Business Associate Agreement

(HIPAA / HITECH)

Exhibit D to the Software as a Service License Agreement

This Business Associate Agreement ("BAA") is entered into effective as of the Effective Date of the Parties' Software as a Service License Agreement (or such other date as the Parties may agree) by and between the healthcare provider, practice, or organization identified as Customer under that Agreement ("Covered Entity") and NoBackOffice, Inc. ("Business Associate") (each a "Party" and collectively, the "Parties").

Recitals

WHEREAS, Covered Entity is a "Covered Entity" as that term is defined under the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-91), as amended, ("HIPAA"), and the regulations promulgated thereunder by the Secretary of the U.S. Department of Health and Human Services ("Secretary"), including, without limitation, the regulations codified at 45 C.F.R. Parts 160 and 164 ("HIPAA Regulations");

WHEREAS, Business Associate performs Services for or on behalf of Covered Entity, and in performing said Services, Business Associate creates, receives, maintains, or transmits individually identifiable health information;

WHEREAS, the Parties intend to protect the privacy and provide for the security of the individually identifiable health information Disclosed by Covered Entity to Business Associate, or accessed, received, created, or transmitted by Business Associate, when providing Services. Such individually identifiable health information or Protected Health Information ("PHI") will be protected in compliance with HIPAA, the Health Information Technology for Economic and Clinical Health Act (Public Law 111-005) (the "HITECH Act") and its implementing regulations and guidance issued by the Secretary, and other applicable state and federal laws, all as amended from time to time; and

WHEREAS, Covered Entity is required under the HIPAA Regulations to enter into a Business Associate Agreement that meet certain requirements with respect to the Use and Disclosure of PHI, which are met by this BAA. Accordingly, to the extent required by HIPAA, Business Associate agrees to comply with this BAA.

WHEREAS, the Parties have entered into a certain Software as a Service License Agreement (the "Agreement"), which may involve transmission of PHI between the parties.

In consideration of the Recitals and for other good and valuable consideration, the receipt and adequacy of which is hereby acknowledged, the Parties agree as follows:

1. Definitions

The following terms shall have the meaning set forth below. Capitalized terms used in this BAA and not otherwise defined shall have the meanings ascribed to them in the HIPAA Regulations.

1.1 "Breach" shall have the meaning given under 45 C.F.R. § 164.402.

1.2 "Designated Record Set" shall have the meaning given such term under 45 C.F.R. § 164.501.

1.3 "Disclose" and "Disclosure" mean, with respect to PHI, the release, transfer, provision of access to, or divulging in any other manner of PHI outside of Business Associate or to other than member of its Workforce, as set forth in 45 C.F.R. § 160.103.

1.4 "Electronic PHI" or "e-PHI" means PHI that is transmitted or maintained in electronic media, as set forth in 45 C.F.R. § 160.103.

1.5 "Protected Health Information" and "PHI" mean any information, whether oral or recorded in any form or medium, provided by Covered Entity to Business Associate, that: (a) relates to the past, present or future physical or mental health or condition of an individual; the provision of health care to an individual, or the past, present or future payment for the provision of health care to an individual; (b) identifies the individual (or for which there is a reasonable basis for believing that the information can be used to identify the individual); and (c) shall have the meaning given to such term under 45 C.F.R. § 160.103. Protected Health Information includes e-PHI.

1.6 "Required by Law" shall have the meaning given to such term under 45 C.F.R. § 160.103.

1.7 "Security Incident" shall have the meaning given to such term under 45 C.F.R. § 164.304.

1.8 "Services" shall mean the services for or functions on behalf of Covered Entity performed by Business Associate pursuant to the Agreement between Covered Entity and Business Associate which may be in effect now or from time to time, or, if no such agreement is in effect, the services or functions performed by Business Associate that constitute a Business Associate relationship, as set forth in 45 C.F.R. § 160.103.

1.9 "Unsecured PHI" shall have the meaning given to such term under 42 U.S.C. § 17932(h), 45 C.F.R. § 164.402, and guidance issued pursuant to the HITECH Act including, but not limited to the guidance issued on April 17, 2009 and published in 74 Federal Register 19006 (April 27, 2009) by the Secretary.

1.10 "Use" or "Uses" mean, with respect to PHI, the sharing, employment, application, utilization, examination or analysis of such PHI within Business Associate's internal operations, as set forth in 45 C.F.R. § 160.103.

1.11 "Workforce" shall have the meaning given to such term under 45 C.F.R. § 160.103.

