Hiive Health Business Associate Agreement
Version 1.0 | Effective Date: August 24, 2026 | Supersedes: None
Hosted at: https://www.hiivehealth.com/legal/baa
This Business Associate Agreement (this “BAA”) applies to the customer identified in a Quote that references this BAA (“Customer”) and ViiNetwork, Inc. d/b/a Hiive Health, a Delaware corporation (“Business Associate”). It governs the Parties’ obligations with respect to Protected Health Information in connection with Business Associate’s provision of the Services and is incorporated into and forms part of the Agreement. Customer accepts this BAA in the same manner it accepts the Hiive Health subscription terms — by executing a Quote that references this BAA or by accessing or using the Services — unless the Parties execute a separate business associate agreement under Section 7.p.
Business Associate and Customer hereby agree as follows:
1. Definitions
a. “HIPAA” means Title II, Subtitle F, “Administrative Simplification,” of the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, as amended by the Health Information Technology for Economic and Clinical Health Act which consists of Division A Title XIII and Division B Title IV of the American Recovery and Reinvestment Act of 2009, Public Law 111-5, and any future amendments or regulations promulgated by HHS, including but not limited to the 2024 HIPAA Privacy Rule modifications.
b. “HIPAA Regulations” means the regulations promulgated under HIPAA by the United States Department of Health and Human Services, including, but not limited to, 45 C.F.R. Part 160 and 45 C.F.R. Part 164, as amended by the HIPAA Omnibus Rule.
c. “HIPAA Omnibus Rule” means the final rule entitled “Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules” promulgated at 78 Fed. Reg. 5,566 et seq. (January 25, 2013).
d. “Agreement” means the Hiive Health subscription terms and the Quote under which the Services are provided, into which this BAA is incorporated.
e. “Quote” means the ordering document that references this BAA and identifies Customer and Customer’s status under HIPAA (Covered Entity or Business Associate).
f. “Services” means the Hiive ePA Platform and any other Hiive Health products or services identified in the Quote.
g. Any other terms used, but not otherwise defined, in this BAA shall have the same meanings as those terms have under HIPAA and the HIPAA Regulations (as applicable).
2. Status of Parties
a. General. Business Associate acknowledges and agrees that it is a business associate of Customer under HIPAA and the HIPAA Regulations, and that Customer is either a covered entity or a business associate under HIPAA and the HIPAA Regulations, as identified on the Quote. Customer is responsible for accurately identifying its status.
b. Customer as Covered Entity. Where Customer is a covered entity, Business Associate is a business associate of Customer, and references in this BAA to “Covered Entity” mean Customer.
c. Customer as Business Associate (Subcontractor). Where Customer is itself a business associate, Business Associate acts as Customer’s subcontractor, and this BAA constitutes the written agreement required of Customer under 45 C.F.R. §§ 164.502(e)(1)(ii), 164.504(e)(1)(iii), and 164.314(a)(2)(iii). In that case: (i) Business Associate’s obligations under this BAA are no less stringent than the obligations that apply to Customer under Customer’s agreement with its upstream covered entity or business associate; (ii) references in this BAA to “Covered Entity” mean Customer and, where the context concerns the individual or the ultimate covered entity, the applicable upstream covered entity, and obligations owed to the Covered Entity are owed to and enforceable by Customer; and (iii) Business Associate will comply with any additional or more-restrictive obligations set out in Customer’s upstream business associate agreement to the extent Customer provides those obligations to Business Associate in writing, they are consistent with the HIPAA Regulations, and they do not conflict with the Agreement.
3. Obligations and Activities of Business Associate
a. Use or Disclosure. Business Associate agrees to not use or further disclose Protected Health Information (as such term is defined at 45 C.F.R. § 160.103) created, received, maintained, or transmitted by Business Associate from, or on behalf of Covered Entity (“PHI”) other than as expressly permitted or required by this BAA or as required by law.
b. Safeguards. Business Associate agrees to use appropriate administrative, physical, and technical safeguards to (i) prevent any use or disclosure of PHI other than uses and disclosures expressly provided for by this BAA, and (ii) protect the confidentiality, integrity, and availability of any PHI. Notwithstanding the generality of the foregoing, Business Associate agrees to comply with each of the Standards and Implementation Specifications of 45 C.F.R. §§ 164.308 (Administrative Safeguards), 164.310 (Physical Safeguards), 164.312 (Technical Safeguards), 164.314 (Organizational Requirements), and 164.316 (Policies and Procedures and Documentation Requirements) with respect to Electronic PHI that it creates, receives, maintains, or transmits on behalf of Covered Entity.
