Business Associate Agreement
version 2026-07-18 · effective July 18, 2026
This Business Associate Agreement ("BAA") is entered into between the healthcare practice accepting it ("Covered Entity") and COYA Systems ("Business Associate") and applies to protected health information ("PHI") that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity in providing the COYA service. It is drafted to satisfy 45 CFR 164.504(e) and related provisions of the HIPAA Privacy, Security, and Breach Notification Rules.
1. Permitted uses and disclosures
Business Associate may use and disclose PHI only: (a) to provide the COYA service to Covered Entity — answering and processing calls and messages, patient intake, eligibility verification, scheduling, care-access follow-through, and related operational functions; (b) as required by law; (c) for the proper management and administration of Business Associate, provided any such disclosure is required by law or made with reasonable assurances of confidentiality and breach notification from the recipient; and (d) to de-identify PHI in accordance with 45 CFR 164.514(b), after which de-identified information is no longer PHI.
2. Prohibition on other uses
Business Associate shall not use or further disclose PHI other than as permitted by this BAA or as required by law, and shall not use PHI for marketing or sell PHI.
3. Safeguards
Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI as required by the HIPAA Security Rule (45 CFR Part 164, Subpart C), including encryption in transit (TLS 1.2 or higher) and at rest (AES-256), access controls with multi-factor authentication, segregation of PHI in a dedicated vault isolated from operational data, and audit logging of PHI access.
4. Reporting
Business Associate shall report to Covered Entity: (a) any use or disclosure of PHI not permitted by this BAA of which it becomes aware; (b) any security incident affecting electronic PHI; and (c) any breach of unsecured PHI as required by 45 CFR 164.410, without unreasonable delay and in no case later than seventy-two (72) hours after discovery, including the nature of the breach, the types of information involved, the identification of affected individuals to the extent known, steps taken to mitigate harm, and recommended actions. Business Associate shall cooperate fully with Covered Entity's breach response and reporting obligations.
5. Subcontractors
Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA, including execution of business associate agreements where required.
6. Individual rights support
To the extent Business Associate maintains PHI in a designated record set, it shall: make PHI available to Covered Entity as necessary to satisfy individuals' access rights under 45 CFR 164.524; make PHI available for amendment and incorporate amendments per 45 CFR 164.526; and provide information required for an accounting of disclosures per 45 CFR 164.528, in each case within ten (10) business days of Covered Entity's request.
7. Availability to HHS
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.
8. Minimum necessary
Business Associate shall request, use, and disclose only the minimum PHI necessary to accomplish the intended purpose, consistent with Covered Entity's minimum-necessary policies communicated to Business Associate.
9. Term and termination
This BAA is effective upon acceptance and continues until the service relationship ends. Covered Entity may terminate the service and this BAA if Business Associate materially breaches this BAA and fails to cure within thirty (30) days of written notice. Upon termination, Business Associate shall return all PHI to Covered Entity in a standard machine-readable format within fourteen (14) business days, and following confirmed export shall permanently destroy remaining copies within thirty (30) days where destruction is feasible; where return or destruction is infeasible (including audit records retained by law), the protections of this BAA extend to such PHI for as long as it is maintained, and uses are limited to those purposes that make return or destruction infeasible.
10. 42 CFR Part 2
Where Covered Entity operates a Part 2 program, records subject to 42 CFR Part 2 received by Business Associate are handled consistent with Part 2's restrictions as applicable to a qualified service organization, and Business Associate resists in judicial proceedings any effort to obtain access to such records except as permitted by Part 2.
11. Miscellaneous
Any ambiguity in this BAA shall be interpreted to permit compliance with HIPAA. References to regulations mean those regulations as amended. This BAA may be updated by Business Associate to reflect changes in law; material changes are versioned and re-presented for acceptance.