The Subscription Agreement is the contract for the service. The Business Associate Agreement is the HIPAA contract that lets NeuryxIQ handle protected health information on your practice's behalf. Both are accepted by the practice's authorized signer at checkout and are effective on the date of payment. Signed and countersigned copies are available on request from support@neuryxiq.com.
NeuryxIQ managed detection and response, and HIPAA compliance evidence, delivered on a dedicated private instance
This Agreement, together with the Order Form (Exhibit A), the Pre-Authorization Matrix (Exhibit B) and the Business Associate Agreement, is the complete agreement between the practice named in the Order Form and NeuryxIQ.
| Customer | ______________________________________________ |
| Provider | Amhage Technology Group LLC, doing business as NeuryxIQ |
| Effective date | Date of the last signature |
| Document | NIQ-SUB · Version 2.1 · September 2026 |
| Exhibits | A Order Form · B Pre-Authorization Matrix · C Founding Customer Addendum (optional) |
This Subscription Agreement (the "Agreement") is between Amhage Technology Group LLC, doing business as NeuryxIQ ("NeuryxIQ"), and the practice named in the Order Form at Exhibit A ("Customer"). It takes effect on the date of the last signature.
A dedicated, private instance of the NeuryxIQ console for Customer, reachable over HTTPS with multi-factor sign-in, with data encrypted in transit and at rest.
Software agents for Customer's Windows workstations and servers, installed by Customer from the console's Setup page with a single provided installer. Support for additional operating systems is added as it ships and is not promised here.
Continuous monitoring of enrolled devices for security events, with automated analysis and case creation, twenty four hours a day.
An asset inventory covering operating systems, installed software and open vulnerabilities, with end of life and unsupported software flagged.
A generated Security Risk Analysis combining Customer's answers on administrative and physical safeguards with measured technical control results, dated and ready for Customer's Security Official to review and sign.
Compliance evidence drawn from live data rather than from a checklist, exportable for audits, cyber insurance questionnaires and attestation.
Human review by a NeuryxIQ analyst of the escalations the automated team raises, 8 AM to 8 PM US Eastern on business days, and a person on call at any hour for a confirmed incident at the response targets in Section 8.
Human oversight by NeuryxIQ for actions that change Customer's environment, per the Pre-Authorization Matrix at Exhibit B.
Stating this plainly protects both parties. Regulators have taken action against vendors who implied otherwise.
NeuryxIQ does not certify Customer as HIPAA compliant. No vendor can. NeuryxIQ provides a management system and automated evidence. Compliance remains Customer's obligation as the covered entity.
NeuryxIQ does not provide legal advice.
NeuryxIQ is not Customer's general IT provider. It does not manage printers, networks, email, or the practice management or EHR system.
NeuryxIQ does not guarantee that every attack will be prevented or detected. No security service can make that promise honestly.
Fees are stated in the Order Form at Exhibit A and summarized here. All amounts are in US dollars.
| Item | Price |
|---|---|
| Base subscription, includes up to 25 devices | $500 per month |
| Each device from 26 to 75 | $15 per device per month |
| Each device above 75 | $12 per device per month |
| Annual prepayment, by invoice on request | Two months free (pay for ten) |
| 24/7/365 human oversight, optional (nights, weekends and holidays) | $250 per month |
| Backup and Recovery, optional, per workstation (100 GB included) | $15 per device per month |
| Backup and Recovery, optional, per server (500 GB included) | $49 per server per month |
| Backup storage above the included amount | $0.10 per GB per month |
| Virtual HIPAA Compliance Officer, optional | $250 per month |
| White Glove setup, optional, one time | $499 |
| Standard onboarding | Included |
Backup and Recovery is ordered from the console and billed from the day it is switched on, at the prices above. The invite-only shared console is priced on the website but not yet available; it is not part of this Agreement and is not billed until Customer orders it in writing after it ships.