2. Obligations of Business Associate

2.1 Permitted Uses and Disclosures of Protected Health Information

Business Associate shall not Use or Disclose PHI received, accessed, maintained, or created for or on behalf of Covered Entity except to perform the Services required by the Agreement, or as permitted by this BAA or Required by Law. Business Associate shall not Use or Disclose PHI in any manner that would constitute a violation of the HIPAA Regulations if so Used or Disclosed by Covered Entity. Without limiting the generality of the foregoing, Business Associate is permitted to (i) Use PHI for the proper management and administration of Business Associate; (ii) Use and Disclose PHI to carry out the legal responsibilities of Business Associate, provided that with respect to any such Disclosure either: (a) the Disclosure is Required by Law; or (b) Business Associate obtains an agreement from the person to whom the PHI is to be Disclosed that such person will hold the PHI in confidence and will not Use and further Disclose such PHI except as Required by Law and for the purpose(s) for which it was Disclosed by Business Associate to such person, and that such person will notify Business Associate of any instances of which it is aware in which the confidentiality of the PHI has been breached; (iii) Use PHI for Data Aggregation purposes in connection with the Health Care Operations of Covered Entity; and (iv) Use PHI for purposes of de-identification of the PHI.

2.2 Adequate Safeguards of PHI

Business Associate shall comply with Subpart C of 45 C.F.R. Part 164 with respect to PHI, to reasonably and appropriately protect the confidentiality, integrity, and availability of e-PHI that it creates, receives, maintains or transmits on behalf of Covered Entity.

2.3 Mitigation

Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a Use or Disclosure of PHI by Business Associate in violation of the requirements of this BAA.

2.4 Reporting Security Incidents and Non-Permitted Uses or Disclosures

Business Associate shall notify Covered Entity in writing of any Security Incident or Use or Disclosure by Business Associate, members of its Workforce, or its Subcontractors that is not specifically permitted by this BAA no later than five (5) calendar days of "discovery" within the meaning of the HITECH Act. Notwithstanding the foregoing, Business Associate and Covered Entity acknowledge the ongoing existence and occurrence of attempted but ineffective Security Incidents that are trivial in nature, such as pings and other broadcast service attacks, and Covered Entity acknowledges and agrees that no additional notification to Covered Entity of such ineffective Security Incidents is required, as long as no such incident results in unauthorized access, Use or Disclosure of PHI. Business Associate shall investigate each unauthorized access, acquisition, Use or Disclosure of PHI that it creates, receives, maintains, or transmits for or on behalf of Covered Entity. If such Security Incident or non-permitted Use or Disclosure constitutes a reportable Breach of Unsecured PHI, then Business Associate shall comply with the requirements of Section 2.5 below.

2.5 Breach of Unsecured PHI

Business Associate shall provide a written report to Covered Entity of such Breach without unreasonable delay but no later than five (5) calendar days after "discovery" of the Breach within the meaning of the HITECH Act. Such notice shall include the identification of each individual whose Unsecured PHI has been, or is reasonably believed by Business Associate to have been, accessed, acquired, or disclosed in connection with such Breach. Business Associate also shall provide any additional information reasonably requested by Covered Entity for purposes of investigating the Breach and any other available information that Covered Entity is required to include to the individual under 45 C.F.R. § 164.404(c) or applicable state law at the time of notification or promptly thereafter as information becomes available. Business Associate's notification of a Breach of Unsecured PHI under this Section shall comply in all respects with each applicable provision of Section 13400 of Subtitle D (Privacy) of ARRA, the HIPAA Rules, related guidance issued by the Secretary or the delegate of the Secretary from time to time and applicable state law. Business Associate shall cooperate with Covered Entity in meeting Covered Entity's obligations with respect to such Breach. Covered Entity shall have sole control over the timing and method of providing notification of such Breach to the affected individual(s), the Secretary and, if applicable, the media.

2.6 Delegated Responsibilities

To the extent that Business Associate carries out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, Business Associate must comply with the requirements of Subpart E that apply to Covered Entities in the performance of such obligations. Business Associate agrees, in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, to require that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such information.

2.7 Availability of Internal Practices, Books, and Records to Government

Business Associate agrees to make its internal practices, books and records relating to the Use and Disclosure of Covered Entity's PHI available to the Covered Entity and the Secretary for purposes of determining the Business Associate's and the Covered Entity's compliance with HIPAA, the HIPAA Regulations, and the HITECH Act.

2.8 Access to and Amendment of Protected Health Information

To the extent that Business Associate maintains a Designated Record Set on behalf of Covered Entity and within ten (10) business days of such request by Covered Entity, Business Associate shall (a) make the PHI it maintains (or which is maintained by its Subcontractors) in such Designated Record Set available to Covered Entity for inspection and copying or, if requested by Covered Entity, to an individual, to enable Covered Entity to fulfill its obligations under 45 C.F.R. § 164.524; or (b) amend the PHI it maintains (or which is maintained by its Subcontractors) in such Designated Record Set to enable Covered Entity to fulfill its obligations under 45 C.F.R. § 164.526. If Business Associate maintains PHI in a Designated Record Set electronically, Business Associate shall provide such information in the electronic form and format requested by Covered Entity if it is readily reproducible in such form and format, and, if not, in such other form and format agreed to by Covered Entity to enable Covered Entity to fulfill its obligations under 45 C.F.R. § 164.524(c)(2).

