HIPAA Business Associate Agreement

Last updated: May 19, 2026

This Business Associate Agreement ("BAA") is entered into between AjutaCare ("Business Associate") and the home care agency customer ("Covered Entity"). This BAA supplements and is incorporated into the AjutaCare Terms of Service. By using AjutaCare to process Protected Health Information, you agree to this BAA.

Need a Signed BAA?

If your organization requires a countersigned Business Associate Agreement for your records, contact our compliance team and we'll provide one within 2 business days.

Request Signed BAA →

Table of Contents

  1. Definitions
  2. Obligations of Business Associate
  3. Obligations of Covered Entity
  4. Permitted Uses and Disclosures
  5. Subcontractors
  6. Breach Notification
  7. Individual Rights
  8. Term and Termination
  9. Miscellaneous

1. Definitions

Unless otherwise defined herein, capitalized terms have the meanings given to them under HIPAA, the HITECH Act, and their implementing regulations.

2. Obligations of Business Associate

2.1 Use and Disclosure Restrictions

Business Associate agrees not to use or disclose PHI other than as permitted or required by this BAA or as required by law.

2.2 Appropriate Safeguards

Business Associate agrees to use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this BAA. Safeguards include:

2.3 Reporting

Business Associate agrees to report to Covered Entity:

2.4 Workforce Training

Business Associate agrees to ensure that any member of its workforce that creates, receives, maintains, or transmits PHI on behalf of Covered Entity has been trained on HIPAA Privacy and Security requirements.

2.5 Minimum Necessary

Business Associate agrees to make reasonable efforts to use, disclose, and request only the minimum necessary amount of PHI to accomplish the intended purpose.

3. Obligations of Covered Entity

Covered Entity agrees to:

4. Permitted Uses and Disclosures

4.1 Service Delivery

Business Associate may use and disclose PHI as necessary to perform the services described in the AjutaCare Terms of Service, including:

4.2 Operations

Business Associate may use PHI for the proper management and administration of the Business Associate, or to carry out the legal responsibilities of the Business Associate, provided disclosures are required by law or Business Associate obtains reasonable assurances from any recipient.

4.3 De-identified Data

Business Associate may use de-identified data (as defined under 45 CFR §164.514) for improving the Service, product development, and benchmarking, provided such data has been de-identified in accordance with HIPAA standards.

5. Subcontractors

Business Associate agrees to ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate under this BAA.

Current subcontractors handling PHI include our cloud infrastructure provider (DigitalOcean) and email delivery services. All subcontractors are subject to Data Processing Agreements with equivalent protections.

6. Breach Notification

In the event of a Breach of Unsecured PHI, Business Associate will:

Business Associate's obligation to report a Breach shall not be construed as an acknowledgment of fault or liability.

7. Individual Rights

7.1 Access

Business Associate agrees to provide access to PHI in a Designated Record Set to Covered Entity or, as directed by Covered Entity, to an Individual, within 30 days of a request.

7.2 Amendment

Business Associate agrees to make any amendment(s) to PHI in a Designated Record Set as directed by Covered Entity pursuant to 45 CFR §164.526.

7.3 Accounting of Disclosures

Business Associate agrees to document and make available to Covered Entity an accounting of disclosures of PHI as would be required for Covered Entity to respond to an Individual's request for an accounting of disclosures.

7.4 Government Access

Business Associate agrees to make its internal practices, books, and records relating to the use and disclosure of PHI received from Covered Entity available to the Secretary of the Department of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Rules.

8. Term and Termination

8.1 Term

This BAA is effective as of the date Customer first uses AjutaCare to process PHI and remains in effect until the termination of the AjutaCare subscription agreement.

8.2 Termination for Cause

Either party may terminate this BAA if the other party materially breaches a provision of this BAA, and such breach is not cured within 30 days of written notice.

8.3 Effect of Termination

Upon termination of this BAA for any reason, Business Associate agrees to return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity. This provision applies to PHI in the possession of subcontractors as well. Business Associate will retain no copies of the PHI, except as required by law.

If return or destruction is not feasible, Business Associate will extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for as long as Business Associate maintains such PHI.

9. Miscellaneous

9.1 Regulatory References

A reference in this BAA to a section in the HIPAA Rules means the section in effect or as amended.

9.2 Amendment

The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for Covered Entity to comply with the requirements of the HIPAA Rules.

9.3 Interpretation

Any ambiguity in this BAA shall be resolved to permit Covered Entity to comply with the HIPAA Rules.

9.4 No Third Party Beneficiaries

Nothing in this BAA shall confer any rights or remedies upon any person other than the parties and their respective successors and permitted assigns.

9.5 Survival

The obligations of Business Associate under Section 8.3 (Effect of Termination) shall survive the termination of this BAA.

Questions About This BAA?

Our compliance team is available to answer questions, provide clarifications, or issue a countersigned copy of this agreement.

Contact Compliance Team →