Business Associate Agreement
Last Updated: June 25, 2026
This Business Associate Agreement ("BAA") is a legally binding contract between the service provider ("Provider") and the customer agreeing to these terms ("Customer"). This BAA covers all services provided by Provider to Customer in accordance with Customer's Order Form ("Services"), is incorporated by reference into the Master Service Agreement located at complya.com/msa, and supersedes the Terms of Service located at complya.com/terms with respect to the handling of PHI. Together, the BAA, MSA, Terms of Service, and Product Privacy Policy constitute the complete Service Agreement governing the parties' relationship.
Provider and Customer are referred to in this BAA individually as a "Party" and collectively as the "Parties." This BAA remains effective for any agreement between the Parties until terminated in accordance with the terms herein.
1. Background
Customer is a Covered Entity or a Business Associate. Customer possesses Protected Health Information ("PHI") that is protected under HIPAA. The services provided to Customer require Provider to host Customer Data that may contain PHI. To the extent Provider creates, receives, maintains, or transmits PHI on behalf of Customer, Provider is a Business Associate of Customer. Accordingly, Provider and Customer shall comply with the obligations under the HIPAA Privacy, Breach Notification, and Security Rules. The terms and conditions in this BAA supersede any conflicting terms and conditions in the Terms of Service.
2. Definitions
Except as otherwise defined in this BAA, all capitalized terms used in this BAA have the meanings set forth in HIPAA and in the Terms of Service.
- "Breach Notification Rule" means the Breach Notification for Unsecured Protected Health Information Final Rule (45 C.F.R. part 164, subpart D).
- "Business Associate" generally has the same meaning as the term "business associate" at 45 CFR 160.103.
- "Covered Entity" generally has the same meaning as the term "covered entity" at 45 CFR 160.103.
- "Customer Data" means data submitted by Users into the Services (as defined in the Terms of Service).
- "Enforcement Rule" means the HIPAA enforcement standards (45 CFR part 160, subparts C, D, and E).
- "HHS" means the United States Department of Health and Human Services.
- "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
- "HITECH" means the Health Information Technology for Economic and Clinical Health Act and its implementing regulations.
3. Obligations and Activities of Provider
3.1 HIPAA Compliance
Provider shall comply with the requirements of HIPAA and HITECH that are applicable to Provider as a Business Associate.
3.2 Limitations on Use and Disclosure
Provider shall not use or disclose PHI other than as permitted or required by this BAA and the Terms of Service, or as otherwise Required by Law. Provider shall make reasonable efforts to Use, Disclose, or request the minimum necessary PHI to accomplish the intended purpose.
3.3 Safeguards
To maintain electronic data security and prevent inappropriate Use or Disclosure of PHI, Provider shall (i) implement appropriate administrative, physical, and technical safeguards, and (ii) comply with the applicable requirements of 45 CFR Part 164 Subpart C of the Security Rule. Provider shall maintain encryption of all ePHI at rest using AES-256 and in transit using TLS 1.2 or higher.
3.4 Reporting
Provider shall report to Customer:
- (a) Impermissible Uses or Disclosures: Any Use or Disclosure of PHI not permitted by this BAA.
- (b) Security Incidents: Any Security Incident of which Provider becomes aware. Provider hereby provides advance notice that unsuccessful Security Incidents (such as pings, port scans, and failed login attempts) occur routinely; no individual notice is required for such events.
- (c) Breach Notification: Any Breach of Customer's Unsecured PHI, reported in two stages:
- (i) Preliminary Notification — within seventy-two (72) hours of Provider's reasonable confirmation that a Breach has occurred, Provider shall deliver a written preliminary notice including the nature of the incident, categories of PHI involved, and approximate number of individuals affected to the extent then known. Provider shall treat this seventy-two (72) hour deadline as a priority obligation, as it initiates Customer's regulatory notification deadlines.
- (ii) Final Report — within sixty (60) calendar days of discovery, Provider shall deliver a final written report covering the full scope of the Breach, affected individuals, and remediation steps taken.
Customer's sixty (60) day obligation to notify affected individuals and the Secretary of HHS under the HIPAA Breach Notification Rule (45 C.F.R. § 164.404) begins upon the date of discovery of the Breach, which may precede Customer's receipt of the preliminary notification described in clause (c)(i) above. Provider's seventy-two (72) hour preliminary notification obligation is designed to provide Customer maximum advance notice within that regulatory window. All incident reports should be directed to support@complya.com.
3.5 Subprocessors
Provider shall require that any Subprocessors who create, receive, maintain, or transmit PHI on behalf of Provider enter into a written Business Associate Agreement with Provider containing restrictions and conditions at least as protective as those imposed on Provider under this BAA. Provider shall notify Customer at least thirty (30) days prior to engaging any new Subprocessor who will create, receive, maintain, or transmit PHI on behalf of Provider, and shall maintain a current list of such Subprocessors at complya.com/privacy.
3.6 Disclosure to Secretary
Provider shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance with HIPAA Rules, subject to attorney-client and other applicable legal privileges.
3.7 Designated Record Sets
Provider maintains PHI in Designated Record Sets on behalf of Customer, including treatment records, session notes, behavior data, behavior intervention plan goals, and clinical progress documentation generated through the Services. Provider agrees as follows:
- Provider will make such PHI in the Designated Record Set available to Customer in accordance with applicable patient access rights under HIPAA.
- Provider will make such PHI available to Customer for amendment and will incorporate any reasonably requested amendment in accordance with HIPAA's amendment requirements.
- If Provider receives a direct request from a patient for access or amendment, Provider will submit such request to Customer for response as soon as reasonably practical.