c. Mitigation. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this BAA.
d. Reporting. Business Associate agrees to report to Covered Entity any use or disclosure of PHI in violation of this BAA as soon as reasonably practicable, including Breaches in accordance with the terms of Section 3.l of this BAA. For clarity, discovery shall include awareness by any employee, agent, or subcontractor of Business Associate. Business Associate also agrees to report to Covered Entity as soon as reasonably practicable any Security Incident involving Electronic PHI of which Business Associate becomes aware.
e. Subcontractors and Agents. In accordance with 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, Business Associate agrees to ensure that any agent, including a subcontractor, that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees, in writing, to the same restrictions, conditions, and requirements that apply through this BAA to Business Associate with respect to such information. Business Associate shall maintain documentation of such compliance and make it available to Covered Entity upon request.
f. Requests for Restrictions. Business Associate agrees to comply with requests for restrictions on use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. §164.522, to the extent that such restriction may affect Business Associate’s use or disclosure of such PHI.
g. Access to PHI. When requested by Covered Entity, Business Associate agrees to provide access to PHI in a designated record set to Covered Entity or to an individual in order to comply with the requirements under 45 C.F.R. § 164.524 and the policies of Covered Entity. Such access shall be provided by Business Associate in the time and manner designated by Covered Entity. In the event any individual requests access to PHI directly from Business Associate, Business Associate shall forward such request to Covered Entity in the time and manner reasonably designated by Covered Entity such that Covered Entity can respond to such individual in accordance with 45 C.F.R. § 164.524. Any denials of access to the PHI requested shall be the responsibility of Covered Entity.
h. Amendment to PHI. When requested by Covered Entity or an individual, Business Associate agrees to make any amendment(s) to PHI in a designated record set that Covered Entity directs or agrees to pursuant to 45 C.F.R. § 164.526 and the policies of Covered Entity. Such amendments shall be made by Business Associate in the time and manner designated by Covered Entity.
i. Audit and Inspection. Business Associate agrees to make internal practices, books, and records relating to the use and disclosure of PHI and the security of Electronic PHI available to Covered Entity, and to the Secretary of the U.S. Department of Health and Human Services (“HHS”) or any officer or employee of HHS to whom the Secretary of HHS has delegated such authority, for the purposes of the Secretary of HHS determining Covered Entity’s compliance with the HIPAA Regulations. Such information shall be made available in a time and manner designated by Covered Entity or the Secretary of HHS.
j. Documentation of Disclosures. Business Associate agrees to document such disclosures of PHI and any information related to such disclosures as would be required for Covered Entity to respond to a request by an individual for an accounting of disclosures of PHI in accordance with 45 C.F.R. § 164.528 and the policies of Covered Entity.
k. Accounting of Disclosures. Business Associate agrees to provide to Covered Entity or an individual information collected in accordance with Section 3.j of this BAA, to permit Covered Entity to respond to a request by an individual for an accounting of disclosures of PHI in accordance with 45 C.F.R. § 164.528 and the policies of Covered Entity. Such information shall be provided in a time and manner designated by Covered Entity.
l. Breaches. Business Associate shall notify Covered Entity of any Breach or potential Breach.
(1) Timeliness of Notification. Business Associate shall provide the notification to Covered Entity without unreasonable delay and in no case later than five (5) business days after Business Associate discovers the Breach or potential Breach.
(2) Content of Notification. The notification shall include, to the extent possible, the identification of each individual whose Unsecured PHI has been, or is reasonably believed by Business Associate to have been, accessed, acquired, used, or disclosed during the Breach. Business Associate shall provide Covered Entity, at the time of the notification or promptly thereafter as information becomes available, with any other available information that Covered Entity is required to include in notification to the individual under the HIPAA Regulations.
m. Prohibition on Sale of PHI. Business Associate agrees to comply with the prohibition of sale of PHI without authorization unless an exception under 45 C.F.R. § 164.508 applies.
n. Compliance with Covered Entity’s Obligations. To the extent that Business Associate carries out one or more of Covered Entity’s obligations under the HIPAA Regulations, Business Associate shall comply with the requirements of the HIPAA Regulations that apply to Covered Entity in the performance of such obligations.
o. Application of Knowledge Elements Associated with Contracts. 45 C.F.R. § 164.504(e)(1)(ii) shall apply to the Business Associate described in subsection (a) in the same manner that it applies to the Covered Entity, with respect to compliance with the standards in 45 C.F.R. §§ 164.502(e) and 164.504(e), except that in applying 45 C.F.R. § 164.504(e)(1)(ii) each reference to the Business Associate shall be treated as a reference to the Covered Entity. Accordingly, as required by HIPAA, if the Business Associate knows of a pattern of activity or practice by Covered Entity that breaches this BAA, but Business Associate fails to require Covered Entity to cure the breach, terminate this BAA, or report the non-compliance to HHS, then Business Associate will be deemed in violation of the HIPAA Regulations.
