Think Beyond Practice LLC | HIPAA BAA v.3.1 (August 2026) | Effective as of the date of acceptance
This Business Associate Agreement (the "Agreement"), between the individual clinician, professional practice, or healthcare entity accepting this Agreement ("Covered Entity") and Think Beyond Practice LLC ("Business Associate"), effective as of the date last accepted by the parties (the "Effective Date"), complies with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), Public Law 104-191, the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act"), Public Law 111-005, and the regulations promulgated thereunder; 45 C.F.R. Parts 160, 162 and 164, to include the "Privacy Rule," the "Security Rule" and the "Breach Notification Rule" (collectively, the "Privacy, Security & Notification Rules").
The Washington Uniform Health Care Information Act (Chapter 70.02 RCW) Addendum, set out below as Exhibit A ("Washington Addendum"), is incorporated into and made part of this Agreement as though fully set forth herein. Business Associate shall comply with all obligations set forth in the Washington Addendum. In the event of any conflict between this Agreement and the Washington Addendum, the more stringent and protective requirement shall control.
Covered Entity and Business Associate may be referred to herein individually as "Party" or collectively as "Parties." By accepting this Agreement, Covered Entity represents that the individual accepting has the authority to bind Covered Entity to this Agreement.
Covered Entity acknowledges that it is subject to the Privacy, Security & Notification Rules. Business Associate provides or will provide services to Covered Entity pursuant to one or more agreements, referred to as "Service Agreement(s)." In the course of executing Service Agreement(s), Business Associate may come into contact with, use, or disclose Protected Health Information ("PHI") (defined in Section 1 below). Each Service Agreement, and any future agreement between the Parties which constitutes a Service Agreement, is incorporated by reference and shall be considered part of this document as if fully set out herein, whether or not the Service Agreement(s) expressly references such incorporation. In accordance with the Privacy, Security & Notification Rules, which require Covered Entity to have a written contract with each of its Business Associates, the Parties wish to establish satisfactory assurances that Business Associate will appropriately safeguard PHI and, therefore, make this Agreement.
1.1. Terms used, but not otherwise defined, in this Agreement shall have the same meaning as those terms are defined in HIPAA.
1.2. "Artificial Intelligence" or "AI" refers to a machine-based system that, given certain objectives, interacts with data to generate predictions, recommendations, or other outputs, including but not limited to large and small language, machine learning and deep learning models.
1.3. "Breach" shall have the meaning set out in 45 C.F.R. § 164.402.
1.4. "Designated Record Set" shall have the meaning set out in 45 C.F.R. § 164.501.
1.5. "Health Care Operations" shall have the meaning set out in 45 C.F.R. § 164.501.
1.6. "HIPAA" refers to the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, the HITECH Act, Public Law 111-005, and the regulations promulgated thereunder; 45 C.F.R. Parts 160, 162 and 164 (as well as any amendments thereto).
1.7. "Individual" shall have the same meaning as the term "individual" set out in 45 C.F.R. § 160.103 and shall include a person who qualifies as a personal representative in accordance with 45 C.F.R. § 164.502(g).
1.8. "Covered Entity Data" means (i) all data and information stored or caused to be stored on or within the Business Associate's Platform (to include PHI); (ii) all data and information processed by Business Associate (to include PHI); and (iii) the transformations, modifications, adaptations, customizations, correlations, hashes, vectors, data mining, matrices, tables, translations, extractions, algorithms, models, improvements, results, outputs, reports or derivatives generated or computed in whole or part from or to the foregoing (i) and (ii).
1.9. "Platform" means the Think Beyond Practice software platform, comprised of three Modules: the Practice Hub, the Credentialing Hub, and the Community and Education Hub (to include all of the tools and features within each Hub), and any other current or future Platform features. The Parties acknowledge that neither the Credentialing Hub nor the Community and Education Hub process PHI — although they may process non-PHI, Personal Information (e.g., the Credentialing Hub may process provider credentialing information such as NPI numbers) — and are included in this definition solely for purposes of completeness.
