Skip to main content
The problem How it works Watch the demo Platform Who we serve Leadership FAQ
Get in touch Log in Part 135 – Register HerePart 135 RegisterPart 135
Menu
The problem How it works Watch the demo Platform Who we serve Leadership FAQ Contact
Log in Part 135 – Register Here

Registration is for Part 135 certificate holders, under our Provider Terms. Transplant centers, OPOs, and brokers should contact us.

Platform agreement

Business Associate Agreement

Version 1.0 · Effective August 20, 2026
This BAA governs MedPathX’s handling of protected health information for covered entities using the platform under the Customer Terms of Service. As to PHI, this BAA and HIPAA control over our Privacy Policy.
About this published copy. This is the operative text of the Business Associate Agreement. The signature block is completed at execution and is not reproduced here. Where this published copy and an executed agreement differ, the executed agreement controls.

This Business Associate Agreement (this “BAA”) is entered into between MedPathX, Inc., a Delaware corporation (“Business Associate”), and the customer identified on the signature page (“Covered Entity”), and is effective as of the date of the last signature below. Business Associate provides Covered Entity a technology platform for organ-transport logistics under the MedPathX Customer Terms of Service and any Order Forms, including any Trial Period access (collectively, the “Services Agreement”). In providing the Services Agreement, Business Associate may create, receive, maintain, or transmit Protected Health Information for or on behalf of Covered Entity. The parties agree as follows.

1. Definitions

1.1 Regulatory Terms

Capitalized terms used but not defined in this BAA have the meanings given in HIPAA, including “Breach”, “Data Aggregation”, “Designated Record Set”, “Disclosure”, “Electronic Protected Health Information” (“ePHI”), “Health Care Operations”, “Individual”, “Required by Law”, “Secretary”, “Security Incident”, “Subcontractor”, “Unsecured Protected Health Information”, and “Use”.

1.2 HIPAA

“HIPAA” means the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164, including the Privacy, Security, Breach Notification, and Enforcement Rules, each as amended, including by the HITECH Act.

1.3 PHI

“Protected Health Information” or “PHI” has the meaning given in 45 CFR 160.103, limited to the information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity, and includes ePHI.

1.4 Platform

“Platform” has the meaning given in the Services Agreement.

2. Permitted Uses and Disclosures

2.1 Services

Business Associate may Use and Disclose PHI as necessary to perform the services set forth in the Services Agreement, including hosting, transmitting, routing, displaying, and supporting case-coordination and messaging functions of the Platform, and as permitted by this BAA, provided the Use or Disclosure would not violate the Privacy Rule if done by Covered Entity, except as permitted under Sections 2.2 and 2.3.

2.2 Management and Administration

Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, and may Disclose PHI for those purposes if the Disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and the recipient will notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

2.3 Required by Law; Data Aggregation

Business Associate may Use or Disclose PHI as Required by Law and may provide Data Aggregation services relating to the Health Care Operations of Covered Entity as permitted by 45 CFR 164.504(e)(2)(i)(B). Where legally permitted, Business Associate will use reasonable efforts to notify Covered Entity before disclosing PHI in response to a subpoena, court order, or other legal process.

2.4 De-Identification

Business Associate may de-identify PHI in accordance with 45 CFR 164.514(a) through (c). De-identified information is not PHI, and Business Associate may use it as permitted by the Services Agreement. Consistent with the Services Agreement, de-identification is the sole pathway from Covered Entity’s data to data Business Associate may use for its own purposes, and Business Associate will not attempt to re-identify de-identified information.

2.5 Minimum Necessary

Business Associate will make Uses, Disclosures, and requests for PHI consistent with the Minimum Necessary standard, including through the Platform’s role-based access controls.

3. Obligations of Business Associate

3.1 Limits on Use and Disclosure

Business Associate will not Use or Disclose PHI other than as permitted or required by this BAA or as Required by Law. Business Associate will not sell PHI, and will not Use or Disclose PHI for marketing purposes, except as permitted by HIPAA with any required authorizations.

3.2 Safeguards

Business Associate will use appropriate safeguards to prevent Use or Disclosure of PHI other than as provided for by this BAA, and will comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to ePHI, including implementing administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI.

3.3 Reporting

Business Associate will report to Covered Entity: (a) any Use or Disclosure of PHI not provided for by this BAA of which it becomes aware; (b) any Security Incident of which it becomes aware, without unreasonable delay, provided that this Section constitutes notice of the ongoing existence and occurrence of attempted but Unsuccessful Security Incidents (such as pings, port scans, and denial-of-service attacks that do not result in unauthorized access to or acquisition of ePHI), for which no further notice is required; and (c) any Breach of Unsecured PHI as required by 45 CFR 164.410, without unreasonable delay and in no case later than five (5) business days after discovery. Reports of a Breach will include, to the extent available, the information required by 45 CFR 164.410(c). As between the parties, Covered Entity is responsible for any notifications to Individuals, the Secretary, or the media required by Subpart D of 45 CFR Part 164, unless the parties agree otherwise in writing.

3.4 Mitigation

Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a Use or Disclosure of PHI in violation of this BAA.

3.5 Subcontractors

In accordance with 45 CFR 164.502(e)(1)(ii) and 164.504(e)(1)(i), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to that PHI. Section 4 (Platform Communications; Independent Recipients) governs which Platform participants are, and are not, Subcontractors of Business Associate.

3.6 Access

To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make that PHI available to Covered Entity, within fifteen (15) business days of a written request, as necessary for Covered Entity to respond to an Individual’s request for access under 45 CFR 164.524. If an Individual requests access directly from Business Associate, Business Associate will forward the request to Covered Entity within five (5) business days.

3.7 Amendment

To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make that PHI available for amendment, and incorporate any amendment directed by Covered Entity, as necessary for Covered Entity to comply with 45 CFR 164.526.

