Business associate agreement

VERSION: 20260921
  1. This Business Associate Agreement (this “Agreement”), is entered into by and between Clinia Health Inc. (“Business Associate”), and the entity identified in the signature block below (“Covered Entity”). For purposes of this Agreement, Covered Entity is either a ‘covered entity’ or a ‘business associate’, as those terms are defined under the HIPAA Rules. Business Associate and Covered Entity are referred to together as the “Parties” and each individually as a “Party.”

  2. Recitals

    A. Business Associate provides certain services to Covered Entity pursuant to Clinia’s General Terms of Service, the Free Tier Services Terms of Service, one or more Order Forms, Product Schedules, Data Processing Addenda, or other services agreements the Parties have entered into, or may in the future enter into (collectively, the “Services Agreements”), which under the HIPAA Rules (see Section 1 for definitions) qualifies Business Associate as a ‘business associate’ to Covered Entity.

    B. To comply with the HIPAA Rules, the Parties are entering into this Agreement to document the terms under which Business Associate may Use and Disclose Protected Health Information it creates on behalf of, or receives from, Covered Entity.

  3. Agreement

    Business Associate and Covered Entity therefore agree as follows:

  4. 1. Definitions

    Capitalized terms that are not defined in this Agreement shall have the meanings set forth in the HIPAA Rules.

    1.1 “Covered Entity Indemnitees” means Covered Entity, the affiliates of Covered Entity authorized to receive services from Business Associate under the Services Agreements, and their respective personnel, officers and directors.

    1.2 “HIPAA Rules” means the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, and its implementing regulations set forth at 45 C.F.R. Parts 160 and 164, which include the Privacy, Security, Breach Notification and Enforcement Rules.

    1.3 “Indemnitees” means the Covered Entity Indemnitees or the Business Associate Indemnitees, as the context requires.

    1.4 “Protected Health Information” or “PHI” has the same meaning as the term “protected health information” in 45 C.F.R. § 160.103, as applied to the information received by Business Associate from, or created by Business Associate on behalf of, Covered Entity.

    1.5 “Business Associate Indemnitees” means Business Associate, and its personnel, officers and directors.

    1.6 “Services Agreements” has the meaning given in Recital A. Where this Agreement conflicts with a Services Agreement with respect to the treatment of PHI, this Agreement controls to the extent of that conflict, as further described in Section 6.4 (Relationship to Other Agreements).

  5. 2. Business Associate’s Use and Disclosure of PHI

    Business Associate shall limit its Use and Disclosure of PHI to the minimum necessary for Business Associate to perform its obligations under the Services Agreements, and such Use and Disclosure shall at all times be in compliance with the HIPAA Rules. Business Associate shall not Use or Disclose PHI except as specifically permitted under this Agreement or as Required by Law. To the extent Business Associate will carry out one or more of Covered Entity’s obligations under Subpart E of 45 C.F.R. Part 164, Privacy of Individually Identifiable Health Information, as expressly set forth in the Services Agreements, Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligations.

    2.1 Uses and Disclosures of PHI. Except as otherwise limited in this Agreement, Business Associate may Use or Disclose PHI to perform functions, activities or services for, or on behalf of, Covered Entity or any affiliate of Covered Entity that is entitled to receive services under the Services Agreements, as specified in the Services Agreements, provided that such Use or Disclosure would not violate the HIPAA Rules if done by Covered Entity or such affiliates.

    2.2 Permitted Uses of PHI. Except as otherwise limited in this Agreement, Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate.

    2.3 Permitted Disclosures of PHI. Except as otherwise limited in this Agreement, Business Associate may Disclose PHI for the proper management and administration of Business Associate, provided that the Disclosures are Required by Law or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and will be Used or further Disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and provided further that the person to whom the information is disclosed agrees to notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached. Business Associate may disclose PHI to report violations of law to appropriate federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1).

