Back to Harbor

Business Associate Agreement

Standard agreement version v2.3-2026-09-11

Harbor Office, Inc. handles protected health information on behalf of subscribing practices as a business associate. Your practice must execute a BAA before submitting patient information or enabling patient communications.

This introduction summarizes the agreement. The full standard text appears below and is the same source used in the signing flow. Your executed agreement governs your relationship with Harbor. A newly published version does not replace an earlier signature.

What the agreement requires

Export, retention, and earlier commitments

The subscription policy provides a 90-day export-access window. That is separate from record retention and the BAA’s return-or-destruction obligation. The agreement, applicable record requirements, and documented instructions govern disposition. Earlier written commitments remain subject to their own terms; this summary does not withdraw them.

See the Privacy Policy for data handling and subprocessors, the Cancellation and Refund Policy for leaving Harbor, and the Security page for descriptions of controls. A contractual safeguard is not proof of an independent audit or certification.

Review and sign

An authorized practice representative reviews and signs the agreement during BAA onboarding. Review your practice’s legal name and the full text before signing. Contact chance@harboroffice.ai for a copy or questions about an existing agreement.

Read the full standard agreement

Preview only: the practice name and execution date are completed in the signing flow.

BUSINESS ASSOCIATE AGREEMENT
Effective Date: 2026-09-12
Version: v2.3-2026-09-11

This Business Associate Agreement (this "Agreement") is entered into by
and between Harbor Office, Inc. (a Delaware corporation, doing business
as "Harbor", referred to herein as the "Business Associate") and
[Practice legal name] (the "Covered Entity"), as of the Effective Date above.

This version applies when executed by the parties. Publishing it does
not amend an earlier executed BAA or change a historical signature.
An existing agreement continues under its own amendment provisions
until the parties validly replace or amend it. Harbor has prepared this
agreement; it is not a representation of outside legal approval or
independent security certification.

1. DEFINITIONS

   1.1 "Protected Health Information" or "PHI" has the meaning set
   forth in 45 C.F.R. § 160.103, limited to information created,
   received, maintained, or transmitted by Business Associate on
   behalf of Covered Entity in the performance of services under
   the parties' underlying services agreement (the "Services").

   1.2 "HIPAA Rules" means the Privacy, Security, Breach
   Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and
   164.

   1.3 Capitalized terms used but not defined herein have the
   meaning ascribed to them by the HIPAA Rules.

2. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE

   2.1 Business Associate may use or disclose PHI only as
   reasonably necessary to provide the Services to Covered Entity,
   including:
     (a) operating an AI receptionist that answers, screens, and
         schedules patient calls;
     (b) operating an electronic health record (EHR) system,
         including intake forms, clinical documentation, assessment
         administration, and billing functions;
     (c) routine system administration, including backup, security
         monitoring, and incident response.

   2.2 Business Associate may use or disclose PHI as Required by
   Law.

   2.3 Business Associate may use PHI for the proper management
   and administration of Business Associate or to carry out the
   legal responsibilities of Business Associate, as permitted by
   45 C.F.R. § 164.504(e)(4).

   2.4 Business Associate may use PHI to provide Data Aggregation
   services to Covered Entity if requested and only to the extent
   that doing so is consistent with 45 C.F.R. §
   164.504(e)(2)(i)(B).

   2.5 De-identification. Covered Entity
   authorizes Business Associate to de-identify PHI in accordance
   with 45 C.F.R. § 164.514(a)-(c). Information de-identified under
   the Safe Harbor method of 45 C.F.R. § 164.514(b)(2) — removal of
   all eighteen identifier categories, with no actual knowledge that
   the remaining information could identify an individual — is no
   longer PHI. Business Associate may use such information only to
   measure and improve the Services and produce aggregate service
   analytics, subject to this section's restrictions. Removing names
   or other direct identifiers alone is not sufficient. Until the
   applicable de-identification requirements have been satisfied,
   the information remains PHI subject to this Agreement. Records
   of patients who have opted out of this use are excluded at source.
   Any re-identification code
   complies with 45 C.F.R. § 164.514(c) and is never disclosed to
   any third party. Records subject to 42 C.F.R. Part 2 are excluded
   from de-identified analytics.

