Legal

The two documents you accept at checkout.

The Subscription Agreement is the contract for the service. The Business Associate Agreement is the HIPAA contract that lets NeuryxIQ handle protected health information on your practice's behalf. Both are accepted by the practice's authorized signer at checkout and are effective on the date of payment. Signed and countersigned copies are available on request from support@neuryxiq.com.


Exhibit A: Order Form

Every field feeds either an agreement, the console branding or a provisioning step. Complete it with the practice on the call.

A.1 The practice

FieldEntry
Practice legal name, as registered
Doing business as, if different
Street address
City, state, ZIP
Type of practice
Number of locations
Console address____________________ .neuryxiq.cloud

A.2 The people

RoleNameTitleEmailMobile
Authorized signer
Security Official (HIPAA)
Billing contact
Day to day contact

The Security Official is a HIPAA requirement and the practice designates them. If the practice elects the Virtual HIPAA Compliance Officer, it still holds the designation.


A.3 Scope and price

ItemElectionMonthly
Devices in scope at start________ devices
Base subscription, up to 25 devicesIncluded$500
Devices 26 to 75, at $15 each________ devices$________
Devices above 75, at $12 each________ devices$________
24/7 human oversightYes / No$250 if yes
Virtual HIPAA Compliance OfficerYes / No$250 if yes
White Glove setup, one timeYes / No$499 once if yes
Billing cycleMonthly / Annual (two months free)
Payment methodCard on file / Invoice, net 15
Monthly total$________

<b>Customer initials: ________ NeuryxIQ initials: ________</b>


Exhibit B: Pre-Authorization Matrix

This is where Customer tells NeuryxIQ, in advance, which actions it may take without calling and which it must call about first. It is what makes a 3:00 AM response possible. Initial one column per row. A blank row follows the recommended level. Reviewed annually and after any incident.

#ActionWhat it means for the practiceLevelPractice election (initial one)
1Quarantine a file confirmed as malicious on a deviceThe file is moved where it cannot run. Nothing else on the device changes. Reversible.Pre-authorizedPre-authorize ____,Call first ____,Never ____
2Deploy or tune detection rules in monitor-only modeNeuryxIQ improves what it watches for. Nothing on your machines is blocked or changed.Pre-authorizedPre-authorize ____,Call first ____,Never ____
3Block a known malicious internet address at the endpointA device stops talking to an address on a published threat list. A false alarm costs a minute, not a day.Pre-authorizedPre-authorize ____,Call first ____,Never ____
4Collect forensic evidence from an affected deviceMemory, logs and files are copied for analysis. Evidence is preserved; the device keeps working.Pre-authorizedPre-authorize ____,Call first ____,Never ____
5Isolate a workstation from the networkThe computer keeps running but cannot reach anything. Staff lose that machine until it is cleared.Call firstPre-authorize ____,Call first ____,Never ____
6Isolate a server from the networkPractice management, imaging or file services on that server stop for everyone until it is cleared.Call firstPre-authorize ____,Call first ____,Never ____
7Disable a user account showing signs of compromiseThat person cannot sign in anywhere until the account is reviewed and reset.Call firstPre-authorize ____,Call first ____,Never ____
8Move a detection rule from monitor to blockingA behavior that was only reported starts being stopped, on every device, automatically.Call firstPre-authorize ____,Call first ____,Never ____
9Take a clinical system offline during patient hoursCare is interrupted. Only the practice can weigh that against the risk.Customer decidesPre-authorize ____,Call first ____,Never ____
10Notify patients, regulators or law enforcementA breach notification starts a legal clock (60 days under 45 CFR 164.404). The covered entity makes this call.Customer decidesPre-authorize ____,Call first ____,Never ____
11Accept a documented risk, or spend money on remediationA risk left open is the practice's decision to record; a purchase is the practice's money.Customer decidesPre-authorize ____,Call first ____,Never ____

B.1 How each level works

Pre-authorized: NeuryxIQ acts, records the action and the evidence, and reports it in the console and the weekly summary. The audit trail is the review.

Call first: NeuryxIQ prepares the action, then calls the contact chain below in order. The action is taken on a verbal yes, which NeuryxIQ records with the time and the name.

Customer decides: NeuryxIQ presents a written recommendation with a deadline and the consequence of waiting. The practice decides. Under HIPAA the covered entity's accountability for these decisions cannot be outsourced.

B.2 Contact chain for call-first actions

OrderNameTitleMobileBest hours
1
2
3

B.3 If nobody answers

During an active, spreading incident, if no contact answers within fifteen minutes of the first call, NeuryxIQ may take any call-first action that limits the spread, and will brief the first reachable contact afterwards with what was done and why. Isolation is preferred over powering off, because it preserves evidence. A false alarm under this clause is an accepted cost of a fast response.