Device count is visible in the console at all times, together with what the next device costs. When Customer adds devices beyond the included 25, NeuryxIQ notifies Customer first and the change appears on the following billing cycle. NeuryxIQ does not meter silently, and no charge appears that Customer has not been told about in advance.
Billed monthly in advance by card or invoice, as elected in the Order Form. The initial term is twelve months. Customer may cancel or pause at any time with thirty days written notice, effective at the end of the then current month. Paused accounts keep their data, and devices are not monitored while paused. Fees already paid are not refunded except as required by law.
24/7/365 human oversight: extends the business-hours review included in the base subscription to nights, weekends and holidays. A person reviews every escalation the automated team raises at any hour, not only the ones that need a decision, with a named analyst and a monthly review call. Without this add on, the automated team still runs continuously, escalations are reviewed 8 AM to 8 PM US Eastern on business days, and NeuryxIQ is still on call for confirmed incidents at the response targets in Section 8.
Virtual HIPAA Compliance Officer: NeuryxIQ performs the work of the Security Official role, owning the policies, the risk analysis and the evidence, and supporting Customer in an audit or an insurance review. Customer retains the designation and the accountability, which under HIPAA cannot be outsourced.
White Glove setup: NeuryxIQ performs the onboarding rather than Customer, including enrolling every device, assigning roles, applying hardening, and walking the first risk analysis through with Customer's team.
Name a Security Official who can make decisions and be reached, and keep the contact chain in Exhibit B current.
Install the agent on the devices in scope, and tell NeuryxIQ when devices are added or retired.
Answer the Security Risk Analysis questionnaire honestly, and review and sign the resulting document.
Act on findings that only Customer can act on, such as decisions to take a system offline, notify patients, accept a risk, or spend money.
Keep credentials confidential, keep multi-factor authentication enabled, and not share console logins between people.
The Business Associate Agreement between the parties is incorporated into this Agreement by reference and must be signed before the first device is connected. Where this Agreement and the Business Associate Agreement conflict on the use or disclosure of protected health information, the Business Associate Agreement controls.
Customer's data is Customer's. On termination Customer may request an export of its findings, cases, inventory and compliance documents, which NeuryxIQ will provide within fifteen days. NeuryxIQ then deletes the instance and its data on the timeline in the Business Associate Agreement, and confirms deletion in writing.
NeuryxIQ improves the service continuously. Changes that add capability or fix defects are applied without notice. A change that removes a capability Customer relies on, or that requires action by Customer, is notified at least thirty days in advance except where needed to address a security risk.
Support is reachable at support@neuryxiq.com. NeuryxIQ responds within these targets, which match the review model in Exhibit B:
| Situation | Response target |
|---|---|
| Active security incident affecting patient data or operations | Within 1 hour, any hour, any day |
| An action awaiting NeuryxIQ review before it changes the environment | Within 4 business hours |
| A question, a report request, or a device that will not enroll | Within 1 business day |
| Business hours | Monday to Friday, 9:00 AM to 6:00 PM Eastern |
These are response targets for a company that is deliberately small. They are stated honestly rather than dressed up as an enterprise service level agreement.
Each party will protect the other's confidential information with at least the care it uses for its own, and will use it only to perform this Agreement. This obligation survives termination.
NeuryxIQ warrants that it will perform the services in a professional and workmanlike manner. Except for that warranty and the obligations in the Business Associate Agreement, the services are provided as is, and NeuryxIQ disclaims all other warranties, express or implied, including merchantability and fitness for a particular purpose.
Counsel to confirm the disclaimer language and its interaction with the HIPAA obligations in the Business Associate Agreement.
Except for a party's breach of Section 9, its obligations under the Business Associate Agreement, or its gross negligence or wilful misconduct, neither party is liable to the other for indirect, incidental, consequential or punitive damages, and each party's total liability under this Agreement is limited to the fees paid by Customer in the twelve months preceding the claim.
Commercial intent: a cap tied to twelve months of fees with the customary carve outs. Counsel to reconcile this clause with the indemnity expectations of Customer's cyber insurer and with the separate liability terms of the Business Associate Agreement.
