Regulatory Basis — HIPAA Business Associate Contract
45 CFR §164.502(e) — Disclosures to business associates; satisfactory assurances standard 45 CFR §164.502(e)(1)(ii) — Satisfactory assurances flow-down to subcontractors 45 CFR §164.504(e)(2) — Required business associate contract provisions 45 CFR §164.308 & §164.314(a) — HIPAA Security Rule safeguards for electronic PHI 45 CFR §164.410 — Breach notification obligations of a business associate HITECH Act (42 U.S.C. §17931 et seq.) — Direct statutory liability of business associates This is a template Business Associate Agreement that helps a covered entity obtain the "satisfactory assurances" the HIPAA Privacy Rule requires before protected health information (PHI) is shared with Summit Billing Services, Inc. . It is a starting framework, not legal or compliance advice; confirm it against your current arrangements and applicable state law before use.
BUSINESS ASSOCIATE AGREEMENT Under the HIPAA Privacy & Security Rules — 45 CFR §164.502(e) and §164.504(e)
This Business Associate Agreement ("Agreement") is entered into as of [Effective Date] by and between:
1. Riverside Health Clinic, LLC , of 500 Medical Center Drive, Austin, TX 78701 (the "Covered Entity"); and
2. Summit Billing Services, Inc. , of 1200 Commerce Blvd, Suite 300, Denver, CO 80202 (the "Business Associate").
The Covered Entity and the Business Associate are each a "Party" and together the "Parties." The Business Associate provides the following services that involve access to PHI: Medical claims processing, billing, coding, and accounts-receivable management for the Covered Entity's patients. . This Agreement supplements, and is incorporated into, the underlying services arrangement between the Parties, and governs the Business Associate's handling of PHI. Where a term in this Agreement conflicts with the underlying arrangement, this Agreement controls as to PHI.
Effective Date [Effective Date]
Covered Entity Riverside Health Clinic, LLC
Business Associate Summit Billing Services, Inc.
Regulatory Basis 45 CFR §164.502(e), §164.504(e) 1. Definitions
Capitalised terms not defined in this Agreement have the meanings given to them in the HIPAA Rules. In this Agreement: (a) "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164; (b) "Protected Health Information" or "PHI" has the meaning at 45 CFR §160.103, limited to information the Business Associate creates, receives, maintains, or transmits for or on behalf of the Covered Entity; (c) "Electronic PHI" or "ePHI" means PHI transmitted or maintained in electronic media; (d) "Breach," "Unsecured PHI," "Security Incident," "Required by Law," "Individual," "Designated Record Set," and "Subcontractor" have the meanings given in the HIPAA Rules; and (e) "Secretary" means the Secretary of the U.S. Department of Health and Human Services ("HHS") or any officer or employee to whom the Secretary's authority is delegated.
2. Permitted and Required Uses and Disclosures of PHI
The Business Associate may use and disclose PHI only: (a) as necessary to perform the services described in this Agreement or the underlying arrangement for the Covered Entity; (b) as Required by Law; and (c) as otherwise expressly permitted by this Agreement. Any use or disclosure of PHI by the Business Associate must be consistent with the minimum-necessary standard at 45 CFR §164.502(b) and §164.514(d). The Business Associate shall make uses, disclosures, and requests for PHI limited to the minimum necessary to accomplish the intended purpose. In addition, the Business Associate may use PHI for the Business Associate's own proper management and administration and to carry out its legal responsibilities, and may disclose PHI for such purposes only if the disclosure is Required by Law, or the Business Associate obtains reasonable written assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and the recipient notifies the Business Associate of any breach of confidentiality.
3. Prohibition on Other Uses and Disclosures
The Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law. The Business Associate shall not use or disclose PHI in any manner that would violate Subpart E of 45 CFR Part 164 (the Privacy Rule) if done by the Covered Entity, except to the extent the Business Associate is expressly permitted to do so under this Agreement for the Business Associate's own management, administration, or legal responsibilities. The Business Associate shall not sell PHI or use or disclose PHI for marketing except as permitted by the HIPAA Rules and only where authorised in writing by the Covered Entity.
4. Safeguards
The Business Associate shall use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to ePHI, to prevent the use or disclosure of PHI other than as provided by this Agreement. Without limitation, the Business Associate shall implement the safeguards required by 45 CFR §§164.308, 164.310, 164.312, and 164.316, and shall maintain a written information security programme reasonably designed to protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of the Covered Entity.
5. Reporting of Breaches and Security Incidents
The Business Associate shall report to the Covered Entity: (a) any use or disclosure of PHI not provided for by this Agreement of which it becomes aware; (b) any Security Incident with respect to ePHI of which it becomes aware; and (c) any Breach of Unsecured PHI, in accordance with 45 CFR §164.410. The Business Associate shall notify the Covered Entity of a Breach without unreasonable delay and no later than 10 calendar days after discovery, and such notice shall include, to the extent known, the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed, together with the other information the Covered Entity is required to include in notifications to Individuals under 45 CFR §164.404. The Parties acknowledge this Agreement as notice that unsuccessful, routine Security Incidents (such as pings, port scans, and blocked access attempts) that result in no unauthorised access to ePHI occur regularly, and no separate report of such events is required unless the Covered Entity requests a summary.
