Pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA)
and the Health Information Technology for Economic and Clinical Health Act (HITECH)
This Business Associate Agreement ("Agreement") is entered into as of the date last signed below ("Effective Date") by and between:
Zelavox, a company operating at zelavox.io ("Business Associate"); and
[COVERED ENTITY NAME], a [type of entity] located at [address] ("Covered Entity").
Covered Entity and Business Associate are collectively referred to herein as the "Parties."
WHEREAS, Covered Entity is a "Covered Entity" as defined under HIPAA; and
WHEREAS, Business Associate provides AI-powered document analysis services ("Services") to Covered Entity, and in connection with providing such Services, may receive, create, maintain, or transmit Protected Health Information ("PHI") on behalf of Covered Entity; and
WHEREAS, HIPAA and HITECH require that Covered Entity and Business Associate enter into a Business Associate Agreement prior to Business Associate receiving, accessing, or processing any PHI on behalf of Covered Entity;
NOW, THEREFORE, in consideration of the mutual promises and covenants contained herein, the Parties agree as follows:
Unless otherwise defined herein, all capitalized terms shall have the meanings assigned to them under HIPAA, HITECH, and their implementing regulations, including 45 CFR Parts 160 and 164.
Business Associate may use or disclose PHI only as follows:
Business Associate shall not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Covered Entity.
Business Associate operates a strict zero data retention architecture with respect to PHI:
Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI, including:
Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement. Business Associate shall obtain written agreement from all such Subcontractors prior to disclosing PHI to them.
Business Associate shall not:
Given Business Associate's zero data retention model, Business Associate does not maintain PHI beyond the duration of each transaction. To the extent Business Associate holds any PHI at the time of a request, Business Associate shall:
Business Associate shall report to Covered Entity:
Given Business Associate's zero data retention architecture, the scope of any potential Breach is limited to PHI actively being processed at the time of the incident, typically a window of less than ten (10) seconds.
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's or Business Associate's compliance with the HIPAA Rules.
Covered Entity shall notify Business Associate of any limitation in Covered Entity's Notice of Privacy Practices that affects Business Associate's use or disclosure of PHI.
Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose PHI, to the extent that such changes affect Business Associate's permitted or required uses and disclosures.
Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR § 164.522, to the extent that such restriction affects Business Associate's use or disclosure of PHI.
Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.
Covered Entity represents and warrants that it has obtained all necessary authorizations, consents, and permissions to submit PHI to Business Associate for processing under this Agreement.
This Agreement shall be effective as of the Effective Date and shall continue in effect until terminated by either Party in accordance with this Section 4, or until the Services Agreement between the Parties is terminated, whichever occurs first.
Either Party may terminate this Agreement immediately upon written notice if the other Party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) days of receiving written notice of the breach.
Given Business Associate's zero data retention model, upon termination of this Agreement:
Any reference in this Agreement to a section of HIPAA, HITECH, or their implementing regulations means the section as in effect or as amended.
The Parties agree to amend this Agreement as necessary to comply with changes in applicable law. Either Party may terminate this Agreement if the Parties are unable to agree on an amendment required to bring the Agreement into compliance with applicable law.
Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Rules.
Nothing in this Agreement shall confer any rights or remedies upon any person other than the Parties and their respective successors and permitted assigns.
This Agreement constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, understandings, negotiations, and discussions, whether oral or written, relating to such subject matter.
This Agreement shall be governed by and construed in accordance with the laws of [STATE], without regard to its conflict of law provisions, and applicable federal law including HIPAA and HITECH.
If any provision of this Agreement is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
Business Associate's liability under this Agreement shall be limited to direct damages and shall not exceed the total fees paid by Covered Entity to Business Associate in the three (3) months preceding the event giving rise to the claim. In no event shall Business Associate be liable for indirect, incidental, consequential, special, or punitive damages.
Given Business Associate's zero data retention architecture, Business Associate's exposure to liability arising from unauthorized disclosure of PHI is inherently limited to the brief window during which PHI is actively being processed, typically less than ten (10) seconds per transaction.
IN WITNESS WHEREOF, the Parties have executed this Business Associate Agreement as of the Effective Date.