Business Associate Agreement
HelloNote Business Associate Agreement
Date last updated: [INSERT DATE]
Effective Date: [INSERT DATE]
Test Version for Review: This template is intended for internal website testing and legal review before publication or customer acceptance.
This Business Associate Agreement, including any applicable exhibits or addenda, is entered into by and between [CUSTOMER LEGAL NAME], a covered entity or business associate under HIPAA, and HelloNote Purchaser, LLC, doing business as HelloNote, referred to in this Agreement as “HelloNote.”
This Agreement applies when Customer uses HelloNote’s services in a way that involves the creation, receipt, maintenance, or transmission of Protected Health Information, as defined under HIPAA.
SECTION 1: DEFINITIONS
For purposes of this Agreement, the following terms have the meanings set forth below. Terms not defined in this Agreement have the same meaning as under HIPAA.
Business Associate means HelloNote, to the extent HelloNote creates, receives, maintains, or transmits Protected Health Information on behalf of Customer.
Covered Entity means the healthcare provider, practice, clinic, organization, or other regulated entity using HelloNote’s services.
HIPAA means the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including the Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule, as amended.
Protected Health Information or PHI means individually identifiable health information that is created, received, maintained, or transmitted by HelloNote on behalf of Customer and is protected under HIPAA.
Electronic Protected Health Information or ePHI means PHI that is transmitted or maintained in electronic form.
Services means the HelloNote software platform, tools, features, support, integrations, and related services provided to Customer.
Subcontractor means any third party that creates, receives, maintains, or transmits PHI on behalf of HelloNote in connection with the Services.
SECTION 2: PURPOSE
Customer may disclose PHI to HelloNote, and HelloNote may create, receive, maintain, or transmit PHI on behalf of Customer, in connection with Customer’s use of the Services.
This Agreement sets forth the obligations of the parties regarding the use, disclosure, protection, and handling of PHI.
SECTION 3: PERMITTED USES AND DISCLOSURES BY HELLONOTE
HelloNote may use or disclose PHI only as permitted or required by this Agreement, the underlying subscription agreement, applicable law, or as otherwise authorized in writing by Customer.
HelloNote may use or disclose PHI for the following purposes:
- To provide, maintain, support, secure, improve, and operate the Services.
- To perform customer support, troubleshooting, training, onboarding, implementation, data migration, billing support, reporting, or technical assistance requested by Customer.
- To carry out HelloNote’s legal responsibilities.
- To use PHI for HelloNote’s proper management and administration, provided such use is permitted by HIPAA.
- To disclose PHI for HelloNote’s proper management and administration, provided the disclosure is required by law or HelloNote obtains reasonable assurances that the recipient will keep the information confidential and use or further disclose it only as required by law or for the purpose for which it was disclosed.
- To provide data aggregation services relating to Customer’s healthcare operations, if applicable and permitted by HIPAA.
- To de-identify PHI in accordance with HIPAA, after which the de-identified information will no longer be considered PHI.
HelloNote will not use or disclose PHI in a manner that would violate HIPAA if done by Customer, except where permitted for HelloNote’s proper management and administration, data aggregation, or as otherwise permitted by HIPAA.
SECTION 4: PROHIBITED USES AND DISCLOSURES
HelloNote will not:
- Use or disclose PHI except as permitted by this Agreement, the applicable subscription agreement, Customer’s written instructions, or applicable law.
- Sell PHI, except as permitted by HIPAA and with any required authorization.
- Use PHI for marketing purposes except as permitted by HIPAA and with any required authorization.
- Use or disclose PHI in a way that is inconsistent with Customer’s obligations under HIPAA, to the extent HelloNote is aware of such obligations.
- Use PHI for any purpose unrelated to providing, supporting, securing, or improving the Services, unless permitted by HIPAA.
SECTION 5: SAFEGUARDS
HelloNote will use appropriate administrative, physical, and technical safeguards to protect PHI from uses or disclosures not permitted by this Agreement.
With respect to ePHI, HelloNote will comply with applicable requirements of the HIPAA Security Rule, including safeguards designed to protect the confidentiality, integrity, and availability of ePHI.
HelloNote’s safeguards may include access controls, workforce training, authentication controls, encryption where appropriate, audit controls, secure hosting practices, backup procedures, incident response procedures, and other commercially reasonable security measures.
SECTION 6: REPORTING OF UNAUTHORIZED USES, DISCLOSURES, SECURITY INCIDENTS, AND BREACHES
HelloNote will report to Customer any use or disclosure of PHI not permitted by this Agreement of which HelloNote becomes aware.
HelloNote will report any Security Incident involving ePHI of which HelloNote becomes aware. For unsuccessful security events, such as routine pings, scans, failed login attempts, or similar events that do not result in unauthorized access, use, disclosure, modification, or destruction of ePHI, the parties agree that this Agreement serves as Customer’s notice unless otherwise required by law.
HelloNote will report any Breach of Unsecured PHI without unreasonable delay and in accordance with HIPAA. Such report will include, to the extent known and available:
- A description of what happened.
- The types of PHI involved.
- The individuals affected or reasonably believed to be affected.
- Steps HelloNote has taken or will take to investigate, mitigate, and remediate the issue.
- Information reasonably needed by Customer to meet its breach notification obligations.
