Business Associate Agreement
BUSINESS ASSOCIATE AGREEMENT (2026-08-14)
BY ACCEPTING THIS AGREEMENT, OR BY USING THE SERVICES TO CREATE, RECEIVE, MAINTAIN, OR TRANSMIT PROTECTED HEALTH INFORMATION, YOU AGREE TO THESE TERMS. IF YOU ARE ACCEPTING ON BEHALF OF AN ENTITY, YOU REPRESENT THAT YOU HAVE AUTHORITY TO BIND THAT ENTITY, AND "COVERED ENTITY" MEANS THAT ENTITY.
This Business Associate Agreement (this “BAA”) is between Customer (“Covered Entity”) and Office Puzzle, Inc., a Delaware corporation with offices at 760 NW 107th Ave, Suite 420, Miami, FL 33172 (“Business Associate”). It supplements and is incorporated into the Office Puzzle Master Subscription Agreement between the parties (the “Subscription Agreement”), and takes effect when Covered Entity accepts it.
This BAA applies from acceptance, including throughout any free trial period, and applies to all Protected Health Information Covered Entity enters into the Services at any time.
The parties acknowledge that Business Associate may create, receive, maintain, or transmit Protected Health Information on Covered Entity’s behalf in performing the Services, and that HIPAA requires a written agreement satisfying 45 C.F.R. §§ 164.314(a) and 164.504(e). The parties agree as follows.
1. Definitions
1.1 “HIPAA” means the Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996, the HITECH Act, and the regulations at 45 C.F.R. Parts 160 and 164, including the Privacy Rule, the Security Rule, and the Breach Notification Rule, each as amended.
1.2 “Protected Health Information” or “PHI” has the meaning given in 45 C.F.R. § 160.103, limited to information Business Associate receives from, or creates, maintains, or transmits on behalf of, Covered Entity. “Electronic Protected Health Information” has the meaning given in 45 C.F.R. § 160.103.
1.3 “Breach,” “Designated Record Set,” “Individual,” “Required By Law,” “Secretary,” “Security Incident,” “Subcontractor,” “workforce,” and “Unsecured Protected Health Information” have the meanings given in 45 C.F.R. Parts 160 and 164.
1.4 “Discovery” means the first day on which the relevant incident is known to Business Associate, or by exercising reasonable diligence would have been known to Business Associate, consistent with 45 C.F.R. § 164.410(a)(2). “Confirmation” means the point at which Business Associate has determined that a Breach of Unsecured PHI has occurred and has identified, at least preliminarily, the Covered Entity affected.
1.5 Capitalized terms not defined here have the meanings given in the Subscription Agreement or, if not defined there, in HIPAA. The terms “use,” “disclose,” and “discover,” though not capitalized, have their HIPAA meanings.
2. Obligations of Business Associate
2.1 Permitted use. Business Associate will not use or disclose PHI other than as permitted or required by this BAA or as Required By Law, and will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted by Sections 3.4 and 3.5.
2.2 Safeguards. Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 C.F.R. Part 164 with respect to Electronic PHI, to prevent use or disclosure of PHI other than as permitted by this BAA. Business Associate will maintain the information security program described in Section 7 of the Subscription Agreement.
2.3 Reporting and breach notification
(a) Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI, as follows:
- for a Security Incident or a suspected Breach affecting Covered Entity’s PHI — without unreasonable delay and in no case later than five business days after Discovery; and
- for a Breach of Unsecured PHI that Business Associate has confirmed — without unreasonable delay and in no case later than forty-eight hours after Confirmation.
(b) Each report will include the information then available that Covered Entity reasonably needs to meet its obligations under 45 C.F.R. §§ 164.404 and 164.408, including identification of each Individual whose PHI was or is reasonably believed to have been involved, to the extent known. Business Associate will supplement its report as further information becomes available.
(c) Business Associate will provide a written summary of its investigation within thirty days after Confirmation, or, where an independent forensic firm is engaged and controls the timeline, will use commercially reasonable efforts to provide it within that period and will keep Covered Entity informed of progress.
