THIS BUSINESS ASSOCIATE AGREEMENT (the “BAA”) FORMS PART OF THE AGREEMENT (AS DEFINED BELOW) BETWEEN CIRCLEBACK AI, INC. (“Circleback” or “Business Associate”) AND THE CUSTOMER THAT ACCEPTS THIS BAA AS DESCRIBED BELOW (“Customer” or “Covered Entity”) (TOGETHER, the “Parties”). CUSTOMER ACCEPTS THIS BAA, AND THIS BAA BECOMES EFFECTIVE AND BINDING ON THE PARTIES, ON THE DATE THAT BOTH OF THE FOLLOWING HAVE OCCURRED: (A) AN AUTHORIZED ADMINISTRATOR OF CUSTOMER’S ACCOUNT HAS ENABLED THE HIPAA COMPLIANCE SETTING FOR CUSTOMER’S WORKSPACE AND AFFIRMATIVELY INDICATED ACCEPTANCE OF THIS BAA, AND (B) CUSTOMER’S WORKSPACE IS SUBSCRIBED TO ENTERPRISE OR ANOTHER HIPAA-ELIGIBLE PLAN (the “BAA Effective Date”). THE INDIVIDUAL ACCEPTING THIS BAA REPRESENTS AND WARRANTS THAT THEY HAVE THE AUTHORITY TO BIND CUSTOMER TO THIS BAA. THE PARTIES AGREE THAT ELECTRONIC ACCEPTANCE OF THIS BAA CONSTITUTES EXECUTION OF THIS BAA AND HAS THE SAME LEGAL EFFECT AS A SIGNED WRITING.
1. Scope
1.1 This BAA supplements and is incorporated by reference into the Circleback Terms of Service or, if applicable, a separately negotiated services agreement between Customer and Circleback governing Customer’s use of the Services (in either case, the “Agreement”).
1.2 This BAA applies only to the workspace for which the HIPAA compliance setting is enabled and only to Protected Health Information that Circleback creates, receives, maintains, or transmits on behalf of Customer through the Services for that workspace. This BAA does not apply to, and creates no obligations with respect to, any other account, workspace, or data.
1.3 As of the BAA Effective Date, this BAA supersedes and replaces in its entirety any business associate agreement previously executed by the Parties covering the Services.
2. Definitions
For purposes of this BAA, the Parties give the following meanings to the terms below. Any capitalized term used in this BAA but not otherwise defined has the meaning given to it in the Privacy Rule or pertinent law, or, if not defined there, in the Agreement.
2.1 “Breach” means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule which compromises the security or privacy of the PHI, as defined in 45 CFR §164.402.
2.2 “Breach Notification Rule” means the portion of HIPAA set forth in Subpart D of 45 CFR Part 164.
2.3 “Electronic PHI” means any PHI maintained in or transmitted by electronic media as defined in 45 CFR §160.103.
2.4 “Health Care Operations” has the meaning given to that term in 45 CFR §164.501.
2.5 “HHS” means the U.S. Department of Health and Human Services.
2.6 “HIPAA” means the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and related regulations promulgated by HHS, each as amended.
2.7 “Individual” has the meaning given to that term in 45 CFR §§164.501 and 160.103 and includes a person who qualifies as a personal representative in accordance with 45 CFR §164.502(g).
2.8 “Privacy Rule” means that portion of HIPAA set forth in 45 CFR Part 160 and Part 164, Subparts A and E.
2.9 “Protected Health Information” or “PHI” has the meaning given to the term “protected health information” in 45 CFR §§164.501 and 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity through the Services for the enabled workspace.
2.10 “Security Incident” means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
2.11 “Services” means the Service as defined in the Agreement.
3. Customer Representations
Customer represents and warrants that (a) it is a “covered entity” or a “business associate” of a covered entity, as those terms are defined under HIPAA; (b) before submitting PHI, the applicable workspace will be subscribed to Enterprise or another HIPAA-eligible plan and an authorized administrator will have enabled the HIPAA compliance setting and accepted this BAA for that workspace; (c) it will not submit new PHI while the workspace is not subscribed to Enterprise or another HIPAA-eligible plan; (d) it will not request that Business Associate use or disclose PHI in any manner that would violate HIPAA if done by Customer; and (e) it will not use the Services to create, receive, maintain, or transmit records subject to 42 CFR Part 2 (confidentiality of substance use disorder patient records).
4. Use and Disclosure of PHI
4.1 Except as otherwise provided in this BAA, Business Associate may use or disclose PHI as reasonably necessary to provide the Services described in the Agreement to Covered Entity, and to undertake other activities of Business Associate permitted or required of Business Associate by this BAA or as required by law.
4.2 Except as otherwise limited by this BAA or federal or state law, Covered Entity authorizes Business Associate to use the PHI in its possession for the proper management and administration of Business Associate’s business and to carry out its legal responsibilities. Business Associate may disclose PHI for its proper management and administration, provided that (a) the disclosures are required by law; or (b) Business Associate obtains, in writing, prior to making any disclosure to a third party (i) reasonable assurances from this third party that the PHI will be held confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to this third party and (ii) an agreement from this third party to notify Business Associate immediately of any breaches of the confidentiality of the PHI, to the extent it has knowledge of the breach.
4.3 Business Associate may provide data aggregation services relating to the Health Care Operations of Covered Entity if requested by Covered Entity.
