Business Associate Agreement
Last updated: July 21, 2026
This Business Associate Agreement (“BAA”) is between the healthcare customer identified in the applicable order (“Covered Entity”) and Berryhill Consulting LLC(“Business Associate”) and supplements the agreement for Rekonix Healthcare Billing (“Services”). A party may instead be a business associate of another covered entity; references will be interpreted as needed to satisfy HIPAA.
1. Definitions
Terms including Breach, Designated Record Set, Electronic Protected Health Information, HIPAA, Individual, Minimum Necessary, Protected Health Information (“PHI”), Required by Law, Secretary, Security Incident, Subcontractor, and Unsecured PHI have the meanings in HIPAA, HITECH, and 45 C.F.R. Parts 160 and 164. PHI covered by this BAA is PHI Business Associate creates, receives, maintains, or transmits for Covered Entity through the Services.
2. Permitted uses and disclosures
Business Associate may use or disclose PHI only:
- To perform the Services and obligations described in the underlying agreement, as permitted by HIPAA and this BAA.
- For proper management and administration or to carry out legal responsibilities, if Required by Law or if the recipient provides reasonable assurances of confidentiality, limited use, and breach reporting as required by 45 C.F.R. § 164.504(e).
- To provide data aggregation services relating to Covered Entity’s healthcare operations, only when expressly directed and permitted by HIPAA.
- To report violations of law to appropriate authorities as permitted by 45 C.F.R. § 164.502(j).
Business Associate will not sell PHI, use PHI for marketing, use it to train a general-purpose AI model, or use or disclose it in a manner that would violate the Privacy Rule if done by Covered Entity, except for uses expressly permitted for business associates. Uses, disclosures, and requests will be limited to the Minimum Necessary.
3. Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards to prevent use or disclosure not permitted by this BAA and will comply with applicable Security Rule requirements for ePHI. Business Associate will maintain a documented risk-analysis and risk-management process, access controls, audit controls, integrity protections, authentication, transmission security, contingency procedures, and workforce training appropriate to its role.
4. Reporting incidents and breaches
Business Associate will report to Covered Entity, without unreasonable delay and no later than the time required by HIPAA, any use or disclosure not permitted by this BAA, Breach of Unsecured PHI, or Security Incident of which it becomes aware. Initial notice may be supplemented as information becomes available and will include, to the extent known, affected individuals, information involved, event dates, discovery date, mitigation, and information reasonably needed for notification. The parties acknowledge that routine unsuccessful probes, pings, blocked attacks, and similar events need not be individually reported unless they result in unauthorized access or material compromise.
5. Subcontractors
Business Associate will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI agrees in writing to restrictions, safeguards, reporting, and Security Rule obligations at least as protective as those applicable to Business Associate. No PHI may enter a provider path until the required downstream BAA is effective. The approved PHI-capable providers will be identified on the Subprocessor List.
6. Access, amendment, and accounting
- If Business Associate maintains PHI in a Designated Record Set, it will make PHI available to Covered Entity or, if directed, the Individual, in the time and manner reasonably necessary for Covered Entity to meet 45 C.F.R. § 164.524.
- Business Associate will make PHI available for amendment and incorporate amendments as directed under 45 C.F.R. § 164.526.
- Business Associate will document disclosures and provide information reasonably required for an accounting under 45 C.F.R. § 164.528.
- To the extent Business Associate performs a Covered Entity Privacy Rule obligation, it will comply with the requirements applicable to Covered Entity in performing it.
7. Availability to the Secretary
Business Associate will make internal practices, books, and records relating to PHI available to the Secretary of the U.S. Department of Health and Human Services for determining Covered Entity’s or Business Associate’s compliance with HIPAA, subject to applicable legal protections.
8. Covered Entity obligations
Covered Entity will:
- Use the Services and disclose PHI to Business Associate only as permitted by HIPAA, this BAA, and its Notice of Privacy Practices.
- Notify Business Associate of restrictions, permission changes, or agreed limitations that affect the Services.
- Submit only the Minimum Necessary PHI and not use fields intended for billing to store unapproved clinical content.
- Maintain workforce, role, device, endpoint, export, and credential security within its control and promptly report suspected incidents.
- Not request Business Associate to use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity.
9. Term and termination
The executed BAA begins on the effective date stated in the signature or electronic acceptance record and continues while Business Associate maintains PHI. Either party may terminate for a material BAA breach if the breach is not cured within a reasonable written cure period, unless immediate termination is required by HIPAA or necessary to prevent harm. If cure or termination is infeasible, the non-breaching party may report the problem to the Secretary as required.
10. Return or destruction
At termination, Business Associate will return or destroy PHI if feasible, including PHI held by Subcontractors, and retain no copies except as legally required or temporarily maintained in protected backups. If return or destruction is infeasible, Business Associate will explain why, extend this BAA’s protections, and limit further use and disclosure to the purpose making return or destruction infeasible.
11. Interpretation and order
This BAA will be interpreted to permit compliance with HIPAA and amended as necessary to comply with changes in law. It controls over the Terms, DPA, and Healthcare Addendum regarding PHI. Other agreement terms apply only if consistent with this BAA. Regulatory references include amendments and successor provisions.
12. No third-party beneficiaries; notices
This BAA creates no third-party beneficiary rights. Formal privacy and security notices will be delivered to the contacts in the customer account or order, with a copy to support@rekonix.com for Business Associate.
13. Execution block
| Covered Entity | To be completed in the approved order or countersigned BAA |
|---|---|
| Business Associate | Berryhill Consulting LLC |
| Effective date | Effective upon Customer execution or electronic acceptance |
| Authorized representatives | To be completed by both parties |