HIPAA & Compliance

Business Associate Agreement
& HIPAA Compliance

Healthcare Data Integration — Protected Health Information safeguards governing PatientXpress’s dental practice management system integrations.

Compliance Standard
HIPAA • HITECH • ARRA
Governing Law
Delaware & Federal HIPAA
Need a Signed BAA?
Request BAA execution from our compliance team

PatientXpress is fully HIPAA compliant. All patient data is encrypted in transit and at rest. Business Associate Agreements (BAAs) are available for all dental practices upon request.

Request BAA →

This Business Associate Agreement (“Agreement”) is entered into by and between the Covered Entity (the dental practice or healthcare organization), and PatientXpress (“Business Associate”) (collectively, the “Parties”). This Agreement governs all uses and disclosures of Protected Health Information (PHI) in connection with PatientXpress’s unified API services for dental practice management system and imaging platform integration.

WITNESSETH

WHEREAS, Covered Entity is a “covered entity” as defined in the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and as described in the Health Information Technology for Economic and Clinical Health Act (“HITECH”) provisions of the American Recovery and Reinvestment Act of 2009 (“ARRA”);

WHEREAS, Business Associate provides unified API services (the “Services”) for integration with dental practice management systems and X-ray/imaging platforms, the performance of which involves the creation, receipt, maintenance, or transmission of Protected Health Information as defined in 45 CFR 160.103 (“PHI”);

WHEREAS, HIPAA requires that Covered Entity enter into written agreements with its business associates in order to regulate the use and disclosure of protected health information; and

WHEREAS, Covered Entity and Business Associate agree to enter into this Agreement to meet applicable requirements under HIPAA.

NOW THEREFORE, for and in consideration of these premises and other good and valuable consideration, the Parties hereto acknowledge, covenant, and agree as follows:

1

Obligations of Business Associate

1.1 Permitted Uses and Disclosures of PHI

Business Associate shall use and disclose any PHI it may receive from Covered Entity only to perform the Services (including API integration with dental practice management systems and X-ray/imaging platforms) and carry out obligations under the Agreement, and in accordance with applicable federal and state laws, including HIPAA. Business Associate will use only the minimum necessary PHI and abide by Covered Entity’s policies relative to minimum use.

Business Associate may also use or disclose PHI for proper management and administration, data aggregation services related to health care operations, or to carry out legal responsibilities — only to the extent such disclosure is required by law or with reasonable assurances of confidentiality from the receiving party.

1.2 Safeguards

Business Associate shall implement and use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic protected health information, to reasonably and appropriately protect the confidentiality, integrity, and availability of the PHI and prevent unauthorized use or disclosure.

Encryption in Transit & At Rest
Secure API Authentication
Regular Security Audits
Comprehensive Audit Logging
Access Controls
Secure PHI Transmission

1.3 Reporting Disclosures of PHI

In the event Business Associate, its agents, employees, or contractors use or disclose PHI in violation of this Agreement, Business Associate shall report such use or disclosure to Covered Entity as soon as it becomes aware of such violation, including the circumstances surrounding the use or disclosure.

Breach Notification: Business Associate shall notify Covered Entity in the event of any breach of unsecured PHI, including the identity of affected individuals and all relevant information, within three (3) business days of becoming aware of such breach.

1.4 Mitigation of Harmful Effects

Business Associate shall establish procedures for mitigating harmful effects of any improper use or disclosure of PHI that Business Associate reports to Covered Entity.

1.5 Third Party Agreements

In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate shall require all subcontractors and agents — including dental practice management system vendors and imaging platform providers — that create, receive, maintain, transmit, use, or have access to PHI under this Agreement to agree in writing to adhere to the same restrictions and requirements applicable herein.

1.6 Access to Information

Within ten (10) business days of a request by Covered Entity, Business Associate shall make available PHI about an individual contained in a Designated Record Set (as defined in 45 C.F.R. 164.501). Any request for access made directly by an individual to Business Associate shall be forwarded to Covered Entity upon receipt.

1.7 Amendment of PHI

Business Associate agrees to make PHI in a Designated Record Set available for amendment and to incorporate any appropriate amendments at the direction of Covered Entity. Any request for amendment made directly by an individual to Business Associate shall be forwarded to Covered Entity, and no action shall be taken until directed by Covered Entity.

1.8 Accounting of Disclosures

Business Associate agrees to document disclosures of PHI and provide Covered Entity with an accounting of such disclosures as required by 45 CFR 164.528.

To the extent Business Associate maintains PHI in an electronic health record, Business Associate agrees to account for all disclosures for a period of at least three (3) years prior to the request, as required by HITECH.

1.9 Access to Books and Records

Business Associate agrees to make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the Department of Health and Human Services for purposes of determining HIPAA compliance.

