Skip to content
See a Demo
Legal

Partner BAA

This is IntelAgree’s business associate agreement for partners. Under HIPAA, IntelAgree acts as Business Associate and the Partner acts as Subcontractor. It forms part of the Partner Agreement between the parties.

This HIPAA Subcontractor Agreement ("Agreement") is entered into as of the Effective Date of the Partner Agreement between the Parties (the "Effective Date") pursuant to the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), by and between IntelAgree, LLC, a Delaware limited liability company with a principal place of business located at 100 E. Madison St., Suite 300, Tampa, FL 33602, or any of its corporate affiliates ("Business Associate") and Partner Name ("Subcontractor").

Article I. Preamble and Definitions

Section 1.01  Business Associate provides services to Covered Entities and other business associates for services pursuant to which the Business Associate may disclose Protected Health Information (“PHI”) to Subcontractor in order to enable Subcontractor to perform one or more functions for the Business Associate (the “Services”). The agreement under which the Subcontractor may perform the Services for the Business Associate is referred to herein as the “Services Agreement”.

Section 1.02  The parties desire to comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Final Rule for Standards for Privacy of Individually Identifiable Health Information adopted by the United States Department of Health and Human Services (“HHS”) and codified at 45 C.F.R. part 160 and part 164, subparts A & E (the “Privacy Rule”), the HIPAA Security Rule (the “Security Rule”; together with the Privacy Rule, the “HIPAA Rules”), codified at 45 C.F.R. Part 164 Subpart C, and Subtitle D and the Health Information Technology for Economic and Clinical Health Act (“HITECH”), including C.F.R. Sections 164.308, 164.310, 164.312, 164.316, and 164.402. Pursuant to changes required under the Health Information Technology for Economic and Clinical Health Act of 2009 (the "HITECH Act") and under the American Recovery and Reinvestment Act of 2009 ("ARRA"), this Agreement also reflects federal breach notification requirements imposed on Subcontractor when "Unsecured PHI" (as defined under the HIPAA Rules) is acquired by an unauthorized party and the expanded privacy and security provisions imposed on business associates and subcontractors. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

Section 1.03  Unless the context clearly indicates otherwise, the following terms in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Covered Entity, Data Aggregation, Designated Record Set, disclosure, Electronic Media, Electronic Protected Health Information (ePHI), Health Care Operations, individual, Minimum Necessary, Notice of Privacy Practices, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured PHI and use.

Section 1.04  A reference in this Agreement to the Privacy Rule means the Privacy Rule, in conformity with the regulations at 45 C.F.R. Parts 160-164 as interpreted under applicable regulations and guidance of general application published by the HHS, including all amendments thereto for which compliance is required, as amended by the HITECH Act, ARRA and the HIPAA Rules.

Article II. General Obligations of Subcontractor

Section 2.01  Subcontractor agrees not to use or disclose PHI, other than as permitted or required by the Services Agreement, this Agreement or as Required By Law.

Section 2.02  Subcontractor agrees to implement and maintain safeguards in compliance with HIPAA, including Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.

Section 2.03  Subcontractor agrees to mitigate, to the extent practicable, any harmful effect that is known to Subcontractor as a result of a use or disclosure of PHI by Subcontractor in violation of the requirements of this Agreement or that would otherwise cause a Breach of Unsecured PHI.

Section 2.04  The Subcontractor agrees to the following breach notification requirements:

  1. Subcontractor agrees to report to Business Associate any use or disclosure of PHI not provided for in connection with this Agreement or performance of the Services, of which it becomes aware without unreasonable delay, but in no event more than three (3) business days after Subcontractor’s “discovery” (within the meaning of the HITECH Act) of such event, including Breaches of Unsecured PHI as required by 45 CFR 164.410.
  2. Notification of a Breach of Unsecured PHI under 45 CFR 164.410 will be made without unreasonable delay, but in no event more than five (5) business days after Subcontractor’s “discovery” of such a Breach and will be delivered to Business Associate by means selected by Subcontractor, including via email.

