HIPAA Business Associate Addendum

Exhibit C to the BFLOW® Solutions Billing Services Agreement.

EXHIBIT C — HIPAA Business Associate Addendum

Last Updated: May 19, 2026

This HIPAA Business Associate Addendum ("Addendum") supplements and is made a part of the Billing Services Agreement ("BSA") by and between Client and BSI, and is effective as of the compliance date of the Privacy and Security Rules, defined below (the "Addendum Effective Date").

Recitals

Client wishes to disclose certain information to BSI pursuant to the terms of the Agreement, some of which may constitute protected health information ("PHI") (defined below).

Client and BSI intend to protect the privacy and provide for the security of PHI disclosed to BSI pursuant to the Agreement in compliance with the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191 ("HIPAA") and regulations promulgated thereunder by the U.S. Department of Health and Human Services (the "HIPAA Regulations") and other applicable laws, all as may be amended from time to time.

As part of the HIPAA Regulations, the Privacy Rule requires Client to enter into an agreement with BSI containing specific requirements prior to the disclosure of PHI and electronic PHI, as set forth in, but not limited to, Title 45, Sections 164.308(b)(1), 164.314(a), 164.502(e) and 164.504(e) of the Code of Federal Regulations ("CFR") and contained in this Addendum.

In consideration of the mutual promises below and the exchange of information pursuant to this Addendum, the parties agree as follows.

1. Definitions

  • "Business Associate" shall have the meaning given to such term under the Privacy Rule, 45 CFR Section 160.103.
  • "Covered Entity" shall have the meaning given to such term under the Privacy Rule, 45 CFR Section 160.103.
  • "Data Aggregation" shall have the meaning given to such term under the Privacy Rule, 45 CFR Section 164.501.
  • "Designated Record Set" shall have the meaning given to such term under the Privacy Rule, 45 CFR Section 164.501.
  • "Health Care Operation" shall have the meaning given to such term under the Privacy Rule, 45 CFR Section 164.501.
  • "Privacy Rule" shall mean the HIPAA Regulation codified at 45 CFR Parts 160 and 164.
  • "Protected Health Information" or PHI means any information, whether oral or recorded in any form or medium, that (i) relates to the past, present or future physical or mental condition of an individual, the provision of health care to an individual, or the past, present or future payment for the provision of health care to an individual; (ii) identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual; and (iii) otherwise conforms to the meaning given to such term under the Privacy Rule, 45 CFR Section 160.103.
  • "Protected Information" shall mean PHI provided by Client to BSI, or created or received by BSI on Client's behalf.
  • "Security Incident", as provided in 45 C.F.R. 164.304, shall mean the attempted or successful unauthorized access, use, disclosure, modification or destruction of information or interference with system operation in an information system.
  • "Security Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information codified at 45 C.F.R. Part 160 and Part 164, Subparts A and C.

2. Obligations of BSI

(a) Permitted Uses. BSI shall not use Protected Health Information except for the purpose of performing BSI's obligations under the Agreement and as permitted under the Agreement, including this Addendum. Further, BSI shall not use Protected Health Information in any manner that would constitute a violation of the Privacy Rule if so used by Client, except that BSI may use Protected Health Information (i) for the proper management and administration of BSI, or (ii) to carry out the legal responsibilities of BSI.

(b) Permitted Disclosures. BSI shall not disclose Protected Health Information in any manner that would constitute a violation of the Privacy Rule if disclosed by Client, except that BSI may disclose Protected Health Information (i) in a manner permitted pursuant to the Agreement including this Addendum, (ii) for the proper management and administration of BSI, or (iii) as required by law.

(c) Appropriate Safeguards. BSI shall implement such appropriate safeguards as are necessary to prevent the use or disclosure of Protected Health Information other than as permitted by the Agreement, within five (5) days of becoming aware of such use or disclosure.

(d) Reporting of Improper Use or Disclosure. BSI shall report to Client any use or disclosure of Protected Health Information otherwise than as provided for by the Agreement, including this Addendum, within five (5) days of becoming aware of such use or disclosure.

(e) BSI Agents. BSI shall ensure that any agents, including subcontractors, to whom it provides Protected Health Information agree in writing to the same restrictions and conditions that apply to BSI with respect to such PHI.

(f) Access to PHI. BSI shall make PHI maintained by BSI or its agents or subcontractors in Designated Record Sets available to Client for inspection and copying within ten (10) days of a request by Client to enable Client to fulfill its obligations under the Privacy Rule, including, but not limited to, 45 CFR Section 164.524.

(g) Amendment of PHI. Within ten (10) days of receipt of a request from Client for an amendment of PHI or a record about an individual contained in a Designated Record Set, BSI or its agents or subcontractors shall make such PHI available to Client for amendment and incorporate any such amendment to enable Client to fulfill its obligations under the Privacy Rule, 45 CFR Section 164.526.

(h) Accounting Rights. Within ten (10) days of notice by Client of a request for an accounting of disclosures of PHI, BSI and its agents or subcontractors shall make available to Client the information required to provide an accounting of disclosures to enable Client to fulfill its obligations under the Privacy Rule, 45 CFR Section 164.528. As set forth in, and as limited by, 45 CFR Section 164.528, BSI shall not provide an accounting to Client of disclosures:

  • to carry out treatment, payment or health care operations, as set forth in 45 CFR Section 164.502;
  • to individuals of PHI about them as set forth in 45 CFR 164.502;
  • to persons involved in the individual's care or for other notification purposes as set forth in 45 CFR Section 164.510;
  • for national security or intelligence purposes as set forth in 45 CFR Section 164.512(k)(2);
  • to correctional institutions or law enforcement officials as set forth in 45 CFR Section 164.514(e).

