Legal · Healthcare
Business Associate Agreement
What this page is: the standard Business Associate Agreement (“BAA”) terms PM Media offers to healthcare clients under the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (45 C.F.R. Parts 160 and 164), as amended by the HITECH Act. These terms take effect for a given engagement only when executed in writing by both parties. Posting them here does not create a BAA. To request an executed copy, email connect@pmmedia-source.com with the subject line “BAA Request.”
Honest statement on “HIPAA certification.” There is no government or universal HIPAA certification for software or vendors, and we will never claim one. What we offer instead is a signed BAA, documented safeguards, tenant isolation, audit logging, and a written security questionnaire response for your compliance file.
Jump to: Express prohibitions · Safeguards · Subcontractors · Breach notification · De-identification · Return or destruction of PHI · Request an executed BAA
1. Parties and scope
These terms apply between the healthcare provider, health plan, or clearinghouse that engages us (“Covered Entity”) and PM Media, including its MedSync PM line (“Business Associate”), with respect to Protected Health Information created, received, maintained, or transmitted by Business Associate on Covered Entity's behalf.
Where Covered Entity is itself a business associate of another covered entity, these terms apply on a subcontractor basis and Business Associate is a subcontractor under 45 C.F.R. § 164.502(e)(1)(ii).
This BAA supplements the parties' Statement of Work or client agreement. If any term of this BAA conflicts with the Statement of Work, the Terms of Service, or the Privacy Policy, this BAA controls as to Protected Health Information.
2. Definitions
Capitalized terms not defined here have the meaning given in 45 C.F.R. Parts 160 and 164. “PHI” means Protected Health Information limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity. “ePHI” means PHI in electronic form. “Breach,” “Designated Record Set,” “Individual,” “Required by Law,” “Security Incident,” “Subcontractor,” and “Unsecured PHI” follow the regulatory definitions.
3. Permitted uses and disclosures
Business Associate may use and disclose PHI only:
- To perform the services described in the Statement of Work — patient intake, scheduling, appointment synchronization, reminders, routing, bilingual communication, and related operational support;
- As Required by Law;
- For the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any disclosure to a third party is Required by Law or made with written assurances of confidentiality, use restriction, and notification of any breach; and
- To provide Data Aggregation services relating to Covered Entity's health care operations, where requested under 45 C.F.R. § 164.504(e)(2)(i)(B).
Business Associate will not use or disclose PHI in a manner that would violate Subpart E of Part 164 if done by Covered Entity, except as permitted above.
4. Express prohibitions
Business Associate will not:
- Sell PHI or receive remuneration in exchange for PHI, except as permitted by 45 C.F.R. § 164.502(a)(5)(ii);
- Use or disclose PHI for marketing or fundraising, or for Business Associate's own advertising, product promotion, or lead generation;
- Use PHI to train general-purpose or foundation machine-learning models, or permit any model provider to do so. Model and voice providers are engaged as Subcontractors under enterprise or zero-retention configurations with training disabled;
- Create voiceprints, faceprints, or other biometric identifiers from PHI;
- Re-identify de-identified information, or attempt to;
- Disclose PHI to a law enforcement or immigration authority except as Required by Law, and will notify Covered Entity promptly where notice is legally permitted;
- Transfer, store, or process PHI outside the United States without Covered Entity's prior written approval.
5. Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided by this BAA. Current practices include:
- Encryption in transit (TLS 1.2 or higher) and at rest;
- Access control — unique user identification, role-based least-privilege access, and revocation on role change or separation;
- Multi-factor authentication for administrative access;
- Tenant isolation — each client's records carry a client identifier and are logically segregated; records are never commingled across clients;
- Audit logging of access to and disclosure of PHI, retained for review;
- Minimum necessary — intake collects only the fields needed for scheduling and routing; clinical questions are escalated to authorized staff rather than answered by an automated assistant;
- Automatic logoff, session expiry, and kill-switch controls on preview and administrative surfaces;
- Workforce training on HIPAA obligations, and confidentiality agreements for personnel with access;
- Backup, integrity verification, and a documented disaster-recovery process.
Business Associate conducts a periodic risk analysis and maintains a written risk-management plan, and will provide a summary to Covered Entity on request for its compliance file.
6. Subcontractors
Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this BAA, in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2). Business Associate remains responsible to Covered Entity for its Subcontractors' performance. On request, Business Associate will provide a current list of Subcontractors with access to PHI and reasonable advance notice of a material addition.
7. Reporting and breach notification
Business Associate will report to Covered Entity:
- Any use or disclosure of PHI not permitted by this BAA of which it becomes aware, without unreasonable delay;
- Any Security Incident of which it becomes aware. The parties acknowledge this notice for unsuccessful Security Incidents that result in no unauthorized access, use, disclosure, modification, or destruction — such as routine firewall pings, port scans, and failed login attempts — with no additional notice required for those;
- Any Breach of Unsecured PHI, without unreasonable delay and no later than thirty (30) calendar days after discovery, which is sooner than the outer limit in 45 C.F.R. § 164.410 so Covered Entity retains time to meet its own 60-day obligation to Individuals.