1.10. "Process" or "Processing" shall mean an operation or set of operations performed upon PHI, to include collection, creating, accessing, viewing, use, disclosure, structuring, adaptation, alteration, manipulation, retrieval, transmission, transfer, sharing, storage, retention, logging, generation, transformation, destruction or disposal of such information.
1.11. "Protected Health Information" or "PHI" — which includes but is not limited to Protected Health Information in electronic form (i.e., ePHI) — shall have the same meaning as the term "protected health information" in 45 C.F.R. § 160.103, and refers to information Processed by Business Associate from or on behalf of Covered Entity, to include through the Platform.
1.12. "Required by Law" shall have the meaning as set out in 45 C.F.R. § 164.103.
1.13. "Secretary" means the Secretary of the United States Department of Health and Human Services or their designee.
1.14. "Security Incident" has the meaning set out in 45 C.F.R. § 164.304.
1.15. "Subcontractor" has the meaning set out in 45 C.F.R. § 160.103.
1.16. "Unsuccessful Security Incident" means an incident such as a "ping" or other unsuccessful attempt to access a network, an unsuccessful login attempt, network probe, port scan, or similar event that, individually and in the aggregate, does not result in actual compromise of the system, or PHI.
1.17. "Workforce Member(s)" shall have the meaning of "Workforce" set out in 45 C.F.R. § 160.103.
2.1. Business Associate agrees to fully comply with the requirements under the Privacy, Security & Notification Rules applicable to "Business Associates" and not use or further disclose PHI other than as permitted or required by this Agreement, Service Agreement(s), or as Required by Law. In case of any conflict between this Agreement and Service Agreement(s), this Agreement shall govern. Business Associate acknowledges that certain information received from Covered Entity constitutes "Health Care Information" subject to Chapter 70.02 RCW, and shall not use or disclose such information in any manner that would violate Chapter 70.02 RCW if such use or disclosure were made by Covered Entity. Business Associate shall comply with the Washington Addendum, and shall cause each Subcontractor, agent and affiliate that receives Health Care Information to agree in writing to comply with obligations no less protective than those imposed by this Agreement and the Washington Addendum. In the event of any inconsistency between HIPAA and applicable Washington law, Business Associate shall comply with the requirement that affords greater protection to the individual whose information is at issue.
2.2. Training. Business Associate agrees to implement a security awareness and training program for all Workforce Members that will have access to PHI, and to train all Workforce Members on the policies and procedures with respect to properly handling and safeguarding PHI, as necessary and appropriate to carry out their functions, in compliance with 45 C.F.R. § 164.530(b). Such training shall include awareness training regarding the privacy and security of PHI (including Role-Based Access and the minimum necessary principle) and periodic reminders; shall be provided to each Workforce Member as necessary and appropriate, to each new Workforce Member within a reasonable period after being given access to PHI, and to each Workforce Member whose job functions are affected by a material change within a reasonable period after the change becomes effective. Business Associate shall document and retain records of training for each Workforce Member for at least six (6) years, and upon request shall provide a certification attesting to its compliance with these training requirements.
2.3. Business Associate agrees to use appropriate procedural, physical, and electronic safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement, including requiring employees to agree to use or disclose PHI only as permitted or required and taking related disciplinary actions for inappropriate use or disclosure, as necessary.
2.4. Business Associate shall require its Subcontractors, agents and affiliates to whom it provides PHI, or that carry out any duties involving the Processing of PHI, to agree by written contract to the same restrictions and conditions that apply to Business Associate under this Agreement, in accordance with 45 C.F.R. § 164.502(e)(1)(ii). Business Associate shall maintain Business Associate Agreements with all such Subcontractors, agents and affiliates. A current list of Subcontractors, agents and affiliates that may process PHI is available at https://thinkbeyondpractice.com/subprocessors.
2.5. Business Associate acknowledges that there may be contractual, legal or regulatory requirements that restrict the location where Covered Entity's PHI can be processed (i.e., restrictions on processing such data outside of the United States). As such, Business Associate agrees to process all of Covered Entity's PHI solely within the United States, unless Business Associate has secured express written consent from Covered Entity to process said information in a different location. This restriction on the location of processing applies not only to Business Associate's Workforce Members, but also to anyone who may have access to PHI through Business Associate, including its Subcontractors, agents, affiliates, and service providers.
