Terms of Service Privacy Policy Business Associate Agreement
DRAFT — under legal review. This document is provided for preview and will be finalized before commercial launch.

BUSINESS ASSOCIATE AGREEMENT — DRAFT

This Business Associate Agreement ("BAA") is entered into as of [DATE] ("Effective Date") between:

Together with the InfiniteApp Terms of Service (the "Underlying Agreement"), this BAA governs Business Associate's creation, receipt, maintenance, and transmission of Protected Health Information ("PHI") on behalf of Covered Entity under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including the Privacy, Security, and Breach Notification Rules at 45 C.F.R. Parts 160 and 164, as amended by the HITECH Act (collectively, "HIPAA").

1. Definitions

Capitalized terms used but not defined in this BAA have the meanings given in HIPAA. "PHI" means Protected Health Information received from, or created, received, maintained, or transmitted on behalf of, Covered Entity by Business Associate, and includes Electronic PHI ("ePHI").

2. Permitted Uses and Disclosures

Business Associate may use and disclose PHI only:

(a) to provide, maintain, support, and improve the InfiniteApp services described in the Underlying Agreement; (b) as required by law; (c) for the proper management and administration of Business Associate, provided any disclosure is required by law or made under reasonable written assurances of confidentiality and breach notification from the recipient; (d) to provide Data Aggregation services relating to the health care operations of Covered Entity, if permitted under the Underlying Agreement; and (e) to de-identify PHI in accordance with 45 C.F.R. § 164.514(b), after which such de-identified data is no longer PHI.

Business Associate shall not use or disclose PHI other than as permitted by this BAA or required by law, and shall not sell PHI or use or disclose PHI for marketing purposes prohibited by HIPAA.

3. Safeguards

Business Associate shall:

(a) implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI as required by the Security Rule, including access controls, encryption of ePHI in transit and at rest, audit logging, and workforce access limitation (role-based, least-privilege); (b) host PHI only with subcontractor infrastructure providers with whom a business associate agreement is in place (including Google LLC for Google Cloud services under Google's Cloud HIPAA Business Associate Addendum); (c) train its workforce with access to PHI on HIPAA obligations; and (d) mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this BAA.

4. Subcontractors

Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this BAA. Current infrastructure subcontractors are listed in Exhibit A.

5. Reporting

Business Associate shall report to Covered Entity:

(a) any use or disclosure of PHI not permitted by this BAA of which it becomes aware, without unreasonable delay; (b) any Security Incident of which it becomes aware, provided that this section constitutes notice of ongoing unsuccessful attempts (e.g., pings, port scans, denial-of-service without access) for which no further reporting is required; and (c) any Breach of Unsecured PHI without unreasonable delay and in no case later than [30/60] days after discovery, including, to the extent known, the identity of affected individuals and the information required by 45 C.F.R. § 164.410.

6. Individual Rights

To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall, within [15] business days of written request from Covered Entity: (a) make PHI available for access as required by § 164.524; (b) make PHI available for amendment and incorporate amendments as required by § 164.526; and (c) make available the information required for an accounting of disclosures under § 164.528. If an individual contacts Business Associate directly, Business Associate will forward the request to Covered Entity within [5] business days.

7. Availability of Books and Records

Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.

8. Term and Termination

(a) This BAA is effective as of the Effective Date and terminates when the Underlying Agreement terminates. (b) Covered Entity may terminate the Underlying Agreement for cause if Business Associate materially breaches this BAA and fails to cure within [30] days of written notice. (c) Upon termination, Business Associate shall, at Covered Entity's election, return or destroy all PHI, including PHI held by subcontractors. Covered Entity may export its data in machine-readable form through the platform's export feature before termination. If return or destruction is infeasible, Business Associate shall extend the protections of this BAA to the retained PHI and limit further uses and disclosures to the purposes making return infeasible.

9. Miscellaneous

(a) Nothing in this BAA creates rights in third parties. (b) Any ambiguity shall be interpreted to permit compliance with HIPAA. (c) This BAA amends and forms part of the Underlying Agreement; in case of conflict regarding PHI, this BAA controls. (d) Governing law: [STATE], excluding conflicts rules, except where preempted by federal law.

Covered Entity — Signature: __ Name/Title: __ Date: ______

Business Associate — Signature: __ Name/Title: __ Date: ______


Exhibit A — Infrastructure Subcontractors

Subcontractor Service Safeguard
Google LLC (Google Cloud) Cloud Firestore, Cloud Storage, Cloud Functions, Identity Platform (us-central1) Google Cloud HIPAA Business Associate Addendum, accepted [DATE]
© 2026 InfiniteApp. Questions: operations@infinitemedicalspa.com · System status