HIPAA Business Associate Agreement
THIS PAGE SETS OUT THE FORM OF AGREEMENT WE OFFER. IT IS NOT SELF-EXECUTING AND IS NOT IN FORCE BETWEEN YOU AND INTELLIGENA LLC UNLESS AND UNTIL IT HAS BEEN EXECUTED IN WRITING BY BOTH PARTIES. UNTIL THEN YOU MUST NOT UPLOAD, ENTER OR TRANSMIT PROTECTED HEALTH INFORMATION THROUGH THE SERVICE.
To request execution, write to legal@intelligena.com with your legal entity name and the account it applies to. There is no charge for it.
1. Parties and definitions
This Business Associate Agreement (“BAA”) is between you (“Covered Entity”) and Intelligena LLC, a California limited liability company (“Business Associate”), and supplements the Terms of Service.
Terms used but not defined here have the meaning given in the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164 (together, “HIPAA”). “PHI” means Protected Health Information that Business Associate creates, receives, maintains or transmits on Covered Entity’s behalf. “Security Incident” has the meaning given in 45 C.F.R. §164.304.
2. Business Associate’s obligations
Business Associate will:
- Not use or disclose PHI other than as this BAA permits, as the Covered Entity directs, or as required by law — and in no case in a way that would violate the Privacy Rule if done by Covered Entity itself.
- Implement safeguards. Use appropriate administrative, physical and technical safeguards, comply with the Security Rule (45 C.F.R. Part 164 Subpart C) with respect to electronic PHI, and maintain the specific controls set out in Section 3.
- Report. Report to Covered Entity any use or disclosure not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI, in each case without unreasonable delay and no later than seventy-two (72) hours after discovery, on the terms set out in Section 5. Unsuccessful attempts that do not result in unauthorised access — pings, port scans, blocked login attempts and the like — are reported on request in aggregate rather than individually.
- Flow down. Ensure that each subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this BAA, including the data residency requirement in Section 4.
- Access. Make PHI in a Designated Record Set available to Covered Entity, or at its direction to the individual, so that Covered Entity can meet §164.524, within ten (10) calendar days of a written request. Where Covered Entity notifies Business Associate that a shorter period applies to it under state law, Business Associate will meet that period.
- Amendment. Make amendments to PHI in a Designated Record Set as Covered Entity directs under §164.526, within fifteen (15) calendar days of a written request.
- Accounting. Document and make available, within fifteen (15) calendar days of a written request, the information needed for Covered Entity to respond to a request for an accounting of disclosures under §164.528.
- Books and records. Make its internal practices, books and records relating to PHI available to the Secretary of Health and Human Services for determining Covered Entity’s compliance, and notify Covered Entity of any such request unless legally prohibited from doing so.
- Minimum necessary. Request, use and disclose only the minimum amount of PHI necessary.
- Mitigate. Mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure in violation of this BAA.
3. Security commitments, and your right to verify them
Business Associate maintains the administrative, technical and physical controls set out in the Security Practices document, which is incorporated into this BAA by reference and forms part of it. Business Associate will not materially reduce the protection those controls provide during the term of this BAA without Covered Entity’s prior written agreement.
- Assessment. Business Associate will complete a reasonable security questionnaire, and provide a summary of its most recent vulnerability assessment or penetration test where one has been carried out, once in any twelve-month period on written request. Covered Entity may treat this as its vendor-risk due diligence.
- Audit. Where Covered Entity is required by a regulator, an auditor or applicable law to inspect Business Associate’s controls, Business Associate will cooperate with that inspection at reasonable times and on reasonable notice, subject to confidentiality and to the protection of other customers’ data.
- Remediation. Business Associate will remediate confirmed vulnerabilities in accordance with the timelines stated in the Security Practices document.
- What is not represented. Business Associate has not obtained a SOC 2, HITRUST or ISO 27001 attestation, and this Section is not a representation that it has. The Security Practices document says so plainly, and stating it here as well is deliberate: a security exhibit read alone is where a buyer forms that impression.
4. Data residency
Business Associate will store PHI, and every copy of it, only within the United States and its territories. This obligation extends to the primary store and to every backup, archive, replica, cache, index, log and disaster-recovery copy, whether held by Business Associate or by any subcontracted hosting, storage, content-delivery or network facility — the data centre in which any such copy rests must be located within the United States and its territories.
Business Associate will not permit PHI to be physically maintained outside the United States and its territories. Where a network or edge service is used for routing, transport security or denial-of-service protection, it is configured so that PHI is not stored, copied or cached outside that region. Personnel located elsewhere may access PHI only where Covered Entity has agreed in writing and the access is subject to the controls in Section 3; access from outside the region is not storage within the meaning of this Section.
