1. Definitions
Terms used herein have the meanings given in 45 CFR Parts 160 and 164 ("the HIPAA Rules"). "Covered Entity" is [Hospital Legal Name]; "Business Associate" is [EchoReview AI Legal Entity].
2. Permitted Uses and Disclosures of PHI
Business Associate may use or disclose PHI only as necessary to perform the Services (echocardiogram triage and review workflow) and as Required by Law.
3. Obligations of Business Associate
- Implement administrative, physical, and technical safeguards meeting the Security Rule (45 CFR §§ 164.308, 164.310, 164.312).
- Report Breaches of Unsecured PHI to Covered Entity within five (5) business days of discovery.
- Ensure any subcontractor that creates, receives, maintains, or transmits PHI agrees in writing to the same restrictions.
- Make PHI available for access, amendment, and accounting in accordance with 45 CFR §§ 164.524, 164.526, 164.528.
- Make internal practices, books, and records available to HHS for HIPAA compliance determinations.
4. Security Controls
The current technical control set is described at /compliance and includes encryption at rest and in transit, role-based access controls, MFA, immutable audit logs, idle timeout, and study sign-off attestations modeled on 21 CFR Part 11.
5. Term & Termination
This BAA is effective on the date of execution and remains in effect until terminated. Either party may terminate for material breach not cured within thirty (30) days. Upon termination, Business Associate will return or destroy all PHI, or, if infeasible, extend the protections of this BAA to the retained PHI.
6. Breach Notification
Business Associate will follow the Breach Notification Rule (45 CFR § 164.410) and provide the information required for Covered Entity to comply with its notification obligations.
7. Indemnification & Insurance
Business Associate maintains cyber liability insurance of not less than $2,000,000 per claim. Each party will indemnify the other for damages arising from its own breach of this BAA.
8. Governing Law
This BAA is governed by the laws of [State]. The HIPAA Rules govern any conflict.
Disclaimer: This template is provided for convenience and is not legal advice. Both parties should have qualified counsel review and execute the final agreement.