BUSINESS ASSOCIATE AGREEMENT
HIPAA — required before any patient-identifiable claims data changes hands
This Business Associate Agreement ("BAA") is entered into between Remend Health, Inc., a Delaware corporation ("Business Associate") and ("Covered Entity"), effective as of the date of the Covered Entity's signature below.
- Definitions. Terms used here (Protected Health Information / PHI, Required by Law, Secretary, etc.) have the meanings in the HIPAA Rules at 45 CFR Parts 160 and 164.
- Permitted uses. Business Associate may use and disclose PHI only to perform the claims-recovery Services for the Covered Entity, or as Required by Law. It will not use or disclose PHI for any other purpose.
- Safeguards. Business Associate will use appropriate administrative, physical, and technical safeguards (and comply with the HIPAA Security Rule for electronic PHI) to prevent unauthorized use or disclosure of PHI.
- Subcontractors. Business Associate will require any subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree to the same restrictions and conditions.
- Reporting. Business Associate will report to the Covered Entity any use or disclosure not permitted by this BAA, any Security Incident of which it becomes aware, and any Breach of Unsecured PHI, without unreasonable delay and no later than 10 business days after discovery.
- Access & amendment. Business Associate will make PHI available to the Covered Entity as needed to meet its obligations under 45 CFR 164.524 (access) and 164.526 (amendment), and will make available an accounting of disclosures under 164.528. To the extent Business Associate carries out one or more of the Covered Entity's obligations under Subpart E of 45 CFR Part 164, it will comply with the requirements of that Subpart that apply to the Covered Entity in the performance of those obligations.
- Books & records. Business Associate will make its internal practices, books, and records relating to PHI available to the Secretary for determining compliance.
- De-identification. Business Associate may de-identify PHI in accordance with 45 CFR 164.514(a)–(c) and may retain and use such de-identified information to improve its services and to produce aggregate benchmarks. De-identified information is not PHI and is not subject to this BAA.
- Return or destruction. On termination, Business Associate will return or destroy all PHI it holds, if feasible; where not feasible, it will extend these protections to that PHI and limit further use to the reasons that made return/destruction infeasible. This obligation applies to PHI and does not extend to information de-identified under the preceding section.
- Term & termination. This BAA is effective on the date above and terminates when all PHI is returned or destroyed, or with any underlying services agreement between the parties. The Covered Entity may terminate this BAA if it determines that Business Associate has violated a material term and failed to cure within 30 days of written notice, or immediately on written notice if cure is not possible.
This BAA stands alone: it governs data handling only and creates no payment or service obligations. Any recovery engagement is documented in a separate services agreement, agreed in writing before work begins.