Business Associate Agreement (BAA)
Nevada, USA
Effective Date: This Agreement is incorporated by reference into, and becomes effective on, the date a Covered Entity creates an EHR 360 account or executes a services agreement with Practice Management 360 LLC, whichever occurs first.
Parties: This Agreement is between the healthcare provider, practice, or organization using EHR 360 (the “Covered Entity”) and Practice Management 360 LLC, a limited liability company (the “Business Associate”), collectively the “Parties.”
1. Background & Purpose
Covered Entity engages Practice Management 360 LLC to provide EHR 360, a web-based electronic health record and practice management platform, along with related services. In the course of providing these services, Business Associate may create, receive, maintain, or transmit Protected Health Information (“PHI”) on behalf of Covered Entity.
The Parties enter into this Agreement to satisfy the requirements of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, the “HIPAA Rules”). This Agreement governs the use and disclosure of PHI by Business Associate and supplements — and where inconsistent, controls over — any underlying services agreement between the Parties with respect to PHI.
2. Definitions
Capitalized terms used but not otherwise defined in this Agreement have the meanings given to them in the HIPAA Rules, including 45 CFR §§ 160.103 and 164.103. Key terms used throughout this Agreement include:
- Breach
- Has the meaning given in 45 CFR § 164.402.
- Business Associate
- Practice Management 360 LLC, in its capacity as a “business associate” as defined in 45 CFR § 160.103, acting on behalf of Covered Entity in connection with EHR 360.
- Covered Entity
- The healthcare provider or organization that has agreed to use EHR 360 and is a “covered entity” as defined in 45 CFR § 160.103.
- Designated Record Set
- Has the meaning given in 45 CFR § 164.501, including the medical and billing records maintained by or for Covered Entity within EHR 360.
- Electronic Protected Health Information (ePHI)
- PHI that is transmitted or maintained in electronic media, as defined in 45 CFR § 160.103.
- Protected Health Information (PHI)
- Has the meaning given in 45 CFR § 160.103, limited to information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity through EHR 360.
- Security Incident
- Has the meaning given in 45 CFR § 164.304.
- Subcontractor
- Has the meaning given in 45 CFR § 164.103, referring to any person or entity to whom Business Associate delegates a function, activity, or service that involves PHI.
3. Obligations of Business Associate
- Permitted use. Business Associate will not use or disclose PHI other than as permitted or required by this Agreement, the underlying services agreement, or as required by law.
- Safeguards. Business Associate will implement and maintain appropriate administrative, physical, and technical safeguards — consistent with the HIPAA Security Rule — to protect the confidentiality, integrity, and availability of ePHI it creates, receives, maintains, or transmits on behalf of Covered Entity within EHR 360.
- Subcontractors. Business Associate will enter into written agreements with any Subcontractor that will have access to PHI, requiring that Subcontractor to agree to restrictions and conditions with respect to PHI that are at least as protective as those in this Agreement.
- Reporting. Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, and any Security Incident, of which it becomes aware, in accordance with Section 7 (Breach Notification).
- Individual rights. Business Associate will make PHI available, and will make any amendments to PHI in a Designated Record Set as directed by Covered Entity, to support Covered Entity’s obligations to individuals under 45 CFR §§ 164.524 and 164.526.
- Accounting of disclosures. Business Associate will document disclosures of PHI, and information related to such disclosures, needed for Covered Entity to respond to an individual’s request for an accounting of disclosures under 45 CFR § 164.528.
- Government access. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity’s compliance with the HIPAA Rules.
- Workforce training. Business Associate will train members of its workforce who have access to PHI on applicable HIPAA privacy and security requirements, and will update that training as regulations evolve.
- No sale of PHI. Business Associate will not receive remuneration, directly or indirectly, in exchange for PHI, except as expressly permitted by HIPAA and HITECH and authorized in writing by Covered Entity.