2.6. Notification and Reporting. Business Associate agrees to: (2.6.1) report to Covered Entity any use or disclosure of PHI not provided for by this Agreement, including any Security Incident or Breach of unsecured PHI, except that this Section constitutes notice of the regular occurrence of Unsuccessful Security Incidents, for which no further notification is required; (2.6.2) mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this Agreement; (2.6.3) notify Covered Entity immediately following the "discovery" (within the meaning of 45 C.F.R. § 164.410(a)) of an unauthorized use or disclosure of PHI, and provide Covered Entity with all information necessary to comply with 45 C.F.R. §§ 164.404(c) and 164.410(c) without unreasonable delay and in no case later than ten (10) business days following discovery — Business Associate shall be liable for the costs associated with a Breach of unsecured PHI if such Breach is caused by Business Associate's acts or omissions, or those of its affiliates, officers, directors, employees, agents, or Subcontractors; (2.6.4) cooperate in good faith with Covered Entity in any investigation of a Breach and in any required notification; (2.6.5) include in any notification, to the extent possible, the identification of each affected Individual, a description of what happened and the dates involved, the types of Unsecured PHI involved, steps Individuals should take, what Business Associate is doing to investigate and mitigate, and contact information; and (2.6.6) Costs. Reasonable costs of Breach notification, mitigation, and remediation shall be allocated so that each Party bears the costs attributable to its own actions or omissions giving rise to the Breach. Where the Breach results from a failure of Business Associate's safeguards or those of its affiliates, officers, directors, employees, agents, or Subcontractors, Business Associate shall bear the reasonable costs of Breach notification and mitigation, subject to the limitations of liability set forth in the Service Agreement(s).
2.7. The Parties acknowledge that the Platform is not designed to maintain a Designated Record Set on behalf of Covered Entity. PHI processed through the Platform is delivered to Covered Entity, who is responsible for maintaining the Designated Record Set within Covered Entity's own records system. To the extent Business Associate retains PHI in a form that constitutes part of a Designated Record Set, Business Associate agrees to provide access in order to meet 45 C.F.R. § 164.524, and to make amendments in accordance with 45 C.F.R. § 164.526, in each case within at least ten (10) days from Covered Entity's notice.
2.8. Business Associate agrees to make its internal practices, books, and records, including policies and procedures for processing PHI, available to Covered Entity or to the Secretary, in a time and manner designated by the Covered Entity or the Secretary, for purposes of determining compliance with the Privacy, Security and Notification Rules.
2.9. Business Associate agrees to document disclosures of PHI and related information as would be required for Covered Entity to respond to a request for an accounting under 45 C.F.R. § 164.528, and to retain a record of each disclosure for no less than six (6) years from the date of such disclosure.
2.10. Business Associate agrees to provide Covered Entity, or an Individual, information to respond to a request for an accounting of disclosures in accordance with 45 C.F.R. § 164.528, within at least fifteen (15) business days from Covered Entity's notice unless a shorter time is required by law.
2.11. Business Associate agrees it must limit any use, disclosure, or request for use or disclosure of PHI to the minimum amount necessary to accomplish the intended purpose in accordance with the Privacy Rule, and represents that all its uses, disclosures, and requests shall be the minimum necessary.
2.12. Business Associate agrees to adequately and properly maintain all PHI, document subsequent uses and disclosures as deemed necessary and appropriate by Covered Entity, and provide Covered Entity with reasonable access to examine and copy such records during normal business hours.
2.13. Business Associate agrees that Covered Entity may at any time review Business Associate's privacy and/or security policies and procedures to determine consistency with Covered Entity's own, and shall promptly notify Business Associate of any modifications Covered Entity reasonably believes are needed.
2.14. Business Associate agrees that Covered Entity may at any time review the training materials used to comply with Section 2.2, along with related records, and shall promptly notify Business Associate of any issues identified.