4. Permitted Uses and Disclosures by Business Associate
a. General Use and Disclosure Provisions. Except as otherwise permitted or required by this BAA, Business Associate may use or disclose PHI on behalf of, or to provide services to, Covered Entity in connection with the performance of the services provided under the Agreement, if such use or disclosure of PHI would not violate HIPAA or the HIPAA Regulations if done by Covered Entity or such use or disclosure is expressly permitted under Section 4.b of this BAA.
b. Specific Use and Disclosure Provisions.
(1) Except as otherwise permitted or required by this BAA, Business Associate may use and disclose PHI for its proper management or administration purposes or to meet its legal responsibilities only if such use or disclosure is in compliance with all applicable requirements of 45 C.F.R. § 164.504(e).
(2) Business Associate may use and disclose PHI to report violations of law to appropriate Federal and State authorities, consistent with 45 C.F.R. § 164.502(j)(1).
c. Business Associate may only use and disclose PHI in accordance with the Minimum Necessary Standard under HIPAA and the HIPAA Regulations to the extent that such standard would apply if the activities performed by Business Associate pursuant to this BAA were performed by Covered Entity. Business Associate will develop and implement policies and procedures as necessary to comply with this Section 4.c.
d. Business Associate may de-identify PHI in accordance with 45 C.F.R. §164.514(b) solely for analytics or reporting, if authorized by Covered Entity.
5. Obligations of Covered Entity
Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Regulations if done by Covered Entity or that is not otherwise expressly permitted under Section 4 of this BAA.
6. Term and Termination
a. Term. This BAA is effective as to Customer on the effective date of the Agreement and shall continue unless or until this BAA is terminated in accordance with the provisions of Section 6.b or 7.b hereof or the Agreement between the parties terminates. Each version of this BAA is identified by its effective date; superseded versions are retained and available on request.
b. Termination for Cause. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity may, in its sole discretion, either (1) provide Business Associate with an opportunity to cure the breach and then terminate this BAA upon written notice to Business Associate if Business Associate does not cure the breach within the time period specified by Covered Entity or (2) terminate this BAA and the Agreement immediately upon written notice to Business Associate.
c. Effect of Termination.
(1) Upon termination of this BAA, for any reason, Business Associate shall return or destroy all PHI. This provision shall also apply to PHI that is in the possession of subcontractors or agents of Business Associate. Business Associate shall retain no copies of PHI.
(2) Notwithstanding the foregoing, in the event that Business Associate determines that returning or destroying the PHI is not feasible, Business Associate shall provide to Covered Entity notification of the conditions that make return or destruction not feasible. Upon mutual agreement of the parties that return or destruction of such PHI is not feasible, Business Associate shall extend the protections of this BAA to such PHI to those purposes that make the return or destruction not feasible, for so long as Business Associate maintains such PHI.
7. Miscellaneous
a. Regulatory References. A reference in this BAA to a section in HIPAA or the HIPAA Regulations means the section as in effect or as amended, and for which compliance is required, except that any standards or implementation specifications described herein that have been added or modified by the HIPAA Omnibus Rule shall have a compliance date of September 23, 2013.
b. Amendment. Covered Entity and Business Associate agree that amendment of this BAA may be required to ensure that Covered Entity and Business Associate comply with changes in state and federal laws and regulations relating to the privacy, security and confidentiality of PHI. Covered Entity may terminate this BAA and the Agreement upon thirty (30) days written notice in the event that Business Associate does not promptly enter into an amendment that Covered Entity, in its sole discretion, deems sufficient to ensure that Covered Entity will be able to comply with such laws and regulations. Business Associate may update the hosted version of this BAA to reflect changes in law in accordance with the change-of-terms process in the Agreement.
c. Survival. The respective rights and obligations of Covered Entity and Business Associate under Sections 6.c., 7.f., 7.g., and 7.j. of this BAA shall survive the termination of this BAA.