(d) Business Associate will reasonably cooperate with Covered Entity’s investigation, mitigation, and notification efforts. Where Business Associate is the source of the Breach, it will bear its own costs of that cooperation. Any reimbursement of Covered Entity’s costs is subject to the limitations of liability in the Subscription Agreement.
(e) The parties acknowledge that this Section constitutes notice of the ongoing occurrence of unsuccessful Security Incidents — including pings and other broadcast attacks on firewalls, port scans, unsuccessful log-on attempts, and denial-of-service attempts — for which no additional notice is required, so long as they do not result in unauthorized access to, or use or disclosure of, Electronic PHI.
2.4 Subcontractors
(a) In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will require each Subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA.
(b) For clarity, individuals who are members of Business Associate’s workforce as defined in 45 C.F.R. § 160.103 — including employees and contractors whose conduct is under Business Associate’s direct control — are not Subcontractors. Business Associate is responsible for its workforce through training, access controls, confidentiality obligations, and a sanctions policy.
(c) Business Associate will maintain a current list of the third-party service providers that may process PHI and will make it available to Covered Entity on request. Business Associate will give Covered Entity at least thirty days’ notice by email before engaging a new third-party service provider that will process PHI. Covered Entity may object on reasonable grounds within fifteen days of that notice; if the parties cannot agree on a remedy, Covered Entity may terminate the affected portion of the Services without penalty as its sole remedy.
2.5 Artificial intelligence
Business Associate will not use PHI to train, fine-tune, or adapt any artificial-intelligence or machine-learning model. Business Associate may train models on data de-identified in accordance with 45 C.F.R. § 164.514(b)(1) or (b)(2), and will not attempt to re-identify that data.
2.6 Individual rights
(a) Business Associate will make PHI in a Designated Record Set available to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.524.
(b) Business Associate will make amendments to PHI in a Designated Record Set as directed or agreed by Covered Entity under 45 C.F.R. § 164.526.
(c) Business Associate will maintain and make available the information required for Covered Entity to provide an accounting of disclosures under 45 C.F.R. § 164.528.
(d) Business Associate will forward to Covered Entity, within five business days, any request it receives directly from an Individual to exercise a right under Subpart E of 45 C.F.R. Part 164, and will not respond to that request itself except at Covered Entity’s direction.
(e) To the extent Business Associate carries out any of Covered Entity’s obligations under Subpart E, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in performing them.
2.7 Records and regulator access
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining compliance with HIPAA, and will notify Covered Entity of any such request unless legally prohibited from doing so.
2.8 Legal process
If Business Associate receives a subpoena, civil investigative demand, or other legal process seeking Covered Entity’s PHI, Business Associate will, unless legally prohibited, promptly notify Covered Entity, will not produce PHI before the response deadline where notice has been given, and will reasonably cooperate with Covered Entity’s efforts to limit or quash the request at Covered Entity’s expense.
3. Permitted Uses and Disclosures
3.1 Business Associate may use and disclose PHI as necessary to perform the Services for Covered Entity and as otherwise permitted by this BAA.
3.2 Business Associate may use and disclose PHI as Required By Law.
3.3 Business Associate will make uses, disclosures, and requests for PHI consistent with Covered Entity’s minimum-necessary policies and procedures, as communicated to Business Associate.
3.4 Business Associate may use PHI for its own proper management and administration and to carry out its legal responsibilities.
3.5 Business Associate may disclose PHI for its own proper management and administration or to carry out its legal responsibilities if the disclosure is Required By Law, or if Business Associate obtains reasonable written assurances that the recipient will hold the information confidentially, will use or further disclose it only as Required By Law or for the purpose for which it was disclosed, and will notify Business Associate of any breach of confidentiality.
3.6 Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c) and may use and disclose the resulting de-identified data as permitted by the Subscription Agreement.
3.7 Business Associate may provide data aggregation services relating to Covered Entity’s health care operations, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
4. Obligations of Covered Entity
4.1 Covered Entity will notify Business Associate of any limitation in its notice of privacy practices under 45 C.F.R. § 164.520, any change in or revocation of an Individual’s permission to use or disclose PHI, and any restriction on use or disclosure that Covered Entity has agreed to or must abide by under 45 C.F.R. § 164.522, in each case to the extent it may affect Business Associate’s use or disclosure of PHI.