Section 2.05  Subcontractor agrees, in accordance with 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, to require that any of its subcontractors that create, receive, maintain or transmit PHI on behalf of the Subcontractor agree to the restrictions, conditions and requirements that are the same as those that apply to the Subcontractor with respect to such PHI under this Agreement.

Section 2.06  In the event that Subcontractor maintains PHI in a Designated Record Set for Business Associate, at the request of Business Associate, Subcontractor shall either provide Business Associate with access to Business Associate’s User Account via the Business Associate’s unique log-in credentials, in accordance with 45 CFR § 164.524 and 45 CFR § 164.526 of the Privacy Rule or make available PHI in a Designated Record Set to Business Associate as necessary to satisfy Business Associate’s obligations under 45 C.F.R. 164.524.

Section 2.07  Subcontractor agrees to maintain and, if requested, make available the information required to provide an accounting of disclosures to Business Associate as necessary to satisfy Business Associate’s obligations under 45 CFR 164.528.

Section 2.08  Subcontractor agrees to make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary, for purposes of determining Business Associate’s compliance with the HIPAA Rules. Nothing in this Section shall be deemed to be a waiver of any applicable privilege or protection, including with respect to trade secrets or confidential commercial information.

Section 2.09  To the extent that Subcontractor is to carry out one or more of Business Associate's obligation(s) under Subpart E of 45 C.F.R. Part 164, Subcontractor agrees to comply with the requirements of Subpart E that apply to the Business Associate in the performance of such obligation(s).

Section 2.10  Subcontractor agrees to account for the following disclosures:

  1. Subcontractor agrees to maintain and document Breaches of Unsecured PHI and any information relating to the disclosure of PHI and Breach of Unsecured PHI in a manner as would be required for Business Associate to respond to a request by an individual or the Secretary for an accounting of PHI disclosures and Breaches of Unsecured PHI.
  2. Subcontractor agrees to provide to Business Associate, or to an individual at Business Associate's request, information collected in accordance with this Section 2.10, to permit Business Associate to respond to a request by an individual or the Secretary for an accounting of PHI disclosures and Breaches of Unsecured PHI.

Section 2.11  Subcontractor agrees that Business Associate shall have the right to conduct an annual security review of Subcontractor’s security and privacy systems, processes, controls and procedures and Subcontractor agrees to participate in any such audit and provide necessary documentation to Business Associate in order to facilitate such an audit review.

Section 2.12  Subcontractor agrees that all PHI and any information relating thereto will be stored on servers located in the United States or other jurisdictions approved by Business Associate in writing and shall not be transferred to any other countries or other jurisdictions without Business Associate’s prior written consent.

Article III. Permitted Uses and Disclosures by Subcontractor

Section 3.01  Subcontractor agrees to receive, create, use or disclose PHI only in a manner that is consistent with this Agreement, the Privacy Rule or Security Rule and only in connection with providing the Services to Business Associate; provided, that the use or disclosure would not violate the Privacy Rule, including 45 C.F.R. 164.504(e), if the use or disclosure would be done by Business Associate.

Section 3.02  Subcontractor may use or disclose PHI as Required By Law and for the proper management and administration of its business and to carry out the Services; provided, that, the use or disclosure is Required by Law or Subcontractor obtains reasonable assurances from the recipient of the information that any PHI will remain confidential, be used or further disclosed only as Required by Law or for the purposes for which it was disclosed to them, and the recipient shall be required to notify Subcontractor of any instances of which it is aware in which the confidentiality of the PHI has been breached.

Section 3.03  Subcontractor may not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Business Associate.

Article IV. Obligations of Business Associate

Section 4.01  Business Associate shall:

  1. Notify Subcontractor of any restriction on the use or disclosure of PHI that Business Associate has agreed to or is required to abide by under 45 C.F.R. 164.522, to the extent that such restriction may affect Subcontractor's use or disclosure of PHI under this Agreement.
  2. Notify Subcontractor of any changes in or revocation of permission by an individual to use or disclose PHI, if such change or revocation may affect Subcontractor's permitted or required uses and disclosures of PHI under this Agreement.