    2.4 Marketing and Sale of PHI. Business Associate shall not Use or Disclose PHI for marketing purposes, unless expressly directed by Covered Entity, and in accordance with § 13406(a) of the HITECH Act and 45 C.F.R. § 164.508(a)(3). Business Associate shall comply with the prohibition on the sale of PHI in accordance with § 13405(d) of the HITECH Act and 45 C.F.R. § 164.502(a)(5)(ii).

    2.5 Data Aggregation and De-identified Data. Business Associate may Use PHI to create De-identified Data in accordance with 45 C.F.R. § 164.514(b), using either the Safe Harbor method or Expert Determination. Once PHI has been de-identified in accordance with HIPAA, it is no longer PHI for purposes of this Agreement and may be used as permitted under Sections 9.3 and 12.3 of Clinia’s General Terms of Service. Business Associate will not provide Data Aggregation services within the meaning of 45 C.F.R. § 164.504(e)(2)(i)(B) unless those services are expressly stated in the applicable Services Agreement.

    2.6 Minimum Necessary. When Using, Disclosing, or requesting PHI, Business Associate shall make reasonable efforts to limit the PHI Used, Disclosed, or requested to the minimum necessary to accomplish the intended purpose of the Use, Disclosure, or request, as required by 45 C.F.R. § 164.502(b).

  6. 3. Business Associate’s Responsibilities

    3.1 HIPAA Safeguards. Business Associate will maintain reasonable and appropriate safeguards designed to prevent unauthorized Use or Disclosure of PHI, including safeguards to protect the confidentiality, integrity, and availability of PHI in electronic format as required by the Security Rule. Business Associate will comply with the provisions of Subpart C of 45 C.F.R. Part 164, Security Standards for the Protection of Electronic Protected Health Information, relating to implementation of administrative, physical and technical safeguards with respect to Electronic PHI in the same manner that such provisions apply to Covered Entity.

    3.2 Location of PHI. Business Associate will store and Process PHI on servers located within the United States or Canada (“North America”), using infrastructure that satisfies the safeguards required under Section 3.1 (HIPAA Safeguards) regardless of which North American jurisdiction hosts the data. If a Covered Entity’s applicable Order Form or Product Schedule specifies that PHI must be stored exclusively within the United States, Business Associate will comply with that requirement with respect to such Covered Entity’s PHI.

    3.3 Reporting of Improper Use or Disclosure, Breach or Security Incident. Business Associate will notify Covered Entity in writing within thirty (30) days after Discovery of a Use or Disclosure of PHI that is not permitted or required under this Agreement, any Security Incident, or a Breach of Unsecured PHI. Such notice shall include the identification of each Individual whose PHI has been, or is reasonably believed by Business Associate to have been, accessed, acquired, or disclosed during such Breach. Business Associate will cooperate with Covered Entity in investigating the Breach so that Covered Entity may meet its obligations under the HIPAA Rules and any other applicable breach notification law. Business Associate agrees to mitigate, to the extent reasonably practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI by Business Associate in violation of this Agreement. This Agreement serves as notice, and no further reporting shall be required, of unsuccessful attempts at unauthorized access, Use, Disclosure, modification, or destruction of information, or interference with system operations in an information system, such as “scans” or “pings” on a firewall. Notice under this Section 3.3 may be provided by email to the contact designated by Covered Entity in the applicable Services Agreement or, if none is designated, to Covered Entity’s signatory below, and shall be effective upon transmission.

    3.4 Subcontractors. In accordance with 45 C.F.R. § 164.502(e)(1)(ii) and § 164.308(b)(2), Business Associate will require its subcontractors and agents that receive, Use, or have access to PHI to agree to restrictions and conditions no less stringent than those that apply to Business Associate under this Agreement.

    3.5 Access to PHI. Within thirty (30) days after receiving a written request from Covered Entity, Business Associate will make PHI in a Designated Record Set available to Covered Entity in accordance with 45 C.F.R. § 164.524.

    3.6 Amendment to PHI. Within thirty (30) days after receiving a written request from Covered Entity, Business Associate will make PHI in a Designated Record Set available to Covered Entity for amendment, or to incorporate amendments into the PHI, in accordance with 45 C.F.R. § 164.526.

