Business Associate Agreement
This Business Associate Agreement ("BAA") is made and entered into at the date and time your ProbityCare account is created and is between you ("Covered Entity") and ProbityCare LLC ("Business Associate"), a limited liability company.
Recitals
WHEREAS, Covered Entity is a "Covered Entity" as that term is defined under the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-91), as amended, ("HIPAA"), and the regulations promulgated thereunder by the Secretary of the U.S. Department of Health and Human Services ("Secretary"), including, without limitation, the regulations codified at 45 C.F.R. Parts 160 and 164 ("HIPAA Regulations");
WHEREAS, Business Associate seeks to perform Services for or on behalf of Covered Entity, and in performing said Services, Business Associate will create, receive, maintain, or transmit Protected Health Information ("PHI") or Electronic Protected Health Information ("ePHI"); and
WHEREAS, the parties intend to protect the privacy and provide for the security of PHI and ePHI disclosed by Covered Entity to Business Associate, or received or created by Business Associate, when providing Services in compliance with the HIPAA Act, the HIPAA regulations, the Health Information Technology for Economic and Clinical Health Act ("the HITECH Act"), and all other applicable state and federal laws, all as amended from time to time.
WHEREAS, Covered Entity is required under HIPAA to enter into a Business Associate Agreement (BAA) with Business Associate that meets certain requirements with respect to the use and disclosure of PHI.
Agreement
In consideration of the above Recitals and for other good and valuable consideration, the receipt and adequacy of which is hereby acknowledged, the Parties agree as follows:
Article I — Definitions
The following terms shall have the meanings set forth below. Capitalized terms used in this BAA and not otherwise defined shall have the meanings ascribed to them in HIPAA, the HIPAA Regulations, or the HITECH Act, as applicable.
"Breach" shall have the meaning given under 42 U.S.C. § 17921(1) and 45 C.F.R. § 164.402.
"Data Aggregation" shall have the meaning given under 45 C.F.R. § 164.501.
"Designated Record Set" shall have the meaning given such term under 45 C.F.R. § 164.501.
"Disclose" and "Disclosure" mean, with respect to PHI, the release, transfer, provision of access to, or divulging in any other manner of PHI outside of Business Associate or to other than members of its Workforce, as set forth in 45 C.F.R. § 160.103.
"Electronic PHI" or "ePHI" means PHI that is transmitted or maintained in electronic media, as set forth in 45 C.F.R. § 160.103.
"Protected Health Information" and "PHI" mean any information, whether oral or recorded in any form or medium, that: (a) relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; and that (b) identifies the individual, or for which there is a reasonable basis for believing that the information can be used to identify the individual. "Protected Health Information" shall have the meaning given to such term under 45 C.F.R. § 160.103. Under 45 C.F.R. § 160.103, Protected Health Information includes Electronic Protected Health Information (ePHI).
"Security Incident" shall have the meaning given to such term under 45 C.F.R. § 164.304.
"Services" shall mean the services for or functions performed by Business Associate on behalf of Covered Entity pursuant to any service agreement(s) between Covered Entity and Business Associates which may be in effect now or from time to time ("Underlying Agreement"), or, if no such agreement is in effect, the services or functions performed by Business Associate that constitute a Business Associate relationship, as set forth in 45 C.F.R. § 160.103.
"Subcontractor" means a person or entity to whom a Business Associate delegates a function, activity, or service, other than in the capacity of a member of the Workforce of such Business Associate.
"Unsecured PHI" shall have the meaning given to such term under 42 U.S.C. § 17932(h), 45 C.F.R. § 164.402, and Federal Register documents.
"Use" or "Uses" mean, with respect to PHI, the sharing, employment, application, utilization, examination, or analysis of such PHI within Business Associate's internal operations, as set forth in 45 C.F.R. § 160.103.
"Workforce" shall have the meaning given to such term under 45 C.F.R. § 160.103.
Article II — Obligations of Business Associate
Permitted Uses and Disclosures of Protected Health Information
Business Associate shall not use or disclose PHI other than for the purposes of performing the Services, as permitted or required by this BAA, or as required by law. Business Associate shall not use or disclose PHI in any manner that would constitute a violation of Subpart E of 45 C.F.R. Part 164 if so used or disclosed by Covered Entity.