6. Subcontractors — Flow-Down of Obligations
In accordance with 45 CFR §164.502(e)(1)(ii) and §164.308(b)(2), the Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of the Business Associate agrees in writing to restrictions, conditions, and requirements at least as protective of the PHI as those that apply to the Business Associate under this Agreement, including compliance with the applicable Security Rule requirements with respect to ePHI. The Business Associate shall not permit a Subcontractor to use or disclose PHI in a manner that would not be permissible if done by the Business Associate. The Business Associate remains responsible to the Covered Entity for the acts and omissions of its Subcontractors.
7. Access, Amendment, and Accounting — Support for Individual Rights
To the extent the Business Associate maintains PHI in a Designated Record Set, the Business Associate shall: (a) make such PHI available to the Covered Entity, or as directed to the Individual, to satisfy the Covered Entity's obligations under 45 CFR §164.524 (right of access); (b) make PHI available for amendment and incorporate any amendments as directed by the Covered Entity under 45 CFR §164.526; and (c) maintain and make available the information required to provide an accounting of disclosures under 45 CFR §164.528. Where an Individual's request is delivered directly to the Business Associate, the Business Associate shall forward it to the Covered Entity within a reasonable time so the Covered Entity can respond within the timeframes the HIPAA Rules require.
8. Availability of Records to HHS
The Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by the Business Associate on behalf of, the Covered Entity available to the Secretary of HHS for purposes of determining the Covered Entity's and the Business Associate's compliance with the HIPAA Rules, in the time and manner designated by the Secretary. Disclosure to the Secretary under this clause does not waive any applicable legal privilege.
9. Compliance with the Covered Entity's Obligations
To the extent the Business Associate is to carry out one or more of the Covered Entity's obligations under Subpart E of 45 CFR Part 164, the Business Associate shall comply with the requirements of that Subpart that apply to the Covered Entity in the performance of those obligations. The Covered Entity shall notify the Business Associate of any limitation in its Notice of Privacy Practices, of any changes in or revocation of an Individual's permission to use or disclose PHI, and of any restriction on the use or disclosure of PHI to which the Covered Entity has agreed under 45 CFR §164.522, to the extent any such limitation, change, or restriction may affect the Business Associate's use or disclosure of PHI.
10. Mitigation and Confidentiality
The Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by the Business Associate in violation of this Agreement. The Business Associate shall keep all PHI confidential and shall ensure that its workforce is appropriately trained on, and bound by, obligations consistent with this Agreement. These confidentiality obligations survive the termination of this Agreement for so long as the Business Associate retains any PHI.
11. Term
This Agreement is effective as of [Effective Date] and continues in effect until all PHI provided by the Covered Entity to the Business Associate, or created or received by the Business Associate on behalf of the Covered Entity, is returned or destroyed in accordance with the Termination clause, or, if return or destruction is infeasible, until the protections of this Agreement are extended to that PHI as provided below.
12. Termination for Breach
The Covered Entity may terminate this Agreement and the underlying arrangement if it determines that the Business Associate has violated a material term of this Agreement, as authorised by 45 CFR §164.504(e)(2)(iii). Upon becoming aware of a material breach or violation by the Business Associate, the Covered Entity shall provide the Business Associate a period of 30 days to cure the breach or end the violation; if the Business Associate fails to cure within that period, or if cure is not possible, the Covered Entity may terminate this Agreement immediately. Where neither cure nor termination is feasible, the Covered Entity shall report the violation to the Secretary of HHS.
13. Return or Destruction of PHI on Termination
Upon termination of this Agreement, for any reason, the Business Associate shall, if feasible, return to the Covered Entity, or destroy, all PHI that the Business Associate still maintains in any form, and shall retain no copies of such PHI. This obligation extends to PHI held by the Business Associate's Subcontractors and agents. Where return or destruction is infeasible, the Business Associate shall notify the Covered Entity of the conditions that make return or destruction infeasible, shall extend the protections of this Agreement to such PHI, and shall limit further uses and disclosures of that PHI to those purposes that make return or destruction infeasible, for so long as the Business Associate retains the PHI. Destruction shall be carried out so that the PHI cannot be read or reconstructed, and the Business Associate shall certify destruction to the Covered Entity upon request.
14. Interpretation, Amendment, and Governing Law
Any ambiguity in this Agreement shall be resolved to permit the Covered Entity and the Business Associate to comply with the HIPAA Rules. The Parties shall amend this Agreement from time to time as necessary for the Parties to comply with the requirements of the HIPAA Rules and any successor law or regulation. Nothing in this Agreement is intended to confer any rights upon any third party. This Agreement is governed by the laws of the State of Texas and applicable federal law, except that federal law controls to the extent of any conflict affecting PHI.
IN WITNESS WHEREOF, the Parties have caused this Business Associate Agreement to be executed by their duly authorised representatives as of [Effective Date].
Covered Entity
__GAP[baa_ce_name|Riverside Health Clinic, LLC]__
__GAP[baa_ce_signatory|Dr. Maria Ellis, Privacy Officer]__
Dr. Maria Ellis, Privacy Officer
______________________
Business Associate
__GAP[baa_ba_name|Summit Billing Services, Inc.]__
__GAP[baa_ba_signatory|James Whitfield, Chief Compliance Officer]__
James Whitfield, Chief Compliance Officer
______________________