Business Associate Addendum for Verbit Customers
This Business Associate Addendum (“BAA”) supplements the Verbit Terms of Use available at https://verbit.ai/terms-and-conditions/, or any other Master Services Agreement entered between the Parties together with any Order incorporating the same (collectively, the “Agreement”). This BAA becomes effective and binding on the Parties, without the need for any further signature, upon the selection of the “HIPAA Compliant” option (or its equivalent) on an applicable Order or statement of work (“SOW”), and applies with respect to each Covered Service ordered thereunder as identified in Annex A hereto (“Service Schedule”). The Agreement governs Customer’s use of the Covered Services. Capitalized terms used and not specifically defined herein shall have the same meaning as in the Agreement. “Business Associate,” as used herein, shall be deemed to refer to Supplier.
I. DEFINITIONS AND GENERAL TERMS.
- Pursuant to the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act of 2009, and the American Recovery and Reinvestment Act of 2009 (as amended, and including its promulgating regulations, collectively referred to herein as “HIPAA”), this BAA addresses the Parties’ obligations under HIPAA with respect to “business associates,” as defined under the privacy, security, breach notification, and enforcement rules at 45 C.F.R. Part 160 and Part 164 (“HIPAA Rules”). A reference in this BAA to a section in the HIPAA Rules means the section as in effect or as amended.
- This BAA is intended to ensure that (i) Business Associate will establish and implement appropriate privacy, security, and data breach related safeguards for the Protected Health Information (as defined under the HIPAA Rules, “PHI”) that Business Associate may receive, create, maintain, use, or disclose in connection with the functions, activities, and services that Business Associate performs for or on behalf of Customer or any authorized user of Customer’s Account that comprise the Covered Services set forth in the Service Schedule attached hereto, to the extent of and subject to the rights, requirements, and limitations set forth therein, and (ii) Customer only transfers, discloses, or provides Business Associate with access to PHI as set forth in this BAA and through the use of Covered Services in accordance with the Conditions of Use, as set forth in the Service Schedule attached hereto. All obligations hereunder shall be construed to relate solely to the provision of the Covered Services by Business Associate and the use of Covered Services by Customer, and only with respect to the current version and other supported versions of the Services at the time of use. Notwithstanding anything to the contrary, deprecated and unsupported versions of the Services shall not be deemed to be Covered Services.
- Unless the context clearly indicates otherwise, the following terms in this BAA shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, disclosure, Electronic Media, Electronic Protected Health Information (ePHI), Health Care Operations, individual, Minimum Necessary, Notice of Privacy Practices, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured PHI, and Use.
- Unless the context clearly indicates otherwise, the capitalized terms in this BAA shall have the same meaning as those terms in the Agreement.
- A reference in this BAA to the Privacy Rule refers to the portions of 45 C.F.R. Part 160 and Subparts A and E of Part 164 that apply to a business associate (the “Privacy Rule”).
- A reference in this BAA to the Security Rule refers to the portions of 45 C.F.R. Part 160 and Subparts A and C of Part 164 that apply to a business associate (the “Security Rule”).
- Customer understands and agrees that Authorized Users shall be bound to comply with all of Customer’s obligations under this BAA. Any breach of this BAA by any of Customer’s Authorized Users shall qualify as a breach by Customer.
II. GENERAL OBLIGATIONS OF BUSINESS ASSOCIATE.
- Business Associate agrees to receive, create, use, and disclose PHI only in a manner that (i) is consistent with this BAA and the HIPAA Rules and only in connection with providing services to Customer, and (ii) would not violate the HIPAA Rules, including 45 C.F.R. 164.504(e), if the use or disclosure would be done by Customer. Notwithstanding the foregoing, Business Associate may use or disclose PHI as Required By Law.
- Business Associate agrees to make only the minimum necessary uses, disclosures, and requests for PHI where required to do so by the HIPAA Rules.
- Business Associate agrees to use appropriate safeguards and to comply with the Security Rule with respect to ePHI and to prevent use or disclosure of PHI other than as provided for by this BAA.
- Business Associate agrees to mitigate, to the extent practicable and in any manner Required By Law, any harmful effect that is known to Business Associate as a result of a use or disclosure of PHI by Business Associate in violation of this BAA’s requirements.
