ChartVoyantSecure e-signature

Business Associate Agreement — Covered Entity

Signed by a practice alongside the Practice Services Agreement. Nothing may send protected health information before both parties have signed it.

  1. 1 · Your email
  2. 2 · Verify
  3. 3 · Complete & sign
  4. 4 · Done

Start signing

We email you a six-digit code to confirm the address, then you complete and sign the agreement. It takes a few minutes.

The executed copy is sent here. Use an address you can open right now.

Read the agreement first

The agreement

CV-BAA-002 · version 1.0. This is the text you are signing; the copy we email you contains it in full, with your answers and a certificate of completion.

Document control
Document IDCV-BAA-002
Version1.0
Effective date(per executed copy)
OwnerSecurity Official (see CV-DES-001)
Review cycleAnnually, and on any change to the HIPAA Rules that affects this Agreement
Retention6 years from the date the agreement terminates (§164.316(b)(2)(i))
Legal entityGeach Medical, PLLC ("the Company"), trading as ChartVoyant

Companion documents: CV-BAA-003 subcontractor agreement (the downstream half of the same chain) · CV-BAA-001 vendor register · CV-POL-001 policies · CV-IRP-001 incident response and breach notification


1. Parties and background

This Business Associate Agreement ("Agreement") is entered into by:

Covered Entity__________ ("Covered Entity")
Address__________
Business AssociateGeach Medical, PLLC trading as ChartVoyant ("Business Associate")
Address__________
Effective Date____

Background. Covered Entity is a covered entity as defined at 45 CFR §160.103. Business Associate provides an electronic health record and related services to Covered Entity (the "Services") under a separate agreement (the "Underlying Agreement"). In performing the Services, Business Associate creates, receives, maintains or transmits protected health information on behalf of Covered Entity and is therefore a business associate as defined at §160.103. The parties enter this Agreement to satisfy §164.502(e), §164.504(e) and §164.314(a).

Where this Agreement and the Underlying Agreement conflict on a matter governed by the HIPAA Rules, this Agreement governs.

2. Definitions

Terms used but not defined here have the meanings given in 45 CFR Parts 160 and 164. "PHI" means protected health information created, received, maintained or transmitted by Business Associate for or on behalf of Covered Entity. "ePHI" means PHI in electronic form. "HIPAA Rules" means the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164, as amended. References to a regulation include any successor provision.

3. Permitted and required uses and disclosures

(§164.504(e)(2)(i) — the contract must establish these. Everything Business Associate may lawfully do with PHI is in this section; anything not listed is prohibited by §4(a).)

(a) Business Associate may use and disclose PHI only as necessary to perform the Services, as required by law, or as this Agreement otherwise permits.

(b) Business Associate may use PHI as necessary for the proper management and administration of Business Associate and to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only if the disclosure is required by law, or Business Associate obtains reasonable assurances from the recipient — in writing — that the PHI will be held confidentially and used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality. For the avoidance of doubt, proper management and administration does not include product improvement, benchmarking across customers, or the training or evaluation of any model. (§164.504(e)(4))

(c) Business Associate may not use or disclose PHI in a manner that would violate Subpart E of Part 164 if done by Covered Entity, except as permitted by §3(b).

(d) Business Associate will limit its uses, disclosures and requests of PHI to the minimum necessary to accomplish the intended purpose, consistent with §164.502(b) and §164.514(d).

(e) De-identification, limited data sets and data aggregation. Business Associate has no right to de-identify PHI, to create a limited data set, or to perform data aggregation except as expressly granted below. Each rests on a separate provision — data aggregation at §164.504(e)(2)(i)(B), de-identification at §164.514(a)–(b), and a limited data set at §164.514(e) and §164.504(e)(3)(iv) — and none is granted by implication.

☐ Not granted (the default). ☐ Granted, as follows: __________

4. Obligations of Business Associate

(Each clause below maps to a required provision. Citations are kept in the text on purpose — an auditor reading this should be able to check completeness without a crosswalk.)

(a) Use and disclosure. Business Associate will not use or further disclose PHI other than as permitted or required by this Agreement or as required by law. (§164.504(e)(2)(ii)(A))

(b) Safeguards. Business Associate will use appropriate safeguards, and will comply with Subpart C of Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. (§164.504(e)(2)(ii)(B); §164.314(a)(2)(i)(A))

(c) Reporting. Business Associate will report to Covered Entity:

  1. any use or disclosure of PHI not provided for by this Agreement of which it becomes aware (§164.504(e)(2)(ii)(C));
  2. any security incident of which it becomes aware (§164.314(a)(2)(i)(C)); and
  3. any breach of unsecured PHI, in accordance with §164.410.

