Business Associate Agreement

HIPAA Business Associate Agreement for AegisGate Security, LLC customers. Required for Professional tier subscribers handling Protected Health Information (PHI).

📋 DRAFT — Not Legal Advice
This document is self-drafted by AegisGate Security, LLC. AegisGate Security, LLC is not a law firm, and this document does not constitute legal advice. Production-grade review by qualified legal counsel is deferred until budget is available. Until then, customers and counterparties should rely on this document at their own risk and consult their own legal counsel.

Business Associate Agreement

Effective Date: Effective upon execution Version: 1.0 DRAFT


RECITALS

This Business Associate Agreement (“Agreement”) is entered into by and between:

Covered Entity: AegisGate Security, LLC, a Wisconsin limited liability company (“Company”) Address: AegisGate Security, LLC, Wisconsin, USA Email: support@aegisgatesecurity.io

and

Business Associate: The entity identified in the applicable Order Form or Statement of Work (“Subscriber”)

collectively referred to as the “Parties.”


WHEREAS:

A. Company provides the AegisGate Security Platform, a software-as-a-service security gateway for AI infrastructure (“Services”);

B. Subscriber is or may become a “covered entity” or “business associate” as defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Health Information Technology for Economic and Clinical Health Act (“HITECH”);

C. Company, in its provision of Services, may create, receive, maintain, or transmit Protected Health Information (“PHI”) on behalf of Subscriber;

D. The Parties desire to establish the terms under which Company may handle PHI in connection with the Services;

NOW, THEREFORE, in consideration of the mutual covenants herein, the Parties agree as follows:


1. DEFINITIONS

1.1 “Business Associate”

Shall have the meaning given to such term under the Privacy Rule, including 45 C.F.R. § 160.103.

1.2 “Covered Entity”

Shall have the meaning given to such term under the Privacy Rule, including 45 C.F.R. § 160.103.

1.3 “HIPAA”

The Health Insurance Portability and Accountability Act of 1996, as amended by HITECH, and all applicable regulations promulgated thereunder.

1.4 “HITECH”

The Health Information Technology for Economic and Clinical Health Act, Title XIII of the American Recovery and Reinvestment Act of 2009.

1.5 “Protected Health Information” or “PHI”

Shall have the meaning given to such term under 45 C.F.R. § 160.103, limited to PHI received, created, maintained, or transmitted by Company on behalf of Subscriber.

1.6 “Privacy Rule”

The Standards for Privacy of Individually Identifiable Health Information, 45 C.F.R. Part 160 and Part 164, Subparts A and E.

1.7 “Security Rule”

The Security Standards for the Protection of Electronic Protected Health Information, 45 C.F.R. Part 160 and Part 164, Subparts A and C.

1.8 “Unsecured PHI”

PHI that is not protected through the use of a technology or methodology that renders PHI unusable, unreadable, or indecipherable to unauthorized individuals, as specified in the guidance issued by the Secretary under Section 13402(h) of the American Recovery and Reinvestment Act.

1.9 Other Terms

Capitalized terms not defined herein shall have the meanings set forth in HIPAA and the regulations promulgated thereunder.


2. OBLIGATIONS OF COMPANY

2.1 Permitted Uses

Company may use or disclose PHI solely as follows:

  • (a) For the proper management and administration of Company and to carry out Company’s legal responsibilities;
  • (b) As required by law in accordance with Section 2.3 below;
  • (c) For Data Aggregation purposes relating to the healthcare operations of Subscriber;
  • (d) To provide Data Aggregation services as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B);
  • (e) To the extent that such use or disclosure is required for Company’s proper performance of the Services.

2.2 Prohibited Uses

Company shall not:

  • (a) Use or disclose PHI other than as permitted or required by this Agreement or as required by law;
  • (b) Use or disclose PHI in any manner that would constitute a violation of applicable law if done by Subscriber;
  • (c) Use or disclose PHI in any manner that would constitute a violation of the Privacy Rule if done by Company;
  • (d) Use or disclose PHI for any purpose other than as permitted under this Agreement;
  • (e) Sell, rent, or lease PHI without prior written authorization from Subscriber.

2.3 Required Disclosures

Company shall disclose PHI as required by law, including:

  • (a) To the Secretary of the Department of Health and Human Services, when required to do so under HIPAA;
  • (b) For the purpose of compliance with the HIPAA Privacy Rule or Security Rule;
  • (c) As required by any applicable law.

2.4 Minimum Necessary Standard

Company shall make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request.

