Legal · HIPAA
Business Associate Agreement
Version 2026-06-01 · Effective on acceptance
Preamble
This Business Associate Agreement ("BAA") supplements and is incorporated into the Terms of Service between MyCareTrail, LLC ("Business Associate") and the provider organization that accepts it ("Covered Entity"). It is entered into to comply with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 C.F.R. Parts 160 and 164 (the "HIPAA Rules"), each as amended.
Because MyCareTrail creates, receives, maintains, or transmits Protected Health Information on behalf of the Covered Entity, the parties are required to enter into this BAA as a prerequisite to use of the Service.
1. Definitions
Capitalized terms used but not defined in this BAA have the meanings given to them in the HIPAA Rules. For clarity:
- "Protected Health Information" ("PHI") means individually identifiable health information that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity, limited to the information involved in the Service.
- "Electronic PHI" ("ePHI") means PHI that is transmitted or maintained in electronic media.
- "Breach," "Designated Record Set," "Required by Law," "Security Incident," and "Subcontractor" have the meanings set out in the HIPAA Rules.
2. Permitted Uses and Disclosures
Business Associate may use or disclose PHI only as necessary to perform the services described in the Terms of Service, as Required by Law, or as otherwise permitted by this BAA. Business Associate will not use or disclose PHI in a manner that would violate the HIPAA Rules if done by the Covered Entity, except that Business Associate may use and disclose PHI:
- for its proper management and administration; and
- to carry out its legal responsibilities, provided that disclosures are Required by Law or are made under reasonable written assurances of confidentiality and breach notification from the recipient.
Business Associate will make reasonable efforts to use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose.
3. Safeguards
Business Associate will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, in compliance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). These include encryption of ePHI in transit and at rest, role-based access controls, audit logging, and tenant isolation between provider organizations.
4. Reporting and Breach Notification
Business Associate will report to Covered Entity, without unreasonable delay and in any event within the timeframes required by the HIPAA Rules, any use or disclosure of PHI not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI of which it becomes aware. Each report will include the information reasonably available to Business Associate to enable Covered Entity to meet its own notification obligations.
5. Subcontractors
Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions on PHI that are at least as protective as those that apply to Business Associate under this BAA.
6. Individual Rights
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will, within commercially reasonable timeframes:
- make PHI available to Covered Entity (or, as directed, to the individual) to satisfy the individual's right of access under 45 C.F.R. § 164.524;
- make PHI available for amendment and incorporate amendments under 45 C.F.R. § 164.526; and
- make available the information required for Covered Entity to provide an accounting of disclosures under 45 C.F.R. § 164.528.
7. Covered Entity Obligations
The Covered Entity is solely responsible for:
- obtaining all authorizations and consents required from individuals whose PHI it enters into the Service;
- implementing and maintaining appropriate safeguards within its own organization to protect PHI;
- training its workforce on HIPAA requirements and proper use of the Service; and
- not requesting Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by the Covered Entity.
8. Term and Termination
This BAA is effective when accepted and remains in effect until all PHI is returned or destroyed, or protections are extended to it as described below. Covered Entity may terminate the Terms of Service and this BAA if Business Associate materially breaches this BAA and fails to cure within a reasonable period after notice.
9. Return or Destruction of PHI
Upon termination, Business Associate will, where feasible, return or securely destroy all PHI it maintains on behalf of Covered Entity and retain no copies. Where return or destruction is not feasible, Business Associate will extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, consistent with applicable record-retention requirements (including Minnesota Statutes § 245D.11).
10. Acceptance
By checking the acceptance box during registration (or in your account settings) and continuing to use the Service, the individual accepting represents that they are authorized to bind the Covered Entity, and the Covered Entity agrees to be bound by this BAA. The date, version, accepting user, and originating IP address of acceptance are recorded as part of the compliance audit trail and are viewable under Settings → Legal & compliance.