For a breach of unsecured PHI, Business Associate will notify Covered Entity without unreasonable delay and in no case later than 60 calendar days after discovery, and will include the information required by §164.410(c) to the extent known, supplementing it as further information becomes available, except where §164.412 permits a delay at the request of law enforcement.

A breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to Business Associate — and Business Associate is deemed to know of a breach known, or knowable by reasonable diligence, to any employee, officer or other agent of Business Associate other than the person who committed it, determined under the federal common law of agency. (§164.410(a)(2), (b), (c))

Unsuccessful security incidents that result in no unauthorized access to, or use, disclosure, modification or destruction of, PHI — for example blocked scans, pings, port scans and failed log-in attempts — may be reported in the aggregate, at a frequency the parties agree and not less than annually.

(d) Subcontractors. Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement, including compliance with Subpart C with respect to ePHI. (§164.502(e)(1)(ii); §164.308(b)(2); §164.504(e)(2)(ii)(D); §164.314(a)(2)(i)(B))

(e) Access. Business Associate will make PHI in a designated record set available to Covered Entity — or, at Covered Entity's direction, to the individual or the individual's designee — as necessary for Covered Entity to satisfy §164.524, within ten (10) business days of a written request. (§164.504(e)(2)(ii)(E))

(f) Amendment. Business Associate will make PHI in a designated record set available for amendment, and will incorporate any amendment Covered Entity directs, as necessary for Covered Entity to satisfy §164.526, within ten (10) business days of a written request. (§164.504(e)(2)(ii)(F))

(g) Accounting of disclosures. Business Associate will maintain and make available to Covered Entity the information required for an accounting of disclosures, as necessary for Covered Entity to satisfy §164.528, within ten (10) business days of a written request. (§164.504(e)(2)(ii)(G))

(h) Covered Entity's obligations. To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation. (§164.504(e)(2)(ii)(H))

(i) Availability of records to the Secretary. Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Rules. (§164.504(e)(2)(ii)(I))

(j) Notice of requests. Business Associate will notify Covered Entity of any request it receives directly from an individual under §164.524, §164.526 or §164.528, and of any subpoena or other legal process seeking PHI, promptly and before responding, except where prohibited by law.

(k) Pass-down of Covered Entity's notices. Business Associate will pass any notice given under §5(a) down to each of its subcontractors to the extent it affects that subcontractor's use or disclosure of PHI. (The corresponding receiving obligation is at CV-BAA-003 §5(b).)

5. Obligations of Covered Entity

(a) Covered Entity will notify Business Associate of any limitation in its Notice of Privacy Practices under §164.520, of any change in or revocation of an individual's permission to use or disclose PHI, and of any restriction on use or disclosure agreed to under §164.522, in each case to the extent it affects Business Associate's use or disclosure of PHI.

(b) Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E if done by Covered Entity, except as §3(b) permits.

(c) Covered Entity is responsible for obtaining any consent, authorization or attestation required by law for PHI it places into the Services, and for its own Notice of Privacy Practices.

6. Term and termination

(a) Term. This Agreement takes effect on the Effective Date and continues until all PHI is returned or destroyed under §7, or until terminated under §6(b) or §6(c).

(b) Termination for cause. Business Associate authorizes termination of this Agreement by Covered Entity if Covered Entity determines that Business Associate has violated a material term. (§164.504(e)(2)(iii) — this authorization is the mandatory element and is stated without condition.) Covered Entity may, at its option, first give Business Associate thirty (30) days to cure. Termination of this Agreement entitles Covered Entity to terminate the Underlying Agreement.

(c) Termination by either party. Either party may terminate on written notice as provided in the Underlying Agreement.

(d) Survival. Business Associate's obligations under §4(b), §4(c), §4(i) and §7 survive termination for so long as Business Associate retains any PHI.

7. Return or destruction of PHI

(§164.504(e)(2)(ii)(J))

(a) On termination for any reason, Business Associate will return to Covered Entity or destroy all PHI it created, received, maintained or transmitted on Covered Entity's behalf, including PHI held by its subcontractors, and will retain no copies. Covered Entity elects, by written notice before or at termination:

☐ Return, in a machine-readable format the parties agree in writing. ☐ Destruction. (Absent an election, Business Associate will return the PHI and then destroy its copies.)

(b) Business Associate will complete this within thirty (30) days of termination and will certify completion in writing.

(c) If return or destruction is infeasible, Business Associate will notify Covered Entity in writing of the conditions that make it infeasible, will extend the protections of this Agreement to that PHI for as long as it is retained, and will limit further uses and disclosures to the purposes that make return or destruction infeasible.