Article V. Compliance with Security Rule

Section 5.01  Subcontractor shall comply with the HIPAA Security Rule, which shall mean the Standards for Security of Electronic Protected Health Information at 45 C.F.R. Part 160 and Subparts A and C of Part 164, as amended by ARRA and the HITECH Act. The term "Electronic Health Record" or "EHR" as used in this Agreement shall mean an electronic record of health- information on an individual that is created, gathered, managed and consulted by authorized health care clinicians and staff.

Section 5.02  In accordance with the related Security Rule, Subcontractor agrees to:

  1. Implement the administrative safeguards set forth at 45 C.F.R. 164.308, the physical safeguards set forth at 45 C.F.R. 164.310, the technical safeguards set forth at 45 C.F.R. 164.312, and the policies and procedures set forth at 45 C.F.R. 164.316 to reasonably and appropriately protect the confidentiality, integrity and availability of the ePHI that it creates, receives, maintains or transmits on behalf of Business Associate as required by the Security Rule. Subcontractor acknowledges that, effective on the Effective Date the foregoing safeguards, policies and procedures requirements shall apply to Subcontractor in the same manner that such requirements apply to Business Associate;
  2. Require that any agent, including a Subcontractor, to whom it provides such PHI agrees to implement reasonable and appropriate safeguards to protect the PHI; and
  3. Report to the Business Associate any Security Incident of which it becomes aware in accordance with the terms hereof.

Article VI. Term and Termination

Section 6.01  This Agreement shall be in effect as of the Effective Date and shall terminate on the earlier of the date that:

  1. Termination or expiration of the Services Agreement.
  2. Either party terminates for cause as authorized under Section 6.02.
  3. All of the PHI received from Business Associate, or created or received by Subcontractor on behalf of Business Associate, is destroyed or returned to Business Associate. If it is not feasible to return or destroy PHI, protections are extended in accordance with Section 6.03.
  4. If the Secretary provides guidance, clarification or interpretation of HIPAA or the HITECH Act or there is a change in HIPAA or the HITECH Act such that the service relationship between Subcontractor and Business Associate is not considered a Subcontractor relationship as defined in HIPAA, this Agreement shall terminate and be null and void.

Section 6.02  Upon either party's knowledge of material breach by the other party, the non-breaching party shall provide an opportunity for the breaching party to cure the breach or end the violation. If the breaching party does not cure the breach or end the violation within a reasonable timeframe not to exceed thirty (30) days from the notification of the breach, or if a material term of the Agreement has been breached and a cure is not possible, the non-breaching party may terminate this Agreement and the Services Agreement(s) upon written notice to the other party.

Section 6.03  Upon termination of this Agreement for any reason, the parties agree that:

  1. Subcontractor, with respect to PHI received from Business Associate, or created, maintained, or received by Subcontractor on behalf of Business Associate, shall:
    1. Retain only that PHI that is necessary for Subcontractor to continue its proper management and administration or to carry out its legal responsibilities;
    2. Return to Business Associate or, if agreed to by Business Associate, destroy the remaining PHI that the Subcontractor still maintains in any form;
    3. Continue to use appropriate safeguards and comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI to prevent use or disclosure of the PHI, other than as provided for in this Section 7, for as long as Subcontractor retains the PHI; or
    4. Not use or disclose the PHI retained by Subcontractor other than for the purposes for which such PHI was retained and subject to the same conditions set forth in this Agreement that applied prior to termination.

Section 6.04  The obligations of Subcontractor under this Section 6 shall survive the termination of this Agreement.

