BUSINESS ASSOCIATE AGREEMENT
(Exhibit A to the Master Provider Services Agreement)
This Business Associate Agreement (this “BAA”) supplements and is made a part of the Master Provider Services Agreement between PaiKnight LLC (“Business Associate”) and Provider (“Covered Entity”). Capitalized terms used but not defined in this BAA have the meanings given to them in the HIPAA Rules.
1. Definitions.
“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164.
“PHI” means Protected Health Information limited to the information Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity. Other capitalized terms used herein (including “Business Associate”, “Covered Entity”, “Breach”, “Disclosure”, “Required by Law”, “Security Incident”, “Subcontractor,” “Unsecured PHI,” and “Use” have the meanings given in the HIPAA Rules.
2. Permitted Uses and Disclosures.
(a) Business Associate may Use and Disclose PHI only as necessary to perform the Services under the Agreement, as Required by Law, or as expressly permitted by this BAA. (b) Business Associate may Use PHI for the proper management and administration of Business Associate and to carry out its legal responsibilities. (c) Business Associate may Disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities provided that the Disclosures are Required by Law or Business Associate obtains reasonable assurances from the person to whom the PHI is Disclosed that it will be held confidentially and Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed, and that the person notifies Business Associate of any instance of which it becomes aware in which the confidentiality of the PHI has been breached. (d) Business Associate may Use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted under 45 C.F.R. Section 164.504(e)(2)(i)(B). (e) Business Associate may de-identify PHI in accordance with 45 C.F.R. Section 164.514(a)-(c) and Use and Disclose such de-identified data for any lawful purpose.
3. Obligations of Business Associate.
Business Associate shall: (a) not Use or further Disclose PHI other than as permitted or required by this BAA, the Agreement, or as Required by Law; (b) Use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, to prevent Use or Disclosure of PHI other than as provided by this BAA; (c) report to Covered Entity any Use or Disclosure of PHI not provided for by this BAA of which it becomes aware, including any Breach of Unsecured PHI as required by 45 C.F.R. Section 164.410, and any Security Incident of which it becomes aware; (d) in accordance with 45 C.F.R. Section 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to substantially the same restrictions, conditions, and requirements that apply to Business Associate with respect to such PHI; (e) make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. Section 164.524; (f) make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 C.F.R. Section 164.526; (g) maintain and make available the information required to provide an accounting of Disclosures to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. Section 164.528; (h) to the extent Business Associate is to carry out one or more of Covered Entity’s obligation(s) under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s); and (i) make its internal practices, books, and records available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules.
4. Breach Notification.
Business Associate shall report any Breach of Unsecured PHI to Covered Entity without unreasonable delay and in any event no later than thirty (30) calendar days after discovery of the Breach. The notification shall include, to the extent then known, the information required by 45 C.F.R. Section 164.410(c), and Business Associate shall provide additional information as it becomes available. Business Associate shall cooperate with Covered Entity in the investigation, mitigation, and notification of any Breach.
5. Offshore Access to PHI
Covered Entity expressly acknowledges and authorizes Business Associate’s access to PHI by Business Associate’s personnel and Subcontractors located outside the United States, including in the United Arab Emirates and the Philippines, subject to (i) the absence of any Payer-contract or state-law restriction prohibiting such offshore access, and (ii) Business Associate’s implementation of appropriate administrative, physical, and technical safeguards including: encrypted transmission, role-based access controls, multi-factor authentication, jurisdiction logging, workforce HIPAA training, and Subcontractor BAAs flowing the foregoing obligations through to all offshore personnel and vendors with access to PHI.
6. Obligations of Covered Entity
Covered Entity shall: (a) notify Business Associate of any limitation in its Notice of Privacy Practices, to the extent such limitation may affect Business Associate’s Use or Disclosure of PHI; (b) notify Business Associate of any changes in, or revocation of, the permission by an Individual to Use or Disclose PHI, to the extent such changes may affect Business Associate’s Use or Disclosure of PHI; (c) notify Business Associate of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. Section 164.522, to the extent such restriction may affect Business Associate’s Use or Disclosure of PHI; and (d) not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as set forth in Sections 2(b)-(d) above with respect to the proper management and administration and legal responsibilities of Business Associate and data aggregation services.
7. Term and Termination
This BAA is effective on the Effective Date of the Agreement and continues until termination or expiration of the Agreement. Upon termination, Business Associate shall return or destroy all PHI received from, created, maintained, or received by Business Associate on behalf of Covered Entity that Business Associate still maintains in any form, and shall retain no copies of such PHI; provided that, if such return or destruction is not feasible, Business Associate shall extend the protections of this BAA to the PHI and limit further Uses and Disclosures to those purposes that make the return or destruction infeasible for so long as Business Associate maintains such PHI.
8. Miscellaneous
(a) Regulatory Reference. A reference in this BAA to a section in the HIPAA Rules means the section as in effect or as amended. (b) Amendment. The Parties shall take such action as is necessary to amend this BAA from time to time as is necessary for compliance with the HIPAA Rules and any other applicable law. (c) Interpretation. Any ambiguity in this BAA shall be resolved to permit compliance with the HIPAA Rules. (d) Survival. The obligations of Business Associate under Section 7 survive termination of this BAA.
End of Business Associate Agreement (Exhibit A to the Master Provider Services Agreement).
Document path:
PaiKnight-Platform-Plan/_legal-docs/business-associate-agreement.md
Last revised: 2026-07-16