Background
Healthcare Compliance

Business Associate Agreement

HIPAA-compliant Business Associate Agreement for healthcare organizations using Chargezen to process Protected Health Information (PHI).

Version: January 2026HIPAA Compliant

Request a BAA

Healthcare organizations that need to share Protected Health Information (PHI) with Chargezen must execute a Business Associate Agreement. This template outlines our standard terms.

To Execute a BAA

legal@chargezen.com

Processing Time

3-5 business days

Note: A signed BAA is required before Chargezen can process any PHI on your behalf. Standard BAAs are included at no additional cost for eligible healthcare plans.

What is Protected Health Information (PHI)?

PHI includes any individually identifiable health information that is transmitted or maintained by a covered entity or business associate. Examples include:

Names, addresses, phone numbers, email addresses
Social Security numbers, medical record numbers
Health insurance information and policy numbers
Dates of treatment, appointment information
Diagnoses, treatment plans, medications
Lab results, imaging reports, clinical notes
Biometric identifiers (fingerprints, voice prints)
Any other information that can identify a patient

Permitted Uses of PHI

Chargezen may only use or disclose PHI for the following purposes:

  • 1
    Performing functions specified in our service agreement
  • 2
    Proper management and administration of our business
  • 3
    Carrying out legal responsibilities
  • 4
    Data aggregation services (if specified in agreement)
  • 5
    Creating de-identified data sets per HIPAA requirements

Business Associate Agreement Terms

The following represents our standard BAA template. Executed agreements may include customer-specific provisions.

1. Definitions

For purposes of this Business Associate Agreement ("Agreement"):

  • "Covered Entity" means a health plan, health care clearinghouse, or health care provider that transmits health information electronically and is subject to HIPAA.
  • "Business Associate" means Chargezen Corporation, which creates, receives, maintains, or transmits Protected Health Information on behalf of the Covered Entity.
  • "Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form or medium, as defined in 45 CFR § 160.103.
  • "Electronic Protected Health Information" or "ePHI" means PHI transmitted or maintained in electronic media.
  • "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations.
  • "Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under HIPAA which compromises the security or privacy of the PHI.

2. Permitted Uses and Disclosures

2.1 Business Associate may use or disclose PHI only as necessary to perform services for Covered Entity as specified in the underlying service agreement, or as required by law.

2.2 Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, provided that any disclosure:

  • Is required by law; or
  • Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used or disclosed only as required by law or for the purposes for which it was disclosed, and the recipient will notify Business Associate of any breaches.

2.3 Business Associate may aggregate PHI with data of other covered entities (if authorized) and may de-identify PHI in accordance with 45 CFR § 164.514.

3. Obligations of Business Associate

3.1 Safeguards. Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, as required by the HIPAA Security Rule.

3.2 Reporting. Business Associate shall:

  • Report any use or disclosure of PHI not permitted by this Agreement within 3 business days of discovery
  • Report any Security Incident within 24 hours of discovery
  • Report any Breach of unsecured PHI within 24 hours of discovery, including information necessary for Covered Entity to comply with breach notification requirements

3.3 Subcontractors. Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions and conditions in this Agreement.

3.4 Access. Business Associate shall make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.524 (individual access rights).

3.5 Amendment. Business Associate shall make PHI available for amendment and incorporate amendments as directed by Covered Entity, as required by 45 CFR § 164.526.

3.6 Accounting. Business Associate shall make available information required for Covered Entity to provide an accounting of disclosures, as required by 45 CFR § 164.528.

3.7 HHS Access. Business Associate shall make its internal practices, books, and records relating to PHI available to the Secretary of HHS for purposes of determining compliance with HIPAA.

3.8 Minimum Necessary. Business Associate shall limit its use, disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose.

4. Obligations of Covered Entity

4.1 Covered Entity shall notify Business Associate of any limitations in its Notice of Privacy Practices that may affect Business Associate's use or disclosure of PHI.

4.2 Covered Entity shall notify Business Associate of any changes in, or revocation of, authorization by an individual to use or disclose PHI.

4.3 Covered Entity shall notify Business Associate of any restrictions on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522.

4.4 Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.

5. Security Measures

Business Associate implements the following security measures to protect ePHI:

5.1 Administrative Safeguards:

  • Security Officer designation
  • Workforce training and awareness programs
  • Access management and authorization procedures
  • Security incident procedures
  • Contingency planning and disaster recovery
  • Regular risk assessments

5.2 Physical Safeguards:

  • Facility access controls (data centers)
  • Workstation use and security policies
  • Device and media controls

5.3 Technical Safeguards:

  • Access controls (unique user IDs, automatic logoff)
  • Audit controls and logging
  • Integrity controls
  • Transmission security (encryption in transit)
  • Encryption at rest (AES-256)

6. Breach Notification

6.1 Discovery. A Breach is deemed "discovered" as of the first day the Breach is known or, by exercising reasonable diligence, would have been known to Business Associate.

6.2 Notification. Upon discovery of a Breach of unsecured PHI, Business Associate shall notify Covered Entity within 24 hours and provide:

  • Identification of each individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed
  • A description of what happened, including the date of the Breach and discovery
  • The types of PHI involved
  • Steps individuals should take to protect themselves
  • Investigation status and mitigation steps taken

6.3 Cooperation. Business Associate shall cooperate with Covered Entity in investigating the Breach and complying with notification requirements under 45 CFR §§ 164.404-164.410.

6.4 Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effects of the Breach that are known to Business Associate.

7. Term and Termination

7.1 Term. This Agreement is effective upon execution and continues until all PHI is destroyed or returned, or the underlying service agreement terminates.

7.2 Termination for Cause. Either party may terminate this Agreement if the other party materially breaches this Agreement and fails to cure within 30 days of written notice.

7.3 Effect of Termination. Upon termination:

  • If feasible, Business Associate shall return or destroy all PHI received or created on behalf of Covered Entity
  • If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible
  • Business Associate shall certify in writing the destruction of PHI or the reasons why return or destruction is not feasible

8. Miscellaneous

8.1 Amendment. This Agreement may not be modified except by written agreement signed by both parties. The parties agree to amend this Agreement as necessary to comply with HIPAA and its implementing regulations.

8.2 Survival. Sections 3.1 (Safeguards), 6 (Breach Notification), and 7.3 (Effect of Termination) shall survive termination of this Agreement.

8.3 Interpretation. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with HIPAA.

8.4 No Third-Party Beneficiaries. Nothing in this Agreement shall confer any rights on any third party.

8.5 Governing Law. This Agreement shall be governed by federal law (HIPAA) and, to the extent not preempted, the laws of the State of Delaware.

Security & Compliance

Chargezen maintains the following certifications and controls relevant to healthcare data:

SOC 2 Type II

Certified

HIPAA

Compliant

Encryption

AES-256

Penetration Testing

Annual

Ready to Execute a BAA?

Contact our legal team to request a Business Associate Agreement for your healthcare organization.

Space, at your fingertips

What would you do with 22% more revenue?