BUSINESS ASSOCIATE AGREEMENT
Version 1.1 — June 9, 2026
This Business Associate Agreement (this "Agreement" or "BAA") is entered into by and between (a) the medical practice, clinic, health care provider, or other covered entity that creates an account for, accepts online terms for, executes an order form for, or otherwise uses the carelinkMD Service to create, receive, maintain, transmit, use, or disclose PHI ("Covered Entity" or "Client"), and (b) Expert Business Consulting LLC, a Florida limited liability company d/b/a carelinkMD ("Business Associate" or "carelinkMD"). Covered Entity and Business Associate are each a "Party" and together the "Parties."
Effective Date. This Agreement is effective on the earliest of: (i) the date Covered Entity or its authorized representative affirmatively clicks "I agree," checks an unchecked box, clicks "Create Account," "Sign Up," or a substantially similar acceptance button, or otherwise takes an affirmative electronic action after being presented with this Agreement or a clear and conspicuous hyperlink to it and a reasonable opportunity to review and retain it; (ii) the date Covered Entity electronically or manually signs this Agreement or an order form incorporating it; or (iii) the date Covered Entity first transmits PHI to Business Associate through the Service after receiving access to this Agreement.
Purpose and Scope
1.1 Purpose. The Parties enter into this Agreement to satisfy the requirements of the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations, including the Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule (collectively, "HIPAA").
1.2 Services. Business Associate provides a digital patient intake software-as-a-service platform and related implementation, hosting, support, account administration, security, backup, and communication services (collectively, the "Service") for Covered Entity. In providing the Service, Business Associate may create, receive, maintain, transmit, use, or disclose PHI on behalf of Covered Entity.
1.3 Relationship. Business Associate is acting as a business associate of Covered Entity and not as a health care provider, health plan, clearinghouse, medical record custodian of record, or fiduciary of Covered Entity or any individual. Covered Entity remains responsible for its clinical operations, patient relationship, medical record retention obligations, Notice of Privacy Practices, and decisions regarding treatment, payment, and health care operations.
Definitions
2.1 HIPAA Terms. Capitalized terms used but not defined in this Agreement have the meanings given to them in HIPAA, including 45 C.F.R. Parts 160 and 164. Without limitation, the terms "Breach," "Data Aggregation," "Designated Record Set," "Disclosure," "Individual," "Protected Health Information," "Required by Law," "Secretary," "Security Incident," "Subcontractor," "Unsecured Protected Health Information," and "Use" have the meanings given to them under HIPAA.
2.2 PHI. "PHI" means Protected Health Information that Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity through the Service, including electronic PHI ("ePHI"). PHI may include patient names, dates of birth, insurance information, health histories, intake responses, signatures, and related metadata submitted through the Service.
2.3 Subcontractor. "Subcontractor" means a person or entity, other than a member of Business Associate's workforce, that creates, receives, maintains, or transmits PHI on behalf of Business Associate. Subcontractors may include cloud hosting providers, storage and backup vendors, email or SMS delivery providers, authentication, logging, monitoring, customer support, security, and analytics providers to the extent they create, receive, maintain, or transmit PHI.
Permitted Uses and Disclosures by Business Associate
3.1 Service Delivery. Business Associate may Use and Disclose PHI as necessary to provide, secure, support, maintain, improve, and administer the Service for Covered Entity, including hosting intake forms, receiving patient submissions, storing intake records, routing or making PHI available to Covered Entity, authenticating users, processing signatures, providing technical support, maintaining backups, preventing fraud or abuse, billing and account administration, and performing other functions, activities, or services on behalf of Covered Entity as described in the applicable online terms, order form, documentation, or instructions of Covered Entity.
3.2 Required by Law. Business Associate may Use or Disclose PHI to the extent Required by Law, provided that the Use or Disclosure complies with and is limited to the relevant requirements of such law.
3.3 Management and Administration. Business Associate may Use PHI for Business Associate's proper management and administration and to carry out Business Associate's legal responsibilities. Business Associate may Disclose PHI for those purposes only if the Disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential, will be Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed to the recipient, and the recipient will notify Business Associate of any known breach of confidentiality.
