Platform
Solutions
Company
Pricing
Register nowSign in

Legal

Business Associate Agreement

This Business Associate Agreement is incorporated by reference into the ProbityCare Terms & Conditions and governs ProbityCare's creation, receipt, maintenance, and transmission of protected health information on your behalf.

Last updated August 22, 2026Effective September 22, 2026Version 3.0

This Business Associate Agreement (the “BAA” or “Agreement”) is entered into by and between ProbityCare Solutions Inc., a Florida corporation (“Business Associate”), and the customer organization that accepts it (“Covered Entity”), and is required by the Health Insurance Portability and Accountability Act of 1996, as amended by the HITECH Act and implemented by 45 C.F.R. Parts 160 and 164 (collectively, “HIPAA”).

How this BAA is executed

A BAA must be in place before any protected health information is submitted to the platform. You may execute this Agreement in either of two ways: (a) by accepting it during onboarding, which constitutes a binding electronic signature under the U.S. E-SIGN Act; or (b) by countersigning a copy of this document, or your own BAA form, returned to legal@probitycare.com. Where your organization requires its own BAA form, that negotiated agreement controls over this one.

1Parties and effective date

Business AssociateProbityCare Solutions Inc., a Florida corporation, with offices at 2125 Biscayne Blvd, Ste 303, Miami, FL 33137.
Covered EntityThe healthcare provider, health plan, healthcare clearinghouse, or other business associate that has entered into a subscription agreement with ProbityCare and accepted this BAA.
Effective dateThe earlier of (a) the date Covered Entity accepts this BAA, or (b) the date Covered Entity first transmits PHI to the Services. This version is effective September 22, 2026 and supersedes all prior versions.
RelationshipBusiness Associate performs revenue cycle management, claims processing, eligibility verification, clinical documentation, and related administrative functions on behalf of Covered Entity, which requires access to PHI.

This BAA is incorporated into and made part of the ProbityCare Terms & Conditions (the “Underlying Agreement”). In the event of any conflict between this BAA and the Underlying Agreement with respect to PHI, this BAA controls.

2Definitions

Capitalized terms used but not defined in this BAA have the meanings assigned to them in HIPAA. For convenience, the following terms are used throughout:

PHIProtected Health Information, as defined at 45 C.F.R. § 160.103, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity.
ePHIPHI that is transmitted by or maintained in electronic media.
BreachThe acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule which compromises the security or privacy of the PHI, as defined at 45 C.F.R. § 164.402.
Security IncidentThe attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations in an information system, as defined at 45 C.F.R. § 164.304.
Required By LawAs defined at 45 C.F.R. § 164.103.
Designated Record SetAs defined at 45 C.F.R. § 164.501.
SubcontractorA person or entity to whom Business Associate delegates a function, activity, or service involving the use or disclosure of PHI, as defined at 45 C.F.R. § 160.103.

3Permitted uses and disclosures

Business Associate may use and disclose PHI only as follows, and only to the minimum extent necessary to accomplish the intended purpose:

  1. To perform the Services. To carry out the revenue cycle, claims, eligibility, coding, documentation, analytics, and administrative functions described in the Underlying Agreement.
  2. As directed by Covered Entity. To perform functions, activities, or services for or on behalf of Covered Entity, consistent with Covered Entity's instructions and its own Notice of Privacy Practices.
  3. For Business Associate's proper management and administration, or to carry out its legal responsibilities, provided that any disclosure to a third party is either Required By Law or made only after Business Associate obtains reasonable assurances that the information will be held confidentially, used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
  4. To provide data aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
  5. To de-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c). Properly de-identified information is not PHI and its use is not restricted by this BAA.
  6. To report violations of law to appropriate federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1).

Use of de-identified data for service improvement

Business Associate may use de-identified data derived from PHI to operate, secure, audit, benchmark, and improve the Services, including to train and validate models used for coding, denial prediction, and anomaly detection. Such data is de-identified under the Safe Harbor or Expert Determination method before use.

