Entity layer
A BAA, MSA, and DPA or equivalent data-processing terms must be signed by an authorized billing-company signatory before non-family customer PHI workflows.
DPA
Medi separates account terms, PHI processing authority, and benchmark data rights. This page is an implementation posture, not final legal advice; attorney review is required before final customer contract language is used.
Agreement stack
The data model records the agreement version, signer authority, data-rights grant, and benchmark eligibility separately so Medi can prove what was allowed, when, and for which billing company.
A BAA, MSA, and DPA or equivalent data-processing terms must be signed by an authorized billing-company signatory before non-family customer PHI workflows.
Users accept account terms and acceptable use at sign-in. That user acceptance references the entity agreement but does not grant entity data rights by itself.
Benchmark or network intelligence requires explicit de-identification permission under 45 CFR 164.514, a de-identified data license, and provider-contract flow-down representation.
Processor posture