Legal

Business Associate Agreement

Last updated: April 16, 2026Version 0.1-draft

Draft — pending attorney review

This document is a placeholder while Compli4nt finalizes its legal documentation with outside counsel. It is not yet binding. A versioned update will be published before this document takes effect, and all users will be prompted to review and re-accept.

1. Purpose

This Business Associate Agreement (“BAA”) is entered into between the Compli4nt customer (“Covered Entity”) and Compli4nt, Inc. (“Business Associate”) to comply with the Health Insurance Portability and Accountability Act of 1996, as amended by the HITECH Act, and the implementing regulations at 45 CFR Parts 160 and 164 (collectively, the “HIPAA Rules”).

2. Definitions

Terms used but not otherwise defined in this BAA have the meanings given in the HIPAA Rules. “PHI” means Protected Health Information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity in connection with the Service.

3. Permitted Uses and Disclosures

Business Associate may use or disclose PHI only as necessary to provide the Service, as permitted or required by this BAA, or as required by law. Business Associate shall not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity.

4. Safeguards

Business Associate shall implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI, consistent with 45 CFR §§ 164.308, 164.310, 164.312, and 164.316.

5. Subcontractors

Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to the same restrictions and conditions that apply to Business Associate under this BAA, in accordance with 45 CFR § 164.308(b)(2).

6. Breach Notification

Business Associate shall notify Covered Entity without unreasonable delay and no later than thirty (30) calendar days after discovery of any Breach of Unsecured PHI, in accordance with 45 CFR § 164.410. Notice shall include the information reasonably available at the time and shall be supplemented as additional information becomes known.

7. Individual Rights

  • Business Associate shall make PHI available to Covered Entity for access, amendment, and accounting of disclosures requests, as required by 45 CFR §§ 164.524, 164.526, and 164.528.
  • Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance with the HIPAA Rules.

8. Term and Termination

This BAA takes effect upon acceptance and remains in effect for the duration of the underlying subscription agreement. Upon termination, Business Associate shall return or destroy all PHI, or if return or destruction is infeasible, extend the protections of this BAA to the PHI and limit further use or disclosure to purposes that make return or destruction infeasible.

9. Amendment

The parties agree to amend this BAA as necessary to comply with changes to the HIPAA Rules. Material changes will be communicated to Covered Entity, who will be asked to re-accept the updated version.

10. Conflicts

In the event of any conflict between this BAA and the Terms of Service or Privacy Policy with respect to PHI, this BAA controls.

11. Signature

[Electronic acceptance flow pending.] This BAA is deemed executed when the Covered Entity accepts the consent checkbox at signup. The acceptance timestamp and version are recorded on the Covered Entity’s account.

12. Contact

Questions may be directed to legal@compli4nt.com.