Standard Business Associate Agreement (BAA)
Effective upon Customer Account Creation & Data Connection
This Business Associate Agreement (“BAA”) is entered into by and between RecoupOps Technologies, Inc. (“Business Associate”) and the subscribing healthcare provider entity (“Covered Entity”) to ensure compliance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and HITECH Act standards.
1. Permitted Uses and Disclosures of PHI
Business Associate agrees to not use or disclose Protected Health Information (“PHI”) other than as permitted or required by the Master Service Agreement or as required by law. Business Associate will use PHI solely to perform remittance ingestion, denial classification, clinical appeal packet assembly, and timely filing tracking.
2. Safeguards and Security Standards
Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI (ePHI) that it creates, receives, maintains, or transmits on behalf of Covered Entity, including AES-256 encryption at rest and TLS 1.3 encryption in transit.
3. Prohibition on Model Training
Business Associate expressly agrees and warrants that no patient PHI shall be utilized to train, retrain, fine-tune, or enhance public, multi-tenant, or foundational artificial intelligence models without explicit de-identification in accordance with 45 CFR § 164.514(b).
4. Breach Notification
Business Associate agrees to notify Covered Entity without unreasonable delay, and in no event later than five (5) business days, following the discovery of any confirmed security incident resulting in unauthorized access, acquisition, or disclosure of unencrypted PHI.
5. Return or Destruction of PHI
Upon termination of the underlying Master Service Agreement, Business Associate shall, if feasible, return or destroy all PHI received from Covered Entity within thirty (30) days.