This Agreement, its Exhibits and the Business Associate Agreement are the entire agreement between the parties on this subject. Changes must be in writing and signed by both. Neither party may assign this Agreement without the other's written consent, except to a successor in a merger or sale of substantially all assets. This Agreement is governed by the laws of the State of New York, and venue for any dispute lies in the state or federal courts sitting in Monroe County, New York. Notices are sent by email to the addresses in the Order Form and are effective on the next business day.
Signed by the authorized representatives of each party. The Order Form and Exhibit B are initialed where indicated.
Every field feeds either an agreement, the console branding or a provisioning step. Complete it with the practice on the call.
| Field | Entry |
|---|---|
| Practice legal name, as registered | |
| Doing business as, if different | |
| Street address | |
| City, state, ZIP | |
| Type of practice | |
| Number of locations | |
| Console address | ____________________ .neuryxiq.cloud |
| Role | Name | Title | Mobile | |
|---|---|---|---|---|
| Authorized signer | ||||
| Security Official (HIPAA) | ||||
| Billing contact | ||||
| Day to day contact |
The Security Official is a HIPAA requirement and the practice designates them. If the practice elects the Virtual HIPAA Compliance Officer, it still holds the designation.
| Item | Election | Monthly |
|---|---|---|
| Devices in scope at start | ________ devices | |
| Base subscription, up to 25 devices | Included | $500 |
| Devices 26 to 75, at $15 each | ________ devices | $________ |
| Devices above 75, at $12 each | ________ devices | $________ |
| 24/7/365 human oversight | Yes / No | $250 if yes |
| Virtual HIPAA Compliance Officer | Yes / No | $250 if yes |
| White Glove setup, one time | Yes / No | $499 once if yes |
| Billing cycle | Monthly / Annual (two months free) | |
| Payment method | Card on file / Invoice, net 15 | |
| Monthly total | $________ |
<b>Customer initials: ________ NeuryxIQ initials: ________</b>
This is where Customer tells NeuryxIQ, in advance, which actions it may take without calling and which it must call about first. It is what makes a 3:00 AM response possible. Initial one column per row. A blank row follows the recommended level. Reviewed annually and after any incident.
| # | Action | What it means for the practice | Level | Practice election (initial one) |
|---|---|---|---|---|
| 1 | Quarantine a file confirmed as malicious on a device | The file is moved where it cannot run. Nothing else on the device changes. Reversible. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 2 | Deploy or tune detection rules in monitor-only mode | NeuryxIQ improves what it watches for. Nothing on your machines is blocked or changed. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 3 | Block a known malicious internet address at the endpoint | A device stops talking to an address on a published threat list. A false alarm costs a minute, not a day. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 4 | Collect forensic evidence from an affected device | Memory, logs and files are copied for analysis. Evidence is preserved; the device keeps working. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 5 | Isolate a workstation from the network | The computer keeps running but cannot reach anything. Staff lose that machine until it is cleared. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 6 | Isolate a server from the network | Practice management, imaging or file services on that server stop for everyone until it is cleared. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 7 | Disable a user account showing signs of compromise | That person cannot sign in anywhere until the account is reviewed and reset. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 8 | Move a detection rule from monitor to blocking | A behavior that was only reported starts being stopped, on every device, automatically. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 9 | Take a clinical system offline during patient hours | Care is interrupted. Only the practice can weigh that against the risk. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
| 10 | Notify patients, regulators or law enforcement | A breach notification starts a legal clock (60 days under 45 CFR 164.404). The covered entity makes this call. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
| 11 | Accept a documented risk, or spend money on remediation | A risk left open is the practice's decision to record; a purchase is the practice's money. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
Pre-authorized: NeuryxIQ acts, records the action and the evidence, and reports it in the console and the weekly summary. The audit trail is the review.
Call first: NeuryxIQ prepares the action, then calls the contact chain below in order. The action is taken on a verbal yes, which NeuryxIQ records with the time and the name.