    3.7 Accounting for Disclosures. Within thirty (30) days after receiving a written request, Business Associate will provide to Covered Entity information necessary for Covered Entity to respond to a request for an accounting of disclosures in accordance with 45 C.F.R. § 164.528. If it will take longer than fifteen (15) days to compile the information, Business Associate shall inform Covered Entity of the delay and the reason for the delay.

    3.8 Other Individual Rights. Within thirty (30) days after receiving a written request from Covered Entity, Business Associate will assist Covered Entity in complying with its obligations under 45 C.F.R. § 164.522 to restrict the Use and Disclosure of PHI and offer confidential communications.

    3.9 Governmental Access to Records. Business Associate will make available its internal practices, books, and records relating to the Use and Disclosure of PHI to the Secretary for purposes of determining compliance with the HIPAA Rules.

    3.10 PHI Data Formatting. Covered Entity and Business Associate agree that formats and requirements of any Designated Record Set, report, or similar deliverable containing PHI shall be consistent with a file format approved by both Covered Entity and Business Associate in advance.

    3.11 Substance Use Disorder Records. Business Associate shall comply with the Confidentiality of Substance Use Disorder (SUD) Patient Record Regulations under 42 C.F.R. Part 2, in alignment with HIPAA, as applicable to Business Associate’s Use or Disclosure of such records, in accordance with the applicable compliance dates set by 42 C.F.R. Part 2 and any related guidance issued by HHS.

  7. 4. Obligations of Covered Entity

    4.1 Notice of Changes. Covered Entity shall notify Business Associate of any of the following changes that may affect Business Associate: (a) changes to Covered Entity’s Notice of Privacy Practices; (b) new or changed authorizations; or (c) new or changed restrictions on the Use or Disclosure of PHI as agreed to by Covered Entity. Business Associate shall implement the changes within fifteen (15) days after receiving notice.

    4.2 Permissible Requests by Covered Entity. Covered Entity shall not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity. Covered Entity shall obtain any and all necessary rights and permissions from the Individual to Disclose the information contemplated in this Agreement and the Services Agreements to Business Associate.

    4.3 Compliance with the HIPAA Rules. In performing its obligations and exercising its rights under the Services Agreements and this Agreement, Covered Entity shall remain in compliance with its legal obligations under the HIPAA Rules and its contractual obligations related to the HIPAA Rules.

  8. 5. Term and Termination

    5.1 Term. This Agreement is effective as of the Effective Date of the applicable Services Agreement between the Parties or, if none exists, the date of the last signature below (the “Effective Date”), and remains in effect until it terminates or expires in accordance with this Section 5.

    5.2 Expiration. This Agreement shall expire automatically when all of the PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity. If it is infeasible to return or destroy PHI, protections are extended to such information in accordance with Section 5.4 (Effect of Termination).

    5.3 Termination for Material Default. If either Party is in material default in the performance of its duties or obligations under this Agreement, the other Party may notify the defaulting Party of the default, and the notice shall describe the default in reasonable detail. The Party receiving a default notice shall attempt to cure the default during a cure period reasonably specified by the non-defaulting Party. If no cure is possible, or if the default is not substantially cured during the applicable cure period, the non-defaulting Party may terminate this Agreement for cause by notifying the defaulting Party of the effective date of termination. If neither termination nor cure is possible, the non-defaulting Party may notify the Secretary and will provide a copy of the notice to the defaulting Party.

    5.4 Effect of Termination. If this Agreement is terminated or expires for any reason, Business Associate will return to Covered Entity or destroy, within ninety (90) days after the effective date of termination, all PHI in its possession. Business Associate may retain copies of PHI for purposes of compliance, and as otherwise required by applicable law. Any PHI destroyed by Business Associate in accordance with this Agreement shall, to the extent practicable, comply with guidance for the destruction of PHI issued by the Secretary from time to time. If return or destruction is infeasible, Business Associate shall notify Covered Entity and extend all protections contained in this Agreement to Business Associate’s Use or Disclosure of any retained PHI, and shall limit any further Uses or Disclosures to those purposes that make the return or destruction of the PHI infeasible.

