<!-- Markdown mirror of https://maxpowerlabs.ai/trust.html — generated 2026-07-26 -->
<!-- Canonical HTML: https://maxpowerlabs.ai/trust.html -->
<!-- MaxPower Labs, LLC · HIPAA-aware workflow systems for medical and behavioral health practices · Ventura, California -->

The part most vendors leave to the contract

# Trust & Security
You are considering letting an outside firm work inside a system that holds patient information. These are the answers your attorney is going to ask for, written down in advance.

**MaxPower Labs signs a Business Associate Agreement before work begins**, on the client’s form or its own, and requires any subcontractor to sign one too. Client data, including backups, stays inside the client’s own BAA-covered Microsoft 365 tenant — MaxPower Labs does not host protected health information. The client owns the deployment, source code, data, workflows and configuration, transferring on final payment.

---

[The first question]

## Yes, we sign a BAA

MaxPower Labs signs a Business Associate Agreement before any engagement in which we could encounter
protected health information — and we sign it **before work begins**, not after a
problem surfaces.

- Your form or ours, whichever your counsel prefers.

- Every subcontractor signs one too, and we disclose that we use subcontractors up front.

- Signed before kickoff, not bolted on at go-live.

Most vendor pages mention BAAs only to explain that *Microsoft* has one. That is a
different question from whether the firm standing inside your tenant will sign one.

### Our security commitments

- **Data residency** — everything, including backups, stays inside your BAA-covered
Microsoft 365 tenant.

- **Encryption** — at rest and in transit, using the Microsoft 365 platform’s
own controls rather than a layer we invented.

- **Least privilege** — access scoped to the specific task, time-limited, and
revoked at project close.

- **Multi-factor authentication** — required for every account with access to your
environment, ours included.

- **Dummy data during build** — development and testing run against synthetic
records, never live patient data.

- **Access review** — documented at each milestone, with a written list of who
holds what.

- **Breach notification** — contractual commitment to notify you without
unreasonable delay, with the timeline written into the BAA.

- **Insurance** — tell us what your counsel requires and we will confirm our
current coverage in writing before you sign.

---

Ownership

## You own what you paid for

This is not a licence you rent from us. When the final payment clears, the work is yours.

### What transfers to you

- The deployment itself, running in your tenant

- The source code

- Your data, workflows and configuration

- Full administrative control

- The right to modify it, or to hire an entirely different developer tomorrow

### What we keep — stated plainly

We retain our pre-existing, general-purpose components, tools and methods. We call these
**Background Tools**, and you get a perpetual, royalty-free licence to keep using them as
embedded in your system.

We will not resell or reuse *your* platform, workflows or configuration
for anyone else. This carve-out appears in the body of every contract in language your attorney can read,
not buried in an appendix — because a client with counsel will find it anyway, and finding it late
is what ends engagements.

---

Why this is urgent right now

## What enforcement actually looks like

The risk to a small practice is not a dramatic breach. It is a routine complaint that turns
into a request for a document you do not have.

21HIPAA settlements resolved by OCR in 2025 — the second-highest annual total on record
Mostof recent enforcement actions cite an inadequate or missing security risk analysis
$225Kpaid by behavioral health provider Deer Oaks in July 2025, in exactly that category

Sources: HHS Office for Civil Rights enforcement announcements
and the OCR risk-analysis enforcement initiative —
[hhs.gov enforcement agreements](https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html).
Figures current as of July 2026; check the source for the latest position.

A risk analysis is not your policies binder and it is not your EHR vendor’s certification. It is a
written, dated assessment of where protected health information actually lives in your practice and what
could go wrong with it — including the intake form your website runs and the board your coordinator
lives in.

Small providers are not exempt from this, and recent actions have included providers of a size comparable to
yours. The documented risk analysis is the first deliverable of our
[$3,000 assessment](https://maxpowerlabs.ai/pricing.html), and you keep it whether or not you build anything with us.

**To be clear about what we are and are not.** We are a workflow systems
firm, not a law firm and not a certification body. We produce the documented analysis, the inventory and the
policy; we do not issue legal opinions, and for anything genuinely contested you should have counsel
involved. Any firm telling you software alone makes you compliant is selling you something.

---

Who you’re working with

## Three people, and you will meet all of them

MaxPower Labs, LLC is its own company, backed by **Max Power Technology**
— the SMB-focused IT shop Jairo has run for more than 17 years. Real engineers and operators,
not a slide deck. There is no account manager layer between you and the people who do the work.

### Paul Tran

Co-Founder & CEO

Leads AI strategy and delivery. Closer to the codebase than the slide deck.
**Runs every workflow review call personally.**

[LinkedIn →](https://linkedin.com/in/paultran)

### Jairo E. Tzunun

Co-Founder & COO

Runs delivery and infrastructure. **17+ years running an SMB IT shop**
— Microsoft 365 tenants, permissions and security are his day job, not a new interest.

[LinkedIn →](https://linkedin.com/in/jairotzunun)

### Jaime Perez

AI Business Development

Leads partnerships. Scopes what AI will actually do, not what it could theoretically
do — which is why the roadmaps we hand you are short.

[LinkedIn →](https://linkedin.com/in/jaimeperez)

Build work is sometimes performed by a subcontractor under a signed BAA, working against dummy data.
We tell you that before you ask. These three remain your point of accountability throughout.

---

## What your attorney will ask

**Q: Will you sign our BAA form instead of yours?**
Yes. If your counsel prefers your paper, we sign yours. We would rather move quickly on your terms than spend three weeks negotiating whose template wins.

**Q: Do you use subcontractors?**
Sometimes, for build work. We tell you this before you ask, name the arrangement in the contract, and require the subcontractor to sign a Business Associate Agreement as well. Subcontractors build against dummy data and receive only scoped, time-limited access to your tenant when the work genuinely requires it. We remain your sole point of accountability and your sole contracting party.

**Q: Where does our data live?**
In your own Microsoft 365 tenant, covered by your BAA with Microsoft, under your administrative control. We do not host your protected health information. There is no MaxPower Labs cloud that your patient data is copied into, and no third-party analytics service watching your clinical workflow.

**Q: What happens if we stop working with you?**
Nothing breaks. The system is in your tenant, you own the source code, and your administrators keep full control. We hand over documentation and, if you want, brief whoever takes over. There is no lock-in mechanism, because a system you cannot leave is a system you were never really sold.

**Q: Are you insured?**
Tell us what your counsel requires and we will confirm our current coverage in writing before you sign anything. We would rather give you a specific answer against your actual requirement than a vague reassurance on a web page.

**Q: Can we speak to a reference?**
Ask us on the call and we will tell you honestly what we can offer at that moment. We are early enough as a firm that we would rather say so than manufacture a reference. What we can always do is walk you through the engagement described on our Proof page in as much detail as you want, including the parts that did not go well. We do not publish client names without written permission, which is the same courtesy we would extend to you.

---

## Bring your hardest question
If there is something on this page your counsel would push back on, raise it on the call. We would rather argue about it now than discover it in legal review.

[Book a Free 30-Minute Workflow Review](https://calendar.google.com/calendar/u/0/appointments/schedules/AcZssZ3LqPtiKILlvoAI3-Q496e-zr30WO1qiVmgMdT7r9X5jVE_2OWxm1tu68fxrZ7aDoCQW0XBYRmU)
30 minutes with Paul Tran, who runs every one of these calls.
Evening slots available — we know your day is patients.
 ·  [paul@maxpowerlabs.ai](mailto:paul@maxpowerlabs.ai)

---
