Business Associate Agreement (BAA)
Between Intrascan360 (“Business Associate”) and Covered Entities (“Client”)
Effective Date: System Generates Date Stamped
Effective Date: The date accepted electronically by Client or otherwise executed by the parties.
This Business Associate Agreement (“BAA” or “Agreement”) is entered into between IntraScan360, LLC (“IntraScan360” or “Business Associate”) and the healthcare provider, practice, clinic, organization, or other entity accepting this Agreement (“Client” or “Covered Entity”), but only to the extent Client is a Covered Entity or Business Associate subject to HIPAA and IntraScan360 creates, receives, maintains, or transmits Protected Health Information on Client’s behalf.
This BAA supplements and is incorporated into the applicable IntraScan360 SaaS Terms and Conditions or other services agreement between the parties (“Services Agreement”).
This BAA applies during any IntraScan360 free-trial period and continues to apply following conversion to a paid subscription for so long as required by applicable law or while IntraScan360 maintains Protected Health Information subject to this Agreement.
1. Purpose
The parties enter into this Agreement to satisfy applicable requirements of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), and their implementing regulations.
In connection with providing the IntraScan360 platform and related services (“Services”), IntraScan360 may create, receive, maintain, process, analyze, store, or transmit PHI on behalf of Client.
2. Definitions
2.1 HIPAA Rules
“HIPAA Rules” means the applicable Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended.
2.2 Business Associate
“Business Associate” has the meaning assigned under 45 CFR § 160.103 and, for purposes of this Agreement, refers to IntraScan360 to the extent it performs Business Associate functions for Client.
2.3 Covered Entity
“Covered Entity” has the meaning assigned under 45 CFR § 160.103.
2.4 Protected Health Information
“Protected Health Information” or “PHI” has the meaning assigned under the HIPAA Rules and, for purposes of this Agreement, is limited to PHI created, received, maintained, or transmitted by IntraScan360 on behalf of Client.
PHI may include, where applicable, patient test results, biomarkers, demographic information, laboratory analyses, scan results, health assessments, reports, protocols, and other individually identifiable health information processed through the Services.
2.5 Electronic Protected Health Information
“Electronic Protected Health Information” or “ePHI” has the meaning assigned under the HIPAA Rules.
2.6 Other Defined Terms
Terms including “Breach,” “Disclosure,” “Individual,” “Security Incident,” “Subcontractor,” “Unsecured Protected Health Information,” “Use,” and “Required By Law” will have the meanings assigned under the HIPAA Rules.
3. Permitted Uses and Disclosures
IntraScan360 may Use or Disclose PHI only:
- As necessary to provide the Services described in the applicable Services Agreement;
- As directed or authorized by Client;
- For the proper management and administration of IntraScan360 or to carry out its legal responsibilities, where permitted by the HIPAA Rules;
- As Required By Law; or
- As otherwise expressly permitted by this Agreement and the HIPAA Rules.
The Services may include processing, storing, analyzing, organizing, displaying, transmitting, and generating reports or AI-assisted outputs using information submitted by Client.
IntraScan360 will not Use or Disclose PHI in a manner that would violate the HIPAA Privacy Rule if performed by Client, except as expressly permitted for a Business Associate under the HIPAA Rules.
4. Prohibited Uses
IntraScan360 will not:
- Sell PHI except as expressly permitted by applicable law and with any authorization required by law;
- Use PHI for unauthorized marketing;
- Disclose PHI outside the purposes permitted by this Agreement;
- Use PHI for purposes unrelated to providing or administering the Services except where expressly permitted by HIPAA or authorized by Client; or
- Use identifiable PHI to train generalized artificial-intelligence models except pursuant to a lawful basis, appropriate agreement, and any authorization required by applicable law.
Nothing in this section prohibits IntraScan360 from using information that has been properly de-identified in accordance with applicable HIPAA requirements, subject to applicable law and contractual restrictions.
5. Minimum Necessary
To the extent required by the HIPAA Rules, IntraScan360 will limit its Uses, Disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose.
Client agrees not to request IntraScan360 to Use or Disclose PHI in a manner that would violate the HIPAA Rules if performed by Client, except where such Use or Disclosure is expressly permitted for a Business Associate.
