Relationship Theory

Business Associate Agreement

Last updated August 15, 2026

This agreement governs how we protect your Clients’ health information as your Business Associate under HIPAA when you use Relationship Theory. It supplements our Terms of Service, Privacy Policy.

1. Background

This Business Associate Agreement (“BAA”) is between you (“Covered Entity”) and Relationship Theory (“Business Associate”). It takes effect when your account is created, supersedes any previous business associate agreement between the parties, and amends, supplements, and is made part of the Terms of Service (the “Agreement”), as amended from time to time.

Covered Entity may be a “covered entity” as defined at 45 C.F.R. § 160.103. In connection with providing the Service under the Agreement, Business Associate may, on behalf of Covered Entity, create, receive, maintain, or transmit Protected Health Information (“PHI”). The parties intend to protect the privacy and provide for the security of PHI in compliance with the Health Insurance Portability and Accountability Act of 1996, Subtitle D of the HITECH Act of 2009, and the regulations and guidance under both (collectively, “HIPAA”), and other applicable federal and state laws. This BAA is intended to satisfy the standards of HIPAA, including 45 C.F.R. §§ 164.308(b), 164.314(a), 164.502(e), and 164.504(e), and applies only where Business Associate meets the definition of “business associate” with respect to Covered Entity at 45 C.F.R. § 160.103.

2. Definitions

Capitalized terms used but not defined here have the meaning given to them in HIPAA. Any inconsistency in a definition is resolved in favor of a meaning that permits compliance with HIPAA.

  • “Breach,” “Unsecured PHI,” “Data Aggregation,” “Designated Record Set,” “Electronic Protected Health Information” (“ePHI”), “Individual,” “Required by Law,” “Secretary,” “Security Incident,” and “Subcontractor” have the meanings given to those terms in the HIPAA Rules (45 C.F.R. Parts 160 and 164). “Secretary” means the Secretary of the U.S. Department of Health and Human Services or their designee.
  • “Protected Health Information” (“PHI”) means individually identifiable health information, as defined at 45 C.F.R. § 160.103, that Business Associate creates, receives, maintains, or transmits from or on behalf of Covered Entity.
  • “Privacy Rule” and “Security Rule” mean, respectively, the Standards for Privacy of Individually Identifiable Health Information and the Security Standards for the Protection of ePHI, as amended.
  • “Reportable Event” means any (1) use or disclosure of PHI not provided for by this BAA; (2) Security Incident; or (3) Breach of Unsecured PHI.

3. Permitted uses and disclosures of PHI

Except as otherwise limited in this BAA or the Agreement, Business Associate may:

  • Use or disclose PHI to perform the functions, activities, or services for or on behalf of Covered Entity described in the Agreement, provided the use or disclosure would not violate the Privacy Rule or applicable state law if done by Covered Entity.
  • Use PHI for the proper management and administration of Business Associate, or to carry out its legal responsibilities.
  • Disclose PHI for its proper management and administration or to carry out its legal responsibilities, provided the disclosure is Required by Law, or Business Associate obtains reasonable written assurances that the recipient will keep the PHI confidential, use or further disclose it only as Required by Law or for the purpose it was disclosed, and notify Business Associate of any breach of confidentiality.
  • Use PHI to report violations of law to appropriate authorities, consistent with 45 C.F.R. § 164.502(j).
  • Use PHI to provide Data Aggregation services relating to Covered Entity’s health care operations, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
  • Use PHI to create de-identified information in accordance with 45 C.F.R. §§ 164.502(d) and 164.514(a)-(c).

Business Associate does not sell PHI and does not use or disclose PHI for marketing or advertising.

4. Obligations of Business Associate

Business Associate will:

