Skip to content
CareBridgeHealthTech

U.S. template

Business Associate Agreement Template

This U.S. template sets out baseline HIPAA business-associate terms for a separately approved CareBridge service relationship.

Template publication date: July 24, 2026

1. Status and parties

The publication notice above controls the status of this template; access to this page alone creates no agreement between any parties.

When executed, this Business Associate Agreement (“BAA”) is between the covered entity identified in the signature block (“Covered Entity”) and CareBridge HealthTech LLC (“Business Associate”). Qualified U.S. healthcare counsel should review and complete it for the actual services, parties, state law, and risk allocation.

2. Definitions

Terms including Breach, Designated Record Set, Electronic Protected Health Information, Individual, Minimum Necessary, Protected Health Information (“PHI”), Required by Law, Secretary, Security Incident, Subcontractor, and Unsecured PHI have the meanings assigned by HIPAA, the HITECH Act, and their implementing regulations. “Services Agreement” means the separately executed agreement that authorizes an approved environment.

3. Permitted uses and disclosures

Business Associate may use or disclose PHI only to perform the Services Agreement, as permitted by this BAA, or as Required by Law. It may use PHI for proper management and administration or to carry out legal responsibilities only when HIPAA permits and, for an external disclosure, the recipient provides required confidentiality assurances. Business Associate may not use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity, except as expressly permitted for a business associate.

4. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as provided by this BAA and will comply with the applicable requirements of the HIPAA Security Rule for electronic PHI. Specific controls, environments, and responsibilities may be described in the Services Agreement or security schedule.

5. Reporting

Business Associate will report to Covered Entity any use or disclosure not permitted by this BAA, any Breach of Unsecured PHI, and any Security Incident of which it becomes aware, without unreasonable delay and within any stricter agreed period. A report will include available identification, scope, mitigation, and notice information required by law. Routine unsuccessful security activity may be reported in aggregate or treated as notice if the parties expressly agree.

6. Subcontractors

Business Associate will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions, conditions, and Security Rule obligations at least as protective as those applicable to Business Associate.

7. Access, amendment, and accounting

To the extent Business Associate maintains PHI in a Designated Record Set or information needed by Covered Entity, it will make PHI available for access and amendment and provide disclosure information for an accounting, in the form and time reasonably requested by Covered Entity and as required by 45 C.F.R. §§ 164.524, 164.526, and 164.528.

8. U.S. Department of Health and Human Services access

Business Associate will make its internal practices, books, and records relating to PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity’s compliance with HIPAA, subject to applicable legal protections.

9. Minimum necessary

Business Associate will request, use, and disclose only the minimum PHI reasonably necessary for the permitted purpose, consistent with Covered Entity’s policies communicated to Business Associate and applicable HIPAA requirements.

10. Mitigation

Business Associate will mitigate, to the extent practicable, harmful effects known to it from a use or disclosure of PHI in violation of this BAA and will cooperate with Covered Entity’s investigation, risk assessment, remediation, and legally required notices.

11. Covered Entity duties

Covered Entity will notify Business Associate of relevant privacy-practice limitations, permission changes, and restrictions that affect permitted uses or disclosures. Covered Entity will not request Business Associate to use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity, and will configure access, obtain authorizations, and provide lawful instructions necessary for the services.

12. Term and termination

The executed BAA begins on its completed effective date and continues while Business Associate maintains PHI for Covered Entity. Either party may terminate for a material breach if the breaching party does not cure within the agreed cure period, or immediately when cure is not possible. If termination is not feasible, the non-breaching party may report the violation to the Secretary as required by HIPAA.

13. Return or destruction

At termination, Business Associate will return or destroy PHI if feasible and retain no copies, except where return or destruction is infeasible or law requires retention. For retained PHI, this BAA’s protections continue and further uses and disclosures are limited to the purpose that makes return or destruction infeasible.

14. Interpretation and order

This BAA will be interpreted to permit compliance with HIPAA and will be amended as necessary for changes in applicable law. Ambiguities are resolved in favor of HIPAA compliance. If this BAA conflicts with the Services Agreement on PHI protection, the more protective term controls unless prohibited by law. Other Services Agreement terms remain in effect.

15. Signature blocks

The parties should complete every field and retain a signed copy. Electronic and counterpart signatures may be accepted if authorized by the parties and applicable law.

  • COVERED ENTITY — Legal name: __________; Authorized representative: __________; Title: __________; Signature: __________; Date: __________.
  • BUSINESS ASSOCIATE — CareBridge HealthTech LLC; Authorized representative: __________; Title: __________; Signature: __________; Date: __________.
  • BAA effective date: __________; Related Services Agreement: __________; Approved environment: __________.

CareBridge HealthTech LLC

Address: 816 Tuscan Road, Harker Heights, Texas 76548, USA

Email: privacy@carebridgehealthtech.com