This Business Associate Agreement (this “BAA”) is entered into between Patient Engagement Technologies Inc., a Delaware corporation, doing business as Hello Patient, with offices at 2025 Guadalupe St, Suite 260, Austin, TX 78705 (“Hello Patient”), and the customer that accepts this BAA as described below, as identified in the applicable Order Form, other ordering document, or Customer’s account (“Customer”), effective as of the date Customer first accepts the agreement that incorporates this BAA (the “BAA Effective Date”). This BAA forms part of, and is incorporated by reference into, the Master Subscription Agreement, the Hello Patient Subscription Terms, or other written agreement between the parties for the provision of the Services (the “Agreement”), and is the written agreement the Agreement requires before Customer may submit Protected Health Information to the Services. Customer’s acceptance of the Agreement, including by clicking to accept the Hello Patient Subscription Terms or by accessing or using the Services after the BAA is presented or made available to Customer, constitutes Customer’s acceptance and execution of this BAA, and no separate signature is required. Capitalized terms used but not defined in this BAA have the meanings given in the Agreement or, if not defined in the Agreement, in the HIPAA Rules.
1.1. The terms “Breach”, “Business Associate”, “Covered Entity”, “Data Aggregation”, “Designated Record Set”, “Disclose” and “Disclosure”, “Electronic Protected Health Information” (“ePHI”), “Individual”, “Required by Law”, “Secretary”, “Security Incident”, “Subcontractor”, “Unsecured Protected Health Information”, and “Use” have the meanings given to them in the HIPAA Rules, and references to sections of the HIPAA Rules mean those sections as in effect or as amended.
1.2. “Eligible Services” means the Services, or the specific features and components of the Services (such as Hello Patient’s AI voice and text messaging patient communication features), identified in the applicable ordering document or in Hello Patient’s then-current HIPAA eligibility documentation made available on Hello Patient’s website, as eligible to receive PHI, as configured in accordance with Hello Patient’s applicable documentation and implementation requirements.
1.3. “HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, promulgated under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Health Information Technology for Economic and Clinical Health Act, each as amended from time to time.
1.4. “Protected Health Information” or “PHI” has the meaning given in 45 C.F.R. § 160.103, limited to the protected health information that Hello Patient creates, receives, maintains, or transmits on behalf of Customer under the Agreement. PHI includes ePHI.
1.5. “Unsuccessful Security Incident” means an unsuccessful attempt at unauthorized access, Use, Disclosure, modification, or destruction of PHI or interference with system operations in an information system containing PHI, such as pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, and denial-of-service attacks, that does not result in unauthorized access to, or acquisition, Use, or Disclosure of, PHI.
1.6.“Upstream Covered Entity” means a Covered Entity on whose behalf Customer creates, receives, maintains, or transmits PHI as a Business Associate.
2.1. Roles. Customer represents and warrants that it is either a Covered Entity or a Business Associate (including a management services organization or billing company acting on behalf of health care providers) of one or more Upstream Covered Entities. Where Customer is a Covered Entity, Hello Patient is a Business Associate of Customer. Where Customer is a Business Associate of one or more Upstream Covered Entities, (i) Hello Patient is a Subcontractor of Customer, (ii) this BAA is the written agreement required under 45 C.F.R. §§ 164.504(e)(5) and 164.308(b), and (iii) Customer represents and warrants that its agreements with each Upstream Covered Entity permit Customer to engage Hello Patient and permit the Uses and Disclosures of PHI contemplated by this BAA. Hello Patient’s obligations under this BAA run to Customer in either capacity.
2.2. Scope; Eligible Services. This BAA applies to all PHI that Hello Patient creates, receives, maintains, or transmits on behalf of Customer. Customer will not submit, or permit any of its authorized users to submit, PHI to any portion of the Services other than the Eligible Services, or include PHI in support requests, account or billing information, credentials, file names, labels, metadata, or other configuration or administrative fields. As between the parties, Customer is solely responsible for PHI submitted in violation of this Section 2.2. Hello Patient may take commercially reasonable steps to remove, quarantine, or migrate such PHI, and the parties will cooperate in good faith in doing so; nothing in this Section 2.2 limits either party’s obligations under applicable law with respect to PHI it actually receives or maintains. Hello Patient does not conduct standard transactions under 45 C.F.R. Part 162 on Customer’s behalf.