Customer decides: NeuryxIQ presents a written recommendation with a deadline and the consequence of waiting. The practice decides. Under HIPAA the covered entity's accountability for these decisions cannot be outsourced.
| Order | Name | Title | Mobile | Best hours |
|---|---|---|---|---|
| 1 | ||||
| 2 | ||||
| 3 |
During an active, spreading incident, if no contact answers within fifteen minutes of the first call, NeuryxIQ may take any call-first action that limits the spread, and will brief the first reachable contact afterwards with what was done and why. Isolation is preferred over powering off, because it preserves evidence. A false alarm under this clause is an accepted cost of a fast response.
<b>Practice initials to accept B.3: ________</b>
This Exhibit applies only if both parties initial it. It is offered to the first ten practices to sign and is not available on the website.
In exchange for the commitments in C.2, NeuryxIQ locks Customer's base rate at $500 per month for as long as Customer remains continuously subscribed, covering up to ________ devices rather than the standard 25. Above that count the per device rates in Section 3 apply to the devices above it, and those rates are locked for the same period. White Glove setup is waived.
Customer agrees to these in good faith, and NeuryxIQ will not use any of them in a way Customer has not approved in writing:
A written testimonial within ninety days of onboarding, which NeuryxIQ may publish.
Participation in one written case study, with Customer reviewing and approving the text and deciding whether the practice is named or described anonymously.
Up to four reference calls per year with prospective customers, scheduled at Customer's convenience.
Candid feedback on the product, including what does not work.
NeuryxIQ will not disclose any protected health information, security finding, vulnerability or incident of Customer in any public material. Marketing material is limited to what Customer approves in writing.
<b>Customer initials: ________ NeuryxIQ initials: ________</b>
Every field feeds either an agreement, the console branding or a provisioning step. Complete it with the practice on the call.
| Field | Entry |
|---|---|
| Practice legal name, as registered | |
| Doing business as, if different | |
| Street address | |
| City, state, ZIP | |
| Type of practice | |
| Number of locations | |
| Console address | ____________________ .neuryxiq.cloud |
| Role | Name | Title | Mobile | |
|---|---|---|---|---|
| Authorized signer | ||||
| Security Official (HIPAA) | ||||
| Billing contact | ||||
| Day to day contact |
The Security Official is a HIPAA requirement and the practice designates them. If the practice elects the Virtual HIPAA Compliance Officer, it still holds the designation.
| Item | Election | Monthly |
|---|---|---|
| Devices in scope at start | ________ devices | |
| Base subscription, up to 25 devices | Included | $500 |
| Devices 26 to 75, at $15 each | ________ devices | $________ |
| Devices above 75, at $12 each | ________ devices | $________ |
| 24/7/365 human oversight | Yes / No | $250 if yes |
| Virtual HIPAA Compliance Officer | Yes / No | $250 if yes |
| White Glove setup, one time | Yes / No | $499 once if yes |
| Billing cycle | Monthly / Annual (two months free) | |
| Payment method | Card on file / Invoice, net 15 | |
| Monthly total | $________ |
<b>Customer initials: ________ NeuryxIQ initials: ________</b>
This is where Customer tells NeuryxIQ, in advance, which actions it may take without calling and which it must call about first. It is what makes a 3:00 AM response possible. Initial one column per row. A blank row follows the recommended level. Reviewed annually and after any incident.