3.4 Data Aggregation and De-Identification. Business Associate may provide Data Aggregation services relating to Covered Entity's health care operations to the extent permitted by HIPAA and the Service. Business Associate may Use PHI to create de-identified information in accordance with 45 C.F.R. § 164.514 and may Use and Disclose de-identified information for lawful business purposes, provided that Business Associate does not attempt to re-identify the information except as permitted by HIPAA and this Agreement.
3.5 Minimum Necessary. Business Associate shall make reasonable efforts to limit PHI Uses, Disclosures, and requests to the minimum necessary to accomplish the intended purpose, except where HIPAA does not require application of the minimum necessary standard.
Prohibited Uses and Disclosures
4.1 No Impermissible Use. Business Associate shall not Use or further Disclose PHI other than as permitted or required by this Agreement, the applicable services agreement, or Required by Law. Business Associate shall not Use or Disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Covered Entity, except for Uses or Disclosures expressly permitted for Business Associate's management and administration, legal responsibilities, Data Aggregation, or de-identification as set forth in this Agreement.
4.2 No Sale, Marketing, Data Monetization, Improper AI Use, or Tracking Disclosures. Business Associate shall not sell PHI, Use PHI for marketing, advertising, data brokerage, or data monetization, Use PHI to train external artificial intelligence or machine-learning models, or deploy third-party tracking, analytics, advertising, session-replay, or similar technologies in connection with the Service in a manner that Discloses PHI to a vendor, except to the extent expressly authorized in writing by Covered Entity, permitted by HIPAA, and supported by a business associate agreement or other legally sufficient arrangement with the applicable vendor if the vendor creates, receives, maintains, or transmits PHI.
4.3 Sensitive or Compulsory Requests. To the extent Business Associate receives a subpoena, court order, law enforcement request, health oversight request, coroner or medical examiner request, or other compulsory or third-party request for PHI that Business Associate knows, based on Covered Entity's written notice or applicable law directly applicable to Business Associate, is subject to special handling, attestation, authorization, consent, or disclosure-limitation requirements under federal or state law then in effect, Business Associate shall, unless prohibited by law, promptly notify Covered Entity and shall not Disclose such PHI except as Required by Law, as directed in writing by Covered Entity, or in compliance with any attestation, authorization, consent, or other condition required by applicable law then in effect. Business Associate may rely on Covered Entity's written instructions regarding special handling requirements unless Business Associate knows the instruction would violate applicable law.
Obligations of Business Associate
5.1 Safeguards. Business Associate shall use appropriate administrative, physical, and technical safeguards to prevent Use or Disclosure of PHI other than as provided for by this Agreement. With respect to ePHI, Business Associate shall comply with the applicable requirements of the HIPAA Security Rule.
5.2 Security Program. Business Associate shall maintain a commercially reasonable information security program appropriate to the size, complexity, and capabilities of Business Associate and the nature and scope of the Service. Such program will include, as applicable and appropriate, periodic security risk analysis and risk management, access controls, unique user identification for Business Associate workforce access, authentication controls, encryption of PHI in transit and at rest, logging and monitoring, secure cloud infrastructure, vulnerability management, backup and disaster recovery controls, workforce access limitations, and incident response procedures.
5.3 U.S. Hosting. Business Associate shall use commercially reasonable efforts to configure production PHI storage for the Service in United States-based cloud infrastructure and shall not knowingly store production PHI outside the United States without prior notice to Covered Entity, except for transient routing, support, security, or backup activities consistent with HIPAA and the Service documentation.
5.4 Reporting of Breaches. Business Associate shall report to Covered Entity any Breach of Unsecured Protected Health Information, and any security breach involving PHI or personal information for which Business Associate is required to notify Covered Entity under applicable breach-notification law, without unreasonable delay and in no event later than ten (10) calendar days after Discovery of the Breach or after Business Associate determines, or has reason to believe, that a reportable security breach occurred, as applicable. For HIPAA purposes, a Breach is treated as discovered as of the first day on which it is known to Business Associate, or by exercising reasonable diligence would have been known, in accordance with 45 C.F.R. § 164.410(a)(2). The notice shall include, to the extent known or reasonably available: (i) a brief description of what happened, including the date of the Breach or security breach and date of Discovery or determination; (ii) the types of PHI or personal information involved; (iii) the identity of each Individual whose Unsecured PHI was, or is reasonably believed to have been, involved, if available; (iv) steps Business Associate has taken or will take to investigate, mitigate harm, and protect against recurrence; and (v) information reasonably available to Business Associate that Covered Entity is required to include in notices to Individuals, the Secretary, media outlets, state regulators, or other persons. Business Associate shall provide supplemental information as it becomes available.