What we do not do

  • We do not sell PHI or de-identified data derived from it, and we do not use PHI for our own advertising or marketing.
  • We do not use one customer's identifiable data to benefit another customer, and we do not commingle customer data across tenants.
  • We do not send PHI to third-party general-purpose AI services that lack an executed BAA and a zero-retention configuration.

4Prohibited uses and disclosures

Business Associate shall not:

  • Use or disclose PHI other than as permitted or required by this BAA or as Required By Law;
  • Use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted under Section 3(3) and 3(4) above;
  • Sell PHI or receive direct or indirect remuneration in exchange for PHI, except as permitted by 45 C.F.R. § 164.502(a)(5)(ii);
  • Use or disclose PHI for marketing or fundraising communications, or for any purpose requiring an authorization under 45 C.F.R. § 164.508, without a valid authorization;
  • Use, disclose, or transmit PHI outside the United States without Covered Entity's prior written consent; or
  • Use genetic information for underwriting purposes, consistent with 45 C.F.R. § 164.502(a)(5)(i).

5Obligations of Business Associate

Business Associate agrees to:

  1. Not use or further disclose PHI except as permitted by this BAA or Required By Law;
  2. Use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this BAA;
  3. Mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this BAA;
  4. Report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including Breaches of unsecured PHI and Security Incidents, as described in Section 7;
  5. Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on Business Associate's behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate, as described in Section 8;
  6. Make available PHI, and provide access, amendment, and accounting support, as described in Section 9;
  7. Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA, and promptly notify Covered Entity of any such request unless prohibited from doing so;
  8. To the extent Business Associate carries out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations;
  9. Request, use, and disclose only the minimum necessary PHI to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b); and
  10. Maintain and, upon request, provide to Covered Entity documentation sufficient to demonstrate compliance with this BAA, including its current SOC 2 Type II report and a summary of its most recent HIPAA Security Rule risk analysis.

6Security Rule compliance

Business Associate shall comply with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) as it applies directly to business associates, and shall implement and maintain a written information security program that includes, at minimum:

Risk analysisAn accurate and thorough assessment of risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI, reviewed at least annually and upon material change, per 45 C.F.R. § 164.308(a)(1)(ii)(A).
Access controlUnique user identification, role-based least-privilege access, automatic logoff, and mandatory multi-factor authentication for all workforce access to production systems.
EncryptionePHI encrypted in transit with TLS 1.2 or higher and at rest with AES-256, such that affected PHI is rendered unusable, unreadable, or indecipherable under the Breach Notification safe harbor at 45 C.F.R. § 164.402(2).
Audit controlsImmutable, tamper-evident logging of PHI access, modification, export, and administrative action, retained no less than six (6) years and reviewed on a defined cadence.
Workforce securityBackground screening where permitted by law, documented HIPAA and security awareness training at onboarding and annually thereafter, sanction policy, and access termination within twenty-four (24) hours of separation.
Integrity & availabilityEncrypted backups with tested restoration, a documented disaster recovery plan with defined RPO and RTO, and an emergency mode operation plan.
Device & mediaFull-disk encryption and mobile device management on all endpoints with potential ePHI access; documented sanitization and disposal of media per NIST SP 800-88.
SegregationLogical tenant isolation enforced at the data layer so that no tenant can access another tenant's PHI.

Business Associate maintains an annual independent SOC 2 Type II examination covering Security, Availability, and Confidentiality, and conducts third-party penetration testing at least annually. Reports are available to Covered Entity under NDA on request. Further operational detail is published on the HIPAA compliance page.

7Reporting and breach notification

Breach of unsecured PHI

Business Associate shall notify Covered Entity of any Breach of unsecured PHI without unreasonable delay and in no case later than fifteen (15) calendar days after discovery. This is intentionally shorter than the sixty (60) days permitted by 45 C.F.R. § 164.410 so that Covered Entity retains sufficient time to meet its own notification deadlines. A Breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to Business Associate.

