
Healthcare organizations that need to share Protected Health Information (PHI) with Chargezen must execute a Business Associate Agreement. This template outlines our standard terms.
To Execute a BAA
legal@chargezen.comProcessing Time
3-5 business days
Note: A signed BAA is required before Chargezen can process any PHI on your behalf. Standard BAAs are included at no additional cost for eligible healthcare plans.
PHI includes any individually identifiable health information that is transmitted or maintained by a covered entity or business associate. Examples include:
Chargezen may only use or disclose PHI for the following purposes:
The following represents our standard BAA template. Executed agreements may include customer-specific provisions.
For purposes of this Business Associate Agreement ("Agreement"):
2.1 Business Associate may use or disclose PHI only as necessary to perform services for Covered Entity as specified in the underlying service agreement, or as required by law.
2.2 Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, provided that any disclosure:
2.3 Business Associate may aggregate PHI with data of other covered entities (if authorized) and may de-identify PHI in accordance with 45 CFR § 164.514.
3.1 Safeguards. Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, as required by the HIPAA Security Rule.
3.2 Reporting. Business Associate shall:
3.3 Subcontractors. Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions and conditions in this Agreement.
3.4 Access. Business Associate shall make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.524 (individual access rights).
3.5 Amendment. Business Associate shall make PHI available for amendment and incorporate amendments as directed by Covered Entity, as required by 45 CFR § 164.526.
3.6 Accounting. Business Associate shall make available information required for Covered Entity to provide an accounting of disclosures, as required by 45 CFR § 164.528.
3.7 HHS Access. Business Associate shall make its internal practices, books, and records relating to PHI available to the Secretary of HHS for purposes of determining compliance with HIPAA.
3.8 Minimum Necessary. Business Associate shall limit its use, disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose.
4.1 Covered Entity shall notify Business Associate of any limitations in its Notice of Privacy Practices that may affect Business Associate's use or disclosure of PHI.
4.2 Covered Entity shall notify Business Associate of any changes in, or revocation of, authorization by an individual to use or disclose PHI.
4.3 Covered Entity shall notify Business Associate of any restrictions on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522.
4.4 Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
Business Associate implements the following security measures to protect ePHI:
5.1 Administrative Safeguards:
5.2 Physical Safeguards:
5.3 Technical Safeguards:
6.1 Discovery. A Breach is deemed "discovered" as of the first day the Breach is known or, by exercising reasonable diligence, would have been known to Business Associate.
6.2 Notification. Upon discovery of a Breach of unsecured PHI, Business Associate shall notify Covered Entity within 24 hours and provide:
6.3 Cooperation. Business Associate shall cooperate with Covered Entity in investigating the Breach and complying with notification requirements under 45 CFR §§ 164.404-164.410.
6.4 Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effects of the Breach that are known to Business Associate.
7.1 Term. This Agreement is effective upon execution and continues until all PHI is destroyed or returned, or the underlying service agreement terminates.
7.2 Termination for Cause. Either party may terminate this Agreement if the other party materially breaches this Agreement and fails to cure within 30 days of written notice.
7.3 Effect of Termination. Upon termination:
8.1 Amendment. This Agreement may not be modified except by written agreement signed by both parties. The parties agree to amend this Agreement as necessary to comply with HIPAA and its implementing regulations.
8.2 Survival. Sections 3.1 (Safeguards), 6 (Breach Notification), and 7.3 (Effect of Termination) shall survive termination of this Agreement.
8.3 Interpretation. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with HIPAA.
8.4 No Third-Party Beneficiaries. Nothing in this Agreement shall confer any rights on any third party.
8.5 Governing Law. This Agreement shall be governed by federal law (HIPAA) and, to the extent not preempted, the laws of the State of Delaware.
Chargezen maintains the following certifications and controls relevant to healthcare data:
SOC 2 Type II
Certified
HIPAA
Compliant
Encryption
AES-256
Penetration Testing
Annual
Contact our legal team to request a Business Associate Agreement for your healthcare organization.
