← EMRFlow

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement ("Agreement") is entered into between Facets Novum LLC d/b/a EMRFlow ("Business Associate" or "EMRFlow") and the individual or entity that accepts this Agreement through its EMRFlow account ("Covered Entity" or "Customer").

Acceptance and Effective Date. Covered Entity accepts this Agreement electronically when it creates an EMRFlow Solo Practice account, or otherwise affirmatively clicks to accept, through which this Agreement is presented. The "Effective Date" is the date and time of that acceptance, which EMRFlow records together with the version of this Agreement accepted. The individual accepting represents and warrants that they are authorized to enter into this Agreement on behalf of the Covered Entity and to bind it. No physical or electronic signature is required beyond this affirmative acceptance.

Identification of the Parties. The identity of the Covered Entity — including its legal or practice name, license type, National Provider Identifier (where provided), and contact information — is the information associated with the accepting EMRFlow account, as it may be updated by the Covered Entity from time to time. Business Associate is a Georgia limited liability company. (State of formation and principal place of business to be confirmed by counsel.)

Covered Entity and Business Associate are each a "Party" and collectively, the "Parties".

1. Background

1.1. Covered Entity is a "covered entity" as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as amended, and its implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Rules").

1.2. Business Associate provides EMRFlow, a software-as-a-service electronic health records and practice-management platform, to Covered Entity pursuant to the EMRFlow Terms and Conditions and applicable subscription terms (the "Services Agreement") and, in connection therewith, will create, receive, maintain, or transmit Protected Health Information ("PHI") on behalf of Covered Entity.

1.3. The Parties wish to enter into this Agreement to comply with the HIPAA Rules' requirements for business associate agreements, in particular 45 C.F.R. § 164.504(e).

1.4. Capitalized terms not otherwise defined in this Agreement have the meanings given to them in the HIPAA Rules.

2. Permitted Uses and Disclosures of PHI

2.1. Use and Disclosure to Provide the Services. Business Associate may use and disclose PHI as necessary to perform the services described in the Services Agreement and as otherwise permitted by this Agreement.

2.2. Management and Administration; Legal Responsibilities. Business Associate may use and disclose PHI for its proper management and administration and to carry out its legal responsibilities, provided that any disclosure is required by law or, before the disclosure, the recipient agrees in writing to (a) maintain the confidentiality of the PHI and use or further disclose it only as required by law or for the purpose for which it was disclosed, and (b) notify Business Associate of any breach of confidentiality.

2.3. Data Aggregation Services. Business Associate may use PHI to provide data aggregation services to Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).

2.4. De-identification. Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c) and use or disclose the resulting de-identified information for any lawful purpose.

2.5. Minimum Necessary. Business Associate will limit its use and disclosure of PHI, and requests for PHI, to the minimum necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.502(b).

3. Obligations of Business Associate

3.1. Use and Disclosure Limits. Business Associate will not use or further disclose PHI other than as permitted or required by this Agreement or as required by law.

3.2. Safeguards. Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with the Security Rule's requirements at 45 C.F.R. Part 164, Subpart C, with respect to electronic PHI, to prevent the use or disclosure of PHI other than as provided for by this Agreement.

3.3. Reporting of Improper Use or Disclosure. Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement of which it becomes aware. Such report will be made promptly, and in any event within five (5) business days of discovery, except for security incidents involving unsuccessful attempts to access PHI (which will be reported on an aggregate basis upon request).

3.4. Breach Notification. Business Associate will notify Covered Entity of any Breach of Unsecured PHI in accordance with 45 C.F.R. § 164.410. The notification will be made without unreasonable delay and in no case later than thirty (30) calendar days after Business Associate's discovery of the Breach. The notification will include, to the extent known: the identification of each individual whose PHI has been or is reasonably believed to have been accessed, acquired, used, or disclosed; a description of what happened; the types of PHI involved; the steps individuals should take to protect themselves; and a brief description of what Business Associate is doing to investigate, mitigate harm, and prevent recurrence.

3.5. Subcontractors. Business Associate will require any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate to enter into a written agreement that imposes substantially the same restrictions and conditions on the subcontractor that apply to Business Associate under this Agreement, in accordance with 45 C.F.R. § 164.502(e)(1)(ii).

