Business Associate Agreement (Template)
Preamble
This Business Associate Agreement (this "BAA") is entered into as of the Effective Date by and between the covered entity identified in the applicable order form or service agreement ("Covered Entity") and Bitechart AI, Inc., a Delaware corporation ("Business Associate"). Covered Entity and Business Associate are each a "Party" and, collectively, the "Parties."
Recitals
WHEREAS, Business Associate performs certain services for or on behalf of Covered Entity pursuant to a separate service agreement (the "Underlying Agreement"), and in performing said services, Business Associate creates, receives, maintains, or transmits Protected Health Information;
WHEREAS, the Parties intend to protect the privacy and provide for the security of Protected Health Information disclosed to Business Associate, created by Business Associate, or otherwise made available to Business Associate, when providing services, in compliance with the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act"), and the regulations promulgated thereunder (collectively, the "HIPAA Regulations"); and
WHEREAS, Covered Entity is required under the HIPAA Regulations to enter into a Business Associate Agreement with Business Associate that meets certain requirements with respect to the use and disclosure of Protected Health Information;
NOW, THEREFORE, in consideration of the mutual promises contained herein and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows.
1. Definitions
Capitalized terms used in this BAA and not otherwise defined shall have the meanings ascribed to them in the HIPAA Regulations. For clarity, the following terms shall have the meanings set forth below:
- 1.1 "Breach" shall have the meaning given at 45 C.F.R. § 164.402.
- 1.2 "Designated Record Set" shall have the meaning given at 45 C.F.R. § 164.501.
- 1.3 "Disclose" and "Disclosure" mean the release, transfer, provision of access to, or divulging in any manner of PHI outside of Business Associate.
- 1.4 "Electronic PHI" or "e-PHI" means Protected Health Information transmitted or maintained in electronic media, as defined at 45 C.F.R. § 160.103.
- 1.5 "Protected Health Information" or "PHI" means individually identifiable health information provided by Covered Entity to Business Associate, or created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity, as defined at 45 C.F.R. § 160.103.
- 1.6 "Required by Law" shall have the meaning given at 45 C.F.R. § 164.103.
- 1.7 "Security Incident" shall have the meaning given at 45 C.F.R. § 164.304.
- 1.8 "Services" means the services provided by Business Associate to Covered Entity under the Underlying Agreement, including but not limited to: (a) synchronizing patient data from Covered Entity's practice management system; (b) presenting patient dental records, treatment plans, radiographs, and insurance data through a patient-facing portal; and (c) generating patient-facing educational summaries and explanations of clinical information using artificial intelligence models operated under Business Associate's control.
- 1.9 "Subcontractor" means a person or entity to whom Business Associate delegates a function, activity, or service (other than in the capacity of a member of the workforce of Business Associate), that involves the creation, receipt, maintenance, or transmission of PHI on behalf of Business Associate.
- 1.10 "Unsecured PHI" shall have the meaning given at 45 C.F.R. § 164.402.
- 1.11 "Use" means, with respect to PHI, the sharing, employment, application, utilization, examination, or analysis of PHI within Business Associate's internal operations.
- 1.12 "Workforce" shall have the meaning given at 45 C.F.R. § 160.103.
2. Permitted Uses and Disclosures of PHI
2.1 Business Associate may use or disclose PHI only:
- (a) to perform the Services described in the Underlying Agreement;
- (b) as Required by Law;
- (c) for the proper management and administration of Business Associate, provided that any such disclosure to a third party is Required by Law or Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially and used or further disclosed only as Required by Law or for the purposes for which it was disclosed; and
- (d) to provide data aggregation services relating to the health care operations of Covered Entity, if requested by Covered Entity.
2.2 Business Associate will not use or disclose PHI other than as permitted or required by this BAA or as Required by Law.
2.3 Business Associate will not sell PHI, will not receive remuneration in exchange for PHI, and will not use PHI for marketing purposes without a written authorization from the individual that meets the requirements of 45 C.F.R. § 164.508.
