Business Associate Agreement
This Business Associate Agreement (this “BAA”) is entered into between MedPathX, Inc., a Delaware corporation (“Business Associate”), and the customer identified on the signature page (“Covered Entity”), and is effective as of the date of the last signature below. Business Associate provides Covered Entity a technology platform for organ-transport logistics under the MedPathX Customer Terms of Service and any Order Forms, including any Trial Period access (collectively, the “Services Agreement”). In providing the Services Agreement, Business Associate may create, receive, maintain, or transmit Protected Health Information for or on behalf of Covered Entity. The parties agree as follows.
1. Definitions
1.1 Regulatory Terms
Capitalized terms used but not defined in this BAA have the meanings given in HIPAA, including “Breach”, “Data Aggregation”, “Designated Record Set”, “Disclosure”, “Electronic Protected Health Information” (“ePHI”), “Health Care Operations”, “Individual”, “Required by Law”, “Secretary”, “Security Incident”, “Subcontractor”, “Unsecured Protected Health Information”, and “Use”.
1.2 HIPAA
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164, including the Privacy, Security, Breach Notification, and Enforcement Rules, each as amended, including by the HITECH Act.
1.3 PHI
“Protected Health Information” or “PHI” has the meaning given in 45 CFR 160.103, limited to the information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity, and includes ePHI.
1.4 Platform
“Platform” has the meaning given in the Services Agreement.
2. Permitted Uses and Disclosures
2.1 Services
Business Associate may Use and Disclose PHI as necessary to perform the services set forth in the Services Agreement, including hosting, transmitting, routing, displaying, and supporting case-coordination and messaging functions of the Platform, and as permitted by this BAA, provided the Use or Disclosure would not violate the Privacy Rule if done by Covered Entity, except as permitted under Sections 2.2 and 2.3.
2.2 Management and Administration
Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, and may Disclose PHI for those purposes if the Disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and the recipient will notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
2.3 Required by Law; Data Aggregation
Business Associate may Use or Disclose PHI as Required by Law and may provide Data Aggregation services relating to the Health Care Operations of Covered Entity as permitted by 45 CFR 164.504(e)(2)(i)(B). Where legally permitted, Business Associate will use reasonable efforts to notify Covered Entity before disclosing PHI in response to a subpoena, court order, or other legal process.
2.4 De-Identification
Business Associate may de-identify PHI in accordance with 45 CFR 164.514(a) through (c). De-identified information is not PHI, and Business Associate may use it as permitted by the Services Agreement. Consistent with the Services Agreement, de-identification is the sole pathway from Covered Entity’s data to data Business Associate may use for its own purposes, and Business Associate will not attempt to re-identify de-identified information.
2.5 Minimum Necessary
Business Associate will make Uses, Disclosures, and requests for PHI consistent with the Minimum Necessary standard, including through the Platform’s role-based access controls.
3. Obligations of Business Associate
3.1 Limits on Use and Disclosure
Business Associate will not Use or Disclose PHI other than as permitted or required by this BAA or as Required by Law. Business Associate will not sell PHI, and will not Use or Disclose PHI for marketing purposes, except as permitted by HIPAA with any required authorizations.
3.2 Safeguards
Business Associate will use appropriate safeguards to prevent Use or Disclosure of PHI other than as provided for by this BAA, and will comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to ePHI, including implementing administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI.
3.3 Reporting
Business Associate will report to Covered Entity: (a) any Use or Disclosure of PHI not provided for by this BAA of which it becomes aware; (b) any Security Incident of which it becomes aware, without unreasonable delay, provided that this Section constitutes notice of the ongoing existence and occurrence of attempted but Unsuccessful Security Incidents (such as pings, port scans, and denial-of-service attacks that do not result in unauthorized access to or acquisition of ePHI), for which no further notice is required; and (c) any Breach of Unsecured PHI as required by 45 CFR 164.410, without unreasonable delay and in no case later than five (5) business days after discovery. Reports of a Breach will include, to the extent available, the information required by 45 CFR 164.410(c). As between the parties, Covered Entity is responsible for any notifications to Individuals, the Secretary, or the media required by Subpart D of 45 CFR Part 164, unless the parties agree otherwise in writing.
3.4 Mitigation
Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a Use or Disclosure of PHI in violation of this BAA.
3.5 Subcontractors
In accordance with 45 CFR 164.502(e)(1)(ii) and 164.504(e)(1)(i), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to that PHI. Section 4 (Platform Communications; Independent Recipients) governs which Platform participants are, and are not, Subcontractors of Business Associate.
3.6 Access
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make that PHI available to Covered Entity, within fifteen (15) business days of a written request, as necessary for Covered Entity to respond to an Individual’s request for access under 45 CFR 164.524. If an Individual requests access directly from Business Associate, Business Associate will forward the request to Covered Entity within five (5) business days.
3.7 Amendment
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make that PHI available for amendment, and incorporate any amendment directed by Covered Entity, as necessary for Covered Entity to comply with 45 CFR 164.526.