BSI agrees to implement a process that allows for an accounting to be collected and maintained by BSI and its agents or subcontractors for at least six (6) years prior to the request, but not before the compliance date of the Privacy Rule. At a minimum, such information shall include:

  • the date of disclosure;
  • the name of the entity or person who received Protected Information and, if known, the address of the entity or person;
  • a brief description of Protected Information disclosed; and
  • a brief statement of purpose of the disclosure that reasonably informs the individual of the basis for the disclosure, or a copy of the individual's authorization, or a copy of the written request for disclosure, as applicable.

(i) Governmental Access to Records. BSI shall make its internal practices, books and records relating to the use and disclosure of Protected Information available to the Secretary of the U.S. Department of Health and Human Services (the "Secretary") for the purposes of determining compliance with the Privacy Rule.

(j) Minimum Necessary. BSI and its subcontractors or agents shall only request, use and disclose the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure.

(k) Retention of PHI. BSI and its subcontractors or agents shall retain all PHI throughout the term of the Agreement, and shall continue to maintain the information required under Section 2(h) of this Addendum for a period of six (6) years prior to the request.

(l) Notification of Breach. During the term of this Agreement, BSI shall notify Client within twenty-four (24) hours of any suspected or actual breach of security, intrusion or unauthorized use or disclosure of PHI, or any actual or suspected use or disclosure of data in violation of any applicable federal or state law or regulations. BSI shall take (1) prompt corrective action to cure any deficiencies, and (2) any action pertaining to such unauthorized disclosure required by applicable federal and state laws and regulations.

(m) Audits, Inspections and Enforcement. Within ten (10) days of a written request by Client, BSI and its agents or subcontractors shall allow Client to conduct a reasonable inspection of the facilities, systems, books, records, agreements, policies and procedures relating to the use or disclosure of PHI pursuant to this Addendum for the purpose of determining whether BSI has complied with this Addendum; provided however, that (i) BSI and Client shall mutually agree in advance upon the scope, timing and location of such an inspection; (ii) Client and its agents shall protect the confidentiality of all confidential and proprietary information of BSI to which Client has access during the course of such inspection; and (iii) Client shall execute a nondisclosure agreement with terms mutually agreed upon by the parties, if requested by BSI.

(n) Security Standards. BSI shall implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of the electronic PHI that it creates, receives, maintains or transmits on behalf of Client.

(o) Notification of Security Breach. BSI shall promptly report to Client any Security Incident with respect to Client electronic PHI of which it becomes aware.

3. Termination

(a) Material Breach. A breach by BSI of any material provision of this Addendum shall constitute a material breach of the Agreement and shall provide grounds for immediate termination of the Agreement by Client pursuant to Section 7 of the Agreement.

(b) Reasonable Steps to Cure Breach. If Client knows of a pattern of activity or practice of BSI that constitutes a material breach or violation of BSI's obligations under the provisions of this Addendum or other arrangement and does not terminate this Agreement pursuant to 3(a), then Client shall take reasonable steps to cure either (1) terminate the Agreement, if feasible, or (2) if termination is not feasible, Client shall report BSI's breach or violation to the Secretary of the Department of Health and Human Services.

(c) Effect of Termination. Upon termination of the Agreement for any reason, BSI shall return or destroy all PHI that BSI or its agents or subcontractors still maintain in any form, and shall retain no copies of such PHI. If return or destruction is not feasible, BSI shall continue to extend the protections of sections 2(a), 2(b), 2(c), and 2(e) of this Addendum to such information, and limit further use of such PHI to those purposes that make the return or destruction of such PHI infeasible. If BSI elects to destroy the PHI, BSI shall certify in writing to Client that such PHI has been destroyed.

(d) Amendment to Comply with Law. The parties acknowledge that state and federal laws relating to data security and privacy of health information are rapidly evolving and that this Addendum may be required to provide for procedures to ensure compliance with such developments. The parties specifically agree to take such action as is necessary to implement the standards and requirements of HIPAA, the Privacy Rule, and other applicable laws relating to the security or confidentiality of PHI. Upon the request of either party, the other party agrees to promptly enter into negotiations concerning the terms of an amendment to this Addendum embodying written assurances consistent with the standards and requirements of HIPAA, the Privacy Rule or other applicable laws. Client may terminate this Agreement upon thirty (30) days prior written notice in the event BSI (1) does not promptly enter into negotiations to amend this Agreement when requested by Client pursuant to this section; or (2) does not enter into an amendment to this Agreement providing assurances regarding the safeguarding of PHI sufficient to satisfy the standards and requirements of HIPAA and the Privacy Rule.

(e) No Third Party Beneficiaries. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than the Client, BSI and their respective successors or assigns, any rights, remedies, obligations or liabilities whatsoever.

(f) Interpretation. The provisions of this Addendum shall prevail over any provisions in the Agreement that may conflict or appear inconsistent with any provision in this Addendum. This Addendum and the Agreement shall be interpreted as broadly as necessary to implement and comply with HIPAA and the Privacy Rule. The parties agree that any ambiguity in this Addendum shall be resolved in favor of a meaning that complies and is consistent with HIPAA and the Privacy Rule.

IN WITNESS WHEREOF, the parties have executed this BAA on the dates appearing below to be effective as of the Effective Date. Execution is completed within your BFLOW® Solutions proposal at the time of contract signing.

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.Learn more about our Cookie Policy