Add attorney-review legal bundle: BAA template v1, cover memo, send-ready docx set

lead-sttil drafted, ops-steward independently reviewed (6 findings fixed).
Entity name corrected to KJF Professional Services LLC dba STTIL Solutions.
Formation state left as attorney question 1. LOI/NDA v3 live in STTIL-Vault/Projects/Legal.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Kisa 2026-07-07 05:35:21 -04:00
parent bd92126384
commit 5ba31fac03
8 changed files with 336 additions and 2 deletions

View file

@ -4,7 +4,7 @@ v:1
ACTIVE: 2026-07-07 [CC]. SIGNAL BUILD UN-PAUSED — readiness-model completion in flight per docs/build-plans/. P1 (wiring) SHIPPED + LIVE-VERIFIED (commit a3af499, deployed to Railway, false-green kill observed live). Executing P2 (citation IDs) -> P3 (rollup) -> P4 (device overrides) -> P5 (plan-type enforcement) next, one item at a time with independent audit each. P6 (frontend nesting) BLOCKED on Kisa approving the rendered mockup (built, awaiting render+review).
NEXT: (CC) P2-P5 per docs/build-plans/02-readiness-model-completion.md; (Kisa) approve/reject P6 mockup decisions A-D; (Kisa) confirm OQ1 plan_type-ingestion decision recorded 2026-07-07 (shipped per umbrella plan; two-line revert if reversed); (Kisa) attorney email bundle + Gaboro re-approach per reactivation plan 00 (unchanged). Queued behind Signal: UMSIS docs-only activation, "63% written off" Draft fix.
NEXT: (CC) P2-P5 per docs/build-plans/02-readiness-model-completion.md; (Kisa) approve/reject P6 mockup decisions A-D; (Kisa) confirm OQ1 plan_type-ingestion decision recorded 2026-07-07 (shipped per umbrella plan; two-line revert if reversed); (Kisa) attorney bundle READY TO SEND (signal/pitch/legal/attorney-bundle-2026-07-07, 5 Word docs + sendable memo): confirm recipient (Clyde Mathes vs Bittinger/Nixon), entity name + formation state, arbitration-vs-courts posture, Partner Concepts carve-out keep/drop, then email; Gaboro re-approach per reactivation plan 00 (unchanged). Queued behind Signal: UMSIS docs-only activation, "63% written off" Draft fix.
PRIOR ACTIVE: 2026-06-28. Signal paused at clean checkpoint — Insight Engine in active BUILD phase for July 4 deadline. See insight-engine/context/current-state.md and insight-engine/handoff-clock.md for full state. Key progress today: x-sight guided experience designed (Compass) and approved by Kisa, lane-lock handoff clock created, frontend finish readiness assessed (15 ranked items). Claude is building the Compass landing + B1 deploy blocker + finish items. Signal READINESS MODEL still queued at the clean checkpoint from 2026-06-27.
@ -25,6 +25,7 @@ Insight Engine (July 4 deadline = tomorrow) is the active project. Key files:
## Decisions (last
- 2026-07-07 [CC]: Attorney-review legal bundle PREPARED (lead-sttil drafted, ops-steward independently reviewed, 6 findings fixed incl. 4 HIGH counterparty-name leaks). LOI template v3 (product-agnostic body, Exhibit A pre-filled for Signal, labABLE negotiation learnings folded in), NDA template v3 (products list corrected to Signal/Vitality Med Tracker/UMSIS + catch-all), BAA template v1 (generalized from Gaboro draft, forward-looking posture block), cover memo bundling both templates + BAA + FDA CDS memo + labABLE AKS question per reactivation plan 00. Entity name corrected everywhere to KJF Professional Services LLC dba STTIL Solutions (per executed labABLE LOI; kg_add recorded); formation state left as placeholder (old docs disagree: Delaware/Florida/Pennsylvania) = attorney Q1. Templates: STTIL-Vault/Projects/Legal/ (LOI+NDA v3) + signal/pitch/legal/ (BAA, memo). Send-ready docx: signal/pitch/legal/attorney-bundle-2026-07-07/.
