Last updated: May 4, 2026

Business Associate Agreement

This Business Associate Agreement ("BAA") between Blocks Platforms Ltd. ("Business Associate"), and the entity engaging Blocks's Services, ("Covered Entity") forms part of, and is subject to the Business Associate Terms of Service ("Agreement"). By clicking "I Agree", the Covered Entity agrees to be bound by this Agreement.

WHEREAS, Covered Entity will make available and/or transfer to Business Associate certain information, including Protected Health Information ("PHI"), in conjunction with goods or services that are being provided by Business Associate to Covered Entity, that is confidential and must be afforded special treatment and protection.

WHEREAS, Business Associate and Covered Entity intend to protect the privacy and provide for the security of PHI disclosed to Business Associate in compliance with the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, as amended by the HITECH Act (as defined below) and the related regulations promulgated by HHS (as defined below) (collectively, "HIPAA"), and the Privacy Rule, Security Rule, Enforcement Rule and Breach Notification Rule set forth at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Rules") promulgated thereunder.

WHEREAS, the purpose of this BAA is to satisfy certain standards and requirements of HIPAA and the HIPAA Rules, including without limitation, Title 45, §§ 164.314(a)(2)(i), 164.502(e) and 164.504(e) of the Code of Federal Regulations ("C.F.R.").

NOW, THEREFORE, Covered Entity and Business Associate agree as follows:

1. Definitions

The following terms shall have the meaning ascribed to them in this Section. Other capitalized terms shall have the meaning ascribed to them in the HIPAA Rules, with such definitions incorporated in this Agreement by reference.

a)"Breach" shall mean the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule which compromises the security or privacy of the PHI, as defined in 45 C.F.R. §164.402.

b)"Breach Notification Rule" shall mean the HIPAA regulations regarding breach notification requirements at 45 C.F.R. Part 164, Subpart D.

c)"Covered Entity" shall have the same meaning given to such term in 45 C.F.R. § 160.103, and shall mean the covered entity specified above, the organization providing/making available PHI.

d)"Data Aggregation" shall mean, with respect to the PHI created or received by Business Associate in its capacity as the "business associate" under HIPAA of Covered Entity, the combining of such PHI by Business Associate with the PHI received by Business Associate in its capacity as a business associate of one or more other "covered entity" under HIPAA, to permit data analyses that relate to the Health Care Operations (defined below) of the respective covered entities. The meaning of "data aggregation" in this BAA shall be consistent with the meaning given to that term in the Privacy Rule.

e)"Designated Record Set" shall have the meaning given to such term under the Privacy Rule, including 45 C.F.R. §164.501(b).

f)"De-Identify" shall mean to alter the PHI such that the resulting information meets the requirements described in 45 C.F.R. §§164.514(a) and (b).

g)"Electronic PHI" shall mean any PHI maintained in or transmitted by electronic media as defined in 45 C.F.R. §160.103.

h)"Health Care Operations" shall have the meaning given to that term in 45 C.F.R. §164.501.

i)"HHS" shall mean the U.S. Department of Health and Human Services.

j)"HITECH Act" shall mean the Health Information Technology for Economic and Clinical Health Act, enacted as part of the American Recovery and Reinvestment Act of 2009, Public Law 111-005.

k)"Individual" shall have the same meaning given to such term in 45 C.F.R. 160.103.

l)"Parties" shall mean Business Associate and Covered Entity.

m)"Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 C.F.R. Part 160 and Part 164, Subparts A and E.

n)"Protected Health Information" or "PHI" shall mean any "protected health information" provided and/or made available by Covered Entity to Business Associate, and has the same meaning as the term "protected health information" as defined by 45 C.F.R. 160.103. For the avoidance of doubt, the term "PHI" shall not include any de-identified data, which may be used by Business Associate without limitation.

o)"Security Incident" shall mean the unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Notwithstanding anything to the contrary in this Agreement, the Parties acknowledge that Security Incident as used herein does not include activities such as pings and other broadcast attacks on Business Associate's firewall, port scans, unsuccessful log-on attempts, denials of service, and any combination of the above, so long as no such incident results in unauthorized access, use, or disclosure of PHI.

p)"Security Rule" shall mean the Security Standards at 45 C.F.R. Part 160 and Part 164, Subparts A and C.

q)"Unsecured PHI" means any PHI as defined in 45 C.F.R. §§164.501 and 160.103 that is not rendered unusable, unreadable or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the HHS Secretary in the guidance issued pursuant to the HITECH Act and codified at 42 U.S.C. §17932(h).