2.15. If Business Associate receives a request from an Individual for a copy of the Individual's PHI in Business Associate's sole possession, Business Associate will provide the copies and notify Covered Entity. If Business Associate receives a request for PHI in Covered Entity's possession, or a request to exercise other individual rights, Business Associate shall notify Covered Entity, forward the request, and assist Covered Entity in responding.
2.16. Security Measures. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the PHI it Processes, and ensure that Subcontractors, agents or affiliates agree to similar safeguards. Such safeguards include, without limitation: encryption of PHI in transit and at rest, where applicable; access controls limiting access to PHI on a least-privilege basis; audit logging of administrative access to systems that process PHI; authentication controls including support for multi-factor authentication; data minimization practices including limited retention of PHI processed through the Platform, in accordance with the Platform's data flow design; vendor management procedures for Subcontractors; Workforce Member training on HIPAA obligations; incident response and breach notification procedures; and encryption of PHI contained in portable devices or removable media. Business Associate shall, at its own cost, monitor the issuance of laws, regulations, and guidance on the most effective and appropriate safeguards.
2.17. Business Associate agrees to fully cooperate in good faith with and to assist Covered Entity in complying with the requirements of the Privacy, Security & Notification Rules.
3.1. Business Associate acknowledges and agrees:
3.1.1. to limit its use, disclosure, and request of PHI to the minimum necessary to accomplish the intended purpose, in accordance with 45 C.F.R. §§ 164.502(b) and 164.514(d).
3.1.2. that the obligations under HIPAA's Privacy, Security & Notification Rules that apply to Covered Entity shall apply equally to Business Associate, and that Business Associate shall not use even aggregated and/or de-identified PHI received from Covered Entity for any type of marketing purposes.
3.1.3. to not: (a) use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity, except as expressly permitted under 45 C.F.R. §§ 164.504(e)(2)(i)(A) or (B); and (b) use or disclose PHI for marketing purposes or to sell PHI, except as permitted under HIPAA and only with Covered Entity's written authorization.
3.1.4. that it is prohibited from using any PHI or Covered Entity Data that it has access to for the purposes of any processing by any AI solutions or models, without the prior written permission of Covered Entity. This prohibition extends to any use of PHI or Covered Entity Data to: (i) train its algorithms or models, or otherwise create transformations, correlations, hashes, vectors, data mining, matrices, tables, classifiers, translations, extractions, algorithms, derivatives or models; and (ii) create, develop, train, or fine-tune AI, including developing or training generative or non-generative models, algorithms, or engineered or machine learning systems, unless specified and approved by Covered Entity in writing. This restriction does not prohibit Business Associate from using de-identified or aggregated data (that does not constitute PHI) solely to monitor, measure, and improve the quality, safety, and performance of the Services. Business Associate shall not use such de-identified or aggregated data to develop, train, or fine-tune any artificial intelligence model offered to or on behalf of third parties, and shall not sell or license such data. Any use of de-identified or aggregated data for research purposes requires the Covered Entity's separate, specific, written opt-in.
3.2. Covered Entity retains all rights, title, interest, ownership, and intellectual property rights in Covered Entity Data, including any vectors, hash indices, files or tables, or any algorithms, models or other derivatives generated in whole or part from or containing any Covered Entity Data.
3.3. Business Associate may de-identify or aggregate PHI solely to monitor, measure, and improve the quality, safety, and performance of the Services. Business Associate will not de-identify or aggregate PHI for any other purpose — including research or the development, training, or fine-tuning of any artificial intelligence model offered to or on behalf of third parties — without the prior written permission of Covered Entity, and will not sell or license de-identified or aggregated data. De-identified or aggregated data will be used only as permitted in this Section and in Section 3.1.4. As between the Parties, Business Associate shall make no claims of rights, title, interest, ownership, or intellectual property rights in any PHI that is de-identified or aggregated.
3.4. Except as otherwise limited in this Agreement, Business Associate may use or disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in Service Agreement(s), provided that such use or disclosure would not violate the Privacy Rule if done by Covered Entity.
