Trust centerSample · not executed
Business Associate Agreement.
The following is the PracticeIQ BAA template, modeled on the HHS sample BAA. We sign a BAA before any Protected Health Information (PHI) is processed. Send redlines to christian@practiceiq.tech.
Version 1.1 · Last updated 2026-04-15
Section 1 · Definitions
Terms used but not defined here have the meaning set out in the HIPAA Rules (45 CFR Parts 160, 162, and 164). “Covered Entity” refers to Customer; “Business Associate” refers to PracticeIQ.
Section 2 · Permitted uses and disclosures
Business Associate may use or disclose PHI only as necessary to perform Services, as required by law, or as otherwise permitted by this BAA. PHI is never sold, rented, or used for marketing.
Section 3 · Safeguards
Business Associate will maintain appropriate administrative, physical, and technical safeguards per 45 CFR § 164.308, 310, 312, and 316 to prevent unauthorized use or disclosure of PHI. Current safeguards are published at /security.
Section 4 · Reporting
Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this BAA, and any breach of Unsecured PHI, within 15 calendar days of discovery (60-day statutory maximum applies).
Section 5 · Subcontractors
Business Associate will ensure any agent or subcontractor that handles PHI on its behalf agrees in writing to the same restrictions. Current subprocessors are published at /legal/subprocessors.
Section 6 · Access, amendment, and accounting
Within 30 days of request, Business Associate will make PHI available to Covered Entity (or the subject individual) for access and amendment, and provide an accounting of disclosures per 45 CFR § 164.528.
Section 7 · Termination
Upon termination, Business Associate will return or destroy all PHI received from Covered Entity. Where return/destruction is infeasible, protections are extended for the duration PHI is retained.
Section 8 · Term
Effective on execution; remains in effect until termination of the Services agreement. Obligations surrounding PHI survive termination.
Section 9 · Miscellaneous
This BAA is governed by the laws of Delaware, USA. Any conflict with the Services agreement is resolved in favor of protecting PHI.
Ready to execute? We'll prepare a signed copy with your practice details.
Request signed BAA