The parties therefore agree as follows:
1. DEFINITIONS
Terms used but not otherwise defined in this Agreement have the meanings given to them in the HIPAA Rules. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164. "Protected Health Information" ("PHI") means protected health information as defined in 45 CFR 160.103, limited to the information Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity, and includes electronic PHI. "Breach," "Designated Record Set," "Individual," "Secretary," "Security Incident," "Subcontractor," and "Unsecured PHI" have the meanings given in the HIPAA Rules.
2. PERMITTED USES AND DISCLOSURES
(a) Business Associate may use and disclose PHI only as necessary to perform the Services for Covered Entity, as permitted by this Agreement, or as required by law.
(b) Business Associate may use PHI for its proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes only if the disclosure is required by law, or if Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as required by law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instance of which it is aware in which the confidentiality of the PHI has been breached.
(c) Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law, and shall not use or disclose PHI in any manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted under this Section 2.
(d) Business Associate shall not sell PHI, shall not use PHI for marketing, and shall not use PHI to train artificial-intelligence or machine-learning models.
(e) Business Associate shall make reasonable efforts to limit its uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose.
3. DE-IDENTIFICATION
Business Associate may de-identify PHI in accordance with 45 CFR 164.514(a)-(c). Information de-identified in accordance with that standard is no longer PHI, and Business Associate may use it for lawful purposes, including improving the Services and analytics.
4. SAFEGUARDS
Business Associate shall use appropriate administrative, physical, and technical safeguards to prevent any use or disclosure of PHI other than as provided for by this Agreement, and shall comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to electronic PHI. These safeguards include encryption of PHI in transit and at rest, access restricted by role to the minimum needed, and audit logging of access to systems holding PHI.
5. REPORTING
(a) Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware.
(b) Business Associate shall report to Covered Entity any Breach of Unsecured PHI without unreasonable delay, and in no case later than thirty (30) days after discovery. The report shall include, to the extent known, the identification of each Individual whose PHI was or is reasonably believed to have been involved, a description of what happened, and the information Covered Entity needs to meet its own notification obligations under 45 CFR 164.404.
(c) Business Associate shall report to Covered Entity any successful Security Incident of which it becomes aware. The parties acknowledge the ongoing existence of unsuccessful attempts (such as pings, port scans, and denied log-in attempts) that do not result in unauthorized access to or compromise of PHI; this paragraph serves as the standing notice of such unsuccessful attempts, and no further report of them is required.
6. SUBCONTRACTORS
In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement. Business Associate's Subcontractors include its speech-to-text transcription provider and its cloud infrastructure and artificial-intelligence platform provider, each engaged under such a written agreement.
7. INDIVIDUAL RIGHTS
(a) Access. Business Associate shall make PHI held in a Designated Record Set available to Covered Entity as necessary for Covered Entity to meet its obligations under 45 CFR 164.524.
(b) Amendment. Business Associate shall make PHI held in a Designated Record Set available for amendment, and shall incorporate any amendment Covered Entity directs or agrees to, as necessary for Covered Entity to meet its obligations under 45 CFR 164.526.
(c) Accounting. Business Associate shall document the disclosures of PHI that are subject to an accounting, and shall make that information available to Covered Entity as necessary for Covered Entity to meet its obligations under 45 CFR 164.528.
(d) To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164, Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation.
8. AVAILABILITY TO THE SECRETARY
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules.
9. OBLIGATIONS OF COVERED ENTITY
(a) Covered Entity shall notify Business Associate of any limitation in Covered Entity's notice of privacy practices, of any change in or revocation of an Individual's permission to use or disclose PHI, and of any restriction on the use or disclosure of PHI that Covered Entity has agreed to under 45 CFR 164.522, in each case to the extent it may affect Business Associate's use or disclosure of PHI.
(b) Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted under Section 2 of this Agreement.
10. TERM AND TERMINATION
(a) Term. This Agreement is effective from the Effective Date and remains in effect until the Services relationship between the parties ends or the Agreement is terminated under this Section.
(b) Termination. Covered Entity may terminate this Agreement at any time by closing its account. Either party may terminate this Agreement if the other party materially breaches it and fails to cure the breach within thirty (30) days of written notice.
(c) Return or destruction of PHI. Upon termination of this Agreement for any reason, Business Associate shall return to Covered Entity or destroy all PHI that Business Associate or its Subcontractors maintain in any form, and shall retain no copies. If return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to the retained PHI, limit its further use or disclosure to the purposes that make return or destruction infeasible, and maintain those protections for as long as it retains the PHI. Deleting the account in the application destroys the PHI Business Associate holds for Covered Entity.
(d) Survival. The obligations of Business Associate under this Section 10 survive termination of this Agreement.
11. LIABILITY
Each party is responsible for its own compliance with the HIPAA Rules. Business Associate is liable for damages arising directly from its material breach of this Agreement or its violation of the HIPAA Rules, except to the extent caused by the acts or omissions of Covered Entity. Neither party is liable to the other for indirect, incidental, special, or consequential damages. Except where such a limitation is prohibited by law, Business Associate's aggregate liability under this Agreement is limited to the fees paid by Covered Entity for the Services in the twelve (12) months preceding the event giving rise to the claim.
12. MISCELLANEOUS
(a) Regulatory references. A reference in this Agreement to a section of the HIPAA Rules means the section as in effect or as amended.
(b) Amendment. The parties agree to take such action as is necessary to amend this Agreement from time to time as required for compliance with the HIPAA Rules. Business Associate may issue a new version of this Agreement; a new version applies to Covered Entity only upon Covered Entity's acceptance of it.
(c) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.
(d) No third-party beneficiaries. Nothing in this Agreement confers any right or remedy on any person other than the parties.
(e) Governing text. This Agreement is made in English, and the English text is the binding text for HIPAA purposes. The Hebrew data-processing terms accepted together with this Agreement govern the relationship under Israeli law; any other introduction, summary, or translation is explanatory only and is not a contract.