| # | Action | What it means for the practice | Level | Practice election (initial one) |
|---|---|---|---|---|
| 1 | Quarantine a file confirmed as malicious on a device | The file is moved where it cannot run. Nothing else on the device changes. Reversible. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 2 | Deploy or tune detection rules in monitor-only mode | NeuryxIQ improves what it watches for. Nothing on your machines is blocked or changed. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 3 | Block a known malicious internet address at the endpoint | A device stops talking to an address on a published threat list. A false alarm costs a minute, not a day. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 4 | Collect forensic evidence from an affected device | Memory, logs and files are copied for analysis. Evidence is preserved; the device keeps working. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 5 | Isolate a workstation from the network | The computer keeps running but cannot reach anything. Staff lose that machine until it is cleared. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 6 | Isolate a server from the network | Practice management, imaging or file services on that server stop for everyone until it is cleared. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 7 | Disable a user account showing signs of compromise | That person cannot sign in anywhere until the account is reviewed and reset. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 8 | Move a detection rule from monitor to blocking | A behavior that was only reported starts being stopped, on every device, automatically. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 9 | Take a clinical system offline during patient hours | Care is interrupted. Only the practice can weigh that against the risk. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
| 10 | Notify patients, regulators or law enforcement | A breach notification starts a legal clock (60 days under 45 CFR 164.404). The covered entity makes this call. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
| 11 | Accept a documented risk, or spend money on remediation | A risk left open is the practice's decision to record; a purchase is the practice's money. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
Pre-authorized: NeuryxIQ acts, records the action and the evidence, and reports it in the console and the weekly summary. The audit trail is the review.
Call first: NeuryxIQ prepares the action, then calls the contact chain below in order. The action is taken on a verbal yes, which NeuryxIQ records with the time and the name.
Customer decides: NeuryxIQ presents a written recommendation with a deadline and the consequence of waiting. The practice decides. Under HIPAA the covered entity's accountability for these decisions cannot be outsourced.
| Order | Name | Title | Mobile | Best hours |
|---|---|---|---|---|
| 1 | ||||
| 2 | ||||
| 3 |
During an active, spreading incident, if no contact answers within fifteen minutes of the first call, NeuryxIQ may take any call-first action that limits the spread, and will brief the first reachable contact afterwards with what was done and why. Isolation is preferred over powering off, because it preserves evidence. A false alarm under this clause is an accepted cost of a fast response.
<b>Practice initials to accept B.3: ________</b>
This Exhibit applies only if both parties initial it. It is offered to the first ten practices to sign and is not available on the website.
In exchange for the commitments in C.2, NeuryxIQ locks Customer's base rate at $500 per month for as long as Customer remains continuously subscribed, covering up to ________ devices rather than the standard 25. Above that count the per device rates in Section 3 apply to the devices above it, and those rates are locked for the same period. White Glove setup is waived.
Customer agrees to these in good faith, and NeuryxIQ will not use any of them in a way Customer has not approved in writing:
A written testimonial within ninety days of onboarding, which NeuryxIQ may publish.
Participation in one written case study, with Customer reviewing and approving the text and deciding whether the practice is named or described anonymously.
Up to four reference calls per year with prospective customers, scheduled at Customer's convenience.
Candid feedback on the product, including what does not work.
NeuryxIQ will not disclose any protected health information, security finding, vulnerability or incident of Customer in any public material. Marketing material is limited to what Customer approves in writing.
<b>Customer initials: ________ NeuryxIQ initials: ________</b>
Every field feeds either an agreement, the console branding or a provisioning step. Complete it with the practice on the call.
| Field | Entry |
|---|---|
| Practice legal name, as registered | |
| Doing business as, if different | |
| Street address | |
| City, state, ZIP | |
| Type of practice | |
| Number of locations | |
| Console address | ____________________ .neuryxiq.cloud |
| Role | Name | Title | Mobile | |
|---|---|---|---|---|
| Authorized signer | ||||
| Security Official (HIPAA) | ||||
| Billing contact | ||||
| Day to day contact |
The Security Official is a HIPAA requirement and the practice designates them. If the practice elects the Virtual HIPAA Compliance Officer, it still holds the designation.
| Item | Election | Monthly |
|---|---|---|
| Devices in scope at start | ________ devices | |
| Base subscription, up to 25 devices | Included | $500 |
| Devices 26 to 75, at $15 each | ________ devices | $________ |
| Devices above 75, at $12 each | ________ devices | $________ |
| 24/7 human oversight | Yes / No | $250 if yes |
| Virtual HIPAA Compliance Officer | Yes / No | $250 if yes |
| White Glove setup, one time | Yes / No | $499 once if yes |
| Billing cycle | Monthly / Annual (two months free) | |
| Payment method | Card on file / Invoice, net 15 | |
| Monthly total | $________ |
<b>Customer initials: ________ NeuryxIQ initials: ________</b>
This is where Customer tells NeuryxIQ, in advance, which actions it may take without calling and which it must call about first. It is what makes a 3:00 AM response possible. Initial one column per row. A blank row follows the recommended level. Reviewed annually and after any incident.