   2.6 Business Associate shall limit requests, uses, and disclosures
   of PHI to the minimum necessary where that standard applies.
   Covered Entity shall communicate applicable restrictions,
   authorization revocations, and limitations in its privacy notice
   that affect the Services. Covered Entity shall not request a use
   or disclosure that would violate the HIPAA Rules.

3. PROHIBITED USES AND DISCLOSURES

   3.1 Business Associate shall not use or disclose PHI in any
   manner that would violate Subpart E of 45 C.F.R. Part 164 if
   done by Covered Entity.

   3.2 Business Associate shall not sell PHI under any
   circumstance.

   3.3 Business Associate shall not use or disclose PHI for
   marketing purposes without obtaining Covered Entity's prior
   written consent and (where required) the individual's
   authorization.

   3.4 To the extent Business Associate carries out an obligation
   of Covered Entity under Subpart E of Part 164, Business Associate
   shall comply with the requirements applicable to that obligation.
   This Agreement does not authorize a use or disclosure prohibited
   by an applicable additional confidentiality law, including
   42 C.F.R. Part 2, or by an agreed patient restriction.

4. SAFEGUARDS

   4.1 Business Associate shall implement administrative,
   physical, and technical safeguards as required by 45 C.F.R. §
   164.308, § 164.310, and § 164.312, that reasonably and
   appropriately protect the confidentiality, integrity, and
   availability of PHI.

   4.2 Business Associate shall maintain: (i) TLS-encrypted transport
   for PHI in transit; (ii) AES-256-equivalent encryption for PHI at
   rest; (iii) audit logging of every PHI access and mutation;
   (iv) per-patient data-collection opt-out gates on AI-derived data;
   and (v) subcontractor agreements required by Section 6. These are
   contractual obligations, not a statement that an independent
   examination has certified their implementation. Business Associate
   shall investigate identified control gaps and document remediation.

5. REPORTING

   5.1 Business Associate shall report to Covered Entity any use
   or disclosure of PHI not permitted by this Agreement, any
   Security Incident, and any Breach of Unsecured PHI of which it
   becomes aware.

   5.2 Reports of Breaches of Unsecured PHI shall be made without
   unreasonable delay and in no case later than sixty (60) calendar
   days following discovery, including the information required by
   45 C.F.R. § 164.410(c).

   5.4 The outside limit in Section 5.2 is not a waiting period.
   A shorter applicable legal deadline or a stricter written
   commitment to Covered Entity continues to apply. An initial
   report may be supplemented as required information becomes
   available; investigation does not justify unreasonable delay.

   5.3 Unsuccessful Security Incidents (e.g. pings, port scans, and
   denied logins that did not result in unauthorized access or
   disclosure) are reported in aggregate on Covered Entity's
   request.

6. SUBCONTRACTORS

   6.1 Business Associate shall ensure that any subcontractor that
   creates, receives, maintains, or transmits PHI on behalf of
   Business Associate agrees to substantially the same
   restrictions and conditions that apply to Business Associate
   under this Agreement.

   6.2 As of the Effective Date, Business Associate's PHI-relevant
   subcontractors include:
     - Amazon Web Services (AWS) — infrastructure hosting, RDS
       database, S3 storage. AWS BAA executed.
     - Paubox — HIPAA-compliant email delivery. Paubox BAA
       executed.
     - SignalWire — carrier-layer voice and SMS transport.
       SignalWire BAA executed.
     - Retell AI — conversational AI for the AI receptionist.
       Retell hosts and runs its own conversational model on its
       own systems; call audio and transcripts are processed by
       Retell. Retell BAA executed.
     - Stedi — EDI 270/271 eligibility and 837/835 claim
       transmission. Stedi BAA executed.

   6.3 Business Associate will update Covered Entity in writing
   when this subcontractor list materially changes.

7. ACCESS, AMENDMENT, AND ACCOUNTING

   7.1 Within fifteen (15) business days of a written request from
   Covered Entity, Business Associate shall make available PHI in a
   Designated Record Set as necessary for Covered Entity to meet
   its obligations under 45 C.F.R. § 164.524.

   7.2 Business Associate shall make any amendment(s) to PHI in a
   Designated Record Set as directed by Covered Entity pursuant to
   45 C.F.R. § 164.526.