  • Not use or disclose PHI other than as permitted or required by this BAA and the Agreement, or as Required by Law.
  • To the extent it carries out an obligation of Covered Entity under HIPAA, comply with the HIPAA requirements that apply to Covered Entity in performing that obligation.
  • Use appropriate safeguards and, where applicable, comply with the Security Rule and HITECH with respect to ePHI, to prevent use or disclosure of PHI other than as this BAA provides. These safeguards include encryption in transit, database-level access controls that isolate each Covered Entity’s data from every other, private file storage served only through short-lived signed links, hashed passwords, optional two-factor authentication, an append-only audit trail, and rate limiting on sensitive actions.
  • Report to Covered Entity, by email or telephone, any Reportable Event of which it becomes aware, without unreasonable delay and in no case later than fifteen (15) business days after discovery. The report will include, to the extent available, the affected Individuals, a description of what happened and when, the types of PHI involved, steps Individuals may take to protect themselves, what Business Associate is doing to investigate and mitigate, and any other information Covered Entity would reasonably need to meet its notification obligations. Business Associate will supplement its report as more information becomes available.
  • Cooperate with Covered Entity in investigating a Reportable Event and help determine whether it constitutes a Breach of Unsecured PHI, and mitigate, to the extent practicable, any known harmful effect.
  • The parties acknowledge that this section is notice of the ongoing occurrence of unsuccessful Security Incidents that do not compromise PHI (such as pings, port scans, and blocked log-in attempts); these are reported only in the aggregate, on request.
  • Require any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree in writing to restrictions and conditions at least as protective as those in this BAA, in compliance with 45 C.F.R. §§ 164.314(a) and 164.504(e).
  • Provide access to PHI in a Designated Record Set to Covered Entity, or as directed to an Individual, via in-app export, so Covered Entity can meet its obligations under 45 C.F.R. § 164.524 (and Section 13405(c) of HITECH where applicable).
  • Make amendments to PHI in a Designated Record Set that Covered Entity directs, in the time and manner required by 45 C.F.R. § 164.526.
  • Provide the information needed for Covered Entity to give an accounting of disclosures under 45 C.F.R. § 164.528, within a reasonable time and in no case fewer than ten (10) business days after a request.
  • Redirect to Covered Entity any access, amendment, accounting, or similar request Business Associate receives directly from an Individual.
  • Make its internal policies, practices, books, and records relating to the use and disclosure of PHI available to the Secretary for determining compliance with HIPAA, without waiving any legal privilege.
  • Comply with HIPAA’s minimum necessary requirements.

5. Obligations of Covered Entity

Covered Entity will:

  • Notify Business Associate in writing of any limitation in its notice of privacy practices, any change in or revocation of an Individual’s authorization, and any restriction on the use or disclosure of PHI it has agreed to under 45 C.F.R. § 164.522, to the extent any of these affects Business Associate’s use or disclosure of PHI.
  • Not request that Business Associate use or disclose PHI in any manner that would not be permissible under HIPAA or other applicable law if done by Covered Entity.
  • Comply with HIPAA’s minimum necessary requirements and provide Business Associate only the minimum PHI necessary for Business Associate to provide the Service.
  • Obtain any consents, authorizations, and notices its clients require, and be responsible for the lawfulness of the information it collects and for its own compliance with the laws that apply to its practice.

6. Term and termination

This BAA commences on the effective date, is coterminous with the Agreement, and continues until the earliest of: the Agreement expiring or terminating; termination for cause; mutual agreement; or termination under applicable law.

Termination for cause. If either party materially breaches this BAA, the other party may give written notice describing the breach and an opportunity to cure. If the breaching party does not cure within thirty (30) days of the notice, the non-breaching party may terminate this BAA and the Agreement.

Effect of termination. On termination for any reason, Business Associate will return or destroy all PHI it still maintains and retain no copies. Where return or destruction is not feasible, Business Associate will retain only that PHI, extend the protections of this BAA to it, continue to use appropriate safeguards and comply with the Security Rule and HITECH for ePHI, limit further use or disclosure to the purposes that make return or destruction infeasible, and return or destroy the PHI once it becomes feasible. This section survives termination.

7. General

Regulatory references and automatic amendment. A reference to a HIPAA section means that section as in effect or amended at the relevant time. If HIPAA is amended or new regulations are issued that apply to this BAA, this BAA is automatically amended so the parties’ obligations remain compliant, unless the parties agree otherwise. No other waiver, change, or amendment is effective unless in writing and signed by the parties.

Interpretation. Any ambiguity is resolved in favor of a meaning that permits compliance with HIPAA. Headings are for convenience only. If a term of this BAA and a term of the Agreement are directly contradictory, the term of this BAA prevails to the extent necessary to permit compliance with HIPAA.

Independent contractors; no third-party beneficiaries. The parties are independent contractors, and nothing here creates an agency, partnership, or employment relationship. Nothing in this BAA confers any right or remedy on any person other than the parties and their permitted successors and assigns.

Severability, assignment, governing law, disputes. If any provision is invalid or unenforceable, it is severed and the rest stays in effect. Assignment, governing law, and dispute resolution follow the provisions of the Agreement, except to the extent preempted by federal law.

Notices. Notices to Business Associate may be sent by email to the address in “Contact” below (and, for formal legal notice, to Relationship Theory, Attn: Compliance, at the mailing address we provide on request). Notices to Covered Entity are sent by email to the address on the account. Either party may update its notice address in writing.

8. Contact

Questions about this BAA or how we handle PHI? Email us at support@relationshiptheory.com.

← Back to sign inPrivacyTermsBAA