2.3. Relationship to Agreement and DPA. This BAA supplements the Agreement. In the event of a conflict between this BAA and the Agreement (including any data processing agreement or similar agreement between the parties (the “DPA”)), this BAA controls solely with respect to PHI and the parties’ compliance with the HIPAA Rules, and the Agreement governs in all other respects. As between this BAA and the DPA, this BAA exclusively governs PHI and the DPA governs Personal Data (as defined in the DPA) that is not PHI. The limitations and exclusions of liability set forth in the Agreement govern all claims arising out of or relating to this BAA and the DPA, and apply regardless of any contrary provision in this BAA or the DPA. Except as expressly set forth in this BAA, all terms of the Agreement remain unchanged and in full force and effect.
3.1. Performance of the Services. Hello Patient may Use and Disclose PHI as necessary to provide, maintain, secure, support, configure, and improve the Eligible Services as provided to Customer, to perform its obligations and exercise its rights under the Agreement and this BAA, as otherwise permitted or required by this BAA, or as Required by Law. Hello Patient will not Use or Disclose PHI other than as permitted or required by this BAA or as Required by Law, or in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Customer (or an Upstream Covered Entity), except as permitted by this Section 3.
3.2. Management and Administration. Hello Patient may Use PHI for the proper management and administration of Hello Patient’s business and to carry out Hello Patient’s legal responsibilities. Hello Patient will not use Protected Health Information to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, except with Customer’s express written authorization, whether or not a data processing agreement is in place between the parties. Hello Patient may Disclose PHI for such purposes only if the Disclosure is Required by Law, or if Hello Patient obtains reasonable assurances from the recipient that the PHI will be held confidentially, Used or further Disclosed only as Required by Law or for the purposes for which it was Disclosed, and that the recipient will notify Hello Patient of any breaches of its confidentiality of which it becomes aware.
3.3. Data Aggregation. Hello Patient may Use PHI to provide Data Aggregation services relating to the health care operations of Customer (or an Upstream Covered Entity) in accordance with 45 C.F.R. § 164.504(e)(2)(i)(B).
3.4. De-identification. Hello Patient may Use PHI to create de-identified information in accordance with 45 C.F.R. § 164.514(a)-(c). Information so de-identified is no longer PHI, is not subject to this BAA, and Hello Patient’s use of de-identified information is governed by the Agreement, including, to the extent permitted under the Agreement, use for model training and improvement.
3.5. Minimum Necessary. Hello Patient will use reasonable efforts to limit its requests for, and Uses and Disclosures of, PHI to the minimum necessary to accomplish the intended purpose. Customer represents that the PHI it submits to the Eligible Services is limited to the minimum necessary for the applicable purpose, and Hello Patient may reasonably rely on Customer’s instructions and submissions in making minimum necessary determinations to the extent permitted by the HIPAA Rules.
4.1. Safeguards. Hello Patient will use appropriate administrative, physical, and technical safeguards designed to prevent the Use or Disclosure of PHI other than as provided for by this BAA, and will comply with the applicable requirements of Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to ePHI within Hello Patient’s environment. Hello Patient’s technical and organizational measures are further described in Hello Patient’s security documentation and, where a DPA is in place, in the DPA.
4.2. Breach and Incident Reporting. Hello Patient will report to Customer: (a) any Use or Disclosure of PHI not provided for by this BAA of which Hello Patient becomes aware; (b) any Breach of Unsecured Protected Health Information, without unreasonable delay and in no event later than seventy-two (72) hours after Hello Patient’s discovery; and (c) any Security Incident of which Hello Patient becomes aware, without unreasonable delay, except that this Section 4.2(c) constitutes notice, and no further reporting is required, of Unsuccessful Security Incidents. Hello Patient may report initially based on the information then available and supplement the report as additional information is confirmed. To the extent known, a report of a Breach will identify each affected Individual and include the information Customer reasonably requires to meet its obligations under 45 C.F.R. §§ 164.404 through 164.408 (or to enable an Upstream Covered Entity to do so), together with Hello Patient’s initial risk assessment under 45 C.F.R. § 164.402, if then available. As between the parties, Customer determines, based on information provided by Hello Patient, whether an impermissible Use or Disclosure is a reportable Breach and controls the content, timing, and method of any notification to Individuals, the Secretary, the media, or any other party, and Hello Patient will not make any such notification unless Required by Law or agreed in writing. No report or response under this Section is an acknowledgment of fault or liability.
4.3. Mitigation. Hello Patient will mitigate, to the extent practicable, any harmful effect known to Hello Patient of a Use or Disclosure of PHI by Hello Patient in violation of this BAA.
