Business Associate Agreement

Version 2026-08-15

This Business Associate Agreement (“Agreement”) is entered into between you, on behalf of the practice or organization you represent (“Covered Entity”), and Practicepicnic (“Business Associate”). It is effective when you accept it at sign-up and applies to all Services provided by Business Associate.

Capitalized terms not defined here have the meanings given in HIPAA and its implementing regulations at 45 C.F.R. Parts 160 and 164.

1. Term

This Agreement remains in effect for the duration of the relationship between Business Associate and Covered Entity and applies to all Services delivered during that period.

2. Permitted Uses and Disclosures

Business Associate may use and disclose PHI only:

  1. To perform the Services for Covered Entity, as described in the Terms and Conditions;
  2. For the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any disclosure for those purposes is either required by law or made only after Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially, used only as required by law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality;
  3. To de-identify PHI in accordance with Section 8; and
  4. As otherwise required by law.

Business Associate will not use or disclose PHI in any manner that would violate HIPAA if done by Covered Entity, and will limit uses, disclosures, and requests to the minimum necessary as required by 45 C.F.R. 164.502(b).

3. HIPAA Assurances

Where Business Associate creates, receives, maintains, or transmits PHI on behalf of Covered Entity, Business Associate shall:

  1. Recognize that the HITECH Act and the regulations thereunder, including 45 C.F.R. 164.308, 164.310, 164.312, and 164.316, apply to a business associate in the same manner they apply to a covered entity;
  2. Use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided by this Agreement;
  3. Comply with each applicable requirement of 45 C.F.R. Part 162 if Business Associate conducts Standard Transactions on behalf of Covered Entity;
  4. Report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, any Security Incident, and any Breach of Unsecured PHI as required by 45 C.F.R. 164.410, without unreasonable delay and in no case later than thirty (30) calendar days after discovery. The report will include, to the extent known at the time, the identification of each individual whose PHI was involved, a description of what happened, the types of information involved, and the steps Business Associate is taking to investigate and mitigate;
  5. Ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as protective as those in this Agreement, as required by 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2);
  6. Make PHI in a Designated Record Set available to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. 164.524, and, if an individual makes a request directly to Business Associate, notify Covered Entity within ten (10) business days and allow Covered Entity to respond;
  7. Make PHI in a Designated Record Set available for amendment and incorporate amendments as directed by Covered Entity, as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. 164.526;
  8. Document and make available disclosures of PHI and related information as necessary for Covered Entity to respond to a request for an accounting of disclosures under 45 C.F.R. 164.528, covering the six (6) years preceding the request and including the date of disclosure, the name of the recipient, a brief description of the PHI disclosed, and a brief statement of the purpose and basis of the disclosure; and
  9. Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.

Security Incidents. For purposes of subsection (4), “Security Incident” does not include unsuccessful attempts to gain unauthorized access to, or to use, disclose, modify, or destroy, electronic PHI or to interfere with system operations, where those attempts do not result in unauthorized access. Examples include pings and other broadcast attacks on firewalls, port scans, unsuccessful log-on attempts, denial of service attempts that do not result in a server being taken offline, and malware that is blocked. This paragraph constitutes notice of the ongoing existence of such attempts, and no additional notice is required.

4. Obligations of Covered Entity

Covered Entity shall notify Business Associate of any limitation in its Notice of Privacy Practices, any change in or revocation of an individual’s authorization, and any restriction on the use or disclosure of PHI agreed to under 45 C.F.R. 164.522, to the extent any of these may affect Business Associate’s use or disclosure of PHI.

Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.

Covered Entity is solely responsible for obtaining any consent or authorization required by law before recording a session or otherwise submitting PHI to the Services.

5. Termination for Breach

Covered Entity may terminate this Agreement if it determines that Business Associate has materially breached it. Covered Entity may give written notice of the breach and allow Business Associate thirty (30) days to cure. Covered Entity may also immediately stop further disclosures of PHI to Business Associate if it reasonably determines that Business Associate has breached its obligations.

