Skip to content
Legal

Business Associate Agreement

For customers who are HIPAA Covered Entities or Business Associates: how we handle Protected Health Information you send us.

Incorporated by reference into the Master Subscription Agreement at MSA §6.6.

All legal documents

NECESSITYWORKS, INC. — BUSINESS ASSOCIATE AGREEMENT

Version: 1.0 Published at: https://necessityworks.com/legal/baa Applies to: NecessityWorks, Inc. (Delaware) Applies when: Customer is a HIPAA Covered Entity (or a Business Associate of one) and discloses PHI to NW in connection with the Services


How this BAA is accepted

This BAA is incorporated by reference into the NW Master Subscription Agreement (“Agreement”) under §6.6 and applies automatically whenever Customer is a Covered Entity (or Business Associate of one) and discloses Protected Health Information (“PHI”) to NW. No separate signature is required: Customer is bound by this BAA by the same acceptance event that binds Customer to the Agreement (click-through, Order Form, or first use of the Platform).

Customer’s affirmative identification as a Covered Entity. NW will not knowingly Process PHI for a Customer that has not identified itself as a Covered Entity or Business Associate. Customer is responsible for identifying its HIPAA status to NW prior to disclosing PHI, either (a) by selecting the corresponding option in the Platform’s data-governance configuration, (b) by stating its HIPAA status in an Order Form, or (c) by sending written notice to [email protected].

Requesting a signed counterpart. A Customer that requires a signed counterpart of this BAA (e.g., to satisfy its own auditor’s documentation expectations under 45 C.F.R. § 164.504(e)) may request one in writing to [email protected]. NW will provide a counter-signed PDF that identifies Customer by legal name. The signed counterpart is evidentiary only; it does not modify the substantive terms of this BAA.


THE AGREEMENT

This Business Associate Agreement (“BAA”) supplements and forms part of the Master Subscription Agreement (the “Agreement”) between NecessityWorks, Inc. (“Business Associate” or “NW”) and the Customer that has accepted the Agreement and identified itself as a Covered Entity (or Business Associate of one) under HIPAA (“Covered Entity” or “Customer”). This BAA is intended to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (together with implementing regulations at 45 C.F.R. Parts 160 and 164, “HIPAA”).


1. Definitions

Terms used in this BAA have the meanings assigned in HIPAA, including the following:

1.1 “Breach” has the meaning in 45 C.F.R. § 164.402.

1.2 “Designated Record Set” has the meaning in 45 C.F.R. § 164.501.

1.3 “Electronic Protected Health Information” or “ePHI” has the meaning in 45 C.F.R. § 160.103.

1.4 “HHS” means the U.S. Department of Health and Human Services or any successor agency.

1.5 “Individual” has the meaning in 45 C.F.R. § 160.103.

1.6 “Privacy Rule” means 45 C.F.R. Part 160 and Subparts A and E of Part 164.

1.7 “Protected Health Information” or “PHI” has the meaning in 45 C.F.R. § 160.103, limited to information that Business Associate Creates, Receives, Maintains, or Transmits on behalf of Covered Entity under the Agreement.

1.8 “Required by Law” has the meaning in 45 C.F.R. § 164.103.

1.9 “Security Incident” has the meaning in 45 C.F.R. § 164.304.

1.10 “Security Rule” means 45 C.F.R. Part 160 and Subparts A and C of Part 164.

1.11 “Subcontractor” has the meaning in 45 C.F.R. § 160.103.

1.12 “Unsecured PHI” has the meaning in 45 C.F.R. § 164.402.

All other capitalized terms have the meanings assigned in the Agreement.


2. Permitted Uses and Disclosures of PHI

2.1 Services to Covered Entity. Business Associate may Use and Disclose PHI only as necessary to perform the Services under the Agreement and as permitted or required by this BAA, the Agreement, or applicable law.

2.2 Specific Permitted Uses and Disclosures. In addition, Business Associate may:

  1. Use PHI for proper management and administration of Business Associate or to carry out Business Associate’s legal responsibilities, as permitted by 45 C.F.R. § 164.504(e)(4)(i);

  2. Disclose PHI for proper management and administration of Business Associate or to carry out Business Associate’s legal responsibilities, provided that such Disclosure is Required by Law, or Business Associate obtains reasonable assurances from the recipient that: (i) the PHI will be held confidentially and Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed to the recipient, and (ii) the recipient will notify Business Associate of any instances of which it becomes aware in which the confidentiality of the PHI has been breached, as permitted by 45 C.F.R. § 164.504(e)(4)(ii);

  3. Provide Data Aggregation services relating to the Health Care Operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B), to the extent Covered Entity instructs Business Associate to do so;

  4. De-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c) and, once de-identified, use such information for its own purposes, provided that the de-identified information is not Re-identified. De-identified information is no longer PHI once properly de-identified.

