Business Associate Agreement

Last updated August 16, 2026

On this page (80 sections)

As medical billing and claim processing processes that involve PHI could fall under that HIPAA Framework for Business Associates This is a crucial document for ZechionMed's clientele of providers. HHS requires a formal business associate agreement or contract that contains specific provisions that include permitted disclosures/uses as well as safeguards, reporting of incidents and assistance with specific rights of individuals obligations, subcontractor requirements and return/destroy of PHI. (HHS.gov)

Effective Date: [Insert Effective Date]

It is a Business Associate Agreement ("BAA") is signed between and by:

Covered Entity:Legal Name: [Insert Client Legal Name] Address: [Insert Client Address] Contact: [Insert Authorized Contact]

and

Business Associate: ZechionMed Legal Entity Name: [Insert Exact ZechionMed Legal Entity Name] Address: Wilmington, Delaware, USA Contact: [Insert Authorized Contact]

Covered Entity and Business Associate Covered Entity and Business Associate can be identified separately as"Party" or "Party" and collectively as the "Parties."

The BAA sets out what are the Parties' obligations regarding the disclosure and use of Protected Health Information ("PHI") in connection with the services offered by a Business Associate to Covered Entity.

1Purpose

Covered Entity has engaged Business Associate to provide specific medical billing medical coding, medical billing, the management of revenue cycles, management of claims and related healthcare administrative services.

The Services could require a Business Associate to create, maintain, receive or transfer PHI on behalf of the Covered Entity.

The objective the purpose of the BAA is to define the authorized and required usages and the disclosures that PHI can be made, as well as secure and privacy obligations of parties under the applicable regulations in the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") as well as the Health Information Technology for Economic and Clinical Health Act ("HITECH") and the applicable regulations for their implementing.

2Regulatory References

To be used in this BAA the following terms are used "HIPAA," "HIPAA Rules," "Privacy Rule," "Security Rule," "Breach Notification Rule," "PHI," "Electronic PHI," "Breach," "Security Incident," "Subcontractor," "Use," "Disclosure," "Minimum Necessary," and any other relevant terms shall be given the meanings that are assigned to them by the applicable HIPAA regulations including 45 C.F.R. Parts 160 and 16164 in addition to any amendments made from time to date.

The HIPAA Rules require an Business Associate agreement to establish the permitted and necessary uses and disclosures of PHI, and requires adequate security measures. (HHS.gov)

3Definitions

3.1 Business Associate

"Business Associate" means ZechionMed according to the applicable HIPAA regulations.

3.2 Covered Entity

"Covered Entity" means the healthcare provider or health plan, healthcare clearinghouse or any other entity listed in this BAA that is an entity covered under HIPAA.

3.3 Protected Health Information

"Protected Health Information" or "PHI" means information protected by the HIPAA Privacy Rule. It is stored, created, received or transferred by a Business Associate on behalf of Covered Entity.

3.4 Electronic Protected Health Information

"Electronic Protected Health Information" or "ePHI" means PHI maintained or transmitted electronically.

3.5 HIPAA Rules

"HIPAA Rules" means the applicable Privacy, Security, Breach Notification, and Enforcement Rules under 45 C.F.R. Parts 160 & 164 in the form of amendments.

3.6 Subcontractor

"Subcontractor" means a person or organization who Business Associate delegates a function or activity that involves the creation, receipt and maintenance or transmission of PHI.

4Services Covered by This Agreement

The Services that are covered by this BAA might include, if relevant:

Other services are listed by the relevant Service Agreement or Statement of Work.

The precise Services will be established by the applicable Agreement between the parties.

  • Medical billing
  • Medical Coding
  • Claim preparation
  • Claims submission
  • Processing of Claims
  • Follow-up on Claims
  • Management of denial
  • Support for appeals
  • Payment posting
  • Accounts receivable management
  • Verification of eligibility
  • Prior authorization support
  • Revenue cycle management
  • Credentialing and support for providers
  • Audits on Coding
  • Services for ensuring the integrity of your revenue
  • Analytics and reporting
  • Administrative healthcare support

5Permitted Uses and Disclosures of PHI

Business Associate is permitted to make use of or disclose PHI for the following purposes:

If permitted, this is in accordance with rules of HIPAA Rules.

Business Associate may utilize or disclose PHI in the manner needed to carry out the Services for the covered Entity.

  • This is a requirement or a permissible use of this BAA
  • Required by the Service Agreement
  • Written authorization from Covered Entity
  • Lawful requirement by applicable law.

