Business Associate Agreement — Subcontractor
What a vendor signs before any patient data reaches it — the downstream half of the same chain as the customer BAA.
- 1 · Your email
- 2 · Verify
- 3 · Complete & sign
- 4 · Done
Start signing
We email you a six-digit code to confirm the address, then you complete and sign the agreement. It takes a few minutes.
The executed copy is sent here. Use an address you can open right now.
Subcontractor
These answers complete §1 and are printed on the Execution Schedule.
What this vendor does for ChartVoyant that involves protected health information.
Where ChartVoyant sends an incident notice, and who is reached for the §164.410 clock.
Who is signing
As it should appear on the agreement.
The agreement
CV-BAA-003 · version 1.0. This is the text you are signing; the copy we email you contains it in full, with your answers and a certificate of completion.
| Document control | |
|---|---|
| Document ID | CV-BAA-003 |
| Version | 1.0 |
| Effective date | (per executed copy) |
| Owner | Security Official (see CV-DES-001) |
| Review cycle | Annually, and on any change to the HIPAA Rules that affects this Agreement |
| Retention | 6 years from the date the agreement terminates (§164.316(b)(2)(i)) |
| Legal entity | Geach Medical, PLLC ("the Company"), trading as ChartVoyant |
Companion documents: CV-BAA-002 customer agreement (the upstream half of the same chain) · CV-BAA-001 vendor register
1. Parties and background
This Subcontractor Business Associate Agreement ("Agreement") is entered into by:
| Business Associate | Geach Medical, PLLC trading as ChartVoyant ("ChartVoyant") |
| Address | __________ |
| Subcontractor | __________ ("Subcontractor") |
| Address | __________ |
| Effective Date | ____ |
| Services covered | __________ |
Background. ChartVoyant is a business associate as defined at 45 CFR §160.103. It provides an electronic health record and related services to covered entities and, in doing so, creates, receives, maintains and transmits protected health information on their behalf. Subcontractor creates, receives, maintains or transmits protected health information on ChartVoyant's behalf in performing the services described above (the "Services") under a separate agreement (the "Underlying Agreement"), and is therefore a business associate in its own right under §160.103.
§164.502(e)(1)(ii) requires ChartVoyant to obtain satisfactory assurances from Subcontractor, §164.502(e)(2) requires those assurances to be documented in a written contract, and §164.504(e)(5) applies the requirements of §164.504(e)(2) through (e)(4) to this Agreement in the same manner as they apply between a covered entity and a business associate. §164.314(a)(2)(iii) does the same for the Security Rule's organizational requirements. Subcontractor acknowledges that it is directly liable under the HIPAA Rules — including, among other things, for the Security Rule in full, for impermissible uses and disclosures, for breach notification to ChartVoyant under §164.410, for providing records to the Secretary, for the minimum necessary standard, and for entering into business associate agreements with its own subcontractors.
Where this Agreement and the Underlying Agreement conflict on a matter governed by the HIPAA Rules, this Agreement governs.
2. Definitions
Terms used but not defined here have the meanings given in 45 CFR Parts 160 and 164. "PHI" means protected health information created, received, maintained or transmitted by Subcontractor for or on behalf of ChartVoyant. "ePHI" means PHI in electronic form. "HIPAA Rules" means the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164, as amended.
3. Permitted and required uses and disclosures
(a) Subcontractor may use and disclose PHI only as necessary to perform the Services, as required by law, or as this Agreement otherwise permits. (§164.504(e)(2)(i))
(b) Subcontractor may use PHI as necessary for its own proper management and administration and to carry out its legal responsibilities. Subcontractor may disclose PHI for those purposes only if the disclosure is required by law, or Subcontractor obtains written reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the recipient will notify Subcontractor of any breach of confidentiality. (§164.504(e)(4). The regulation does not require the recipient's assurances to be in writing — that is a deliberate tightening.)
(c) Subcontractor may not use or disclose PHI in a manner that would violate Subpart E of Part 164 if done by a covered entity, except as §3(b) permits.
(d) Subcontractor will limit its uses, disclosures and requests of PHI to the minimum necessary to accomplish the intended purpose. (§164.502(b); §164.514(d))
(e) No training, no derived products, no retention beyond the Services. Subcontractor will not use PHI, or anything derived from PHI, to train, fine-tune, evaluate or improve any model, algorithm or product, and will not retain PHI after it is no longer needed to perform the Services. This applies whether or not the PHI has been de-identified.
Note on §3(e). This clause goes beyond the regulatory floor deliberately. The vendors this Agreement is most often sent to — model providers, transcription services and document processors — commonly default the other way, and treat silence as permission to retain and learn from what they are sent. The Company will not route protected health information to a vendor that has not accepted it.
4. Obligations of Subcontractor
(a) Use and disclosure. Subcontractor will not use or further disclose PHI other than as permitted or required by this Agreement or as required by law. (§164.504(e)(2)(ii)(A))
(b) Safeguards. Subcontractor will use appropriate safeguards, and will comply with Subpart C of Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. (§164.504(e)(2)(ii)(B); §164.314(a)(2)(i)(A))
(c) Reporting. Subcontractor will report to ChartVoyant:
- any use or disclosure of PHI not provided for by this Agreement of which it becomes aware (§164.504(e)(2)(ii)(C));
- any security incident of which it becomes aware (§164.314(a)(2)(i)(C)); and
- any breach of unsecured PHI, in accordance with §164.410.