2.9 Accounting

Business Associate and its Subcontractors shall make available to Covered Entity the information required to provide an accounting of disclosures to enable Covered Entity to fulfill its obligations under 45 C.F.R. § 164.528.

2.10 Use of Subcontractors

Business Associate shall require each of its Subcontractors that creates, receives, maintains, or transmits PHI on behalf of Business Associate, to execute a written agreement that includes substantially the same restrictions and conditions that apply to Business Associate under this BAA with respect to PHI.

2.11 Minimum Necessary

Business Associate (and its Subcontractors) shall, to the extent practicable, limit its request, Use, or Disclosure of PHI to the minimum amount of PHI necessary to accomplish the purpose of the request, Use or Disclosure, in accordance with 42 U.S.C. § 17935(b) and 45 C.F.R. § 164.502(b)(1) or any other guidance issued thereunder.

2.12 Qualified Service Organization

Business Associate acknowledges that it may be a Qualified Service Organization ("QSO"), as defined in 42 C.F.R. § 2.11, with regard to the services provided to Covered Entity. To the extent Business Associate qualifies as a QSO with regard to the services provided to Covered Entity, Business Associate acknowledges that certain PHI may not be Disclosed or re-disclosed under the rules addressing the Confidentiality of Alcohol and Drug Abuse Patient Records pursuant to 42 C.F.R. Part 2 ("Confidentiality Regulations") without the individual's written consent, even though such Disclosure or re-disclosure might be permitted by HIPAA or other laws. Further, Business Associate agrees to be fully bound by the Confidentiality Regulations in receiving, storing, processing, transmitting, transporting or otherwise dealing with any PHI that is subject to the Confidentiality Regulations. Business Associate will also resist in judicial proceedings any efforts to obtain applicable PHI except as permitted by the Confidentiality Regulations.

2.13 Compliance with Security Rule

Business Associate shall comply with the HIPAA Security Rule, which shall mean the Standards for Security of Electronic Protected Health Information at 45 C.F.R. Part 160 and Subparts A and C of Part 164, as amended by ARRA and the HITECH Act. The term "Electronic Health Record" or "EHR" as used in this BAA shall mean an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff. In accordance with the Security Rule, Business Associate agrees to implement the administrative safeguards set forth at 45 C.F.R. § 164.308, the physical safeguards set forth at 45 C.F.R. § 164.310, the technical safeguards set forth at 45 C.F.R. § 164.312, and the policies and procedures set forth at 45 C.F.R. § 164.316, to reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the Security Rule. Business Associate acknowledges that, effective on the Effective Date of this BAA: (a) the foregoing safeguards, policies, and procedures requirements shall apply to Business Associate in the same manner that such requirements apply to Covered Entity; and (b) Business Associate shall be liable under the civil and criminal enforcement provisions set forth at 42 U.S.C. § 1320d-5 and 1320d-6, as amended from time to time, for failure to comply with the safeguards, policies, and procedures requirements and any guidance issued by the Secretary from time to time with respect to such requirements. The Business Associate shall require that any agent, including a subcontractor, to whom it provides such PHI agrees to implement reasonable and appropriate safeguards to protect the PHI and report to the Covered Entity any Security Incident of which it becomes aware.

3. Term and Termination

3.1 Term

The term of this BAA shall be effective as of the Effective Date of the Agreement and shall terminate as of the later of the date of termination of the Agreement, or such later date when all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity.

3.2 Termination for Cause

In addition to and notwithstanding the termination provisions set forth in any Agreement, upon Covered Entity's knowledge of a material breach or violation of this BAA by Business Associate, Covered Entity shall Notify Business Associate of the breach in writing, and provide an opportunity for the Business Associate to cure the breach or end the violation within fifteen (15) days of such notification; provided that if Business Associate fails to cure the breach or end the violation within such time period to the satisfaction of Covered Entity, Covered Entity may immediately terminate this BAA and the Agreement upon written notice to Business Associate.

3.3 Return or Destruction of PHI / Continuing Obligations

Upon termination of this BAA for any reason, Business Associate, with respect to PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, shall:

  • Retain only that PHI which is necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities;
  • Return to Covered Entity or, if agreed to by Covered Entity, destroy the remaining PHI that the Business Associate still maintains in any form;
  • Continue to use appropriate safeguards and comply with the provisions of this Business Associate Agreement to prevent use or disclosure of the PHI, other than as provided for in this Section, for as long as Business Associate retains the PHI;
  • Not use or disclose the PHI retained by Business Associate other than for the purposes for which such PHI was retained and subject to the same conditions set out at Section 2.1(i) and (ii) which applied prior to termination; and
  • Return to Covered Entity or, if agreed to by Covered Entity, destroy the PHI retained by Business Associate when it is no longer needed by Business Associate for its proper management and administration or to carry out its legal responsibilities.

