Business Associate Agreement

This Business Associate Agreement ("BAA") is made by and between Novexx Health, LLC ("Novexx" or "Business Associate") and the healthcare practice, covered entity, or authorized customer using Novexx services ("Customer" or "Covered Entity"). This BAA supplements the customer agreement between the parties and applies when Novexx creates, receives, maintains, or transmits Protected Health Information on behalf of Customer.

Recitals

WHEREAS, Customer is or may be a covered entity or business associate under HIPAA and uses Novexx services in connection with healthcare operations, billing, clinical workflow, payment, or related practice management activities;

WHEREAS, Novexx may create, receive, maintain, or transmit Protected Health Information on behalf of Customer while providing the services;

WHEREAS, the parties intend to protect the privacy and security of Protected Health Information in accordance with HIPAA, the HITECH Act, and applicable implementing regulations;

NOW, THEREFORE, in consideration of the services and mutual obligations described below, the parties agree as follows:

I. Definitions

  1. Breach has the meaning assigned to it under 45 C.F.R. § 164.402.
  2. Electronic Protected Health Information or ePHI, means protected health information that is created, received, maintained, or transmitted electronically.
  3. Protected Health Information or PHI, has the meaning assigned under HIPAA and includes PHI Novexx creates, receives, maintains, or transmits on behalf of Customer.
  4. Security Incident has the meaning assigned under 45 C.F.R. § 164.304.
  5. Subcontractor means a person or entity to whom Novexx delegates a function, activity, or service involving PHI.

II. Permitted Uses and Disclosures

Novexx may use and disclose PHI only as necessary to provide the services, fulfill obligations under the customer agreement, comply with applicable law, and perform internal management, administration, security, and legal responsibilities.

Novexx will not use or disclose PHI in a manner that would violate HIPAA if done by Customer, except where HIPAA permits such use or disclosure by a business associate.

III. Safeguards

Novexx will use appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of ePHI.

Novexx will limit access to PHI to workforce members, systems, and subcontractors that need access to provide, secure, support, or improve the services.

IV. Reporting

Novexx will report to Customer any use or disclosure of PHI not permitted by this BAA that Novexx becomes aware of.

Novexx will report breaches of unsecured PHI and material security incidents involving ePHI without unreasonable delay and will provide information reasonably available to Novexx for Customer to meet its own obligations.

V. Subcontractors

Novexx may use subcontractors to provide, host, secure, or support the services. Novexx will require subcontractors that create, receive, maintain, or transmit PHI on Novexx's behalf to agree to restrictions and safeguards that are at least as protective as those in this BAA.

VI. Access, Amendment, and Accounting

To the extent PHI is maintained by Novexx and is not otherwise available to Customer through the services, Novexx will provide reasonable assistance so Customer can respond to individual requests for access, amendment, accounting of disclosures, or other HIPAA rights.

Customer remains responsible for determining whether an individual request is valid and for communicating directly with the requesting individual unless the parties agree otherwise in writing.

VII. Return or Destruction

Upon termination of the services, Novexx will return or destroy PHI as required by the applicable customer agreement and law, unless return or destruction is infeasible or continued retention is required for legal, security, backup, or audit purposes.

Any retained PHI will remain subject to the protections of this BAA for as long as Novexx maintains it.

VIII. Term and Termination

This BAA applies while Novexx maintains PHI on behalf of Customer. Either party may terminate the applicable services if the other party materially breaches this BAA and fails to cure the breach within a reasonable period after written notice, where cure is possible.

IX. Interpretation

This BAA is intended to comply with HIPAA and will be interpreted consistently with HIPAA and related regulations. If any provision is invalid or unenforceable, the remaining provisions will remain in effect to the extent permitted by law.

This page provides Novexx's standard BAA language for customers. It is not legal advice, and practices should review their own HIPAA obligations with counsel.