2.5 Safeguards

Company shall implement and maintain administrative, physical, and technical safeguards that:

  • (a) Are designed to ensure the confidentiality, integrity, and availability of PHI;
  • (b) Are designed to prevent any intentional or unintentional use or disclosure of PHI in violation of this Agreement or applicable law;
  • (c) Comply with the Security Rule’s requirements for nonelectronic PHI;
  • (d) Comply with the Security Rule’s requirements for electronic PHI, including:
    • (i) Access controls;
    • (ii) Audit controls;
    • (iii) Integrity controls;
    • (iv) Transmission security.

2.6 Security Incidents

Company shall:

  • (a) Implement and maintain policies and procedures to detect, investigate, and respond to Security Incidents;
  • (b) Notify Subscriber of a Security Incident involving PHI without unreasonable delay, but in no event later than 30 days after discovery;
  • (c) For purposes of this Agreement, “Security Incident” means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of PHI, or interference with system operations in an information system.

2.7 Mitigation

Company shall mitigate, to the extent practicable, any harmful effect known to Company resulting from a use or disclosure of PHI by Company in violation of this Agreement.

2.8 Agents and Subcontractors

Company shall ensure that any agent or subcontractor to whom Company discloses PHI agrees to the same restrictions and conditions that apply to Company under this Agreement.

2.9 Availability of PHI

Company shall make PHI available in accordance with:

  • (a) The HIPAA Privacy Rule’s right of access requirements;
  • (b) The HIPAA Privacy Rule’s amendment requirements.

2.10 Accounting of Disclosures

Company shall document and provide an accounting of disclosures of PHI in accordance with 45 C.F.R. § 164.528.

2.11 Compliance with HIPAA

Company shall comply with the applicable requirements of HIPAA, including the Privacy Rule, Security Rule, and HITECH.


3. OBLIGATIONS OF SUBSCRIBER

3.1 Subscriber Responsibilities

Subscriber shall:

  • (a) Provide Company with a copy of its privacy practices and policies relevant to PHI, if any;
  • (b) Not request Company to use or disclose PHI in any manner not permitted under this Agreement;
  • (c) Take appropriate steps to ensure that any third party who creates, receives, maintains, or transmits PHI on behalf of Subscriber complies with HIPAA.

3.2 Permission for Other Disclosures

Subscriber shall not disclose PHI to any third party without Company’s prior written consent, except as permitted by HIPAA.


4. TERM AND TERMINATION

4.1 Term

This Agreement shall be effective as of the Effective Date and shall continue until terminated as provided herein.

4.2 Termination for Breach

Either Party may terminate this Agreement immediately upon written notice if the other Party breaches a material term of this Agreement and fails to cure such breach within 30 days after receipt of written notice thereof.

4.3 Termination for Insolvency

This Agreement shall terminate automatically upon the filing of a petition in bankruptcy or insolvency by or against either Party.

4.4 Effect of Termination

Upon termination of this Agreement for any reason:

  • (a) Company shall return or securely destroy all PHI in Company’s possession or control;
  • (b) Company shall retain PHI only as required by law and shall continue to maintain the confidentiality of such PHI;
  • (c) Company shall notify Subscriber of any circumstances that cannot be cured by return or destruction of PHI.

5. GENERAL PROVISIONS

5.1 No Third-Party Beneficiaries

Nothing in this Agreement shall confer any rights upon any person or entity other than the Parties.

5.2 Amendment

This Agreement may be amended only by a written instrument signed by both Parties.

5.3 Governing Law

This Agreement shall be governed by and construed in accordance with the laws of the State of Wisconsin.

5.4 Entire Agreement

This Agreement constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, and communications.

5.5 Counterparts

This Agreement may be executed in counterparts, each of which shall be deemed an original, and all of which together shall constitute one and the same instrument.

5.6 Severability

If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

5.7 Survival

The following sections shall survive termination of this Agreement: Sections 2.5, 2.6, 2.7, 4.4, 5, 6, 8, 9, 10, 11, and 12.


6. INDEMNIFICATION

6.1 Indemnification by Company

Company shall indemnify, defend, and hold harmless Subscriber and its officers, directors, employees, and agents from and against any claims, damages, losses, costs, and expenses (including reasonable attorneys’ fees) arising out of or related to Company’s breach of this Agreement or Company’s negligent or wrongful acts or omissions.

6.2 Indemnification by Subscriber

Subscriber shall indemnify, defend, and hold harmless Company and its officers, directors, employees, and agents from and against any claims, damages, losses, costs, and expenses (including reasonable attorneys’ fees) arising out of or related to Subscriber’s breach of this Agreement or Subscriber’s negligent or wrongful acts or omissions.