- 2026-07-07 [CC]: Readiness model WIRED LIVE (plan 01, commit a3af499, Railway deploy verified). Phase 2a seam confirmed: readiness AUGMENTS legacy output (byte-identical legacy proven by live diff). OQ1 executed per umbrella plan 00 ("ship plan_type ingestion with the wiring") — minimal client-mapped column, never guessed; flagged for Kisa's explicit confirmation, two-line revert if reversed. Adversarial review caught a false-green in the draft row-resolution; fixed via dedup-group-keyed ReadinessIndex, regression-locked. Grounded test count: 132 (the old "73 tests" figure corrected per plan 01 §12.5).
- 2026-07-06 [CC]: Model routing SETTLED (Kisa agreed) — strongest model in the orchestrator seat (plain claude, full MCP, skip-permissions), sonnet/haiku subagents for mechanical work, Fable-as-subagent only for cleanly separable hard problems. Docs-verified: delegation multiplies tokens on one shared pool; per-agent model override + mid-session /model GROUNDED. Config application PARKED. Discovered com.sttil.cos-model-switch: Fable-to-Opus swap fires 2026-07-07 09:00. Watcher audit: 9 agents healthy, clean exits; research watcher never built.
- 2026-07-06 [CC]: Crew Compounding Memory Phase 1 shipped + independently verified — retrieve-and-inject wired into the dispatch skill (validity-stamped "WHAT THE CREW ALREADY KNOWS" block, current==true filter, recall guard) + ~/.claude/crew-log.md; built by the memory-crew, verified PASS (2 agents flagged every planted contradiction, independent grader confirmed). Also ruled: UMSIS activates sttil/umsis docs-only (state in the repo, not the vault). Spec + build record: STTIL-Vault/Projects/STTIL Solutions/Crew Compounding Memory - Design Spec - 2026-07-05.md.
@ -58,4 +59,4 @@ Insight Engine (July 4 deadline = tomorrow) is the active project. Key files:
State protocol: read = `git pull --rebase` then read this file (warn if Updated > 24h old); write = edit ACTIVE/NEXT, append one author-stamped decision, then commit + push. Full protocol in the `state-sync` skill. Detailed ship-status (what shipped / didn't / why) = docs/ship-status-ledger.md. TriLane = searchable archive, not live state.
## Updated: 2026-07-07 (CC: Signal un-paused; P1 readiness wiring shipped+live-verified a3af499; P2-P5 executing; P6 mockup awaiting Kisa; OQ1 recorded for confirmation.)
## Updated: 2026-07-07 (CC: Signal un-paused; P1 readiness wiring shipped+live-verified a3af499; P2-P5 executing; P6 mockup awaiting Kisa; OQ1 recorded for confirmation; attorney legal bundle prepared and ready to send.)

View file

@ -0,0 +1,224 @@
# BUSINESS ASSOCIATE AGREEMENT (Template v1)
> **DRAFT, for attorney review before use. Not legal advice.**
> Prepared 2026-07-07. Generalized from the a prior supplier-specific BAA into a reusable STTIL Solutions template. This is a FORWARD-LOOKING instrument. See "Status and posture" immediately below before reading the operative terms.
---
## STATUS AND POSTURE (read first, attorney)
This BAA template is prepared as a forward-looking instrument, not a description of the current live environment. As of 2026-07-07:
- Real PHI is BLOCKED. The Product operates on mock and de-identified data today; no real protected health information is in active exposure (Signal current-state.md, 2026-07-07).
- The current pilot stack (Supabase, Railway, Vercel, Clerk) does NOT have executed subprocessor BAAs in place. The subprocessor table in Section 2.5 describes the pilot stack, not a BAA-covered chain.
- AWS is the compliant migration path. An AWS BAA was signed and became active 2026-05-27; RDS and S3 are provisioned but parked, not in active build until post-funding. If and when a Covered Entity relationship requires real PHI, the Product migrates to the AWS (or equivalent BAA-capable) environment before any PHI is processed, and the subprocessor table is updated accordingly.
Counsel should review this template as the instrument STTIL would execute at the point real PHI enters the system, and advise on the threshold question in Attorney Review Note 1 (whether a BAA is required at all given the crosswalk-stays-with-supplier architecture).
