Business Associate Agreement
Standard agreement version v2.3-2026-09-11
Harbor Office, Inc. handles protected health information on behalf of subscribing practices as a business associate. Your practice must execute a BAA before submitting patient information or enabling patient communications.
This introduction summarizes the agreement. The full standard text appears below and is the same source used in the signing flow. Your executed agreement governs your relationship with Harbor. A newly published version does not replace an earlier signature.
What the agreement requires
- Use and disclosure of PHI only for the authorized services, the specified permitted purposes, or as required by law.
- Administrative, physical, and technical safeguards, with contractual commitments for encryption, audit logging, and patient data choices.
- Reporting of unauthorized uses, disclosures, security incidents, and breaches. Breach notice is due without unreasonable delay and no later than 60 calendar days after discovery; a shorter applicable deadline or written commitment still applies.
- Written agreements imposing the required protections on subcontractors handling PHI.
- Assistance with patient access, amendment, and disclosure-accounting requests. Section 7.1 specifies 15 business days for the practice’s written access request.
- Return or destruction of PHI at termination where feasible. If infeasible, the BAA’s protections continue and further uses are limited to the purposes making return or destruction infeasible.
- De-identification only under the specified standard. Direct-identifier removal alone is insufficient. Opted-out patients and Part 2 records are excluded from the described analytics.
- The BAA’s own indemnity, Delaware governing-law, and court-venue provisions. Those provisions should be read together with the Terms.
Export, retention, and earlier commitments
The subscription policy provides a 90-day export-access window. That is separate from record retention and the BAA’s return-or-destruction obligation. The agreement, applicable record requirements, and documented instructions govern disposition. Earlier written commitments remain subject to their own terms; this summary does not withdraw them.
See the Privacy Policy for data handling and subprocessors, the Cancellation and Refund Policy for leaving Harbor, and the Security page for descriptions of controls. A contractual safeguard is not proof of an independent audit or certification.
Review and sign
An authorized practice representative reviews and signs the agreement during BAA onboarding. Review your practice’s legal name and the full text before signing. Contact chance@harboroffice.ai for a copy or questions about an existing agreement.
Read the full standard agreement
Preview only: the practice name and execution date are completed in the signing flow.
BUSINESS ASSOCIATE AGREEMENT
Effective Date: 2026-09-12
Version: v2.3-2026-09-11
This Business Associate Agreement (this "Agreement") is entered into by
and between Harbor Office, Inc. (a Delaware corporation, doing business
as "Harbor", referred to herein as the "Business Associate") and
[Practice legal name] (the "Covered Entity"), as of the Effective Date above.
This version applies when executed by the parties. Publishing it does
not amend an earlier executed BAA or change a historical signature.
An existing agreement continues under its own amendment provisions
until the parties validly replace or amend it. Harbor has prepared this
agreement; it is not a representation of outside legal approval or
independent security certification.
1. DEFINITIONS
1.1 "Protected Health Information" or "PHI" has the meaning set
forth in 45 C.F.R. § 160.103, limited to information created,
received, maintained, or transmitted by Business Associate on
behalf of Covered Entity in the performance of services under
the parties' underlying services agreement (the "Services").
1.2 "HIPAA Rules" means the Privacy, Security, Breach
Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and
164.
1.3 Capitalized terms used but not defined herein have the
meaning ascribed to them by the HIPAA Rules.
2. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
2.1 Business Associate may use or disclose PHI only as
reasonably necessary to provide the Services to Covered Entity,
including:
(a) operating an AI receptionist that answers, screens, and
schedules patient calls;
(b) operating an electronic health record (EHR) system,
including intake forms, clinical documentation, assessment
administration, and billing functions;
(c) routine system administration, including backup, security
monitoring, and incident response.
2.2 Business Associate may use or disclose PHI as Required by
Law.
2.3 Business Associate may use PHI for the proper management
and administration of Business Associate or to carry out the
legal responsibilities of Business Associate, as permitted by
45 C.F.R. § 164.504(e)(4).
2.4 Business Associate may use PHI to provide Data Aggregation
services to Covered Entity if requested and only to the extent
that doing so is consistent with 45 C.F.R. §
164.504(e)(2)(i)(B).
