Last updated: September 8, 2026

Business Associate Agreement

This is the agreement we sign with customers who handle protected health information. It is free, and we countersign it on request.

1. Definitions

Terms used here that are capitalized in the HIPAA Rules carry the meaning the Rules give them. That includes Breach, Covered Entity, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

In this agreement:

  • Business Associate means Waiver.com LLC, a Texas limited liability company at 363 North Sam Houston Pkwy E, Suite 125, Houston, TX 77060.
  • Covered Entity means the customer that has requested this agreement and on whose behalf we process Protected Health Information. Where that customer is itself a business associate of another covered entity, this agreement operates as a subcontractor agreement and reads accordingly.
  • HIPAA Rules means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended.
  • Service means the Waiver.com digital waiver and consent platform provided under the Terms of Service, which this agreement supplements.
  • PHI means Protected Health Information that Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity through the Service.

2. Permitted uses and disclosures

Business Associate may use and disclose PHI only:

  • to perform the Service for Covered Entity, as described in the Terms of Service and as Covered Entity configures it;
  • as Covered Entity instructs in writing, including through the settings and integrations it chooses in the product;
  • as Required By Law;
  • as this agreement otherwise expressly permits.

Business Associate will not use or disclose PHI in a way that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as section 3 permits. Business Associate will not sell PHI, will not use or disclose it for marketing or for its own advertising, and will not use it to train models or build products for anyone other than Covered Entity.

3. Uses and disclosures for management, administration, and data aggregation

Business Associate may use PHI for its own proper management and administration and to carry out its legal responsibilities. It may disclose PHI for those purposes only if the disclosure is Required By Law, or if it first obtains reasonable assurances in writing from the person receiving it that the information will be kept confidential and used or further disclosed only as Required By Law or for the purpose it was provided, and that the recipient will notify Business Associate of any breach of confidentiality it becomes aware of.

Business Associate may also use PHI to provide Data Aggregation services relating to Covered Entity’s Health Care Operations, and may de-identify PHI in accordance with 45 CFR 164.514(a) through (c). Properly de-identified information is no longer PHI and is not subject to this agreement.

4. Uses and disclosures Business Associate will not make

Business Associate will not use or disclose PHI other than as this agreement permits or as Required By Law. It will not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as section 3 permits. If Business Associate is compelled by law to disclose PHI, it will, unless legally prohibited, notify Covered Entity before the disclosure so that Covered Entity may seek protective relief.

5. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent any use or disclosure of PHI that this agreement does not permit.

Those safeguards include, today: encryption of PHI in transit and at rest, field-level encryption of sensitive answers and dates of birth, write-once hash-chained storage of signed records enforced by the database itself, an access log of every human read of a signer’s record, role-based least-privilege access, mandatory two-factor authentication for Business Associate’s own administrative access, and session controls.

In addition, Business Associate will maintain a written incident response plan, a risk assessment revisited after any material change to the architecture, workforce training before any workforce member is given access to PHI, and a review of production access when a workforce member leaves or changes roles.

The HIPAA and security pages describe these in more detail and are descriptive; this section is the obligation.

6. Reporting unauthorized use or disclosure, security incidents, and breaches

Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this agreement of which it becomes aware, any Security Incident affecting electronic PHI, and any Breach of Unsecured Protected Health Information.

Notice of a Breach will be given without unreasonable delay and no later than 10 business days after Business Associate confirms it, at the email address of the account owner and any additional contact Covered Entity has given us. The notice will identify each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed, and will include the information required by 45 CFR 164.410(c), supplemented promptly as more becomes known.

The parties acknowledge that unsuccessful attempts of the kind every internet-facing system receives constantly — pings, port scans, blocked login attempts, and denied access requests that do not result in unauthorized access to PHI — are reported on request in aggregate rather than individually, and this paragraph is that notice.

Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI made in violation of this agreement.

7. Subcontractors

Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing, before receiving any PHI, to restrictions and conditions at least as protective as those that apply to Business Associate under this agreement, in accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2). The current list of such Subcontractors is published at waiver.com/subprocessors, and Covered Entity will receive at least 30 days’ notice by email before a new one begins handling PHI. A business associate agreement with Business Associate’s hosting provider is in place before any customer business associate agreement is countersigned. No other Subcontractor receives PHI: email delivery carries names and addresses for notifications only, payment processing receives billing data only, and DNS receives no customer data at all.

