Business Associate Agreement
This Business Associate Agreement ("BAA") supplements and is incorporated into the Terms of Service between QSP Central ("Business Associate," "QSP Central," "we," "us") and the organization that accesses the QSP Central care-operations platform (the "Covered Entity" or "Customer"). It governs the parties' obligations with respect to Protected Health Information ("PHI") and is required by the HIPAA Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164). Where this BAA conflicts with the Terms of Service regarding PHI, this BAA controls.
1. Definitions
Capitalized terms not defined here have the meaning given in the HIPAA Rules. "PHI" means Protected Health Information, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Customer. "Security Incident," "Breach," "Unsecured PHI," "Required by Law," and "Subcontractor" have the meanings in 45 C.F.R. §§ 164.304, 164.402, and 160.103.
2. Permitted uses and disclosures
- Business Associate may use and disclose PHI only as necessary to provide the Service to Customer, as permitted or required by this BAA, or as Required by Law.
- Business Associate may use PHI for its own proper management and administration, and to carry out its legal responsibilities, provided that any disclosure for those purposes is Required by Law or made under written assurances of confidentiality and breach notification from the recipient.
- Business Associate may use PHI to provide Data Aggregation services relating to Customer's health care operations, and to de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c).
- Business Associate will not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Customer, except as expressly permitted above.
- Business Associate will make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose.
3. Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with the HIPAA Security Rule with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided by this BAA. Current safeguards include encryption of PHI in transit and at rest, tenant data isolation, role-based access controls, audit logging of access to PHI, and a hosting environment covered by the hosting provider's own BAA.
4. Reporting and breach notification
- Business Associate will report to Customer any use or disclosure of PHI not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI of which it becomes aware, without unreasonable delay and in no case later than five (5) business days after discovery.
- The report will include, to the extent known, the identification of each individual whose Unsecured PHI was or is reasonably believed to have been involved, and the information Customer needs to meet its own notification obligations under 45 C.F.R. § 164.404.
- Routine, unsuccessful Security Incidents (e.g., pings, port scans, blocked log-in attempts) that do not result in unauthorized access to PHI are reported on an aggregate basis upon request.
5. Subcontractors
Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA, in accordance with 45 C.F.R. §§ 164.308(b)(2) and 164.502(e)(1)(ii).
6. Individual rights
- Access. Business Associate will make PHI in a Designated Record Set available to Customer (or, as directed, to the individual) as necessary for Customer to meet its access obligations under 45 C.F.R. § 164.524.
- Amendment. Business Associate will make PHI available for amendment and incorporate any amendments as directed by Customer under 45 C.F.R. § 164.526.
- Accounting. Business Associate will document and make available the information required for Customer to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528.
- Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance with the HIPAA Rules.
7. Term and termination
- This BAA is effective on the date Customer accepts it and continues until all PHI is returned or destroyed, or protections are extended under Section 8.
- Customer may terminate this BAA and the Service if Business Associate materially breaches a term and fails to cure within thirty (30) days of notice, or immediately if cure is not possible.
- On termination, Business Associate will, if feasible, return or destroy all PHI it maintains and retain no copies. Where return or destruction is not feasible, Business Associate will extend the protections of this BAA to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible, for as long as it retains the PHI.
8. Survival
The obligations of Business Associate under Section 7 with respect to retained PHI survive termination of this BAA for as long as such PHI is retained.
9. Miscellaneous
This BAA will be interpreted to permit compliance with the HIPAA Rules, and the parties will amend it as necessary to comply with changes in the HIPAA Rules. This BAA is governed by the laws of the State of North Dakota and by applicable federal law. Nothing in this BAA is intended to confer any rights on any third party.
10. Contact
Questions about this BAA, or to request the signed agreement, email qspcentral@gmail.com.