5.4A Primary Notification Responsibility. Unless otherwise agreed in writing or Required by Law directly applicable to Business Associate, Covered Entity retains primary responsibility for making notifications to Individuals, the Secretary, media outlets, state attorneys general, state regulators, consumer reporting agencies, and other persons or authorities. Business Associate shall reasonably cooperate with Covered Entity in Covered Entity's notification, investigation, documentation, and response obligations.
5.5 Reporting of Impermissible Uses and Security Incidents. Business Associate shall report to Covered Entity any Use or Disclosure of PHI not provided for by this Agreement and any Security Incident of which Business Associate becomes aware, without unreasonable delay and in no event later than ten (10) calendar days after Discovery, except that routine unsuccessful Security Incidents are deemed reported by this Agreement and need not be reported individually unless Business Associate determines that they resulted in unauthorized access, Use, Disclosure, modification, destruction, or interference with system operations involving PHI.
5.6 Mitigation and Cooperation. Business Associate shall mitigate, to the extent practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI by Business Associate in violation of this Agreement. Business Associate shall reasonably cooperate with Covered Entity in Covered Entity's breach-risk assessment, notification, investigation, documentation, and response obligations under HIPAA.
5.7 Individual Rights Support. To the extent PHI in Business Associate's possession constitutes part of Covered Entity's Designated Record Set and is not available directly to Covered Entity through the Service, Business Associate shall, at Covered Entity's written request and within a reasonable time, make PHI available to Covered Entity as necessary for Covered Entity to satisfy Individual rights of access under 45 C.F.R. § 164.524, amendment under 45 C.F.R. § 164.526, and accounting of disclosures under 45 C.F.R. § 164.528. Business Associate may satisfy this obligation by making PHI available through export, administrative tools, or reasonable support assistance.
5.8 Covered Entity Functions. To the extent Business Associate expressly agrees to carry out an obligation of Covered Entity under Subpart E of 45 C.F.R. Part 164, Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation.
5.9 Access by Secretary. Business Associate shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary for purposes of determining compliance with HIPAA.
5.10 Workforce. Business Associate shall limit Business Associate workforce access to PHI to personnel with a need to know for authorized purposes and shall provide appropriate privacy and security training or instructions to such personnel.
Subcontractors
6.1 Authorization to Use Subcontractors. Covered Entity authorizes Business Associate to use Subcontractors to provide, secure, support, maintain, and improve the Service, provided that Business Associate complies with this Section 6.
6.2 Flow-Down Agreements. Before permitting a Subcontractor to create, receive, maintain, or transmit PHI on behalf of Business Associate, Business Associate shall obtain a written business associate agreement or other written arrangement that requires the Subcontractor to agree to the same restrictions and conditions that apply to Business Associate with respect to PHI, including compliance with the applicable requirements of the HIPAA Security Rule and reporting of Breaches, impermissible Uses or Disclosures, and Security Incidents to Business Associate.
6.3 Cloud, Email, and SMS Vendors. Business Associate shall not knowingly route PHI through, store PHI with, or permit PHI to be created, received, maintained, or transmitted by a cloud hosting, email delivery, SMS/messaging, storage, support, or similar vendor unless that vendor has executed a HIPAA-compliant business associate agreement with Business Associate or Business Associate has reasonably determined that the vendor does not create, receive, maintain, or transmit PHI. A vendor that maintains encrypted ePHI on behalf of Business Associate is treated as a Subcontractor even if the vendor does not possess the decryption key.
6.4 Subcontractor Issues. If Business Associate knows of a pattern of activity or practice of a Subcontractor that constitutes a material breach or violation of the Subcontractor's obligations with respect to PHI, Business Associate shall take reasonable steps to cure the breach or end the violation and, if such steps are unsuccessful, terminate the applicable arrangement if feasible.
