United States · HIPAA
HIPAA Business Associate Agreement
Version 2026-09-11Effective 11 September 2026
This document is incorporated by reference into 2care.ai service agreements. Where it conflicts with a signed Order Form, the Order Form controls the specific item it addresses.
This HIPAA Business Associate Agreement (the BAA) applies to the processing of Protected Health Information (PHI) by 2Care AI Inc. (the Business Associate) on behalf of the clinic identified on the Order Form (the Covered Entity) in connection with the Services. It is incorporated by reference into, and governed alongside, that Service Agreement; execution of the Order Form executes this BAA. Execution of this BAA is a condition precedent to the Business Associate processing any PHI on the Covered Entity's behalf.
1. Definitions
Capitalized terms not defined here have the meanings given in the HIPAA Rules (45 C.F.R. Parts 160 and 164). Breach, Required by Law, Security Incident and Unsecured PHI have the meanings in those Rules. PHI is limited to information the Business Associate creates, receives, maintains or transmits on behalf of the Covered Entity. ePHI means PHI in electronic form. Subcontractor means a person to whom the Business Associate delegates a function involving the use or disclosure of PHI.
2. Permitted uses and disclosures
The Business Associate may use or disclose PHI only: as necessary to perform its obligations under the Agreement, including operating and maintaining the Services; as Required by Law; for its proper management and administration, provided disclosure is Required by Law or made under reasonable assurances of confidential treatment; and for data-aggregation services relating to the Covered Entity's health-care operations as permitted under 45 C.F.R. § 164.504(e)(2)(i)(B).
The Business Associate will not use or disclose PHI for any other purpose, including marketing, commercial benefit, or AI/ML model training or improvement, regardless of whether the PHI has been de-identified, aggregated or transformed, unless full de-identification complies with 45 C.F.R. § 164.514(b).
3. Safeguards
The Business Associate will implement and maintain appropriate administrative, physical and technical safeguards in accordance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), including:
- Encryption of ePHI in transit and at rest using industry-standard methods.
- Role-based access controls limiting access to personnel who require it to perform their duties for the Covered Entity.
- Unique user authentication and logging of access to systems that store or process ePHI.
- Periodic review of access permissions, with prompt revocation on a change in role or termination.
The Business Associate will make a summary of relevant security policies available to the Covered Entity on written request.
4. Subcontractors
Before disclosing PHI to any Subcontractor, the Business Associate will execute a written agreement requiring the Subcontractor to comply with the same restrictions and conditions that apply to the Business Associate under this BAA. The Business Associate remains responsible for Subcontractors' compliance to the extent required by HIPAA.
5. Reporting obligations
- Breach notification: no later than 30 calendar days after discovery of a Breach of Unsecured PHI, in accordance with 45 C.F.R. § 164.410, including to the extent known the affected individuals, a description of the Breach, the types of PHI involved, recommended protective steps, remediation actions and contact information.
- Security Incidents: without unreasonable delay upon awareness of any Security Incident involving ePHI.
- Unpermitted use or disclosure: within 5 business days of discovery of any use or disclosure of PHI not permitted by this BAA.
This section is deemed satisfied without further notice for routine unsuccessful attempts at unauthorized access (for example blocked login attempts or routine port scans) that do not result in actual access to, or disclosure of, PHI.
6. Individual rights
Within 30 days of a written request from the Covered Entity, the Business Associate will provide access to PHI in a Designated Record Set (45 C.F.R. § 164.524), make PHI available for amendment and incorporate directed amendments (§ 164.526), maintain records of disclosures sufficient to support an accounting for at least 6 years (§ 164.528), and accommodate reasonable restrictions on PHI use or disclosure directed in writing by the Covered Entity.
7. HHS inspection and minimum necessary
The Business Associate will make its internal practices, books and records relating to PHI available to the Secretary of HHS for compliance determinations within a reasonable time upon request, and will use, disclose and request only the minimum amount of PHI necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.502(b).
8. Obligations of the Covered Entity
- Notify the Business Associate of any limitation in its Notice of Privacy Practices that may affect the Business Associate's use or disclosure of PHI.
- Notify the Business Associate of any change in, or revocation of, patient permissions affecting permitted uses or disclosures.
- Notify the Business Associate of any restriction on PHI use or disclosure agreed under 45 C.F.R. § 164.522.
- Obtain all authorizations and consents required by HIPAA before submitting PHI to the Services.
- Not request the Business Associate to use or disclose PHI in any manner that would be impermissible if done by the Covered Entity itself.
9. Term and termination
This BAA is effective on the effective date of the Agreement and continues until termination of the Agreement or this BAA. Either party may terminate on 30 days' written notice if the other materially breaches this BAA and fails to cure within the notice period; if cure is not possible, the non-breaching party may terminate immediately.
On termination for any reason, the Business Associate will, at the Covered Entity's written election, return or destroy all PHI (including copies held by Subcontractors) and certify destruction in writing. Where return or destruction is infeasible, the Business Associate will notify the Covered Entity with the reason, continue applying this BAA's protections, and limit further use or disclosure solely to the purposes making return or destruction infeasible. Obligations relating to return or destruction of PHI and to Breaches discovered before termination survive indefinitely.
10. General
This BAA will be interpreted broadly to implement and comply with the HIPAA Rules, and ambiguities resolved in favor of a meaning that permits the Covered Entity to comply with HIPAA. It is governed by the laws of the State of Delaware and the liability provisions of the Agreement apply, except where applicable law does not permit liability to be limited. This BAA does not confer rights on any patient or other third party. This document is a plain-language template and not legal advice; both parties should have it reviewed by qualified counsel.