Notification will include, to the extent then known and as it becomes available:

  • The identification of each individual whose PHI was or is reasonably believed to have been accessed, acquired, used, or disclosed;
  • A description of what happened, including the date of the Breach and the date of discovery;
  • The types of PHI involved (for example, name, Social Security number, date of birth, diagnosis, or claim data);
  • The results of Business Associate's risk assessment under 45 C.F.R. § 164.402(2);
  • Steps taken to investigate, mitigate harm, and protect against further Breaches; and
  • Contact details for a person able to answer Covered Entity's questions.

Security Incidents

Business Associate shall report Security Incidents that result in unauthorized access, use, disclosure, modification, or destruction of ePHI within five (5) business days of discovery. The parties acknowledge that Business Associate's systems continuously receive unsuccessful and immaterial attempts — including pings, port scans, denied login attempts, and blocked malware — and agree that this paragraph constitutes notice of such attempts, so that no separate report is required for them unless they result in unauthorized access to ePHI.

Who notifies individuals

Unless the parties agree otherwise in writing, Covered Entity is responsible for notifying affected individuals, the Secretary of HHS, and, where applicable, the media under 45 C.F.R. §§ 164.404–164.408. At Covered Entity's written request, Business Associate will provide reasonable assistance with notification and, where the Breach arose from Business Associate's acts or omissions, will bear the reasonable, documented cost of notification, call center support, and credit monitoring where legally required.

Notice under this Section shall be sent to the security and privacy contacts Covered Entity designates in the platform. Covered Entity is responsible for keeping those contacts current. Business Associate's reporting contact is security@probitycare.com.

8Subcontractors

Business Associate may engage Subcontractors to perform functions involving PHI only where it has first entered into a written agreement imposing obligations at least as restrictive as those in this BAA, consistent with 45 C.F.R. §§ 164.308(b)(2) and 164.502(e)(1)(ii). Business Associate remains responsible to Covered Entity for its Subcontractors' performance.

A current list of Subcontractors that may process PHI, together with their function and hosting location, is published on the HIPAA compliance page and is incorporated here by reference. Business Associate will provide at least thirty (30) days' advance notice before adding a new Subcontractor with PHI access. If Covered Entity reasonably objects on documented security or compliance grounds, the parties will work in good faith toward an alternative; if none is available, Covered Entity may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees.

All Subcontractors with access to PHI are located in and process data within the United States.

9Individual rights support

Because Business Associate maintains PHI in a Designated Record Set on behalf of Covered Entity, it agrees to:

Access — § 164.524Make PHI available to Covered Entity, or at its direction to the individual, within ten (10) business days of request, in the form and format requested where readily producible, so that Covered Entity can meet its thirty (30) day obligation.
Amendment — § 164.526Make PHI available for amendment, and incorporate any amendment Covered Entity directs, within ten (10) business days of request.
Accounting — § 164.528Document and make available the information required to provide an accounting of disclosures, retaining such records for at least six (6) years, within ten (10) business days of request.
Restrictions — § 164.522Honor any restriction on use or disclosure that Covered Entity has agreed to or is required to accept, including the self-pay restriction under 45 C.F.R. § 164.522(a)(1)(vi), provided Covered Entity communicates the restriction through the platform.
Confidential commsSupport Covered Entity's accommodation of reasonable requests to receive communications by alternative means or at alternative locations.

Business Associate provides self-service tooling in the platform for access, amendment, and accounting requests. Covered Entity is responsible for evaluating and responding to individual requests, including any applicable denials and review rights.

