Business Associate Agreement
Stillbook LLC · version draft-1
You accept this agreement in-app when you create your account, and Stillbook countersigns it. It's here so you can read it first.
This Business Associate Agreement ("Agreement") is entered into between Stillbook LLC ("Business Associate") and the massage-therapy practice that has created a Stillbook account ("Provider"), effective on the date the Provider accepts it below.
1. Applicability. This Agreement applies to the extent the Provider is a Covered Entity under HIPAA and Business Associate creates, receives, maintains, or transmits Protected Health Information ("PHI") on the Provider's behalf. Where this Agreement applies, the Provider is the "Covered Entity." Nothing in this Agreement makes a Provider a Covered Entity, or subjects a Provider to the HIPAA Rules, if the Provider is not otherwise a Covered Entity under law.
2. Definitions. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164. Capitalized terms used but not otherwise defined in this Agreement — including "Breach," "Unsecured PHI," "Security Incident," "Subcontractor," "Designated Record Set," and "Protected Health Information" — have the meanings given in the HIPAA Rules. "PHI" means Protected Health Information that Business Associate creates, receives, maintains, or transmits on behalf of the Provider.
3. Permitted uses and disclosures. (a) Business Associate may use and disclose PHI only to perform the scheduling, charting, and client-management services the Provider has engaged Stillbook to provide, and as otherwise required by law. (b) Business Associate may also use PHI for its own proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes if the disclosure is required by law, or if Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as required by law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instance of which it is aware in which the confidentiality of the PHI has been breached.
4. No other uses; compliance with the Privacy Rule. Business Associate will not use or further disclose PHI other than as permitted or required by this Agreement or as required by law, and will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by the Provider (except as permitted under Section 3(b)). To the extent Business Associate carries out one or more of the Provider's obligations under Subpart E of 45 CFR Part 164, Business Associate will comply with the requirements of that Subpart that apply to the Provider in the performance of those obligations.
5. Minimum necessary. Business Associate will request, use, and disclose only the minimum PHI necessary to accomplish the purpose of the request, use, or disclosure, consistent with 45 CFR § 164.502(b).
6. Safeguards; Security Rule. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, including encryption in transit and at rest and tenant isolation between practices, and will comply with the applicable requirements of the Security Rule (45 CFR Part 164, Subparts A and C) with respect to electronic PHI.
7. Subcontractors. Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees, by written contract, to the same restrictions and conditions that apply to Business Associate under this Agreement, including compliance with the applicable requirements of the Security Rule with respect to electronic PHI.
8. Reporting. (a) Business Associate will report to the Provider any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, and any Breach of Unsecured PHI, without unreasonable delay and in no case later than ten (10) business days after discovery, along with the information the Provider needs to meet its own notification obligations under 45 CFR § 164.404 (to the extent known: the identity of each affected individual, a description of what happened, the types of information involved, and the mitigation steps taken), supplementing promptly as information becomes available. A Breach is treated as discovered in accordance with 45 CFR § 164.410(a)(2). (b) Business Associate will report to the Provider any Security Incident of which it becomes aware. (c) The parties agree that this Agreement constitutes notice of the ongoing occurrence of unsuccessful Security Incidents — routine, unsuccessful attempts to penetrate or disrupt Business Associate's systems, such as pings, port scans, blocked firewall or denial-of-service attempts, and failed log-in attempts — that do not result in unauthorized access to, or acquisition, use, or disclosure of, PHI; no additional per-incident notice is required for them, and any incident that results in such access or acquisition is reported under (a) or (b). (d) Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement.
9. Access, amendment, and accounting. Business Associate will make PHI in a Designated Record Set available to the Provider as needed to satisfy the Provider's obligations under 45 CFR § 164.524; will make PHI in a Designated Record Set available for amendment and incorporate any amendments the Provider directs, as required by 45 CFR § 164.526; and will make available the information required for the Provider to provide an accounting of disclosures under 45 CFR § 164.528.
10. Availability of records to HHS. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, the Provider available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining the Provider's compliance with the HIPAA Rules.
11. Term. This Agreement is effective on acceptance and continues until the Provider's account is closed or the underlying services end, and thereafter until all PHI is returned or destroyed in accordance with Section 12(c).
12. Termination. (a) The Provider may terminate this Agreement and the underlying services if the Provider determines that Business Associate has violated a material term of this Agreement and Business Associate has not cured the violation within thirty (30) days of written notice, or immediately if cure is not feasible. (b) If Business Associate learns of a pattern of activity or practice of the Provider that would constitute a material breach of this Agreement, Business Associate may require the Provider to cure, and may terminate the services if the Provider does not. (c) On termination, Business Associate will return or securely destroy all PHI it maintains (including PHI held by Subcontractors), where feasible; where return or destruction is not feasible, Business Associate will notify the Provider, extend the protections of this Agreement to that PHI, and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as the PHI is maintained.
13. Miscellaneous. (a) Business Associate is an independent contractor of the Provider, and nothing in this Agreement creates an agency relationship between the parties. (b) The parties will amend this Agreement as necessary to comply with changes to the HIPAA Rules or other applicable law; Business Associate may effect such an amendment by notice and re-acceptance through the service. (c) A reference in this Agreement to a section of the HIPAA Rules means the section as in effect or as amended. (d) Any ambiguity in this Agreement will be resolved to permit compliance with the HIPAA Rules. (e) The obligations of Business Associate under Section 12(c) survive termination. (f) Nothing in this Agreement confers any right or remedy on any person other than the parties. (g) If this Agreement conflicts with the Terms of Service or any other agreement between the parties with respect to PHI, this Agreement controls.
This is a working draft provided so the acceptance flow can be exercised end to end. The final, binding Business Associate Agreement is provided by counsel and replaces this text before public launch.