6. Safeguards
IntraScan360 will implement appropriate administrative, physical, and technical safeguards to protect PHI.
With respect to ePHI, IntraScan360 will comply with the applicable requirements of the HIPAA Security Rule.
Safeguards may include, as appropriate to IntraScan360’s systems and risk-management program:
Technical Safeguards
- Encryption of data in transit;
- Encryption of stored ePHI where appropriate;
- Access controls;
- Authentication controls;
- Audit logging and system monitoring;
- Data-integrity protections; and
- Transmission security.
Administrative Safeguards
- HIPAA and security training for applicable workforce members;
- Access-management policies;
- Security and incident-response procedures;
- Risk-management practices;
- System monitoring; and
- Vendor and subcontractor management.
Physical Safeguards
- Appropriate controls governing physical access to systems and infrastructure;
- Secure data-center environments; and
- Workstation and device security policies.
7. Security Incidents and Breach Notification
IntraScan360 will report to Client any Use or Disclosure of PHI not permitted by this Agreement of which IntraScan360 becomes aware.
IntraScan360 will report Security Incidents as required by the HIPAA Rules.
Following discovery of a Breach of Unsecured PHI subject to notification under applicable law, IntraScan360 will notify Client without unreasonable delay and in no event later than thirty (30) calendar days after discovery.
To the extent reasonably available, the notification will include information required for Client to fulfill its applicable breach-notification obligations, including:
- The nature of the incident;
- The categories of PHI involved;
- Identification of affected Individuals where reasonably available;
- Known or reasonably suspected circumstances of the Breach;
- Corrective or mitigation measures undertaken; and
- Other information required by applicable law.
IntraScan360 will reasonably cooperate with Client’s investigation and legally required response.
8. Subcontractors
IntraScan360 may engage Subcontractors to assist in providing the Services.
IntraScan360 will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on behalf of IntraScan360 agrees in writing to applicable restrictions, conditions, and safeguards that are at least as protective as those required of IntraScan360 under the HIPAA Rules.
Where required by HIPAA, IntraScan360 will enter into a Business Associate Agreement with the applicable Subcontractor.
9. Individual Access to PHI
To the extent IntraScan360 maintains PHI in a Designated Record Set on behalf of Client, IntraScan360 will make such PHI available to Client as reasonably necessary for Client to satisfy its obligations regarding Individual access under 45 CFR § 164.524.
Unless separately agreed, Client remains responsible for receiving, evaluating, and responding to requests from Individuals.
10. Amendment of PHI
To the extent required by 45 CFR § 164.526, IntraScan360 will make PHI available to Client for amendment and will incorporate amendments or corrections as directed by Client and required by applicable law.
11. Accounting of Disclosures
IntraScan360 will document applicable Disclosures of PHI and maintain information necessary for Client to respond to requests for an accounting of Disclosures under 45 CFR § 164.528.
Upon appropriate request, IntraScan360 will provide such information to Client as required by the HIPAA Rules.
12. HHS Access
IntraScan360 will make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, created by, or received on behalf of Client available to the Secretary of the U.S. Department of Health and Human Services as required for determining compliance with the HIPAA Rules.
13. Client Responsibilities
Client agrees to:
- Comply with applicable HIPAA requirements governing its activities;
- Maintain appropriate privacy and security policies;
- Limit access to the Services to authorized personnel;
- Maintain appropriate account and credential security;
- Provide IntraScan360 only PHI that Client is legally permitted to provide;
- Obtain any authorization or consent required by applicable law;
- Notify IntraScan360 of applicable restrictions affecting IntraScan360’s permitted Use or Disclosure of PHI;
- Notify IntraScan360 of relevant changes or revocations of an Individual’s permission to Use or Disclose PHI;
- Notify IntraScan360 of restrictions on Use or Disclosure that Client has agreed to or is legally required to observe, to the extent those restrictions affect IntraScan360; and
- Promptly notify IntraScan360 of suspected unauthorized use of the Services or PHI.
Client will not request IntraScan360 to Use or Disclose PHI in a manner that would violate applicable HIPAA requirements if performed by Client, except where permitted for Business Associates.