3.5. Except as otherwise limited in this Agreement, Business Associate may use PHI as required for Business Associate's proper management and administration or to carry out its legal responsibilities.
3.6. Except as otherwise limited in this Agreement, Business Associate may disclose PHI for its proper management and administration, provided that disclosures are Required by Law, or that any third-party recipient agrees in writing to maintain confidentiality, use or further disclose the PHI only as Required by Law or for the purpose disclosed, and notify Business Associate of any Breach.
3.7. Except as otherwise limited in this Agreement, Business Associate may use PHI to provide data aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
4.1. Covered Entity has publicly posted its Notice of Privacy Practices ("Notice") on its website, in accordance with HIPAA. Business Associate acknowledges that it is responsible for reviewing that Notice and abiding by all commitments in it, including all permitted, prohibited and required uses or disclosures of PHI, as well as any revisions.
4.2. Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose PHI, if such changes affect Business Associate's permitted or required uses or disclosures.
4.3. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 C.F.R. § 164.522, to the extent such restriction may affect Business Associate's use or disclosure of PHI.
4.4. Covered Entity shall retain responsibility for securing the consent of their patients to the collection and Processing of their PHI in accordance with this Agreement. To the extent that Covered Entity provides Business Associate with the cellular/mobile phone number/email of a patient, Covered Entity will have secured the patient's consent for Business Associate to contact that patient (on behalf of Covered Entity) for purposes of treatment, payment and healthcare operations.
5.1. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity.
6.1. Email and Messaging Channels. The Parties acknowledge that certain Platform features may transmit PHI to Covered Entity through email or other messaging channels (e.g., delivery of patient assessment results, letter generator outputs, or notifications). Business Associate maintains Business Associate Agreements with its print and mail service provider, as well as with the email and messaging service providers through which digital transmissions are routed, and applies appropriate administrative, physical and technical safeguards to such transmissions. Business Associate's safeguards do not extend to email systems or environments outside of Business Associate's (or its Subcontractors', agents' and affiliates') control. Covered Entity acknowledges and agrees that Covered Entity is responsible for the security of Covered Entity's own email/messaging environment(s), including the email address and account through which Covered Entity receives communications.
6.2. Appropriate Use of Platform. Covered Entity shall: (a) use the Platform in accordance with the Service Agreement and any supporting documentation provided by Business Associate; (b) submit PHI only through Platform features designed to handle PHI; (c) obtain consents, authorizations, and/or provide notices required by HIPAA, state law, or applicable professional standards, relating to such information; (d) maintain the security of its account credentials and notify Business Associate promptly of any suspected compromise; and (e) comply with Covered Entity's own HIPAA obligations when using the Platform.
7.1. Term. This Agreement, effective as of the Effective Date, shall terminate when all of the PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, unless it is infeasible to return or destroy PHI, in which case Section 7.3 shall apply.
7.2. Termination for Cause. Covered Entity shall have the right to immediately terminate this Agreement and any Service Agreement(s) in the event Business Associate fails to comply with, or violates, a material provision of this Agreement or any requirements of the Privacy, Security & Notification Rules. Upon Covered Entity's knowledge of a material breach, Covered Entity shall, whenever practicable, provide a reasonable opportunity to cure; if cure is not possible or does not occur within a reasonable time specified by Covered Entity, Covered Entity may immediately terminate. Business Associate shall have the same right upon its knowledge of a material breach by Covered Entity.
7.3. Effect of Termination. Except as provided below, upon termination Business Associate shall return or destroy all PHI, including PHI in the possession of Subcontractors, agents or affiliates, and retain no copies. If return or destruction is infeasible, Business Associate shall notify Covered Entity of the conditions making it infeasible and, upon mutual agreement, extend the protections of this Agreement to such information and limit further uses and disclosures for so long as it maintains the information. To the extent a particular tool within the Platform processes PHI transiently, the Parties acknowledge that such PHI is not retained for ongoing storage beyond what is necessary to deliver the requested outputs to Covered Entity, and that at the time of termination little or no such PHI may remain in operational systems subject to return or destruction. To the extent other tools store PHI persistently, the return or destruction obligations above apply. Patient information may persist transiently in encrypted backups during normal backup rotation, after which it is destroyed.