2.3 No Other Uses. Business Associate will not Use or Disclose PHI in any manner that would violate HIPAA if done by Covered Entity, except as expressly permitted by this BAA or the Agreement.

2.4 No AI Training on PHI. Consistent with MSA §6.3, DPA §3.3, and the AI Services Supplement §4.1, Business Associate will not Use PHI to train, fine-tune, or otherwise improve any machine-learning or artificial-intelligence model that is made available to any other customer or third party. Tenant-scoped artifacts are permitted only where isolated to Covered Entity’s tenant.


3. Obligations of Business Associate

3.1 Safeguards. Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided by this BAA.

3.2 Minimum Necessary. Business Associate will make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the Use, Disclosure, or request.

3.3 Mitigation. Business Associate will use reasonable efforts to mitigate, to the extent practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI by Business Associate in violation of this BAA.

3.4 Subcontractors. Business Associate will enter into a written agreement with each Subcontractor that Creates, Receives, Maintains, or Transmits PHI on behalf of Business Associate. The agreement will impose obligations on the Subcontractor that are at least as protective as the obligations imposed on Business Associate under this BAA, in accordance with 45 C.F.R. § 164.502(e)(1)(ii) and 164.504(e)(5).

3.5 Access to PHI. Within ten (10) business days of a written request from Covered Entity, Business Associate will make available PHI that Business Associate Maintains in a Designated Record Set to Covered Entity, or as directed by Covered Entity, to an Individual, to enable Covered Entity to comply with 45 C.F.R. § 164.524. If the request for access is made directly to Business Associate by an Individual, Business Associate will forward the request to Covered Entity.

3.6 Amendment of PHI. Within ten (10) business days of a written request from Covered Entity, Business Associate will make any amendment(s) to PHI in a Designated Record Set that Covered Entity directs or agrees to pursuant to 45 C.F.R. § 164.526.

3.7 Accounting of Disclosures. Business Associate will maintain the information required to provide an accounting of Disclosures as required under 45 C.F.R. § 164.528. Within thirty (30) days of a written request from Covered Entity, Business Associate will make such information available to Covered Entity.

3.8 HHS Access. Business Associate will make its internal practices, books, and records, including policies and procedures and PHI, relating to the Use and Disclosure of PHI Received from, or Created or Received by Business Associate on behalf of, Covered Entity available to the Secretary of HHS for purposes of determining Covered Entity’s compliance with HIPAA.

3.9 Compliance Obligations. To the extent Business Associate is to carry out one or more of Covered Entity’s obligation(s) under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of such obligation(s).


4. Reporting

4.1 Unauthorized Use or Disclosure. Business Associate will report to Covered Entity any Use or Disclosure of PHI not permitted by this BAA of which Business Associate becomes aware, without unreasonable delay and in no event later than forty-eight (48) hours after discovery. [NEEDS COUNSEL REVIEW — 48 hours is tighter than HIPAA's "without unreasonable delay, and in no case later than 60 calendar days" standard in 45 C.F.R. § 164.410; we are adopting the tighter MSA commitment]

4.2 Security Incidents.

  1. Unsuccessful Security Incidents. The Parties acknowledge that unsuccessful Security Incidents (e.g., routinely logged unsuccessful login attempts, ping probes, port scans, malware blocked at perimeter) occur frequently and would be impractical to report individually. Business Associate reports such unsuccessful Security Incidents on request in aggregate summary form, and this BAA constitutes such notice where no separate request is made.

  2. Successful Security Incidents. Business Associate will notify Covered Entity of a successful Security Incident affecting ePHI without unreasonable delay and in no event later than forty-eight (48) hours after Business Associate’s confirmation of the Security Incident.

4.3 Breach of Unsecured PHI. Business Associate will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay and in no event later than forty-eight (48) hours after Business Associate’s discovery of the Breach, as required by 45 C.F.R. § 164.410.

4.4 Content of Notification. Each notification under this §4 will include, to the extent known at the time of notification and updated as further information becomes available:

  1. the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed;
  2. a brief description of what happened, including the date of the Breach or Security Incident and the date of discovery;
  3. a description of the types of Unsecured PHI involved;
  4. a description of the investigation, mitigation, and protective actions taken; and
  5. any other information reasonably requested by Covered Entity to comply with its own notification obligations under 45 C.F.R. §§ 164.404, 164.406, and 164.408.