6Medical Billing and Revenue Cycle Activities

As per the conditions of this BAA, Business Associate may use or disclose PHI when needed to carry out contracted revenue cycle and billing activities for example:

The processing of claims and medical billing are two types of activities that can lead to the Business Associate relationship in the event that PHI can be involved. (HHS.gov)

  • Coding claims
  • Formulating claims
  • Submitting claims
  • Checking claim status
  • Managing denials
  • Performing payer follow-up
  • Payments by post
  • Management of accounts receivables
  • Verifying eligibility
  • Helping to support authorization workflows
  • Conducting quality code reviews
  • Making reports on the revenue cycle
  • Aiding in healthcare operations.

7Business Associate Obligations

Business Associate accepts:

7.1 Use and Disclosure Restrictions

Do not disclose or use PHI unless permitted or required under this BAA and the underlying contract and the written instructions issued by the Covered Entity or the applicable law.

7.2 Safeguards

Install appropriate physical, administrative and technological safeguards to stop unauthorized use or disclosure of PHI.

7.3 Security Rule Compliance

Concerning ePHI Be sure to comply with the all applicable requirements of HIPAA Security Rule.

7.4 Incident Reporting

Notify the Covered Entity any unauthorized use or disclosure of PHI, or any other Security Incident as required by the law in force in this BAA.

7.5 Breach Reporting

Notify the Covered Entity of a breach of unsecured PHI in accordance to this BAA as well as applicable HIPAA regulations.

7.6 Minimum Necessary

Limit disclosures, uses or requests to access PHI, only the bare minimum needed to fulfill the purpose with respect to any specific exceptions.

7.7 Workforce

Employers who have the ability to access PHI to adhere to the applicable privacy and security regulations.

7.8 Subcontractors

The subcontractors you choose to access PHI to accept substantially the same terms and restrictions that apply to Business Associate under this BAA.

7.9 Assistance

Offer reasonable assistance in assisting the Covered Entity in meeting applicable HIPAA obligations as stated in the BAA.

7.10 HHS Access

Create relevant internal practices and policies, records, and documents available at officials of the U.S. Department of Health and Human Services ("HHS") when it is required by law in order to determine the whether the covered entity is in compliance in accordance with HIPAA Privacy Rule.

These obligations are based on the elements specified as required by HHS in Business Associate contracts. (HHS.gov)

8Safeguards

Business Associate must use reasonable and appropriate safeguards to safeguard PHI against unauthorised access, use or disclosure, as well as alteration or destruction.

The types of safeguards comprise:

Business Associate will implement safeguards in accordance with the nature and extent of the Services as well as the risks related to the processing of PHI.

  • Access control
  • User authentication
  • Role-based permissions
  • Access management for the workforce
  • Training and awareness of security
  • When appropriate, encryption
  • Secure transmission
  • Monitoring of the system
  • Logging
  • Endpoint security
  • Security of the network
  • Backup procedures
  • Incident response procedures
  • Physical security controls
  • Secure disposal procedures.

9Electronic Protected Health Information

Business Associate must abide by all applicable requirements of HIPAA Security Rule in relation to ePHI.

Business Associate will put in place reasonable and appropriate security measures designed to protect:

Be sure to protect confidentiality.

Be sure to protect your integrity.

Security measures for Business Associates are regularly updated to reflect the latest developments in technology and threats, risks and requirements of the regulatory system.

  • Support availability
  • Prevent unauthorized access
  • Find security events that are suspicious
  • Respond to security incidents that are identified.

10Security Risk Management

Business Associate must maintain appropriate processes to identify and address the risks that could affect ePHI.

These processes could include:

Both parties acknowledge any information system cannot guarantee to be 100% safe.

  • Risk assessment
  • Access reviews
  • Security monitoring
  • Management of vulnerability
  • Incident response
  • Security of the workforce
  • Vendor risk management
  • Recovery and backup procedures
  • Security awareness.

11Security Incidents

Business Associate should submit to Security Incidents of Covered Entity involving PHI, in accordance with the current legislation and BAA.

Business Associate can employ routine security and technical procedures to protect its systems. However, it is not giving separate notice of each incident that fails to protect the system and does not result in an unauthorized access to, use, disclosure, modification or the destruction PHI.

If an incident has a significant impact on PHI, Business Associate will examine and provide information required to allow the Covered Entity to assess its legal and contractual obligations.