10Obligations of Covered Entity

Covered Entity agrees to:

  1. Notify Business Associate of any limitation in its Notice of Privacy Practices, to the extent that the limitation may affect Business Associate's use or disclosure of PHI;
  2. Notify Business Associate of any change in, or revocation of, an individual's permission to use or disclose their PHI;
  3. Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by;
  4. Not request that Business Associate use or disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted under Sections 3(3) and 3(4);
  5. Obtain any consents, authorizations, or permissions necessary for Business Associate to perform the Services and process PHI as contemplated;
  6. Configure and administer its own tenant appropriately, including provisioning and deprovisioning user accounts promptly, assigning least-privilege roles, enforcing multi-factor authentication for its workforce, and reviewing access and audit reports on a regular basis; and
  7. Maintain accurate security and privacy notification contacts within the platform, and refrain from submitting PHI through unsupported channels such as unencrypted email or general support chat.

Shared responsibility

Business Associate secures the platform; Covered Entity governs who inside its own organization may use it. Most real-world PHI incidents originate in account administration — stale accounts, shared logins, over-broad roles — which sit on Covered Entity's side of this line.

11Term and termination

This BAA takes effect on the effective date described in Section 1 and remains in force until all PHI is returned or destroyed under Section 12, or until terminated as provided below. It terminates automatically upon termination or expiration of the Underlying Agreement, subject to the survival of Section 12.

Termination for cause

Upon a party's knowledge of a material breach of this BAA by the other party, the non-breaching party shall provide written notice and an opportunity to cure within thirty (30) days. If cure is not achieved within that period, the non-breaching party may terminate this BAA and the Underlying Agreement. If cure is not feasible and termination is not feasible, Covered Entity shall report the violation to the Secretary of HHS, as contemplated by 45 C.F.R. § 164.504(e)(1)(ii).

Suspension

Business Associate may suspend processing of PHI, in whole or in part, where it reasonably believes continued processing would violate HIPAA or create imminent risk to PHI. Business Associate will notify Covered Entity promptly and limit any suspension to what is necessary.

12Return or destruction of PHI

Upon termination or expiration of this BAA, Business Associate shall return to Covered Entity, or destroy, all PHI it created, received, maintained, or transmitted on behalf of Covered Entity, including PHI in the possession of its Subcontractors, and shall retain no copies.

Export windowCovered Entity has thirty (30) days from termination to export its data through the platform's export tooling in a structured, machine-readable format. Business Associate will provide reasonable migration assistance on request.
DeletionProduction PHI is deleted within sixty (60) days of the close of the export window; encrypted backups age out on their normal rotation within ninety (90) days thereafter. Written certification of destruction is available on request.
Infeasible returnWhere return or destruction is infeasible — for example, PHI embedded in immutable audit logs or required to be retained by law — Business Associate shall extend the protections of this BAA to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible, for as long as it is retained.
Retained recordsAudit logs and compliance records that evidence PHI handling are retained for six (6) years as required by 45 C.F.R. § 164.316(b)(2), and remain subject to this BAA.

The obligations of this Section survive termination of this BAA indefinitely.

13Indemnification and liability

Each party shall indemnify, defend, and hold harmless the other party and its officers, directors, employees, and agents from and against any third-party claims, losses, liabilities, fines, civil monetary penalties, and reasonable attorneys' fees arising out of or relating to the indemnifying party's breach of this BAA or its violation of HIPAA, to the extent caused by that party's acts or omissions.

The party seeking indemnification shall provide prompt written notice of the claim, reasonable cooperation, and, at the indemnifying party's option and expense, control of the defense and settlement, provided that no settlement imposing non-monetary obligations on the indemnified party may be entered without its consent.

Liability cap

Liability arising from a Breach of unsecured PHI, or from a party's violation of HIPAA, is excluded from the general liability cap in the Underlying Agreement and is instead subject to a separate cap equal to the greater of three (3) times the fees paid in the twelve (12) months preceding the incident or $1,000,000. Nothing in this BAA limits liability for gross negligence, willful misconduct, or fraud, or for civil monetary penalties assessed directly against a party by a regulator.