d. Interpretation. Any ambiguity in this BAA shall be resolved in favor of a meaning that permits Covered Entity to comply with applicable law protecting the privacy, security and confidentiality of PHI, including, but not limited to, HIPAA and the HIPAA Regulations.
e. State Law. Nothing in this BAA shall be construed to require Business Associate to use or disclose PHI without a written authorization from an individual who is a subject of the PHI, or written authorization from any other person, where such authorization would be required under state law for such use or disclosure. Business Associate shall also comply with applicable state privacy laws governing health or personal data, including but not limited to the California Privacy Rights Act and Washington My Health My Data Act.
f. Injunctions. Covered Entity and Business Associate agree that any violation of the provisions of this BAA may cause irreparable harm to Covered Entity. Accordingly, in addition to any other remedies available to Covered Entity at law, in equity, or under this BAA, Covered Entity shall be entitled to an injunction or other decree of specific performance with respect to any violation of this BAA or explicit threat thereof, without any bond or other security being required and without the necessity of demonstrating actual damages.
g. Indemnification. Business Associate shall indemnify, hold harmless and defend Covered Entity, and all of its officers, trustees, employees, agents, students, volunteers, and medical staff members, from and against any and all claims, losses, liabilities, costs and other expenses (including, but not limited to, reasonable attorneys’ fees) arising from or relating to (i) any negligent act or omission, or willful misconduct, of Business Associate in connection with this BAA, (ii) any breach by Business Associate of any of its representations, duties and obligations under this BAA, or (iii) any violation by Business Associate of HIPAA or the HIPAA Regulations.
h. No Third Party Beneficiaries. Nothing express or implied in this BAA is intended or shall be deemed to confer upon any person other than Covered Entity, Business Associate, and their respective successors and assigns, any rights, obligations, remedies or liabilities.
i. Primacy. To the extent that any provisions of this BAA conflict with the provisions of any other agreement or understanding between the parties (including but not limited to the Agreement), this BAA shall control with respect to the subject matter of this BAA.
j. Applicable Law; Jurisdiction and Venue. This BAA will be governed by and construed in accordance with the substantive laws of the United States of America and the State of Delaware. For the purposes of this BAA, each party hereby irrevocably, unconditionally and exclusively submits to the jurisdiction of the United States federal courts for Delaware and of the state courts of the State of Delaware, and irrevocably agrees that all actions or proceedings arising out of or relating to this BAA shall be litigated exclusively in such courts. Each party hereby expressly submits to the exclusive personal jurisdiction of and venue in such courts for the limited purposes of any suit, action or other proceeding (whether at law, in equity, or otherwise) relating to this BAA, and expressly waives any claim of improper venue and any claim that any such court is an inconvenient forum.
k. Independent Contractors. No provision of this BAA is intended to create, nor shall be deemed or construed to create, any employment, agency or joint venture relationship between Covered Entity and Business Associate other than that of independent entities contracting with each other hereunder solely for the purpose of effectuating the provisions of this BAA. None of the parties nor any of their respective representatives shall be construed to be the agent, employer, or representative of the other.
l. Notices. Notices under this BAA are given in the manner, and to the addresses, set forth in the Agreement, or by secure electronic means to the contact identified by a Party in writing. Business Associate may also give Customer operational and change-of-terms notices as provided in the Agreement.
m. Counterparts; Facsimiles. Where separately executed under Section 7.p, this BAA may be executed in any number of counterparts (including by means of signature pages sent by facsimile or other electronic means), all of which together shall constitute a single instrument and be deemed original.
n. Periodic Review. The parties shall review this BAA at least every two years or upon regulatory change.
o. Cyber Insurance. Business Associate represents that it maintains cyber liability insurance sufficient to cover security incidents involving PHI, and shall provide proof of such coverage upon request.
p. Separately Executed BAA (Override). If Customer and Business Associate execute a separate, mutually signed business associate agreement covering the Services, that separate agreement supersedes and replaces this BAA in its entirety as of its effective date, and this hosted BAA no longer applies to the Parties.
HOW THIS BAA IS ACCEPTED.
This BAA is not signed on its own. Customer accepts it by signing a Quote that incorporates it (which also identifies Customer’s HIPAA status — Covered Entity or Business Associate) or by accessing or using the Services, as described in the preamble and Section 2 — unless the Parties execute a separate BAA under Section 7.p.
Hiive Health BAA Version 1.0 — Effective August 24, 2026 — Page of