<b>Practice initials to accept B.3: ________</b>

Customer
Security Official or authorized signer

Signature ______________________
Name, title, date
Amhage Technology Group LLC
Doing business as NeuryxIQ

Signature ______________________
Name, title, date

Exhibit C: Founding Customer Addendum (optional)

This Exhibit applies only if both parties initial it. It is offered to the first ten practices to sign and is not available on the website.

C.1 The founding rate

In exchange for the commitments in C.2, NeuryxIQ locks Customer's base rate at $500 per month for as long as Customer remains continuously subscribed, covering up to ________ devices rather than the standard 25. Above that count the per device rates in Section 3 apply to the devices above it, and those rates are locked for the same period. White Glove setup is waived.

C.2 What the founding customer gives back

Customer agrees to these in good faith, and NeuryxIQ will not use any of them in a way Customer has not approved in writing:

A written testimonial within ninety days of onboarding, which NeuryxIQ may publish.

Participation in one written case study, with Customer reviewing and approving the text and deciding whether the practice is named or described anonymously.

Up to four reference calls per year with prospective customers, scheduled at Customer's convenience.

Candid feedback on the product, including what does not work.

NeuryxIQ will not disclose any protected health information, security finding, vulnerability or incident of Customer in any public material. Marketing material is limited to what Customer approves in writing.

<b>Customer initials: ________ NeuryxIQ initials: ________</b>


HIPAA · 45 CFR Parts 160 and 164

Business Associate Agreement

Between the Covered Entity named within and Amhage Technology Group LLC, doing business as NeuryxIQ

This Agreement governs every use and disclosure of protected health information that NeuryxIQ creates, receives, maintains or transmits on the Covered Entity's behalf in the course of providing managed detection and response and HIPAA compliance evidence.

Covered Entity______________________________________________
Business AssociateAmhage Technology Group LLC, doing business as NeuryxIQ
Effective date______________________
DocumentNIQ-BAA · Version 2.0 · September 2026
RetentionSix years from the date last in effect, 45 CFR 164.530(j)(2)

Parties and purpose

This Business Associate Agreement (the "Agreement") is entered into as of the Effective Date stated on the cover page by and between:

FieldEntry
Covered Entity
Address
Business AssociateAmhage Technology Group LLC, doing business as NeuryxIQ, a New York limited liability company
Address1718 Edgemere Drive, Rochester, New York 14612

The parties enter into this Agreement to comply with the Standards for Privacy and Security of Individually Identifiable Health Information at 45 CFR Parts 160 and 164, as amended, in connection with the services described in Exhibit A.

1. Definitions

Terms used but not otherwise defined in this Agreement have the meaning given to them in the HIPAA Rules. As used here:

"Business Associate" has the meaning given at 45 CFR 160.103, and in reference to a party to this Agreement means Amhage Technology Group LLC.

"Covered Entity" has the meaning given at 45 CFR 160.103, and in reference to a party to this Agreement means the entity named above.

"HIPAA Rules" means the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164.

"Protected Health Information" or "PHI" has the meaning given at 45 CFR 160.103, limited to information created, received, maintained or transmitted by Business Associate from or on behalf of Covered Entity.

2. Obligations and activities of Business Associate

Business Associate agrees to:

(a) Not use or disclose PHI other than as permitted or required by this Agreement or as required by law.

(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.

(c) Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including breaches of unsecured PHI as required at 45 CFR 164.410, and any security incident of which it becomes aware. Business Associate will make that report without unreasonable delay and in no case later than the number of calendar days stated in Exhibit A.

(d) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate with respect to that information. Business Associate's current subcontractors are listed in Exhibit B.

(e) Make available PHI in a designated record set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524.

(f) Make any amendment to PHI in a designated record set as directed or agreed to by Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under that section.

(g) Maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.528.

(h) To the extent Business Associate carries out one or more of Covered Entity's obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.

(i) Make its internal practices, books and records available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules.

3. Permitted uses and disclosures by Business Associate

(a) Business Associate may only use or disclose PHI as necessary to perform the services described in Exhibit A, and shall limit its uses and disclosures to the minimum necessary consistent with 45 CFR 164.502(b).

(b) Business Associate may use or disclose PHI as required by law.

(c) Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only if the disclosure is required by law, or if Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and be used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the person will notify Business Associate of any breach of confidentiality.

(d) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity if, and only if, that election is initialed in Exhibit A.

(e) Business Associate shall not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity.

(f) Business Associate shall not sell PHI, shall not use or disclose PHI for marketing purposes, and shall not use or disclose PHI to train, fine tune or otherwise improve any general purpose machine learning model.

4. Obligations of Covered Entity

(a) Covered Entity shall notify Business Associate of any limitation in its notice of privacy practices under 45 CFR 164.520, to the extent that the limitation may affect Business Associate's use or disclosure of PHI.

(b) Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an individual to use or disclose the individual's PHI, to the extent that the change may affect Business Associate's use or disclosure of PHI.