A Breach notice will include, to the extent known: the Individuals affected, the nature and timing of the incident, the types of PHI involved, the steps taken to investigate, mitigate, and prevent recurrence, and a contact for follow-up. Business Associate will supplement as further information becomes available and will cooperate with Covered Entity's investigation and notification obligations. Business Associate will mitigate, to the extent practicable, any harmful effect of a use or disclosure that violates this BAA.
Unless a Breach is caused by Covered Entity, Business Associate will bear the reasonable, documented costs of investigation and of any notification to Individuals, regulators, and media that Covered Entity is required to make because of that Breach.
8. Individual rights
To the extent Business Associate maintains PHI in a Designated Record Set, it will:
- Access — make PHI available to Covered Entity, or to the Individual as directed, to satisfy 45 C.F.R. § 164.524, within ten (10) business days of Covered Entity's request;
- Amendment — make PHI available for amendment and incorporate amendments under § 164.526, within ten (10) business days of request;
- Accounting — document and make available the information required for an accounting of disclosures under § 164.528, within ten (10) business days of request;
- Restrictions — comply with restrictions and confidential-communication requests Covered Entity has agreed to and communicated to Business Associate;
- Government access — make its internal practices, books, and records relating to PHI available to the Secretary of Health and Human Services for determining compliance.
Business Associate will forward any request it receives directly from an Individual to Covered Entity rather than responding on its own, unless Covered Entity has instructed otherwise in writing.
9. Patient communications and automated assistance
Where Business Associate operates patient-facing chat, SMS, or voice on Covered Entity's behalf:
- The assistant identifies itself as an automated assistant and offers a path to a human at any time;
- It handles scheduling, intake, directions, hours, and administrative questions — it does not diagnose, triage clinically, give medical advice, or alter a treatment plan, and it escalates clinical questions to Covered Entity's authorized staff;
- It presents emergency instructions and directs callers to 911 or the nearest emergency department where the interaction suggests urgency;
- Recording, transcription, and retention occur only with notice and as permitted by this BAA and applicable state law, including all-party consent requirements;
- Communications are limited to treatment, payment, and health care operations purposes as directed by Covered Entity, and are not marketing under 45 C.F.R. § 164.501;
- Content, scripts, and escalation rules are configured by, and remain subject to approval by, Covered Entity.
Covered Entity is responsible for the clinical accuracy of content it approves and for its own Notice of Privacy Practices and patient consent processes.
10. De-identification
Business Associate may de-identify PHI only in accordance with 45 C.F.R. § 164.514(a)–(c), using either the Safe Harbor method or an Expert Determination. Properly de-identified information is not PHI and may be used for Business Associate's operations, benchmarking, quality improvement, and service improvement, and may be retained after termination. Business Associate will not attempt to re-identify it and will bind recipients to the same restriction. Business Associate will not sell de-identified data derived from Covered Entity's PHI and will not disclose it in a form that identifies Covered Entity without written consent.
11. Covered Entity obligations
Covered Entity will: maintain a compliant Notice of Privacy Practices and notify Business Associate of limitations that affect its use or disclosure of PHI; notify Business Associate of changes in, or revocation of, an Individual's permission; notify Business Associate of restrictions it has agreed to under § 164.522; provide only the minimum necessary PHI for the services; and not request that Business Associate use or disclose PHI in a way that would violate Subpart E if done by Covered Entity, except as permitted under Section 3.
12. Term and termination
This BAA takes effect on its execution date and continues until all PHI is returned or destroyed, or protections are extended under Section 13.
Termination for cause. If either party knows of a pattern of activity or practice of the other that constitutes a material breach of this BAA, it will provide written notice and a thirty (30) day opportunity to cure. If cure does not occur, the non-breaching party may terminate this BAA and the underlying Statement of Work. If termination is not feasible, the matter will be reported to the Secretary of Health and Human Services.
13. Return or destruction of PHI
On termination, Business Associate will return or securely destroy all PHI it maintains in any form and retain no copies, where feasible, and will extend the same requirement to Subcontractors. Where return or destruction is not feasible — including PHI in backups, archives, or records retained under a legal hold or Required by Law — Business Associate will notify Covered Entity in writing, extend the protections of this BAA to that PHI, and limit further use and disclosure to the purposes that make return or destruction infeasible, for as long as it retains the PHI. On request, Business Associate will provide written certification of destruction.
14. General
Regulatory references are to the sections as in effect or as amended. Amendment — the parties will take reasonable action to amend this BAA as necessary to comply with changes in HIPAA, HITECH, or their implementing regulations. Interpretation — ambiguity is resolved to permit compliance with HIPAA. State law — where a state law, including Florida's information-protection and medical-records statutes, is more stringent, the more stringent requirement applies. No third-party beneficiaries — nothing here creates rights in any Individual or third party. Survival — Sections 4, 7, 10, 13, and 14 survive termination. Governing law — Florida law governs, subject to federal preemption.
15. Request an executed BAA
Email connect@pmmedia-source.com with the subject line “BAA Request” and include your organization's legal name, the signatory's name and title, and the services in scope. We will return a countersigned copy, and we will also complete a standard security questionnaire or vendor-risk assessment for your compliance file on request.
We are able to sign Covered Entity's own BAA form in most cases. Send it with your request.
This standard form is provided for review. It is not legal advice to Covered Entity, and each organization should have its own privacy officer or counsel review before signing.
← Back to PM Media · Terms of Service · Privacy Policy · MedSync PM