4. Permitted Uses & Disclosures
Except as otherwise limited in this Agreement, Business Associate may use or disclose PHI as reasonably necessary to:
- Provide EHR 360 and related services to Covered Entity, consistent with the underlying services agreement;
- Carry out Business Associate’s own proper management, administration, and legal responsibilities, provided any such disclosure is required by law, or Business Associate obtains reasonable written assurances from the recipient that the PHI will remain confidential and be used only for the purpose disclosed, with prompt notice back to Business Associate of any known breach of that confidentiality;
- Provide data aggregation services relating to the health care operations of Covered Entity, as permitted under 45 CFR § 164.504(e)(2)(i)(B); and
- Report violations of law to appropriate federal and state authorities, consistent with 45 CFR § 164.502(j)(1).
5. De-Identified Information
Business Associate may de-identify PHI in accordance with the standards set out in 45 CFR § 164.514(a)-(b). Once information meets that de-identification standard, it is no longer PHI and is not subject to the restrictions of this Agreement.
6. Obligations of Covered Entity
- Covered Entity will notify Business Associate of any limitation(s) in its notice of privacy practices, and any changes to that notice, to the extent such limitation may affect Business Associate’s use or disclosure of PHI.
- Covered Entity will notify Business Associate of any changes in, or revocation of, an individual’s authorization to use or disclose PHI, to the extent it affects Business Associate’s permitted uses or disclosures.
- Covered Entity will notify Business Associate of any restriction on the use or disclosure of PHI that it has agreed to under 45 CFR § 164.522, to the extent it affects Business Associate’s use or disclosure of PHI.
- Covered Entity will not request Business Associate to use or disclose PHI in a manner that would not be permissible if done directly by Covered Entity under the HIPAA Rules, except as permitted for data aggregation or management/administrative purposes described above.
7. Breach Notification
Business Associate will notify Covered Entity in writing without unreasonable delay, and in no event later than five (5) business days after discovering a Breach of unsecured PHI. To the extent known, that notice will include:
- Identification of each individual whose PHI was, or is reasonably believed to have been, accessed, acquired, used, or disclosed;
- A description of what happened, including the date of the Breach and the date of discovery;
- The type of PHI involved;
- Steps individuals should take to protect themselves from potential harm; and
- Steps Business Associate is taking to investigate, mitigate harm, and prevent further Breaches.
Covered Entity retains sole discretion over whether and how to notify affected individuals, the Secretary, and the media, as HITECH may require. Business Associate will cooperate with Covered Entity’s investigation and will bear the costs of notification and remediation to the extent the Breach resulted from Business Associate’s violation of this Agreement.
8. Term & Termination
- Term. This Agreement takes effect on the date identified above and remains in effect for as long as Business Associate maintains PHI on behalf of Covered Entity, or until the underlying services agreement terminates, whichever is later.
- Termination for cause. If either Party determines the other has materially breached this Agreement, it will notify the breaching Party and allow a reasonable opportunity to cure. If the breach is not cured within that period, the non-breaching Party may terminate the underlying services agreement and this Agreement.
- Effect of termination. Upon termination, Business Associate will, at Covered Entity’s direction, return or securely destroy all PHI in its possession, including copies held by Subcontractors. Where return or destruction is not feasible (for example, due to legal retention requirements), Business Associate will extend the protections of this Agreement to that PHI for as long as it is retained, and limit further use or disclosure to the purposes that make return or destruction infeasible.
9. Indemnification & Liability
Each Party will indemnify and hold the other Party harmless from third-party claims, liabilities, and reasonable costs (including attorneys’ fees) arising from that Party’s material breach of this Agreement, or its gross negligence or willful misconduct, except to the extent such liabilities were caused by the other Party. This provision survives termination of this Agreement.
10. Miscellaneous
- Regulatory references. References to the HIPAA Rules mean the section as currently in effect or as later amended.
- Amendment. The Parties will amend this Agreement as necessary for continued compliance with HIPAA and HITECH. Amendments must be in writing and signed by both Parties, except where required automatically by a change in law.
- Interpretation. Any ambiguity in this Agreement will be resolved in favor of an interpretation that permits compliance with HIPAA and HITECH.
- No third-party beneficiaries. Nothing in this Agreement confers any right or remedy on any person other than the Parties.
- Relationship to services agreement. Except as necessary to implement the purposes of this Agreement, or where inconsistent with it, all other terms of the underlying services agreement between the Parties remain in full force.
- Governing law. This Agreement is governed by the laws of the state in which Practice Management 360 LLC is organized, without regard to conflict-of-law principles.