- Provider will maintain a record of disclosures of PHI from Designated Record Sets and will make such accounting available to Customer within sixty (60) days of a written request.
3.8 Performance of Covered Entity Obligations
To the extent Provider is to carry out one or more of Customer's obligation(s) under Subpart E of 45 CFR Part 164, Provider shall comply with the requirements of Subpart E that apply to Customer in the performance of such obligation(s).
4. Obligations and Activities of Customer
4.1 No Impermissible Requests
Customer shall not request Provider to Use or Disclose PHI in any manner that would not be permissible under HIPAA if done by a Covered Entity.
4.2 Safeguards and Appropriate Use
Customer is responsible for implementing appropriate administrative, technical, and physical safeguards to protect its PHI in compliance with HIPAA. This includes implementing privacy and security safeguards in the systems, applications, networks, and software Customer controls, configures, and uses to upload Customer Data into the Services. Customer shall not include PHI in information submitted to technical support personnel or community support forums.
4.3 Contact Information for Notices
Provider may deliver any report, notification, or notice under this BAA electronically. Customer shall provide contact information to support@complya.com and keep it current. Contact information must include the name, title, and email address of the individual(s) to be contacted, and the name of the Customer organization.
5. Permitted Uses and Disclosures by Provider
5.1 Management and Administration
Provider may Use and Disclose PHI for its proper management and administration or to carry out its legal responsibilities, provided that any Disclosure occurs only if (i) Required By Law, or (ii) (a) Provider obtains reasonable written assurances from the recipient that it will remain confidential and used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and (b) the recipient notifies Provider of any instances of which the recipient is aware in which the confidentiality of the PHI has been breached.
5.2 AI-Assisted Service Processing
AI-powered features within the Services may process Customer Data, including PHI, through Provider's AI infrastructure and third-party AI subprocessors, solely to provide the Services to Customer. Provider does not use Customer Data or PHI to develop, train, or improve AI or machine learning models. All subprocessors that process PHI in connection with AI features have executed Business Associate Agreements with Provider and are listed at complya.com/privacy. Provider may also use PHI to provide data aggregation services to Customer as otherwise permitted by applicable HIPAA rules.
5.3 Legal Violations Disclosure
Provider may use PHI to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR §164.502(j)(1).
6. Term and Termination
6.1 Term
This BAA remains in effect until the earlier to occur of (1) the expiration or termination of the Master Service Agreement ("MSA"), the Terms of Service, or any other governing Agreements that cause Provider to be a Business Associate of Customer, or (2) the date on which either Party terminates this BAA for cause.
6.2 Termination for Cause
If either Party is in material breach or default of any obligation under this BAA, the other Party may: (i) provide a reasonable opportunity to cure and, if not cured within thirty (30) days, terminate this BAA and all associated Agreements; or (ii) if cure is not possible, immediately terminate this BAA and all associated Agreements. Upon any such termination, Provider shall return or destroy PHI in accordance with Section 6.3.
6.3 Return or Retention of PHI
Upon termination, if it is feasible to do so, Provider shall return or destroy all PHI in its possession. If Provider determines that it is not feasible to return or destroy PHI, this BAA shall remain in full force and effect solely with respect to such retained PHI, and Provider shall limit further Use or Disclosure to those purposes that make the return or destruction infeasible. Provider will make Customer Data available for export for sixty (60) days before final destruction.
7. Limitation of Liability
IN NO EVENT SHALL PROVIDER BE LIABLE FOR ANY INDIRECT, CONSEQUENTIAL, OR PUNITIVE DAMAGES. PROVIDER'S TOTAL AGGREGATE LIABILITY SHALL NOT EXCEED THE FEES PAID BY CUSTOMER IN THE TWELVE (12) MONTH PERIOD PRECEDING THE DATE OF THE ACCRUAL OF THE CLAIM ("LIABILITY LIMIT"). The Parties agree that only reasonable breach mitigation costs primarily caused by Provider's material breach of this BAA shall be considered direct damages and shall be subject to the Liability Limit. Provider's pricing under the Terms of Service reflects, in part, this allocation of risk. Notwithstanding the foregoing, the Liability Limit shall not apply to claims arising from Provider's gross negligence or willful misconduct in causing a Breach of Unsecured PHI.
8. Miscellaneous
8.1 Survival
The Parties' obligations regarding PHI, confidentiality, limitation of liability, and indemnification shall survive termination of this BAA.
8.2 Interpretation
Any ambiguity shall be resolved to permit compliance with HIPAA. This BAA is an addendum to the Master Service Agreement; in the event of conflict between this BAA and any other agreement governing the parties' relationship, this BAA shall govern with respect to PHI. Under no circumstances shall the terms of the Terms of Service or the Master Service Agreement modify the terms of this BAA.
8.3 Amendments & Waiver
Except as expressly set forth in this BAA, a provision of this BAA may be altered only by a writing signed by both Parties. This BAA shall be renegotiated in good faith if changes to HIPAA regulations require amendment to maintain compliance. The waiver of a breach hereunder may be effected only by a writing signed by the waiving Party and shall not constitute a waiver of any other breach.
8.4 No Third-Party Beneficiaries
Nothing express or implied in this BAA confers any rights, remedies, or liabilities upon any person other than the Parties.
8.5 Counterparts
This BAA may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one and the same instrument.
8.6 Severability
If any provision of this BAA is found invalid or unenforceable, it shall be enforced to the maximum extent permissible and the other provisions shall remain in full force and effect.
8.7 Applicability to Future Agreements
As of the effective date of this BAA, this BAA is applicable to all Agreements between the Parties, whether current or future, without additional action by the Parties.