---
**Effective Date:** __________ , 20__
**Between:**
- **KJF Professional Services LLC d/b/a STTIL Solutions** ("Business Associate"), a [STATE, confirm formation state with counsel] limited liability company, Kisa Fenn, Managing Member
- **[COVERED ENTITY FULL LEGAL NAME]** ("Covered Entity"), [SIGNER NAME], [SIGNER TITLE]
Each a "Party" and together the "Parties."
---
## Recitals
Covered Entity is [a durable medical equipment supplier / a healthcare provider / other] subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"). Business Associate provides a documentation readiness platform (the "Service"), described in the Pilot Letter of Intent between the Parties (the "LOI") and its Exhibit A. In connection with the Service, Business Associate may receive, create, maintain, or transmit data on behalf of Covered Entity that may constitute Protected Health Information ("PHI") as defined under HIPAA. The Parties enter into this Agreement to satisfy the Business Associate Agreement requirements of 45 C.F.R. Part 164, Subpart C.
---
## 1. Definitions
Terms used in this Agreement have the meanings assigned under HIPAA and its implementing regulations, including the HITECH Act amendments, as of the Effective Date.
**"Protected Health Information" or "PHI"** means individually identifiable health information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity, in any form or medium.
**"Minimum Necessary"** means the least amount of PHI required to accomplish the intended purpose of a given use, disclosure, or request.
**"Security Incident"** means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations in an information system.
---
## 2. Obligations of Business Associate
### 2.1 Permitted Uses and Disclosures
Business Associate may use or disclose PHI only:
(a) To perform the Service described in the LOI and its Exhibit A, specifically: receiving order-management data uploaded by Covered Entity limited to the minimum-necessary fields specified in the LOI, calculating documentation readiness status per record, and returning a prioritized worklist to Covered Entity staff;
(b) As required by law; or
(c) For the proper management and administration of Business Associate's own operations, provided that any such disclosure is required by law or Business Associate obtains reasonable assurances that the information will be held in confidence and used or further disclosed only as required by law or for the purpose for which it was disclosed.
Business Associate will not use or disclose PHI in any manner that would violate HIPAA if done by Covered Entity directly.
### 2.2 Minimum Necessary
Business Associate will make reasonable efforts to use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose.
### 2.3 Safeguards
Business Associate will implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI it creates, receives, maintains, or transmits on behalf of Covered Entity, in accordance with 45 C.F.R. Part 164, Subpart C (Security Rule).
Business Associate's safeguards include:
- HTTPS enforced on all data transmission surfaces
- SHA-256 hashing of patient_id before storage in any log or database record
- Row Level Security restricting data access by organization
- JWT authentication required on all API endpoints
- No storage of patient names, dates of birth, Social Security numbers, addresses, or contact information at any time
- The patient identity crosswalk (supplier's internal patient_id to real patient identity) is maintained solely by Covered Entity staff and is never transmitted to or stored by Business Associate
*Attorney note: this safeguards list reflects the current pilot architecture. When the Service migrates to a BAA-capable host for real PHI (see Status and posture), this list is updated to reflect the production environment, including encryption at rest.*
### 2.4 Reporting
Business Associate will report to Covered Entity, without unreasonable delay and in no event later than 30 calendar days of discovery:
(a) Any use or disclosure of PHI not permitted by this Agreement of which Business Associate becomes aware;
(b) Any Security Incident of which Business Associate becomes aware, including breaches of Unsecured PHI as required by 45 C.F.R. Part 164, Subpart D;
(c) Any attempted but unsuccessful Security Incident of which Business Associate becomes aware, to the extent practicable.
Reports will be made to Covered Entity's designated contact in writing.
### 2.5 Subcontractors
Business Associate will ensure that any subcontractor or agent to which it provides PHI on behalf of Covered Entity agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement, before any PHI is provided to that subcontractor.