4.4. Subcontractors. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Hello Patient will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Hello Patient agrees in writing to restrictions and conditions at least as protective as those that apply to Hello Patient under this BAA, including compliance with the applicable requirements of the Security Rule with respect to ePHI. Hello Patient remains responsible for its Subcontractors’ performance of Hello Patient’s obligations under this BAA. Where a DPA is in place between the parties, Subcontractors that process PHI are also Sub-processors under it, and its Sub-processor list, notice, and objection provisions apply to them.
4.5. Access, Amendment, and Accounting. Customer acknowledges that the Services are not intended to serve as Customer’s system of record, that Customer’s medical and business records remain in Customer’s electronic health record and practice management systems, and that Customer maintains its own records and can access, export, amend, and delete PHI through the Eligible Services. To the extent Hello Patient maintains PHI in a Designated Record Set, Hello Patient will make such PHI available to Customer for access and amendment, and incorporate amendments directed by Customer, as reasonably necessary for Customer (or an Upstream Covered Entity) to meet its obligations under 45 C.F.R. §§ 164.524 and 164.526, and will make available the information required for an accounting of Disclosures under 45 C.F.R. § 164.528. Hello Patient will forward any request received directly from an Individual to Customer promptly, and in any event within ten (10) business days; Customer is solely responsible for Individual-rights determinations and responses, and Hello Patient will not respond directly to an Individual unless Required by Law.
4.6. Delegated Obligations. To the extent Hello Patient is expressly designated in writing to carry out an obligation of Customer (or an Upstream Covered Entity) under Subpart E of 45 C.F.R. Part 164, Hello Patient will comply with the requirements of Subpart E that apply to Customer (or the Upstream Covered Entity) in performing that obligation.
4.7. Regulator Access. Hello Patient will make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by Hello Patient on behalf of, Customer available to the Secretary for purposes of determining compliance with the HIPAA Rules, subject to attorney-client and other applicable legal privileges. Unless prohibited by law, Hello Patient will promptly notify Customer of any such request received directly from the Secretary.
4.8. Documentation. Hello Patient will retain the documentation required of it under the HIPAA Rules for the periods the HIPAA Rules require. This obligation does not require retention of PHI, which is governed by Section 6.3 (Return and Deletion of PHI).
5.1. Lawful Basis; Consents. Customer represents and warrants that it has obtained, and will maintain, all consents, authorizations, and other permissions required under the HIPAA Rules and other applicable law for Hello Patient to receive, Use, and Disclose PHI as contemplated by this BAA, and that its Disclosure of PHI to Hello Patient is permitted under the HIPAA Rules.
5.2.Notice of Restrictions. Customer will notify Hello Patient in writing of any limitation in an applicable notice of privacy practices under 45 C.F.R. § 164.520, any change in or revocation of an Individual’s permission to Use or Disclose PHI, and any restriction agreed to under 45 C.F.R. § 164.522, in each case to the extent it may affect Hello Patient’s Use or Disclosure of PHI. Customer will not agree to any restriction under 45 C.F.R. § 164.522 that affects Hello Patient’s Use or Disclosure of PHI without Hello Patient’s prior written consent, not to be unreasonably withheld. Hello Patient is not responsible for compliance with any limitation or restriction of which it has not been notified in writing.
5.3.Permissible Requests. Customer will not request that Hello Patient Use or Disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Customer (or an Upstream Covered Entity), except as permitted under Section 3 (Permitted Uses and Disclosures).
5.4.Customer Environment. Customer is responsible for the security of its own systems, devices, and credentials used to access the Services, for configuring and using the Eligible Services in accordance with Hello Patient’s applicable documentation and the implementation requirements identified in its HIPAA eligibility documentation, and for maintaining current notice contacts with Hello Patient for reports under Section 4.2 (Breach and Incident Reporting). Hello Patient is not responsible for compliance failures attributable solely to the acts or omissions of Customer or its authorized users.
6.1.Term. This BAA is effective as of the BAA Effective Date and continues until the termination or expiration of the Agreement, except that this BAA continues in effect with respect to any PHI that Hello Patient retains until that PHI is returned, deleted, or de-identified in accordance with Section 6.3 (Return and Deletion of PHI).
