BAA_VERSION in lib/legal/agreements.js so clinics are re-prompted.1. Parties & definitions
This Business Associate Agreement ("BAA") is entered into between your clinic or organization (the "Covered Entity") and Clinlytics LLC (the "Business Associate"). Terms used but not defined here have the meanings given in HIPAA (45 CFR Parts 160 and 164).
2. Permitted uses and disclosures
The Business Associate may use or disclose Protected Health Information ("PHI") only as necessary to perform the services described in the applicable Terms of Service, as required by law, or as otherwise permitted by this BAA. The Business Associate will not use or disclose PHI in a manner that would violate HIPAA if done by the Covered Entity.
3. Safeguards
The Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, consistent with the HIPAA Security Rule.
4. Subcontractors, breach reporting & termination
- The Business Associate will ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions and conditions.
- The Business Associate will report to the Covered Entity any use or disclosure of PHI not provided for by this BAA, including breaches of unsecured PHI, without unreasonable delay.
- Upon termination, the Business Associate will return or destroy all PHI where feasible, or extend the protections of this BAA to any PHI retained.
5. Authority to accept
The individual accepting this BAA on behalf of the Covered Entity represents that they are authorized to bind the organization. Questions may be directed to legal@clinlytics.com.