- Business Associate agrees to report to Customer any Breach of Unsecured PHI by Business Associate of which it becomes aware without unreasonable delay, where a report is required by 45 C.F.R. 164.410. Business Associate’s notification of a Breach of Unsecured PHI under this Section shall comply in all material respects with the HIPAA Rules. Business Associate also agrees to report to Customer, without unreasonable delay after becoming aware, (i) any use or disclosure of PHI not provided for by this BAA of which it becomes aware, and (ii) any Security Incident that results in unauthorized access to, or the unauthorized use, disclosure, modification, or destruction of, ePHI. Business Associate hereby provides and Customer hereby acknowledges this general notice of the ongoing occurrence of attempted or unsuccessful or immaterial Security Incidents that do not result in Breach of Unsecured PHI.
- Business Associate agrees, in accordance with 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, to require that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of the Business Associate in connection with Business Associate’s provision of services to Customer agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such information.
- If Required By Law, Business Associate agrees to make available PHI in a Designated Record Set to, at Customer’s sole option, either Customer or the individual or individual’s designee, as necessary to satisfy Customer’s obligations under 45 C.F.R. 164.524. Business Associate agrees to make any amendments to PHI in a Designated Record Set as directed or agreed to by Customer pursuant to 45 C.F.R. 164.526, or to take other measures as necessary to satisfy Customer’s obligations under 45 C.F.R. 164.526, at Customer’s cost and expense. Nothing herein shall be construed to impose a duty on Business Associate to retain PHI.
- Business Associate agrees to comply with an individual’s request to restrict the disclosure of their personal PHI where such request has been communicated to Business Associate in a manner consistent with 45 C.F.R. 164.522, except where such use, disclosure, or request is required or permitted under applicable law.
- Business Associate agrees to maintain and make available the information required to provide an accounting of disclosures to, at Customer’s sole option, either Customer or the individual or individual’s designee, as necessary to satisfy Customer’s obligations under 45 C.F.R. 164.528.
- Business Associate agrees to make its internal practices, books, and records, including policies and procedures regarding PHI, relating to the use and disclosure of PHI and Breach of any Unsecured PHI received from Customer, or created or received by the Business Associate on behalf of Customer, available to Customer (or the Secretary) for the purpose of Customer or the Secretary determining compliance with the HIPAA Rules. Customer shall be responsible for reasonable costs incurred by Business Associate in connection with any request by Customer or the Secretary made pursuant to this Section.
- To the extent Business Associate is to carry out one or more of Customer’s obligation(s) under Subpart E of 45 C.F.R. Part 164, Business Associate agrees to comply with the requirements of Subpart E that apply to Customer in the performance of such obligation(s).
- Notwithstanding anything to the contrary herein, Customer acknowledges and agrees that Business Associate’s obligations and responsibilities herein are limited to transmission, use, storage, and disclosure of PHI pursuant to Customer’s use of Covered Services strictly in accordance with the requirements and limitations of this BAA, including applicable Service Schedules; and that Business Associate shall bear no responsibility for use or storage of PHI on systems outside of Business Associate’s reasonable control (for example, local storage or cloud storage by Customer, Authorized Users, or third parties).
III. OBLIGATIONS OF CUSTOMER.
- To the extent it creates any potential impact on Business Associate’s use or disclosure of PHI hereunder, Customer shall: (i) provide Business Associate with the Notice of Privacy Practices that Customer produces in accordance with the Privacy Rule, and any changes or limitations to such notice under 45 C.F.R. 164.520; (ii) notify Business Associate of any restriction to the use or disclosure of PHI that Customer has agreed to or is required to abide by under 45 C.F.R. 164.522; and (iii) notify Business Associate of any changes in or revocation of permission by an individual to use or disclose PHI.
- Customer is solely responsible for ensuring that it does not (and it does not cause patients to) use Covered Services to disclose, use, transmit, or store PHI, except as permitted in connection with the requirements of both this BAA and HIPAA, and shall defend, indemnify, and hold Supplier harmless against any claims or losses arising from breach of the foregoing.
- Customer acknowledges and agrees that the Covered Services may be accessed and used through Customer’s own systems, accounts, integrations, and environments. Customer further acknowledges and agrees that it is solely responsible for ensuring that any such system, account, integration, or environment, and its configuration and use of the Covered Services, comply with Customer’s obligations under HIPAA, including specifically that (i) where Customer is required by applicable law to use a HIPAA-compliant service or configuration, Customer is solely responsible for selecting and enabling the applicable HIPAA-compliant option (including by checking the “HIPAA Compliant” box on the applicable Order or SOW); and (ii) Customer is solely responsible for following appropriate security practices when transmitting Files and other content to, and accessing transcripts and other output from, the Covered Services.
- Customer shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Customer.