8.1. Indemnification. To the extent permitted by law, each Party (the "Indemnifying Party") agrees to indemnify and hold harmless the other Party, and its affiliates, officers, directors, employees, agents, and Subcontractors, from and against all actual and direct losses (including reasonable attorney's fees, defense costs, and equitable relief) arising out of, resulting from, or attributable to any acts or omissions or other conduct of the Indemnifying Party in connection with the performance of duties under this Agreement. This indemnity shall not be construed to limit either Party's rights, if any, to common law indemnity.
8.2. Insurance Coverage. Business Associate shall maintain sufficient insurance coverage as shall be necessary to insure Business Associate, its Subcontractors, agents and affiliates, for damages incurred, including but not limited to any costs and expenses associated with notification under the Breach Notification Rule and/or state law, by Covered Entity and/or other third parties as a result of Business Associate's unauthorized use or disclosure of PHI, Breach of unsecured PHI, or a Security Incident.
8.3. Regulatory Reference. A reference in this Agreement to a section in the HIPAA Privacy, Security & Notification Rules means the section as in effect or as amended.
8.4. Amendment. The Parties agree to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of HIPAA, the Privacy, Security & Notification Rules, and any amendments thereto, upon the effective date of such amendment, regardless of whether this Agreement has been formally amended.
8.5. Survival. The respective rights and obligations of the Parties under this Agreement shall survive the termination of this Agreement.
8.6. Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits compliance with the Privacy, Security & Notification Rules.
8.7. No Third-Party Beneficiaries. Nothing in this Agreement shall be construed to create any rights or remedies in any third party, including any Individual, except as expressly required by HIPAA.
8.8. Notices and Communications. All instructions, notices, consents, demands, or other communications required or contemplated by this Agreement shall be in writing and delivered by hand, facsimile, email, overnight courier, or prepaid first-class registered or certified mail, addressed to the respective Party at the address it designates.
8.9. Strict Compliance. No failure by any Party to insist upon strict compliance with any term, exercise any option, enforce any right, or seek any remedy shall affect or constitute a waiver of that Party's right to demand strict compliance with all provisions of this Agreement.
8.10. Severability. Any provision finally determined by a court of competent jurisdiction to be unenforceable shall be reformed to the maximum extent permitted by applicable law; if it cannot be reformed, it shall be severed, and every other provision shall remain in full force and effect.
8.11. Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the State of Washington.
8.12. Compensation. There shall be no remuneration for performance under this Agreement except as specifically provided by, in, and through, the Service Agreement(s) referenced herein.
8.13. Recitals. This Agreement's preliminary recitals are incorporated herein by reference as though fully set forth at length herein.
8.14. Counterparts and Electronic Acceptance. This Agreement may be accepted electronically, and electronic acceptance shall have the same force and effect as a signed original.
This Washington Uniform Health Care Information Act Addendum ("Washington Addendum") is incorporated into and made part of this Agreement. In the event of a conflict between this Washington Addendum and the Agreement, this Washington Addendum shall control with respect to Health Care Information governed by Washington law.
Purpose. The Parties acknowledge that Health Care Information maintained, used, or disclosed by Business Associate may be subject to both HIPAA and Wash. Rev. Code ch. 70.02 (the Washington Uniform Health Care Information Act, "UHCIA"), and that Washington law may impose requirements more restrictive or protective than HIPAA.
1. Definitions. Capitalized terms not otherwise defined herein have the meanings assigned in the Agreement, HIPAA, or UHCIA, as applicable. "Health Care Information" shall have the meaning set forth in Wash. Rev. Code § 70.02.010. "More Stringent Requirement(s)" means the legal requirement that affords greater protection to the individual, imposes a narrower disclosure authorization, creates additional procedural safeguards, grants greater rights of access, amendment, or control, or otherwise provides greater privacy or confidentiality protections.