2.4 AI Training Restriction. Business Associate will not use PHI to train, fine-tune, or otherwise improve any foundation model, large language model, or other artificial intelligence system, whether operated by Business Associate or by a Subcontractor. Business Associate will require, by written agreement, that any Subcontractor providing artificial intelligence services (including but not limited to third-party model providers) contractually commits to a Zero Data Retention configuration or an equivalent arrangement that prohibits use of Covered Entity's PHI for model training or general model improvement.
2.5 De-identified Data. Business Associate may create de-identified information from PHI in accordance with 45 C.F.R. § 164.514(b) and may use such de-identified information for any lawful purpose, including product improvement and analytics. Data that has been de-identified in accordance with 45 C.F.R. § 164.514(b) is no longer subject to this BAA.
3. Safeguards
3.1 Business Associate will implement and maintain reasonable and appropriate administrative, physical, and technical safeguards that comply with the HIPAA Security Rule (45 C.F.R. §§ 164.308, 164.310, 164.312) and that protect the confidentiality, integrity, and availability of e-PHI created, received, maintained, or transmitted on behalf of Covered Entity.
3.2 Without limiting the generality of Section 3.1, Business Associate will maintain the following controls:
- (a) encryption of e-PHI in transit using TLS 1.2 or higher;
- (b) encryption of e-PHI at rest using AES-256 or an equivalent industry-standard algorithm;
- (c) role-based access controls and multi-factor authentication for all administrative accounts;
- (d) audit logging of all access to and disclosure of PHI, with logs retained for a minimum of six (6) years;
- (e) an annual security risk assessment consistent with 45 C.F.R. § 164.308(a)(1)(ii)(A);
- (f) documented workforce security awareness training conducted at least annually;
- (g) a documented incident response plan and business continuity / disaster recovery plan; and
- (h) reasonable physical security controls at any facility housing e-PHI.
4. Reporting
4.1 Security Incidents. Business Associate will report to Covered Entity any Security Incident of which it becomes aware. The Parties acknowledge the ongoing existence and occurrence of attempted but ineffective Security Incidents that are trivial in nature (such as pings, port scans, and other broadcast attacks against Business Associate's networks) and agree that no additional notification of such ineffective Security Incidents is required so long as no such incident results in unauthorized access, Use, or Disclosure of PHI. Business Associate will report material Security Incidents to Covered Entity without unreasonable delay and in no event later than ten (10) business days after discovery.
4.2 Breach Notification. Business Associate will notify Covered Entity of any Breach of Unsecured PHI in accordance with 45 C.F.R. § 164.410. Such notification will be made without unreasonable delay and in no event later than twenty (20) calendar days after discovery of the Breach. The notification will include, to the extent then known: (a) the identification of each individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the Breach; (b) a description of what happened, including the date of the Breach and the date of discovery; (c) a description of the types of Unsecured PHI involved; and (d) a description of the steps Business Associate is taking to investigate the Breach, mitigate harm, and prevent recurrence.
4.3 Mitigation. Business Associate will mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a Use or Disclosure of PHI in violation of this BAA.
5. Subcontractors
5.1 Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees, in writing, to substantially the same restrictions and conditions that apply to Business Associate under this BAA.
5.2 Current Subcontractors. Current Subcontractors that may handle PHI include:
- Cloud infrastructure: Amazon Web Services, Inc. (BAA in place);
- Database and application hosting: Supabase, Inc. and Vercel, Inc. (BAAs required prior to production use);
- Artificial intelligence services: OpenAI, LLC (BAA and Zero Data Retention configuration required prior to production use; PHI is contractually prohibited from being used for model training);
- Communications: Twilio Inc. and other SMS/email delivery vendors (BAAs required prior to production use).
5.3 Notice of New Subcontractors. Business Associate will provide Covered Entity with at least thirty (30) days' prior written notice before engaging any new Subcontractor that will handle PHI. Business Associate will maintain and provide upon request a current list of Subcontractors that handle PHI.
6. Access, Amendment, and Accounting
6.1 Access. Business Associate will, within fifteen (15) business days of a written request by Covered Entity, make PHI in a Designated Record Set available to Covered Entity as necessary for Covered Entity to comply with 45 C.F.R. § 164.524.
6.2 Amendment. Business Associate will, within fifteen (15) business days of a written request by Covered Entity, make PHI in a Designated Record Set available for amendment and incorporate any amendments as directed by Covered Entity, in accordance with 45 C.F.R. § 164.526.
