Business Associate Agreement
Last updated: June 14, 2026
This Business Associate Agreement ("BAA") is entered into between CaseLift ("Business Associate") and the practice or organization that uses the CaseLift Service ("Covered Entity"). It supplements and is incorporated into the Terms of Service between the parties. It governs the handling of Protected Health Information (PHI) and is required by the HIPAA Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164) and the HITECH Act.
1. Definitions
Capitalized terms not defined here have the meanings given in the HIPAA Rules. "PHI" means Protected Health Information, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity. "Electronic PHI" (ePHI), "Breach," "Security Incident," "Required by Law," "Subcontractor," and "Designated Record Set" have the meanings in 45 C.F.R. §§ 160.103 and 164.402.
2. Permitted uses & disclosures by Business Associate
Business Associate may use and disclose PHI only:
- To perform the services described in the Terms of Service and as directed by Covered Entity;
- As Required by Law;
- For the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that disclosures are Required by Law or the recipient agrees in writing to protect the PHI and to notify Business Associate of any breach of confidentiality;
- To provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B); and
- To de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c); de-identified information is not PHI and is not subject to this BAA.
Business Associate will not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted above for management, administration, and data aggregation. Business Associate will not sell PHI and will not use or disclose PHI for marketing except as permitted by law and authorized by Covered Entity.
3. Obligations of Business Associate
- Safeguards. Implement administrative, physical, and technical safeguards (including those required by the Security Rule, 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316) that reasonably protect PHI, including encryption of ePHI in transit and at rest.
- Minimum necessary. Use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose.
- No impermissible use. Not use or disclose PHI other than as permitted by this BAA or Required by Law.
- Mitigation. Mitigate, to the extent practicable, any harmful effect of a use or disclosure of PHI in violation of this BAA that is known to Business Associate.
- Report. Report to Covered Entity any use or disclosure not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI of which it becomes aware, as set out in Section 5.
- Subcontractors. Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this BAA.
- Access. Make available PHI in a Designated Record Set to Covered Entity (or, as directed, to an individual) as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524.
- Amendment. Make available PHI for amendment and incorporate amendments as directed, consistent with 45 C.F.R. § 164.526.
- Accounting. Maintain and make available information required to provide an accounting of disclosures, consistent with 45 C.F.R. § 164.528.
- Books & records. Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining Covered Entity's compliance with the HIPAA Rules.
- Covered Entity obligations. To the extent Business Associate carries out an obligation of Covered Entity under the Privacy Rule, comply with the requirements of the Privacy Rule that apply to that obligation.
4. Obligations of Covered Entity
- Notify Business Associate of any limitation in its Notice of Privacy Practices, of any changes in or revocation of an individual's permission to use or disclose PHI, and of any restriction on use or disclosure to which Covered Entity has agreed, to the extent these affect Business Associate's use or disclosure of PHI.
- Obtain any consent, authorization, or permission required by law, including consent to record consultations, before using the Service to capture PHI.
- Not request that Business Associate use or disclose PHI in a manner that would not be permitted under the HIPAA Rules if done by Covered Entity, except as permitted under Section 2 for management, administration, and data aggregation.
5. Breach & Security Incident reporting
Business Associate will notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and no later than thirty (30) calendar days after discovery. The notification will include, to the extent known, the nature of the Breach, the PHI involved, the individuals affected, and the steps taken to mitigate and prevent recurrence. The parties acknowledge this Section as notice of the ongoing occurrence of unsuccessful Security Incidents (such as routine pings and port scans) for which no additional notice will be made. Covered Entity is responsible for any notifications to individuals, HHS, or the media that the HIPAA Rules require it to make.
6. Term & termination
Term
This BAA is effective on the date Covered Entity first accepts the Terms of Service or uses the Service to process PHI, and continues until all PHI is returned or destroyed or protections are extended as provided below.
Termination for cause
If Covered Entity determines that Business Associate has materially breached this BAA, Covered Entity may provide written notice and an opportunity to cure within a reasonable period; if the breach is not cured, Covered Entity may terminate this BAA and the Terms of Service.
Effect of termination
Upon termination, Business Associate will, if feasible, return or destroy all PHI it maintains in any form and retain no copies. Where return or destruction is not feasible, Business Associate will extend the protections of this BAA to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it maintains the PHI.
7. Miscellaneous
- Regulatory references. A reference to a section of the HIPAA Rules means the section as in effect or amended.
- Amendment. The parties will amend this BAA as necessary to comply with changes in the HIPAA Rules.
- Interpretation. Any ambiguity is resolved to permit compliance with the HIPAA Rules. This BAA controls over any conflicting term of the Terms of Service or Privacy Policy with respect to PHI.
- No third-party beneficiaries. Nothing in this BAA confers any rights on any person other than the parties.
- Survival. Obligations that by their nature should survive termination (including Section 6 effect-of-termination) will survive.
8. Contact
To request a countersigned BAA or discuss its terms, email hello@caselift.io.
