Purpose
This Business Associate Agreement (the “BAA”) is entered into between Vinician inc. (“Business Associate”) and the treatment program that creates an account (“Covered Entity”). It governs the handling of Protected Health Information (“PHI”) that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity under the Health Insurance Portability and Accountability Act (“HIPAA”) and its implementing regulations. Covered Entity accepts this BAA when an authorized representative agrees to it during signup.
Permitted Uses And Disclosures
Business Associate may use and disclose PHI only to perform the services described in the Terms of Service, to carry out its own proper management and administration, and as otherwise required by law. Business Associate will not use or disclose PHI in any manner that would violate HIPAA if done by Covered Entity.
Safeguards
Business Associate maintains administrative, physical, and technical safeguards for PHI, including:
- Encryption of sensitive information in transit and at rest.
- Role based access controls and least privilege access.
- Audit logging of access to patient records.
- One time login links and secure authentication for staff accounts.
Subcontractors
Business Associate will require any subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree in writing to restrictions and conditions at least as protective as those in this BAA.
Reporting
Business Associate will report to Covered Entity, without unreasonable delay, any use or disclosure of PHI not permitted by this BAA of which it becomes aware, including any breach of unsecured PHI as required by the HIPAA Breach Notification Rule.
Access, Amendment, And Accounting
To the extent Business Associate holds PHI in a Designated Record Set, it will support Covered Entity in responding to individual requests for access, amendment, and an accounting of disclosures as required by HIPAA.
Covered Entity Responsibilities
Covered Entity is responsible for obtaining any patient consents and authorizations required by law, configuring the platform accurately, limiting staff access to authorized personnel, and using exported or displayed PHI in accordance with its own policies and applicable law.
Term And Termination
This BAA remains in effect for as long as Covered Entity uses Vinician. On termination, Business Associate will, to the extent feasible, return or destroy PHI it maintains, or continue to protect any PHI that cannot feasibly be returned or destroyed.
Contact
Questions about this BAA may be sent to noah@vinician.com.