THIS PAGE SETS OUT THE FORM OF AGREEMENT WE OFFER. IT IS NOT SELF-EXECUTING AND IS NOT
IN FORCE BETWEEN YOU AND INTELLIGENA LLC UNLESS AND UNTIL IT HAS BEEN
EXECUTED IN WRITING BY BOTH PARTIES. UNTIL THEN YOU MUST NOT UPLOAD, ENTER OR TRANSMIT
PROTECTED HEALTH INFORMATION THROUGH THE SERVICE.
To request execution, write to
legal@intelligena.com with your legal
entity name and the account it applies to.
1. Parties and definitions
This Business Associate Agreement (“BAA”) is between
you (“Covered Entity”) and
Intelligena LLC, a California limited liability company (“Business Associate”), and
supplements the Terms of Service.
Terms used but not defined here have the meaning given in the Health Insurance
Portability and Accountability Act of 1996, the Health Information Technology for
Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R.
Parts 160 and 164 (together, “HIPAA”).
“PHI” means Protected Health Information that Business
Associate creates, receives, maintains or transmits on Covered Entity’s behalf.
2. Business Associate’s obligations
Business Associate will:
- Not use or disclose PHI other than as this BAA permits, as the
Covered Entity directs, or as required by law — and in no case in a way that
would violate the Privacy Rule if done by Covered Entity itself.
- Implement safeguards. Use appropriate administrative, physical
and technical safeguards, and comply with the Security Rule (45 C.F.R. Part 164
Subpart C) with respect to electronic PHI.
- Report. Report to Covered Entity any use or disclosure not
permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI, in
each case without unreasonable delay and no later than ten (10) business
days after discovery, together with the information 45 C.F.R.
§164.410(c) requires. Unsuccessful attempts that do not result in unauthorised
access — pings, port scans, blocked login attempts and the like — are
reported on request in aggregate rather than individually.
- Flow down. Ensure that each subcontractor that creates, receives,
maintains or transmits PHI on its behalf agrees in writing to restrictions and
conditions at least as protective as those in this BAA.
- Access. Make PHI in a Designated Record Set available to Covered
Entity, or at its direction to the individual, so that Covered Entity can meet
§164.524, within fifteen (15) business days of a written request.
- Amendment. Make amendments to PHI in a Designated Record Set as
Covered Entity directs under §164.526.
- Accounting. Document and make available the information needed
for Covered Entity to respond to a request for an accounting of disclosures under
§164.528.
- Books and records. Make its internal practices, books and records
relating to PHI available to the Secretary of Health and Human Services for
determining Covered Entity’s compliance.
- Minimum necessary. Request, use and disclose only the minimum
amount of PHI necessary.
- Mitigate. Mitigate, to the extent practicable, any harmful effect
known to it of a use or disclosure in violation of this BAA.
3. Permitted uses and disclosures
Business Associate may use and disclose PHI only to perform the Service, and
additionally may use PHI for its own proper management and administration and to carry
out its legal responsibilities, and may disclose PHI for those purposes where the
disclosure is required by law or where it obtains reasonable assurances from the
recipient that the PHI will be kept confidential, used or further disclosed only as
required by law or for the purpose it was provided, and that the recipient will notify
Business Associate of any breach of confidentiality.
Business Associate may de-identify PHI in accordance with 45 C.F.R. §164.514(b)
and use the resulting de-identified data for any lawful purpose;
de-identified data is not PHI.
Business Associate will not use PHI to train any machine-learning model, and
will not permit any subcontractor to do so.
4. Covered Entity’s obligations
Covered Entity will:
- obtain every consent, authorisation and permission necessary for Business
Associate to process PHI as contemplated;
- maintain and, where required, provide its own Notice of Privacy Practices, and
notify Business Associate of any limitation in it, of any change or revocation of an
individual’s permission, and of any restriction agreed under §164.522,
in each case to the extent it affects Business Associate’s use or disclosure;
- not request Business Associate to use or disclose PHI in any way that
would not be permitted if done by Covered Entity; and
- configure and use the Service appropriately, and be solely responsible for its own
HIPAA compliance, its own risk analysis, its own workforce training, and the acts of
its own workforce.
5. Term and termination
This BAA takes effect on execution and continues until all PHI is returned or
destroyed or, if return or destruction is infeasible, until the protections here are
extended to it indefinitely. Covered Entity may terminate this BAA and the Service
immediately if Business Associate materially breaches it and fails to cure the breach
within thirty (30) days of written notice.
On termination, Business Associate will return or destroy all PHI it still holds,
including copies held by subcontractors, where feasible. Where it is not feasible
— including PHI in routine encrypted backups pending scheduled overwriting
— Business Associate will extend the protections of this BAA to that PHI and
limit further use and disclosure to the purposes that make return or destruction
infeasible, for as long as it retains it.
6. General
- Interpretation. Any ambiguity is resolved to permit compliance
with HIPAA. Amendments to HIPAA that change the parties’ obligations apply
automatically, and the parties will execute any amendment reasonably necessary.
- Precedence. Where this BAA conflicts with the Terms of Service,
this BAA controls with respect to PHI, and only with respect to PHI.
The limitation of liability, warranty disclaimer, no-personal-liability provision,
indemnity, dispute-resolution provision and governing law in the Terms of Service
apply to this BAA in full and are not modified by it.
- No third-party beneficiaries. Nothing in this BAA confers any
right on any individual or other third party, including any right to enforce it.
- Governing law. The laws of the State of
California, with disputes resolved as the Terms of Service
provide.