Read and scroll through the complete agreement before signing. Version 2026-09-04.
HIPAA BUSINESS ASSOCIATE AGREEMENT
This HIPAA BUSINESS ASSOCIATE AGREEMENT (the “Agreement”) is effective as of the earlier of (a) the date on which the healthcare practice, facility, organization, or other entity identified during registration or execution of this Agreement (“Covered Entity”) electronically executes this Agreement, or (b) the date Covered Entity first receives services (the “Services”) from Malama Health Inc., a Delaware corporation (“Business Associate”), to the extent that the Services involve the creation, receipt, maintenance, or transmission of Protected Health Information (“PHI”) on behalf of Covered Entity (the “Effective Date”).
1. Definitions
Capitalized terms used without definition herein shall have the respective meanings assigned to them under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including, without limitation, the Standards for Privacy of Individually Identifiable Health Information (the “Privacy Rule”), the Security Standards (the “Security Rule”), the Breach Notification for Unsecured Protected Health Information Rule, and the HIPAA Omnibus Rule, found at 45 C.F.R. Parts 160 and 164, as such provisions are amended or renumbered from time to time (collectively, “HIPAA”).
2. Permitted Uses and Disclosures
Business Associate may use or disclose PHI to perform the Services, as permitted herein and as Required by Law.
Business Associate may not use or disclose PHI if such use or disclosure would violate the Privacy Rule if done by Covered Entity.
3. Activities by Business Associate
Business Associate shall:
3.1 Permitted Uses and Disclosures
Not use or disclose PHI other than as permitted or required by this Agreement, except that Business Associate may use and disclose PHI for the following purposes:
(a) the proper management and administration of Business Associate;
(b) to carry out the legal responsibilities of Business Associate;
(c) to provide data aggregation services relating to the health care operations of Covered Entity; and
(d) to de-identify PHI received, created, maintained, or transmitted by Business Associate in accordance with HIPAA, and such de-identified information shall no longer be subject to this Agreement and may be used and disclosed on Business Associate’s own behalf in accordance with the de-identification requirements of the Privacy Rule.
3.2 De-Identified Information
Business Associate may freely use and otherwise exploit de-identified PHI for Business Associate’s business purposes, including, without limitation, for purposes of developing and improving its products and services, benchmarking, and producing white papers and other publications relating to Business Associate’s business or technology.
For purposes of this Section 3.2, de-identified PHI means data submitted to, collected by, or generated by Business Associate in connection with its performance of the Services and/or Covered Entity’s use of the Services, but only in anonymized form that cannot reasonably be linked specifically to Covered Entity or any other entity or individual.
3.3 Safeguards
Use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement.
3.4 Security Rule
Comply with the applicable requirements of the Security Rule with respect to electronic PHI.
3.5 Reporting of Unauthorized Uses, Disclosures, Breaches, and Security Incidents
Report to Covered Entity any:
(a) use or disclosure of PHI not provided for by this Agreement, without unreasonable delay and in no case later than sixty (60) days after it is discovered by Business Associate, including breaches of unsecured PHI as required by HIPAA; or
(b) Security Incident of which Business Associate becomes aware;
provided, however, that the parties acknowledge and agree that this Section 3.5 constitutes notice by Business Associate to Covered Entity of the ongoing existence and occurrence or attempts of Unsuccessful Security Incidents for which no additional notice to Covered Entity shall be required.
“Unsuccessful Security Incidents” means, without limitation, pings and other broadcast attacks on Business Associate’s firewalls, port scans, unsuccessful log-on attempts, denial-of-service attacks, and any combination of the above, so long as no such incident results in unauthorized access, use, or disclosure of PHI.
3.6 Subcontractors
Require that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions and conditions that apply to Business Associate under this Agreement with respect to such information, including compliance with the applicable requirements of the Security Rule.
3.7 Access
At the request of Covered Entity, make available PHI in a Designated Record Set in order for Covered Entity to meet the requirements of 45 C.F.R. § 164.524.
3.8 Amendment
At the request of Covered Entity, make available to Covered Entity PHI for amendment and, if requested by Covered Entity, incorporate any amendment(s) to PHI in accordance with 45 C.F.R. § 164.526.
3.9 Accounting of Disclosures
Make available the information required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 C.F.R. § 164.528.
3.10 Access by Secretary
Make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary for purposes of the Secretary determining Covered Entity’s compliance with HIPAA.
