Business Associate Agreement
Our standard form. Accepting it is done from inside your organization, where the acceptance is recorded against the exact version you agreed to.
This is the standard HIPAA Business Associate Agreement under which TechGig acts as your Business Associate. It is pending counsel review; a negotiated form may apply for some clients.
1 Definitions
Capitalized terms have the meanings given in the HIPAA Rules (45 CFR Parts 160 and 164). "Covered Entity" is your organization; "Business Associate" is TechGig LLC.
2 Permitted Uses and Disclosures
Business Associate may use or disclose Protected Health Information (PHI) only as necessary to perform the services, as Required by Law, or as permitted by this Agreement and for its own proper management and administration. Business Associate will apply the Minimum Necessary standard and will not sell PHI or use it for marketing without authorization.
3 Safeguards
Business Associate will implement administrative, physical, and technical safeguards (including Security Rule requirements) that reasonably protect the confidentiality, integrity, and availability of electronic PHI it handles.
4 Subcontractors
Business Associate will ensure that any subcontractor that handles PHI on its behalf agrees in writing to restrictions at least as protective as those in this Agreement.
5 Reporting
Business Associate will report to Covered Entity any Breach of Unsecured PHI without unreasonable delay and no later than [NUMBER] calendar days after discovery, along with Security Incidents and any impermissible use or disclosure of which it becomes aware.
6 Individual Rights
At Covered Entity's request, Business Associate will make PHI available for access, amendment, and an accounting of disclosures as required by the HIPAA Rules, to the extent Business Associate holds such PHI.
7 Term and Termination
This Agreement is effective on acceptance and continues until all PHI is returned or destroyed. On termination, Business Associate will return or destroy PHI it maintains, or, where infeasible, extend these protections and limit further use.
8 Miscellaneous
Regulatory references are to the HIPAA Rules as amended. Ambiguities are resolved to permit compliance with the HIPAA Rules. To the extent this Agreement conflicts with the services agreement regarding PHI, this Agreement controls. [Insurance, indemnification, and governing law — pending counsel.]