3.4 Survival

The obligations of the Business Associate under Section 3.3 shall survive the termination of the term of this BAA.

4. Indemnification

Business Associate shall indemnify, defend, and hold harmless the Covered Entity from and against any and all losses, expense, damage, or injury (including, without limitation, all costs and reasonable attorney's fees) that the Covered Entity may sustain as a result of third party claims arising out of: (a) a breach of this BAA by Business Associate or its agents or Subcontractors, including but not limited to any unauthorized use, disclosure, or breach of PHI; or (b) Business Associate's failure to notify any and all parties required to receive notification of any Breach of Unsecured PHI pursuant to this Agreement.

Notwithstanding the foregoing, nothing in this Section shall limit any rights that any of the Indemnified Parties may have to additional remedies under applicable law for any acts or omissions of Business Associate or its agents or Subcontractors.

5. Miscellaneous

5.1 Amendment to Comply with Law

To the extent applicable, amendments or modification to HIPAA or the HITECH Act or any applicable law may require amendments to certain provisions of this BAA. Amendments shall only be effective if executed in writing and signed by a duly authorized representative of each Party. The Covered Entity may terminate the term of this BAA immediately upon notice to the Business Associate in the event that the Business Associate does not amend this BAA to comply with any amendments or modification to HIPAA or the HITECH Act or any applicable law. In the event that a provision of this BAA is contrary to a provision of an Agreement, the provision of this BAA shall control. Otherwise, this BAA shall be construed under, and in accordance with, the terms of such Agreement, and shall be considered an amendment of and supplement to such Agreement, subject to Section 5.3 below.

5.2 Notices

Any notices or communications hereunder shall be in writing and shall be sent via email and by a nationally recognized courier service with delivery confirmation, such as FedEx, via overnight delivery at the addresses designated by the Parties. A new delivery address may be designated by notice.

5.3 Relationship of Parties

Notwithstanding anything to the contrary in any Agreement, Business Associate is an independent contractor and not an agent of Covered Entity under this BAA. Business Associate has the sole right and obligation to supervise, manage, contract, direct, procure, perform or cause to be performed all Business Associate obligations under this BAA.

5.4 Interpretation

This BAA shall be interpreted as broadly as necessary to implement and comply with HIPAA, the HIPAA Regulations and the HITECH Act. The parties agree that any ambiguity in this BAA shall be resolved in favor of a meaning that complies and is consistent with such laws.

5.5 No Third Party Beneficiaries

Nothing express or implied in this BAA is intended to confer, nor shall anything herein confer, upon any person other than the Parties and the respective successors or assigns of the Parties, any rights, remedies, obligations, or liabilities whatsoever.

5.6 State Privacy Laws

Business Associate shall comply with state laws to the extent that such state privacy laws are applicable.

5.7 Counterparts; Electronic Signatures

This BAA may be executed in one or more counterparts, all of which together shall constitute only one agreement. If any signature is delivered by facsimile or email or is signed in any electronic format, such signature shall create a valid and binding obligation with the same force and effect as if such signature were handwritten.

5.8 Entire Agreement

This BAA constitutes the entire agreement between the parties related to the subject matter of this BAA, except to the extent that the Agreement imposes more stringent requirements related to the use and protection of PHI upon Business Associate. This BAA supersedes all prior negotiations, discussions, representations, or proposals, whether oral or written. This BAA may not be modified unless done so in writing and signed by a duly authorized representative of both parties. If any provision of this BAA, or part thereof, is found to be invalid, the remaining provisions shall remain in effect.

5.9 Assignment

This BAA may not be assigned, in whole or in part, without the written consent of the other party. Any attempted assignment in violation of this provision shall be null and void.

5.10 Audit Rights

Covered Entity or its advisors may, upon ten (10) days' advance notice, conduct an audit of Business Associate's books, records, and policies relevant to the services Business Associate provides to Covered Entity. Such audits may occur no more than once annually. Any and all costs associated with such audits are the responsibility of the Covered Entity. Notwithstanding the above, in the event of a Breach of Unsecured PHI or a Security Incident Covered Entity or its advisors may, upon two (2) days notice, conduct an audit of Business Associate's books, records and policies relevant to the services Business Associate provides to Covered Entity and any and all reasonable costs associated with such audits are the responsibility of the Business Associate. The provisions of this Section 5.10 shall survive notwithstanding the termination of the Term of this Agreement.

This BAA is Exhibit D to the Software as a Service License Agreement. See also our Privacy Policy.