Business Associate Agreement (BAA)
Overview
This Business Associate Agreement ("BAA") is a proposed template for Paz Technologies LLC d/b/a Data Hippo ("Business Associate") and the customer identified in the signed service agreement ("Customer"). Customer may be a Covered Entity or an upstream Business Associate; in the latter case, Data Hippo acts as its subcontractor. References below to Covered Entity mean Customer solely for allocating contractual instructions, notices, and assistance, without changing Customer's status under HIPAA.
This BAA takes effect only when it is separately executed in writing by Data Hippo and an eligible customer, or where it is expressly incorporated into a signed service agreement between the parties. It does not take effect merely by using Data Hippo's services, and it is not universally available: a BAA is offered only to customers whose account has been confirmed in writing by Data Hippo as eligible to process PHI. Publishing this template does not by itself create a BAA or any HIPAA business-associate relationship.
This template, including its liability allocation, is open to review and negotiation on a client-by-client basis. The executed version must identify the parties, effective date, covered services and deployments, notice contacts, and any agreed changes. PHI approval for one service does not approve other services, sandboxes, or third-party AI integrations. No website update changes an executed agreement. Statutory duties arising from the parties' actual activities apply regardless of eligibility labels or whether an agreement has been signed.
1. Definitions
Terms used but not otherwise defined, including Breach, Unsecured PHI, Security Incident, and Designated Record Set, have the meanings in the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164 ("HIPAA Rules"), as amended, including applicable HITECH Act requirements.
- Protected Health Information (PHI): Individually identifiable health information transmitted or maintained in any form or medium, as defined in 45 CFR § 160.103.
- Covered Entity: A health plan, health care clearinghouse, or health care provider that transmits health information in electronic form in connection with a transaction covered by HIPAA.
- Business Associate: Paz Technologies LLC d/b/a Data Hippo, acting as a business associate or subcontractor as defined in 45 CFR § 160.103.
2. Permitted Uses and Disclosures
Business Associate may use or disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the service agreement, provided that such use or disclosure would not violate the HIPAA Privacy Rule if done by Covered Entity or the minimum necessary policies and procedures of the Covered Entity.
Business Associate may use PHI for its proper management and administration or legal responsibilities. Disclosures for those purposes are permitted only if required by law or if the recipient provides reasonable assurances that the information will remain confidential, will be used or further disclosed only as required by law or for the disclosed purpose, and that the recipient will notify Business Associate of any known breach of its confidentiality. Uses, disclosures, and requests must meet applicable minimum-necessary requirements.
3. Obligations of Business Associate
3.1 Use and Disclosure Restrictions
Business Associate agrees to:
- Not use or disclose PHI other than as permitted or required by this BAA or as required by law
- Use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this BAA
- Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI
- Report to Covered Entity any use or disclosure of PHI not provided for by this BAA, any Breach of Unsecured PHI, and any Security Incident of which it becomes aware, as provided in Section 4
- Before a subcontractor creates, receives, maintains, or transmits PHI on its behalf, obtain a written agreement imposing the same applicable restrictions, conditions, and requirements, including compliance with the Security Rule for electronic PHI, in accordance with 45 CFR §§ 164.502(e), 164.308(b), and 164.314(a)
- Make available PHI in accordance with 45 CFR § 164.524
- Make available PHI for amendment and incorporate any amendments to PHI in accordance with 45 CFR § 164.526
- Make available the information required to provide an accounting of disclosures in accordance with 45 CFR § 164.528
- Make its internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance with HIPAA
For individual access, amendment, and accounting requests, Business Associate will provide assistance to Customer in time for Customer to meet applicable legal deadlines and any shorter agreed service deadlines. Requests received directly from individuals will be promptly forwarded to Customer unless Customer authorizes a direct response. When Customer is an upstream Business Associate, notices and assistance flow through Customer to the relevant Covered Entity, except where law requires otherwise.
3.2 Security Safeguards
Business Associate shall implement and maintain:
- Administrative safeguards including security management, workforce security, information access management, and security awareness training
- Physical safeguards including facility access controls and workstation security
- Technical safeguards including access control, audit controls, integrity controls, and transmission security
- Encryption of electronic PHI in transit and at rest within Business Associate-controlled systems used for the covered services, including applicable logs and backups; the signed service scope will allocate customer-managed key and infrastructure responsibilities without reducing either party's applicable HIPAA obligations
- Regular security risk assessments and remediation
4. Incident and Breach Notification
Business Associate will report unauthorized uses or disclosures and Security Incidents to Customer's designated security contact without unreasonable delay. For a Breach of Unsecured PHI, notice will be given without unreasonable delay and no later than 60 calendar days after discovery, or an earlier deadline agreed in writing or required by applicable law, subject to a lawful delay under 45 CFR § 164.412. Discovery has the meaning in 45 CFR § 164.410(a), including knowledge that reasonable diligence would have revealed. Completion of an investigation is not a condition of initial notice.
Notice will identify affected individuals to the extent possible and include the following information to the extent available, with prompt supplements as further information becomes available:
- The identification of each individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach
- A brief description of what happened, including the date of the breach and the date of discovery
- A description of the types of Unsecured PHI involved
- Steps individuals should take to protect themselves from potential harm
- A brief description of what Business Associate is doing to investigate the breach, mitigate losses, and protect against further breaches
- Available information needed for individual contact procedures and other notice content required by 45 CFR § 164.404(c)
Business Associate will mitigate known harmful effects to the extent practicable and cooperate with Customer's legally required response. Customer retains responsibility for notices to individuals, regulators, and media unless the parties expressly delegate that work in writing or law independently requires Business Associate to give notice. The parties may agree in writing on aggregate or standing notice for routine unsuccessful Security Incidents; no such arrangement excuses reporting an actual unauthorized use, disclosure, or Breach.
