1 Parties and purpose
This Business Associate Agreement ("BAA") is between the covered entity that executes it ("Covered Entity", "you") and Efferent Media LLC, a New York limited liability company doing business as Consential ("Business Associate", "we"). It supplements the Terms of Service and takes effect when executed.
Its purpose is to satisfy 45 CFR §§ 164.502(e), 164.504(e) and 164.308(b) of the HIPAA Privacy and Security Rules, as amended by the HITECH Act and the Omnibus Rule, in relation to the Service.
2 Definitions
Capitalised terms not defined here have the meanings given in 45 CFR Parts 160 and 164 — including Breach, Designated Record Set, Individual, Protected Health Information ("PHI"), Required By Law, Security Incident, Subcontractor, and Unsecured PHI. "Service" has the meaning given in the Terms of Service.
3 The architectural position, stated first
The Service is designed so that it does not create, receive, maintain, or transmit PHI. This is not a disclaimer bolted onto a general-purpose product; it is the product's central design constraint, and the rest of this agreement should be read in light of it.
A consent record consists of ten fields. It contains no name, no email address, no telephone number, no raw IP address, no device or browser fingerprint, and no page URL, title or referrer. The omission of the URL is deliberate and load-bearing: on a medical website the path is frequently the most sensitive element on the page, because a URL naming a procedure is a health inference about the person reading it. We do not collect it, so we cannot hold it. The full field list and the full list of omissions are in DPA Schedule 1.
We nonetheless offer and will execute this BAA, for three reasons: because a covered entity may reasonably conclude a vendor in this position is a business associate; because incidental disclosure is always possible; and because a practice should not have to take a vendor's word for an architectural claim when it can have a contract instead.
Accordingly, to the extent we do create, receive, maintain, or transmit PHI on your behalf, every obligation in this BAA applies to it in full, and nothing in this section limits those obligations.
If you configure the Service to link a consent record to an identified patient in your own systems, that linkage occurs in your systems, under your control. If you send us PHI in a support ticket, an email, or an uploaded file, we will treat it under this BAA — and we would rather you did not send it at all.
4 Permitted uses and disclosures
We may use or disclose PHI only:
- to perform the Service as described in the Terms of Service and as directed by you;
- for our own proper management and administration, or to carry out our legal responsibilities;
- to provide data aggregation services relating to your health care operations, as permitted by § 164.504(e)(2)(i)(B), where you have asked for them; and
- as Required By Law.
Where we disclose PHI to a third party under (2), we will obtain reasonable assurances in writing that it will be held confidentially, used or further disclosed only as Required By Law or for the purpose it was disclosed, and that the recipient will notify us of any breach of confidentiality.
We will make uses, disclosures, and requests for PHI consistent with your minimum necessary policies and with § 164.502(b).
5 Prohibited uses
We will not use or disclose PHI other than as permitted by this BAA or as Required By Law, and we will not use or disclose it in a manner that would violate Subpart E of Part 164 if done by you, except as permitted by section 4(2) and (3).
Specifically, we will not: sell PHI; use or disclose it for marketing or fundraising; use it for our own product analytics, advertising, or lead generation; use it to train machine-learning models; or combine it with data from other customers except in a permitted data aggregation service you have asked for.
6 Safeguards
We will use appropriate administrative, physical and technical safeguards, and will comply with Subpart C of Part 164 (the Security Rule) with respect to electronic PHI, to prevent use or disclosure other than as this BAA provides. The measures in place are set out in DPA Schedule 3 and described, with dates, on our Security page.
We will mitigate, to the extent practicable, any harmful effect known to us of a use or disclosure in violation of this BAA.
7 Reporting, security incidents, and breach notification
7.1 Reporting
We will report to you any use or disclosure of PHI not provided for by this BAA of which we become aware, and any Security Incident, without unreasonable delay and in any event within five business days of discovery.
7.2 Breach of Unsecured PHI
We will notify you of any Breach of Unsecured PHI without unreasonable delay and in any event within fifteen calendar days of discovery, as required by § 164.410 — comfortably inside the outer limit at § 164.410(b), so that you retain a usable share of your own 60-day window under § 164.404.
The notice will include, to the extent known and as it becomes known: the identification of each Individual whose PHI was or is reasonably believed to have been involved; the date of the Breach and the date of discovery; a description of what happened and the types of information involved; and the steps we have taken to investigate, mitigate, and protect against recurrence.
7.3 Unsuccessful attempts
The parties acknowledge that unsuccessful attempts requiring no action — pings, port scans, blocked login attempts, denied requests — occur constantly. This section is deemed notice of them, and we will not report them individually. Nothing here excuses reporting an incident that actually compromises PHI.