3.8 Accounting of Disclosures. Business Associate will maintain and, within fifteen (15) business days of a written request, make available to Covered Entity the information required for Covered Entity to respond to an Individual’s request for an accounting of Disclosures under 45 CFR 164.528.
3.9 Obligations Performed for Covered Entity
To the extent Business Associate is to carry out one or more of Covered Entity’s obligations under Subpart E of 45 CFR Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.
3.10 Books and Records
Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA.
4. Platform Communications; Independent Recipients
4.1 Recipients at Covered Entity’s Direction
The Platform enables Covered Entity and its authorized users to communicate case and logistics information, which may include PHI, with other participants that Covered Entity selects for a case, including Part 135 air carriers and other transport providers (“Operators”). Each such participant receives PHI through the Platform at the direction of, and on behalf of, Covered Entity, as an independent recipient, and not on behalf of Business Associate. Business Associate’s role is limited to providing the technology through which Covered Entity transmits the information.
4.2 Not a Subcontractor Chain
Business Associate is a business associate of Covered Entity only, and is not a Subcontractor of any party. Operators and other participants that receive PHI at Covered Entity’s direction are not Subcontractors of Business Associate, and Business Associate has no obligation to enter into, or flow down, business associate agreements with them. As between the parties, Covered Entity is responsible for determining the HIPAA status of each participant it selects for a case, for any business associate agreement or other assurances required with such participants, and for the participants’ handling of PHI they receive at its direction. MedPathX separately requires supply-side participants, under its provider terms, to observe use limitations, minimum-necessary access, safeguards, and incident-notification obligations with respect to case information they receive.
4.3 Access Controls
Business Associate will make available role-based access controls and similar Platform features that permit Covered Entity to limit the case information visible to each participant, and Covered Entity is responsible for configuring case participation and using those features consistent with its Minimum Necessary policies.
5. Obligations of Covered Entity
5.1 Notices and Restrictions
Covered Entity will notify Business Associate of: (a) any limitation in its notice of privacy practices under 45 CFR 164.520, to the extent the limitation may affect Business Associate’s Use or Disclosure of PHI; (b) any change in, or revocation of, an Individual’s permission to Use or Disclose PHI, to the extent it may affect Business Associate; and (c) any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent it may affect Business Associate.
5.2 Permissible Requests
Covered Entity will not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity, except as permitted under Sections 2.2 and 2.3.
5.3 Consents and Submissions
Covered Entity is responsible for obtaining and maintaining all patient and third-party consents and authorizations required for it to submit PHI through the Platform and for Business Associate to process it as contemplated by the Services Agreement, and will submit PHI through the Platform only as contemplated by the Services Agreement.
6. Term and Termination
6.1 Term
This BAA is effective as of the effective date above and continues for so long as Business Associate creates, receives, maintains, or transmits PHI for Covered Entity under the Services Agreement (including during any Trial Period), unless earlier terminated under this Section 6.
6.2 Termination for Cause
Either party may terminate this BAA, and the portions of the Services Agreement that require the processing of PHI, if the other party has materially breached this BAA and has not cured the breach within thirty (30) days after written notice. If cure is not possible, the non-breaching party may terminate on written notice.
6.3 Effect of Termination
On termination of this BAA for any reason, Business Associate will return or destroy all PHI that Business Associate or its Subcontractors maintain in any form, and retain no copies, if feasible, subject to Covered Entity’s export rights under the Services Agreement. If return or destruction is not feasible (including for PHI held in routine backups or retained as Required by Law), Business Associate will extend the protections of this BAA to that PHI, limit further Uses and Disclosures to those purposes that make return or destruction infeasible, and destroy the PHI when it becomes feasible. This Section also applies to PHI in the possession of any Subcontractor.
7. Miscellaneous
7.1 Regulatory References
A reference to a section of HIPAA means the section as in effect or as amended.
7.2 Amendment
The parties will take such action to amend this BAA as is necessary for Covered Entity or Business Associate to comply with HIPAA.
7.3 Interpretation
Any ambiguity in this BAA will be resolved to permit the parties to comply with HIPAA. As to PHI, this BAA controls over any conflicting term of the Services Agreement.
7.4 No Third-Party Beneficiaries
Nothing in this BAA confers any rights on any person other than the parties.
7.5 Survival
The obligations of Business Associate under Section 6.3 (Effect of Termination) and any other provisions that by their nature should survive will survive termination of this BAA.
7.6 Governing Law
This BAA is governed by the laws of the State of Delaware to the extent not preempted by HIPAA or other federal law. To the extent applicable state law imposes privacy or security requirements more stringent than HIPAA with respect to PHI, Business Associate will comply with such requirements, and the parties will cooperate in good faith to document any state-specific terms in an addendum.
7.7 Counterparts
This BAA may be executed in counterparts and by electronic signature, each of which is an original and together one instrument.
7.8 Independent Contractors
The parties are independent contractors, and nothing in this BAA or the Services Agreement creates an agency, partnership, or joint-venture relationship between them.