This Section exists because Texas Senate Bill 1188 (2025), whose storage requirement applies to electronic health records stored on or after 1 January 2026, requires an electronic health record under a covered entity’s control to be physically maintained in the United States or a United States territory, including where it is held by a third-party or subcontracted computing facility. Our Subprocessors page describes where each category of subprocessor operates; that page is a notice we may update, and this Section is the commitment.
5. Breach response, cooperation and costs
- The report. A report under Section 2.3 will be made without unreasonable delay and no later than seventy-two (72) hours after discovery, and will contain the information 45 C.F.R. §164.410(c) requires so far as it is then known: the individuals whose PHI was or is reasonably believed to have been involved, what happened, when it happened and when it was discovered, the nature of the information involved, and what Business Associate has done and is doing about it. An incomplete report is made on time and supplemented; it is not withheld until it is complete, because the covered entity’s own 60-day clock under §164.404 runs from discovery either way.
- Cooperation. Business Associate will cooperate in good faith with Covered Entity’s investigation, will make knowledgeable personnel reasonably available to it, and will provide the relevant forensic findings, log extracts and timeline it holds — subject to legal privilege, to any instruction of a law-enforcement agency, and to the protection of other customers’ data.
- Regulators. Business Associate will cooperate with any inquiry from the Secretary of Health and Human Services, the Office for Civil Rights, a State Attorney General or any other regulator with authority over the incident, and will provide Covered Entity with the information it needs to meet its own state and federal notification duties — including those under Texas Business and Commerce Code §521.053 and Texas Health and Safety Code Chapter 181, which run to their own deadlines and their own recipients.
- Notification. Covered Entity decides whether and how individuals are notified; Business Associate will not notify Covered Entity’s individuals directly without its written agreement, except where separately required by law to do so. Where the Breach was caused by Business Associate’s breach of this BAA, Business Associate will bear the reasonable and documented costs of the individual notifications, of the substitute and media notices HIPAA requires, and of credit monitoring where applicable law or the circumstances reasonably require it, subject to Section 11.2.
- No admission. A report made under this Section is not an admission of fault by either party.
6. Permitted uses and disclosures
Business Associate may use and disclose PHI only to perform the Service, and additionally may use PHI for its own proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes where the disclosure is required by law or where it obtains reasonable assurances from the recipient that the PHI will be kept confidential, used or further disclosed only as required by law or for the purpose it was provided, and that the recipient will notify Business Associate of any breach of confidentiality.
Business Associate may de-identify PHI in accordance with 45 C.F.R. §164.514(b) and use the resulting de-identified data for any lawful purpose; de-identified data is not PHI. Business Associate will not use PHI to train any machine-learning model, and will not permit any subcontractor to do so.
7. Covered Entity’s obligations
Covered Entity will:
- obtain every consent, authorisation and permission necessary for Business Associate to process PHI as contemplated;
- maintain and, where required, provide its own Notice of Privacy Practices, and notify Business Associate of any limitation in it, of any change or revocation of an individual’s permission, and of any restriction agreed under §164.522, in each case to the extent it affects Business Associate’s use or disclosure;
- not request Business Associate to use or disclose PHI in any way that would not be permitted if done by Covered Entity;
- tell Business Associate if it is a Part 2 program, if it holds records subject to a state mental-health or substance-use confidentiality statute, or if any state law imposes a shorter period than this BAA states — Business Associate cannot know any of those from the data itself; and
- configure and use the Service appropriately, and be solely responsible for its own HIPAA compliance, its own risk analysis, its own workforce training, and the acts of its own workforce.
8. State law — Texas
Where Covered Entity is a covered entity within the meaning of Texas Health and Safety Code Chapter 181 (House Bill 300), or holds the records of a Texas patient, the following apply in addition to everything above. They are stated because Chapter 181 defines “covered entity” far more broadly than HIPAA does — it reaches any person who assembles, collects, analyses, uses, evaluates, stores or transmits protected health information — so Business Associate is itself within its scope.
- Storage. Section 4 above satisfies the requirement, in force from 1 January 2026, that an electronic health record be physically maintained in the United States or a United States territory.
- Access control. Business Associate limits access to electronic health record information to those personnel who require it to perform duties related to treatment, payment or health care operations, and records every access to PHI in an append-only audit log.
- Parental and guardian access. The Service makes a minor’s complete record available to Covered Entity so that it can give a parent, conservator or guardian full and immediate access where the law requires it. Whether a particular person is entitled to that access, and whether it is limited by law or by court order, is Covered Entity’s decision and not Business Associate’s — Business Associate holds no custody order and cannot make it.
- Training. Chapter 181 requires Covered Entity to train its own workforce on state and federal health-privacy law. Business Associate trains its own personnel and does not discharge that duty for Covered Entity; see the Terms of Service, section on training and continuing education.