    5.5 Survival. Any provisions of this Agreement that require or contemplate performance or application after termination are enforceable against the other Party and its respective successors and assignees notwithstanding termination, including Section 6.2 (Indemnification) and Section 6.3 (Limitation of Liability). Any termination of this Agreement shall be without prejudice to the terminating Party’s legal rights and remedies as provided under this Agreement, including injunction and other equitable remedies, subject to the limitations and exclusions set forth in this Agreement.

  9. 6. Miscellaneous

    6.1 Injunctive Relief. The Parties acknowledge that monetary damages may not be a sufficient remedy for certain defaults under this Agreement, including unauthorized Use or Disclosure of PHI. Notwithstanding anything to the contrary in this Agreement or in any dispute resolution provisions incorporated into this Agreement as provided in Section 6.9 (Dispute Resolution), either Party may at any time, without waiving any rights or remedies under this Agreement, seek from any court having jurisdiction any interim or provisional relief necessary to protect the rights or property of that Party pending resolution of the dispute, including injunctive relief and specific performance.

    6.2 Indemnification. The indemnification obligations in this Section 6.2 are subject to Section 6.2.1 through Section 6.2.7 below, and to the Limitation of Liability set forth in Section 6.3.

    6.2.1 Indemnification by Business Associate. If an unaffiliated third party brings a claim against one or more Covered Entity Indemnitees as a result of any act or omission of Business Associate, Business Associate’s subcontractor, or any of their respective personnel in the Use or Disclosure of PHI that violated this Agreement, then Business Associate shall defend the claim and pay all defense costs, any settlement amount negotiated by Business Associate, and all damages awarded by a court, or government agency with appropriate authority, after all appeals have concluded.

    6.2.2 Indemnification by Covered Entity. If an unaffiliated third party brings a claim against one or more Business Associate Indemnitees as a result of any act or omission of Covered Entity, any affiliate of Covered Entity receiving services from Business Associate under the Services Agreements, or any of their respective personnel in the Use or Disclosure of PHI that violated this Agreement, then Covered Entity shall defend the claim and pay all defense costs, any settlement amount negotiated by Covered Entity, and all damages awarded by a court, or government agency with appropriate authority, after all appeals have concluded.

    6.2.3 Notice. Each Party’s defense and indemnity obligations are conditioned on the Indemnitees (i) promptly notifying the indemnifying Party of any claim subject to or potentially subject to an indemnification obligation; (ii) cooperating with the indemnifying Party in the defense of the claim; and (iii) granting the indemnifying Party sole control of the defense and settlement of the claim.

    6.2.4 Monitoring. Indemnitees may monitor the defense undertaken by the indemnifying Party, at the Indemnitees’ expense and with counsel of its choosing.

    6.2.5 Conditions on Settlements. Unless it has the consent of the affected Indemnitees, the indemnifying Party shall not enter into any settlement of a claim that (i) does not include a full release of the affected Indemnitees; (ii) contains any admission of liability or fault by any Indemnitee; or (iii) involves a remedy other than the payment of money or the performance of obligations by the indemnifying Party.

    6.2.6 Failure to Assume Control. If the Party with an indemnification obligation does not assume control over the defense of an indemnifiable claim as required in this Section 6.2, then the Indemnitees may defend or settle the claim in a reasonable manner at the expense of the Party with the indemnification obligation.

    6.2.7 Contribution. If any claim entitles each Party to indemnification from the other, the Parties shall allocate between themselves the damages finally awarded to the third party making the claim, or the amount reasonably paid in settlement of the claim, according to each Party’s relative share of liability.