IV. TERM AND TERMINATION.
- This BAA shall be in effect with respect to each Covered Service in accordance with the applicable Service Schedule, provided that it shall terminate on the earlier of the date that (i) either Party terminates this BAA for material breach, or (ii) the Agreement is terminated.
- Upon either Party’s knowledge of a material breach by the other Party, the non-breaching Party shall provide an opportunity for the breaching Party to cure the breach or end the violation. If the breaching Party does not cure the breach or end the violation within a reasonable timeframe, not to exceed thirty days from the notification of the breach, or if a material term of the BAA has been breached and a cure is not possible, the non-breaching Party may terminate this BAA and the Agreement upon written notice to the breaching Party.
- Upon termination of this BAA for any reason, the Parties agree that Business Associate shall return to Customer or, if expressly agreed to in writing by Customer, destroy all PHI received from or on behalf of Customer, or created, maintained, or received by Business Associate on behalf of Customer, which Business Associate still maintains in any form. Business Associate shall retain no copies of any PHI, except that, to the extent return or destruction of PHI is infeasible, Business Associate shall extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for so long as Business Associate retains such PHI. Without limiting the foregoing, Business Associate may retain (i) PHI contained in routine, secured back-up or disaster-recovery media or system-generated logs that cannot be selectively deleted in the ordinary course, until such media or logs are cycled out and overwritten in the ordinary course of business, during which period Business Associate shall not access, use, or disclose such PHI except as necessary to maintain the applicable back-up or logging function or as Required By Law; and (ii) de-identified data created in accordance with 45 C.F.R. § 164.514(a)-(b).
V. MISCELLANEOUS
- As between Customer and Business Associate, all PHI subject to this BAA shall remain the sole property of Customer.
- The Parties agree to take such action as is necessary to amend this BAA to comply with the requirements of the Privacy Rule, the Security Rule, HIPAA, ARRA, the HITECH Act, the HIPAA Rules, and any other applicable law.
- This BAA constitutes the entire agreement between the Parties related to the subject matter of this BAA, except to the extent that the Agreement imposes more stringent requirements related to the use and protection of PHI upon Business Associate. This BAA supersedes all prior negotiations, discussions, representations, or proposals, whether oral or written. Business Associate may amend this BAA in accordance with the amendment provisions of the Agreement, including by posting an updated version at the URL referenced above, and any such amendment shall comply with the requirements of the HIPAA Rules. If any provision of this BAA, or part thereof, is found to be invalid, the remaining provisions shall remain in effect.
- This BAA will be binding on the permitted successors and permitted assignees of Customer and the Business Associate. However, this BAA may not be assigned, in whole or in part, by Customer without the written consent of the Business Associate. Any attempted assignment in violation of this provision shall be null and void.
- Except to the extent preempted by federal law, this BAA shall be governed by and construed in accordance with the same internal laws as that of the Agreement.
- The limitations of liability, exclusions and disclaimers of damages, and related risk-allocation provisions set forth in the Agreement shall apply to this BAA and to any claim arising out of or relating to this BAA, including any claim relating to PHI, and the subject matter of this BAA shall be deemed part of the Agreement for purposes of such provisions, in each case except to the extent expressly provided otherwise in the Agreement.
- This BAA does not create, and shall not be construed to create, any rights in any third party, including any individual whose PHI is used, disclosed, created, received, maintained, or transmitted under this BAA. No such third party shall be a third-party beneficiary of this BAA or have any right to enforce any provision hereof.
ANNEX A
Service Schedule
Each of the following Services shall be deemed Covered Services only to the extent that Customer’s usage complies with all of the corresponding conditions (“Conditions of Use”) associated with such Covered Service, as set forth in the table below.
| Covered Services |
Conditions of Use |
| Legal Visor
Legal Capture
Post-Production Transcription – Legal |
- The applicable Order or SOW must have the “HIPAA Compliant” option (or its equivalent) selected at the time of the usage, and the usage must occur under the Account associated with that Order or SOW.
- The Covered Services must be used only for the processing of Files submitted by or on behalf of Customer through the Platform, and PHI must be transmitted to and received from the Covered Services only through the secure, encrypted methods made available by Supplier for that purpose.
- Customer is responsible for ensuring that it does not disclose (or cause to be disclosed) PHI to Supplier in connection with any Service, feature, channel, or use that is not designated as a Covered Service under a HIPAA-Compliant Order or SOW, including by not entering PHI into account, order, file-name, session-title, or other metadata or free-text fields not intended to carry the content being processed.
|