2. Use and Disclosure of PHI

a)Permitted Uses

Except as otherwise provided in this BAA, Business Associate may use or disclose PHI as reasonably necessary to provide the services described in the Agreement to Covered Entity, and to undertake other activities of Business Associate permitted or required of Business Associate by this BAA or as required by law.

b)Limits on Use and Further Disclosure Established by Contract and Law

Business Associate shall not further use or disclose other than as permitted or required by this BAA or as Required by Law.

c)Use of PHI for Management, Administration and Legal Responsibilities

Business Associate may use PHI for the proper management and administration of Business Associate or to carry out legal responsibilities of Business Associate.

d)Disclosure of PHI for Management, Administration and Legal Responsibilities

Business Associate may disclose PHI received from Covered Entity for the proper management and administration of Business Associate or to carry out legal responsibilities of Business Associate, provided: i. The disclosure is required by law; or ii. Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will be held confidentially and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, the person will use appropriate safeguards to prevent use or disclosure of the PHI, and the person agrees to notify Business Associate of any instance of which it is aware in which the confidentiality of the PHI has been breached.

e)Data Aggregation Services

Business Associate may use or disclose PHI to provide Data Aggregation services as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).

f)De-Identification

Business Associate may de-identify PHI in accordance with the standards set forth in 45 C.F.R. § 164.514(b) and may use or disclose such de-identified data for any purpose.

3. Obligations and Activities of Business Associate

a)Appropriate Safeguards

Business Associate shall implement appropriate administrative, physical, and technical safeguards and comply with the HIPAA Security Rule with respect to Electronic PHI, to prevent any use or disclosure of such information other than as provided for by this BAA.

b)Minimum Necessary

To the extent required by HIPAA, Business Associate will limit any use or disclosure of, or request for, PHI to the minimum amount necessary to accomplish the intended purpose of the use, disclosure, or request.

c)Reporting Disclosures of PHI and Security Incidents

Business Associate will report to Covered Entity in writing any use or disclosure of PHI not provided for by this BAA of which it becomes aware and Business Associate agrees to report to Covered Entity any Security Incident affecting Electronic PHI of Covered Entity of which it becomes aware. Business Associate agrees to report any such event within five business days of becoming aware of the event.

d)Reporting Breaches of Unsecured PHI

Reporting Breaches of Unsecured PHI. Business Associate will notify Covered Entity in writing promptly upon the discovery of any Breach of Unsecured PHI in accordance with the requirements set forth in 45 CFR §164.410, but in no case later than 30 calendar days after discovery of a Breach.

e)Agents and Subcontractors

Business Associate agrees to take appropriate measures to ensure that any agent, including a subcontractor, to whom it provides PHI received from, or created or received by Business Associate on behalf of Covered Entity: (1) agrees to the same restrictions and conditions that apply through this BAA to Business Associate with respect to such information. (2) appropriately safeguards any Electronic PHI; and (3) complies with the applicable requirements of 45 CFR Part 164 Subpart C of the Security Rule. To the extent Business Associate uses agents and subcontractors in its performance of its obligations hereunder, Business Associate shall remain responsible for their compliance with obligations in this BAA.

f)Access to PHI

Upon request, Business Associate agrees to furnish Covered Entity with copies of the PHI maintained by Business Associate in a Designated Record Set in the time and manner designated by Covered Entity to enable Covered Entity to respond to an Individual's request for access to PHI under 45 C.F.R. §164.524. If an Individual makes a request for access directly to Business Associate, or inquiries about his or her right to access, Business Associate shall direct the Individual to Covered Entity. Any disclosure of, or decision not to disclose, the PHI requested by an Individual or a personal representative and compliance with the requirements applicable to an Individual's right to obtain access to PHI shall be the sole responsibility of Covered Entity.

g)Amendment of PHI

Upon request and instruction from Covered Entity, Business Associate will amend PHI or a record about an Individual in a Designated Record Set that is maintained by, or otherwise within the possession of, Business Associate as directed by Covered Entity in accordance with procedures established by 45 CFR §164.526. Any request by Covered Entity to amend such information will be completed by Business Associate within 15 business days of Covered Entity's request. If an Individual makes a request directly to Business Associate to amend such Individual's PHI or record in a Designated Record Set, Business Associate shall direct Individual to Covered Entity. Any amendment of, or decision not to amend, the PHI or record as requested by an Individual and compliance with the requirements applicable to an Individual's right to request an amendment of PHI will be the sole responsibility of Covered Entity.

h)Accounting of Disclosures

Business Associate will document any disclosures of PHI made by it to account for such disclosures as required by 45 CFR §164.528(a). Business Associate also will make available information related to such disclosures as would be required for Covered Entity to respond to a request for an accounting of disclosures in accordance with 45 CFR §164.528. In the event that Covered Entity elects to provide an Individual with a list of its business associates, Business Associate will provide an accounting of its disclosures of PHI upon request of the Individual, if and to the extent that such accounting is required under the HITECH Act or under HHS regulations adopted in connection with the HITECH Act. Otherwise, in the event an Individual delivers the initial request for an accounting directly to Business Associate, Business Associate shall direct Individual to Covered Entity.

i)Availability of Books and Records

Business Associate will make available its internal practices, books, agreements, records, and policies and procedures relating to the use and disclosure of PHI, upon request, to the Secretary of HHS for purposes of determining Covered Entity's and Business Associate's compliance with HIPAA, and this BAA.

j)Performance of a Covered Entity's Obligations

To the extent Business Associate is to carry out a Covered Entity obligation under the Privacy Rule, Business Associate shall comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of such obligation.