Business Associate may terminate this Agreement if it determines that Covered Entity has materially breached it and has not cured within thirty (30) days of written notice.

Termination of this Agreement terminates Covered Entity’s right to use the Services, and termination of the Services terminates this Agreement.

If termination is not feasible, Business Associate acknowledges that Covered Entity may report the breach to the Secretary of the U.S. Department of Health and Human Services.

6. Return or Destruction of PHI

On termination, unless otherwise directed by Covered Entity, Business Associate will return or destroy the PHI it maintains on behalf of Covered Entity, following the export period described in the Terms and Conditions.

Copies of PHI may persist in encrypted backup media after deletion from production systems. Business Associate deletes those copies as the backups age out of its retention cycle, and PHI in backups remains subject to this Agreement until deleted.

If Business Associate determines that return or destruction is otherwise infeasible, it will notify Covered Entity of the conditions making it so. The terms of this Agreement survive as to any PHI retained, and that PHI will be used or disclosed solely as permitted by law for as long as Business Associate maintains it.

7. No Third Party Beneficiaries

This Agreement is for the benefit of the parties only.

8. De-Identified Data and Artificial Intelligence

No training. Business Associate does not use PHI, session audio, transcripts, clinical documentation, or any other Customer Data to train, fine-tune, evaluate, or otherwise develop any artificial intelligence or machine learning model, and does not permit its subcontractors to do so. Session audio is transcribed by a model operated by Business Associate on its own infrastructure and is not disclosed to any third-party transcription service. Where Business Associate uses third-party artificial intelligence services, it does so under agreements that prohibit the service provider from using inputs or outputs to train models or from sharing them with model providers.

De-identification. Business Associate may create de-identified information from PHI, and may use and disclose such information, only where the de-identification meets the standard in 45 C.F.R. 164.514(a) through (c), by either (i) removal of all identifiers listed in 164.514(b)(2) with no actual knowledge that the remaining information could be used to identify an individual, or (ii) a documented determination by a qualified expert under 164.514(b)(1). Business Associate will not attempt to re-identify de-identified information or disclose any key or mechanism enabling re-identification.

9. Order of Precedence

Where this Agreement conflicts with the Terms and Conditions with respect to PHI, this Agreement controls. In all other respects the Terms and Conditions apply, including their limitation of liability, which applies to claims arising under this Agreement except where a limitation is prohibited by law.

10. Amendment

The parties agree to amend this Agreement to the extent necessary for either party to comply with the Privacy Standards, the Standards for Electronic Transactions, the Security Standards, or other applicable state or federal law. Business Associate may propose amendments by publishing a revised version and requesting acceptance.

11. Interpretation

Any ambiguity in this Agreement will be resolved in favor of a meaning that permits Covered Entity to comply with the then-current version of HIPAA and its implementing regulations.

12. Records Subject to 42 C.F.R. Part 2

The Services are not intended for records subject to 42 C.F.R. Part 2 governing the confidentiality of substance use disorder patient records, and Business Associate makes no representation that the Services meet the requirements of Part 2. Covered Entity will not submit Part 2 records to the Services without a separate written agreement with Business Associate.

13. Governing Law and Survival

This Agreement is governed by the laws of the State of Iowa. The obligations imposed by this Agreement survive its expiration or termination.

14. Acceptance

Covered Entity accepts this Agreement electronically at sign-up. Business Associate maintains a record of that acceptance, including the accepting user and the date. Each version carries a version identifier at the top of this page, and prior versions are available on request.

Practicepicnic is the registered trade name of Blobbackup, LLC, an Iowa limited liability company, which is the contracting party under this Agreement. Notices may be sent to Practicepicnic, c/o Blobbackup, LLC, 15920 Hickman Rd, Ste 400 #448, Clive, IA 50325.