Business Associate Agreement

The agreement Modulon signs with every U.S. clinic before handling any patient information: how we may use it, how we protect it, and what happens if something goes wrong.

Last updated

01Parties and purpose#

This Business Associate Agreement (the "Agreement") is between Modulon Health ("Modulon") and the healthcare provider or organization named in the order form that references it (the "Clinic").

The Clinic is a covered entity under the Health Insurance Portability and Accountability Act of 1996, as amended by the HITECH Act, and their implementing regulations (together, "HIPAA"). Modulon provides the Clinic with software and services under a master services agreement and one or more order forms (together, the "Services Agreement"). In doing so, Modulon creates, receives, maintains and transmits protected health information on the Clinic's behalf, and so acts as the Clinic's business associate.

This Agreement sets out how Modulon may use and disclose that information and how it must protect it, as required by 45 C.F.R. §§ 164.308, 164.314, 164.410 and 164.504(e). Clinics outside the United States sign our Data Processing Agreement instead.

02Definitions#

Capitalized terms used but not defined in this Agreement have the meanings given to them in HIPAA, including Breach, Data Aggregation, Designated Record Set, Disclosure, Individual, Minimum Necessary, Required by Law, Secretary, Security Incident, Unsecured Protected Health Information and Use. In addition:

  • "PHI" means protected health information, as defined in 45 C.F.R. § 160.103, that Modulon creates, receives, maintains or transmits on behalf of the Clinic. It includes electronic PHI.
  • "Services" means the services Modulon provides to the Clinic under the Services Agreement, including operating, maintaining, securing and supporting the Modulon platform.
  • "Subcontractor" means a person or company to whom Modulon delegates a function involving PHI. Our current Subcontractors are listed on our subprocessors page.
  • "Business day" means a day other than a Saturday, Sunday or U.S. federal holiday.

03Permitted uses and disclosures#

To provide the Services

Modulon may use and disclose PHI as necessary to perform the Services for the Clinic, provided that the use or disclosure would not violate HIPAA if done by the Clinic itself.

Management and administration

Modulon may use PHI for its own proper management and administration and to carry out its legal responsibilities. It may disclose PHI for those purposes only if the disclosure is Required by Law, or if Modulon first obtains reasonable written assurances from the recipient that it will hold the PHI confidentially, use or further disclose it only as Required by Law or for the purpose for which it was disclosed, and notify Modulon of any instance in which the confidentiality of the PHI has been breached.

Data aggregation

Modulon may use PHI to provide Data Aggregation services relating to the health care operations of the Clinic, only when the Clinic asks for them in writing.

De-identification

Modulon may de-identify PHI in accordance with 45 C.F.R. § 164.514(b) only to provide the Services to the Clinic, such as to report on the Clinic's own operations, or as the Clinic otherwise authorizes in writing.

Required by law

Modulon may use or disclose PHI as Required by Law. Unless the law prohibits it, Modulon will notify the Clinic before making such a disclosure, so the Clinic can seek a protective order or other remedy.

Minimum necessary

Modulon will limit every use, disclosure and request for PHI to the minimum necessary to accomplish its intended purpose, in accordance with 45 C.F.R. § 164.502(b) and the Clinic's reasonable minimum necessary policies that it shares with Modulon.

04Restrictions#

Modulon will not use or disclose PHI other than as this Agreement permits or as Required by Law. It will not:

  • Sell PHI, or receive any payment, direct or indirect, in exchange for PHI.
  • Use or disclose PHI for marketing or fundraising.
  • Use PHI, or information de-identified from it, to train or improve general-purpose artificial intelligence models, or allow any Subcontractor to do so.
  • Store or process PHI outside the United States.
  • Use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Clinic, except as permitted by Section 3 for management, administration and Data Aggregation.

Where Modulon carries out one of the Clinic's obligations under Subpart E of 45 C.F.R. Part 164, it will comply with the requirements of that Subpart that apply to the Clinic in carrying out that obligation.

05Safeguards#

Modulon will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, to prevent any use or disclosure of PHI other than as this Agreement provides. At a minimum, Modulon will:

  • Maintain a written information security program, a designated security officer, and a risk analysis that is reviewed at least once a year.
  • Encrypt PHI in transit with TLS 1.2 or higher and at rest with AES-256.
  • Limit access to PHI by role, require unique accounts and multi-factor authentication, and remove access promptly when it is no longer needed.
  • Keep an audit trail of every action taken on PHI in the platform, whether by staff or by the AI.
  • Train its workforce on HIPAA and security when they join and every year after, and bind everyone with access to PHI to confidentiality.
  • Maintain and test an incident response plan and a contingency plan, including encrypted backups.

