# Legal Center: Terms, Privacy, DPA & HIPAA BAA — Medrecords AI

> Every legal document that governs Medrecords AI in one place: Terms, Privacy Notice, DPA, HIPAA & BAA, Subprocessor List, Cookie Policy, and the Master Service Agreement.

Canonical page: https://medrecords.ai/legal/

---
New — **Missing Records Detection:** flags every visit, provider, and date missing from the file. [See how →](https://medrecords.ai/product/missing-records-identification/)
Medrecords AI · Legal Center

## The paperwork, written like we mean it.

7 documents govern everything we do with your data and your money. Each opens with a plain-English summary, and the commitments that matter (never training on your records, deletion with certificates, breach clocks in hours) are contractual, not marketing.

All documents effective July 7, 2026
 AI Health Studio LLC · Sheridan, Wyoming
[
DOCUMENT 01
 v2.0 · Jul 7, 2026
Terms of Service
The master agreement: who may use the platform, per-page billing with spend caps, Test-a-File evaluation terms, your duty to verify AI output, and the not-a-medical-device line.

cancel anytime
 verify-before-filing duty
 aggregate liability cap
](https://medrecords.ai/terms/)

 [
DOCUMENT 02
 v2.0 · Jul 7, 2026
Privacy Notice
Visitor, customer, and applicant data: what we collect, the full sharing list, a named retention table, US state and GDPR rights, and what individuals do when their records went through our platform.

never sold
 no ad pixels
 GPC honored
](https://medrecords.ai/privacy/)

 [
DOCUMENT 03
 v1.0 · Jul 7, 2026
Data Processing Addendum
Processor terms for the records you upload: instructions-only processing, the contractual never-train clause, customer-controlled retention with deletion certificates, subprocessor objection rights, SCCs — plus per-plan data paths in Annex 3.

never-train §4.4
 72h incident notice
 deletion certificates
](https://medrecords.ai/dpa/)

 [
DOCUMENT 04
 Jul 7, 2026
HIPAA & BAA
Where covered entities, business associates, and non-covered legal and casualty teams each stand — and the clause-by-clause map of what our Business Associate Agreement commits us to.

BAA at signup
 covers Test a File
 workers' comp explained
](https://medrecords.ai/hipaa/)

 [
DOCUMENT 05
 Updated Jul 7, 2026
Subprocessor List
4 vendors can touch Customer Content: AWS, Anthropic, OpenAI, OpenRouter — every one under a BAA with zero-retention, no-training terms. Business-ops vendors listed separately. Subscribe for 30-day advance change notices.

US-only processing
 30-day notice
 changelog
](https://medrecords.ai/subprocessors/)

 [
DOCUMENT 06
 v1.1 · Jul 8, 2026
Cookie Policy
Every cookie and localStorage key, named with provider, purpose, and lifetime. Analytics and marketing run by default, public site only, never the platform; nothing sensitive in browser storage.

named cookies
 opt-out anytime
 no PHI in storage
](https://medrecords.ai/cookies/)

 [
DOCUMENT 07
 v1.0 · Aug 28, 2026
Master Service Agreement
The signed framework agreement for AI Enablement and Enterprise On-Prem customers: Order Form mechanics, fees, PHI handling, liability, and termination, negotiated once so renewals don't start from scratch.

enterprise only
 Order Form mechanics
 signed, not click-through
](https://medrecords.ai/msa/)
How the documents fit together
1 · BAA — controls for PHI
 →
 2 · DPA — controls for personal data
 →
 3 · Order Form — enterprise plans
 →
 4 · Master Service Agreement — enterprise framework
 →
 5 · Terms of Service — everything else
Self-Service and Test-a-File customers get the whole stack automatically: accepting the Terms incorporates the DPA, and the BAA is presented click-through before any upload. Enterprise customers sign a Master Service Agreement and countersign an Order Form for each deal. The Privacy Notice and Cookie Policy cover the website and your account regardless of plan.

### For procurement & security review

Countersigned BAA / DPA
Need executed copies on your paper or ours? We accept reasonable redlines.

[legal@medrecords.ai →](mailto:legal@medrecords.ai)
Security package
Controls documentation, SOC 2 evidence summary, pen-test summary (under NDA).

[Request via Trust Center →](https://medrecords.ai/security/)
Subprocessor notices
30-day advance notice of any change to who can process Customer Content.

[Subscribe on the list →](https://medrecords.ai/subprocessors/)
Questions about any of this?
Legal: [legal@medrecords.ai](mailto:legal@medrecords.ai) · Privacy: [privacy@medrecords.ai](mailto:privacy@medrecords.ai) · Security: [security@medrecords.ai](mailto:security@medrecords.ai)

AI Health Studio LLC d/b/a Medrecords AI
30 North Gould Street, Sheridan, WY 82801
