Business Associate Agreement (BAA)
Version: 1.0 Effective Date: [DATE] Status: Template
PARTIES
This Business Associate Agreement ("Agreement") is entered into by and between:
Covered Entity: [CUSTOMER NAME] Address: [CUSTOMER ADDRESS] Contact: [CUSTOMER CONTACT]
Business Associate: Cynthia Sylvia / LNC Nexus Address: [BUSINESS ASSOCIATE ADDRESS] Contact: sshaffer@woclegalnurse.net
(Collectively referred to as the "Parties")
RECITALS
WHEREAS, Covered Entity is subject to the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH");
WHEREAS, Covered Entity wishes to engage Business Associate to perform services that may involve access to Protected Health Information ("PHI");
WHEREAS, Business Associate agrees to comply with applicable HIPAA requirements;
NOW, THEREFORE, the Parties agree as follows:
1. DEFINITIONS
1.1 Protected Health Information (PHI)
PHI means individually identifiable health information transmitted or maintained in any form or medium that is created or received by a covered entity, and relates to:
- The past, present, or future physical or mental health or condition of an individual
- The provision of health care to an individual
- The past, present, or future payment for health care
1.2 HIPAA Regulations
References to HIPAA regulations include 45 CFR Parts 160 and 164 as amended.
1.3 HITECH Act
References to HITECH include applicable provisions of the HITECH Act and implementing regulations.
2. PERMITTED USES AND DISCLOSURES OF PHI
2.1 Permitted Uses
Business Associate may use PHI only for the purpose of providing services to Covered Entity as described in this Agreement.
2.2 Permitted Disclosures
Business Associate may disclose PHI only:
- To Covered Entity
- As required by law
- For proper management and administration of Business Associate
- As expressly permitted by this Agreement
2.3 Prohibited Uses
Business Associate shall NOT:
- Use PHI for marketing purposes
- Sell PHI
- Use PHI for any purpose not permitted by HIPAA
- Use PHI for training AI models without explicit authorization
3. SAFEGUARDS
3.1 Administrative Safeguards
Business Associate shall implement:
- Security management processes
- Assigned security responsibility
- Workforce security procedures
- Information access management
- Security awareness and training
- Incident procedures
- Contingency plans
- Periodic evaluations
3.2 Physical Safeguards
Business Associate shall implement:
- Facility access controls
- Workstation use policies
- Device and media controls
3.3 Technical Safeguards
Business Associate shall implement:
- Access control mechanisms
- Audit controls
- Integrity controls
- Authentication procedures
- Transmission security
- Encryption appropriate to the data and deployment risk
3.4 Minimum Necessary
Business Associate shall limit PHI access to the minimum necessary to accomplish the intended purpose.
4. REPORTING REQUIREMENTS
4.1 Breach Notification
Business Associate shall report any breach of unsecured PHI:
- Within 24 hours of discovery for critical breaches
- Within 72 hours for all other breaches
- Include: nature of breach, PHI involved, affected individuals, mitigation measures
4.2 Security Incidents
Business Associate shall report security incidents that may affect PHI within 72 hours of discovery.
4.3 Unauthorized Use or Disclosure
Business Associate shall report any unauthorized use or disclosure of PHI within 72 hours.
5. SUBCONTRACTORS
5.1 Flow-Down Requirements
Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions and conditions that apply to Business Associate.
5.2 Subcontractor List
Business Associate shall maintain a list of subcontractors with access to PHI and provide it to Covered Entity upon request.
5.3 Current Subcontractors
The current subcontractor list, service scope, and access boundary are provided to covered entities through the private contracting process and are not published in this public template.
6. ACCESS TO PHI
6.1 Individual Access
Business Associate shall provide access to PHI to individuals or their designees as required by 45 CFR 164.524.
6.2 Amendment
Business Associate shall incorporate amendments to PHI as required by 45 CFR 164.526.
6.3 Accounting of Disclosures
Business Associate shall provide accounting of disclosures as required by 45 CFR 164.528.
6.4 Access to Records
Business Associate shall make internal practices, books, and records relating to PHI available to the Secretary of HHS for compliance determination.
7. TERMINATION
7.1 Termination for Cause
Covered Entity may terminate this Agreement immediately if Business Associate materially breaches the Agreement.
7.2 Effect of Termination
Upon termination, Business Associate shall:
- Return or destroy all PHI
- If return/destruction not possible, extend protections indefinitely
- Continue to comply with BAA requirements for received PHI
7.3 Transition Assistance
Business Associate shall provide reasonable assistance during transition to a new vendor.
8. COMPLIANCE
8.1 HIPAA Compliance
Business Associate represents compliance with applicable HIPAA requirements.
8.2 Audits
Business Associate shall permit audits and assessments by Covered Entity or HHS.
8.3 Documentation
Business Associate shall maintain documentation of policies and procedures for 6 years.
8.4 Training
Business Associate shall provide security awareness training to all workforce members.
9. MISCELLANEOUS
9.1 Governing Law
This Agreement shall be governed by federal HIPAA regulations and applicable state law.
9.2 Amendments
This Agreement may only be amended in writing signed by both Parties.
9.3 Severability
If any provision is held invalid, the remainder shall remain in effect.
9.4 Entire Agreement
This Agreement constitutes the entire agreement between the Parties regarding PHI.
9.5 Relationship
Nothing in this Agreement creates an agency, partnership, or joint venture.
10. SIGNATURES
COVERED ENTITY:
Signature: _________________________ Name: [NAME] Title: [TITLE] Date: [DATE]
BUSINESS ASSOCIATE:
Signature: _________________________ Name: Cynthia Sylvia Title: [TITLE] Date: [DATE]
APPENDIX A: SECURITY CONTROLS
LNC Nexus maintains application, administrative, and operational safeguards appropriate to the deployment. A deployment-specific control schedule, evidence packet, and responsibility matrix are provided through the private contracting and security-review process.
Physical safeguards, endpoint controls, network boundaries, storage, key management, backup schedules, and retention periods are determined by the environment and the executed agreement.
APPENDIX B: DATA RETENTION
Retention periods, legal holds, backup handling, and secure-disposal methods are agreed in the customer’s data-processing and retention schedule. This public template does not publish operational retention values.
APPENDIX C: CONTACT INFORMATION
Security Contact: Email: sshaffer@woclegalnurse.net Phone: [PHONE]
Compliance Contact: Email: sshaffer@woclegalnurse.net Phone: [PHONE]
Breach Reporting: Email: sshaffer@woclegalnurse.net Response Time: As specified in the executed agreement
Document Control:
- Version: 1.0
- Created: 2026-07-14
- Next Review: 2027-07-14
- Owner: Legal/Security Team
- Status: Template - Requires Legal Review
Disclaimer: This is a template BAA and should be reviewed by legal counsel before use. Specific terms may need to be adjusted based on customer requirements and applicable laws.