Business Associate Agreement
HIPAA Business Associate Agreement for US Healthcare Providers
Last Updated: April 21, 2026 | Effective Date: April 17, 2026 | Version 3.0
Regulatory Conformance Statement
This Business Associate Agreement ("BAA") is drafted to conform to and implement the requirements of:
- 45 CFR § 164.504(e) -- the Business Associate Contract requirements under the HIPAA Privacy Rule
- 45 CFR § 164.314(a) -- the Business Associate Contract requirements under the HIPAA Security Rule
- Subtitle D of the HITECH Act (Pub. L. 111-5, Title XIII), as incorporated by the HIPAA Omnibus Rule (78 Fed. Reg. 5566, January 25, 2013)
- HHS Office for Civil Rights Sample BAA Provisions, published at hhs.gov
Capitalized terms not defined herein have the meanings assigned under the HIPAA Rules (45 CFR Parts 160, 162, and 164).
Electronic Signature & Acceptance
This Business Associate Agreement ("BAA") becomes legally binding when you:
- Check the "I agree to the Business Associate Agreement" checkbox during account setup
- Type your name in the signature field
- Click the "Sign Agreement" button
Your electronic signature has the same legal effect as a handwritten signature. When you sign, we automatically countersign and email you the fully executed PDF (both signatures, dates, and the complete agreement text) for your compliance records. Need another copy? Email ben@clinicospro.com.
Who Needs This Agreement
This BAA is required for US healthcare providers ("Covered Entities" under HIPAA) before they can connect their EMR, import patient data, or use messaging features in Clinic OS Pro. No BAA = No PHI access.
Using Clinic OS Pro with PHI without an executed BAA is a violation of our Terms of Service and is done at your sole risk.
This Business Associate Agreement ("BAA") is entered into by and between:
- Covered Entity: The healthcare practice or clinic accepting this agreement ("You" or "Covered Entity")
- Business Associate: Clinic OS Pro (a business name registered in Ontario, Canada, BIN 1001580753), based in Windsor, Ontario, Canada ("We," "Us," or "Business Associate")
This BAA supplements and is incorporated into the Terms of Service (the "Agreement").
1. Definitions
Terms used in this BAA have the meanings set forth in the HIPAA Rules (45 CFR Parts 160 and 164). The following definitions apply:
- "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended
- "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164
- "Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form
- "Electronic Protected Health Information" or "ePHI" means PHI transmitted or maintained in electronic form
- "Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI
- "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations
2. Scope of PHI
2.1 PHI We Process
Through Clinic OS Pro, we may access and process the following limited PHI:
- Patient names
- Patient email addresses
- Patient phone numbers
- Appointment dates and times
- Visit counts and visit history
- Plan of care status (planned vs. completed visits)
- No-show and cancellation flags
- Treatment program type (e.g., "Sports Rehab," "Post-Op")
For US Covered Entities, the information in this Section 2.1 is treated as PHI under HIPAA.
2.2 PHI We Do NOT Process
Under the standard configuration of Clinic OS Pro, our services do not require and we do not intentionally collect the following additional categories of PHI:
- Medical diagnoses or ICD/CPT codes
- Clinical notes, SOAP notes, or treatment documentation
- Imaging studies, lab results, or test results
- Prescription or medication information
- Insurance policy numbers or detailed billing codes
- Social Security Numbers
- Genetic information
- Mental health or substance abuse treatment records
3. Permitted Uses and Disclosures
3.1 Service Provision
Business Associate may use and disclose PHI only as necessary to perform services under the Agreement, including:
- Storing and displaying patient contact information
- Generating task lists for patient outreach
- Sending communications on your behalf (email and SMS)
- Calculating revenue metrics and generating reports
- Providing customer support related to patient data
3.2 Management and Administration
Business Associate may use PHI for its proper management and administration, provided that disclosures are required by law or Business Associate obtains reasonable assurances regarding confidentiality from any third party.
3.3 Aggregated and De-Identified Data
Business Associate may de-identify PHI in accordance with 45 CFR 164.514(b) and use de-identified data for any lawful purpose. Business Associate may create and use aggregated data that does not identify any individual. Business Associate will not attempt to re-identify de-identified data, and will not disclose de-identified or aggregated data in a manner that would reasonably permit re-identification of an individual.
3.4 Prohibited Uses
Business Associate shall NOT:
- Use or disclose PHI for marketing purposes (except as permitted by HIPAA)
- Sell PHI
- Use or disclose PHI in a manner that would violate the Privacy Rule if done by Covered Entity
3.5 Treatment vs. Marketing Determination
Covered Entity is solely responsible for determining whether its use of Clinic OS Pro (including any messages sent using PHI) is for treatment, payment, healthcare operations, or marketing, and for obtaining any patient authorizations required under HIPAA. Business Associate will act only on Covered Entity's documented instructions.
4. Minimum Necessary Standard
In accordance with 45 CFR § 164.502(b) and the HITECH Act, Business Associate shall limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose. Business Associate will make reasonable efforts to use, disclose, and request only the minimum amount of PHI needed to perform its obligations under the Agreement.