6.2.Termination for Cause. Either party may terminate this BAA upon written notice if the other party materially breaches this BAA and fails to cure the breach within thirty (30) days after receiving written notice of it. If cure is not possible, the non-breaching party may terminate this BAA, and the portions of the Agreement (including any affected Order Form) that involve the Use or Disclosure of PHI, upon written notice. Upon any termination of this BAA, Customer will immediately cease submitting PHI to the Services. In lieu of termination, Hello Patient may suspend the ability to submit PHI to the Eligible Services while continuing to provide Services that do not involve the Use or Disclosure of PHI.
6.3.Return and Deletion of PHI. Upon termination or expiration of this BAA or the Agreement, Hello Patient will, at Customer’s election, return PHI in an industry-standard, machine-readable format or securely delete it, using commercially reasonable efforts to do so within thirty (30) days, and will provide written certification of return or deletion upon written request. If return or deletion is infeasible, Hello Patient will extend the protections of this BAA to the retained PHI, limit further Uses and Disclosures to the purposes that make return or deletion infeasible, and delete the PHI when feasible. Customer agrees that return or deletion is infeasible for PHI in routine system backups until they are overwritten or expire in the ordinary course, PHI subject to a legal hold or an order or request of a court, regulator, or other governmental authority, PHI retained in accordance with Section 3.2 (Management and Administration) to the extent reasonably necessary for Hello Patient’s proper management and administration or to carry out its legal responsibilities, and PHI reasonably required for an ongoing investigation of a Security Incident or Breach. This Section applies equally to PHI held by Subcontractors.
6.4.Survival. Sections 3 (Permitted Uses and Disclosures), 4.1 through 4.7, and 6.3 (Return and Deletion of PHI) survive termination or expiration of this BAA for as long as Hello Patient retains PHI; Section 4.8 (Documentation) survives for the retention period required by the HIPAA Rules; and Sections 6.4 (Survival), 7 (Liability), and 8 (Miscellaneous) survive termination or expiration of this BAA.
7. LIABILITY. To the maximum extent permitted by applicable law, each party’s liability arising out of or relating to this BAA is subject to the limitations and exclusions of liability set forth in the Agreement, which apply to this BAA to the same extent they apply to the Agreement. Nothing in this Section 7 (Liability) limits either party’s liability to the extent it may not be limited by contract under applicable law.
8.1. Regulatory References; Amendment. The parties will negotiate in good faith to amend this BAA as necessary for compliance with the HIPAA Rules and other applicable law. If the parties are unable to agree on a required amendment within thirty (30) days after negotiations begin, or if a change in law makes it commercially impracticable for a party to provide or use the Eligible Services in compliance with applicable law, either party may terminate the affected Eligible Services (or, if necessary, this BAA) upon thirty (30) days’ prior written notice, in which case Customer will cease submitting PHI to the affected Eligible Services and Section 6.3 (Return and Deletion of PHI) will apply.
8.2. Notices. General notices under this BAA will be given in accordance with the notice provisions of the Agreement. Reports under Section 4.2 (Breach and Incident Reporting) will be delivered, and may be delivered by email, to the notice contact identified in the applicable ordering document or as Customer otherwise designates in writing.
8.3. Entire Agreement. This BAA, together with the Agreement, constitutes the entire agreement between the parties with respect to PHI and supersedes all prior and contemporaneous business associate agreements and understandings between the parties with respect to PHI.
8.4. Amendments; Waiver; Severability; No Third-Party Beneficiaries. Except as set forth in Section 8.1 (Regulatory References; Amendment), this BAA may only be amended by a written instrument signed by both parties. The failure of either party to enforce any right or provision of this BAA will not constitute a waiver of such right or provision. Any ambiguity in this BAA will be interpreted to permit the parties to comply with the HIPAA Rules, and if any provision is held to be invalid or unenforceable, it will be modified to the minimum extent necessary and the remaining provisions will continue in full force and effect. Nothing in this BAA is intended to or will confer any rights or remedies on any person or entity other than the parties and their respective successors and permitted assigns, including any Individual or Upstream Covered Entity. The parties are independent contractors, and neither party is the agent of the other under the federal common law of agency or otherwise. No Force Majeure Event under the Agreement excuses either party from complying with obligations under the HIPAA Rules to the extent those obligations may not be excused by contract, including Hello Patient’s obligations under Section 4.1 (Safeguards) and Section 4.2 (Breach and Incident Reporting).
8.5. Governing Law; Counterparts; Signature. This BAA is governed by the governing law specified in the Agreement, and the dispute resolution provisions of the Agreement apply to this BAA. This BAA is accepted electronically as part of the Agreement, and electronic acceptance has the same legal effect as execution by original signature.