EXHIBIT C – BUSINESS ASSOCIATE AGREEMENT
MULHOLLAND, INC.
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement (“BAA”) is entered into as of [EFFECTIVE DATE] by and between [INSERT CUSTOMER NAME] (“Covered Entity”) and Mulholland, Inc., a Delaware corporation (“Business Associate”). This BAA supplements and is incorporated into the Master Services Agreement between the Parties (the “MSA”) and applies where Business Associate creates, receives, maintains, or transmits (“process/es”) Protected Health Information on behalf of Covered Entity in providing the Platform or performing the Services under the MSA. To the extent of any conflict between this BAA and the MSA or any related addenda regarding Protected Health Information subject to HIPAA Rules, this BAA controls. For clarity, in the event Business Associate is a subcontractor and “Covered Entity” is a “business associate” (as such term is defined under 45 C.F.R. § 164.103), then all terms will be read the same and any references to “Business Associate” shall be read as “Subcontractor” and all references to “Covered Entity” shall be read as “Business Associate”.
RECITALS
Covered Entity is, or acts on behalf of, a covered entity or business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the HITECH Act (collectively, “HIPAA”). Business Associate provides services to Covered Entity that involve the use or disclosure of Protected Health Information. This BAA applies to all PHI that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity in providing the Platform or performing the Services (including Professional Services and support), wherever that processing occurs; an Order Form identifies the portions of the Platform subject to this BAA. Covered Entity agrees not to submit PHI to Business Associate as part of Customer Data except as explicitly permitted under an Order Form executed by the parties. The Parties enter into this BAA to comply with the requirements of HIPAA, including 45 C.F.R. § 164.504(e), as applicable to each respective party.
1. Definitions
Capitalized terms used but not defined in this BAA have the meanings given to them in HIPAA. The following terms have the meanings set out below:
“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Part 160 and Part 164.
“Subcontractor” means a person to whom Business Associate delegates a function, activity, or service to process PHI in its provision of the Platform or performance of the Services, other than a member of Business Associate’s workforce.
The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information (including ePHI) (“PHI”), Required By Law, Secretary, Security Incident, Unsecured Protected Health Information, and Use.
The following terms used in this Agreement shall have the same meaning as those terms in the MSA: “Platform” and “Services”, except that “Services” includes any Free Services (as defined in the MSA) that involve PHI.
For any other capitalized term not defined in this BAA, such shall have the meaning set forth in the following order of precedence: (1) HIPAA Rules; and (2) the MSA.
2. Obligations and Activities of Business Associate
Business Associate agrees to:
(a) not use or disclose PHI other than as permitted or required by this BAA, including to provide the services under the MSA, or as Required by Law;
(b) use appropriate safeguards, and comply, where applicable, with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this BAA;
(c) report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including any confirmed Security Incident of which it becomes aware; and report any Breach of Unsecured PHI without unreasonable delay and in any event within the shorter of (i) ten (10) days after discovery (as 45 C.F.R. § 164.410(a)(2) defines it) and (ii) any shorter period that applicable law requires of Business Associate (including Fla. Stat. § 501.171(6)(a)), supplementing the report as information becomes available. The Parties agree that this BAA constitutes notice of the ongoing occurrence of unsuccessful Security Incidents (such as but not limited to routine, unsuccessful access attempts and pings, attempts to log on to a system with an invalid password or username, malware, and denial-of-service attacks that do not result in a server being taken off-line) for which no further notice is required;
(d) in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate with respect to PHI under this BAA;
(e) make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.524, to the extent Business Associate maintains such PHI;
(f) make any amendment(s) to PHI in a Designated Record Set as directed or agreed by Covered Entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations, to the extent Business Associate maintains such PHI;
(g) maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.528;
(h) to the extent Business Associate is to carry out one or more of Covered Entity’s obligations under Subpart E of 45 C.F.R. Part 164 (the Privacy Rule), comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s);
(i) make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules; and
(j) request, use, and disclose only the minimum necessary PHI to accomplish the intended purpose of the use, disclosure, or request, consistent with 45 C.F.R. § 164.502(b).
3. Permitted Uses and Disclosures by Business Associate
3.1 Service Performance. Except as otherwise limited by this BAA, Business Associate may use and disclose PHI to provide the Platform and perform the Services for Covered Entity, provided such use or disclosure would not violate the HIPAA Rules if done by Covered Entity.