Covered Entity acknowledges that the PHI scope described in Section 2.1 is limited by design to the minimum required to operate the platform.
5. Safeguards
5.1 Administrative Safeguards
- Designated security and privacy officer
- Workforce training on HIPAA requirements
- Access management and role-based permissions
- Policies and procedures for handling PHI
- Regular risk assessments
5.2 Physical Safeguards
- Data hosted in secure, access-controlled Amazon Web Services data centers in the United States, under an executed AWS Business Associate Addendum
- Business Associate uses commercially reasonable efforts to avoid storing PHI on local devices or removable media. Where limited local use is necessary for support or development, Business Associate applies safeguards that are at least as protective as those described in this BAA.
5.3 Technical Safeguards
- Encryption in Transit: TLS 1.2 or higher (HTTPS only)
- Encryption at Rest: AES-256 encryption for database storage
- Access Controls: Unique user IDs, automatic session timeouts
- Audit Logging: Comprehensive logs of data access and modifications
- Multi-Factor Authentication: Available for all user accounts
6. Subcontractors
Business Associate may engage subcontractors to assist in performing services. Business Associate shall:
- Enter into written agreements with subcontractors that provide the same protections as this BAA
- Ensure subcontractors agree to the same restrictions and conditions regarding PHI
- Maintain a list of subcontractors that access PHI (see Subprocessors)
6.1 Current Subcontractors
We maintain an up-to-date list of subprocessors that may access PHI at /legal/subprocessors. This list may change over time. We will provide notice of material changes as required by law and as described in the Subprocessors page.
If Covered Entity objects in writing to a new subcontractor that will access PHI within thirty (30) days after notice, and the parties cannot agree on a reasonable alternative, Covered Entity may terminate the affected services as its sole and exclusive remedy.
7. Breach Notification
Timely Notification
We will notify you of a Breach of unsecured PHI without unreasonable delay and in no event later than five (5) business days after discovery.
7.1 Breach Notification Process
Upon discovering a Breach, Business Associate shall:
- Notify Covered Entity without unreasonable delay and in no event later than five (5) business days after discovery
- Provide written notice including:
- Description of the Breach
- Date of the Breach and date of discovery
- Types of PHI involved
- Individuals affected (if known)
- Steps taken to investigate and mitigate
- Contact information for follow-up
- Cooperate with Covered Entity's investigation
- Assist with required notifications to affected individuals and regulators
7.2 Security Incidents
Business Associate shall report Security Incidents that result in unauthorized access to PHI within a commercially reasonable time and no later than ten (10) business days after discovery. Routine unsuccessful attempts (e.g., automated scans, failed logins) may be reported in aggregate.
8. Covered Entity Obligations
Covered Entity agrees to:
- Only provide the minimum necessary PHI required for Business Associate to perform services
- Obtain any required patient authorizations before sharing PHI
- Notify Business Associate of any restrictions on use or disclosure of PHI
- Notify Business Associate of any changes to patient authorization status
- Not request Business Associate to use or disclose PHI in violation of HIPAA
9. Individual Rights
Business Associate shall:
- Access: Make PHI available to Covered Entity within 10 business days to fulfill patient access requests
- Amendment: Make amendments to PHI as directed by Covered Entity
- Accounting: Maintain records and provide information for accounting of disclosures
- Restrictions: Honor restrictions on use and disclosure as communicated by Covered Entity
10. Term and Termination
10.1 Term
This BAA is effective upon your acceptance and remains in effect for the duration of the Agreement.
10.2 Termination for Cause
Either party may terminate this BAA if the other party materially breaches the BAA and fails to cure the breach within 30 days of written notice.
10.3 Effect of Termination
Upon termination:
- Business Associate shall return or destroy all PHI in its possession
- If return or destruction is not feasible, Business Associate shall extend the protections of this BAA to the remaining PHI and limit further uses and disclosures
- Business Associate shall certify destruction in writing upon request
10.4 Survival
The obligations of Business Associate regarding confidentiality and safeguarding of PHI shall survive termination of this BAA.
11. Miscellaneous
11.1 Amendment
The parties agree to amend this BAA as necessary to comply with changes in HIPAA or its implementing regulations.
11.2 Interpretation
This BAA shall be interpreted in a manner consistent with HIPAA. In the event of a conflict between this BAA and the Agreement, this BAA shall govern with respect to PHI.
11.3 Relationship to Agreement
The limitations of liability, disclaimers, and dispute resolution terms in the Agreement (including arbitration and class action waiver) apply equally to this BAA and any claims arising from Business Associate's processing of PHI.
11.4 No Third-Party Beneficiaries
This BAA does not create any third-party beneficiary rights in any individual, including patients.
11.5 Regulatory Changes
If new HIPAA regulations are issued that require modification of this BAA, the parties shall negotiate in good faith to amend this BAA accordingly.
Contact Information
For questions about this BAA or to report a potential Breach:
Clinic OS ProAttn: HIPAA Privacy Officer (Ben Wiebe)
Windsor, Ontario, Canada
Email: ben@clinicospro.com
Document Version: 2.0
Last Reviewed: April 21, 2026
Next Review Date: January 2027