8. Access, amendment, and accounting for individuals

The Service is built so that Covered Entity holds and controls its own Designated Record Set directly. Business Associate will nevertheless provide the access and assistance the HIPAA Rules require:

  • Access. Business Associate will make PHI in a Designated Record Set available to Covered Entity, or as directed to an Individual, so that Covered Entity can meet 45 CFR 164.524, promptly on written request and in time for Covered Entity to meet its own deadline under that section.
  • Amendment. Business Associate will make PHI in a Designated Record Set available for amendment, and incorporate any amendment Covered Entity directs, as required by 45 CFR 164.526. Because a signed record is written once and cannot be altered, an amendment is made by recording a new signed record; the original is retained, and may be voided with a reason, so that both remain retrievable.
  • Accounting of disclosures. Business Associate will document disclosures of PHI and the information related to them as required for Covered Entity to respond to a request for an accounting under 45 CFR 164.528, and will provide that documentation on written request in time for Covered Entity to meet its own deadline under that section.

9. Carrying out Covered Entity's obligations

To the extent Business Associate is to carry out one or more of Covered Entity’s obligations under Subpart E of 45 CFR Part 164, it will comply with the requirements of that Subpart that apply to Covered Entity in the performance of those obligations.

10. Minimum necessary

Business Associate will request, use, and disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use, or disclosure, in accordance with 45 CFR 164.502(b) and 164.514(d). Covered Entity decides which questions its forms ask; Business Associate does not review that choice, and Covered Entity is responsible for applying the minimum necessary standard to its own form design.

11. Availability of records to the Secretary

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for the purpose of determining Covered Entity’s compliance with the HIPAA Rules. Unless legally prohibited, Business Associate will notify Covered Entity of any such request.

12. Obligations of Covered Entity

Covered Entity will:

  • notify Business Associate of any limitation in its Notice of Privacy Practices, of any change to or revocation of an Individual’s permission to use or disclose PHI, and of any restriction on use or disclosure it has agreed to under 45 CFR 164.522, to the extent any of these affects Business Associate’s use or disclosure of PHI;
  • obtain any consent, authorization, or permission its own operations require before collecting PHI through the Service;
  • configure the Service, its forms, its staff roles, and its integrations consistently with the HIPAA Rules;
  • not request Business Associate to use or disclose PHI in a way that would not be permitted under Subpart E of 45 CFR Part 164 if done by Covered Entity, except where section 3 permits it for Business Associate’s management and administration or for Data Aggregation.

13. Term and termination

This agreement takes effect on the date Business Associate countersigns it and continues until all PHI is returned or destroyed under section 14, or until it is terminated as provided here.

Covered Entity may terminate this agreement and the Service if Business Associate materially breaches this agreement and fails to cure the breach within 30 days of written notice, or immediately if a cure is not possible. Business Associate has the same right where Covered Entity’s breach of this agreement puts PHI at risk. Termination of the underlying subscription terminates this agreement, subject to section 14.

14. Return or destruction of PHI

On termination, Business Associate will return to Covered Entity, or destroy, all PHI it maintains in any form and retain no copies, and will require the same of its Subcontractors. Covered Entity may export its records at any time before termination and may ask for an export afterwards.

Where return or destruction is not feasible — including where retention is Required By Law or by a legal hold — Business Associate will extend the protections of this agreement to that information, limit further uses and disclosures to the purposes that make return or destruction infeasible, and destroy it when those purposes end.

15. Miscellaneous

  • Regulatory references. A reference to a section of the HIPAA Rules means that section as in effect or as amended.
  • Amendment. The parties will take such action as is necessary to amend this agreement from time to time so that each remains in compliance with the HIPAA Rules.
  • Interpretation. Ambiguity is resolved in favor of a meaning that permits compliance with the HIPAA Rules. This agreement controls over the Terms of Service and the Privacy Policy as to PHI, and those documents govern everything else.
  • Survival. The obligations of Business Associate under sections 5, 6, 11, and 14 survive termination.
  • No third-party beneficiaries. Nothing here creates rights in any person other than the parties.
  • Governing law. The law of the State of Texas governs, except where the HIPAA Rules preempt it.

16. How this agreement is entered

This page is the text of the agreement, published so you can read and route it for approval before you ask for it. It becomes binding by countersignature: email help@waiver.comfrom an address on your account with the legal name and address of your covered entity and the subject “BAA request”, and we will return an executed copy. There is no charge and no plan requirement.

If your organization requires its own form, send it and we will review it. Until an agreement is executed, do not put protected health information into the Service.

All legal documents

QUESTIONS ABOUT THIS DOCUMENT?

Ask a person, not a form.

Write to help@waiver.com and someone who works on the product will answer. We would rather explain a clause than have you guess at it.