CaseBridge Business Associate and Data Protection Agreement Version 1.0 — October 5, 2026 1. Parties, purpose, and effective date This Agreement is between Legal Services Network, LLC, organized in Delaware and doing business as CaseBridge under its Nebraska trade-name registration (Provider), and the law firm or business identified at checkout (Firm). It takes effect when Firm completes the electronic-signature process described in Section 12, in consideration of the parties' mutual promises and Provider's managed record-review services. It applies to all such services and subsequent orders while effective. Protected Information means medical, health, personal, confidential client, and matter information received, created, maintained, or transmitted by Provider on Firm's behalf, including source records, prompts, intermediate files, and deliverables. PHI, electronic PHI, Breach, Unsecured PHI, Security Incident, Covered Entity, Business Associate, Designated Record Set, Required by Law, and Secretary have the meanings assigned in 45 CFR Parts 160 and 164 (HIPAA Rules), as amended. Secretary means the Secretary of the United States Department of Health and Human Services. 2. HIPAA and non-HIPAA relationships If Firm is a Covered Entity, Provider acts as its Business Associate to the extent the services create that relationship. If Firm is a Business Associate, Provider acts as its subcontractor Business Associate; Firm is responsible for its upstream authority and obligations. In those circumstances this Agreement satisfies the parties' contractual requirements under 45 CFR 164.502(e), 164.504(e), and 164.314(a), and HIPAA-required obligations apply to PHI. If Firm instead holds records under patient authorization or another lawful basis without being a Covered Entity or Business Associate, this Agreement does not manufacture HIPAA status. Its confidentiality, restricted-use, safeguards, incident-response, assistance, subcontractor, and return/destruction obligations nevertheless apply contractually to Protected Information, to the extent relevant and lawful. Nothing limits duties imposed directly by applicable federal or state law. The more protective applicable legal requirement controls. This Agreement is not itself patient consent, a HIPAA disclosure authorization, a Part 2 consent, or a court order. 3. Permitted uses and disclosures Provider may use and disclose Protected Information only to perform the ordered record-review services at Firm's documented lawful direction, including approved secure storage, processing, AI-assisted preparation, human review, delivery, support, and necessary security operations, as expressly permitted here, or as Required by Law. Provider shall not use or disclose PHI in a manner that would violate the Privacy Rule if done by the applicable Covered Entity, except the limited management and administration provisions below. Provider shall limit uses, disclosures, and requests to the minimum necessary where applicable. Provider may use PHI for its proper management and administration or legal responsibilities. Disclosure for those purposes is permitted only if Required by Law or if Provider obtains reasonable assurances that the recipient will hold it confidentially, use or further disclose it only as Required by Law or for the disclosed purpose, and notify Provider of any breach of confidentiality. These provisions do not authorize marketing, sale, unrelated product development, or unrestricted data aggregation. Provider shall not sell Protected Information, use it for advertising, train or fine-tune general-purpose or cross-client AI models with it, combine it into another client's matter, or permit a subcontractor to do so. De-identification for an independent secondary purpose requires Firm's separate written authorization and compliance with applicable law; this Agreement supplies no such authorization. Ordinary service and billing records must exclude patient and case-content information whenever practicable. Provider will notify Firm of compulsory disclosure requests unless law prohibits notification, reasonably cooperate with lawful protective measures, and disclose only what is legally required. Nothing permits obstruction of a regulator or withholding information lawfully required by the Secretary. 4. Safeguards and personnel Provider shall use appropriate administrative, physical, and technical safeguards to prevent unauthorized use or disclosure and comply with the HIPAA Security Rule, 45 CFR Part 164 Subpart C, with respect to electronic PHI as applicable. Provider shall maintain a documented risk analysis and risk-management process, access restrictions based on job duties, user access revocation, security training, incident response, and reasonable monitoring, backup, and recovery procedures. Protected Information shall be encrypted in transit and at rest in Provider-controlled systems, with appropriately protected keys. These are continuing contractual duties, not a claim of government certification or an assurance that no incident can occur. Access is limited to personnel with a service need who are bound by enforceable confidentiality obligations and receive appropriate privacy and security instruction. Provider is responsible for its workforce and its compliance with this Agreement; classification as an independent contractor does not eliminate applicable subcontractor requirements. Before permitting access, Provider must establish required contractual protections and confirm that the systems used are suitable for the information and restrictions involved. 