Legal

Business Associate Agreement

Sample for review

Important notice: this is a sample Business Associate Agreement for informational purposes only. The legally binding BAA is signed electronically during account creation and is accessible in your account settings. For compliance questions, contact compliance@medchartmax.com.

BUSINESS ASSOCIATE AGREEMENT

MedChartMax AI-Powered Medical Documentation Platform

Effective Date: Upon Electronic Acceptance

Business Associate: HDN Works LLC, operator of the MedChartMax platform

Covered Entity: You (Individual Healthcare Provider)

IMPORTANT NOTICE

This Business Associate Agreement (BAA) is required by HIPAA law before MedChartMax can process any Protected Health Information (PHI) on your behalf. This agreement establishes your individual responsibility as a healthcare provider for HIPAA compliance when using MedChartMax services.

DEFINITIONS

For purposes of this Agreement, the terms used herein shall have the same meaning as those terms in the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations.

PERMITTED USES AND DISCLOSURES OF PHI

Business Associate may use or disclose PHI only to provide the Services specified in this Agreement, which include AI-powered medical note generation and documentation assistance. Business Associate may not use or disclose PHI in any manner that would constitute a violation of HIPAA if done by Covered Entity.

SAFEGUARDS

Business Associate will implement appropriate safeguards to prevent use or disclosure of PHI other than as permitted by this Agreement, including:

  • Enterprise-grade encryption using AES-256-GCM for all PHI transmission
  • Secure processing through AWS Bedrock with valid Business Associate Agreement
  • No permanent storage of patient encounter information
  • Comprehensive audit logging maintained for seven (7) years
  • Customer-managed encryption keys for enhanced security

INDIVIDUAL PRACTITIONER RESPONSIBILITIES

As an individual healthcare provider, you acknowledge and agree that:

  1. You are a licensed healthcare provider authorized to access and use PHI
  2. You will use MedChartMax solely for legitimate medical documentation purposes
  3. You understand your HIPAA responsibilities for PHI processing and patient privacy protection
  4. You are responsible for ensuring your use complies with any applicable organizational policies
  5. You will limit PHI sharing to the minimum necessary for treatment purposes
  6. You have the authority to enter into this agreement in your individual capacity

BREACH NOTIFICATION

Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement within sixty (60) days of becoming aware of such breach. Business Associate will provide such other information regarding the breach as Covered Entity may reasonably request.

RETURN OR DESTRUCTION OF PHI

Upon termination of this Agreement, Business Associate will return to Covered Entity or destroy all PHI received from Covered Entity that Business Associate still maintains in any form. Business Associate will retain no copies of such PHI.

TERM AND TERMINATION

This Agreement shall remain in effect until terminated by either party with thirty (30) days written notice. Upon termination, the provisions regarding return or destruction of PHI shall survive termination.

COMPLIANCE WITH LAW

Business Associate will comply with all applicable provisions of HIPAA, HITECH, and their implementing regulations with respect to the use and disclosure of PHI.

By accepting this Agreement, you acknowledge that you have read, understood, and agree to be bound by all terms and conditions set forth herein.


Questions About This Agreement?

For compliance questions or to discuss this Business Associate Agreement, please contact our HIPAA compliance team: compliance@medchartmax.com.