**Business Associate Addendum**
This Business Associate Addendum ("BAA") is made and entered into between <mark>[LEGAL NAME OF COMPANY]</mark>, a <mark>[STATE OF INCORPORATION OF COMPANY]</mark> company ("Company") and the entity listed in the signature block ("Customer") as an addendum to the existing services agreement in place between Customer and Company (the "Services Agreement"). The Services Agreement governs Customer's use of the <mark>[cloud-based software services]</mark> made available by Company (the "Services") and prohibits Customer from utilizing the Services in a manner that would result in Company Processing any Protected Health Information without Company's prior written consent.
Customer, as a Covered Entity or Business Associate under the Health Insurance Portability and Accountability Act (HIPAA), now desires to utilize certain HIPAA-Eligible Services that can be configured by Customer to Process Protected Health Information. Subject to Customer's purchase of HIPAA-Eligible Services under the Services Agreement and application of required security configurations, Company hereby consents to Customer's use of the HIPAA-Eligible Services for the Processing of Protected Health Information. Customer acknowledges that this BAA does not apply to any Services that are not designated as HIPAA-Eligible Services or to any accounts Customer, or its personnel, may create with Company, now or in the future, that are outside the scope of the Services Agreement.
This BAA will take effect from the effective date of the first executed ordering document for HIPAA-Eligible Services between Company and Customer.

# Definitions For the purposes of this BAA, capitalized terms shall have the meanings ascribed to them in Appendix A. Any capitalized terms used herein but not defined in Appendix A will have the meanings ascribed to them under HIPAA or the Services Agreement, respectively.

# Application This BAA shall only apply to HIPAA-Eligible Services purchased under the Services Agreement in an ordering document that expressly references and applies this BAA, and only to the extent that Customer is a Covered Entity or Business Associate.

# Required Uses and Disclosures Company may Process PHI: (a) for or on behalf of Customer to provide the HIPAA-Eligible Services as specified in the Services Agreement; and (b) as necessary for the proper management and administration of its business, provided that any disclosures of PHI by Company for this purpose are subject to reasonable assurances from the recipient that all such PHI will be held in confidence, only be used in accordance with Applicable Law and for the purpose for which it was disclosed to the recipient, and that recipient will notify Company of any instances in which the confidentiality of the PHI has been breached.

# Obligations of Company

Limitations on Use and Disclosure.

Company, its agents and its subcontractors shall: (i) not use or disclose PHI other than as permitted or required by this BAA or Applicable Law; (ii) not use or disclose PHI in any manner that violates Applicable Law; and (iii) only use or disclose the minimum amount of PHI necessary to provide the HIPAA-Eligible Services or to carry out Company's legal responsibilities.

Company is permitted, for Data Aggregation purposes to the extent permitted under HIPAA, to use, disclose, and combine PHI received from, or on behalf of, Customer by Company pursuant to this BAA with PHI, as defined by 45 C.F.R. 160.103, received by Company in its capacity as a Business Associate of other Covered Entities, to perform data analyses relating to the health care operations of the respective Covered Entities and/or Customer.

Company may delete, de-identify PHI, or further Secure PHI rendering it unusable and not easily recoverable, when it is no longer useful or necessary to accomplish the purpose for which it was collected, or in accordance with the retention schedule agreed by the parties.

Specific Use and Disclosures. Company may use PHI for the proper management and administration of Company's services or to carry out the legal responsibilities of Company. Company may use PHI to create de-identified health information in accordance with 45 C.F.R. 164.514(a)-(c) for the purpose of improving its AI services; Company shall ensure that its AI services do not store or retain PHI beyond what is necessary for the immediate interaction, unless explicitly authorized by the Covered Entity.
Safeguards. Company shall employ appropriate administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI and prevent the use or disclosure of PHI in any manner inconsistent with the terms of this BAA or the Services Agreement. Company shall further comply with its obligations under the HIPAA Rules relating to the treatment of electronic PHI, including Subpart C of 45 C.F.R. Part 164.
Secretary Audits. Company shall, in accordance with HIPAA, make available to Customer and the Secretary its documented internal practices and records relating to the Processing of PHI on behalf of Customer under this BAA to the extent necessary for Customer to satisfy its reporting and audit obligations to the Secretary.
Reporting. Customer acknowledges that Company will not Process any directly identifying information about the identities of Individuals other than certain limited device identifiers like IP address and that it may not be possible for Company to provide this information after it has been deleted, de-identified, or further Secured in accordance with Section 4.1(c). As such, and in relation to all reporting obligations under this BAA, Company will only be obligated to provide the limited device identifiers it Processes in the course of providing the HIPAA-Eligible Services when reporting on the identities of any Individuals who may have been affected by a Security Incident or Breach.
Designated Record Set. Notwithstanding anything to the contrary contained herein, Customer acknowledges that Company does not create or maintain a Designated Record Set on behalf of Customer in the course of providing the HIPAA-Eligible Services.
Requests for Production or Amendment.