Business Associate's current subprocessors are:
| Subprocessor | Purpose | Data Touched |
|---|---|---|
| Supabase | PostgreSQL database hosting | Hashed patient_id, device_type, shipment_date, payer, doc status fields |
| Railway | Backend API hosting | Processes upload requests in transit; does not persist PHI |
| Vercel | Frontend hosting | No PHI; serves static application only |
| Clerk | Staff authentication | No PHI; stores staff identity only |
*Attorney note: none of the subprocessors listed above currently has an executed subprocessor BAA. Real PHI is blocked today (see Status and posture). Before any real PHI is processed, Business Associate will either (a) obtain an executed BAA from each subprocessor that will touch PHI, or (b) migrate the PHI-touching functions to a BAA-capable environment (an AWS BAA is signed and active as of 2026-05-27; AWS RDS and S3 are provisioned and parked). This table is updated to reflect the production chain at that point.*
Business Associate will notify Covered Entity of any material change to subprocessors that will touch PHI, and will obtain Covered Entity's written approval before adding any new subprocessor that will receive or process PHI.
### 2.6 Access to PHI
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make such PHI available to Covered Entity as necessary to fulfill Covered Entity's obligations under 45 C.F.R. Section 164.524 within 15 business days of a written request.
### 2.7 Amendment
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make such PHI available for amendment and will incorporate any amendments requested by Covered Entity as required by 45 C.F.R. Section 164.526.
### 2.8 Accounting of Disclosures
Business Associate will maintain a record of disclosures of PHI and will make such information available to Covered Entity as necessary to respond to a request for an accounting of disclosures under 45 C.F.R. Section 164.528.
### 2.9 Government Access
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
---
## 3. Obligations of Covered Entity
Covered Entity agrees to:
(a) Notify Business Associate of any limitation in Covered Entity's Notice of Privacy Practices that would affect Business Associate's permitted uses or disclosures;
(b) Notify Business Associate of any changes in, or revocations of, authorization by individuals that would affect Business Associate's permitted uses or disclosures;
(c) Not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity directly;
(d) Ensure that any data uploaded to the Service is limited to the minimum-necessary fields specified in the LOI: an internal patient identifier (patient_id), device type, shipment date, quantity, and payer name, plus any optional documentation-status fields the Parties agree to. Covered Entity will not upload patient names, Social Security numbers, dates of birth, addresses, or direct contact information to the Service at any time.
---
## 4. Term and Termination
### 4.1 Term
This Agreement is effective as of the Effective Date and continues until the later of: (a) the termination of the LOI or any subsequent formal agreement between the Parties; or (b) the date on which Business Associate has completed its data return and destruction obligations under Section 4.3.
### 4.2 Termination for Cause
Either Party may terminate this Agreement immediately upon written notice to the other Party if the other Party has materially breached a provision of this Agreement and has not cured the breach within 10 business days of written notice identifying the breach.
### 4.3 Return or Destruction of PHI
Upon termination of this Agreement for any reason:
(a) Business Associate will return to Covered Entity or destroy all PHI received from or created on behalf of Covered Entity, including PHI in the possession of subcontractors, within 10 business days of the effective termination date;
(b) Business Associate will certify in writing to Covered Entity that all such PHI has been returned or destroyed;
(c) If return or destruction is not feasible, Business Associate will extend the protections of this Agreement to such PHI and limit further use or disclosure to the purposes that make return or destruction infeasible, for as long as Business Associate maintains the PHI.
---
## 5. Miscellaneous
### 5.1 Regulatory References
Any reference in this Agreement to a section of HIPAA includes the most recent amendment or regulatory guidance applicable to that section.
### 5.2 Interpretation
This Agreement is intended to comply with HIPAA as amended. Where this Agreement conflicts with HIPAA, HIPAA controls. Where this Agreement is silent, HIPAA controls.
### 5.3 No Third-Party Beneficiaries
Nothing in this Agreement confers any right, remedy, or claim upon any third party, including any patient whose PHI is involved.
### 5.4 Governing Law
This Agreement is governed by the laws of the State of [STATE, confirm formation state with counsel], without regard to conflict of law principles.
### 5.5 Entire Agreement
This Agreement, together with the LOI and the mutual NDA between the Parties, constitutes the entire agreement with respect to PHI and supersedes all prior understandings on the subject.