4.2 Except with respect to the uses and disclosures permitted by Sections 3.4, 3.5, 3.6, and 3.7, Covered Entity will not ask Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Covered Entity.
4.3 Covered Entity is responsible for obtaining and maintaining any consent, authorization, or parental permission required for the information it enters into the Services, and for configuring and using the access controls, user management, and other security features Business Associate makes available.
4.4 Scope exclusion. The Services are not intended for, and Covered Entity will not enter into the Services, records subject to 42 C.F.R. Part 2 (substance use disorder records held by a federally assisted Part 2 program) without a separate written agreement with Business Associate.
5. Term and Termination
5.1 This BAA takes effect on the Effective Date and continues until the Subscription Agreement terminates or expires, or until this BAA is terminated under Section 5.2, whichever is earlier.
5.2 Covered Entity may terminate this BAA and the Subscription Agreement on written notice if Business Associate has materially breached this BAA and has not cured the breach within thirty days after written notice describing it.
5.3 PHI on termination
(a) For sixty days after termination, Business Associate will make PHI available for Covered Entity to export in a machine-readable format, as described in the Subscription Agreement.
(b) On Covered Entity’s written instruction, Business Associate will return or destroy the PHI it maintains, and will provide written confirmation on request.
(c) Business Associate has no obligation to retain PHI after the sixty-day export period and may destroy it at any time thereafter. Business Associate does not offer extended or archival retention of PHI. Covered Entity is solely responsible for exporting and independently retaining any records it is required to keep under applicable law, professional licensure rules, or payor requirements.
(d) Business Associate may otherwise retain only the PHI necessary for its proper management and administration or to carry out its legal responsibilities, will continue to apply the safeguards in Section 2.2 to it, will not use or disclose it other than as permitted by Sections 3.4 and 3.5, and will destroy it when it is no longer needed for those purposes.
(e) If return or destruction is infeasible, Business Associate will notify Covered Entity, explain why, and extend the protections of this BAA to the retained PHI for as long as it is retained.
5.4 The obligations in this Section survive termination.
6. General
6.1 Regulatory references. A reference to a provision of HIPAA means that provision as then in effect or as amended.
6.2 Amendment. The parties will take such action as is necessary to amend this BAA from time to time as required for Covered Entity or Business Associate to comply with HIPAA or other applicable law.
6.3 Interpretation. Any ambiguity in this BAA will be resolved to permit compliance with HIPAA.
6.4 Governing law and disputes. This BAA is governed by the laws of the State of Florida, and the dispute-resolution provisions of the Subscription Agreement — binding arbitration before a single arbitrator under the American Arbitration Association Commercial Arbitration Rules, seated in Miami-Dade County, Florida, with the exceptions and class waiver stated there — apply to this BAA, except to the extent preempted by federal law, including HIPAA.
6.5 Notices. Notices under this BAA must be in writing and are effective when delivered by personal delivery, by nationally recognized overnight courier, or by email with confirmation of receipt. Notices to Business Associate must be sent to Office Puzzle, Inc., Attn: Legal, 760 NW 107th Ave, Suite 420, Miami, FL 33172, and by email to legal@officepuzzle.com. Notices to Covered Entity will be sent to the administrator email address on record. The mechanics in this Section control for any notice involving PHI, including breach notification.
6.6 No third-party beneficiaries. Nothing in this BAA confers any right or remedy on any person other than the parties and their permitted successors and assigns.
6.7 Precedence. As to any matter involving PHI, this BAA controls over the Subscription Agreement. In all other respects the Subscription Agreement controls. This BAA supersedes any prior business associate agreement between the parties with respect to conduct occurring after the Effective Date.
6.8 Severability and counterparts. If any provision is held invalid or unenforceable, the remainder stays in effect to the extent it can reasonably be given effect. This BAA may be accepted electronically and in counterparts, each of which is an original.