If any Individual requests access to, or amendment of PHI or an accounting of disclosures directly from Company, Company will deny the request as invalid and redirect the Individual to submit its requests to Customer.

Customer will be responsible for making all determinations regarding the grant or denial of an Individual's request for access to, or the amendment of PHI and Company will make no such determinations. Except as otherwise required by law, only Customer will be responsible for releasing PHI to an Individual pursuant to a request for access to PHI. Any denial of access to PHI determined by Customer pursuant to 45 CFR Section 164.524 or 45 CFR Section 164.526 (as applicable), and conveyed to Company by Customer, shall be the responsibility of Customer, including resolution or reporting of all appeals and/or complaints arising from such denial.

Company will make available to Customer the information reasonably necessary for Customer to respond to a request for an accounting of disclosures in accordance with 45 CFR Section 164.528. The requested information may include: (1) the date of the disclosure; (2) the name of the entity or person who received the PHI, and if known, the address of such entity or person; (3) a brief description of the PHI disclosed; and (4) a brief statement of the purpose of such disclosure.

Subcontractors. In accordance with 45 CFR § 164.502(e)(1)(ii) and 45 CFR § 164.308(b)(2), and to the extent that Company discloses PHI to a subcontractor, Company will obtain and maintain a written agreement with each such subcontractor that ensures the confidentiality and reasonable protection of PHI and passes through substantially similar restrictions and obligations as those that apply to Company under this BAA.

Security Incidents & Breaches.

If Company becomes aware of any use or disclosure of PHI not provided for by this BAA, then Company will report such use or disclosure to Customer without unreasonable delay and in no case later than 30 calendar days after discovery of a Breach. Company also agrees to report any successful Security Incident to Customer, within the meaning of 45 CFR 164.304, no later than 30 calendar days of becoming aware of the Security Incident if it is not otherwise reported to Customer pursuant to 4.9(b) below.
Company agrees to report any Breach of Customer's Unsecured PHI in accordance with the requirements set forth in 45 CFR 164.400 et seq. as soon as is reasonably practicable, but in no event later than thirty (30) calendar days after it is discovered. A Breach report will include the following information: (i) a brief description of what happened, including the date of the Breach (if known) and the date of discovery; (ii) the identities or related identifiers of the individuals affected, if known; (iii) a brief description of the data elements involved in the Breach; and (iv) a brief description of the efforts Company is undertaking to investigate, mitigate, and resolve the Breach and any preventative measures being taken to prevent its recurrence. If the necessary information is not available to Company at the time of a Breach, then Company will continue to work diligently to investigate the Breach and will provide the information to Customer as it becomes available. Company shall maintain complete records regarding a Breach for the required period under 45 CFR 164.530(j) or such longer period as may be required under Applicable Law and will make such records available to Customer within a reasonable time upon Customer's written request.
In the event of an Incident caused by, or arising from, an act or omission of Company, or any subcontractor of Company, Company shall, where requested by Customer, provide the required notifications under 45 CFR 164.404 and 45 CFR 164.406.
The parties acknowledge that unsuccessful Security Incidents (e.g., pings and other broadcast attacks on a firewall, denial of service attacks, port scans, unsuccessful login attempts, or other security incidents that do not result in the unauthorized use, disclosure, modification, or destruction of Customer's PHI) occur within the normal course of business and the parties stipulate and agree that this paragraph constitutes notice by Company to Customer for such unsuccessful Security Incidents satisfying the notice requirement of the HIPAA Rules.

# Customer Obligations

Customer <mark>agrees that: (i) it shall comply with its obligations as a Covered Entity under Applicable Law(s) with respect to its use of the HIPAA-Eligible Services; (ii) it has provided notice and obtained (or shall obtain) all necessary consents (including without limitation, verifiable consent) and rights necessary under Applicable Law(s) for Company to Process any PHI transmitted to Company while providing the </mark>HIPAA-Eligible <mark>Services; (iii) it shall not transmit PHI to, or store PHI with, Company through any means other than through enabled HIPAA-Eligible Services to which this BAA applies; and (iv) it is solely responsible for configuring its HIPAA-Eligible Services in accordance with the HIPAA Rules.</mark>

Customer shall limit its transmission and storage of PHI to Company through the HIPAA-Eligible Services to the minimum extent necessary in accordance with 45 C.F.R. §164.502(b).

Customer shall notify Company of any limitations in its privacy practices under 45 C.F.R. §164.520, to the extent that such limitations may affect Company's ability to provide the HIPAA-Eligible Services or to use or disclose PHI.

Customer shall notify Company of any changes in permissions granted by an Individual, or restrictions on the use or disclosure of their PHI under 45 C.F.R. §164.522, to the extent that such changes or restrictions affect Company's provision of the HIPAA-Eligible Services or use or disclosure of PHI.

Customer shall not configure the HIPAA-Eligible Services in a manner that will cause Company to use or disclose PHI in any way that is impermissible under the HIPAA Rules.