---
## Signatures
**KJF Professional Services LLC d/b/a STTIL Solutions (Business Associate)**
By: ___________________________
Name: Kisa Fenn
Title: Managing Member
Date: _________________________
Email: [KISA EMAIL]
**[COVERED ENTITY FULL LEGAL NAME] (Covered Entity)**
By: ___________________________
Name: [SIGNER NAME]
Title: [SIGNER TITLE]
Date: _________________________
Email: ___________________________
---
## Attorney Review Notes
Each load-bearing factual claim is labeled GROUNDED (cited source) or GRAFTED (assumption for counsel to confirm). Items to confirm before this Agreement is executed with any Covered Entity:
1. **LOAD-BEARING: Is a BAA required at all? (GRAFTED as applied.)** Confirm whether Business Associate's receipt of Covered Entity's internal patient_id (a supplier account number, one of HIPAA's 18 identifiers) makes STTIL a Business Associate requiring this Agreement, or whether the Service's de-identification architecture (no names, no DOBs, no SSNs; the crosswalk stays with Covered Entity) satisfies the Safe Harbor or Expert Determination de-identification standards such that no BAA is triggered. GROUNDED that patient_id is an account number and the sole crosswalk key, and that names/DOBs/SSNs are refused at the normalizer (Signal CLAUDE.md, PHI Architecture; data-handling.md). Whether that architecture avoids Business Associate status is GRAFTED and is the single most important question in this bundle.
2. **Subprocessor agreements (GROUNDED posture, GRAFTED requirement).** GROUNDED that the current pilot stack (Supabase, Railway, Vercel, Clerk) has no executed subprocessor BAAs and that an AWS BAA is signed and active as of 2026-05-27 (Signal current-state.md; KG Signal). Confirm which of the subprocessors, in the production PHI configuration, legally requires its own BAA, and confirm the AWS migration path satisfies the subcontractor obligation in 45 C.F.R. 164.308(b) and 164.314.
3. **Accounting of disclosures scope (GRAFTED as applied).** Confirm the scope of Section 2.8 as applied to a software service that processes de-identified or minimum-necessary data only.
4. **State-specific requirements (GRAFTED).** Confirm which state's health-data statutes (beyond HIPAA) apply once formation state and Covered Entity location are known. A prior supplier-specific version governed under Pennsylvania; this template uses a placeholder. Confirm no additional state-law obligations attach.
5. **Governing law and entity alignment (GROUNDED that documents disagree).** The v1 LOI and NDA said Delaware; the a prior supplier BAA said Pennsylvania; an executed letter of intent states Florida. Entity name is now "KJF Professional Services LLC d/b/a STTIL Solutions." Confirm the correct legal name and formation state and align Section 5.4 with the LOI and NDA.
6. **Forward-looking status (GROUNDED).** Real PHI is blocked/mock today (Signal current-state.md, 2026-07-07). Confirm this template is the correct instrument to execute at the point real PHI enters the system, and advise whether any interim data-handling addendum is needed for a pilot that stays inside the de-identified minimum-necessary field set before that point.
---
*Document prepared for attorney review. Not legal advice.*
*Related: STTIL-pilot-LOI-template-v3, STTIL-NDA-template-v3*

View file

@ -0,0 +1,109 @@
> **DRAFT, for attorney review before use. Not legal advice.**
> Cover memo prepared 2026-07-07. Bundles five items for a single review pass.
**To:** [ATTORNEY NAME, CONFIRM RECIPIENT before sending. Session records dated 2026-06-05 name Clyde Mathes as attorney of record; the Signal compliance checklist rows name Bittinger Law / Nixon Law Group. These conflict. Reconcile before this memo goes out.]
**From:** Kisa Fenn, Founder and CEO, KJF Professional Services LLC d/b/a STTIL Solutions
**Date:** [DATE]
**Re:** Single-pass review of three template agreements plus two focused legal questions
---
Hello [ATTORNEY NAME],
I would like to engage you for one bundled review pass covering five items. I have grouped them deliberately so you can scope the whole thing at once rather than in pieces. An associate handling the bulk of this is completely fine with me. What I need first is a turnaround estimate and a fee estimate so I can plan around it.
Here is what is in the bundle:
1. **Pilot Letter of Intent (LOI) template (v3)**, a product-agnostic pilot LOI. Product specifics live in an Exhibit A, pre-filled for our active product, Signal.
2. **Mutual Non-Disclosure Agreement (NDA) template (v3)**, portfolio-wide.
