This Business Associate Agreement ("Agreement") is entered into by and between [Covered Entity legal name] ("Covered Entity") and Cardio AI, operating the MedCRM Healthcare Suite under the Cardio AI brand ("Business Associate"), effective as of the date last signed below (the "Effective Date"). Covered Entity and Business Associate are each a "Party" and together the "Parties." This Agreement supplements and is incorporated into the Terms of Use and any order or master agreement between the Parties (the "Underlying Agreement").
Contents
1. Definitions
Capitalized terms not defined here have the meanings given in the HIPAA Rules. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended (including by the HITECH Act).
2. Permitted uses & disclosures of PHI
- Business Associate may use and disclose PHI only as necessary to perform the services described in the Underlying Agreement (operating the MedCRM Platform for the Covered Entity), as permitted or required by this Agreement, or as Required by Law.
- Business Associate may use PHI for its proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes only if the disclosure is Required by Law or the recipient provides reasonable assurances of confidentiality and agrees to notify Business Associate of any breach.
- Business Associate may de-identify PHI in accordance with 45 CFR §164.514(a)–(c) and may use aggregate, de-identified data to operate, secure, and improve the Platform, consistent with the HIPAA Rules.
- Business Associate will not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as expressly permitted above.
- Business Associate will not sell PHI or use or disclose PHI for marketing except as permitted by the HIPAA Rules and this Agreement.
3. Obligations of Business Associate
- Not use or further disclose PHI other than as permitted by this Agreement or Required by Law.
- Use appropriate safeguards, and comply with the Security Rule with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
- Mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this Agreement.
- Report to Covered Entity as described in Section 5.
- Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on Business Associate's behalf agrees to the same restrictions and conditions (Section 6).
- Make available PHI and records as described in Sections 7 and, to the Secretary of HHS, its internal practices, books, and records relating to the use and disclosure of PHI for purposes of determining compliance.
- To the extent Business Associate carries out any of Covered Entity's obligations under the Privacy Rule, comply with the requirements that apply to Covered Entity in performing those obligations.
4. Safeguards & Security Rule
Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI as required by 45 CFR §§164.308, 164.310, 164.312, and 164.316. The Platform's controls include encryption of PHI in transit, hashed credentials, role-based and permission-based access with administrator approval, session expiration, and audit logging. Business Associate will maintain policies and workforce training consistent with the Security Rule.
5. Reporting & breach notification
- Business Associate will report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, and any Security Incident, without unreasonable delay.
- Business Associate will notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and no later than [e.g., 30] calendar days after discovery, and will provide the information Covered Entity needs to meet its notification obligations under 45 CFR §164.404, to the extent known.
- Unsuccessful Security Incidents (e.g., routine pings, port scans, blocked attempts) that result in no unauthorized access to PHI are hereby reported on an aggregate basis and require no individual notice.
6. Subcontractors
In accordance with 45 CFR §§164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will require each Subcontractor that creates, receives, maintains, or transmits PHI on its behalf to enter into a written agreement containing restrictions and conditions at least as protective as those in this Agreement. Current categories of Subcontractors include cloud hosting and managed database providers; additional Subcontractors may be engaged subject to the flow-down requirement.
7. Individual rights (access, amendment, accounting)
- Access (§164.524): Business Associate will make PHI in a Designated Record Set available to Covered Entity (or, as directed, to the individual) to enable Covered Entity to meet access requirements.
- Amendment (§164.526): Business Associate will make PHI available for amendment and incorporate amendments as directed by Covered Entity.
- Accounting (§164.528): Business Associate will document and make available information required for Covered Entity to provide an accounting of disclosures.
- Business Associate will forward to Covered Entity any request it receives directly from an individual regarding these rights.
8. Obligations of Covered Entity
- Notify Business Associate of any limitation in its Notice of Privacy Practices, any change in or revocation of an individual's permission, and any restriction on use or disclosure to which Covered Entity has agreed, to the extent these affect Business Associate's use or disclosure of PHI.
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as permitted under Section 2.
- Use the Platform's access, role, and configuration controls appropriately and only submit PHI it is authorized to process.
9. Term & termination
- This Agreement is effective on the Effective Date and continues until all PHI is returned or destroyed, or protections are extended to any retained PHI.
- Covered Entity may terminate the Underlying Agreement and this Agreement if Business Associate materially breaches this Agreement and fails to cure within a reasonable period, as provided by 45 CFR §164.504(e)(2)(iii).
10. Return or destruction of PHI
Upon termination, Business Associate will, if feasible, return or destroy all PHI it maintains on behalf of Covered Entity and retain no copies. Where return or destruction is not feasible, Business Associate will extend the protections of this Agreement to the retained PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for so long as it retains the PHI.
11. Miscellaneous
- Regulatory references are to the sections as in effect or amended.
- Amendment. The Parties will amend this Agreement as necessary to comply with changes to the HIPAA Rules.
- Interpretation. Any ambiguity is resolved to permit compliance with the HIPAA Rules. This Agreement controls over any conflicting term of the Underlying Agreement regarding PHI.
- No third-party beneficiaries. Nothing in this Agreement confers rights on any person other than the Parties.
- Survival. Sections addressing return/destruction and retained PHI survive termination.