A future-ready HIPAA BAA template, available on request.
This Business Associate Agreement ("BAA") is a future-ready template structured according to the U.S. Health Insurance Portability and Accountability Act ("HIPAA") and its implementing regulations. This BAA is not automatically in effect for any Clinexaa Customer. It becomes binding only when separately executed in writing between a specific Covered Entity (or upstream Business Associate) and Hermitz Ventures, operating as Clinexaa, for U.S.-based or HIPAA-relevant engagements. See the separate HIPAA Disclaimer for Clinexaa's current default status.
This BAA is between the Covered Entity (or Business Associate) identified in the applicable Subscription agreement ("Covered Entity") and Hermitz Ventures, operating as Clinexaa ("Business Associate"), and is incorporated into and forms part of the parties' underlying Clinexaa Terms and Conditions once both parties have executed this BAA in writing.
Terms used in this BAA — including "Protected Health Information" ("PHI"), "Electronic Protected Health Information" ("ePHI"), "Covered Entity," "Business Associate," "Breach," "Required by Law," and "Security Incident" — have the meanings given to them under HIPAA, the HITECH Act, and their implementing regulations (collectively, "HIPAA Rules").
Business Associate may use or disclose PHI only: (a) as necessary to perform its obligations under the underlying Clinexaa Terms and this BAA; (b) as Required by Law; (c) for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided any disclosure is either Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and be used only for the purpose disclosed, with the recipient notifying Business Associate of any known breach; and (d) to provide data aggregation services relating to the health care operations of Covered Entity, where applicable. Business Associate shall not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted under this Section.
Business Associate shall: (a) not use or disclose PHI other than as permitted by this BAA or Required by Law; (b) implement appropriate safeguards, including the administrative, physical, and technical safeguards required under the HIPAA Security Rule, to prevent unauthorized use or disclosure of ePHI; (c) report to Covered Entity any use or disclosure of PHI not permitted by this BAA, including Security Incidents, of which it becomes aware; (d) ensure any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees to materially the same restrictions and conditions applicable to Business Associate under this BAA; (e) make PHI available to Covered Entity to enable Covered Entity to respond to individual rights requests under the HIPAA Rules; (f) make its internal practices, books, and records relating to PHI available to the U.S. Department of Health and Human Services for purposes of determining HIPAA compliance; and (g) maintain documentation of compliance activities as required under the HIPAA Rules.
Business Associate will maintain a written information security program reasonably designed to protect the confidentiality, integrity, and availability of ePHI it creates, receives, maintains, or transmits on behalf of Covered Entity, including measures such as encryption of ePHI in transit, role-based access controls, audit logging of access to PHI, workforce confidentiality obligations, and incident response procedures. Specific technical detail of these safeguards is available to Covered Entity on request to support its own HIPAA risk assessment obligations.
Business Associate will obtain satisfactory assurances, through a written agreement, that any Subcontractor that creates, receives, maintains, or transmits PHI on Business Associate's behalf will appropriately safeguard such PHI in a manner consistent with this BAA and the HIPAA Rules. Business Associate will maintain a list of relevant Subcontractors and make it available to Covered Entity on reasonable request.
Business Associate shall notify Covered Entity without unreasonable delay, and in no case later than the timeframe required under the HIPAA Breach Notification Rule, following discovery of a Breach of unsecured PHI. Such notification will include, to the extent known: a description of the Breach; the types of PHI involved; the individuals affected or reasonably believed to be affected; and the steps Business Associate has taken or recommends Covered Entity take in response. Business Associate will cooperate with Covered Entity's own breach assessment and notification obligations under the HIPAA Rules.
Covered Entity shall: (a) notify Business Associate of any limitation in its notice of privacy practices, to the extent such limitation may affect Business Associate's use or disclosure of PHI; (b) notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent it affects Business Associate's permitted uses; and (c) not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done directly by Covered Entity.
This BAA takes effect upon execution by both parties and remains in effect for as long as Business Associate creates, receives, maintains, or transmits PHI on behalf of Covered Entity under the underlying Clinexaa Terms. Either party may terminate this BAA for the other party's material breach, provided the breaching party is given written notice and a reasonable opportunity to cure; if the breach is not cured, the non-breaching party may terminate the underlying Clinexaa Terms and this BAA. Where termination for cause is infeasible because return or destruction of PHI is not practicable, the protections of this BAA will continue to apply to any PHI retained, and further use or disclosure will be limited to those purposes that make return or destruction infeasible.
Upon termination of this BAA, Business Associate shall, at Covered Entity's election and to the extent feasible, return or securely destroy all PHI received from, or created or received on behalf of, Covered Entity that it still maintains, and retain no copies, except where retention is required by law, in which case the protections of this BAA will continue to apply to any PHI retained for so long as it is maintained.
This BAA is interpreted to comply with the HIPAA Rules; any ambiguity is resolved in favor of an interpretation permitting compliance. In the event of a conflict between this BAA and the underlying Clinexaa Terms with respect to the treatment of PHI, this BAA controls. This BAA does not apply, and Business Associate does not act as a HIPAA Business Associate, unless and until both parties have executed it in writing in connection with a specific Subscription.
Hermitz Ventures — Clinexaa
Email: hello@hermitz.com
WhatsApp / Phone: +971 54 438 1614
Location: Dubai, United Arab Emirates