Business Associate Agreement
A proposed UP-to-practice agreement for handling protected health information. This is separate from workforce confidentiality acknowledgments and vendor-specific agreements.
1. Parties, purpose and effective date
This Business Associate Agreement (Agreement) is between the healthcare practice identified in the signature schedule (Practice), acting as a covered entity or business associate as applicable, and the legal entity operating Unique Practice identified in that schedule (UP), acting as Practice's business associate or subcontractor. The Agreement applies when UP creates, receives, maintains or transmits protected health information on Practice's behalf to provide the authorized services.
This draft uses the product name Unique Practice only as a reference; it does not establish UP's legal entity name. The effective date is the date completed by the parties in the signature schedule. No signature, acceptance or effective date is implied by viewing or downloading this draft.
The services include the behavioral-health electronic health record, practice-management and client-portal functions specifically authorized by Practice under a separate service agreement or order. This Agreement does not activate an integration, prescribe a treatment, enroll a payer, process a payment or replace any required practice-to-vendor agreement.
2. Definitions and order of documents
Protected health information (PHI), electronic PHI, breach, unsecured PHI, security incident, designated record set, required by law and Secretary have the meanings assigned under the applicable HIPAA regulations. References to HIPAA include applicable Privacy, Security and Breach Notification Rules in 45 CFR Parts 160 and 164, as amended.
For PHI obligations, this Agreement controls over conflicting service terms, pricing pages, privacy summaries or acceptable-use provisions. Additional protections required by applicable law are not waived. The parties must address any applicable substance-use-disorder confidentiality requirements, psychotherapy-note protections or more protective state requirements before enabling the affected workflow.
3. Permitted uses and disclosures
UP may use and disclose PHI only to perform the authorized services for Practice, as specifically permitted by this Agreement, or as required by law. UP will not use or disclose PHI in a way that would violate the Privacy Rule if Practice performed the same activity, except for a permitted business-associate purpose expressly stated here.
UP may use PHI for its own proper management, administration and legal responsibilities only to the extent necessary and permitted by HIPAA. A disclosure for these purposes must be required by law or made to a recipient who provides reasonable assurances of confidentiality, limits further use and disclosure to the permitted purpose or legal requirement, and agrees to report a breach of that confidentiality to UP.
This Agreement does not authorize selling PHI, marketing with PHI, combining another practice's identifiable records for unrelated use, training a general-purpose model on PHI, or product research unrelated to Practice's authorized services. Data aggregation or de-identification for an additional purpose requires a separate written authorization from Practice and compliance with applicable law.
UP will limit PHI to the minimum necessary for a permitted purpose when that standard applies. UP will implement Practice's lawful restrictions that have been communicated and agreed to in writing and will promptly identify instructions it cannot lawfully or technically fulfill.
4. Safeguards, access and workforce
UP will apply reasonable and appropriate administrative, physical and technical safeguards against unauthorized uses or disclosures of PHI and will comply with the applicable Security Rule requirements for electronic PHI. UP will maintain risk analysis and risk-management practices, appropriate access controls, workforce authorization, confidentiality obligations, security training, auditability, contingency arrangements and incident-response procedures appropriate to the services.
UP will restrict access to authorized personnel and subcontractors with a service-related need, remove access when that need ends, and provide reasonable cooperation with Practice's security inquiries. Any allocation of security responsibilities in the service agreement must remain consistent with this Agreement and applicable law.
5. Incidents, breaches and cooperation
UP will notify Practice of a use or disclosure of PHI not permitted by this Agreement, an applicable security incident, or a breach of unsecured PHI after discovery, without unreasonable delay. For a breach, notice will be provided no later than 60 calendar days after discovery, or sooner if applicable law or the signed service agreement requires. This outside limit is not a waiting period.
The initial notice will include information then available concerning the nature and timing of the event, affected systems and individuals, types of PHI, mitigation, corrective actions and a responsible contact. UP will provide additional relevant information as it becomes available and will preserve appropriate evidence. An investigation does not justify withholding timely notice.
UP will take reasonable steps to contain and mitigate harm from an impermissible use or disclosure of which it becomes aware and will cooperate with Practice in investigating, documenting and resolving the incident. Practice remains responsible for notices to individuals, regulators and other parties unless a lawful written delegation assigns a defined notice obligation to UP. Neither party may make a false statement about an incident on the other's behalf.