7. INSURANCE

Company shall maintain insurance coverage appropriate to its obligations under this Agreement, including:

  • (a) Commercial general liability insurance;
  • (b) Professional liability (errors and omissions) insurance;
  • (c) Cyber liability insurance.

8. MINIMUM NECESSARY STANDARD

8.1 Minimum Necessary Standard (45 C.F.R. § 164.502(b))

Business Associate shall only request, use, or disclose the minimum amount of Protected Health Information necessary to accomplish the intended purpose of the use, disclosure, or request. Business Associate shall implement policies and procedures to limit access to PHI to those persons who need access to carry out their duties.


9. RIGHT TO AN ACCOUNTING OF DISCLOSURES

9.1 Right to an Accounting of Disclosures (HITECH § 13405(c))

Covered Entity has the right to request an accounting of disclosures of PHI made by Business Associate during the six years prior to the date of the request, as required by 45 C.F.R. § 164.528. Business Associate shall maintain and make available to Covered Entity a record of all disclosures of PHI for purposes other than treatment, payment, or health care operations, including: (a) the date of disclosure; (b) the name of the entity or person who received the PHI; (c) a brief description of the PHI disclosed; and (d) a brief statement of the purpose of the disclosure. Business Associate shall provide this accounting within 30 days of a written request from Covered Entity.


10. HITECH ACT BREACH NOTIFICATION REQUIREMENTS

10.1 Breach Notification (45 C.F.R. § 164.400-414)

Business Associate shall comply with the breach notification requirements of the HITECH Act and implementing regulations at 45 C.F.R. §§ 164.400-414, including but not limited to the following obligations:

10.2 Notification Timeline

Business Associate shall notify Covered Entity of any breach of Unsecured PHI without unreasonable delay, and in no event later than 60 calendar days from the date of discovery of the breach.

10.3 Notification to Individuals, HHS, and Media

Covered Entity shall be responsible for providing breach notification to affected individuals, the U.S. Department of Health and Human Services (HHS), and, where applicable, prominent media outlets serving a State or jurisdiction, in accordance with the following:

  • (a) If the breach affects 500 or more individuals in a single State or jurisdiction, Covered Entity shall notify prominent media outlets serving that State or jurisdiction without unreasonable delay and no later than 60 calendar days from discovery;
  • (b) Covered Entity shall notify HHS of breaches affecting fewer than 500 individuals on an annual basis, and of breaches affecting 500 or more individuals without unreasonable delay and within 60 calendar days of discovery;
  • (c) Business Associate shall provide Covered Entity with all information necessary for Covered Entity to fulfill its notification obligations under this Section.

10.4 Content of Breach Notifications

Each breach notification shall include, at a minimum, the following content:

  • (a) A description of what happened, including the date of the breach and the date of discovery, if known;
  • (b) A description of the types of unsecured PHI that were involved in the breach (e.g., name, Social Security number, date of birth, diagnosis, etc.);
  • (c) The steps individuals should take to protect themselves from potential harm resulting from the breach;
  • (d) A brief description of what Business Associate and Covered Entity are doing to investigate the breach, mitigate harm, and protect against further breaches;
  • (e) Contact information for individuals to ask questions, including a toll-free telephone number, email address, website, or postal address.

11. HHS AUDIT AND COMPLIANCE REVIEW RIGHTS

11.1 Availability of Records to the Secretary

Business Associate agrees to make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity’s compliance with the HIPAA Rules, pursuant to 45 C.F.R. § 164.502(i) and 42 U.S.C. § 1320d-2.


12. REPORTING OF CRIMINAL OR CIVIL PROCEEDINGS

12.1 Reporting Requirement (45 C.F.R. § 164.530(d))

Business Associate shall report to Covered Entity any criminal or civil proceedings initiated against Business Associate relating to the privacy or security of PHI, within 10 business days of Business Associate becoming aware of such proceedings.


SIGNATURES

IN WITNESS WHEREOF, the Parties have executed this Agreement as of the date first written above.

COMPANY:

AegisGate Security, LLC Signature: _________________________________ Name: _________________________________ Title: _________________________________ Date: _________________________________

SUBSCRIBER:

[SUBSCRIBER NAME] Signature: _________________________________ Name: _________________________________ Title: _________________________________ Date: _________________________________


This document is a DRAFT and has not been reviewed by legal counsel. It is intended for discussion purposes only and shall not constitute a binding agreement until signed by all parties and reviewed by qualified legal counsel.