8 Subcontractors
In accordance with §§ 164.502(e)(1)(ii) and 164.308(b)(2), we will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on our behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to us under this BAA.
Our current subprocessors are named in DPA Schedule 2, which states for each one whether it receives consent data. You will receive at least 30 days' written notice before we add or replace one, with the objection right in DPA section 5.
This obligation and the design constraint in section 3 work together. Because the Service is built not to receive PHI, no infrastructure provider in the current path receives PHI, and Schedule 2 says so provider by provider rather than asserting it in the abstract. If that ever stops being true for a given provider, this clause requires a signed agreement with that provider before the change is made, not afterwards.
9 Individual rights
9.1 Access — § 164.524
To the extent we hold PHI in a Designated Record Set, we will make it available to you, or at your direction to the Individual, within ten business days of your written request, so that you can meet your own 30-day obligation.
9.2 Amendment — § 164.526
We will make PHI in a Designated Record Set available for amendment, and incorporate any amendment you direct, within ten business days of your written request.
9.3 Accounting of disclosures — § 164.528
We will document disclosures of PHI and the information related to them that would be required for you to respond to a request for an accounting, and will provide that information to you within ten business days of a written request. We retain the underlying records for six years, which is the period § 164.528(a)(1) reaches back.
9.4 Your obligations carried out by us
To the extent we carry out an obligation of yours under Subpart E of Part 164, we will comply with the requirements of Subpart E that apply to you in performing it.
9.5 The append-only limit, disclosed
The consent event table is append-only: UPDATE and DELETE are revoked
at the database permission level, which is the property that makes the record worth anything as
evidence. A record therefore cannot be edited or erased in place, including by us. Where
§ 164.526 or a state statute requires an amendment, we will implement it as a linked,
dated correcting entry rather than by rewriting history, and we will say so rather than imply a
capability we deliberately removed.
10 Access by the Secretary
We will make our internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, you available to the Secretary of the US Department of Health and Human Services for purposes of determining your compliance with Subpart E of Part 164. We will notify you of such a request unless prohibited from doing so.
11 Your obligations
You will: not ask us to use or disclose PHI in any way that would violate Subpart E if done by you; notify us of any limitation in your notice of privacy practices, any change or revocation of an Individual's permission, and any restriction you have agreed to under § 164.522, to the extent any of them affects our use or disclosure of PHI; and configure the Service so that PHI is not transmitted to it beyond what section 3 contemplates.
12 Term and termination
This BAA begins on execution and continues until all PHI is returned or destroyed, or the protections in section 13 are extended to it.
You may terminate immediately if we materially breach this BAA and fail to cure within 30 days of written notice, or immediately without an opportunity to cure if cure is not possible. Termination of this BAA terminates the Terms of Service unless you say otherwise.
13 Return or destruction on termination
On termination we will, if feasible, return or destroy all PHI we hold and retain no copies, and will require the same of our Subcontractors.
Where return or destruction is not feasible, we will tell you in writing which records are affected and why, extend the protections of this BAA to them, and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as we retain them.
Two categories are known in advance to fall into that second case, and we would rather name them here than surprise you at termination: the append-only consent archive, which cannot be deleted in place and which is retained for the six-year period in section 9.3 as your evidence; and routine encrypted backups, which age out on their ordinary cycle rather than being individually purged. You are entitled at any time to a complete machine-readable export of your records under section 13.3 of the Terms of Service. Retention is not conditioned on payment, and we will not withhold an archive over an invoice.
14 General
Any ambiguity is resolved in favour of a meaning that permits compliance with HIPAA. A reference to a section of the CFR means that section as amended from time to time. The parties will negotiate in good faith any amendment needed for either of them to comply with a change in the law. This BAA prevails over the Terms of Service and the DPA to the extent of any conflict concerning PHI. Nothing in it creates rights in any third party other than the Secretary's rights under section 10. New York law governs, except where preempted by HIPAA.
Our liability under this BAA is not subject to the twelve-month cap in section 10 of the Terms of Service; see Terms section 10(d).
15 How to execute this
This page is our standard form, published so it can be reviewed before it is requested rather than after. It is an offer to contract on these terms; it does not become binding on either party until both have signed a counterpart.
To execute, or to raise a change with our counsel, write to Contact naming the covered entity, and we will send a countersignable copy. We are also willing to sign your form instead of ours; most practices already have one, and we would rather sign yours than argue about whose paper wins.