3. **Business Associate Agreement (BAA) template (v1)**, a reusable BAA, generalized from an earlier supplier-specific draft. Please read it as a forward-looking instrument; I explain why below.
4. **U.S. Food and Drug Administration (FDA) device-status memo for Signal**, a draft I am providing for your review, not asking you to write. It argues that Signal is not an FDA-regulated medical device. It is candid about its weakest points. I need you to confirm, correct, or reject its position.
5. **Anti-Kickback Statute question** on a specific partner integration, described below. This one is time-sensitive because it gates whether we can deepen an existing partner relationship.
I have written my own focused questions under each item. Please treat these as a starting list, not a limit.
---
### Overarching question (applies to all three templates)
**Q1. Confirm our legal name, our state of formation, and align governing law across every document.** Our entity is KJF Professional Services LLC d/b/a STTIL Solutions. Our documents currently disagree on the state: two older templates say Delaware, an executed letter of intent says Florida, and an older business associate agreement says Pennsylvania. I have replaced the state with a placeholder everywhere so nothing is asserted incorrectly. Please tell me the correct legal name and formation state, and set governing law and dispute-resolution venue consistently across the LOI, NDA, and BAA.
**Q2. Standardize my signing title.** The LOI and NDA sign as "Founder and CEO" while the BAA signs as "Managing Member." Tell me which title is correct for an LLC signer and I will use it across all three.
---
### 1. Pilot LOI template (v3)
1. The BAA cross-reference in Section 5.3 turns on whether we are a Business Associate at all. That is the BAA question below; please keep the two consistent.
2. Section 8.3 (we retain all rights to any modification or enhancement made during a pilot, regardless of who requested it) and Section 8.4 (a narrow carve-out for a partner's pre-documented pre-existing concepts). Confirm both are enforceable and that 8.4 does not erode 8.3.
3. Section 12.3, a new mutual exclusion of consequential damages for a no-cost pilot. Confirm it is adequate and enforceable.
4. Section 14, a dispute-resolution path (30-day good-faith discussion, then arbitration, with the American Arbitration Association (AAA) as fallback, and a court carve-out for injunctive relief). We added this after an out-of-state counterparty objected to exclusive Delaware court jurisdiction. Tell me whether to keep arbitration here and whether to match it in the NDA, which currently uses courts.
5. Sections 6.1 and 13.3, confirming that a successful pilot does not obligate us to offer a commercial agreement. Confirm this closes any promissory-estoppel exposure.
### 2. Mutual NDA template (v3)
1. The residuals clause (Articles 1.2 and 2.3), which carves our algorithms, payer and coverage logic, and scoring formulas out of what a counterparty may reuse from memory. Confirm the carve-out is enforceable.
2. The Health Insurance Portability and Accountability Act (HIPAA) carve-out (Article 6). I softened the flat claim that the data we handle is never protected health information (PHI). Confirm the new framing is defensible.
3. The tightened third-party exclusion (Article 3.1(d)). Confirm it closes the loophole cleanly and applies equally to both sides.
4. The named-products list (Article 1.1(c)): Signal, Vitality Med Tracker, UMSIS, plus a catch-all for any current or future offering. Confirm the catch-all is sufficient to cover future products we have not named.
### 3. BAA template (v1)
1. **The single most important question in this whole bundle:** does our receipt of a supplier's internal patient_id, which is an account number and one of HIPAA's 18 identifiers, make us a Business Associate that needs this agreement, or does our architecture (we never receive names, dates of birth, or Social Security numbers, and the identity crosswalk stays with the supplier) avoid Business Associate status? Everything downstream depends on your answer.
2. Please read this as forward-looking. Real patient data is blocked today; we run on mock and de-identified data. Our current pilot vendors do not have subprocessor BAAs. Our compliant path is AWS, where we already have a signed BAA (active since 2026-05-27) with database and storage provisioned and parked until funding. I want you reviewing the instrument we would sign at the moment real data enters, and advising whether we need any interim addendum before then.