14Insurance

Throughout the term of this BAA, Business Associate shall maintain, at its own expense, insurance coverage with carriers rated A- or better by A.M. Best, including:

  • Cyber liability and privacy liability of not less than $5,000,000 per claim and in the aggregate, expressly covering HIPAA regulatory defense, civil monetary penalties where insurable by law, breach notification costs, and credit monitoring;
  • Technology errors and omissions of not less than $5,000,000 per claim; and
  • Commercial general liability of not less than $2,000,000 per occurrence.

Certificates of insurance are available to Covered Entity upon written request. Business Associate will provide notice of cancellation or material reduction in coverage within ten (10) days.

15Miscellaneous

Regulatory references and amendment

A reference in this BAA to a section of HIPAA means the section as in effect or as amended. The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for compliance with HIPAA and other applicable law, including any successor regulation to the HIPAA Security Rule. Business Associate may update this BAA to maintain regulatory compliance on thirty (30) days' notice; material changes adverse to Covered Entity require its consent, which will not be unreasonably withheld.

Interpretation

Any ambiguity in this BAA shall be resolved to permit compliance with HIPAA. This BAA controls over any conflicting term in the Underlying Agreement with respect to PHI. If any provision is held invalid, the remainder continues in force.

State law

Where a state law affording greater privacy protection to health information is not preempted by HIPAA, the parties shall comply with that law. This includes applicable state medical records, substance use disorder (42 C.F.R. Part 2), reproductive health, mental health, minor consent, and HIV/AIDS confidentiality statutes.

Governing law and venue

This BAA is governed by the laws of the State of Florida, without regard to its conflict of laws principles, except to the extent superseded by federal law. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in Miami-Dade County, Florida.

No third-party beneficiaries

Nothing in this BAA confers any rights, remedies, obligations, or liabilities upon any person other than the parties and their respective successors and permitted assigns.

Independent contractors

Neither party is an agent, partner, or joint venturer of the other. Each is solely responsible for its own workforce and for its own compliance obligations under HIPAA.

Notices

Notices under this BAA shall be in writing and delivered to the addresses in Section 16 by email with confirmation of receipt, or by nationally recognized overnight courier, and are effective upon receipt.

Entire agreement

This BAA, together with the Underlying Agreement, constitutes the entire agreement of the parties with respect to PHI and supersedes all prior BAAs and understandings on that subject.

16Execution

By accepting this BAA during onboarding, or by continuing to transmit PHI to the Services after its effective date, the parties execute this Agreement and intend to be legally bound. Electronic acceptance has the same force and effect as a handwritten signature under the U.S. E-SIGN Act and applicable state law. ProbityCare records the accepting user, their organization, the document version, and the timestamp of acceptance, and makes that record available to Covered Entity on request.

Business Associate

ProbityCare Solutions Inc.2125 Biscayne Blvd, Ste 303
Miami, FL 33137
Legal & contracts: legal@probitycare.com
Security & breach reporting: security@probitycare.com
Privacy Officer: privacy@probitycare.com

Requesting a countersigned copy

To receive a countersigned PDF of this BAA, or to submit your organization's own BAA form for review, email legal@probitycare.com with your legal entity name, state of formation, and the name and title of your authorized signatory. We typically return executed agreements within three (3) business days.

Revision history

  • Version 3.0. Corrected the governing entity to ProbityCare Solutions Inc., a Florida corporation, with venue in Miami-Dade County. Shortened Breach notification to fifteen (15) days and Security Incident reporting to five (5) business days. Added Sections 6 (Security Rule detail), 8 (Subcontractor notice and objection rights), 9 (individual rights service levels), 13 (super-cap for PHI liability), and 14 (insurance). Added explicit prohibitions on offshore processing, sale of PHI, and use of general-purpose AI services without a BAA.
  • Version 2.0. Added data aggregation and de-identification permissions; expanded termination and return-of-PHI provisions.
  • Version 1.0. Initial Business Associate Agreement.