    6.3 Limitation of Liability. Except for liability arising from a Party’s (or its personnel’s or Subcontractor’s) gross negligence, willful misconduct, or knowing and intentional violation of the HIPAA Rules, each Party’s aggregate liability to the other Party and its Indemnitees arising out of or relating to this Agreement, whether arising under Section 6.2 (Indemnification) or otherwise, and whether in contract, tort, or under any other theory of liability, shall not exceed the limitation(s) of liability, if any, set forth in the applicable Services Agreement(s). Where a Services Agreement contains no limitation of liability applicable to a claim under this Agreement, this Section 6.3 shall not be construed to impose one. Neither Party shall be liable to the other for any indirect, incidental, consequential, special, exemplary, or punitive damages, except to the extent such damages are included in a third-party claim for which a Party owes indemnification under Section 6.2.

    6.4 Relationship to Other Agreements. This Agreement supplements, and is incorporated into, the Services Agreements. Where Business Associate processes Personal Information that is not PHI, that processing is governed by the Data Processing Addendum between the Parties, where applicable. Where Business Associate processes PHI, this Agreement governs, and in the event of a conflict between this Agreement and the Data Processing Addendum or any other Services Agreement with respect to the treatment of PHI, this Agreement controls to the extent of that conflict.

    6.5 Changes in Laws. If the HIPAA Rules embodied in the terms of this Agreement are amended in a manner that changes the obligations of business associates or covered entities, the Parties shall negotiate in good faith an appropriate amendment to this Agreement to give effect to such revised obligations. To the extent permitted by applicable law, upon the compliance date of any final regulation, or amendment to a final regulation, promulgated by HHS that affects Business Associate’s or Covered Entity’s obligations under this Agreement, this Agreement will automatically amend such that the obligations imposed on Business Associate or Covered Entity remain in compliance with the final regulation or amendment.

    6.6 Interpretation. The terms of this Agreement shall be construed in light of interpretive guidance available from U.S. federal government agencies with authority over the HIPAA Rules. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the Parties to comply with applicable HIPAA Rules.

    6.7 No Third Party Beneficiaries. There are no intended third-party beneficiaries under this Agreement other than the Covered Entity Indemnitees and Business Associate Indemnitees, who are intended third-party beneficiaries of the indemnification obligations under Section 6.2 (Indemnification).

    6.8 Governing Law. This Agreement is governed by and shall be interpreted in accordance with the laws that govern the applicable Services Agreements.

    6.9 Dispute Resolution. If the applicable Services Agreements contain alternative dispute resolution provisions, then any dispute under this Agreement shall be resolved in accordance with those provisions as if they were included in this Agreement.

    6.10 Notices. Any notice required or permitted to be given under this Agreement, other than notice under Section 3.3 (Reporting of Improper Use or Disclosure, Breach or Security Incident), shall be in writing and delivered (a) by hand; (b) by nationally recognized overnight courier; or (c) by certified or registered U.S. mail, postage prepaid, return receipt requested, in each case addressed to the receiving Party at the address set forth in the applicable Services Agreement or in the signature block below, or such other address as a Party designates by notice given in accordance with this Section 6.10. Notice is deemed given upon receipt.

    6.11 Entire Agreement. This Agreement, together with the Services Agreements, is the entire and only agreement between the Parties regarding its subject matter, and supersedes and fully integrates all prior and contemporaneous discussions, understandings, and agreements between the Parties regarding its subject matter. To the extent of any conflict between the terms of this Agreement and the terms of the Services Agreements, this Agreement shall control with respect to the treatment of PHI, as further described in Section 6.4 (Relationship to Other Agreements). This Agreement binds the Parties and each of their respective successors and permitted assigns. The Services Agreements are separate but related agreements, existing or contemplated, that are not superseded or amended by this Agreement except as expressly stated herein.

  10. To witness their understanding, the Parties have caused this Agreement to be signed by their duly authorized representatives.

    CLINIA HEALTH INC. (“Business Associate”) By: ____________________ Name: ____________________ Title: ____________________ Date: ____________________ Address: ____________________

    [COVERED ENTITY NAME] (“Covered Entity”) By: ____________________ Name: ____________________ Title: ____________________ Date: ____________________ Address: ____________________