14. AI Processing of PHI
Where Client uses IntraScan360’s AI-assisted functionality, PHI may be processed as necessary to provide the requested Services, including generating analyses, reports, protocols, recommendations, summaries, or other outputs.
Such processing does not authorize IntraScan360 to use PHI for purposes unrelated to providing or administering the Services.
Client remains responsible for reviewing AI-generated outputs and determining whether and how such outputs may appropriately be used in connection with Client’s professional activities.
Nothing in this BAA changes the professional-responsibility, AI-use, licensure, or scope-of-practice provisions contained in the IntraScan360 SaaS Terms and Conditions.
15. Term
This BAA becomes effective when:
- It is electronically accepted by Client;
- It is otherwise executed by the parties; or
- Another written agreement between the parties makes this BAA effective.
The BAA applies during a free trial where IntraScan360 performs Business Associate functions and will continue without requiring a new BAA if Client converts to a paid subscription.
The Agreement remains effective for so long as IntraScan360 creates, receives, maintains, or transmits PHI subject to this Agreement or otherwise has obligations that survive termination.
16. Termination for Cause
If Client determines that IntraScan360 has materially violated this BAA, Client may provide written notice describing the violation.
Where cure is reasonably possible, IntraScan360 will be provided a reasonable opportunity to cure the violation.
If the material violation is not cured within the applicable period, Client may terminate the applicable Services Agreement and this BAA to the extent required or permitted by applicable law.
Nothing in this section limits either party’s rights or obligations under the HIPAA Rules regarding known patterns or practices constituting material violations.
17. Return or Destruction of PHI
Upon termination of the Services and where feasible, IntraScan360 will return or destroy PHI maintained on behalf of Client in accordance with the HIPAA Rules and the applicable Services Agreement.
Client may request an available export of PHI before deletion, subject to applicable Services functionality, law, and contractual requirements.
If return or destruction is not feasible, IntraScan360 will:
- Retain only PHI that must reasonably or legally be retained;
- Continue to apply appropriate safeguards;
- Limit further Uses and Disclosures to the purposes that make return or destruction infeasible; and
- Return or destroy retained PHI when retention is no longer necessary or legally required.
Obligations concerning retained PHI survive termination of this Agreement.
18. Effect of Subscription Cancellation
Cancellation or expiration of a free trial or paid IntraScan360 subscription does not immediately extinguish obligations concerning PHI.
This BAA will continue to govern PHI retained by IntraScan360 following termination for as long as required under the HIPAA Rules and applicable law.
Conversion from a free trial to a paid subscription does not require execution of a new BAA unless the parties’ relationship or applicable legal requirements materially change.
19. Regulatory Changes
References to HIPAA regulations mean those provisions as currently in effect or subsequently amended.
The parties agree to amend this BAA as reasonably necessary to maintain compliance with changes in applicable HIPAA requirements.
20. Relationship to SaaS Terms
This BAA supplements the IntraScan360 SaaS Terms and Conditions.
If a provision of the SaaS Terms conflicts with this BAA concerning the Use, Disclosure, safeguarding, return, or destruction of PHI, this BAA controls with respect to PHI to the extent required by applicable law.
All other provisions of the SaaS Terms remain in effect.
21. Interpretation
Any ambiguity in this BAA will be interpreted in a manner that permits the parties to comply with applicable HIPAA requirements.
22. Governing Law
This Agreement will be governed by applicable federal HIPAA requirements and other applicable law.
To the extent not preempted by federal law, the governing-law and venue provisions contained in the IntraScan360 SaaS Terms and Conditions will apply.
23. Electronic Acceptance
This Agreement may be accepted electronically.
Electronic acceptance will have the same effect as execution of a written agreement to the extent permitted by applicable law.
IntraScan360 may maintain electronic records documenting:
- Client or practice name;
- Authorized accepting user;
- Date and time of acceptance;
- BAA version accepted; and
- Other information reasonably necessary to document acceptance.
Acceptance
By accepting this Business Associate Agreement, Client acknowledges that it has reviewed and agrees to the terms above and represents that the individual accepting the Agreement is authorized to accept it on behalf of Client.