Legal

Business Associate Agreement

Last updated: June 14, 2026

This Business Associate Agreement ("BAA") is entered into between CaseLift ("Business Associate") and the practice or organization that uses the CaseLift Service ("Covered Entity"). It supplements and is incorporated into the Terms of Service between the parties. It governs the handling of Protected Health Information (PHI) and is required by the HIPAA Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164) and the HITECH Act.

Covered Entity accepts this BAA when it accepts the Terms of Service, signs an order, or first uses the Service to process PHI. A countersigned copy is available on request at hello@caselift.io.

1. Definitions

Capitalized terms not defined here have the meanings given in the HIPAA Rules. "PHI" means Protected Health Information, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity. "Electronic PHI" (ePHI), "Breach," "Security Incident," "Required by Law," "Subcontractor," and "Designated Record Set" have the meanings in 45 C.F.R. §§ 160.103 and 164.402.

2. Permitted uses & disclosures by Business Associate

Business Associate may use and disclose PHI only:

Business Associate will not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted above for management, administration, and data aggregation. Business Associate will not sell PHI and will not use or disclose PHI for marketing except as permitted by law and authorized by Covered Entity.

3. Obligations of Business Associate

4. Obligations of Covered Entity

5. Breach & Security Incident reporting

Business Associate will notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and no later than thirty (30) calendar days after discovery. The notification will include, to the extent known, the nature of the Breach, the PHI involved, the individuals affected, and the steps taken to mitigate and prevent recurrence. The parties acknowledge this Section as notice of the ongoing occurrence of unsuccessful Security Incidents (such as routine pings and port scans) for which no additional notice will be made. Covered Entity is responsible for any notifications to individuals, HHS, or the media that the HIPAA Rules require it to make.

6. Term & termination

Term

This BAA is effective on the date Covered Entity first accepts the Terms of Service or uses the Service to process PHI, and continues until all PHI is returned or destroyed or protections are extended as provided below.

Termination for cause

If Covered Entity determines that Business Associate has materially breached this BAA, Covered Entity may provide written notice and an opportunity to cure within a reasonable period; if the breach is not cured, Covered Entity may terminate this BAA and the Terms of Service.

Effect of termination

Upon termination, Business Associate will, if feasible, return or destroy all PHI it maintains in any form and retain no copies. Where return or destruction is not feasible, Business Associate will extend the protections of this BAA to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it maintains the PHI.

7. Miscellaneous

8. Contact

To request a countersigned BAA or discuss its terms, email hello@caselift.io.