Business Associate Agreement
Effective Date: Upon account activation for healthcare providers
This Business Associate Agreement (“BAA”) supplements the TallyFlex Terms of Service for users who are Covered Entities or Business Associates under HIPAA.
Definitions
- “PHI” means Protected Health Information as defined by HIPAA
- “Covered Entity” means you, the healthcare provider using TallyFlex
- “Business Associate” means TallyFlex, LLC
- “HIPAA” means the Health Insurance Portability and Accountability Act
Business Associate Obligations
TallyFlex agrees to:
Use and Disclosure
- Use PHI only to provide TallyFlex services
- Not use or disclose PHI except as permitted by this BAA and HIPAA
- Use minimum necessary PHI to accomplish intended purposes
Safeguards
- Implement administrative, physical, and technical safeguards
- Comply with HIPAA Security Rule (45 CFR Part 164, Subpart C)
- Encrypt PHI at rest and in transit
Breach Notification
- Report breaches of unsecured PHI within 24 hours of discovery
- Discovery means when we first become aware or reasonably should have become aware
- Provide details required by HIPAA Breach Notification Rule
- Cooperate with Covered Entity’s breach response
Subcontractors
- Ensure subcontractors agree to same restrictions
- Obtain written agreement before sharing PHI
- Remain responsible for subcontractor compliance
Access and Amendment
- Provide access to PHI as directed by Covered Entity
- Make amendments to PHI as directed
- Maintain audit logs for 7 years
Covered Entity Obligations
You agree to:
- Obtain necessary patient authorizations
- Provide notice of privacy practices to patients
- Notify us of any restrictions on PHI use
- Use appropriate safeguards when transmitting PHI
Permitted Uses
TallyFlex may use PHI to:
- Provide and support the services
- Create de-identified data sets
- Comply with legal obligations
- Perform data aggregation services
Term and Termination
- This BAA is effective upon account activation
- Terminates with your TallyFlex account
- Upon termination, PHI will be returned or destroyed
- Obligations survive for PHI retained for legal requirements
No Third Party Rights
This BAA is between TallyFlex and Covered Entity only. No third parties have rights under this agreement.
Contact
For HIPAA-related questions:
Email: compliance@tallyflex.com