3.8 Accounting of Disclosures. Business Associate will maintain and, within fifteen (15) business days of a written request, make available to Covered Entity the information required for Covered Entity to respond to an Individual’s request for an accounting of Disclosures under 45 CFR 164.528.

3.9 Obligations Performed for Covered Entity

To the extent Business Associate is to carry out one or more of Covered Entity’s obligations under Subpart E of 45 CFR Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.

3.10 Books and Records

Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA.

4. Platform Communications; Independent Recipients

4.1 Recipients at Covered Entity’s Direction

The Platform enables Covered Entity and its authorized users to communicate case and logistics information, which may include PHI, with other participants that Covered Entity selects for a case, including Part 135 air carriers and other transport providers (“Operators”). Each such participant receives PHI through the Platform at the direction of, and on behalf of, Covered Entity, as an independent recipient, and not on behalf of Business Associate. Business Associate’s role is limited to providing the technology through which Covered Entity transmits the information.

4.2 Not a Subcontractor Chain

Business Associate is a business associate of Covered Entity only, and is not a Subcontractor of any party. Operators and other participants that receive PHI at Covered Entity’s direction are not Subcontractors of Business Associate, and Business Associate has no obligation to enter into, or flow down, business associate agreements with them. As between the parties, Covered Entity is responsible for determining the HIPAA status of each participant it selects for a case, for any business associate agreement or other assurances required with such participants, and for the participants’ handling of PHI they receive at its direction. MedPathX separately requires supply-side participants, under its provider terms, to observe use limitations, minimum-necessary access, safeguards, and incident-notification obligations with respect to case information they receive.

4.3 Access Controls

Business Associate will make available role-based access controls and similar Platform features that permit Covered Entity to limit the case information visible to each participant, and Covered Entity is responsible for configuring case participation and using those features consistent with its Minimum Necessary policies.

5. Obligations of Covered Entity

5.1 Notices and Restrictions

Covered Entity will notify Business Associate of: (a) any limitation in its notice of privacy practices under 45 CFR 164.520, to the extent the limitation may affect Business Associate’s Use or Disclosure of PHI; (b) any change in, or revocation of, an Individual’s permission to Use or Disclose PHI, to the extent it may affect Business Associate; and (c) any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent it may affect Business Associate.

5.2 Permissible Requests

Covered Entity will not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity, except as permitted under Sections 2.2 and 2.3.

5.3 Consents and Submissions

Covered Entity is responsible for obtaining and maintaining all patient and third-party consents and authorizations required for it to submit PHI through the Platform and for Business Associate to process it as contemplated by the Services Agreement, and will submit PHI through the Platform only as contemplated by the Services Agreement.

6. Term and Termination

6.1 Term

This BAA is effective as of the effective date above and continues for so long as Business Associate creates, receives, maintains, or transmits PHI for Covered Entity under the Services Agreement (including during any Trial Period), unless earlier terminated under this Section 6.

6.2 Termination for Cause

Either party may terminate this BAA, and the portions of the Services Agreement that require the processing of PHI, if the other party has materially breached this BAA and has not cured the breach within thirty (30) days after written notice. If cure is not possible, the non-breaching party may terminate on written notice.

6.3 Effect of Termination

On termination of this BAA for any reason, Business Associate will return or destroy all PHI that Business Associate or its Subcontractors maintain in any form, and retain no copies, if feasible, subject to Covered Entity’s export rights under the Services Agreement. If return or destruction is not feasible (including for PHI held in routine backups or retained as Required by Law), Business Associate will extend the protections of this BAA to that PHI, limit further Uses and Disclosures to those purposes that make return or destruction infeasible, and destroy the PHI when it becomes feasible. This Section also applies to PHI in the possession of any Subcontractor.

7. Miscellaneous

7.1 Regulatory References

A reference to a section of HIPAA means the section as in effect or as amended.

7.2 Amendment

The parties will take such action to amend this BAA as is necessary for Covered Entity or Business Associate to comply with HIPAA.

7.3 Interpretation

Any ambiguity in this BAA will be resolved to permit the parties to comply with HIPAA. As to PHI, this BAA controls over any conflicting term of the Services Agreement.

7.4 No Third-Party Beneficiaries

Nothing in this BAA confers any rights on any person other than the parties.

7.5 Survival

The obligations of Business Associate under Section 6.3 (Effect of Termination) and any other provisions that by their nature should survive will survive termination of this BAA.

7.6 Governing Law

This BAA is governed by the laws of the State of Delaware to the extent not preempted by HIPAA or other federal law. To the extent applicable state law imposes privacy or security requirements more stringent than HIPAA with respect to PHI, Business Associate will comply with such requirements, and the parties will cooperate in good faith to document any state-specific terms in an addendum.

7.7 Counterparts

This BAA may be executed in counterparts and by electronic signature, each of which is an original and together one instrument.

7.8 Independent Contractors

The parties are independent contractors, and nothing in this BAA or the Services Agreement creates an agency, partnership, or joint-venture relationship between them.

MedPathX, Inc. · 210 Delburg Street, Davidson, NC 28036 · support@medpathx.com

The transparency layer for organ transport.

MedPathX, Inc.
210 Delburg Street
Davidson, NC 28036
support@medpathx.com

Explore

  • The problem
  • How it works
  • Platform
  • Who we serve
  • Leadership
  • FAQ
  • Contact

Client access

  • Part 135 Register
  • Log in

Registration is for Part 135 certificate holders, under our Provider Terms. Transplant centers, OPOs, and brokers should contact us and are governed by our Customer Terms. Accounts are verified before activation.

© 2026 MedPathX. All rights reserved.
LegalPrivacy PolicyTerms of Use