3.2 Management and Administration. Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities. Business Associate may disclose PHI for such purposes only if the disclosure is Required by Law, or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
3.3 Data Aggregation. Business Associate may use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity.
3.4 De-identification.
(a) Authorization. Pursuant to 45 C.F.R. § 164.502(d), Covered Entity authorizes Business Associate to use PHI that Business Associate receives or creates under this BAA to create information that is de-identified in accordance with 45 C.F.R. § 164.514(a)–(c), whether or not Covered Entity will use that information, including for Business Associate’s own purposes under Section 3.3 of the MSA. De-identification is part of the Services covered by this BAA and is performed only within Covered Entity’s logically isolated environment on the Platform, as Section 3.3(d)(i) of the MSA requires. This Section 3.4 does not apply to PHI that Business Associate first received or created before the Effective Date, or to anything derived from it.
(b) Method. Business Associate will de-identify PHI either (i) by expert determination under 45 C.F.R. § 164.514(b)(1), which it will use for free text, documents, images, and model inputs and outputs, which will be in writing and in effect before Business Associate first uses PHI under this Section 3.4, which will treat Business Associate itself (which retains the identified PHI and any codes, keys, and dataset-source records) and every person to whom a resulting model is made available as anticipated recipients, which will be renewed when its stated term ends or its assumptions change, whose conditions Business Associate will follow, and which will address the use of the resulting information to train models made available to others; or (ii) for structured data fields only, by the safe harbor method under 45 C.F.R. § 164.514(b)(2). Business Associate will use only the minimum necessary PHI that it already holds to provide the Platform and perform the Services, will not request or receive PHI for this purpose, will not use PHI subject to a restriction notified under Section 4.1 that prohibits this use, and will document its methods and the results of its analysis as 45 C.F.R. § 164.514(b) requires, retain that documentation for at least six (6) years, and give Covered Entity a summary on request.
(c) Codes. Any code or other means of record identification will meet 45 C.F.R. § 164.514(c): it will not be derived from or related to information about the individual, will not be capable of being translated to identify the individual, and will not be used or disclosed for any other purpose. Any such code, and any key that links it to an individual, is PHI.
(d) Status and Use. Information de-identified under this Section 3.4 is not PHI, and, except for this Section 3.4, this BAA does not apply to it. It is De-Identified Data, whose use and ownership Section 3.3 of the MSA governs, only if it also meets the MSA’s definition of De-Identified Data; Business Associate will use any other de-identified information only to provide the Platform and perform the Services for Covered Entity. Information that is re-identified, or that does not meet this Section 3.4, remains PHI subject to this BAA. Business Associate will not use De-Identified Data derived from PHI, or any Mulholland Model, to solicit or market goods or services to any patient of Covered Entity.
(e) No Remuneration. This authorization is a standard term that applies equally to paid and free services. Business Associate provides no payment, discount, credit, or other remuneration, direct or indirect, in exchange for PHI or for this authorization.
(f) California. To the extent this BAA, or any permitted transfer of De-Identified Data derived from PHI, is a sale or license of information that has met the requirements of Cal. Civ. Code § 1798.146(a)(4): (i) the deidentified information being sold or licensed includes deidentified patient information; (ii) reidentification, and attempted reidentification, of the deidentified information by the purchaser or licensee of the information is prohibited pursuant to Cal. Civ. Code § 1798.148; and (iii) unless otherwise required by law, the purchaser or licensee of the deidentified information may not further disclose the deidentified information to any third party unless the third party is contractually bound by the same or stricter restrictions and conditions. Business Associate will include these statements in each contract under which it transfers such information.
(g) Failed De-identification. If Business Associate discovers, within the meaning of 45 C.F.R. § 164.410(a)(2), that information it has used or disclosed as de-identified under this Section 3.4 is PHI, including because a model can output it, (i) each such use or disclosure is a use or disclosure not provided for by this BAA, reportable under Section 2(c) within the time Section 2(c) requires and with the information 45 C.F.R. § 164.410(c) requires; (ii) Business Associate will stop using and disclosing the information, require each recipient to do the same and to return or destroy it, remove it from every dataset, and retrain, modify, or retire every model that can output it, in each case without unreasonable delay and in any event before termination of this BAA; and (iii) Business Associate will mitigate, to the extent practicable, any harmful effect known to it. Section 3.3(g) of the MSA does not limit this Section 3.4(g).