6.5 Subcontractor Information. Upon Covered Entity's reasonable written request, Business Associate will provide a summary of its material categories of Subcontractors that create, receive, maintain, or transmit PHI for the Service, subject to confidentiality, security, and legal restrictions.
Obligations of Covered Entity
7.1 Compliance. Covered Entity shall Use the Service and provide PHI to Business Associate in compliance with HIPAA and all other applicable laws. Covered Entity shall not request or direct Business Associate to Use or Disclose PHI in a manner that would violate HIPAA if done by Covered Entity.
7.2 Authority and Notices. Covered Entity represents that it has authority to disclose PHI to Business Associate for the purposes contemplated by this Agreement and has provided all required notices and obtained any consents, authorizations, opt-ins, or permissions required by HIPAA, state law, communication laws, or Covered Entity's policies for its Use of the Service, patient intake forms, electronic signatures, email or SMS communications, and related workflows.
7.3 Restrictions and Changes. Covered Entity shall notify Business Associate in writing of: (i) any limitation in Covered Entity's Notice of Privacy Practices; (ii) any restriction on the Use or Disclosure of PHI agreed to or required under HIPAA; (iii) any change in or revocation of an Individual's permission; and (iv) any special handling requirement applicable to PHI, in each case to the extent such limitation, restriction, change, revocation, or requirement may affect Business Associate's Use or Disclosure of PHI. Business Associate is not responsible for complying with a restriction or special handling instruction until Business Associate has received written notice and had a reasonable opportunity to implement the instruction. If implementation is not technically or operationally feasible, Business Associate may decline or suspend the affected processing to the extent permitted by law and the applicable commercial agreement.
7.4 Configuration and Users. Covered Entity is responsible for configuring the Service, intake questions, templates, routing, user roles, exports, and communication settings in a HIPAA-compliant manner; limiting its users' access to the minimum necessary; disabling access for terminated users; maintaining the confidentiality of login credentials; and reviewing PHI before using it for clinical or administrative purposes.
7.5 Email and SMS. Covered Entity is responsible for determining whether and to what extent patient email or SMS communications may include PHI, for obtaining patient communication consents and preferences, and for configuring message content to limit PHI. Unless otherwise agreed, Business Associate is not responsible for the content of messages configured by Covered Entity or for Covered Entity's compliance with the Telephone Consumer Protection Act, CAN-SPAM Act, state mini-TCPA laws, professional rules, or other non-HIPAA communication requirements.
7.6 No Unnecessary PHI in Support Channels. Covered Entity shall not include PHI in support tickets, emails, chat, screenshots, or other support communications unless reasonably necessary and transmitted through a secure channel designated by Business Associate.
7.7 Special Categories. Covered Entity shall not configure the Service to collect, transmit, or store substance use disorder records subject to 42 C.F.R. Part 2, psychotherapy notes, genetic information, minor-consent records, reproductive health information subject to special restrictions, or other specially protected information unless Covered Entity has determined that its use of the Service complies with applicable law, has obtained all required consents, authorizations, notices, or permissions, and has notified Business Associate in writing of any restriction or workflow requirement that Business Associate must implement.
Term and Termination
8.1 Term. This Agreement begins on the Effective Date and remains in effect until all PHI is returned, destroyed, or protected in accordance with Section 8.4.
8.2 Termination for Cause by Covered Entity. Covered Entity may terminate this Agreement and the applicable Service relationship if Business Associate materially breaches this Agreement and fails to cure the breach within thirty (30) days after written notice, or within a shorter period if required by HIPAA or if cure is not reasonably possible.
8.3 Termination by Business Associate. If Business Associate determines that a request or instruction from Covered Entity would require Business Associate to violate HIPAA or other applicable law, Business Associate may refuse to follow the instruction and may suspend the affected activity. If Covered Entity does not withdraw or modify the instruction after notice, Business Associate may terminate the affected Service relationship to the extent permitted by applicable law and the parties' commercial agreement.