5. Obligations of Covered Entity
Covered Entity agrees to:
- Notify Business Associate of any limitation(s) in its notice of privacy practices that may affect Business Associate's use or disclosure of PHI
- Notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose their PHI
- Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is legally required to follow, to the extent it affects Business Associate's services
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule if done by Covered Entity
6. Term and Termination
This BAA shall remain in effect until terminated in accordance with this section. Either party may terminate this BAA:
- For cause upon 30 days written notice to the other party of a material breach, if the breach is not cured within the 30-day period
- Immediately if the other party is found to have breached a material term of this BAA and cure is not possible
- As otherwise provided in the service agreement
Upon termination, Business Associate shall:
- Return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity
- Retain no copies of such PHI
- If return or destruction is not feasible, extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible
Return or destruction will be completed promptly according to a written offboarding schedule, including PHI held by subcontractors. Any infeasibility, including legally required retention or non-separable backup copies, will be documented and communicated to Customer; retained PHI remains protected, access-restricted, and used only for the reason retention is necessary until return or destruction becomes feasible. Backup convenience alone does not establish infeasibility. Business Associate will confirm completion in writing on request.
7. Compliance with HITECH Act
Business Associate acknowledges that the HITECH Act applies certain provisions of the HIPAA Security and Privacy Rules directly to Business Associates. Business Associate agrees to comply with:
- All applicable requirements of the HIPAA Security Rule (45 CFR Parts 160 and 164, Subparts A and C)
- Privacy Rule obligations applicable to Business Associate and, to the extent it performs Customer's obligations under Subpart E of 45 CFR Part 164, the requirements applicable to those delegated obligations
- Civil and criminal penalties for violations of HIPAA as applied to Business Associates under HITECH
8. Miscellaneous
This BAA shall be interpreted in accordance with HIPAA and HITECH. Any ambiguity in this BAA shall be resolved to permit Covered Entity to comply with HIPAA and HITECH.
The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for Covered Entity to comply with the requirements of HIPAA, HITECH, and any other applicable law.
This BAA shall survive termination of the service agreement to the extent necessary for Business Associate to comply with its obligations regarding PHI.
The executed BAA controls conflicting service-agreement terms concerning required PHI protections. A signed customer-specific amendment expressly identifying the affected BAA provision may modify it only to the extent permitted by law. General website terms do not override this BAA.
9. Proposed Liability Allocation
The following mutual commercial terms are negotiable and apply only if included in the executed agreement. They allocate monetary liability between the parties, not statutory duties or regulatory authority. A signed customer-specific liability schedule expressly covering this BAA controls instead.
Fee Base. A single Fee Base applies to all capped claims under this BAA. It is measured at the first event giving rise to any such claim and equals the fees paid or payable for the covered services during the preceding 12 months. If that event occurs during the first 12 months of those services, use the fees paid or contractually committed for their initial 12-month period, including implementation fees. If the first event occurs after the covered services end, use their final 12-month service period instead. For services lasting less than 12 months, use the fees for that committed term, without annualizing them. Uncommitted renewals, taxes, and third-party pass-through charges are excluded.
General cap. Each party's total aggregate monetary liability arising out of this BAA will not exceed one times the Fee Base.
PHI protection cap. For claims arising from a breach of this BAA's confidentiality, privacy, security, or incident-notification obligations, the cap is two times the Fee Base instead of the general cap. This is not an additional pool: all capped claims together may not exceed two times the Fee Base, and ordinary claims remain subject to the general cap. Related events are treated as one event when calculating the Fee Base; the caps do not reset per individual, claim, or year.
Covered loss and exclusions. Neither party is liable to the other under this BAA for consequential, special, incidental, exemplary, or punitive damages, or lost profits, to the extent permitted by law. Reasonable, documented investigation, containment, legally required notification, and data-restoration costs attributable to the other party's breach are treated as direct damages subject to the applicable cap, not excluded merely because a third party performs the work. This BAA creates no standalone indemnity obligation. Unless a signed customer-specific schedule expressly provides otherwise, claims arising from the same acts or omissions covered by this BAA share these caps, whether asserted under this BAA, the service agreement, an indemnity, or another legal theory; these caps replace, rather than add to, service-agreement caps for those claims. Unrelated service-agreement claims remain governed by that agreement. The same loss cannot be recovered twice.
Exceptions and preserved duties. These caps and exclusions do not apply to a party's fraud, willful misconduct, gross negligence, or liability that cannot lawfully be limited. They do not limit payment of agreed service fees, either party's own compliance and remediation duties, required reporting, return or destruction of PHI, cooperation with HHS, or available equitable relief. They do not bind regulators, limit governmental fines or penalties, or restrict rights or remedies of individuals or other nonparties under applicable law.
Pilots and negotiated terms. No zero-dollar liability cap is intended for a free pilot: before any no-fee PHI engagement, the parties must sign a specific monetary cap or fee basis. Customers may request different caps, minimum amounts, insurance requirements, indemnities, or notice deadlines for review. Any change requires mutual written agreement and cannot waive mandatory HIPAA requirements.
10. Contact and Customer Review
For a customer-specific BAA review or proposed amendments, contact legal@datahippo.ai. The final agreement should be reviewed by the parties' legal advisers before execution; this public template is not a representation that a particular service or deployment is compliant.
For questions about this BAA or to report a potential breach, please contact:
Paz Technologies LLC d/b/a Data Hippo
HIPAA Compliance Officer
Email: legal@datahippo.ai
In case of a security incident or breach, please contact us immediately at the above email address or through your designated account representative.