For a breach of unsecured PHI, Subcontractor will notify ChartVoyant without unreasonable delay and in no case later than 30 calendar days after discovery, and will include the information required by §164.410(c) to the extent known, supplementing it as further information becomes available, except where §164.412 permits a delay at the request of law enforcement.
A breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to Subcontractor — and Subcontractor is deemed to know of a breach known, or knowable by reasonable diligence, to any employee, officer or other agent of Subcontractor other than the person who committed it, determined under the federal common law of agency. (§164.410(a)(2))
The regulation permits 60 days, and each party's 60 runs from its own discovery — so a slow vendor does not literally eat ChartVoyant's window. Two things make 30 the right ask anyway. Serially, 60 + 60 + 60 means a patient could learn of a breach six months after it happened, which is indefensible however the clocks nest. And where the vendor is an agent rather than an independent contractor, §164.410(a)(2) imputes its knowledge upward: its discovery IS ChartVoyant's discovery, ChartVoyant's clock has been running the whole time, and the 60 days it thought it had are already spent. Which category a given vendor falls into is a federal-common-law question nobody wants to litigate after the fact. Thirty calendar days is the outer limit this Agreement accepts, not a target; a shorter period is negotiated wherever the vendor will accept one, and the agreed period is recorded on that vendor's row in CV-BAA-001.
Unsuccessful security incidents that result in no unauthorized access to, or use, disclosure, modification or destruction of, PHI may be reported in the aggregate, at a frequency the parties agree and not less than annually. The carve-out is conventional, but §164.304 defines a security incident to include an attempted unauthorized access, so it has no basis in the regulation's own text — it is a negotiated convenience.
(d) Its own subcontractors. Subcontractor will ensure that any subcontractor it engages that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this Agreement, including compliance with Subpart C with respect to ePHI. (§164.502(e)(1)(ii); §164.308(b)(2); §164.504(e)(2)(ii)(D); §164.314(a)(2)(i)(B))
(e) Access. Subcontractor will make PHI in a designated record set available to ChartVoyant as necessary for the covered entity to satisfy §164.524, within five (5) business days of a written request. (§164.504(e)(2)(ii)(E))
(f) Amendment. Subcontractor will make PHI in a designated record set available for amendment, and will incorporate any amendment ChartVoyant directs, as necessary for the covered entity to satisfy §164.526, within five (5) business days of a written request. (§164.504(e)(2)(ii)(F))
(g) Accounting of disclosures. Subcontractor will maintain and make available to ChartVoyant the information required for an accounting of disclosures, as necessary for the covered entity to satisfy §164.528, within five (5) business days of a written request. (§164.504(e)(2)(ii)(G))
Five days rather than the ten in CV-BAA-002 is deliberate: a request arrives at the practice, passes to ChartVoyant, and only then reaches the vendor, and every downstream link has to fit inside the link above it.
(h) Covered entity obligations. To the extent Subcontractor carries out an obligation of a covered entity under Subpart E of Part 164, Subcontractor will comply with the requirements of Subpart E that apply to a covered entity in the performance of that obligation. (§164.504(e)(2)(ii)(H))
(i) Availability of records to the Secretary. Subcontractor will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules. (§164.504(e)(2)(ii)(I))
(j) Notice of requests and legal process. Subcontractor will notify ChartVoyant of any request it receives directly from an individual under §164.524, §164.526 or §164.528, and of any subpoena, warrant, court order or governmental demand seeking PHI, in each case promptly and, where lawful, before responding. (The first half mirrors CV-BAA-002 §4(j): ChartVoyant cannot pass a notice upstream that it never received.)
5. Obligations of ChartVoyant
(a) ChartVoyant will not request Subcontractor to use or disclose PHI in any manner that would not be permissible under Subpart E if done by a covered entity, except as §3(b) permits.
(b) ChartVoyant will notify Subcontractor of any limitation in a covered entity's Notice of Privacy Practices under §164.520, of any restriction on use or disclosure agreed to by a covered entity under §164.522, and of any change in or revocation of an individual's permission, in each case to the extent it affects Subcontractor's use or disclosure of PHI. (Mirrors CV-BAA-002 §5(a) and §4(k) — the whole point of that clause is that it reaches the party actually holding the data.)
6. Term and termination
(a) Term. This Agreement takes effect on the Effective Date and continues until all PHI is returned or destroyed under §7, or until terminated under §6(b) or §6(c).
(b) Termination for cause. Subcontractor authorizes termination of this Agreement by ChartVoyant if ChartVoyant determines that Subcontractor has violated a material term. (§164.504(e)(2)(iii) — the mandatory element, stated without condition.) ChartVoyant may, at its option, first give Subcontractor fifteen (15) days to cure. Termination of this Agreement entitles ChartVoyant to terminate the Underlying Agreement.