8.4 Return or Destruction of PHI. Upon termination or expiration of the Service or this Agreement for any reason, Business Associate shall, if feasible, return to Covered Entity or destroy PHI that Business Associate still maintains in any form and retain no copies. Business Associate may satisfy return obligations by making PHI available for export through the Service or another reasonable secure method for thirty (30) days after termination, unless a different period is stated in the applicable Service terms or order form. Covered Entity is responsible for exporting PHI during the export period. After the export period, Business Associate may delete PHI in accordance with this Agreement, the Service terms, and its ordinary deletion and backup-retention practices.
8.5 Infeasible Return or Destruction; Backups and Logs. If return or destruction is not feasible, including PHI retained in archived backups, audit logs, legal holds, disaster recovery systems, or records required by law, Business Associate shall extend the protections of this Agreement to such PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible for so long as Business Associate maintains such PHI. PHI in backups will be deleted, overwritten, or rendered inaccessible in accordance with Business Associate's ordinary backup retention cycle and will not be restored to production except as necessary for disaster recovery, legal compliance, security, or integrity purposes.
8.6 Certificate. Upon Covered Entity's reasonable written request, Business Associate will provide a written certification or confirmation of return or destruction when return or destruction has been completed, subject to the infeasibility exceptions in Section 8.5.
Data Ownership and Retained Rights
9.1 PHI. As between the Parties, PHI remains the property and responsibility of Covered Entity or the applicable Individual. Business Associate obtains no ownership rights in PHI by virtue of this Agreement.
9.2 Service Data. Business Associate owns the Service, software, documentation, templates supplied by Business Associate, usage metrics, aggregated operational data, and de-identified information created in accordance with HIPAA, excluding PHI.
Audit and Compliance Assistance
10.1 Documentation. Upon reasonable written request, Business Associate will provide Covered Entity with available documentation reasonably necessary to demonstrate Business Associate's compliance with this Agreement, such as a security overview, responses to reasonable security questionnaires, summaries of applicable policies, or third-party security reports if available.
10.2 Limits. Business Associate is not required to provide direct access to systems, facilities, source code, confidential security information, personnel records, other customers' information, or information that would compromise security or confidentiality. Any enhanced audit, penetration test, onsite review, or customer-specific compliance deliverable must be agreed in a separate written agreement and may be subject to additional fees and confidentiality restrictions.
Electronic Acceptance; Incorporation
11.1 Electronic Acceptance. The Parties consent to transact electronically. Covered Entity's affirmative electronic acceptance of this Agreement, including through a clickwrap, checkbox, account-creation, order-form, or substantially similar online workflow, is binding and has the same force and effect as a manual signature if the workflow reasonably identifies the agreement being accepted and gives Covered Entity a reasonable opportunity to review and retain it. No wet-ink signature or countersignature is required for this Agreement to be effective.
11.2 Authority. The individual accepting this Agreement for Covered Entity represents that he or she is authorized to bind Covered Entity to this Agreement, the carelinkMD Terms and Conditions, and any applicable order form or service terms.
11.3 Acceptance Records. Business Associate may maintain records of electronic acceptance, including the accepted version, account owner name, clinic name, email address, IP address, timestamp, user-agent or device information, and related audit metadata. Covered Entity agrees that those records are business records admissible to evidence acceptance, attribution, version control, and the Effective Date of this Agreement.
11.4 Availability of Terms. Business Associate shall make this Agreement available to Covered Entity before or at the time of acceptance in a form capable of being retained by Covered Entity, such as a downloadable or printable webpage or PDF/DOCX copy.
11.5 Order of Precedence. This Agreement supplements and is incorporated into the carelinkMD Terms and Conditions and any applicable order form or service agreement. In the event of a conflict, this Agreement controls with respect to PHI and HIPAA matters, and the Terms and Conditions control with respect to non-PHI commercial matters unless this Agreement expressly states otherwise.
11.6 SaaS Signup Mechanics. Business Associate may condition account creation, access to PHI functionality, or continued use of the Service on electronic acceptance of this Agreement. Covered Entity agrees that incorporation by a clear hyperlink, versioned electronic record, or order-form reference is sufficient to incorporate this Agreement into the Service relationship, provided that Covered Entity is given a reasonable opportunity to review and retain the Agreement before or at acceptance.