| # | Action | What it means for the practice | Level | Practice election (initial one) |
|---|---|---|---|---|
| 1 | Quarantine a file confirmed as malicious on a device | The file is moved where it cannot run. Nothing else on the device changes. Reversible. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 2 | Deploy or tune detection rules in monitor-only mode | NeuryxIQ improves what it watches for. Nothing on your machines is blocked or changed. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 3 | Block a known malicious internet address at the endpoint | A device stops talking to an address on a published threat list. A false alarm costs a minute, not a day. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 4 | Collect forensic evidence from an affected device | Memory, logs and files are copied for analysis. Evidence is preserved; the device keeps working. | Pre-authorized | Pre-authorize ____,Call first ____,Never ____ |
| 5 | Isolate a workstation from the network | The computer keeps running but cannot reach anything. Staff lose that machine until it is cleared. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 6 | Isolate a server from the network | Practice management, imaging or file services on that server stop for everyone until it is cleared. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 7 | Disable a user account showing signs of compromise | That person cannot sign in anywhere until the account is reviewed and reset. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 8 | Move a detection rule from monitor to blocking | A behavior that was only reported starts being stopped, on every device, automatically. | Call first | Pre-authorize ____,Call first ____,Never ____ |
| 9 | Take a clinical system offline during patient hours | Care is interrupted. Only the practice can weigh that against the risk. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
| 10 | Notify patients, regulators or law enforcement | A breach notification starts a legal clock (60 days under 45 CFR 164.404). The covered entity makes this call. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
| 11 | Accept a documented risk, or spend money on remediation | A risk left open is the practice's decision to record; a purchase is the practice's money. | Customer decides | Pre-authorize ____,Call first ____,Never ____ |
Pre-authorized: NeuryxIQ acts, records the action and the evidence, and reports it in the console and the weekly summary. The audit trail is the review.
Call first: NeuryxIQ prepares the action, then calls the contact chain below in order. The action is taken on a verbal yes, which NeuryxIQ records with the time and the name.
Customer decides: NeuryxIQ presents a written recommendation with a deadline and the consequence of waiting. The practice decides. Under HIPAA the covered entity's accountability for these decisions cannot be outsourced.
| Order | Name | Title | Mobile | Best hours |
|---|---|---|---|---|
| 1 | ||||
| 2 | ||||
| 3 |
During an active, spreading incident, if no contact answers within fifteen minutes of the first call, NeuryxIQ may take any call-first action that limits the spread, and will brief the first reachable contact afterwards with what was done and why. Isolation is preferred over powering off, because it preserves evidence. A false alarm under this clause is an accepted cost of a fast response.
<b>Practice initials to accept B.3: ________</b>
This Exhibit applies only if both parties initial it. It is offered to the first ten practices to sign and is not available on the website.
In exchange for the commitments in C.2, NeuryxIQ locks Customer's base rate at $500 per month for as long as Customer remains continuously subscribed, covering up to ________ devices rather than the standard 25. Above that count the per device rates in Section 3 apply to the devices above it, and those rates are locked for the same period. White Glove setup is waived.
Customer agrees to these in good faith, and NeuryxIQ will not use any of them in a way Customer has not approved in writing:
A written testimonial within ninety days of onboarding, which NeuryxIQ may publish.
Participation in one written case study, with Customer reviewing and approving the text and deciding whether the practice is named or described anonymously.
Up to four reference calls per year with prospective customers, scheduled at Customer's convenience.
Candid feedback on the product, including what does not work.