- Notification. Section 5.3 covers cooperation with the Texas Attorney General and with the notification duties in Texas Business and Commerce Code §521.053.
- Artificial intelligence. Where Covered Entity uses an AI feature of the Service in connection with diagnosis or treatment, Covered Entity is responsible for reviewing the output and for informing the patient that an AI tool was used. The Service records where AI-assisted content was generated so that Covered Entity can identify it.
Other states impose their own requirements and this Section does not attempt to list them. Where a state law that applies to Covered Entity is more protective of an individual than this BAA, that law governs, and Business Associate will on request execute an addendum stating what it requires of us.
9. Substance use disorder records — 42 C.F.R. Part 2
Records of the identity, diagnosis, prognosis or treatment of a patient of a federally assisted substance use disorder program are protected by 42 U.S.C. §290dd-2 and 42 C.F.R. Part 2, whose amendments became enforceable on 16 February 2026. Part 2 is not satisfied by a Business Associate Agreement. It requires a Qualified Service Organization Agreement, and a business associate that is not a qualified service organization has no lawful basis to receive Part 2 records at all.
- The undertaking. Where Covered Entity is a Part 2 program, or holds Part 2 records, and has told Business Associate so under Section 7, Business Associate acknowledges that in receiving those records it is fully bound by 42 C.F.R. Part 2, and it undertakes to resist in judicial proceedings any effort to obtain access to records referring to a patient except as Part 2 expressly provides. This paragraph, together with the description of the Service in the Terms, is intended to constitute a Qualified Service Organization Agreement.
- Redisclosure. Business Associate will not redisclose Part 2 records except as Part 2 permits, and will include the prohibition-on-redisclosure notice Part 2 requires with any permitted disclosure it makes.
- Segregation is Covered Entity’s. Business Associate cannot tell a Part 2 record from any other clinical record by looking at it. Identifying them, and configuring the Service accordingly, is Covered Entity’s responsibility.
- State mental-health statutes stack on top. Several states protect psychotherapy and mental-health records more strictly than either HIPAA or Part 2, and those laws are not displaced by this BAA.
10. Term and termination
This BAA takes effect on execution and continues until all PHI is returned or destroyed or, if return or destruction is infeasible, until the protections here are extended to it indefinitely. Covered Entity may terminate this BAA and the Service immediately if Business Associate materially breaches it and fails to cure the breach within thirty (30) days of written notice.
On termination, Business Associate will return or destroy all PHI it still holds, including copies held by subcontractors, where feasible. Where it is not feasible — including PHI in routine encrypted backups pending scheduled overwriting — Business Associate will extend the protections of this BAA to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible, for as long as it retains it.
Before PHI is returned or destroyed, Covered Entity may export it. The export right in the Terms of Service applies to PHI in the same way as to any other of Your Content, and this Section does not shorten it.
11. General
- Interpretation. Any ambiguity is resolved to permit compliance with HIPAA. Amendments to HIPAA that change the parties’ obligations apply automatically, and the parties will execute any amendment reasonably necessary.
- Precedence and limits. Where this BAA conflicts with the Terms of Service, this BAA controls with respect to PHI, and only with respect to PHI. The warranty disclaimer, no-personal-liability provision, indemnity, dispute-resolution provision and governing law in the Terms of Service apply to this BAA. The limitation of liability in the Terms of Service applies to this BAA as enhanced by the security-incident cap in that document, which is the figure that applies to a claim arising out of a Breach of Unsecured PHI.
- The cap does not bind a regulator. The limitation of liability is an agreement between Covered Entity and Business Associate. It does not bind, limit or affect the U.S. Department of Health and Human Services, its Office for Civil Rights, any State Attorney General, or any other regulator, none of which is a party to it. A civil money penalty or other enforcement action brought by any of them against either party is unaffected by anything in this BAA or in the Terms of Service, and neither party can contract out of it.
- No third-party beneficiaries. Nothing in this BAA confers any right on any individual or other third party, including any right to enforce it. This does not limit paragraph 3 above, which describes what the parties cannot do rather than granting anyone a right.
- Governing law. The laws of the State of California, with disputes resolved as the Terms of Service provide.
How to reach us
- General and legal
- legal@intelligena.com
- Privacy requests
- privacy@intelligena.com
- Copyright / DMCA
- dmca@intelligena.com
- Abuse reports
- abusereport@intelligena.com
- Support
- support@practiceful.com
- Telephone
- (619) 335-8730
Notices in writing
Any notice this agreement requires to be given in writing may be sent to:
Intelligena LLC3400 Cottage Way Ste G2
Sacramento CA 95825
United States of America