Business Associate Agreement
Version 1· Executed electronically in-app by each customer facility's owner (Settings → Legal). Questions: see our security page.
1. Parties; Relationship; Definitions
This Business Associate Agreement ("BAA") is between the customer organization identified in the CareCommand account ("Covered Entity," which for purposes of this BAA includes any customer that is a HIPAA covered entity or that elects HIPAA-grade handling of resident health information) and Intervene Technologies LLC d/b/a CareCommand ("Business Associate"). Capitalized terms not defined here have the meanings in HIPAA, the HITECH Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, "HIPAA"). "PHI" means Protected Health Information created, received, maintained, or transmitted by Business Associate for or on behalf of Covered Entity through the CareCommand service. This BAA supplements the Terms of Service and controls over them as to PHI.
2. Permitted Uses and Disclosures
Business Associate may use and disclose PHI only: (a) to provide, maintain, support, and improve the service for Covered Entity as described in the Terms of Service; (b) as required by law; (c) for the proper management and administration of Business Associate and to carry out its legal responsibilities, provided any disclosure for such purposes is required by law or made under reasonable assurances of confidentiality and breach notice from the recipient; and (d) to provide data aggregation services relating to Covered Entity's health care operations as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(b); de-identified information is no longer PHI. Business Associate shall not sell PHI, and shall not use or disclose PHI for marketing, except as HIPAA permits.
3. Minimum Necessary; Safeguards
Business Associate shall limit uses, disclosures, and requests of PHI to the minimum necessary for the intended purpose, and shall implement and maintain administrative, physical, and technical safeguards that comply with the HIPAA Security Rule (45 C.F.R. §§ 164.308, 164.310, 164.312, 164.316) for electronic PHI, including role-based access control, encryption of PHI in transit and at rest, access logging, and workforce training. Business Associate's current subprocessor and security practices are described on its published security page.
4. Reporting; Breach Notification
Business Associate shall report to Covered Entity: (a) any use or disclosure of PHI not permitted by this BAA of which it becomes aware; (b) any Security Incident (excluding Unsuccessful Security Incidents such as pings, port scans, and blocked intrusion attempts, for which this sentence is deemed ongoing notice); and (c) any Breach of Unsecured PHI as required by 45 C.F.R. § 164.410 — without unreasonable delay and in no case later than ten (10) business days after discovery, including to the extent known the identification of affected individuals, a description of the event, the PHI involved, and steps taken to mitigate and prevent recurrence. Business Associate shall cooperate with Covered Entity's own notification obligations.
5. Subcontractors
Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and safeguards at least as protective as those in this BAA (45 C.F.R. §§ 164.502(e)(1)(ii), 164.308(b)(2)) before the subcontractor touches PHI.
6. Individual Rights Support
To the extent PHI in the service constitutes a Designated Record Set, Business Associate shall, within ten (10) business days of Covered Entity's request, make PHI available to Covered Entity as necessary for Covered Entity to meet its obligations regarding individual access (45 C.F.R. § 164.524), amendment (§ 164.526, and shall incorporate amendments Covered Entity directs), and accounting of disclosures (§ 164.528, and shall document and provide the disclosures Business Associate makes that are subject to accounting). The service's in-app records and export features may be used to satisfy these requests.
7. Access by the Secretary; Internal Records
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with HIPAA.
8. Covered Entity Responsibilities
Covered Entity shall: (a) not request Business Associate to use or disclose PHI in a manner impermissible under HIPAA if done by Covered Entity; (b) notify Business Associate of restrictions on use or disclosure of PHI Covered Entity has agreed to, and of changes in, or revocation of, individual permissions, to the extent they affect Business Associate; and (c) use the service's role-based access controls appropriately for its workforce.
9. Term; Termination; Return or Destruction
This BAA takes effect on electronic execution and continues as long as Business Associate holds PHI for Covered Entity. Either party may terminate this BAA and the underlying service for the other's material breach of this BAA not cured within fifteen (15) days of written notice. Upon termination of the service, Business Associate shall, consistent with the account-deletion process described in the Terms of Service (30-day export window, then permanent deletion), return PHI to Covered Entity via the in-app export and thereafter destroy PHI from production systems, retaining no copies except as required by law or standard backup cycles, in which case this BAA's protections survive for as long as such PHI is retained and further use is limited to the purposes making return or destruction infeasible.
10. Miscellaneous
Nothing in this BAA creates third-party-beneficiary rights in any individual. This BAA shall be interpreted to permit the parties to comply with HIPAA, and any ambiguity shall be resolved in favor of that compliance; it shall be deemed amended to conform to any amendment of HIPAA that requires it, and the parties shall negotiate in good faith any further required changes. This BAA is governed by Florida law to the extent not preempted by federal law. The parties agree this document may be executed or accepted electronically (checkbox acceptance or typed name in the CareCommand application), with the same force and effect as a handwritten signature under the U.S. ESIGN Act and the Florida Uniform Electronic Transaction Act.
Note
This document is provided as a starting draft. Parties are encouraged to seek independent legal counsel before signing. Company reserves the right to modify terms upon attorney review; modified terms apply prospectively and require fresh acceptance.