RESEARCH PREVIEW — NOT FOR CLINICAL USE. EchoReview AI is an investigational workflow tool. Output is a preliminary, non-diagnostic impression intended to support cardiologist review for research and quality-improvement purposes only. Not FDA-cleared. Do not use for patient care decisions. Do not upload identified PHI without an executed BAA.
Template — for review by hospital counsel

Business Associate Agreement (BAA)

Required under 45 CFR §§ 164.502(e) and 164.504(e) before EchoReview AI may receive, store, or process Protected Health Information (PHI) on behalf of a Covered Entity.

1. Definitions

Terms used herein have the meanings given in 45 CFR Parts 160 and 164 ("the HIPAA Rules"). "Covered Entity" is [Hospital Legal Name]; "Business Associate" is [EchoReview AI Legal Entity].

2. Permitted Uses and Disclosures of PHI

Business Associate may use or disclose PHI only as necessary to perform the Services (echocardiogram triage and review workflow) and as Required by Law.

3. Obligations of Business Associate

  • Implement administrative, physical, and technical safeguards meeting the Security Rule (45 CFR §§ 164.308, 164.310, 164.312).
  • Report Breaches of Unsecured PHI to Covered Entity within five (5) business days of discovery.
  • Ensure any subcontractor that creates, receives, maintains, or transmits PHI agrees in writing to the same restrictions.
  • Make PHI available for access, amendment, and accounting in accordance with 45 CFR §§ 164.524, 164.526, 164.528.
  • Make internal practices, books, and records available to HHS for HIPAA compliance determinations.

4. Security Controls

The current technical control set is described at /compliance and includes encryption at rest and in transit, role-based access controls, MFA, immutable audit logs, idle timeout, and study sign-off attestations modeled on 21 CFR Part 11.

5. Term & Termination

This BAA is effective on the date of execution and remains in effect until terminated. Either party may terminate for material breach not cured within thirty (30) days. Upon termination, Business Associate will return or destroy all PHI, or, if infeasible, extend the protections of this BAA to the retained PHI.

6. Breach Notification

Business Associate will follow the Breach Notification Rule (45 CFR § 164.410) and provide the information required for Covered Entity to comply with its notification obligations.

7. Indemnification & Insurance

Business Associate maintains cyber liability insurance of not less than $2,000,000 per claim. Each party will indemnify the other for damages arising from its own breach of this BAA.

8. Governing Law

This BAA is governed by the laws of [State]. The HIPAA Rules govern any conflict.

Disclaimer: This template is provided for convenience and is not legal advice. Both parties should have qualified counsel review and execute the final agreement.