The parties may document a separate, specific reporting arrangement for routine unsuccessful security events that do not result in unauthorized access or harm. This draft does not waive incident reporting by treating every attempted attack as already reported.
6. Subcontractors and connected services
Before a subcontractor creates, receives, maintains or transmits PHI on UP's behalf, UP will obtain a written agreement imposing the same applicable PHI restrictions, safeguards and obligations that apply to UP. UP will maintain an accurate inventory of these subcontractors and provide the applicable information to Practice through the agreed notice process.
A practice-selected integration is not automatically a UP subcontractor. The parties will identify the relationship and data flow before activation, verify the required agreements and authorize the necessary data exchange. A BAA with UP does not automatically create a BAA with a telehealth, messaging, clearinghouse or prescribing provider.
UP will not treat a vendor connection, possession of credentials, encrypted storage or an approval-pending status as proof that the necessary agreements are in place. Vendor agreements and service eligibility must be verified for the particular account and service used.
7. Individual rights and Practice obligations
UP will make relevant PHI in a designated record set available to Practice, or to an individual at Practice's lawful direction, to support access under 45 CFR 164.524. UP will support amendments and incorporate amendments directed by Practice under 45 CFR 164.526. UP will retain and make available the information required for an accounting of disclosures under 45 CFR 164.528.
UP will cooperate in sufficient time for Practice to meet applicable legal deadlines, using secure delivery and the response process documented in the service agreement. If UP receives a request directed to Practice, UP will promptly refer it to Practice rather than independently granting access without authority.
To the extent UP performs a Privacy Rule obligation for Practice, UP will comply with the requirements applicable to that obligation. UP will make its relevant internal practices, books and records available to the Secretary for determining HIPAA compliance as required by law.
Practice is responsible for its privacy notices, lawful collection and disclosure instructions, authorizations, client/guardian authority, workforce access decisions and accurate source records. Practice will notify UP of applicable restrictions, changes to permission, and limitations in its privacy practices that affect UP's handling of PHI. Practice will not instruct UP to act unlawfully.
8. Termination, return and destruction
This Agreement remains in effect while UP holds PHI subject to it. Practice may terminate for UP's material violation. If Practice offers a cure opportunity, the parties will document a reasonable period consistent with applicable law; if the violation cannot be cured or is not cured within that period, Practice may terminate the affected services.
At termination, UP will return PHI to Practice through an agreed secure process, or destroy it at Practice's lawful direction, including PHI held by subcontractors, to the extent feasible. UP will retain no copies except as legally required or where return or destruction is infeasible. UP will explain any infeasibility and the affected information to Practice in writing.
For PHI that must remain, UP will continue the protections of this Agreement, limit use and disclosure to the purpose that prevents return or destruction, and return or destroy the PHI when that reason ends. Protected backup copies will remain restricted and follow the agreed documented disposal process. There is no unlimited retention permission.
A payment dispute or account termination does not eliminate HIPAA obligations or justify unlawful withholding of PHI. Operational export timing, formats and costs belong in a separate service or data-exit schedule consistent with this Agreement. PHI protections and incident cooperation survive termination for as long as required.
9. Administration and amendments
The parties will maintain current notice contacts and a secure incident-reporting route. Required legal notices must not be sent solely to an unverified support address. Each party will notify the other of changes to its authorized contact.
The parties will amend this Agreement when necessary to comply with applicable law. Ambiguities will be interpreted to permit HIPAA compliance. Neither the website nor a unilateral product change reduces an executed PHI protection. Commercial allocation of costs, liability, indemnity, dispute resolution and governing law must be reviewed in the separate service agreement; nothing in those provisions may negate this Agreement's required protections.
Signature schedule - complete before execution
Practice legal name: ______________________________________________
Practice role (covered entity or upstream business associate): __________________
Practice address and notice contact: ______________________________________
Practice privacy/security contact and secure notice route: ______________________
UP operating legal entity name: __________________________________________
UP address and notice contact: __________________________________________
UP privacy/security contact and secure notice route: __________________________
Related service agreement/order identifier: _________________________________
Agreed effective date: __________________________________________________
Practice authorized signer / title: _________________________________________
Practice signature / date: _______________________________________________
UP authorized signer / title: _____________________________________________
UP signature / date: ____________________________________________________