Business associate agreementRequired before your members’ records can be held here. Scroll to the end to accept.
# Business Associate Agreement
This Business Associate Agreement (the "BAA") is entered into as of the date it is
accepted electronically, by and between **Vince Systems LLC** (formerly Insta Perf LLC),
an Iowa limited liability company, operating the ProveTrip service ("Business
Associate"), and the organization accepting this BAA ("Covered Entity"), in accordance
with the meaning given to those terms at 45 CFR § 160.103.
In this BAA, Covered Entity and Business Associate are each a "Party" and, collectively,
are the "Parties".
## Background
1. Covered Entity is either a "covered entity" or a "business associate" of a covered
entity as each is defined under the Health Insurance Portability and Accountability
Act of 1996, Public Law 104-191, as amended by the HITECH Act and the related
regulations promulgated by HHS (collectively, "HIPAA"), and as such is required to
comply with HIPAA's provisions regarding the confidentiality and privacy of Protected
Health Information.
2. The Parties have entered into or will enter into one or more agreements under which
Business Associate provides or will provide specified services to Covered Entity
(collectively, the "Agreement"), being the provision of the ProveTrip software service
for recording non-emergency medical transport trips and reconciling payment for them.
3. In providing services pursuant to the Agreement, Business Associate will have access
to Protected Health Information.
4. By providing the services pursuant to the Agreement, Business Associate will become a
"business associate" of Covered Entity as that term is defined under HIPAA.
5. Both Parties are committed to complying with all federal and state laws governing the
confidentiality and privacy of health information.
## 1. Definitions
Capitalized terms used but not defined in this BAA have the meaning given to them by
HIPAA. For clarity:
- **"Breach"** has the meaning given at 45 CFR § 164.402.
- **"Designated Record Set"** has the meaning given at 45 CFR § 164.501.
- **"Electronic Protected Health Information" ("ePHI")** has the meaning given at
45 CFR § 160.103, limited to information created, received, maintained or transmitted
by Business Associate on behalf of Covered Entity.
- **"HITECH Act"** means the Health Information Technology for Economic and Clinical
Health Act, Public Law 111-005.
- **"Individual"** has the meaning given at 45 CFR § 160.103 and includes a person who
qualifies as a personal representative under 45 CFR § 164.502(g).
- **"Protected Health Information" ("PHI")** has the meaning given at 45 CFR § 160.103,
limited to information created, received, maintained or transmitted by Business
Associate on behalf of Covered Entity.
- **"Required By Law"** has the meaning given at 45 CFR § 164.103.
- **"Security Incident"** has the meaning given at 45 CFR § 164.304.
- **"Unsecured PHI"** has the meaning given at 45 CFR § 164.402.
## 2. Use and Disclosure of PHI
Business Associate may use and disclose PHI only as follows:
(a) as necessary to perform the services described in the Agreement;
(b) as Required By Law;
(c) for the proper management and administration of Business Associate, or to carry out
its legal responsibilities, provided that any disclosure for such purposes is either
Required By Law or made only where Business Associate obtains reasonable assurances from
the person to whom the PHI is disclosed that it will be held confidentially and used or
further disclosed only as Required By Law or for the purpose for which it was disclosed,
and that the person will notify Business Associate of any instance of which it is aware
in which the confidentiality of the information has been breached; and
(d) to provide data aggregation services relating to the health care operations of
Covered Entity, as permitted by 45 CFR § 164.504(e)(2)(i)(B).
Business Associate will not use or disclose PHI in any manner that would constitute a
violation of HIPAA if so used or disclosed by Covered Entity, and will not sell PHI or
use or disclose PHI for marketing or fundraising purposes.
Business Associate will make reasonable efforts to use, disclose and request only the
minimum necessary PHI to accomplish the intended purpose, consistent with
45 CFR § 164.502(b).
## 3. Safeguards Against Misuse of PHI
Business Associate will use appropriate administrative, physical and technical safeguards
to prevent the use or disclosure of PHI other than as permitted by this BAA, and will
comply with the Security Rule at 45 CFR Part 164, Subpart C, with respect to ePHI.
Without limiting the foregoing, Business Associate:
(a) isolates each Covered Entity's records from every other customer's records, and
enforces that isolation in the database itself rather than by application logic alone;
(b) restricts access to PHI to those of its workforce who require it, and does not
provide its own administrative staff with any means of reading a Covered Entity's member
records through its administrative console;
(c) records access to member records in an append-only audit log available to Covered
Entity; and
(d) encrypts PHI in transit and at rest.
## 4. Reporting Disclosures of PHI and Security Incidents
Business Associate will report to Covered Entity any use or disclosure of PHI not
permitted by this BAA, and any Security Incident of which it becomes aware, without
unreasonable delay and in any event within five (5) business days of becoming aware of
it.
The Parties acknowledge that this section constitutes notice of the ongoing existence and
occurrence of attempted but unsuccessful Security Incidents — such as pings and other
broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, and denial of
service attacks — for which no additional notice will be required.
## 5. Reporting Breaches of Unsecured PHI
Business Associate will notify Covered Entity of any Breach of Unsecured PHI without
unreasonable delay and in no case later than twenty (20) calendar days after discovery of
the Breach. A Breach is treated as discovered on the first day on which it is known, or
by exercising reasonable diligence would have been known, to Business Associate.
The notification will include, to the extent known at the time and supplemented as
further information becomes available:
(a) the identification of each Individual whose Unsecured PHI has been, or is reasonably
believed to have been, accessed, acquired, used or disclosed;
(b) a description of what happened, including the date of the Breach and the date of its
discovery;
(c) a description of the types of Unsecured PHI involved;
(d) a description of what Business Associate is doing to investigate, to mitigate harm,
and to protect against further breaches; and
(e) a contact at Business Associate able to answer questions.