2.5 De-identification. Covered Entity
authorizes Business Associate to de-identify PHI in accordance
with 45 C.F.R. § 164.514(a)-(c). Information de-identified under
the Safe Harbor method of 45 C.F.R. § 164.514(b)(2) — removal of
all eighteen identifier categories, with no actual knowledge that
the remaining information could identify an individual — is no
longer PHI. Business Associate may use such information only to
measure and improve the Services and produce aggregate service
analytics, subject to this section's restrictions. Removing names
or other direct identifiers alone is not sufficient. Until the
applicable de-identification requirements have been satisfied,
the information remains PHI subject to this Agreement. Records
of patients who have opted out of this use are excluded at source.
Any re-identification code
complies with 45 C.F.R. § 164.514(c) and is never disclosed to
any third party. Records subject to 42 C.F.R. Part 2 are excluded
from de-identified analytics.
2.6 Business Associate shall limit requests, uses, and disclosures
of PHI to the minimum necessary where that standard applies.
Covered Entity shall communicate applicable restrictions,
authorization revocations, and limitations in its privacy notice
that affect the Services. Covered Entity shall not request a use
or disclosure that would violate the HIPAA Rules.
3. PROHIBITED USES AND DISCLOSURES
3.1 Business Associate shall not use or disclose PHI in any
manner that would violate Subpart E of 45 C.F.R. Part 164 if
done by Covered Entity.
3.2 Business Associate shall not sell PHI under any
circumstance.
3.3 Business Associate shall not use or disclose PHI for
marketing purposes without obtaining Covered Entity's prior
written consent and (where required) the individual's
authorization.
3.4 To the extent Business Associate carries out an obligation
of Covered Entity under Subpart E of Part 164, Business Associate
shall comply with the requirements applicable to that obligation.
This Agreement does not authorize a use or disclosure prohibited
by an applicable additional confidentiality law, including
42 C.F.R. Part 2, or by an agreed patient restriction.
4. SAFEGUARDS
4.1 Business Associate shall implement administrative,
physical, and technical safeguards as required by 45 C.F.R. §
164.308, § 164.310, and § 164.312, that reasonably and
appropriately protect the confidentiality, integrity, and
availability of PHI.
4.2 Business Associate shall maintain: (i) TLS-encrypted transport
for PHI in transit; (ii) AES-256-equivalent encryption for PHI at
rest; (iii) audit logging of every PHI access and mutation;
(iv) per-patient data-collection opt-out gates on AI-derived data;
and (v) subcontractor agreements required by Section 6. These are
contractual obligations, not a statement that an independent
examination has certified their implementation. Business Associate
shall investigate identified control gaps and document remediation.
5. REPORTING
5.1 Business Associate shall report to Covered Entity any use
or disclosure of PHI not permitted by this Agreement, any
Security Incident, and any Breach of Unsecured PHI of which it
becomes aware.
5.2 Reports of Breaches of Unsecured PHI shall be made without
unreasonable delay and in no case later than sixty (60) calendar
days following discovery, including the information required by
45 C.F.R. § 164.410(c).
5.4 The outside limit in Section 5.2 is not a waiting period.
A shorter applicable legal deadline or a stricter written
commitment to Covered Entity continues to apply. An initial
report may be supplemented as required information becomes
available; investigation does not justify unreasonable delay.
5.3 Unsuccessful Security Incidents (e.g. pings, port scans, and
denied logins that did not result in unauthorized access or
disclosure) are reported in aggregate on Covered Entity's
request.
6. SUBCONTRACTORS
6.1 Business Associate shall ensure that any subcontractor that
creates, receives, maintains, or transmits PHI on behalf of
Business Associate agrees to substantially the same
restrictions and conditions that apply to Business Associate
under this Agreement.
6.2 As of the Effective Date, Business Associate's PHI-relevant
subcontractors include:
- Amazon Web Services (AWS) — infrastructure hosting, RDS
database, S3 storage. AWS BAA executed.
- Paubox — HIPAA-compliant email delivery. Paubox BAA
executed.
- SignalWire — carrier-layer voice and SMS transport.
SignalWire BAA executed.
- Retell AI — conversational AI for the AI receptionist.
Retell hosts and runs its own conversational model on its
own systems; call audio and transcripts are processed by
Retell. Retell BAA executed.
- Stedi — EDI 270/271 eligibility and 837/835 claim
transmission. Stedi BAA executed.
6.3 Business Associate will update Covered Entity in writing
when this subcontractor list materially changes.