3.11 Performance of Covered Entity Obligations
To the extent that Business Associate is to carry out an obligation of Covered Entity under the Privacy Rule, comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of such obligation.
4. Term and Termination
4.1 Term
The term of this Agreement shall commence as of the Effective Date and shall terminate when all PHI provided by Covered Entity to Business Associate, or created, received, transmitted, or maintained by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity or, if it is infeasible to return or destroy PHI, protections are extended to such information in accordance with Section 4.3 of this Agreement.
4.2 Termination for Cause
In the event a party has knowledge of a material breach by the other party, such party may either:
(a) provide an opportunity for the breaching party to cure the breach or end the violation and terminate this Agreement and the Services if the breaching party does not cure the breach within thirty (30) days; or
(b) immediately terminate this Agreement and the Services if cure of the breach is not possible.
4.3 Effect of Termination
4.3.1 Return or Destruction
Except as provided in Section 4.3.2 or otherwise required by applicable law or regulation, upon termination of this Agreement for any reason, if feasible, Business Associate shall return or destroy all PHI received from, or created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity that Business Associate still maintains in any form, and retain no copies of such PHI.
This provision shall apply to PHI that is in the possession of subcontractors or agents of Business Associate.
4.3.2 Infeasibility
If return or destruction of PHI is infeasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible for so long as Business Associate maintains such PHI.
5. Notice
All notices, requests, and other communications made pursuant to this Agreement shall be in writing and shall be deemed to have been given:
(a) when delivered by hand;
(b) when received by the addressee if sent by a nationally recognized overnight courier, receipt requested;
(c) on the date sent by facsimile or email of a PDF document, with confirmation of transmission, if sent during normal business hours of the recipient, and on the next business day if sent after normal business hours of the recipient; or
(d) on the third day after the date mailed by certified or registered mail, return receipt requested, postage prepaid.
Notices shall be addressed as follows:
If to Business Associate:
Malama Health Inc.
2261 Market St. #4875
San Francisco, CA 94114
Attention: Malama Health
Email: hello@heymalama.com
Phone Number: 949-424-5479
If to Covered Entity:
Covered Entity Name: {organization_name}
Covered Entity Address 1: {organization_address_1}
Covered Entity Address 2: {organization_address_2}
Attention: {organization_contact_name}
Email: {organization_contact_email}
The information above may be populated using information provided during registration or otherwise maintained in Covered Entity’s account.
6. Miscellaneous
The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity and Business Associate to comply with the requirements of HIPAA, the HITECH Act, and other applicable law or regulation.
The respective rights and obligations of the parties under Section 4.3 of this Agreement shall survive the expiration or termination of this Agreement and any services agreement between the parties in effect from time to time (each, a “Services Agreement”).
Nothing expressed or implied in this Agreement is intended to confer, nor shall anything herein confer, any rights, remedies, obligations, or liabilities whatsoever upon any person other than Covered Entity, Business Associate, and their respective permitted successors or assigns.
This Agreement constitutes the entire agreement between the parties hereto with respect to the subject matter set forth herein and expressly supersedes and replaces any prior HIPAA business associate agreement between the parties, whether written or oral; provided that, for the avoidance of doubt, this Agreement shall not be deemed to modify, supersede, or replace any Services Agreement entered into by the parties, except to the extent of any conflict between the terms of any Services Agreement and this Agreement, in which case this Agreement shall control.
Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits each party to comply with HIPAA, the HITECH Act, and any other applicable law or regulation.
Except to the extent required in connection with the performance of Services, no party may assign its rights or obligations hereunder without the prior written consent of the other party.
This Agreement shall be governed by and construed in accordance with the internal laws of the State of Delaware without giving effect to any choice or conflict-of-law provision or rule, whether of the State of Delaware or any other jurisdiction, that would cause the application of laws of any jurisdiction other than those of the State of Delaware.
7. Electronic Execution
The parties agree that this Agreement may be executed electronically.
Covered Entity agrees that an electronic signature or other affirmative electronic execution of this Agreement by an individual authorized to bind Covered Entity shall have the same legal effect as a handwritten signature.
The individual electronically signing this Agreement on behalf of Covered Entity represents that they have authority to bind Covered Entity to this Agreement.
Business Associate may maintain records relating to electronic execution of this Agreement, including the Covered Entity name, signer name, signer email address, signer role or title, date and time of execution, Agreement version, electronic signature, and other records reasonably necessary to evidence execution of this Agreement.