12Breach of Unsecured PHI

When a Business Associate discovers a Breach of Private Health Information that is not secured, Business Associate shall notify Covered Entity without unreasonable delay and according to applicable HIPAA guidelines.

Unless a shorter timeframe is required by law or is agreed upon by the parties, notice is given without delay and not more then 60 calendar days from the discovering the breach.

HHS declares that an Business Associate must notify the Covered Entity following discovery of the breach of protected health information and not more than 60 days following discovering pursuant to the HIPAA Breach Notification Rule. (HHS.gov)

13Contents of Breach Notification

If it is possible the Business Associate's notice must contain:

When was the date that discovery took place

Other information that is reasonably required to be provided by Covered Entity.

Business Associate will update the announcement as more information is made available.

  • An account of the events that transpired
  • Date of incident the date of the incident, if it is known
  • The different types of PHI that are used
  • Identification of individuals affected in cases where it is reasonably possible to do so
  • The actions taken to investigate
  • Interventions to minimize the possibility of damage
  • The actions taken to prevent the occurrence of the problem

14Covered Entity Responsibilities Following a Breach

Covered Entity remains responsible for meeting its applicable HIPAA obligation to notify the affected persons, HHS, and the media when required.

Business Associate will cooperate together with Covered Entity in fulfilling those obligations.

The Parties can have a written agreement to the effect that Business Associate will assist with or carry out specific notification actions.

HHS clarifies that covered entities typically are responsible for individuals, HHS, and applicable media notification obligations, whereas Business Associates must notify the covered entity whenever a breach is discovered by or at or through the Business Associate. (HHS.gov)

15Use of PHI for Management and Administration

Business Associate may use PHI to manage its business administration, and for carrying out its legal obligations when allowed by HIPAA.

If applicable, Business Associate is permitted to provide PHI for this purpose only if:

The disclosure is in compliance with the applicable HIPAA requirements for disclosures of this kind.

Business Associate must not make use of this provision to engage in unrelated commercial activities that involve PHI.

  • It is mandatory under law or

16Data Aggregation

If permitted by the underlying agreement and regulated in accordance with HIPAA, Business Associate may utilize PHI to carry out permitted data aggregation functions in connection with the health care operations of the Covered Entity and other covered entities or business associates that are served through Business Associate.

Any activity that aggregates data must be in compliance with the the applicable HIPAA obligations and limitations.

17De-Identification

When legally permitted and authorized, Business Associate may create or use de-identified data as per the applicable HIPAA regulations.

When information is properly removed from the database in accordance with relevant HIPAA rules, it's not considered to be PHI as per the requirements under the HIPAA Privacy Rule. This is subject to the applicable laws and the agreement that governs it.

Business Associate will not present information as de-identified until it meets the relevant standards.

18Limited Data Sets

Business Associate is permitted to develop or utilize an Limited Data Set only where specifically authorized by a Covered Entity and permitted under the applicable law.

If it is required, the parties will conclude a Data Use Agreement.

19Requests From Individuals

Covered Entity remains responsible for providing assistance to those who exercise their legal rights in accordance with the HIPAA Privacy Rule which includes any rights that apply to:

Business Associate will help Covered Entity in responding to these requests to the extent permitted under this BAA and any applicable law.

HHS states that covered entities remain accountable to fulfill Privacy Rule obligations to individuals and Business Associate agreements can require the Business Associate to assist the covered entity in fulfilling its obligations. (HHS.gov)

  • Access
  • Amendment
  • Restrictions
  • Accountability of Disclosures.

20Access to PHI

When Covered Entity requests access to PHI held by a Business Associate as necessary to satisfy an individual's request to access, Business Associate shall provide the requested information within a time frame that is reasonably required by Covered Entity and applicable law.

Business Associate may employ secure methods to transfer requested data.

21Amendment of PHI

When Covered Entity determines that an amending PHI is necessary, Business Associate shall reasonably assist Covered Entity in making the request for an amendment to the PHI that is maintained through Business Associate, where required by law.

22Accounting of Disclosures

Business Associate should keep information regarding disclosures of PHI, in accordance with the applicable HIPAA regulations.

If requested in a reasonable manner, Business Associate shall provide Covered Entity with information necessary to enable Covered Entity to respond to the request of an individual for an accounting of the disclosures that are applicable.

23Covered Entity's Notice of Privacy Practices

Covered Entity remains responsible for maintaining and disseminating its Privacy Notice in accordance with applicable law.