4.5 Cooperation. Business Associate will cooperate with Covered Entity, at Covered Entity’s expense, in any investigation, notification, or remediation relating to a Breach, Security Incident, or unauthorized Use or Disclosure.


5. Obligations of Covered Entity

5.1 Notice of Privacy Practices. Covered Entity will notify Business Associate of any limitations in Covered Entity’s Notice of Privacy Practices in accordance with 45 C.F.R. § 164.520, to the extent such limitations may affect Business Associate’s Use or Disclosure of PHI.

5.2 Changes in Authorization. Covered Entity will notify Business Associate of any changes in, or revocation of, Permission by an Individual to Use or Disclose PHI, to the extent such changes may affect Business Associate’s Use or Disclosure of PHI.

5.3 Restrictions. Covered Entity will notify Business Associate of any restriction to the Use or Disclosure of PHI that Covered Entity has agreed to in accordance with 45 C.F.R. § 164.522, to the extent such restrictions may affect Business Associate’s Use or Disclosure of PHI.

5.4 Appropriate Requests. Covered Entity will not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except to the extent Business Associate may Use or Disclose PHI for the limited purposes set forth in §2.2 of this BAA.

5.5 Transmission. Covered Entity will not transmit to Business Associate any PHI that Business Associate has not agreed to Process, and will comply with the AUP when transmitting PHI through the Services.


6. Term and Termination

6.1 Term. This BAA commences on the effective date of the Agreement and continues for so long as Business Associate Creates, Receives, Maintains, or Transmits PHI on behalf of Covered Entity under the Agreement.

6.2 Termination for Cause. Upon either Party’s knowledge of a material breach of this BAA by the other Party, the non-breaching Party will provide notice to the breaching Party, specifying the nature of the breach. If the breaching Party does not cure the breach within thirty (30) days, the non-breaching Party may terminate this BAA (and, at its option, the Agreement) by providing written notice of termination. If cure is not feasible, the non-breaching Party may terminate immediately upon written notice. Each Party may also report the breach to HHS as required or permitted by law.

6.3 Return or Destruction of PHI.

  1. Upon termination or expiration of this BAA for any reason, Business Associate will, if feasible, return or destroy all PHI received from, or Created, Received, Maintained, or Transmitted on behalf of, Covered Entity, including PHI held by Subcontractors. Business Associate will retain no copies of PHI.

  2. If return or destruction of PHI is not feasible (e.g., because retention is required by law or operational necessity), Business Associate will extend the protections of this BAA to the PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible, for so long as Business Associate maintains the PHI.

  3. Business Associate will provide written certification of destruction upon Covered Entity’s request.

6.4 Data Portability. Consistent with MSA §6.10 and DPA §10, Covered Entity may export PHI from the Platform during the Term and for thirty (30) days after termination, after which Business Associate will delete PHI within sixty (60) days, except as permitted in §6.3(b).


7. Miscellaneous

7.1 Regulatory Changes. The Parties agree to amend this BAA from time to time as necessary to comply with changes to HIPAA or related state laws. If either Party reasonably determines that this BAA does not comply with applicable law, that Party will notify the other Party and the Parties will cooperate in good faith to amend this BAA.

7.2 Conflict with Agreement. In the event of a conflict between this BAA and the Agreement, this BAA controls with respect to matters governing PHI and HIPAA compliance; otherwise, the Agreement controls.

7.3 Interpretation. Any ambiguity in this BAA will be resolved in favor of a meaning that permits the Parties to comply with HIPAA.

7.4 No Third-Party Beneficiaries. Except as expressly provided by HIPAA, nothing in this BAA confers any rights or remedies on any person other than the Parties.

7.5 Incorporated HIPAA Provisions. Each Party will comply with the HIPAA provisions applicable to its role (Covered Entity or Business Associate). This BAA is intended to meet the requirements of 45 C.F.R. § 164.504(e) (Privacy Rule business-associate contract requirements) and 45 C.F.R. § 164.314(a) (Security Rule business-associate contract requirements).


ACCEPTANCE

This BAA does not require a separate signature. It is binding on the Parties by operation of the Agreement, which incorporates this BAA by reference, and applies once Customer has identified itself to NW as a Covered Entity (or Business Associate of one). A Customer that requires a signed counterpart may request one in writing to [email protected] under the procedure described in the “How this BAA is accepted” section above.

Join the Waitlist