Business Associate Agreement
HIPAA Privacy and Security Rules, 45 CFR Parts 160 and 164
- Version 1.0
- Effective date:
- August 10, 2026
- Last updated:
- August 10, 2026
1. Definitions
Capitalized terms not defined here have the meanings given to them in the HIPAA Rules.
"HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended, including by the HITECH Act.
"PHI" means Protected Health Information that Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity.
"Services" means the administrative support services described in the Scope of Services.
2. Permitted Uses and Disclosures
Business Associate may use and disclose PHI only:
- to perform the Services, and only to the extent necessary to perform them;
- for its own proper management and administration or to carry out its legal responsibilities, provided that any such disclosure is Required by Law or is made subject to written assurances of confidentiality, limited use, and notification to Business Associate of any breach of confidentiality;
- to provide data aggregation services relating to the health care operations of Covered Entity, if requested in writing; and
- as Required by Law.
Business Associate shall not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity. The minimum necessary standard applies in accordance with 45 CFR 164.502(b).
Business Associate does not sell PHI and does not use PHI for marketing or fundraising. Business Associate does not disclose PHI to advertising platforms, analytics providers, or tracking technologies, and does not transmit PHI to any generative artificial intelligence service.
3. Safeguards
Business Associate uses appropriate administrative, physical, and technical safeguards, and complies with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided by this Agreement. Specific controls include:
- encrypted credential vault storage;
- individually named accounts, with shared logins prohibited;
- multi-factor authentication where supported by the system;
- private VPN on dedicated IP addresses with geographic access restriction;
- biometric identity verification at session start;
- continuous endpoint monitoring and data loss detection;
- unique strong passwords per system, rotated not less than every thirty days;
- documented HIPAA training before access is granted and refreshed at least annually.
4. Workforce and Location Disclosure
Covered Entity acknowledges that Business Associate's workforce members may be located outside the United States, specifically in Latin America, Europe, and the Philippines. Business Associate applies the safeguards described in Section 3 to all personnel regardless of location and will disclose the location of assigned personnel on request.
Covered Entity is solely responsible for determining whether its payer agreements, government program participation, accreditation obligations, or applicable state law restrict access to patient data by personnel located outside the United States, and for notifying Business Associate in writing of any such restriction before granting access to PHI.
5. Subcontractors
Any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate must agree in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement, in accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2). Business Associate remains liable for the acts and omissions of its subcontractors with respect to PHI.
6. Reporting, Security Incidents, and Breach Notification
Business Associate reports to Covered Entity any use or disclosure of PHI not provided for by this Agreement, any Breach of Unsecured PHI as required by 45 CFR 164.410, and any Security Incident of which it becomes aware.
Notification is made without unreasonable delay and no later than five business days after discovery, with a preliminary notification within twenty-four hours where the incident appears likely to involve Unsecured PHI. Notification includes the nature of the incident, identification of affected individuals, the types of information involved, and mitigation steps taken or planned.
Unsuccessful attempts such as pings, port scans, and blocked login attempts that do not result in unauthorized access, use, or disclosure of PHI do not require individual reporting. Aggregate records of such attempts are available on request.
Business Associate cooperates with any investigation, mitigates to the extent practicable any harmful effect known to it, and preserves relevant records and logs.
7. Individual Rights
Within ten business days of a written request from Covered Entity, Business Associate will:
- make PHI in a Designated Record Set available in accordance with 45 CFR 164.524;
- make any amendment to PHI in a Designated Record Set in accordance with 45 CFR 164.526;
- provide an accounting of disclosures sufficient to allow Covered Entity to meet its obligations under 45 CFR 164.528.
Business Associate forwards to Covered Entity, and does not respond directly to, any request received directly from an Individual regarding access, amendment, accounting, restriction, or confidential communications, unless directed otherwise in writing by Covered Entity.
8. Compliance with Covered Entity Obligations
To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164, Business Associate complies with the requirements of that Subpart that apply to Covered Entity in the performance of that obligation.
9. Availability of Records to the Secretary
Business Associate makes its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules, and promptly notifies Covered Entity of any such request unless prohibited by law from doing so.
10. Term and Termination
This Agreement is effective on the engagement effective date and continues until all PHI is returned or destroyed or the Agreement is otherwise terminated.
Covered Entity may terminate immediately on written notice for a material violation of this Agreement that is not cured within thirty days of notice, or where cure is not possible.
On termination, Business Associate returns or destroys all PHI it still maintains, including PHI held by subcontractors, retains no copies, completes this within thirty days, and certifies completion in writing. Where return or destruction is infeasible, the protections of this Agreement extend to that PHI and further uses and disclosures are limited to those purposes that make return or destruction infeasible.
Credential revocation: on termination, or when a workforce member leaves the account, access is revoked and credentials are removed from the vault. Covered Entity remains responsible for disabling accounts in systems it controls.
11. Miscellaneous
A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended. The parties will amend this Agreement as necessary for compliance with the HIPAA Rules. Any ambiguity is resolved in favor of a meaning that permits compliance with the HIPAA Rules.
In the event of a conflict with any other agreement between the parties, this Agreement controls with respect to PHI. There are no third-party beneficiaries. Sections 6, 7, 9, 10, and 11 survive termination.
A countersigned Business Associate Agreement is executed with each client before any access to Protected Health Information. This posted version reflects our standard terms.