Limitation of Liability
12.1 General Cap. To the maximum extent permitted by applicable law, and except as provided in Section 12.1A, Business Associate's aggregate liability arising out of or relating to this Agreement or the Service shall not exceed the greater of: (i) the fees paid or payable by Covered Entity to Business Associate for the Service during the twelve (12) months preceding the event giving rise to liability; or (ii) Ten Thousand Dollars (US$10,000).
12.1A Data Protection Cap. Notwithstanding Section 12.1, Business Associate's aggregate liability for all claims arising out of or relating to a Breach of Unsecured PHI, a Security Incident, or Business Associate's material violation of its safeguards or other HIPAA obligations under this Agreement, including reimbursement of Covered Entity's reasonable and documented breach-notification, forensic-investigation, call-center, credit-monitoring, and regulatory-response costs to the extent recoverable under this Agreement (collectively, "Data Protection Claims"), shall not exceed the greater of: (i) three (3) times the fees paid or payable by Covered Entity to Business Associate for the Service during the twelve (12) months preceding the event giving rise to liability; or (ii) Fifty Thousand Dollars (US$50,000) (the "Data Protection Cap"). The Data Protection Cap is the sole cap for Data Protection Claims. The caps in Sections 12.1 and 12.1A are separate and are not additive.
12.1B Insurance. Business Associate shall not be deemed to maintain, and is not required by this Agreement to maintain, cyber, privacy, or technology errors-and-omissions liability insurance unless Business Associate expressly agrees to an insurance obligation in an order form, service agreement, or the carelinkMD Terms and Conditions. If Business Associate maintains such insurance, Business Associate may provide evidence of coverage upon Covered Entity's reasonable written request, subject to confidentiality, policy terms, and insurer requirements.
12.2 Exclusion of Damages. To the maximum extent permitted by applicable law, neither Party shall be liable to the other for indirect, incidental, consequential, special, exemplary, punitive, multiplied, or enhanced damages, or for lost profits, lost revenue, loss of goodwill, reputational harm, or business interruption, even if the Party was advised of the possibility of such damages. Breach-notification expenses, regulatory-response costs, and third-party claim costs are subject to the applicable cap in Section 12.1 or 12.1A unless expressly excluded by Section 12.3.
12.3 Exclusions from Cap. The limitations in this Section 12 do not limit: (i) Covered Entity's payment obligations; (ii) Covered Entity's indemnification obligations under Section 13; (iii) a Party's liability for gross negligence, fraud, willful misconduct, or intentional unauthorized sale or disclosure of PHI; (iv) equitable relief; or (v) civil monetary penalties, corrective action obligations, or other remedies imposed directly by a governmental authority to the extent such liability cannot be limited by contract. As between the Parties, however, contractual damages, reimbursement, and indemnification remain subject to this Section 12 except to the extent expressly excluded above.
12.4 Allocation of Risk. The Parties agree that the limitations in this Section 12 are a material basis of the bargain and apply regardless of the form of action, whether in contract, tort, negligence, strict liability, statute, indemnity, or otherwise, and regardless of whether any limited remedy fails of its essential purpose.
Indemnification
13.1 Indemnification by Covered Entity. Covered Entity shall defend, indemnify, and hold harmless Business Associate and its members, managers, officers, employees, contractors, and agents from and against any third-party claim, investigation, penalty, fine, loss, liability, damage, cost, or expense, including reasonable attorneys' fees, arising out of or relating to: (i) Covered Entity's violation of HIPAA or other applicable law; (ii) Covered Entity's instructions, configurations, templates, intake questions, message content, exports, or Use of the Service; (iii) Covered Entity's failure to obtain required notices, consents, authorizations, opt-ins, or permissions; (iv) unauthorized access or misuse by Covered Entity's users or workforce; (v) PHI or other data supplied by Covered Entity; or (vi) Covered Entity's clinical, billing, patient communication, medical record, or professional obligations.
13.2 Limited Indemnification by Business Associate. Subject to Section 12, Business Associate shall defend and indemnify Covered Entity from third-party claims to the extent finally determined to have been caused by Business Associate's material breach of this Agreement or violation of HIPAA in its capacity as Business Associate, except to the extent the claim arises from Covered Entity's acts or omissions, instructions, configurations, data, users, communication choices, or failure to comply with law.