Business Associate will not independently issue or create a Privacy Notice for the benefit of Covered Entity unless expressly authorized to make such a statement.

24Subcontractors

When Business Associate engages a Subcontractor to provide services that require the creation, reception maintenance, transmission, or creation or transmission of patient information Business Associate shall require the Subcontractor to sign an agreement in writing that imposes the any applicable HIPAA security and privacy restrictions and terms.

HHS specifically mentions this as a mandatory element in Business Associate contracts. (HHS.gov)

Business Associate remains responsible for its contractual obligations with respect to these subcontractors.

25Cloud Service Providers

When Business Associate uses a cloud service provider who creates, receives and maintains or transmits ePHI on the behalf of Business Associate, Business Associate will address the applicable HIPAA Business Associate requirements through the appropriate agreements with the contractual provider.

HHS declares that cloud service providers that handle ePHI in the name of a covered entity, or Business Associate generally requires a BAA and is subject to HIPAA rules. (HHS.gov)

26Prohibited Uses and Disclosures

Business associates are not allowed to:

Do not sell PHI unless specifically permitted by law and a legally enforceable agreement.

Utilize PHI for purposes that are not within the scope of Services without authorization.

Utilize PHI in a way which would be in violation of HIPAA in the event of a Covered Entity, except where other than expressly allowed by applicable law.

  • Use PHI to promote unrelated ads
  • Use PHI for unauthorized marketing
  • Disclose PHI to unauthorized persons

27No Sale of PHI

Business Associate is not permitted to offer PHI for sale in exchange for compensation, in any way, unless permitted by applicable law and specifically permitted by Covered Entity where required.

Any activity that is permitted to involve the payment of PHI must be in accordance with the applicable HIPAA regulations.

28Minimum Necessary Standard

Business Associate will take reasonable steps to limit disclosures, uses and requests for personal health information to the minimum required to achieve the purpose for which they were designed subject to the applicable HIPAA exceptions.

Access to the workforce could be restricted depending on:

  • Job purpose
  • Client authorization
  • Service needs
  • System permissions
  • It is a business requirement.

29Covered Entity Responsibilities

The Covered Entity accepts:

Offer Business Associate with information necessary to provide the Services legally.

The covered Entity should not direct Business Associate to use or divulge PHI in a way that is in violation of the applicable HIPAA regulations.

  • Inform Business Associate of applicable limitations regarding PHI disclosure or use
  • Inform Business Associate of changes to restrictions or permissions that affect PHI
  • Offer Business Associate with relevant policies and directions if necessary
  • Request the patient's authorization if necessary
  • Keep up-to-date HIPAA guidelines and policies
  • Meet the requirements of individual rights
  • Maintain its Notice of Privacy Practices

30Prohibited Client Instructions

Covered Entity shall not request Business Associate to use or divulge PHI in a way in which Business Associate reasonably believes would be in violation of applicable law.

Business Associate can deny or suspend a PHI-related activity if it is necessary to conform with any applicable law or regulation.

31Compliance With Law

Each Party must abide by the any applicable laws to their individual obligations in this BAA.

There is nothing in the BAA obliges either party to carry out an act that is prohibited by law.

If the law in force imposes additional requirements that are mandatory and the parties must work with each other to adjust their practices and agreements when required.

32Regulatory Cooperation

Business Associate shall make its relevant records, books as well as policies and practices regarding PHI accessible to HHS as required in accordance with the applicable HIPAA rules.

Access to information will be subject to legal requirements and restrictions.

33Confidentiality

Alongside HIPAA regulations in addition, each Party must safeguard confidential information obtained through another Party.

Confidential information could comprise:

Confidentiality obligations endure termination to the extent that is required by law or in the contract that they are based on.

  • PHI
  • Information on business
  • Financial information
  • Credentials
  • Systems that are proprietary
  • Information on security
  • Information about operations
  • Trade secrets.

34Data Security Documentation

On reasonable request, Business Associate may provide Covered Entity with appropriate information regarding security and privacy protections subject to:

It is important to note that the HIPAA rules do not explicitly require each Business Associate to permit customer audits of its security procedures, but additional assurances can be negotiated in a contract. (HHS.gov)

  • Confidentiality
  • Security concerns
  • Protection of confidential information
  • Reasonable restrictions on auditing actions
  • Applicable law
  • Security documentation in place.

35Security Assessments

The parties may also set additional security assessment criteria via an Service Agreement, security addendum, SLA, or other written agreement.

