Business Associate Agreement (HIPAA · United States)
AgendaMED · versión baa-2026-07-v1
BUSINESS ASSOCIATE AGREEMENT (HIPAA)
Between the clinic holding the account (the "Covered Entity") and AgendaMED (the "Business Associate"), pursuant to 45 CFR 164.504(e).
1. PERMITTED USES AND DISCLOSURES. Business Associate may use or disclose Protected Health Information (PHI) only to provide the contracted services (scheduling, patient records, communications, billing), as required by law, or as otherwise permitted by this Agreement. Business Associate will not use PHI for its own purposes, marketing, or sale.
2. SAFEGUARDS. Business Associate implements administrative, physical, and technical safeguards consistent with the HIPAA Security Rule: mandatory multi-factor authentication, encryption in transit and of secrets at rest, per-clinic isolation (row-level security), immutable (WORM) audit logging including clinical-record reads and exports, and least-privilege role-based access.
3. REPORTING. Business Associate will report to Covered Entity any use or disclosure not permitted by this Agreement, any Security Incident, and any Breach of Unsecured PHI without unreasonable delay (operational target: 72 hours from detection; in no case later than required by 45 CFR 164.410), including the information Covered Entity needs to fulfill its own notification duties.
4. SUBCONTRACTORS. Business Associate ensures that subcontractors that create, receive, maintain, or transmit PHI on its behalf (Google Cloud hosting; email delivery with PHI minimized) agree to restrictions and conditions at least as protective, through written agreements.
5. INDIVIDUAL RIGHTS. Business Associate provides the tools for Covered Entity to fulfill individuals' rights: access and portability (full patient-record export, audited), amendment (record editing), and accounting of disclosures (audit log).
6. HHS ACCESS. Business Associate will make its internal practices, books, and records relating to PHI available to the Secretary of HHS for purposes of determining compliance.
7. TERMINATION. Upon termination, Covered Entity may export all its data; thereafter Business Associate will return or destroy PHI where feasible, or extend protections to retained PHI where return is infeasible due to legal retention duties.
8. BREACH OF AGREEMENT. Covered Entity may terminate the service if Business Associate materially breaches this Agreement and fails to cure within a reasonable period.