3.6. Access to PHI. Within fifteen (15) business days of a request from Covered Entity, Business Associate will make available PHI in a Designated Record Set to Covered Entity (or, as directed by Covered Entity, to the individual) as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524.

3.7. Amendment of PHI. Within fifteen (15) business days of a request from Covered Entity, Business Associate will make any amendment(s) to PHI in a Designated Record Set as Covered Entity directs or agrees to, in accordance with 45 C.F.R. § 164.526.

3.8. Accounting of Disclosures. Business Associate will maintain and, upon request, provide an accounting of disclosures of PHI as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.528, retaining such information for at least six (6) years from the date of disclosure.

3.9. Internal Practices, Books, and Records. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI received from Covered Entity available to the Secretary of the U.S. Department of Health and Human Services as required for purposes of determining Covered Entity's compliance with the HIPAA Rules.

3.10. Mitigation. Business Associate will mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI in violation of this Agreement.

4. Obligations of Covered Entity

4.1. Notice of Privacy Practices. Covered Entity will notify Business Associate of any limitation(s) in Covered Entity's Notice of Privacy Practices to the extent that such limitation may affect Business Associate's use or disclosure of PHI.

4.2. Restrictions and Authorizations. Covered Entity will notify Business Associate of (a) any changes in, or revocation of, an individual's authorization to use or disclose PHI, and (b) any restriction on the use or disclosure of PHI to which Covered Entity has agreed under 45 C.F.R. § 164.522, to the extent that any of the foregoing may affect Business Associate's use or disclosure of PHI.

4.3. Permissible Requests. Covered Entity will not request that Business Associate use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as permitted by this Agreement.

5. Term and Termination

5.1. Term. This Agreement is effective as of the Effective Date and continues for the duration of the Services Agreement, unless terminated earlier as provided herein.

5.2. Termination for Breach. Either Party may terminate this Agreement upon thirty (30) days' written notice if the other Party materially breaches this Agreement and fails to cure the breach within the notice period. If neither cure nor termination is feasible, the non-breaching Party will report the violation to the Secretary of the U.S. Department of Health and Human Services.

5.3. Effect of Termination. Upon termination of this Agreement, Business Associate will, to the extent feasible, return to Covered Entity or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity. If return or destruction is not feasible, Business Associate will extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible. Business Associate will provide Covered Entity with written certification of the disposition of PHI within thirty (30) days of termination.

6. Miscellaneous

6.1. Regulatory References. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

6.2. Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the HIPAA Rules and any other applicable law.

6.3. Survival. The respective rights and obligations of Business Associate under Section 5.3 survive termination of this Agreement.

6.4. Interpretation. Any ambiguity in this Agreement will be resolved in favor of a meaning that permits compliance with the HIPAA Rules.

6.5. No Third-Party Beneficiaries. Nothing in this Agreement is intended to confer, nor will anything herein confer, any rights or remedies upon any person other than the Parties.

6.6. Counterparts. This Agreement may be executed in counterparts, each of which will be deemed an original, but all of which together will constitute one and the same instrument. Electronic signatures (including DocuSign) are acceptable.

6.7. Governing Law. This Agreement is governed by the laws of the State of Georgia, without regard to its conflict-of-laws principles. (Governing-law choice to be confirmed by counsel and kept consistent with the EMRFlow Terms and Conditions.)

6.8. Entire Agreement. This Agreement, together with the Services Agreement, constitutes the entire agreement between the Parties regarding the subject matter hereof and supersedes all prior agreements and understandings.


Acceptance

By clicking to accept — or by creating an EMRFlow Solo Practice account through which this Agreement is presented — Covered Entity agrees to be bound by this Business Associate Agreement as of the Effective Date. The individual accepting represents that they are authorized to bind the Covered Entity. No separate physical or electronic signature is required. EMRFlow records the version accepted, together with the date and time of acceptance, as evidence of this Agreement, and makes the accepted version available to Covered Entity within the Service.

Business Associate: Facets Novum LLC d/b/a EMRFlow