Prohibited Marketing and Sale of PHI
Notwithstanding any other provision in this BAA, Business Associate shall comply with the following requirements: (i) Business Associate shall not use or disclose PHI for fundraising or marketing purposes; and (ii) Business Associate shall not directly or indirectly receive remuneration in exchange for PHI, except with the prior written consent of Covered Entity.
Adequate Safeguards of PHI
Business Associate shall implement and maintain appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this BAA. Business Associate shall reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI.
Mitigation
Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this BAA.
Reporting Non-Permitted Use or Disclosure
Reporting Security Incidents and Non-Permitted Use or Disclosure: Business Associate shall report to Covered Entity in writing each security incident or use or disclosure that is not specifically permitted by this BAA, no later than three (3) business days after becoming aware of such security incident or non-permitted use or disclosure.
Breach of Unsecured PHI: If Business Associate determines that a reportable breach of unsecured PHI has occurred, Business Associate shall provide a written report to Covered Entity without unreasonable delay, but no later than thirty (30) calendar days after discovery of the breach.
Availability of Internal Practices, Books, and Records to Government
Business Associate agrees to make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining Covered Entity's compliance with HIPAA, the HIPAA Regulations, and the HITECH Act.
Access to and Amendment of Protected Health Information
To the extent that Business Associate maintains a Designated Record Set on behalf of Covered Entity and within fifteen (15) days of a request by Covered Entity, Business Associate shall make the PHI it maintains in Designated Record Sets available to Covered Entity for inspection and copying, or amend the PHI to enable the Covered Entity to fulfill its obligations.
Accounting
To the extent that Business Associate maintains a Designated Record Set on behalf of Covered Entity, within thirty (30) days of receipt of a request from Covered Entity or an individual for an accounting of disclosures of PHI, Business Associate shall make available to Covered Entity the information required to provide an accounting of disclosures.
Use of Subcontractors
Business Associate shall require each of its Subcontractors that creates, maintains, receives, or transmits PHI on behalf of Business Associate, to execute a Business Associate Agreement that imposes on such Subcontractors the same restrictions, conditions, and requirements that apply to Business Associate under this BAA.
Minimum Necessary
Business Associate shall, to the extent practicable, limit its request, use, or disclosure of PHI to the minimum amount of PHI necessary to accomplish the purpose of the request, use, or disclosure.
Article III — Term and Termination
Term
The term of this Agreement shall be effective as of the Effective Date and shall terminate as of the date that all of the PHI provided by Covered Entity to Business Associate, created, or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity.
Termination for Cause
Upon Covered Entity's knowledge of a material breach or violation of this BAA by Business Associate, Covered Entity shall either provide Business Associate an opportunity to cure the breach within ten (10) business days or immediately terminate this BAA if Covered Entity determines that such breach cannot be cured.
Disposition of Protected Health Information Upon Termination or Expiration
Upon termination or expiration of this BAA, Business Associate shall either return or destroy all PHI received from, created, or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form and retain no copies of such PHI.
Article IV — Miscellaneous
Amendment to Comply with Law
This BAA shall be deemed amended to incorporate any mandatory obligations of Covered Entity or Business Associate under the HITECH Act and its implementing HIPAA Regulations.
Indemnification
Both companies/organizations hereby agree to indemnify and hold harmless the other, its affiliates, and their respective officers, directors, managers, members, shareholders, employees, and agents from and against any and all fines, penalties, damage, claims, or causes of action and expenses.
Notices
Any notices required or permitted to be given hereunder by either Party to the other shall be given in writing by personal delivery; electronic mail or facsimile; bonded courier; or United States first class registered or certified mail.
Relationship of Parties
Business Associate is an independent contractor and not an agent of Covered Entity under this BAA.
Survival
The respective rights and obligations of the Parties under termination and indemnification sections of this BAA shall survive the termination of this BAA.
Applicable Law and Venue
This Agreement shall be governed by and construed in accordance with the laws of the state of Florida (without regards to conflict of laws principles). The Parties agree that all actions or proceedings arising in connection with this BAA shall be tried and litigated exclusively in the state or federal courts of Florida.

