Business Associate Agreement
Effective Date: January 1, 2024 · iHealthcare, Inc. · Miami, Florida
Recitals
This Business Associate Agreement ("BAA" or "Agreement") is entered into between iHealthcare, Inc. ("Business Associate") and the covered entity or business associate ("Covered Entity") that executes a service agreement or order form with iHealthcare, Inc. referencing this BAA. This Agreement is intended to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations, collectively referred to as the "HIPAA Rules."
1. Definitions
Capitalized terms used but not otherwise defined in this Agreement shall have the meanings ascribed to them under the HIPAA Rules, including:
- Protected Health Information (PHI) — individually identifiable health information transmitted or maintained in any form or medium.
- Electronic PHI (ePHI) — PHI that is created, received, maintained, or transmitted in electronic form.
- Breach — the acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the PHI.
- Security Incident — the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
2. Obligations of Business Associate
iHealthcare, Inc. agrees to:
- Not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
- Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
- Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required by 45 CFR 164.410, and any Security Incident of which it becomes aware.
- In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information.
- Make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524.
- Make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 CFR 164.526.
- Maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.528.
- To the extent Business Associate is to carry out one or more of Covered Entity's obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligations.
- Make its internal practices, books, and records available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules.
3. Permitted Uses and Disclosures
Business Associate may only use or disclose PHI as follows:
- As necessary to perform the services set forth in the applicable service agreement between the parties.
- As required by law.
- For the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that disclosures are required by law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential.
- To provide Data Aggregation services to Covered Entity as permitted by 45 CFR 164.504(e)(2)(i)(B).
- To report violations of law to appropriate Federal and State authorities, consistent with 45 CFR 164.502(j)(1).
4. Breach Notification
Business Associate shall notify Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery of a Breach of Unsecured PHI. Notification shall include, to the extent possible: (i) the identification of each individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; (ii) a brief description of what happened; (iii) a description of the types of Unsecured PHI involved; (iv) steps individuals should take to protect themselves; (v) a brief description of what Business Associate is doing to investigate the Breach, mitigate harm, and protect against further Breaches; and (vi) contact information for Business Associate. Notice shall be provided to: [email protected].
5. Security Safeguards
Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, as required by 45 CFR Part 164, Subpart C. Business Associate shall conduct regular risk assessments and implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
6. Term and Termination
This Agreement shall be effective as of the date the underlying service agreement is executed and shall terminate when all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information.
Either party may terminate this Agreement if it determines that the other party has violated a material term of this Agreement. Upon termination, Business Associate shall, if feasible, return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible.
7. Miscellaneous
- Amendment. The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of the HIPAA Rules.
- Interpretation. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with the HIPAA Rules.
- Governing Law. This Agreement shall be governed by the laws of the State of Florida, without regard to its conflict of law provisions.
- Entire Agreement. This Agreement, together with the applicable service agreement, constitutes the entire agreement between the parties with respect to the subject matter hereof.
Execute a BAA
To execute a Business Associate Agreement with iHealthcare, Inc., please contact our compliance team. We will provide a countersigned copy within five (5) business days.
Request BAA Execution