Our Security page describes these safeguards in more detail. Modulon may update them over time, provided that no change reduces the overall protection of PHI.

06Reporting#

Reports under this section are sent to the Clinic's designated privacy contact, or to its account administrator if no privacy contact has been named.

Breaches of unsecured PHI

Modulon will notify the Clinic of any Breach of Unsecured Protected Health Information without unreasonable delay, and in no case later than ten business days after discovering it. A Breach is treated as discovered on the first day it is known to Modulon, or would have been known by exercising reasonable diligence, as set out in 45 C.F.R. § 164.410(a)(2).

The notice will include, to the extent then known, the identity of each Individual whose PHI was or is reasonably believed to have been involved, a description of what happened, the dates of the Breach and of its discovery, the types of PHI involved, the steps Modulon is taking to investigate, mitigate harm and prevent a recurrence, and any other information the Clinic needs to notify Individuals, the Secretary and, where required, the media under 45 C.F.R. §§ 164.404 to 164.408. Modulon will supplement the notice as more information becomes available.

Other unpermitted uses and disclosures

Modulon will report to the Clinic any use or disclosure of PHI not provided for by this Agreement within ten business days of becoming aware of it, whether or not it amounts to a Breach.

Security incidents

Modulon will report to the Clinic any successful Security Incident involving electronic PHI within ten business days of becoming aware of it. The parties agree that this section serves as notice, with no further report required, of unsuccessful Security Incidents, such as pings, port scans, denied sign-in attempts and blocked denial-of-service attempts, that do not result in unauthorized access to, or use, disclosure, modification or destruction of, PHI.

Mitigation and cooperation

Modulon will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement. It will cooperate with the Clinic's investigation and keep the Clinic informed as its own investigation proceeds. Modulon will not notify affected Individuals, regulators or the media of a Breach on the Clinic's behalf unless the Clinic asks it to in writing.

Notification costs

Where a Breach is caused by Modulon or its Subcontractors, Modulon will reimburse the Clinic for the reasonable costs of the notifications that HIPAA or other applicable law requires the Clinic to give, and of any credit monitoring that law or regulators require it to offer.

07Subcontractors#

In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Modulon will ensure that every Subcontractor that creates, receives, maintains or transmits PHI on its behalf first agrees in writing to the same restrictions, conditions and requirements that apply to Modulon under this Agreement, including the safeguards in Section 5 and the restriction on training artificial intelligence models in Section 4. Modulon remains responsible to the Clinic for the acts and omissions of its Subcontractors with respect to PHI.

Modulon will notify the Clinic at least 30 days before a new Subcontractor begins handling PHI. If the Clinic objects on reasonable grounds related to the protection of PHI, the parties will work in good faith to resolve the objection. If they cannot, the Clinic may end the affected Services without penalty and receive a refund of any fees prepaid for them.

If Modulon learns of a pattern of activity or practice of a Subcontractor that is a material breach of its agreement with Modulon, Modulon will take reasonable steps to cure the breach or end the violation, and if those steps are unsuccessful, will end the Subcontractor's access to PHI.

08Individual rights#

Access

To the extent Modulon maintains PHI in a Designated Record Set, it will make that PHI available to the Clinic, in the electronic form and format the Clinic reasonably asks for, within ten business days of the Clinic's request, so the Clinic can meet its obligations under 45 C.F.R. § 164.524.

Amendment

To the extent Modulon maintains PHI in a Designated Record Set, it will make any amendment to that PHI the Clinic directs under 45 C.F.R. § 164.526 within ten business days of the Clinic's request.

Accounting of disclosures

Modulon will document disclosures of PHI as needed for the Clinic to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528, and will provide that information to the Clinic within ten business days of its request. Clinic administrators can also export the platform's audit trail at any time.

Restrictions and confidential communications

Modulon will comply with any restriction on the use or disclosure of PHI, or request for confidential communications, that the Clinic has agreed to under 45 C.F.R. § 164.522 and tells Modulon about in writing, to the extent it affects Modulon's use or disclosure of PHI.