All assessments must have to be carried out in a way that will not cause excessive disruption to Business Associate's activities or compromise of security information that is confidential.

36Return or Destruction of PHI

In the event of expiration of the applicable Services, Business Associate shall, whenever possible and as stipulated by the applicable contract:

Business Associate can retain PHI if it is required by law or when destruction or return is not possible.

In the event that Business Associate retains PHI because destruction or return is impossible or required by law, Business Associate shall continue to secure the information and may utilize or divulge it only to the extent of requiring its retention, or in accordance with any other permitted purpose by law.

HHS specifies the destruction or return of PHI when the contract is terminated, as it is feasible, as an part of the Business Associate contract. (HHS.gov)

  • Return PHI to Covered Entity; or
  • Make sure to securely destroy all PHI.

37Data Backup and Disaster Recovery

Business Associate is able to keep back-up copies PHI within their normal operations continuity as well as disaster recovery procedures.

Backup copies will be subject to any applicable privacy and security requirements.

In the event that PHI cannot be immediately deleted from backup systems Business Associate will continue to secure the information and eliminate or secure eliminate it in accordance with the applicable retention and backup protocols.

38Termination for Material Breach

Covered Entity may terminate this BAA or the contract underlying it in the event that a Business Associate materially breaches a clause in this BAA in the absence of a remedy to correct the violation within the time stipulated in a written notice.

In the event that a breach can't reasonably be remedied, Covered Entity may terminate the agreement in question if it is permitted under law or contract.

HHS recognizes the termination of a contract as a mandatory contractual remedy when the Business Associate materially violates the agreement and the remedy is not successful or unattainable. (HHS.gov)

39Business Associate Right to Terminate

Business Associate can terminate the relevant agreement when Covered Entity materially breaches its obligations and fails in resolving any breach in the deadline for remedy under the agreement.

Business Associate may also be terminated when continued performance could result in the disclosure or use of PHI.

40Transition Assistance

After the termination of the agreement, both parties will cooperate in a reasonable manner to transition PHI and the applicable information on revenue cycles in a timely and secure in a timely and secure manner.

Transition activities could include:

Additional fees for transitions may be charged as per the terms of the Service Agreement.

  • Data export
  • Secure transfer
  • Return of records
  • Access ending
  • Credential deactivation
  • System transition
  • Vendor transition support.

41Term and Effective Date

This BAA is effective from the date it is signed by both parties.

It will be in effect throughout the relationship which is involving PHI and for as it continues to exist as long as the Business Associate retains PHI subject to this BAA.

42Survival

Business Associate's obligations regarding PHI will continue to be in force after the expiration in this BAA for the duration that Business Associate retains PHI.

Confidentiality, security, permitted use limitations, and any other obligations that are intended to endure the termination of the agreement shall continue to be effective in the manner required by law or in the underlying agreement.

43Relationship to Underlying Agreement

This BAA supplement the current Master Services Agreement, Service Agreement Statement of Work, or any other written agreements between the parties.

The contract that is underlying regulates relationships between Parties.

This BAA defines PHI and the Parties' obligations with respect to PHI.

44Order of Precedence

If there is an incompatibility with the BAA and the agreement regarding PHI the BAA will prevail with respect to the HIPAA privacy and security obligations.

If the law that applies requires a more stringent requirement than the other agreement, that law will govern.

45Amendments

The parties may modify the BAA by writing.

The Parties can also amend the BAA as needed to reflect the latest developments in:

Both parties will cooperate with respect to in implementing legally-required modifications.

  • HIPAA prescriptions
  • Federal regulations
  • Privacy laws of the states that are applicable
  • Security needs
  • Services
  • Technology
  • Business agreements.

46Regulatory Changes

If changes in state or federal law significantly impacts the scope of this BAA The Parties will work together on a good basis to amend the BAA as is reasonably necessary in order to conform with the applicable requirements.

47Assignment

No Party can the BAA contract in any way which would be in violation of law.

A transfer that results from a merger acquisition, corporate restructuring or the sale of all relevant assets could be allowed in cases where it is legal and contractually acceptable.

The successor entity will remain in compliance with the all obligations in force.

48No Third-Party Beneficiaries

Unless applicable law states the contrary This BAA does not confer rights for third parties.

This BAA is designed to create a private rights of action that is not covered by law.

49Indemnification

Indemnification obligations related to HIPAA breaches or security breaches or any other claim are governed by an relevant Master Services Agreement or Service Agreement unless explicitly stated otherwise within this BAA.