Business Associate will cooperate with Covered Entity in meeting Covered Entity's
obligations under 45 CFR §§ 164.404 through 164.410.
## 6. Mitigation of Disclosures of PHI
Business Associate will mitigate, to the extent practicable, any harmful effect known to
it of a use or disclosure of PHI by Business Associate in violation of this BAA.
## 7. Agreements with Agents or Subcontractors
Business Associate will ensure that any subcontractor that creates, receives, maintains or
transmits PHI on behalf of Business Associate agrees in writing to restrictions and
conditions at least as protective as those that apply to Business Associate under this
BAA, as required by 45 CFR § 164.502(e)(1)(ii) and § 164.308(b)(2).
Business Associate's hosting infrastructure is provided by Amazon Web Services under an
executed AWS Business Associate Addendum.
Business Associate does not transmit PHI by text message or by electronic mail. Messages
sent to a Covered Entity's drivers state only the number of trips assigned and their
scheduled times; they name no Individual and contain no information about any
Individual's condition, treatment or destination.
## 8. Audit Report
Upon written request, Business Associate will provide Covered Entity with a summary of
its then-current information security practices relevant to the services, and will
reasonably cooperate with Covered Entity's inquiries regarding Business Associate's
compliance with this BAA.
## 9. Access to PHI by Individuals
Business Associate will, within ten (10) business days after written request by Covered
Entity, make available to Covered Entity PHI in a Designated Record Set held by Business
Associate as necessary for Covered Entity to satisfy its obligations under
45 CFR § 164.524. Where an Individual makes such a request directly to Business
Associate, Business Associate will forward it to Covered Entity, which is responsible for
responding.
## 10. Amendment of PHI
Business Associate will, within ten (10) business days after written request by Covered
Entity, make available PHI in a Designated Record Set for amendment, and incorporate any
amendment to that PHI, as necessary for Covered Entity to satisfy its obligations under
45 CFR § 164.526.
## 11. Accounting of Disclosures
Business Associate will document disclosures of PHI and information related to those
disclosures as would be required for Covered Entity to respond to a request for an
accounting of disclosures under 45 CFR § 164.528, and will, within ten (10) business days
after written request by Covered Entity, make that information available to Covered
Entity.
## 12. Availability of Books and Records
Business Associate will make its internal practices, books and records relating to the
use and disclosure of PHI available to the Secretary of the U.S. Department of Health and
Human Services for purposes of determining Covered Entity's compliance with HIPAA.
## 13. Responsibilities of Covered Entity
Covered Entity will:
(a) notify Business Associate of any limitation in its notice of privacy practices, of
any changes in or revocation of an Individual's permission to use or disclose PHI, and of
any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is
required to abide by, in each case to the extent it affects Business Associate's use or
disclosure of PHI;
(b) not request Business Associate to use or disclose PHI in any manner that would not be
permissible under HIPAA if done by Covered Entity; and
(c) be solely responsible for the accuracy and lawfulness of the PHI it, or those acting
on its behalf, enters into the service, and for managing which of its own workforce have
access to it.
## 14. Data Ownership
As between the Parties, all PHI and all records created in the service on behalf of
Covered Entity remain the property of Covered Entity. Business Associate acquires no
ownership interest in them and no right to use them other than as set out in this BAA and
the Agreement.
Covered Entity may export its records at any time while its account is open.
## 15. Term and Termination
This BAA takes effect on the date it is accepted and continues until the Agreement ends
or it is terminated as provided below.
Covered Entity may terminate this BAA and the Agreement if Business Associate materially
breaches this BAA and fails to cure the breach within thirty (30) days of written notice,
or immediately if cure is not possible.
Upon termination, Business Associate will, if feasible, return or destroy all PHI it
maintains on behalf of Covered Entity and retain no copies. Where return or destruction is
not feasible, Business Associate will extend the protections of this BAA to that PHI and
limit further use and disclosure to those purposes that make return or destruction
infeasible, for so long as it is retained.
Covered Entity may request an export of its records for a period of thirty (30) days after
termination.
The obligations of Business Associate under this section survive termination.
## 16. Effect of BAA
To the extent this BAA conflicts with any other term of the Agreement in respect of PHI,
this BAA controls. In all other respects the Agreement remains in effect.
Any ambiguity in this BAA will be resolved in favour of a meaning that permits the Parties
to comply with HIPAA.
## 17. Regulatory References
A reference in this BAA to a section of HIPAA means that section as in effect or as
amended, and for which compliance is required.
## 18. Notices
Notices to Business Associate go to:
> Vince Systems LLC
> 3930 Westwind Ct, Waukee, IA 50263
> vince@vincesystems.com
Notices to Covered Entity go to the address and email held on its account, which Covered
Entity is responsible for keeping current.
## 19. Amendments and Waiver
This BAA may not be amended except in writing. The Parties agree to take such action as
is necessary to amend this BAA from time to time as is necessary for the Parties to comply
with HIPAA.
No failure or delay in exercising a right under this BAA operates as a waiver of it.
## 20. HITECH Act Compliance
Business Associate acknowledges that it is directly subject to those provisions of the
HITECH Act and the HIPAA Security and Privacy Rules that apply to business associates,
and agrees to comply with them.
---
This agreement is governed by the laws of the State of Iowa.
Accepted electronically by the person named at acceptance, on behalf of Covered Entity,
who represents that they are authorised to bind it. The version accepted, the full text
shown, a SHA-256 hash of that text, the acceptor's name, title and email, the IP address
and the time of acceptance are recorded by Business Associate.