NeuryxIQ will not disclose any protected health information, security finding, vulnerability or incident of Customer in any public material. Marketing material is limited to what Customer approves in writing.
<b>Customer initials: ________ NeuryxIQ initials: ________</b>
Between the Covered Entity named within and Amhage Technology Group LLC, doing business as NeuryxIQ
This Agreement governs every use and disclosure of protected health information that NeuryxIQ creates, receives, maintains or transmits on the Covered Entity's behalf in the course of providing managed detection and response and HIPAA compliance evidence.
| Covered Entity | ______________________________________________ |
| Business Associate | Amhage Technology Group LLC, doing business as NeuryxIQ |
| Effective date | ______________________ |
| Document | NIQ-BAA · Version 2.0 · September 2026 |
| Retention | Six years from the date last in effect, 45 CFR 164.530(j)(2) |
This Business Associate Agreement (the "Agreement") is entered into as of the Effective Date stated on the cover page by and between:
| Field | Entry |
|---|---|
| Covered Entity | |
| Address | |
| Business Associate | Amhage Technology Group LLC, doing business as NeuryxIQ, a New York limited liability company |
| Address | 1718 Edgemere Drive, Rochester, New York 14612 |
The parties enter into this Agreement to comply with the Standards for Privacy and Security of Individually Identifiable Health Information at 45 CFR Parts 160 and 164, as amended, in connection with the services described in Exhibit A.
Terms used but not otherwise defined in this Agreement have the meaning given to them in the HIPAA Rules. As used here:
"Business Associate" has the meaning given at 45 CFR 160.103, and in reference to a party to this Agreement means Amhage Technology Group LLC.
"Covered Entity" has the meaning given at 45 CFR 160.103, and in reference to a party to this Agreement means the entity named above.
"HIPAA Rules" means the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164.
"Protected Health Information" or "PHI" has the meaning given at 45 CFR 160.103, limited to information created, received, maintained or transmitted by Business Associate from or on behalf of Covered Entity.
Business Associate agrees to:
(a) Not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
(c) Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including breaches of unsecured PHI as required at 45 CFR 164.410, and any security incident of which it becomes aware. Business Associate will make that report without unreasonable delay and in no case later than the number of calendar days stated in Exhibit A.
(d) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate with respect to that information. Business Associate's current subcontractors are listed in Exhibit B.
(e) Make available PHI in a designated record set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524.
(f) Make any amendment to PHI in a designated record set as directed or agreed to by Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under that section.
(g) Maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.528.
(h) To the extent Business Associate carries out one or more of Covered Entity's obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.
(i) Make its internal practices, books and records available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules.
(a) Business Associate may only use or disclose PHI as necessary to perform the services described in Exhibit A, and shall limit its uses and disclosures to the minimum necessary consistent with 45 CFR 164.502(b).
(b) Business Associate may use or disclose PHI as required by law.
(c) Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only if the disclosure is required by law, or if Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and be used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the person will notify Business Associate of any breach of confidentiality.
(d) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity if, and only if, that election is initialed in Exhibit A.
(e) Business Associate shall not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity.
(f) Business Associate shall not sell PHI, shall not use or disclose PHI for marketing purposes, and shall not use or disclose PHI to train, fine tune or otherwise improve any general purpose machine learning model.
(a) Covered Entity shall notify Business Associate of any limitation in its notice of privacy practices under 45 CFR 164.520, to the extent that the limitation may affect Business Associate's use or disclosure of PHI.
(b) Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an individual to use or disclose the individual's PHI, to the extent that the change may affect Business Associate's use or disclosure of PHI.
(c) Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that the restriction may affect Business Associate's use or disclosure of PHI.
(d) Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted by Sections 3(c) and 3(d) above.
(e) Covered Entity is responsible for designating which of its systems and devices are within the scope of the services, and for the accuracy of the device and contact information it provides.
This Agreement takes effect on the Effective Date and remains in effect until all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if return or destruction is infeasible, protections are extended to that information in accordance with Section 5.3.