1.10 Obligations under ARRA

Business Associate acknowledges that it is subject to the security and data breach provisions of HIPAA and agrees to abide thereby, including all privacy provisions set forth in Title XIII, Subtitle D of ARRA, including restrictions on marketing and sales of PHI and requirements relating to limited data sets and minimum necessary disclosures.

2

Obligations of Covered Entity

2.1 Notice of Privacy Practices

Covered Entity agrees to provide Business Associate with a copy of Covered Entity’s “Notice of Privacy Practices” required to be provided to individuals in accordance with 45 CFR 164.520, as well as any subsequent changes to such notice.

2.2 Changes to or Restrictions on Use or Disclosure of PHI

Covered Entity will provide Business Associate with any changes to, or revocation of, permission to use or disclose PHI if such changes affect Business Associate’s permitted or required uses or disclosures, and any restriction requested by an individual that Covered Entity is required to comply with under HITECH.

2.3 Requested Uses or Disclosures of PHI

Covered Entity shall not request Business Associate to use or disclose PHI in any manner inconsistent with state or federal law.

3

Term and Termination

3.1 Term

This Agreement shall be deemed effective on the Effective Date and shall continue in effect until all obligations of the Parties have been met, unless otherwise terminated under the terms and conditions set forth herein.

3.2 Termination for Cause

Upon Covered Entity’s knowledge of a material breach of this Agreement by Business Associate, this Agreement and any underlying services agreement may be immediately terminated by Covered Entity as provided under 45 CFR 164.504(e)(2)(iii). Covered Entity may choose to provide written notice and permit Business Associate to cure the breach upon mutually agreeable terms before termination.

In the event Covered Entity violates its obligations under HIPAA in a manner related to this Agreement, Business Associate shall provide Covered Entity with notice of such breach; if Covered Entity does not cure within a reasonable period, Business Associate may terminate this Agreement.

3.3 Effect of Termination

Upon termination, Business Associate shall return or destroy all PHI created or received by Business Associate, its agents, and subcontractors to the extent feasible, without retaining any copies.

If return or destruction of PHI is not reasonably feasible, Business Associate agrees to extend the protections of this Agreement and limit further uses and disclosures. These obligations survive termination of this Agreement.

4

Miscellaneous Provisions

4.1 Definitions and Interpretation; Indemnification

All words used herein but not defined shall have the meanings set out in HIPAA. This Agreement shall be interpreted to cause the parties to be in compliance with HIPAA. Covered Entity and Business Associate agree to indemnify, defend, and hold harmless each other and each other’s respective employees, directors, officers, subcontractors, and agents against all actual and direct losses and all liability to third parties arising from or in connection with any breach of this Agreement or any negligence or wrongful acts, including failure to perform obligations under HIPAA. Accordingly, on demand, the indemnifying party shall reimburse any indemnified party for any and all actual and direct losses, liabilities, fines, penalties, costs, or expenses (including reasonable attorneys’ fees). The provisions of this paragraph survive the expiration or termination of this Agreement.

4.2 Assignment

Neither party shall have the right to assign its rights or obligations under this Agreement without the prior written consent of the other party, and any such attempted assignment shall be void.

4.3 Amendment

This Agreement shall not be modified or amended except by a written document executed by each of the parties, and such written modification shall be attached hereto.

4.4 Waiver of Provisions

Any waiver of any terms and conditions of this Agreement must be in writing, signed by both Business Associate and Covered Entity. The waiver of any terms shall not be construed as a waiver of any other terms of the Agreement.

4.5 Parties In Interest; No Third-Party Beneficiaries

The terms and conditions of this Agreement shall inure to the benefit of and be binding upon the respective heirs, legal representatives, successors, and permitted assigns of the parties. Neither this Agreement nor any other agreement contemplated herein shall be deemed to confer upon any person not a party to this Agreement any rights or remedies contained herein.

4.6 Governing Law

This Agreement and the entire relationship between the parties shall be governed by and construed in accordance with the substantive laws of the State of Delaware (but not the rules governing conflicts of laws) and with HIPAA.

4.7 Notice

Whenever this Agreement requires or permits any notice, request, or demand, the notice must be in writing to be effective and shall be deemed delivered: (i) if personally delivered or delivered by facsimile or courier — when actually received; or (ii) if delivered by mail — at the close of business on the third business day next following the day when placed in the mail, postage prepaid, certified or registered, addressed to the appropriate party.

Questions About This Agreement?

For questions regarding this Business Associate Agreement or to request execution of this agreement, please contact our compliance team.

patientxpress.us  •  +1 (949) 542-6773  •  30021 Alicia Pkwy, Laguna Niguel, CA 92677