Legal

Business Associate Agreement

Version 2026-09-09

Business Associate Agreement (BAA) — version 2026-09-09. Supplements TrazaLab’s Terms of Service and DPA. Implements the elements required by 45 CFR § 164.504(e) (HHS sample provisions).

Between the covered entity or business associate customer using TrazaLab (the Covered Entity for purposes of this BAA) and TrazaLab (the Business Associate). Contact: [email protected].

Breach, Disclosure, Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, and Use have the meanings in the HIPAA Rules (45 CFR Parts 160 and 164).

1. Obligations of Business Associate

Business Associate agrees to:

  1. Not use or disclose PHI other than as permitted or required by this Agreement or as required by law;
  2. Use appropriate safeguards and, with respect to ePHI, comply with Subpart C of 45 CFR Part 164 (Security Rule) to prevent unauthorized use or disclosure;
  3. Report to Covered Entity any use or disclosure not provided for by this Agreement of which it becomes aware, including breaches of unsecured PHI as required at 45 CFR § 164.410, and any security incident of which it becomes aware;
  4. Ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions and conditions (45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2));
  5. Make available PHI in a designated record set as necessary to satisfy Covered Entity’s obligations under 45 CFR § 164.524;
  6. Make amendments to PHI in a designated record set as directed under 45 CFR § 164.526;
  7. Maintain and make available the information required to provide an accounting of disclosures under 45 CFR § 164.528;
  8. To the extent Business Associate carries out a Covered Entity obligation under Subpart E, comply with the requirements applicable to that obligation; and
  9. Make its internal practices, books, and records relating to use and disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules.

2. Permitted uses and disclosures

Business Associate may use or disclose PHI only as necessary to perform the Service set forth in the Terms of Service / underlying services agreement; as required by law; and, optionally, for its own proper management and administration or to carry out legal responsibilities, with the reasonable assurances required by 45 CFR § 164.504(e)(4). Business Associate may not use or disclose PHI in a manner that would violate Subpart E if done by Covered Entity, except for those permitted management uses.

3. Term and termination

This BAA is effective upon electronic acceptance at registration (or later signature) and terminates when the services agreement ends, or earlier if Covered Entity terminates for cause after a material breach. Upon termination, Business Associate shall return or destroy, if feasible, PHI it still maintains; if return or destruction is infeasible, it shall extend the protections of this BAA and limit further uses to those purposes.

4. Interpretation

Any ambiguity shall be resolved to permit compliance with the HIPAA Rules. This BAA does not constitute a third-party HIPAA certification and does not replace clinical judgment. Security practices align with the technical measures described in TrazaLab’s public documentation; Covered Entity remains responsible for its own compliance program.