   7.3 Business Associate shall document and make available to
   Covered Entity the information required for Covered Entity to
   respond to a request for an accounting of disclosures pursuant
   to 45 C.F.R. § 164.528.

8. ACCESS BY THE SECRETARY

   Business Associate shall make its internal practices, books,
   and records relating to the use and disclosure of PHI received
   from, or created or received by Business Associate on behalf of,
   Covered Entity available to the Secretary of the U.S.
   Department of Health and Human Services for purposes of
   determining Covered Entity's compliance with the HIPAA Rules.

9. TERM AND TERMINATION

   9.1 This Agreement shall be effective as of the Effective Date
   and shall terminate when all PHI provided by Covered Entity to
   Business Associate, or created or received by Business
   Associate on behalf of Covered Entity, is destroyed or returned
   to Covered Entity, or, if it is infeasible to return or destroy
   PHI, protections are extended to such PHI in accordance with
   Section 9.4.

   9.2 Either party may terminate this Agreement if it determines,
   in good faith, that the other party has materially breached a
   provision of this Agreement and such breach is not cured within
   thirty (30) days of written notice.

   9.3 Covered Entity may terminate this Agreement immediately
   upon written notice if Business Associate has violated a
   material term of this Agreement and cure is not possible.

   9.4 Upon termination, Business Associate shall, if feasible,
   return or destroy all PHI received from Covered Entity, or
   created, maintained, or received by Business Associate on
   behalf of Covered Entity. If return or destruction is
   infeasible, Business Associate shall extend the protections of
   this Agreement to such PHI and limit further uses and
   disclosures to those purposes that make the return or
   destruction infeasible, for so long as Business Associate
   retains the PHI.

   9.5 The parties shall coordinate the return or destruction of
   records, including copies held by subcontractors. If retention
   is necessary, Business Associate shall document the records
   retained, the reason return or destruction is infeasible, the
   permitted purpose, and the disposition plan. A subscription
   export-access window is not a blanket destruction deadline or
   permission for unrestricted continued use. Applicable legal
   holds and record-specific obligations must be addressed before
   destruction. No general retention default overrides this section.

10. INDEMNIFICATION

   Each party shall indemnify, defend, and hold harmless the
   other party (and its officers, directors, employees, and
   agents) from and against any and all claims, losses,
   liabilities, damages, costs, and expenses (including reasonable
   attorneys' fees) arising out of or resulting from the
   indemnifying party's breach of this Agreement or violation of
   the HIPAA Rules. This Section 10 survives termination.

11. MISCELLANEOUS

   11.1 Regulatory References. A reference in this Agreement to
   a section in the HIPAA Rules means the section as in effect or
   as amended.

   11.2 Amendment. The parties agree to take such action as is
   necessary to amend this Agreement from time to time as is
   necessary for Covered Entity to comply with the requirements of
   the HIPAA Rules and any other applicable law.

   11.3 Survival. The respective rights and obligations of
   Business Associate under Sections 5 (Reporting), 9.4 (Return or
   Destruction), and 10 (Indemnification) survive termination of
   this Agreement.

   11.4 Interpretation. Any ambiguity in this Agreement shall be
   resolved to permit Covered Entity to comply with the HIPAA
   Rules.

   11.5 Governing Law and Venue. This Agreement shall be governed
   by and construed in accordance with the laws of the State of
   Delaware, without regard to its conflicts-of-law
   principles. The exclusive venue for any action arising out of or
   relating to this Agreement shall be the state and federal courts
   located in the State of Delaware, and each party
   consents to the personal jurisdiction of those courts.

   11.6 Entire Agreement. This Agreement, together with the
   parties' underlying services agreement, constitutes the entire
   agreement between the parties with respect to its subject
   matter and supersedes all prior or contemporaneous agreements
   and understandings, oral or written, relating to such subject
   matter only when a replacement or amendment validly takes effect.
   This Agreement controls conflicting PHI obligations and the forum
   for disputes arising out of or relating to this Agreement. The
   services agreement's arbitration clause does not override Section
   11.5. Accrued rights and obligations that survive are preserved.

EXECUTION

By signing below, the Covered Entity's authorized signatory
acknowledges that they have read, understood, and agreed to be
bound by the terms of this Agreement.

Covered Entity: [Practice legal name]

Terms of Service · Privacy Policy