4. Obligations of Covered Entity
4.1 Notice and Authorizations. Covered Entity will promptly notify Business Associate of any limitation(s) in its notice of privacy practices, any changes in or revocation of permission by an individual to use or disclose PHI, and any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, in each case to the extent such limitation, change, revocation, or restriction may affect Business Associate’s use or disclosure of PHI.
4.2 Permissible Requests. Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as permitted under Sections 3.2 (Management and Administration), 3.3 (Data Aggregation), and subject to any legal responsibilities of the Business Associate.
4.3 Consents. Covered Entity will obtain all required authorizations and consents required under applicable law, including state and local laws, for Business Associate’s processing of PHI as permitted herein, except that Business Associate will not use PHI under Section 3.4 where applicable law requires an authorization or consent for that use that has not been obtained, and Business Associate, not Covered Entity, is responsible for determining whether any such authorization or consent is required.
5. Term and Termination
5.1 Term. This BAA is effective as of the Effective Date and remains in effect until all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned, or, if return or destruction is infeasible, protections are extended in accordance with Section 5.3. From the Effective Date, this BAA also applies to PHI that Business Associate created, received, maintained, or transmitted on behalf of Covered Entity before the Effective Date.
5.2 Termination for Cause. If Covered Entity determines that Business Associate has materially breached this BAA, Covered Entity may provide an opportunity to cure within thirty (30) days and, if Business Associate does not cure, terminate this BAA and any related services agreement; or, if cure is not possible, terminate this BAA.
5.3 Effect of Termination. On termination, Business Associate will, if feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity that Business Associate (and its Subcontractors) maintains, and retain no copies. If return or destruction is not feasible, Business Associate will extend the protections of this BAA to the retained PHI, limit further uses and disclosures to those purposes that make return or destruction infeasible, and continue these protections for as long as it retains the PHI.
5.4 Termination of PHI Processing. Business Associate may suspend or terminate the processing of PHI if it reasonably determines it can no longer comply with its obligations herein, and the Parties will cooperate in good faith to transition or wind down such processing.
6. Miscellaneous
6.1 Regulatory References. A reference to a section in the HIPAA Rules means the section as in effect or as amended.
6.2 Amendment. The Parties will take such action as is necessary to amend this BAA from time to time as is necessary for compliance with the HIPAA Rules and other applicable law.
6.3 Interpretation. Any ambiguity in this BAA will be resolved to permit the Parties to comply with the HIPAA Rules.
6.4 Survival. Business Associate’s obligations under Sections 3.4 and 5.3 survive termination.
6.5 No Third-Party Beneficiaries. Nothing in this BAA confers any rights on any person other than the Parties.
6.6 Relationship to MSA. The MSA remains in full force except as expressly modified by this BAA. Each Party’s liability arising out of or relating to this BAA is subject to the limitations of liability set forth in the MSA, except to the extent prohibited by applicable law and except as follows. Notwithstanding Sections 7.2 and 7.4 of the MSA and any other limitation of liability in the MSA (including as they apply to Free Services and Professional Services), each Party’s aggregate liability arising out of or relating to Protected Health Information, including under this BAA and under Section 3.3 of the MSA as to Protected Health Information, will not exceed One Million Dollars ($1,000,000), except to the extent applicable law prohibits that limitation; Sections 7.1 and 7.3 of the MSA continue to apply.
6.7 Notices. Any notice under this BAA must be in writing and sent to the receiving Party at the contact below, or to another address a Party later designates in writing, and is deemed given on receipt. Reports of a Breach or Security Incident under Section 2(c) must be sent to the Covered Entity contact below by email without undue delay. For Business Associate (Mulholland, Inc.): legal@mulholland.ai. For Covered Entity (CUSTOMER NAME): [name, title, and email to be completed].
6.8 Permitted Use; MSA Use Restrictions. Notwithstanding Sections 2.2(e) and 2.2(g) of the MSA, Covered Entity is permitted to use the Platform to process Protected Health Information solely for operational and business analytics on Customer Data that may contain Protected Health Information, subject to this BAA. This BAA does not authorize use of Output to provide clinical, diagnostic, or treatment advice.
6.9 Limitation of Liability. Except as Section 6.6 provides, the limitations of liability set forth in the MSA apply to this BAA.
IN WITNESS WHEREOF, the parties have executed this BAA as of the Effective Date.
MULHOLLAND, INC.
By: ____________________________________
Name: ____________________________________
Title: ____________________________________
Date: ____________________________________
[CUSTOMER NAME]
By: ____________________________________
Name: ____________________________________
Title: ____________________________________
Date: ____________________________________