Covered Entity may terminate this Agreement if Covered Entity determines that Business Associate has violated a material term of this Agreement and Business Associate has not cured the breach or ended the violation within the period stated in Exhibit A. Covered Entity may terminate immediately if cure is not possible.
Upon termination of this Agreement for any reason, Business Associate shall return to Covered Entity, or destroy, all PHI received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form. Business Associate shall retain no copies of the PHI. Where return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to that PHI, limit further uses and disclosures to those purposes that make return or destruction infeasible, and return or destroy the PHI when those purposes no longer apply. Exhibit A states the standard timeline and the method of destruction.
The obligations of Business Associate under Section 5.3 survive the termination of this Agreement.
(a) A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.
(b) The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPAA Rules.
(c) Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.
(d) Nothing in this Agreement is intended to confer, nor shall anything in it confer, upon any person other than the parties any rights, remedies, obligations or liabilities whatsoever.
(e) This Agreement is governed by the laws of the State of New York, without regard to its conflict of laws provisions. Venue for any dispute lies in the state or federal courts sitting in Monroe County, New York.
(f) If this Agreement conflicts with any services agreement between the parties, this Agreement controls with respect to the use and disclosure of PHI.
Business Associate provides NeuryxIQ, a managed detection and response and HIPAA compliance evidence service. Software agents installed on Covered Entity's designated computers collect security telemetry, which is transmitted to a dedicated, single-tenant instance operated by Business Associate, analyzed for security events, and presented to Covered Entity through a web console together with compliance evidence and reports.
The service is not designed to collect, store or process patient records, and Business Associate does not request them. The service collects security telemetry: file names and paths, user account names, process and command information, network connection metadata, software and operating system inventory, and authentication and audit events. Some of that telemetry can incidentally contain protected health information, for example where a file name or folder path includes a patient name. The parties therefore treat all telemetry as if it may contain PHI, and this Agreement applies to it in full.
| Term | Value |
|---|---|
| Breach and security incident notification | Without unreasonable delay and no later than five (5) calendar days after discovery, with a written follow up as facts develop. |
| Cure period for material breach | Thirty (30) calendar days from written notice. |
| Return or destruction after termination | Within thirty (30) calendar days of termination, unless Covered Entity requests an export first. |
| Method of destruction | Cryptographic erasure and deletion of the dedicated instance, its storage volumes and its snapshots, with written confirmation to Covered Entity. |
| Data location | United States. Amazon Web Services, US East (Ohio) region. |
| Data retention during the term | Security telemetry retained for the retention period stated in the Subscription Agreement, then deleted. |
| Encryption | Encrypted in transit (TLS) and encrypted at rest (AES-256, AWS KMS managed keys). |
| Data aggregation services | Not provided unless initialed here by Covered Entity: ________ |
| Role | Covered Entity | Business Associate |
|---|---|---|
| Primary contact | Michael Romansky | |
| Title | Security Official | |
| security@neuryxiq.com | ||
| Phone |
Business Associate uses the subcontractors listed below in providing the services. Each has agreed in writing to restrictions and conditions equivalent to those in this Agreement. Business Associate will update this list and notify Covered Entity before adding a subcontractor that will create, receive, maintain or transmit PHI.
| Subcontractor | Role in the service | Written agreement |
|---|---|---|
| Amazon Web Services, Inc. | Hosting and storage of the dedicated instance and its data, backups and snapshots. | AWS Business Associate Addendum, accepted in AWS Artifact. Effective August 5, 2026. |
| AI model provider | Automated analysis and summarization of security findings. | Business Associate Agreement. Provider: ________________ Date: __________ |
The AI model provider row must be completed, or PHI must be demonstrably excluded from every prompt by a redaction layer, before the first customer device is connected. An unsigned subcontractor agreement is the most common finding in enforcement actions against vendors of this type.
Each party has caused this Agreement to be executed by its duly authorized representative as of the Effective Date.
Retain a signed copy for at least six years from the date of creation or the date it was last in effect, whichever is later, per 45 CFR 164.530(j)(2).