Article VII. Indemnification

Section 7.01  Each party will indemnify, defend and hold harmless the other party and any of the other party's affiliates, officers, directors, employees or agents from and against any claim, cause of action, liability, damage, cost or expense, including attorneys' fees and court or proceeding costs, arising out of or in connection with any non-permitted use or disclosure of PHI or other breach of this Agreement by the indemnifying party. The obligations of the indemnifying party under this Article VII are subject to (A) the indemnified party notifying the indemnifying party promptly of any such claim (provided, however, that the indemnifying party shall be relieved of its obligations under this Article VII on account of any failure of the indemnified party promptly to provide such notice only if, and to the extent that, the indemnifying party is demonstrably prejudiced thereby), (B) the indemnified party offering the indemnifying party sole control of the defense or settlement of any such claim, provided that it prosecutes such defense diligently and indemnified party shall be entitled to reasonably participate therein at its own cost and the indemnifying party shall not settle any such claim without the consent of the indemnified party if the settlement includes any relief other than the payment of money which is fully funded by the indemnifying party, and (C) the indemnified party providing reasonable assistance and information necessary in connection with the defense of any such claim, at the indemnifying party’s sole expense.

Section 7.02  Subcontractor shall reimburse Business Associate for any reasonable costs of defense and mitigation of penalties or damages exposures, including investigative and mitigation cost, as well as attorneys’ fees and costs including administrative enforcement and pretrial, trial, and appeal proceedings. The parties will mutually agree to the selection of legal counsel to defend claims for which Business Associate is indemnified hereunder and the selection may be subject to the terms of insurance coverage if defense is covered by an insurance policy. In the event of legal action to enforce this provision, the prevailing Party shall be awarded its reasonable attorneys’ fees and costs. If the Services Agreement includes a limitation on Subcontractor’s liability, whether a maximum recovery for direct damages or a disclaimer against any consequential, indirect or punitive damages, such limitations shall exclude all damages to Business Associate arising from Subcontractor’s breach of its obligations relating to the use or disclosure of Protected Health Information.

Article VIII. Miscellaneous

Section 8.01  The parties agree to take such action as is necessary to amend this Agreement to comply with the requirements of the Privacy Rule, the Security Rule, HIPAA, ARRA, the HITECH Act, the HIPAA Rules and any other applicable law.

Section 8.02  The respective rights and obligations of Subcontractor under Article VI and Article VII of this Agreement shall survive the termination of this Agreement.

Section 8.03  This Agreement shall be interpreted in the following manner:

  1. Any ambiguity shall be resolved in favor of a meaning that permits the parties to comply with the HIPAA Rules.
  2. Any inconsistency between the Agreement's provisions and the HIPAA Rules, including all amendments, as interpreted by the HHS, court or another regulatory agency with authority over the Parties, shall be interpreted according to the interpretation of the HHS, the court or the regulatory agency.

Section 8.04  This Agreement constitutes the entire agreement between the parties related to the subject matter of this Agreement. This Agreement supersedes all prior negotiations, discussions, representations or proposals, whether oral or written. This Agreement may not be modified unless done so in writing and signed by a duly authorized representative of both parties. If any provision of this Agreement, or part thereof, is found to be invalid, the remaining provisions shall remain in effect.

Section 8.05  This Agreement may not be assigned, in whole or in part, by Subcontractor without the written consent of Business Associate. Any attempted assignment in violation of this provision shall be null and void.

Section 8.06  This Agreement may be executed in two or more counterparts, each of which shall be deemed an original.

Section 8.07  Except to the extent preempted by federal law, this Agreement shall be governed by and construed in accordance with the law of the State of Florida without regard to its conflicts of law principles. The Parties consent to the personal and exclusive jurisdiction of the federal and state courts of Tampa, Florida.

See IntelAgree put AI to work on your contracts.

Get a personalized walkthrough of the AI-native CLM platform.

  • AI review, redlining, and risk scoring built into every contract.
  • Native connections to the systems your team already uses.
  • A searchable, obligation-aware repository for every executed agreement.

Request a demo