QSP Central ← Back to home

Business Associate Agreement

Effective date: June 21, 2026 · Last updated: June 21, 2026

This Business Associate Agreement ("BAA") supplements and is incorporated into the Terms of Service between QSP Central ("Business Associate," "QSP Central," "we," "us") and the organization that accesses the QSP Central care-operations platform (the "Covered Entity" or "Customer"). It governs the parties' obligations with respect to Protected Health Information ("PHI") and is required by the HIPAA Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164). Where this BAA conflicts with the Terms of Service regarding PHI, this BAA controls.

1. Definitions

Capitalized terms not defined here have the meaning given in the HIPAA Rules. "PHI" means Protected Health Information, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Customer. "Security Incident," "Breach," "Unsecured PHI," "Required by Law," and "Subcontractor" have the meanings in 45 C.F.R. §§ 164.304, 164.402, and 160.103.

2. Permitted uses and disclosures

3. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with the HIPAA Security Rule with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided by this BAA. Current safeguards include encryption of PHI in transit and at rest, tenant data isolation, role-based access controls, audit logging of access to PHI, and a hosting environment covered by the hosting provider's own BAA.

4. Reporting and breach notification

5. Subcontractors

Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA, in accordance with 45 C.F.R. §§ 164.308(b)(2) and 164.502(e)(1)(ii).

6. Individual rights

7. Term and termination

9. Miscellaneous

This BAA will be interpreted to permit compliance with the HIPAA Rules, and the parties will amend it as necessary to comply with changes in the HIPAA Rules. This BAA is governed by the laws of the State of North Dakota and by applicable federal law. Nothing in this BAA is intended to confer any rights on any third party.

10. Contact

Questions about this BAA, or to request the signed agreement, email qspcentral@gmail.com.