Business Associate Agreement
Last updated: July 29, 2026
This Business Associate Agreement (the "Agreement" or "BAA") is entered into between the clinical practice registering for or using the HootCare platform (the "Covered Entity" or "practice") and Hootcare Inc (the "Business Associate"), operator of HootCare (the "Services"). It takes effect on the date the practice's authorized representative accepts it electronically at sign-up (the "Effective Date"). In providing the Services, Business Associate may create, receive, maintain, or transmit Protected Health Information ("PHI") on behalf of Covered Entity, and the parties intend to comply with HIPAA, the HITECH Act, and the regulations at 45 CFR Parts 160 and 164 (the "HIPAA Rules").
1. Definitions
Capitalized terms used but not defined in this Agreement have the meanings given in the HIPAA Rules (including Breach, Designated Record Set, Disclosure, ePHI, Individual, Minimum Necessary, PHI, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured PHI, and Use). "Services" means the HootCare platform and related services Business Associate provides to Covered Entity under the HootCare Terms of Service (the "Underlying Agreement"). "Subprocessor List" means Business Associate's then-current list of Subcontractors that may create, receive, maintain, or transmit PHI, made available to Covered Entity and updated from time to time.
2. Permitted uses and disclosures of PHI
Business Associate may Use or Disclose PHI only as necessary to perform the Services, as permitted or required by this Agreement or the Underlying Agreement, or as Required By Law, and will make reasonable efforts to limit Use, Disclosure, and requests to the Minimum Necessary (45 CFR § 164.502(b)). Business Associate may Use PHI for its proper management and administration or to carry out its legal responsibilities, and may Disclose PHI for those purposes only if Required By Law or with reasonable assurances of confidentiality from the recipient. Business Associate may provide Data Aggregation services relating to Covered Entity's Health Care Operations and may de-identify PHI in accordance with 45 CFR § 164.514(a)–(c).
3. Prohibited uses and disclosures
Business Associate will not Use or Disclose PHI other than as permitted by this Agreement or Required By Law; will not sell PHI; will not Use or Disclose PHI for marketing or fundraising; and will not Use or Disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity (except as permitted under 45 CFR § 164.504(e)(2)(i)(A) for Business Associate's own management, administration, and Data Aggregation services).
4. Safeguards
Business Associate will implement and maintain reasonable and appropriate administrative, physical, and technical safeguards in accordance with the Security Rule (45 CFR §§ 164.308, 164.310, 164.312) protecting the confidentiality, integrity, and availability of ePHI, including: encryption in transit (TLS) and at rest; unique user identification, role-based access control, authentication, and automatic session logoff; append-only audit logging of access to ePHI; and workforce training and sanction policies. Business Associate will comply with the applicable requirements of the Security Rule as required by the HITECH Act.
5. Subcontractors
In accordance with 45 CFR §§ 164.308(b)(2) and 164.502(e)(1)(ii), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and safeguards at least as restrictive as those applying to Business Associate under this Agreement. Business Associate maintains a Subprocessor List and will provide notice of material changes.
6. Reporting of security incidents and breaches
Business Associate will report to Covered Entity any Security Incident of which it becomes aware (45 CFR § 164.314(a)(2)(i)(C)); this section constitutes notice of routine unsuccessful attempts (pings, port scans, failed logins) that do not result in unauthorized access. Business Associate will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay and no later than sixty (60) calendar days after Discovery (45 CFR § 164.410), including the information specified in § 164.410(c), and will reasonably cooperate with Covered Entity's investigation and required notifications. Notices to Business Associate go to support@hootcare.io.
7. Individual rights — access, amendment, accounting
Business Associate will make PHI in a Designated Record Set available to Covered Entity (or, as directed, to the Individual) for access under 45 CFR § 164.524; will make PHI available for amendment and incorporate amendments as directed under § 164.526; will document and make available the information required for an accounting of Disclosures under § 164.528; and will forward to Covered Entity any such request made directly to Business Associate. To the extent Business Associate carries out a Covered Entity obligation under the Privacy Rule, it will comply with the requirements that apply to Covered Entity in performing it.
8. Access to records by the Secretary
Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules.
9. Return or destruction of PHI on termination
Upon termination, Business Associate will, if feasible, return or destroy all PHI it still maintains and retain no copies. If return or destruction is not feasible, Business Associate will extend the protections of this Agreement to the retained PHI and limit further Uses and Disclosures to the purposes that make return or destruction infeasible. These obligations flow down to Subcontractors that maintain PHI.
10. Term and termination
This Agreement is effective as of the Effective Date and remains in effect until all PHI is returned or destroyed, or until terminated. If either party knows of a pattern of activity of the other that constitutes a material breach of this Agreement, it will provide written notice and a thirty (30) day opportunity to cure; failing cure, the non-breaching party may terminate this Agreement and, where applicable, the Underlying Agreement, or report the violation to the Secretary if termination is not feasible. Section 9 survives termination.
11. Miscellaneous
The HITECH Act provisions applicable to Business Associates are incorporated into this Agreement. References to the HIPAA Rules mean those sections as amended from time to time. The parties will amend this Agreement as necessary for compliance with the HIPAA Rules. Ambiguities will be resolved to permit compliance with the HIPAA Rules, and in a conflict between this Agreement and the Underlying Agreement regarding PHI, this Agreement controls. There are no third-party beneficiaries. This Agreement is governed by the laws of the State of Delaware, except to the extent preempted by federal law.
12. Electronic acceptance
This Agreement is executed electronically: by checking the acceptance box at sign-up, the person accepting represents that they are authorized to bind the practice being registered, and the practice and Hootcare Inc agree to this Agreement as of that date. The acceptance (including its date, the accepting user, and the version accepted) is recorded by the Service and constitutes a signed writing to the maximum extent permitted by law (including the federal ESIGN Act and state UETA equivalents).
Contact
Questions about this Agreement: Hootcare Inc — support@hootcare.io.