3. Whether each pilot vendor legally needs its own subprocessor BAA in the production configuration.
### 4. FDA device-status memo for Signal (for your review, not to be drafted)
The memo is at `signal/docs/compliance/fda-cds-exemption-memo-DRAFT.md`. I am not asking you to write it; I am asking you to rule on it. Its own author flagged these as the points to press on:
1. Confirm or correct the primary position: Signal is not a device under section 201(h) because its intended use is administrative and billing support, with the section 520(o)(1)(A) administrative-support exclusion as reinforcement.
2. Rule on whether a DMEPOS supplier can rely on 520(o)(1)(A) as a "health care facility," or whether the position must rest on the 201(h) intended-use analysis alone.
3. Review our live worklist status labels, reason strings, and "recommended action" strings verbatim, and tell us if any wording reads as clinical rather than documentation-focused.
4. Approve a short list of permitted marketing claim framings so our intended use stays administrative.
5. Confirm the memo's citations against FDA's Clinical Decision Support (CDS) guidance current at the time of your review (it was verified against the January 29, 2026 version).
6. Advise whether, once settled, this should be reissued as a counsel letter we can hand to supplier compliance contacts and investors.
### 5. Anti-Kickback Statute question (time-sensitive, privileged, confidential)
**Confidentiality note:** the partner named here is bound to us by a confidentiality clause that bars public mention of the relationship. I am sharing the name with you only because you are our counsel and I need the facts to get sound advice. Please keep it inside privilege.
We have an executed 180-day discovery letter of intent with Pathogens Artificial Intelligence Inc., which does business as LabABLE, a diagnostic-laboratory software platform run by Dr. Mehul Patel's team. During discovery we discussed a reciprocal integration concept, informally called "kit in kit": LabABLE could be made available as a component inside our Signal platform, and Signal could be made available as a component inside the LabABLE platform.
Both of our customer bases serve providers who bill federal healthcare programs (our suppliers bill Medicare for DMEPOS; laboratories bill Medicare Part B). My question:
1. Does this reciprocal embedding or cross-availability arrangement, where each party's product carries value into the other's platform and could influence orders or referrals of federally reimbursable items or services, implicate the federal Anti-Kickback Statute (42 U.S.C. 1320a-7b(b)), the Eliminating Kickbacks in Recovery Act, or the Stark Law?
2. If so, what structure or safe harbor would we need before executing any definitive agreement with this partner?
This must be resolved before we execute any further agreement with them, so please tell me how heavily it weighs on your timeline.
---
### What I need back
- A turnaround estimate and a fee estimate for the full bundle.
- Your answers, or corrections, to the questions above.
- A flag on anything I have framed wrong or missed.
Thank you. I am happy to get on a call to walk through any of it.
Kisa Fenn
KJF Professional Services LLC d/b/a STTIL Solutions
[KISA EMAIL] / [PHONE]
---
## ATTORNEY REVIEW NOTES (for internal use, do not send)
Load-bearing facts in this memo, labeled GROUNDED (cited source) or GRAFTED (assumption to confirm):
- Recipient is unresolved. GROUNDED that 2026-06-05 records name Clyde Mathes and the Signal compliance checklist names Bittinger/Nixon; the two conflict (Signal CLAUDE.md; FDA memo routing note). Confirm before sending. GRAFTED which is correct.
- labABLE LOI executed 2026-06-12, 180-day discovery term. GROUNDED (KG Signal; executed PDF `signal/pitch/legal/labABLE-LOI-v3-EXECUTED-2026-06-12.pdf`). Verify signer names and clause numbers against the executed PDF before any citation; the "kit-in-kit" description here is from the 2026-06-06 markup, not the final executed text.
- labABLE legal entity is Pathogens Artificial Intelligence Inc. d/b/a LabABLE. GROUNDED (labABLE LOI markup 2026-06-06).
- AWS BAA signed and active 2026-05-27, RDS and S3 provisioned and parked. GROUNDED (KG Signal; Signal current-state.md).
- Real PHI blocked/mock today. GROUNDED (Signal current-state.md 2026-07-07).
- FDA memo location and its own self-identified weak points. GROUNDED (`fda-cds-exemption-memo-DRAFT.md`).
- The AKS/EKRA/Stark characterization is a lay framing of the question, not a legal conclusion. GRAFTED, for counsel to analyze.
---
*Prepared for attorney review. Not legal advice.*