Requests made to Modulon

If an Individual makes any of these requests directly to Modulon, Modulon will forward it to the Clinic within five business days and will not respond to the Individual itself unless the Clinic directs it to.

09The Clinic's obligations#

The Clinic will:

  • Tell Modulon of any limitation in its Notice of Privacy Practices, and of any change in or revocation of an Individual's permission, to the extent it may affect Modulon's use or disclosure of PHI.
  • Not ask Modulon to use or disclose PHI in any manner that would not be permitted under HIPAA if done by the Clinic, except as Section 3 allows for Modulon's management, administration and Data Aggregation.
  • Obtain any consent or authorization that HIPAA or other applicable law requires before PHI is shared with Modulon or used for the Services, including the consents needed for calls and texts sent to patients on its behalf.
  • Share with Modulon only the PHI reasonably needed for the Services, and use the platform's access controls to grant its own staff only the access their roles require.

10Records and audits#

Modulon will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary for the purpose of determining compliance with HIPAA. Unless the law prohibits it, Modulon will tell the Clinic of any such request and give it a copy of anything it provides.

Once a year, and following any Breach, Modulon will on request give the Clinic a completed security questionnaire, a summary of its most recent risk analysis and independent security testing, and its current list of Subcontractors.

11Term and termination#

Term

This Agreement takes effect on the earlier of the date the Clinic signs an order form that references it and the date Modulon first receives PHI from the Clinic. It continues for as long as the Services Agreement is in effect, and after that until Modulon has returned or destroyed all PHI as set out below.

Termination for breach

If either party determines that the other has materially breached this Agreement, it will give the other written notice describing the breach. If the breach is not cured within 30 days of that notice, the non-breaching party may end this Agreement and the affected parts of the Services Agreement. Where cure is not possible, it may end them immediately.

Return or destruction of PHI

When this Agreement ends, the Clinic may export its data for 30 days. Within 60 days after this Agreement ends, Modulon will return to the Clinic or destroy all PHI it and its Subcontractors still hold, retain no copies, and certify the return or destruction in writing.

PHI held in encrypted backups is destroyed as those backups expire under Modulon's regular rotation, within 90 days after this Agreement ends. Where returning or destroying any PHI is otherwise infeasible, Modulon will tell the Clinic why, extend the protections of this Agreement to that PHI, and limit its further use and disclosure to the purposes that make return or destruction infeasible, for as long as Modulon holds it.

Survival

Modulon's obligations under this section, and under Sections 4, 5 and 6 for as long as it holds any PHI, survive the end of this Agreement.

12General#

Precedence

This Agreement forms part of the Services Agreement. If they conflict on any matter relating to PHI, this Agreement controls.

Changes in law

The parties will amend this Agreement as necessary for either of them to comply with any change in HIPAA. Any reference to a section of HIPAA means that section as in effect or as amended, and any ambiguity in this Agreement will be resolved in favor of a meaning that permits both parties to comply with HIPAA.

Amendments to this text

Modulon may publish updated versions of this Agreement on this page. An update applies to an existing Clinic only if the Clinic accepts it in writing, or if it is required by a change in law and Modulon gives the Clinic at least 30 days' notice. No other amendment is effective unless it is in writing and signed by both parties.

No third-party beneficiaries

Nothing in this Agreement gives any person other than the Clinic and Modulon, and their permitted successors and assigns, any rights, remedies, obligations or liabilities.

Independent parties

Modulon is an independent contractor and not an agent of the Clinic for purposes of federal common law under HIPAA.

Governing law

This Agreement is governed by HIPAA and, to the extent not preempted by it, by the laws of the State of Delaware, without regard to conflict-of-law rules.

Notices

Notices to the Clinic are sent to the contacts named in its order form or in the platform's settings. Notices to Modulon are sent to hello@modulonhealth.com.

13Signing this agreement#

The Clinic accepts this Agreement by signing an order form that references it. Modulon sends this Agreement with every pilot order form, and both are signed electronically before onboarding begins and before any PHI is shared. Each party receives a countersigned copy.

A multi-location group, management services organization or health system may sign one Agreement that covers each of its affiliated practices named in its order form. Each such practice is then a Clinic under this Agreement.

If your organization has its own BAA template, we are glad to review it in its place. Most terms can be accommodated, and we will flag any that conflict with how the Services work. To request a copy of this Agreement to sign, or to send us your own, write to hello@modulonhealth.com.

Questions about this page? Write to hello@modulonhealth.com.