SECTION 7: SUBCONTRACTORS
HelloNote may use subcontractors to support the Services. HelloNote will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of HelloNote agrees in writing to restrictions, conditions, and safeguards that are at least as protective as those that apply to HelloNote under this Agreement.
HelloNote remains responsible for its subcontractors’ performance of obligations related to PHI to the extent required by HIPAA.
SECTION 8: ACCESS TO PHI
To the extent Customer requires HelloNote’s assistance to meet its obligations under HIPAA, HelloNote will make PHI maintained in a Designated Record Set available to Customer or, as directed by Customer, to an individual, in accordance with HIPAA.
Customer is responsible for determining whether PHI is part of a Designated Record Set and for responding to individual requests unless otherwise agreed in writing.
SECTION 9: AMENDMENT OF PHI
To the extent Customer requires HelloNote’s assistance to meet its obligations under HIPAA, HelloNote will make PHI available for amendment and will incorporate amendments to PHI as directed by Customer and required by HIPAA.
Customer is responsible for determining whether an amendment is required.
SECTION 10: ACCOUNTING OF DISCLOSURES
HelloNote will document disclosures of PHI as required by HIPAA and will make such information available to Customer as reasonably necessary for Customer to respond to an individual’s request for an accounting of disclosures.
Customer is responsible for handling requests for an accounting of disclosures unless otherwise agreed in writing.
SECTION 11: ACCESS BY THE SECRETARY OF HHS
HelloNote will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
SECTION 12: CUSTOMER RESPONSIBILITIES
Customer is responsible for:
- Using the Services in compliance with HIPAA and other applicable laws.
- Obtaining and maintaining any required patient consents, authorizations, notices, and permissions.
- Configuring user access appropriately.
- Maintaining the confidentiality of login credentials.
- Ensuring that Customer’s workforce members are properly trained.
- Notifying HelloNote of any restrictions, limitations, or changes that may affect HelloNote’s use or disclosure of PHI.
- Not using the Services to request or require HelloNote to use or disclose PHI in a way that would violate HIPAA.
SECTION 13: MINIMUM NECESSARY
HelloNote will make reasonable efforts to use, disclose, and request only the minimum necessary PHI required to perform the Services or comply with applicable law, except where the minimum necessary standard does not apply under HIPAA.
Customer is responsible for limiting the PHI submitted to the Services to the minimum necessary for Customer’s use of the Services.
SECTION 14: TERM AND TERMINATION
This Agreement begins on the Effective Date and continues for as long as HelloNote creates, receives, maintains, or transmits PHI on behalf of Customer, unless terminated earlier in accordance with this Agreement or the applicable subscription agreement.
Either party may terminate this Agreement if the other party materially breaches this Agreement and fails to cure the breach within a reasonable period after written notice.
Upon termination of the Services, HelloNote will return or destroy PHI received from, or created or received by HelloNote on behalf of, Customer, if feasible.
If return or destruction is not feasible, HelloNote will continue to extend the protections of this Agreement to such PHI and will limit further uses and disclosures to those purposes that make return or destruction infeasible.
SECTION 15: DATA EXPORT AND RETENTION
Upon termination or expiration of the Services, Customer may request export of Customer data in accordance with HelloNote’s then-current data export procedures and applicable subscription terms.
HelloNote may retain copies of PHI as required by law, for backup, archival, audit, compliance, security, dispute resolution, or legitimate business continuity purposes, provided that HelloNote continues to protect such PHI in accordance with this Agreement.
SECTION 16: MITIGATION
HelloNote will mitigate, to the extent practicable, any harmful effect known to HelloNote resulting from a use or disclosure of PHI by HelloNote that violates this Agreement.
SECTION 17: NO THIRD-PARTY BENEFICIARIES
Nothing in this Agreement is intended to create any rights for third parties, including patients, clients, or individual users, except as required by applicable law.
SECTION 18: RELATIONSHIP TO OTHER AGREEMENTS
This Agreement supplements the subscription agreement, terms of service, order form, or other agreement between Customer and HelloNote.
If there is a conflict between this Agreement and another agreement between the parties regarding PHI, this Agreement controls with respect to PHI.
SECTION 19: REGULATORY REFERENCES
Any reference to HIPAA or another law means the law as amended from time to time. Any reference to a regulatory section means the section currently in effect or any successor provision.
SECTION 20: INTERPRETATION
This Agreement will be interpreted as broadly as necessary to permit the parties to comply with HIPAA. Any ambiguity will be resolved in favor of a meaning that permits compliance with HIPAA.
SECTION 21: NOTICES
Notices under this Agreement must be sent to:
For HelloNote:
HelloNote Purchaser, LLC
447 Broadway #435
New York, NY 10013 U.S.A.
Email: [INSERT LEGAL OR PRIVACY EMAIL]
For Customer:
The notice contact listed in Customer’s account, order form, or subscription records.
SECTION 22: ACCEPTANCE
By signing, clicking to accept, or using the Services in a manner that involves PHI, the parties agree to this Business Associate Agreement.
HelloNote Purchaser, LLC
By: ___________________________
Name: _________________________
Title: __________________________
Date: __________________________
Customer
Legal Name: ____________________
By: ___________________________
Name: _________________________
Title: __________________________
Date: __________________________