# Term and Termination

Upon any termination or expiration, Company's consent to the storage and transmission of PHI as provided for herein shall be immediately revoked. The obligations of Company under this BAA shall survive termination or expiration to the extent that Company retains any PHI, and shall continue until Company has completed its obligations under Section 6.3 and all PHI has been returned or destroyed in accordance therewith. Sections of this BAA that by their nature should survive termination -- including without limitation those relating to confidentiality, breach notification for pre-termination incidents, record retention, and subcontractor obligations -- shall so survive.

In the event Customer downgrades any of its HIPAA-Eligible Services to a service or product offering that is not HIPAA-Eligible, then Company's consent to the transmission and storage of PHI through the Services shall be immediately revoked and, subject to Company's completion of its obligations under Section 6.3, all obligations of Company under this BAA shall terminate; provided, however, that obligations of Company that by their nature should survive, including those relating to confidentiality, breach notification for pre-downgrade incidents, and record retention, shall so survive until Company has completed its obligations under Section 6.3.

Upon the termination of the Services Agreement for any reason or downgrading of the Services to any non-HIPAA-Eligible Service offering, Company shall, upon receipt of a written request from Customer, either return or destroy all of Customer's PHI in its possession within sixty (60) days. Customer may request, and Company will provide, a written certification verifying that the return or destruction is complete.

# General

Amendment. If any of the regulations promulgated under HIPAA or the HITECH Act are amended or interpreted in a manner that renders this BAA inconsistent therewith, the parties shall cooperate in good faith to amend this BAA to the extent necessary to comply with such amendments or interpretations.
Interpretation. Any ambiguity in this BAA shall be resolved to permit the parties to comply with HIPAA and the HITECH Act.
Indemnification and Limitation of Liability. The parties agree and acknowledge that the indemnification obligations and limitation of liability provisions contained under the Services Agreement shall apply and govern each party's performance under this BAA.
Conflicting Terms. In the event that any terms of this BAA conflict with any terms of the Services Agreement, the terms of this BAA shall govern and control over the conflicting term in the Services Agreement. All other non-conflicting terms of the Services Agreement shall remain valid and enforceable.
**IN WITNESS WHEREOF,** the parties have caused this BAA to be signed by their authorized representatives.

---
**Signature Block**

- [LEGAL NAME OF CUSTOMER]
**Company**
- By:   Printed Name:   Title:
- Address for notices:  [CUSTOMER ADDRESS] With copy to: [CUSTOMER EMAIL]
- Address for notices:  [COMPANY ADDRESS] With copy to: [COMPANY EMAIL]

---

**Appendix A (Definitions)**

# "Applicable Law" means any national, state, or local laws, rules, regulations, and regulatory guidance applicable to either party's performance under the Services Agreement.

# "Breach" shall have the meaning ascribed to it under the HIPAA Rules (45 CFR 164.402).

# "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended by Subtitle D of the 2009 Health Information Technology for Economic and Clinical Health (HITECH) Act, and their implementing regulations.

# "HIPAA Rules" means the Privacy, Security, and Breach Notification and Enforcement Rules at 45 CFR Part 160 and Part 164.

# "HIPAA-Eligible Services" means the products and services listed in an ordering document that: (1) expressly references being governed by this BAA; and (2) expressly identifies the services as being "HIPAA-Eligible services" or "Advanced Compliance services", regardless of whether they are purchased individually or as a part of a service package.

# "Incident" means any use or disclosure of PHI not provided for in this BAA, any Breach, or any successful Security Incident involving the PHI of Customer that Company, or any subcontractor of Company, becomes aware of.

# "Individual" shall have the meaning ascribed to it under 45 CFR 160.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR 164.502(g) or other applicable federal or state law.

# "Process" means any operation or set of operations that are performed on information or on sets of information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

# "Protected Health Information" or "PHI" shall have the meaning ascribed to it in 45 CFR 160.103, but is limited to information Processed for, or on behalf of, Customer while providing HIPAA-Eligible Services.

# "Secure" means to render unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary in the guidance issued under section 13402(h)(2) of the Health Information Technology for Economic and Clinical Health Act (the "Guidance"), as updated from time to time, which, in the case of electronic information, requires that it be encrypted in accordance with certain standards specified in the Guidance.

# "Security Incident" means any access, use, disclosure, modification, transmission, or destruction, of PHI that is not authorized under the Services Agreement, this BAA, or is otherwise permissible under the HIPAA Rules.

# "Unsecured PHI" means PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in the Guidance.

--- 

This template was prepared and made publicly available by General Legal, PC ("General Legal"). It is provided for general reference purposes only and does not constitute, and should not be construed as, legal advice, or an endorsement or review of any particular transaction in which it is used. Use of this template does not create an attorney-client relationship with General Legal. General Legal has not reviewed, and takes no position on, any modifications made to this document or the deal terms it is used to document.