This section does not limit any responsibility that is not legally be legally limited.

50Limitation of Liability

The liability limitations applicable to HIPAA-related claims will be determined by the underlying written contract between the parties subject to the the applicable laws.

The provisions of this BAA is designed to relieve or restrict obligations or liabilities that can't legally waived, or reduced.

51Governing Law

Unless specifically stated in the written agreement underlying the BAA is subject to the applicable federal law in addition to the state laws applicable in Delaware. State of Delaware, without any consideration of conflict-of-law rules.

State and federal health privacy laws will remain in effect when legally needed.

52Dispute Resolution

The provisions for dispute resolution in the base Service Agreement or Master Services Agreement will apply to any disputes that arise under this BAA unless otherwise specified by law.

The Parties will endeavor to settle HIPAA-related disputes via honest discussions prior to pursuing legal remedies, when appropriate.

53Severability

If any of the provisions in this BAA is found as invalid, or ineffective or unenforceable, the other provisions remain in effect.

The parties will work together to substitute the invalid clause with one which is most faithful to the original intention.

54No Waiver

Failure of either Party to comply with any provision of the BAA does not mean any waiver of the provision and/or the ability to enforce that provision in the future.

55Entire Agreement

This BAA together with the applicable underlying contract is the Parties agreement regarding the treatment of PHI related to the Services.

Any additional security or privacy conditions must be agreed upon in writing.

56Electronic Signatures

The Parties can sign the BAA electronically.

Electronic signatures could have the same legal impact as signatures that are original to the extent that they are permitted by law.

57Counterparts

The BAA could be signed in multiple counterparts, and each will be considered an original, and all of them together form one agreement.

58Notices

Notifications to be sent pursuant to this BAA will be delivered at the address or contacts below unless the parties establish distinct notice procedures in the agreement underlying them.

Covered Entity

Legal Name: [Insert Legal Name] Address: [Insert Address] HIPAA/Privacy Contact: [Insert Name] Email: [Insert Email] Phone: [Insert Phone]

Business Associate

ZechionMed Legal Entity Name: [Insert Exact Legal Entity Name] Address: Wilmington, Delaware, USA HIPAA/Privacy Contact: [Insert Name/Title] Email: [Insert HIPAA/Privacy Email] Phone: [Insert Phone]

59Signatures

By signing the following document the parties acknowledge that they are authorized to sign the Business Associate Agreement and agree to abide by the applicable terms.

COVERED ENTITY

Legal Name: ______________________________________

Authorized Representative: __________________________

Title: _____________________________________________

Signature: _________________________________________

Date: _____________________________________________

BUSINESS ASSOCIATE

ZechionMed

Legal Entity Name: __________________________________

Authorized Representative: __________________________

Title: _____________________________________________

Signature: _________________________________________

Date: _____________________________________________

EXHIBIT A -- AUTHORIZED SERVICES

The following Services are authorised in this BAA:

  • Medical Billing
  • Medical Coding
  • Claims Submission
  • Claims Management
  • Denial Management
  • Accounts Receivable Management
  • Payment Posting
  • Eligibility Verification
  • Prior Authorization Support
  • Revenue Cycle Management
  • Provider Credentialing
  • Coding Audits
  • Revenue Integrity
  • Patient Financial Services Support
  • Revenue Cycle Reporting
  • Healthcare Administrative Support
  • Other: ___________________________________________

EXHIBIT B -- AUTHORIZED PHI CATEGORIES

Based on the services provided Business Associate might be able to receive or perform:

Other PHI that is required to provide the Services.

Business Associate will only use the types of PHI needed to carry out the authorized Services.

  • Patient names
  • Patient demographic information
  • Contact details
  • Birth date
  • Information about insurance
  • Subscriber and member information
  • Claim information
  • Information about diagnosis
  • Information on the procedure
  • Medical Coding Information
  • Billing information
  • Information about payments
  • Information about the provider
  • Information on eligibility
  • Information about authorization

EXHIBIT C -- BREACH AND SECURITY INCIDENT CONTACT

ZechionMed HIPAA Contact

Name/Title: [Insert] Email: [Insert Secure Email] Phone: [Insert] Emergency/Security Contact: [Insert]

Covered Entity HIPAA Contact

Name/Title: [Insert] Email: [Insert] Phone: [Insert] Emergency/Security Contact: [Insert]

Security breaches and security incidents must be reported to the contact details and the procedure established by the parties.

Questions about this policy?

Our team can walk you through anything in this document.