7. ACCESS, AMENDMENT, AND ACCOUNTING
7.1 Within fifteen (15) business days of a written request from
Covered Entity, Business Associate shall make available PHI in a
Designated Record Set as necessary for Covered Entity to meet
its obligations under 45 C.F.R. § 164.524.
7.2 Business Associate shall make any amendment(s) to PHI in a
Designated Record Set as directed by Covered Entity pursuant to
45 C.F.R. § 164.526.
7.3 Business Associate shall document and make available to
Covered Entity the information required for Covered Entity to
respond to a request for an accounting of disclosures pursuant
to 45 C.F.R. § 164.528.
8. ACCESS BY THE SECRETARY
Business Associate shall make its internal practices, books,
and records relating to the use and disclosure of PHI received
from, or created or received by Business Associate on behalf of,
Covered Entity available to the Secretary of the U.S.
Department of Health and Human Services for purposes of
determining Covered Entity's compliance with the HIPAA Rules.
9. TERM AND TERMINATION
9.1 This Agreement shall be effective as of the Effective Date
and shall terminate when all PHI provided by Covered Entity to
Business Associate, or created or received by Business
Associate on behalf of Covered Entity, is destroyed or returned
to Covered Entity, or, if it is infeasible to return or destroy
PHI, protections are extended to such PHI in accordance with
Section 9.4.
9.2 Either party may terminate this Agreement if it determines,
in good faith, that the other party has materially breached a
provision of this Agreement and such breach is not cured within
thirty (30) days of written notice.
9.3 Covered Entity may terminate this Agreement immediately
upon written notice if Business Associate has violated a
material term of this Agreement and cure is not possible.
9.4 Upon termination, Business Associate shall, if feasible,
return or destroy all PHI received from Covered Entity, or
created, maintained, or received by Business Associate on
behalf of Covered Entity. If return or destruction is
infeasible, Business Associate shall extend the protections of
this Agreement to such PHI and limit further uses and
disclosures to those purposes that make the return or
destruction infeasible, for so long as Business Associate
retains the PHI.
9.5 The parties shall coordinate the return or destruction of
records, including copies held by subcontractors. If retention
is necessary, Business Associate shall document the records
retained, the reason return or destruction is infeasible, the
permitted purpose, and the disposition plan. A subscription
export-access window is not a blanket destruction deadline or
permission for unrestricted continued use. Applicable legal
holds and record-specific obligations must be addressed before
destruction. No general retention default overrides this section.
10. INDEMNIFICATION
Each party shall indemnify, defend, and hold harmless the
other party (and its officers, directors, employees, and
agents) from and against any and all claims, losses,
liabilities, damages, costs, and expenses (including reasonable
attorneys' fees) arising out of or resulting from the
indemnifying party's breach of this Agreement or violation of
the HIPAA Rules. This Section 10 survives termination.
11. MISCELLANEOUS
11.1 Regulatory References. A reference in this Agreement to
a section in the HIPAA Rules means the section as in effect or
as amended.
11.2 Amendment. The parties agree to take such action as is
necessary to amend this Agreement from time to time as is
necessary for Covered Entity to comply with the requirements of
the HIPAA Rules and any other applicable law.
11.3 Survival. The respective rights and obligations of
Business Associate under Sections 5 (Reporting), 9.4 (Return or
Destruction), and 10 (Indemnification) survive termination of
this Agreement.
11.4 Interpretation. Any ambiguity in this Agreement shall be
resolved to permit Covered Entity to comply with the HIPAA
Rules.
11.5 Governing Law and Venue. This Agreement shall be governed
by and construed in accordance with the laws of the State of
Delaware, without regard to its conflicts-of-law
principles. The exclusive venue for any action arising out of or
relating to this Agreement shall be the state and federal courts
located in the State of Delaware, and each party
consents to the personal jurisdiction of those courts.
11.6 Entire Agreement. This Agreement, together with the
parties' underlying services agreement, constitutes the entire
agreement between the parties with respect to its subject
matter and supersedes all prior or contemporaneous agreements
and understandings, oral or written, relating to such subject
matter only when a replacement or amendment validly takes effect.
This Agreement controls conflicting PHI obligations and the forum
for disputes arising out of or relating to this Agreement. The
services agreement's arbitration clause does not override Section
11.5. Accrued rights and obligations that survive are preserved.
EXECUTION
By signing below, the Covered Entity's authorized signatory
acknowledges that they have read, understood, and agreed to be
bound by the terms of this Agreement.
Covered Entity: [Practice legal name]