Legal · Template

Business Associate Agreement

Last updated · June 1, 2026
This is our template Business Associate Agreement, executed with every customer that handles PHI. Email partners@louneh.ai to request a fully executed copy on your business’s letterhead for your records.

This Business Associate Agreement (“BAA”) is entered into between Louneh, Inc. (“Business Associate”) and the entity identified on the signature page (“Covered Entity”) to comply with the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH (“HIPAA”), and its implementing regulations at 45 CFR Parts 160 and 164.

1. Parties and effective date

This BAA takes effect on the date Covered Entity first transmits PHI through the Services, or on the date of execution, whichever is earlier. It supplements and is incorporated into the Terms of Service between the parties; where this BAA and those Terms conflict regarding PHI, this BAA controls.

2. Definitions

Capitalized terms used but not defined in this BAA have the meanings assigned to them in HIPAA. “PHI” means Protected Health Information that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.

3. Permitted uses and disclosures

Business Associate may use and disclose PHI only:

  • To perform the Services for Covered Entity, as described in the underlying Terms of Service.
  • For the proper management and administration of Business Associate, provided that any disclosure is required by law or made with reasonable assurances of confidentiality and notice of any breach.
  • To carry out Business Associate’s legal responsibilities.
  • For data aggregation services, as that term is defined at 45 CFR § 164.501.

Business Associate will not use or disclose PHI in any manner that would violate HIPAA if done by Covered Entity, except as permitted above.

4. Safeguards

Business Associate will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, as required by the HIPAA Security Rule (45 CFR Part 164, Subpart C). Current safeguards are described on the public Security page; material reductions will be communicated to Covered Entity in writing.

5. Reporting breaches

Business Associate will report to Covered Entity:

  • Any use or disclosure of PHI not permitted by this BAA of which it becomes aware, without unreasonable delay and no later than 30 days after discovery.
  • Any Security Incident as defined by 45 CFR § 164.304, with the timing and content required by the Security Rule.
  • Any Breach of Unsecured PHI under 45 CFR § 164.402, without unreasonable delay and no later than 60 days after discovery, in the form required by 45 CFR § 164.410.

Louneh’s practical commitment is to provide written notice of confirmed PHI breaches within 72 hours; the regulatory floors above are the contractual fallback.

6. Subcontractors

Business Associate will enter into written agreements with any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf, requiring the Subcontractor to comply with substantially the same restrictions and conditions as this BAA. The current Subcontractor list is published at /sub-processors.

7. Access, amendment, accounting

To the extent Business Associate maintains a Designated Record Set on behalf of Covered Entity, Business Associate will:

  • Make PHI available to Covered Entity to fulfill an Individual’s right of access under 45 CFR § 164.524.
  • Make PHI available for amendment, and incorporate amendments, as required by 45 CFR § 164.526.
  • Document and make available the information needed to provide an accounting of disclosures, as required by 45 CFR § 164.528.

8. Minimum necessary

Business Associate will request, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose of the use, disclosure, or request, in accordance with 45 CFR § 164.502(b).

9. Audit cooperation

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining Covered Entity’s compliance with HIPAA.

10. Term and termination

This BAA is effective as set out in Section 1 and continues until terminated. Either party may terminate this BAA for material breach if the breach is not cured within 30 days of written notice. If termination is not feasible, the non-breaching party may report the breach to the Secretary.

11. Return or destruction of PHI

On termination of this BAA, Business Associate will, if feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity that Business Associate still maintains, and will retain no copies. Where return or destruction is not feasible, Business Associate will extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, for as long as Business Associate maintains the PHI.

12. Miscellaneous

This BAA will be interpreted to permit compliance with HIPAA. Amendments to HIPAA that affect the rights and obligations of the parties are incorporated by reference on their effective date. This BAA is governed by the laws of the State of Delaware.

Help & support

Ask about any platform task. The AI assistant uses our public guides and cannot view or change your account.

Keep patient details, passwords and verification codes out of messages.