4. Obligations of Covered Entity

With regard to the use and/or disclosure of Protected Health Information by Business Associate, Covered Entity agrees to:

a)Notice of Privacy Practices

Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices in accordance with 45 C.F.R. §164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.

b)Notification of Changes Regarding Individual Permission

Covered Entity shall obtain any consent or authorization that may be required by the HIPAA Privacy Rule, or applicable state law, prior to furnishing Business Associate with PHI. Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.

c)Notification of Restrictions to Use or Disclosure of PHI

Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 C.F.R. § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

d)Permissible Requests by Covered Entity

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as otherwise permitted under this BAA.

5. HIPAA Compliance; Subprocessors and Integrations

a)Business Associate represents that the core components of the Services that are necessary for their intended operation are designed to be HIPAA-compliant and are implemented with appropriate administrative, physical, and technical safeguards consistent with the requirements of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").

b)Notwithstanding the foregoing, Covered Entity acknowledges and agrees that certain optional features, third-party services, integrations, or sub-processors made available through or in connection with the Services (collectively, "Optional Components") may not be HIPAA-compliant or covered under this Agreement. Some Optional Components are provided by third-party vendors that, although they may maintain high security standards, have not entered into a Business Associate Agreement ("BAA") with Business Associate or have not been formally designated as covered for purposes of PHI processing under this Agreement.

c)Covered Entity is solely responsible for reviewing the current list of sub-processors and integrations, including their applicable compliance designations, prior to using the Services and prior to transmitting, storing, or otherwise processing any Protected Health Information ("PHI") through the Services or any applications built using the Services. The current list of sub-processors and related information is available at: https://www.blocks.diy/website/hipaa-subprocessors.

d)Covered Entity agrees not to transmit or process PHI through any Optional Components that are not expressly designated as covered under this Agreement for purposes of PHI processing. No use of Optional Components with PHI shall be deemed authorized unless explicitly approved in writing by Business Associate.

e)Business Associate does not warrant or guarantee the accuracy, completeness, or ongoing validity of any compliance designation, and reserves the right to update, modify, or reclassify any Optional Component at any time.

f)Covered Entity assumes all risk and liability arising from any decision to transmit, store, or process PHI through the Services in connection with any Optional Components.

6. Term and Termination

a)Term

This BAA will become effective as of the date on which the Covered Entity accepts it (the "Effective Date") and will continue in effect until all obligations of the Parties have been met under the Agreement and under this BAA.

b)Termination for Cause

i. Covered Entity may terminate immediately this BAA, the Agreement, and any other related agreements if Covered Entity makes a determination that Business Associate has breached a material term of this BAA and Business Associate has failed to cure that material breach, to Covered Entity's reasonable satisfaction, within 30 days after written notice from Covered Entity. Covered Entity may report the problem to the Secretary of HHS if termination is not feasible. ii. If Business Associate determines that Covered Entity has breached a material term of this BAA, then Business Associate will provide Covered Entity with written notice of the existence of the breach and shall provide Covered Entity with 30 days to cure the breach. Covered Entity's failure to cure the breach within the 30-day period will be grounds for immediate termination of the Agreement and this BAA by Business Associate. Business Associate may report the breach to HHS.

c)Effect of Termination

Upon termination of the Agreement or this BAA for any reason, all PHI maintained by Business Associate will be returned to Covered Entity or destroyed by Business Associate. Business Associate will not retain any copies of such information. This provision will apply to PHI in the possession of Business Associate's agents and subcontractors. If return or destruction of the PHI is not feasible, in Business Associate's reasonable judgment, Business Associate will furnish Covered Entity with notification, in writing, of the conditions that make return or destruction infeasible. Upon mutual agreement of the Parties that return or destruction of the PHI is infeasible, Business Associate will extend the protections of this BAA to such information for as long as Business Associate retains such information and will limit further uses and disclosures to those purposes that make the return or destruction of the information not feasible. The Parties understand that this Section 5(c) will survive any termination of this BAA.

7. Effect of BAA

This BAA is a part of and subject to the terms of the Agreement, except that to the extent any terms of this BAA conflict with any term of the Agreement, the terms of this BAA will govern. Except as expressly stated in this BAA or as provided by law, this BAA will not create any rights in favor of any third party.

8. Regulatory References

A reference in this BAA to a section in HIPAA means the section as in effect or as amended at the time.

9. Amendments and Waiver

This BAA may not be modified, nor will any provision be waived or amended, except in writing duly signed by authorized representatives of the Parties. A waiver with respect to one event shall not be construed as continuing, or as a bar to or waiver of any right or remedy as to subsequent events.