HIPAA BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement ("BAA" or "Agreement") is entered into and made effective as of
July 29, 2026,
by and between
[Covered Entity] ("Covered Entity")
and TrackRoad ("Business Associate").
RECITALS
WHEREAS, Covered Entity and Business Associate have entered into or may enter into one or more underlying service agreements (collectively, the "Underlying Agreement") pursuant to which Business Associate provides routing, dispatch, or logistics services to Covered Entity;
WHEREAS, in performing services for Covered Entity, Business Associate may create, receive, maintain, or transmit Protected Health Information ("PHI") and Electronic Protected Health Information ("ePHI") as defined under federal regulations; and
WHEREAS, the parties intend to comply with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and the implementing regulations set forth at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Rules").
NOW, THEREFORE, in consideration of the mutual promises contained herein, the parties agree as follows:
1. DEFINITIONS
- General: Capitalized terms used but not otherwise defined in this BAA shall have the same meaning given to them in the HIPAA Rules (45 C.F.R. Parts 160 and 164).
- Protected Health Information (PHI): Shall have the same meaning given to the term in 45 C.F.R. § 160.103, limited to the information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
2. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE
Business Associate agrees to:
- Limits on Use and Disclosure: Not use or disclose PHI other than as permitted or required by this Agreement, the Underlying Agreement, or as required by law.
- Safeguards: Implement appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 (HIPAA Security Rule), to prevent unauthorized use or disclosure of ePHI.
-
Reporting: Report promptly to Covered Entity:
- Any use or disclosure of PHI not provided for by this Agreement of which it becomes aware;
- Any Security Incident affecting ePHI of which it becomes aware; and
- Any Breach of Unsecured PHI as required under 45 C.F.R. § 164.410 without unreasonable delay and in no event later than 10 business days after discovery.
- Subcontractors: Ensure that any subcontractors or agents that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to the same restrictions, conditions, and safeguards that apply to Business Associate under this BAA.
- Access to PHI: Within ten (10) business days of receiving a written request from Covered Entity, make available PHI in a Designated Record Set as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.524.
- Amendments to PHI: Make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 C.F.R. § 164.526.
- Accounting of Disclosures: Maintain and make available the information required to provide an accounting of disclosures of PHI in accordance with 45 C.F.R. § 164.528.
- Audits and Books: Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the Department of Health and Human Services (HHS) for purposes of determining compliance with the HIPAA Rules.
3. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
- Service Delivery: Business Associate may use or disclose PHI only to perform routing, dispatch, and delivery management services for Covered Entity as specified in the Underlying Agreement, provided that such use or disclosure would not violate HIPAA if done by Covered Entity.
- Management and Administration: Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities.
- Legal Disclosures: Business Associate may disclose PHI for its proper management and administration or legal responsibilities if:
- The disclosure is required by law; or
- Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed.
4. OBLIGATIONS OF COVERED ENTITY
Covered Entity shall:
- Inform Business Associate of any limitations in its notice of privacy practices under 45 C.F.R. § 164.520, to the extent such limitations affect Business Associate's use or disclosure of PHI.
- Inform Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI.
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
5. TERM AND TERMINATION
- Term: This BAA shall take effect on the Effective Date and shall terminate when all PHI provided by Covered Entity to Business Associate is destroyed or returned, or if infeasible, when protections are extended to such information in accordance with this Section.
- Termination for Cause: Upon Covered Entity's knowledge of a material breach of this Agreement by Business Associate, Covered Entity shall provide written notice and an opportunity to cure the breach within thirty (30) days. If Business Associate fails to cure the breach, Covered Entity may immediately terminate the Underlying Agreement and this BAA.
-
Effect of Termination:
- Upon termination of this BAA, Business Associate shall return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity.
- If return or destruction of PHI is infeasible, Business Associate shall extend all protections, limitations, and restrictions of this BAA to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible.
6. MISCELLANEOUS
- Regulatory References: A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.
- Amendment: The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with HIPAA requirements.
- Interpretation: Any ambiguity in this Agreement shall be resolved to permit compliance with the HIPAA Rules.
Sign in to execute this agreement
You may read the complete Business Associate Agreement without an account.
To enter your organization information and legally execute the agreement on behalf of your company,
please sign in or create a TrackRoad account first.