Business Associate Agreement
Last updated: August 20, 2026
This Business Associate Agreement (the "BAA") is between Pragmatic Business Solutions, LLC, doing business as Vadia Health ("Business Associate"), and the practice, clinic, or other covered entity that uses the Vadia Health platform ("Covered Entity"). It takes effect when the Covered Entity accepts the Terms of Service or first submits protected health information to the Service, whichever is earlier, and it is incorporated into those Terms. A countersigned copy on paper is available on request. Where this BAA and any other agreement conflict as to protected health information, this BAA controls.
1. Definitions
Terms used but not defined here have the meaning given in the HIPAA Rules — the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended, including by the HITECH Act. "PHI" means protected health information, as defined at 45 CFR § 160.103, that Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity. "Electronic PHI" and "Security Incident" have the meanings at 45 CFR § 160.103 and § 164.304. "Breach" has the meaning at 45 CFR § 164.402. "Required by Law" has the meaning at 45 CFR § 164.103. "Service" means the Vadia Health platform.
2. Permitted uses and disclosures
Business Associate may use and disclose PHI only: (a) to perform the services described in the Terms of Service and any order form — hosting, scheduling, clinical documentation, telehealth, communications, forms and e-signature, billing and revenue-cycle processing, support, and the security and availability of the Service; (b) as Required by Law; (c) for the proper management and administration of Business Associate, or to carry out its legal responsibilities; (d) to provide data aggregation services relating to the health care operations of Covered Entity, as permitted by 45 CFR § 164.504(e)(2)(i)(B); and (e) to de-identify PHI in accordance with 45 CFR § 164.514(b), after which the resulting data is not PHI and is governed by the Terms of Service rather than this BAA. Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as clauses (c) and (d) permit.
3. Disclosures for Business Associate's own management
Business Associate may disclose PHI for the purposes in section 2(c) only if the disclosure is Required by Law, or if Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
4. What Business Associate will never do with PHI
Business Associate will not sell PHI or receive remuneration in exchange for PHI except as 45 CFR § 164.502(a)(5)(ii) permits; will not use or disclose PHI for marketing or fundraising as those terms are defined at 45 CFR § 164.501 without a valid authorization; will not use PHI for its own advertising or product-marketing purposes; will not use PHI to train, fine-tune, or otherwise improve any general-purpose artificial-intelligence model, whether its own or a third party's; and will not disclose PHI for marketing purposes without the authorization required by Texas Health and Safety Code § 181.152.
5. Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to Electronic PHI, to prevent use or disclosure of PHI other than as this BAA provides. Those safeguards include, at minimum: per-tenant isolation enforced in the database by row-level security; encryption of PHI in transit and at rest; role-based least-privilege access; multi-factor authentication for privileged access; an append-only, tamper-evident audit trail of access and change; workforce training and sanctions; exclusion of PHI from application logs, URLs, error reports, and analytics; and a documented contingency and disaster-recovery plan with tested restoration.
6. Reporting security incidents and breaches
Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this BAA of which it becomes aware, any Security Incident, and any Breach of unsecured PHI. Notice of a Breach will be given without unreasonable delay and in no case later than TEN (10) BUSINESS DAYS after discovery — a window the parties agree is shorter than the sixty-day outer limit at 45 CFR § 164.410 — and will include, to the extent known, the individuals affected, what happened, when it happened and was discovered, the PHI involved, and the mitigation and corrective steps taken, with supplemental information as the investigation develops. The parties agree that unsuccessful attempts at unauthorized access that are routine and cause no unauthorized access, use, disclosure, modification, or interference — such as scans, pings, and blocked log-in attempts — need not be reported individually, and this paragraph is notice of them. Business Associate will mitigate, to the extent practicable, any harmful effect known to it of an impermissible use or disclosure. Covered Entity is responsible for making the notifications required of it by 45 CFR §§ 164.404-164.408, and Business Associate will cooperate with them.
7. Subcontractors
In accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as stringent as those that apply to Business Associate under this BAA, and will obtain documented assurances of that subcontractor's safeguards rather than relying on signature alone. Business Associate remains responsible to Covered Entity for its subcontractors' performance. The current list of subprocessors, and which of them handle PHI, is published at vadiahealth.com/subprocessors; Business Associate will give reasonable advance notice of a new subprocessor that will handle PHI, and Covered Entity may object on reasonable data-protection grounds, in which case the parties will work in good faith toward a resolution and Covered Entity may terminate if none is reached.
8. Individual access to PHI
Business Associate will make PHI in a designated record set available to Covered Entity, and where required to an individual, as necessary for Covered Entity to meet its obligations under 45 CFR § 164.524, within a reasonable time and in any event within fifteen (15) business days of a written request, and in the electronic form and format requested where readily producible. Business Associate will forward to Covered Entity, without responding to it, any request it receives directly from an individual.