(c) Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that the restriction may affect Business Associate's use or disclosure of PHI.

(d) Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted by Sections 3(c) and 3(d) above.

(e) Covered Entity is responsible for designating which of its systems and devices are within the scope of the services, and for the accuracy of the device and contact information it provides.

5. Term and termination

5.1 Term

This Agreement takes effect on the Effective Date and remains in effect until all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if return or destruction is infeasible, protections are extended to that information in accordance with Section 5.3.

5.2 Termination for cause

Covered Entity may terminate this Agreement if Covered Entity determines that Business Associate has violated a material term of this Agreement and Business Associate has not cured the breach or ended the violation within the period stated in Exhibit A. Covered Entity may terminate immediately if cure is not possible.

5.3 Obligations of Business Associate upon termination

Upon termination of this Agreement for any reason, Business Associate shall return to Covered Entity, or destroy, all PHI received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form. Business Associate shall retain no copies of the PHI. Where return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to that PHI, limit further uses and disclosures to those purposes that make return or destruction infeasible, and return or destroy the PHI when those purposes no longer apply. Exhibit A states the standard timeline and the method of destruction.

5.4 Survival

The obligations of Business Associate under Section 5.3 survive the termination of this Agreement.

6. Miscellaneous

(a) A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

(b) The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPAA Rules.

(c) Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.

(d) Nothing in this Agreement is intended to confer, nor shall anything in it confer, upon any person other than the parties any rights, remedies, obligations or liabilities whatsoever.

(e) This Agreement is governed by the laws of the State of New York, without regard to its conflict of laws provisions. Venue for any dispute lies in the state or federal courts sitting in Monroe County, New York.

(f) If this Agreement conflicts with any services agreement between the parties, this Agreement controls with respect to the use and disclosure of PHI.


Exhibit A: Services, scope and operating terms

A.1 Description of services

Business Associate provides NeuryxIQ, a managed detection and response and HIPAA compliance evidence service. Software agents installed on Covered Entity's designated computers collect security telemetry, which is transmitted to a dedicated, single-tenant instance operated by Business Associate, analyzed for security events, and presented to Covered Entity through a web console together with compliance evidence and reports.

A.2 The PHI involved, and why

The service is not designed to collect, store or process patient records, and Business Associate does not request them. The service collects security telemetry: file names and paths, user account names, process and command information, network connection metadata, software and operating system inventory, and authentication and audit events. Some of that telemetry can incidentally contain protected health information, for example where a file name or folder path includes a patient name. The parties therefore treat all telemetry as if it may contain PHI, and this Agreement applies to it in full.

A.3 Operating terms

TermValue
Breach and security incident notificationWithout unreasonable delay and no later than five (5) calendar days after discovery, with a written follow up as facts develop.
Cure period for material breachThirty (30) calendar days from written notice.
Return or destruction after terminationWithin thirty (30) calendar days of termination, unless Covered Entity requests an export first.
Method of destructionCryptographic erasure and deletion of the dedicated instance, its storage volumes and its snapshots, with written confirmation to Covered Entity.
Data locationUnited States. Amazon Web Services, US East (Ohio) region.
Data retention during the termSecurity telemetry retained for the retention period stated in the Subscription Agreement, then deleted.
EncryptionEncrypted in transit (TLS) and encrypted at rest (AES-256, AWS KMS managed keys).
Data aggregation servicesNot provided unless initialed here by Covered Entity: ________

A.4 Contacts for notice

RoleCovered EntityBusiness Associate
Primary contactMichael Romansky
TitleSecurity Official
Emailsecurity@neuryxiq.com
Phone

Exhibit B: Subcontractors

Business Associate uses the subcontractors listed below in providing the services. Each has agreed in writing to restrictions and conditions equivalent to those in this Agreement. Business Associate will update this list and notify Covered Entity before adding a subcontractor that will create, receive, maintain or transmit PHI.

SubcontractorRole in the serviceWritten agreement
Amazon Web Services, Inc.Hosting and storage of the dedicated instance and its data, backups and snapshots.AWS Business Associate Addendum, accepted in AWS Artifact. Effective August 5, 2026.
AI model providerAutomated analysis and summarization of security findings.Business Associate Agreement. Provider: ________________ Date: __________
Before first connection

The AI model provider row must be completed, or PHI must be demonstrably excluded from every prompt by a redaction layer, before the first customer device is connected. An unsigned subcontractor agreement is the most common finding in enforcement actions against vendors of this type.


Signatures

Each party has caused this Agreement to be executed by its duly authorized representative as of the Effective Date.

Covered Entity
The entity named on the cover page

Signature ______________________
Name, title, date
Amhage Technology Group LLC
Doing business as NeuryxIQ

Signature ______________________
Name, title, date

Retain a signed copy for at least six years from the date of creation or the date it was last in effect, whichever is later, per 45 CFR 164.530(j)(2).