5. Subcontractors and processing restrictions Before a subcontractor creates, receives, maintains, or transmits PHI on Provider's behalf, Provider shall enter a written agreement imposing the same applicable restrictions, conditions, and Security Rule requirements as this Agreement, including further subcontractor flow-down, as required by 45 CFR 164.502(e) and 164.308(b). For other Protected Information, Provider shall obtain materially equivalent written confidentiality, security, restricted-use, and return/destruction obligations. Provider remains responsible for its own obligations and oversight. A cloud service's eligibility for HIPAA workloads is not a substitute for an executed BAA or compliant configuration. Provider shall not route PHI to a service requiring a BAA before that agreement and applicable controls are in place. Public marketing, advertising, analytics, and payment platforms shall not receive case records or patient information through Provider's service workflows. Provider will identify applicable subprocessors and their functions on its subprocessor page or in a written engagement-specific list, and provide at least 30 days' advance written notice of material additions or replacements, except an urgent security or legal change for which notice will be given as soon as reasonably possible. Firm may raise a reasonable data-protection objection during that period. The parties will seek a workable alternative; if none is reasonably available, Firm may terminate the affected unperformed services and receive a refund of their unused prepaid fees. Provider will not introduce processing outside the United States without Firm's prior written approval and compliance with applicable restrictions. 6. Incident and breach notification Provider shall report to Firm any use or disclosure not permitted by this Agreement, Breach of Unsecured PHI, or Security Incident affecting Protected Information without unreasonable delay and no later than 72 hours after discovery. Discovery has the meaning in 45 CFR 164.410(a)(2) where applicable, including when known or when reasonable diligence would have revealed it to Provider or its relevant personnel or agents; the clock does not await final confirmation or a completed investigation. A shorter applicable legal deadline controls. For non-PHI Protected Information, the same contractual timing applies to discovered unauthorized access, acquisition, use, disclosure, alteration, loss, or destruction. Initial notice may be preliminary. Provider will provide known details and timely supplements: nature and dates, affected persons and information to the extent identifiable, likely consequences, containment and mitigation, protective recommendations, and an incident contact. Breach notices shall include the information required by 45 CFR 164.410(c). Provider shall promptly investigate, contain, preserve relevant evidence, mitigate harmful effects to the extent practicable, and reasonably cooperate with Firm's required assessment and notifications. The parties acknowledge that routine unsuccessful probes, rejected login attempts, and blocked attacks occur. This paragraph constitutes ongoing notice solely of such unsuccessful events that cause no unauthorized access, use, disclosure, loss, or material interference with Protected Information; Provider will provide summaries on reasonable request. It does not excuse reporting successful incidents, suspected actual compromise, material service interference, or legally reportable events. Firm coordinates notifications to its clients and upstream entities unless law requires Provider to notify directly. The parties will coordinate practicably without delaying any required notice; neither needs the other's permission to comply with law. Costs are allocated under the Terms according to responsibility, without limiting mandatory reporting or regulators' rights. Notify Firm at its designated security contact or, absent one, its business email of record, with reasonable additional contact attempts for urgent incidents. Firm reports incidents and updates contacts at dan@casebridge-legal.com. 7. Access, amendment, accounting, and oversight Within ten business days of Firm's request, or sooner as reasonably necessary for a notified applicable deadline, Provider shall make PHI in a Designated Record Set available to Firm, or at Firm's lawful direction to the individual or designee, to support 45 CFR 164.524; make PHI available for amendment and incorporate amendments as directed under 45 CFR 164.526; and provide information about disclosures needed for an accounting under 45 CFR 164.528. Provider shall keep records reasonably necessary to support these duties. For non-PHI Protected Information, Provider shall provide comparable reasonable assistance with applicable access, correction, deletion, and other privacy rights. Provider shall promptly forward individual requests to Firm and not independently deny or resolve them unless legally required or authorized by Firm. To the extent Provider carries out a Covered Entity's Privacy Rule obligation, Provider shall comply with the requirements applicable to that obligation. Provider shall make its internal practices, books, and records relating to PHI available to the Secretary as required to determine HIPAA compliance. Firm may obtain reasonable written compliance information and, following a material incident or substantiated concern, a reasonably scoped review subject to safeguards for other customers, security, and privilege. No confidentiality term limits lawful government access. 