9. Amendment of PHI
Business Associate will make PHI in a designated record set available for amendment, and will incorporate any amendment Covered Entity directs, as necessary for Covered Entity to meet its obligations under 45 CFR § 164.526, within fifteen (15) business days of a written request. Amendments are appended and versioned; an existing entry is never silently overwritten.
10. Accounting of disclosures
Business Associate will document disclosures of PHI and information related to them as would be required for Covered Entity to respond to a request for an accounting under 45 CFR § 164.528, and will make that documentation available to Covered Entity within fifteen (15) business days of a written request. The Service's tamper-evident audit trail and disclosure log are the source of truth for that accounting.
11. Minimum necessary
Business Associate will limit its uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 CFR §§ 164.502(b) and 164.514(d) and with Covered Entity's minimum-necessary policies, except where the minimum-necessary standard does not apply.
12. Compliance with Covered Entity's obligations
To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164, it will comply with the requirements that apply to Covered Entity in performing that obligation. Business Associate will comply with any restriction on the use or disclosure of PHI that Covered Entity has agreed to under 45 CFR § 164.522, and with any request for confidential communications, to the extent Covered Entity notifies Business Associate of it in writing and the Service can give it effect.
13. Availability of records to the Secretary
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules, and will notify Covered Entity of such a request to the extent the law permits.
14. Covered Entity's obligations
Covered Entity will: obtain any consent, authorization, or permission required for Business Associate to use and disclose PHI as this BAA contemplates; notify Business Associate of any limitation in its Notice of Privacy Practices, of any change in or revocation of an individual's permission, and of any restriction agreed to under 45 CFR § 164.522, to the extent it affects Business Associate's use or disclosure; configure and administer the Service — roles, permissions, retention settings, and communications consent — appropriately for its practice; and not request that Business Associate use or disclose PHI in a way that would violate the HIPAA Rules or other law if done by Covered Entity, except as sections 2(c) and 2(d) permit.
15. Substance use disorder records
Where Covered Entity operates a federally assisted substance use disorder program, Business Associate acts as a qualified service organization under 42 CFR § 2.11 and, consistent with 42 CFR § 2.12(c)(4), acknowledges that in receiving, storing, or transmitting patient identifying information it is fully bound by 42 CFR Part 2; will resist in judicial proceedings any effort to obtain access to that information except as Part 2 permits; and will apply the security and disclosure-limiting measures Part 2 requires, including the prohibition on redisclosure without consent or a Part 2 exception.
16. Texas law
Business Associate is a covered entity as that term is used in the Texas Medical Records Privacy Act (Texas Health and Safety Code Chapter 181) and will comply with it, including its workforce-training requirement, its restriction on disclosure of PHI for marketing, and its provisions on electronic disclosure. Business Associate will handle mental-health records consistently with the confidentiality requirements of Texas Health and Safety Code Chapter 611, and will give the notice required by the Texas Identity Theft Enforcement and Protection Act (Texas Business and Commerce Code Chapter 521) for any breach of sensitive personal information that is not otherwise covered by the HIPAA Breach Notification Rule. PHI is stored in the United States.
17. Term and termination
This BAA takes effect as stated above and continues until all PHI is returned or destroyed or, if return or destruction is infeasible, until the protections in section 18 are extended to it. Covered Entity may terminate this BAA and the Terms of Service if Business Associate materially breaches this BAA and fails to cure within thirty (30) days of written notice, and Business Associate has the same right as to Covered Entity's material breach. Termination of the Terms of Service terminates this BAA, subject to the survival of section 18.
18. Return or destruction of PHI on termination
On termination, Business Associate will return or destroy all PHI it maintains for Covered Entity and will retain no copies, except that: it will make PHI available for export for at least thirty (30) days after termination; and to the extent return or destruction is infeasible — including PHI held in backups that age out on a fixed cycle, and PHI Business Associate must retain to meet its own legal, audit, or record-retention obligations — Business Associate will extend the protections of this BAA to that PHI, limit further uses and disclosures to the purposes that make return or destruction infeasible, and destroy it when those purposes end. Business Associate will confirm destruction in writing on request.
19. Interpretation, amendment, and miscellaneous
Any ambiguity in this BAA is resolved in favor of a meaning that complies with the HIPAA Rules. The parties will take such action as is necessary to amend this BAA from time to time so that each complies with the requirements of the HIPAA Rules and applicable Texas law, and Business Associate may publish an updated BAA with at least thirty (30) days' notice; continued submission of PHI after the effective date constitutes acceptance, and Covered Entity may terminate instead. Nothing in this BAA creates a third-party beneficiary right in any individual. This BAA is governed by the laws of the State of Texas and by federal law, and the venue and dispute-resolution provisions of the Terms of Service apply. Except as this BAA provides, the Terms of Service — including their limitations of liability — apply to it. HIPAA does not create a private right of action.
20. Requesting a signed copy
A practice that needs a countersigned BAA for its own compliance file, or that needs Vadia to sign the practice's own BAA form, may request one at [email protected]. A signed practice form supersedes this online BAA to the extent the two conflict.