6.3 Accounting of Disclosures. Business Associate will document Disclosures of PHI and information related to such Disclosures as would be required for Covered Entity to respond to a request for an accounting of Disclosures in accordance with 45 C.F.R. § 164.528, and will make such information available to Covered Entity within fifteen (15) business days of a written request.
7. Governmental Access
Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Regulations.
8. Insurance
Business Associate will maintain cyber liability and technology errors-and-omissions insurance with limits of not less than $1,000,000 per occurrence and $2,000,000 in the aggregate, covering unauthorized access, disclosure, or loss of PHI. Business Associate will provide Covered Entity with a certificate of insurance upon written request.
9. Audit and Assessment
Upon Covered Entity's reasonable written request, and not more than once per calendar year (except in the event of a Breach), Business Associate will provide Covered Entity with a summary of its most recent security risk assessment or an equivalent third-party attestation (such as a SOC 2 Type II report, once available). Business Associate will use reasonable efforts to respond to Covered Entity's reasonable security questionnaires.
10. Indemnification
Each Party will indemnify, defend, and hold harmless the other Party from and against any third-party claims, damages, fines, penalties, and reasonable attorneys' fees to the extent arising out of or resulting from the indemnifying Party's negligence, willful misconduct, or breach of this BAA that causes a violation of the HIPAA Regulations. This Section 10 is subject to any limitation of liability set forth in the Underlying Agreement, provided that no limitation of liability will apply to a Party's indemnification obligations under this Section 10 with respect to violations resulting from that Party's gross negligence or willful misconduct.
11. Term and Termination
11.1 Term. This BAA is effective on the date last signed by the Parties (the "Effective Date") and continues until terminated as provided herein or until all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity.
11.2 Termination for Cause. Either Party may terminate this BAA and the Underlying Agreement if the other Party engages in a pattern of activity or practice that constitutes a material breach or violation of the terminating Party's obligations under this BAA, and the breaching Party does not cure such breach within thirty (30) days of written notice.
11.3 Return or Destruction of PHI. Upon termination of this BAA for any reason, Business Associate will return or destroy all PHI in its possession within thirty (30) days, and will not retain any copies. If return or destruction is not feasible, Business Associate will extend the protections of this BAA to such PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible, for so long as Business Associate maintains such PHI.
12. Miscellaneous
12.1 Amendment. The Parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for the Parties to comply with the requirements of the HIPAA Regulations. Any other amendment must be in writing and signed by both Parties.
12.2 Interpretation. Any ambiguity in this BAA shall be interpreted to permit compliance with the HIPAA Regulations. In the event of a conflict between this BAA and the Underlying Agreement regarding the subject matter of this BAA, this BAA shall control.
12.3 Regulatory References. A reference in this BAA to a section of the HIPAA Regulations means the section as in effect or as amended.
12.4 No Third-Party Beneficiaries. Nothing in this BAA is intended to confer, nor shall anything herein confer, upon any person other than the Parties and their respective successors and assigns, any rights, remedies, obligations, or liabilities whatsoever.
12.5 Counterparts; Electronic Signatures. This BAA may be executed in one or more counterparts, each of which shall be deemed an original but all of which together shall constitute one and the same instrument. Signatures delivered by facsimile or email, or executed in any electronic signature format, shall be valid and binding.
12.6 Governing Law. This BAA shall be governed by and construed in accordance with the HIPAA Regulations and the laws of the State of Delaware, without regard to conflict-of-laws principles.
12.7 Notices. Notices under this BAA shall be given in writing to the addresses set forth in the Underlying Agreement, or to such other address as either Party may designate in writing.
12.8 Independent Contractors. Business Associate is an independent contractor and not an agent of Covered Entity under this BAA. Business Associate has the sole right and obligation to supervise, manage, contract, direct, procure, perform, or cause to be performed all Business Associate obligations under this BAA.
Signature blocks and effective date are intentionally omitted from this public template. Executed originals are exchanged during customer onboarding.
This BAA template is provided for transparency and is a working draft. Bitechart AI, Inc. reserves the right to modify this template based on legal review and customer negotiation prior to execution.