8. Firm's obligations and specially protected information Firm shall provide lawful processing instructions and necessary permissions; notify Provider of relevant limits in privacy notices, agreed restrictions under 45 CFR 164.522, changes or revocations of permission, and court or other legal restrictions that affect Provider's work; and not request an impermissible use or disclosure. Firm must minimize unnecessary data, use approved secure transfer, maintain its own original records, and keep account and security contacts current. Provider shall notify Firm if it reasonably believes an instruction violates applicable privacy law and may suspend the affected processing pending resolution. Before transferring records governed by 42 CFR Part 2, psychotherapy-note restrictions, or other special federal or state protections, Firm must identify those restrictions and the parties must confirm lawful authority and appropriate handling in writing. Provider may decline information it cannot lawfully safeguard. This does not shift Provider's direct statutory duties to Firm or permit reliance on an instruction Provider knows is unlawful. 9. Term, breach, and termination This Agreement continues while Provider holds Protected Information. If Provider materially breaches it, Firm may require cure or cessation within a reasonable period specified in written notice, and may terminate affected services if the breach is not cured or immediately if cure is not feasible. Provider has comparable termination rights for Firm's unlawful instructions or material breach, subject to lawful return and protection of information. A party shall take other steps required by law if termination is not feasible. Ending a service order does not end duties concerning retained information. 10. Return, destruction, and retention Provider shall retain Protected Information only as needed for authorized services, Firm's documented lawful instructions, or legal obligations. For individual Case Reviews, source records and working files are scheduled for deletion 30 days after delivery unless Firm requests earlier deletion or a documented lawful continued-service or preservation need applies. Firm may retain and export delivered work products during the engagement. For ongoing packages, Provider follows the agreed retention instructions. Provider is not a substitute for Firm's file-retention system. Upon termination, Provider shall make records and deliverables available for secure return or export for 30 days, or a different period lawfully agreed with Firm, and then return or destroy all Protected Information, including subcontractor copies, if feasible. Earlier lawful return or destruction instructions will be reasonably accommodated. Provider will confirm completion on request. Provider shall not retain copies for unrelated commercial use. Where return or destruction is infeasible, including legally required preservation or protected backup media that cannot reasonably be selectively erased, Provider shall identify the reason to Firm, retain only the information necessary, continue all applicable safeguards, and limit further use and disclosure to the purpose making return or destruction infeasible. Backups remain protected and are deleted through the applicable documented lifecycle; restored information must again follow Firm's deletion instructions. Provider shall destroy retained information when the impediment ends. An unpaid invoice is not an independent reason to retain PHI or deny access required by law. Deidentified billing and signature records may be retained as legally necessary without retaining patient records. 11. Relationship to Terms and applicable law This Agreement controls conflicting commercial or website terms on use, disclosure, security, notification, access, and disposition of Protected Information. The Managed Services Terms supply commercial remedies, lawful liability allocation, notices, and dispute provisions. No commercial cap, indemnity, dispute process, or payment condition reduces mandatory HIPAA or other statutory duties, obstructs a regulator, delays a required report, or restricts individuals' nonwaivable rights. Applicable federal law controls HIPAA matters. The Terms' Virginia governing-law provision applies to commercial disputes subject to nonwaivable federal and state law, including more protective applicable privacy and breach-notification requirements in any state. The parties shall cooperate on amendments needed to comply with changes in law; no amendment may authorize conduct prohibited by law. Ambiguities shall be resolved to permit compliance. Invalid provisions are severed to the extent lawful. No contractual third-party beneficiary is created, and statutory rights remain intact. 12. Execution and retained copies Firm's authorized representative signs this BAA and the Managed Services Terms by entering the signatory information required at Stripe checkout, checking the explicit electronic-signature acceptance for both linked documents, and submitting checkout. The representative confirms authority to bind the identified Firm, intent to sign each document, and ability to access and retain them electronically. Provider adopts this agreement through authorized publication and order acceptance in the name of Legal Services Network, LLC d/b/a CaseBridge. The completed checkout, signatory information, acceptance record, date, and document versions are logically associated with both documents as the execution record. No patient information belongs in that record. The effective date is the completed checkout date. Both agreements may be downloaded or printed before signing and afterward; contact dan@casebridge-legal.com for copies or to arrange manual execution before purchase. These obligations cover subsequent orders while this Agreement remains in effect. Reaffirmation does not erase earlier duties, reset retention requirements, or retroactively amend another signed version. Provider contact: dan@casebridge-legal.com; https://casebridge-legal.com.