2. General Compliance Obligation. Business Associate shall comply with (a) HIPAA; (b) the UHCIA; (c) this Washington Addendum; (d) any Washington regulations implementing the UHCIA; and (e) any other applicable federal or Washington law governing the privacy, confidentiality, use, disclosure, retention, access, amendment, or security of Health Care Information.
3. Hierarchy of Laws. Where both HIPAA and Washington law apply, the Parties shall comply with the More Stringent Requirement; Business Associate shall not rely solely upon HIPAA where Washington law imposes additional conditions or restrictions; and compliance with HIPAA shall not excuse noncompliance with Washington law.
4. Washington-Specific Privacy Requirements. Business Associate shall implement policies and procedures reasonably designed to ensure compliance with Washington law requirements concerning patient authorization; disclosures without authorization; revocation of authorizations; third-party payor release; limitations on redisclosure; disclosure pursuant to subpoenas, discovery, and legal process; disclosure to personal and authorized representatives; disclosures for forensic examinations; release of information to protect the public; patient access rights; amendment or correction rights; accounting and documentation obligations; disclosure restrictions applicable to specially protected records; and any Washington-law restrictions on secondary use or disclosure of Health Care Information.
5. Subpoenas, Litigation, and Legal Process. Business Associate shall not disclose Health Care Information in response to a subpoena, discovery request, administrative demand, investigative request, or other legal process unless (a) such disclosure is expressly permitted under HIPAA and UHCIA; and (b) all notice, authorization, court order, protective order, or procedural requirements imposed by Washington law have been satisfied. Pursuant to Wash. Rev. Code § 70.02.170, individuals may have additional rights to civil remedies for violations of the UHCIA.
6. Authorizations. Business Associate shall not use or disclose Health Care Information pursuant to an authorization unless the authorization satisfies all applicable requirements of HIPAA and Washington law.
7. Redisclosure. Business Associate shall implement reasonable safeguards to prevent unauthorized redisclosure of Health Care Information, and where Washington law limits redisclosure more strictly than HIPAA, shall comply with the Washington limitation and verify the legal authority of any downstream recipient before sharing.
8. Individual Rights. Business Associate shall cooperate with Covered Entity in responding to requests relating to access to records, copies of records, amendment or correction, restrictions on disclosures, revocation of authorizations, and other rights granted under Washington law, including any broader rights or shorter, more stringent timelines Washington law provides.
9. Special Categories of Information. Business Associate acknowledges that certain information may be subject to additional Washington or federal confidentiality protections, including behavioral health, mental health, adolescent behavioral health, substance use disorder, reproductive health, sexually transmitted disease, HIV-related, and genetic information, and shall comply with the More Stringent Requirements governing such information.
10. Breach Notification. To the extent Business Associate is required to provide Breach notification to Covered Entity, Business Associate recognizes the shorter timeframe for Covered Entity's compliance under Washington law and agrees to provide notification within no more than ten (10) business days following discovery of a Breach of Health Care Information.
11. Subcontractors. Business Associate shall require each Subcontractor that handles Health Care Information to agree in writing to comply with HIPAA, the UHCIA, this Washington Addendum, any implementing Washington regulations, and any other applicable federal or Washington law governing Health Care Information.
12. Training and Policies. Business Associate shall maintain policies, procedures, and training reasonably designed to ensure compliance with Washington privacy requirements applicable to the services performed under the Agreement.
13. Conflicts Analysis. Washington state law governs to the extent it is more protective than HIPAA. Upon Covered Entity's reasonable request, Business Associate shall cooperate in evaluating whether a Washington-law requirement is more stringent, and shall document material determinations regarding conflicts when they affect operational practices or disclosure decisions.
14. Survival. The obligations of this Addendum shall survive termination of the Agreement to the same extent as the confidentiality, privacy, security, return, destruction, and post-termination obligations contained in the Agreement.
By clicking to accept, or by otherwise accessing or using Platform features that process PHI, Covered Entity agrees to be bound by this Agreement, and the individual accepting represents that they have the authority to bind Covered Entity. Electronic acceptance has the same force and effect as a signed original.