13.3 Procedures. The indemnified Party shall promptly notify the indemnifying Party of any claim, provide reasonable cooperation at the indemnifying Party's expense, and allow the indemnifying Party to control the defense and settlement of the claim. The indemnifying Party may not settle any claim in a manner that admits fault by the indemnified Party or imposes non-monetary obligations on the indemnified Party without the indemnified Party's prior written consent, not to be unreasonably withheld. Failure to give prompt notice reduces the indemnifying Party's obligations only to the extent materially prejudiced by the delay.
Notices
14.1 Notices to Business Associate. Privacy, security, breach, and legal notices to Business Associate shall be sent to: Expert Business Consulting LLC d/b/a carelinkMD, 1200 Riverplace Blvd, Suite 105-1282, Jacksonville, Florida 32207, Attn: Legal/Privacy, email: r.babu@carelinkmd.com, or to any updated notice address or email designated by Business Associate in the Service.
14.2 Notices to Covered Entity. Notices to Covered Entity may be sent to the account owner, administrator, billing contact, email address, or notice address provided by Covered Entity through the Service or in an order form.
Miscellaneous
15.1 Amendment for Compliance. The Parties shall amend this Agreement as reasonably necessary to comply with HIPAA or other applicable law. Business Associate may update this Agreement by making a revised version available through the Service; material changes that materially reduce Covered Entity's rights with respect to PHI will not apply to Covered Entity until accepted electronically or otherwise agreed, except to the extent required by law.
15.2 Regulatory References. A reference to a statute or regulation means the statute or regulation as amended, re-codified, or superseded.
15.3 Interpretation. Any ambiguity in this Agreement shall be interpreted to permit the Parties to comply with HIPAA. Nothing in this Agreement shall be construed to require either Party to violate HIPAA or other applicable law.
15.4 No Third-Party Beneficiaries. This Agreement is for the benefit of the Parties and their permitted successors and assigns only and does not create any third-party beneficiary rights.
15.5 Assignment. Covered Entity may not assign this Agreement without Business Associate's prior written consent, except in connection with a merger, acquisition, reorganization, or sale of substantially all assets if the assignee assumes Covered Entity's obligations. Business Associate may assign this Agreement in connection with a merger, acquisition, reorganization, sale of substantially all assets, financing, or change of control.
15.6 Severability. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions will remain in effect, and the invalid or unenforceable provision will be modified to the minimum extent necessary to make it valid and enforceable.
15.7 Governing Law. This Agreement is governed by the laws of the State of Florida, without regard to conflicts-of-law principles, except to the extent preempted by federal law. Each Party irrevocably submits to the exclusive jurisdiction and venue of the state and federal courts located in Duval County, Florida for any dispute arising out of or relating to this Agreement, and waives any objection to such venue on the basis of forum non conveniens. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EACH PARTY WAIVES ANY RIGHT TO A TRIAL BY JURY IN ANY SUCH DISPUTE. Nothing in this Agreement limits the statutory rights or remedies of any patient, the Secretary, or any other governmental authority under HIPAA or other applicable law, including the Florida Information Protection Act of 2014 (Fla. Stat. § 501.171).
15.8 Survival. Sections relating to PHI retained after termination, confidentiality, return or destruction, limitation of liability, indemnification, interpretation, and any other provisions that by their nature should survive will survive termination or expiration of this Agreement.
15.9 Entire Agreement. This Agreement, together with the carelinkMD Terms and Conditions and any applicable order form or service agreement, constitutes the complete agreement between the Parties regarding PHI and supersedes prior or contemporaneous understandings on that subject.
Acceptance and Signature Blocks
Covered Entity may accept this Agreement electronically through the Service. The following signature block may be used for manual execution if the Parties elect to sign manually.
COVERED ENTITY:
Legal Name: ____________________________________________
Authorized Signatory Name/Title: ___________________________
Signature: __________________________________ Date: _______
BUSINESS ASSOCIATE:
Expert Business Consulting LLC d/b/a carelinkMD
Authorized Signatory Name/Title: ___________________________
Signature: __________________________________ Date: _______