8. Miscellaneous

(a) Regulatory references. A reference to a section of the HIPAA Rules means that section as in effect or as amended.

(b) Amendment. The parties will negotiate in good faith to amend this Agreement as necessary for either party to comply with a change in the HIPAA Rules.

(c) Interpretation. Ambiguity is resolved in favour of an interpretation that permits compliance with the HIPAA Rules.

(d) No third-party beneficiaries. Nothing in this Agreement confers rights on any person other than the parties, their successors and permitted assigns.

(e) Counterparts and signatures. This Agreement may be executed in counterparts, and an electronic signature has the same effect as an original.

(f) Governing law. This Agreement is governed by the law that governs the Underlying Agreement.

9. Signatures

Covered EntityBusiness Associate
Entity______Geach Medical, PLLC
Signed____________
Name____________
Title____________
Date____

10. Optional rider — 42 CFR Part 2 (substance use disorder records)

Attach this rider only if it applies.

When it applies. The 2024 Part 2 final rule became enforceable on 16 February 2026 (89 FR 12472). Part 2 attaches to "records" — defined at 42 CFR §2.11 far more broadly than the underlying statute, as any information, recorded or not, created by, received or acquired by a Part 2 program relating to a patient, including billing information, emails, voicemails and texts — held by a federally assisted "Part 2 program". §2.11 defines a Part 2 program in three prongs:

  1. a person other than a general medical facility that holds itself out as providing, and provides, SUD diagnosis, treatment or referral for treatment;
  2. an identified unit within a general medical facility that holds itself out as providing, and provides, the same; or
  3. medical personnel or other staff in a general medical facility whose primary function is SUD diagnosis, treatment or referral and who are identified as such providers.

Records do not lose Part 2 protection by leaving the program — §2.12(d)(2) extends the restrictions to third-party payers, persons with direct administrative control over the program, and recipients notified under §2.32.

A general medical practice that prescribes controlled substances will often fall outside all three prongs; a practice with an identified addiction-medicine or medication-assisted-treatment service line may fall inside the second or third. That determination belongs to Covered Entity, and it is not one to reach by assumption.

What it requires. Where a Part 2 program discloses Part 2 records to a qualified service organization, §2.11's definition of "qualified service organization" requires a written agreement containing two acknowledgements, and the clause below supplies them. The 2024 rule also added §2.11(3), which includes a HIPAA business associate of a Part 2 program that is itself a covered entity within the QSO definition. Two further Part 2 obligations sit outside this rider and outside this Agreement: §2.16 (formal policies and safeguards, and breach notification applied to Part 2 records through 45 CFR Part 160 and Part 164 Subpart D) and §2.32 (the notice and copy of consent that must accompany a disclosure made with the patient's written consent — note that this is a consent-disclosure requirement, not a general redisclosure rule, and §2.32(b) also requires a copy of the consent or a clear explanation of its scope).

Part 2 rider. In receiving, storing, processing or otherwise dealing with any patient records received from Covered Entity that are subject to 42 CFR Part 2, Business Associate: (i) acknowledges that it is fully bound by the regulations in that Part; and (ii) agrees to resist in judicial proceedings any effort to obtain access to patient identifying information relating to substance use disorder diagnosis, treatment or referral for treatment, except as those regulations permit. Business Associate will not redisclose such records except as Part 2 permits, will accompany any permitted redisclosure with the §2.32 notice — whether or not the disclosure is one §2.32 reaches, since §2.32 by its terms applies to disclosures made with the patient's written consent — and will apply the same restrictions to any subcontractor that receives them. (Acknowledgements per the "qualified service organization" definition at 42 CFR §2.11(2)(i) and (ii).) ☐ This rider applies. ☐ This rider does not apply — Covered Entity confirms it is not a Part 2 program and will not place Part 2 records into the Services.

A note on the second election. An electronic medical record cannot distinguish Part 2 records from any others. If Covered Entity elects that this rider does not apply and Part 2 records reach the Services regardless — through an inbound fax, a records request or a clinician's note — the protection will be absent. Where there is doubt, elect the first box.


11. Document history

DateVersionChange
2026-09-021.0Issued. Drafted against 45 CFR §164.504(e), §164.314(a) and §164.410, and against the sample business associate agreement provisions published by the Department of Health and Human Services. An optional 42 CFR Part 2 rider is attached at §10; its compliance date passed on 16 February 2026. The 2024 reproductive-health attestation requirement is deliberately absent: that rule was vacated nationally in Purl v. HHS (June 2025) and the appeals were dropped.