The agreement conditions the use of Protected Health Information with the Service on execution of a Business Associate Addendum. The agreement also states that the Service is not PCI compliant, which the customer acknowledges.
This analysis describes what Harvey AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a prerequisite BAA execution for any use of PHI with the Service, consistent with HIPAA requirements for covered entities and business associates. The explicit PCI non-compliance acknowledgment restricts use cases involving payment card data and places contractual notice on customers regarding that limitation.
Under this clause, customers who are HIPAA covered entities or business associates using PHI with the Service must execute a separate Business Associate Addendum before doing so. The terms include a customer acknowledgment that the Service is not PCI compliant, precluding payment card data from being submitted to the Service.
Cross-platform context
See how other platforms handle Protected Health Information and Business Associate Addendum and similar clauses.
Compare across platforms →"If You utilize Protected Health Information with the Service, such usage will further be subject to the terms of an executed Harvey Business Associate Addendum. You acknowledge that the Service is not Payment Card Industry (PCI) compliant.Excerpt from Harvey AI's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA and the HITECH Act, including 45 CFR Parts 160 and 164, which require covered entities and business associates to execute a compliant BAA before sharing PHI with …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes a prerequisite BAA execution for any use of PHI with the Service, consistent with HIPAA requirements for covered entities and business associates. The explicit PCI non-compliance acknowledgment restricts use cases involving payment card data and places contractual notice on customers regarding that limitation.
Under this clause, customers who are HIPAA covered entities or business associates using PHI with the Service must execute a separate Business Associate Addendum before doing so. The terms include a customer acknowledgment that the Service is not PCI compliant, precluding payment card data from being submitted to the Service.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Harvey AI.