Fifteen days rather than the thirty in CV-BAA-002, for the same nesting reason as §4(e)–(g): if a practice gives ChartVoyant thirty days to cure something a vendor caused, ChartVoyant cannot spend all thirty waiting on the vendor.
(c) Termination by either party. Either party may terminate on written notice as provided in the Underlying Agreement.
(d) Survival. Subcontractor's obligations under §3(e), §4(b), §4(c), §4(i) and §7 survive termination for so long as Subcontractor retains any PHI.
7. Return or destruction of PHI
(§164.504(e)(2)(ii)(J))
(a) On termination for any reason, Subcontractor will return to ChartVoyant or destroy all PHI it created, received, maintained or transmitted on ChartVoyant's behalf, including PHI held by its own subcontractors, and will retain no copies. ChartVoyant elects the method by written notice before or at termination, and where it elects return, Subcontractor will return the PHI in a machine-readable format the parties agree in writing; absent an election, Subcontractor will destroy the PHI.
Note the asymmetry: CV-BAA-002 §7(a) defaults to return-then-destroy, this one defaults to destroy. ChartVoyant holds both elections, so whenever a practice has elected return upstream — or made no election at all, since the upstream default is return-then-destroy — ChartVoyant must affirmatively elect return here. A default destroy downstream cannot satisfy a return owed above it.
(b) Subcontractor will complete this within fifteen (15) days of termination and will certify completion in writing, identifying the method of destruction.
Fifteen days, not the thirty CV-BAA-002 promises a practice. ChartVoyant's own thirty-day obligation covers "PHI held by its subcontractors", and a vendor clock that runs the same length as the clock it sits inside cannot be met — the vendor's period has to finish first, with room to spare for ChartVoyant to collect, verify and certify.
(c) If return or destruction is infeasible, Subcontractor will notify ChartVoyant in writing of the conditions that make it infeasible, will extend the protections of this Agreement to that PHI for as long as it is retained, and will limit further uses and disclosures to the purposes that make return or destruction infeasible.
8. Miscellaneous
(a) Regulatory references. A reference to a section of the HIPAA Rules means that section as in effect or as amended.
(b) Amendment. The parties will negotiate in good faith to amend this Agreement as necessary for either party to comply with a change in the HIPAA Rules.
(c) Interpretation. Ambiguity is resolved in favour of an interpretation that permits compliance with the HIPAA Rules.
(d) No third-party beneficiaries. Nothing in this Agreement confers rights on any person other than the parties, their successors and permitted assigns.
(e) Counterparts and signatures. This Agreement may be executed in counterparts, and an electronic signature has the same effect as an original.
(f) Governing law. This Agreement is governed by the law that governs the Underlying Agreement.
9. Signatures
| ChartVoyant | Subcontractor | |
|---|---|---|
| Entity | Geach Medical, PLLC | ______ |
| Signed | ______ | ______ |
| Name | ______ | ______ |
| Title | ______ | ______ |
| Date | __ | __ |
10. Optional rider — 42 CFR Part 2
Attach only where Part 2 records may reach the vendor. See CV-BAA-002 §10 for when Part 2 applies and why the "does not apply" box is riskier than it looks — an EMR cannot tell which records are Part 2 records, and neither can a downstream vendor.
Part 2 rider. In receiving, storing, processing or otherwise dealing with any patient records received from ChartVoyant that are subject to 42 CFR Part 2, Subcontractor: (i) acknowledges that it is fully bound by the regulations in that Part; and (ii) agrees to resist in judicial proceedings any effort to obtain access to patient identifying information relating to substance use disorder diagnosis, treatment or referral for treatment, except as those regulations permit. Subcontractor will not redisclose such records except as Part 2 permits, will accompany any permitted redisclosure with the §2.32 notice — whether or not the disclosure is one §2.32 reaches, since that section by its terms applies to disclosures made with the patient's written consent — and will bind any subcontractor of its own to the same terms. (Acknowledgements per the "qualified service organization" definition at 42 CFR §2.11(2)(i) and (ii) — not §2.12(c)(4), which is the separate exception permitting program-to-QSO communications and contains no acknowledgements. Enforceable since 16 February 2026, 89 FR 12472. §2.16(a) — formal policies and safeguards — binds "the part 2 program or other lawful holder" independently of this rider; §2.16(b), which applies the HIPAA breach-notification provisions to Part 2 records, is by its terms addressed to part 2 programs and does not reach a qualified service organization.) ☐ Applies. ☐ Does not apply.
11. Document history
| Date | Version | Change |
|---|---|---|
| 2026-09-02 | 1.0 | Issued. Drafted against 45 CFR §164.504(e) and (e)(5), §164.314(a)(2)(iii), §164.308(b)(2) and §164.410, and against the sample business associate agreement provisions published by the Department of Health and Human Services. One addition beyond the regulatory floor at §3(e) — no training, no derived products, no retention beyond the term — together with tightened response times. An optional 42 CFR Part 2 rider is attached at §10. |
Confirm and sign
Typing your name here is your signature. It has the same legal effect as signing on paper.
Signing records your name, the time, your IP address and browser on a certificate of completion bound into the signed PDF.