4.4 Business Associate may de-identify PHI in accordance with 45 CFR §164.514(a)–(c) if requested by Covered Entity.
5. Safeguards Against Misuse of PHI
Business Associate will use appropriate safeguards designed to prevent the use or disclosure of PHI other than as provided by the Agreement or this BAA, and Business Associate agrees to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic PHI that it creates, receives, maintains, or transmits on behalf of Covered Entity. Business Associate agrees to take reasonable steps, including providing adequate training to its employees, to ensure compliance with this BAA and to ensure that the actions or omissions of its employees or agents do not cause Business Associate to breach the terms of this BAA. In accordance with 45 CFR §§164.502(e)(1)(ii) and 164.308(b)(2), if applicable, Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to substantially the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information. Business Associate shall upon request make its internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance with the HIPAA Rules.
6. Reporting Disclosures of PHI and Security Incidents
6.1 Business Associate will report to Covered Entity in writing any Breach of unsecured PHI without unreasonable delay after discovery, and in any event within the time required by applicable law.
6.2 Business Associate will report to Covered Entity in writing any use or disclosure of PHI not provided for by this BAA, and any Security Incident affecting Electronic PHI of Covered Entity, of which it becomes aware, without unreasonable delay.
6.3 This Section shall constitute notice, and no further notice shall be required, of pings, broadcast attacks on firewalls, port scans, unsuccessful log-on attempts, denial of service attacks, and similar events that do not result in unauthorized access to or use of PHI.
7. Mitigation of Disclosures of PHI
Business Associate will take reasonable measures to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of any use or disclosure of PHI by Business Associate or its agents or subcontractors in violation of the requirements of this BAA.
8. Individual Rights
8.1 The Services include self-service features that allow Customer to access, export, correct, and delete Customer’s data, including PHI. Customer is responsible for using those features to respond to requests by Individuals under 45 CFR §§164.524 and 164.526. To the extent PHI in a Designated Record Set held by Business Associate is not available to Customer through the Services, Business Associate will make that PHI available to Customer, or incorporate amendments to it as directed by Customer, within fifteen (15) business days of Covered Entity’s written request.
8.2 Business Associate will document disclosures of PHI, and information related to such disclosures, as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures under 45 CFR §164.528, and will provide such documentation to Covered Entity within thirty (30) days of written request.
8.3 If an Individual makes a request directly to Business Associate, Business Associate will forward the request to Covered Entity, and Covered Entity is responsible for responding to it.
9. Responsibilities of Covered Entity
With regard to the use and/or disclosure of PHI by Business Associate, Covered Entity agrees to (a) notify Business Associate of any limitation(s) in its notice of privacy practices in accordance with 45 CFR §164.520, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI; and (b) notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate’s use or disclosure of PHI.
10. Term and Termination
10.1 This BAA is effective as of the BAA Effective Date and remains in effect until the earliest of (a) the termination or expiration of the Agreement; (b) the date on which the HIPAA compliance setting is disabled for the workspace; (c) the date on which the workspace ceases to be subscribed to Enterprise or another HIPAA-eligible plan; or (d) termination under Section 10.2. If, following termination under clause (b) or (c), the workspace again becomes subscribed to Enterprise or another HIPAA-eligible plan and the HIPAA compliance setting is again enabled, including where the Services automatically restore the setting, the then-current version of this BAA is automatically accepted by Customer and becomes effective on that date.
10.2 Either Party may terminate this BAA if the other Party materially breaches this BAA and fails to cure the breach within thirty (30) days of written notice describing the breach. If cure is not reasonably possible, the non-breaching Party may terminate this BAA immediately upon written notice.
10.3 Upon termination of this BAA for any reason, Customer will immediately cease submitting PHI to the Services.
10.4 Customer is responsible for exporting and deleting PHI from the Services before this BAA terminates, using the export and deletion features of the Services. If any PHI remains in the Services after termination, Business Associate will extend the protections of this BAA to that PHI until it is deleted, whether through Customer’s use of the deletion features or, upon termination of the Agreement, through Business Associate’s standard deletion of Customer data, except to the extent retention is required by law.
11. Amendments and Waiver
11.1 Circleback may modify or update this BAA from time to time, including as necessary to comply with HIPAA or other changes in applicable law, by posting the updated BAA at circleback.ai/baa and providing notice to Customer through the Services or by email to Customer’s account administrator. The updated BAA will become effective on the earlier of (a) thirty (30) days after such notice and (b) Customer’s continued submission of PHI to the Services after such notice.
11.2 Upon the effective date of any final regulation or amendment to final regulations promulgated by HHS with respect to PHI, this BAA will be deemed automatically amended such that the obligations imposed on the Parties remain in compliance with such regulations.
11.3 A waiver of any provision of this BAA with respect to one event shall not be construed as continuing, or as a bar to or waiver of any right or remedy as to subsequent events.
12. No Third-Party Beneficiaries
Nothing expressed or implied in this BAA is intended to confer, nor shall anything herein confer, upon any person other than the Parties and their respective successors or permitted assigns, any rights, remedies, obligations, or liabilities whatsoever.
13. Interpretation
13.1 With respect to PHI, in the event of a conflict between this BAA and the Agreement or any data processing agreement between the Parties, this BAA controls. In all other respects, the Agreement remains in full force and effect.
13.2 Notwithstanding Section 13.1, nothing in this BAA will be deemed to waive or modify any provision of the Agreement, including its limitations of liability, which apply to this BAA and to Business Associate’s obligations with respect to PHI.
13.3 This BAA is governed by the law governing the Agreement, without regard to its conflict-of-laws principles, except to the extent preempted by federal law.
13.4 Any ambiguity in this BAA shall be interpreted to permit the Parties to comply with HIPAA.
For questions about this BAA, contact support@circleback.ai.