BUSINESS ASSOCIATE AGREEMENT

Pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA)
45 CFR Parts 160 and 164

Effective Date:  

This Business Associate Agreement ("Agreement") is entered into by and between:

Covered Entity:   ("Practice" or "Covered Entity")

Business Associate: Dental Spaces LLC, d/b/a Ayla ("Ayla" or "Business Associate")

Collectively referred to as the "Parties."

RECITALS

WHEREAS, Covered Entity is a dental practice that is subject to the privacy and security requirements of the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act), and the regulations promulgated thereunder at 45 CFR Parts 160 and 164 (collectively, "HIPAA Rules");

WHEREAS, Business Associate provides a cloud-based dental practice management software platform ("Platform") that enables Covered Entity to manage patient records, scheduling, billing, communications, and other practice operations;

WHEREAS, in the course of providing the Platform, Business Associate may create, receive, maintain, or transmit Protected Health Information ("PHI") on behalf of Covered Entity;

WHEREAS, the Parties desire to enter into this Agreement to ensure compliance with the HIPAA Rules and to establish the permitted and required uses and disclosures of PHI by Business Associate.

1. DEFINITIONS

Terms used in this Agreement that are defined in the HIPAA Rules shall have the same meaning as those terms in the HIPAA Rules. The following terms shall have the meanings set forth below:

  1. "Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule which compromises the security or privacy of the PHI, as defined at 45 CFR 164.402.
  2. "Designated Record Set" means a group of records maintained by or for a Covered Entity as defined at 45 CFR 164.501.
  3. "Electronic Protected Health Information" or "ePHI" means PHI that is transmitted by or maintained in electronic media, as defined at 45 CFR 160.103.
  4. "Protected Health Information" or "PHI" means individually identifiable health information, as defined at 45 CFR 160.103, that is created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
  5. "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system, as defined at 45 CFR 164.304.
  6. "Subcontractor" means a person or entity to whom Business Associate delegates a function, activity, or service involving the creation, receipt, maintenance, or transmission of PHI.
  7. "Unsecured PHI" means PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through encryption or destruction, as specified at 45 CFR 164.402.

2. OBLIGATIONS OF BUSINESS ASSOCIATE

2.1 Permitted Uses and Disclosures

Business Associate agrees to not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law. Business Associate may use or disclose PHI:

  1. To perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the underlying Service Agreement between the Parties, provided that such use or disclosure would not violate the HIPAA Rules if done by Covered Entity;
  2. For the proper management and administration of Business Associate, provided that the disclosures are Required by Law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purposes for which it was disclosed;
  3. To de-identify PHI in accordance with 45 CFR 164.514(a)-(c);
  4. To provide Data Aggregation services to Covered Entity as permitted by 45 CFR 164.504(e)(2)(i)(B);
  5. To report violations of law to appropriate Federal and State authorities, consistent with 45 CFR 164.502(j)(1).

2.2 Safeguards

Business Associate agrees to:

  1. Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, receives, maintains, or transmits on behalf of the Covered Entity, in compliance with 45 CFR Part 164, Subpart C;
  2. Ensure that any agent, including a Subcontractor, to whom it provides ePHI agrees to implement reasonable and appropriate safeguards to protect such ePHI;
  3. Encrypt all ePHI at rest and in transit using AES-256 or equivalent encryption standards;
  4. Maintain access controls ensuring that only authorized personnel can access PHI;
  5. Conduct periodic risk assessments and implement measures to address identified risks;
  6. Maintain audit logs of all access to and modifications of PHI.

2.3 Breach Notification

Business Associate agrees to:

  1. Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including any Breach of Unsecured PHI as required by 45 CFR 164.410;
  2. Provide such notification without unreasonable delay and in no case later than five (5) business days after discovery of the Breach;
  3. Include in any such notification: (i) the identification of each individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; (ii) a description of the nature of the Breach; (iii) the date of the Breach and the date of discovery; (iv) a description of the types of PHI involved; (v) any steps Business Associate has taken or will take to mitigate harmful effects and protect against further Breaches;
  4. Report any Security Incident of which Business Associate becomes aware. For purposes of this provision, unsuccessful attempts at unauthorized access (such as pings, port scans, and similar automated attacks) shall be reported upon request by Covered Entity.

2.4 Subcontractors

Business Associate agrees to:

  1. Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement;
  2. Enter into a written agreement with each Subcontractor that contains the same obligations as those imposed on Business Associate by this Agreement;
  3. Business Associate's current Subcontractors that process PHI include, but may not be limited to: Amazon Web Services (AWS) for cloud hosting, Twilio for SMS communications, Stripe for payment processing, and Stedi for insurance clearinghouse transactions. Each maintains a BAA or equivalent data processing agreement with Business Associate.

2.5 Access to PHI

Business Associate agrees to:

  1. Make available PHI in a Designated Record Set to Covered Entity or, as directed by Covered Entity, to an Individual, as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524;
  2. Provide such access through the Platform's data export functionality or, upon reasonable request, in a mutually agreed-upon electronic format within thirty (30) days of the request.

2.6 Amendment of PHI

Business Associate agrees to make amendments to PHI in a Designated Record Set as directed by Covered Entity, or upon request of an Individual, pursuant to 45 CFR 164.526. Such amendments shall be made through the Platform's standard functionality within thirty (30) days of the request.

2.7 Accounting of Disclosures

Business Associate agrees to make available information required to provide an accounting of disclosures of PHI as necessary to satisfy Covered Entity's obligations under 45 CFR 164.528. Business Associate shall maintain audit logs sufficient to provide such accounting for a period of six (6) years from the date of the disclosure.

2.8 Government Access

Business Associate agrees to make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules.

2.9 Minimum Necessary Standard

Business Associate agrees to use, disclose, or request only the minimum amount of PHI necessary to accomplish the intended purpose of the use, disclosure, or request, in accordance with 45 CFR 164.502(b) and 164.514(d).

3. OBLIGATIONS OF COVERED ENTITY

Covered Entity agrees to:

  1. Notify Business Associate of any limitations in the Covered Entity's notice of privacy practices to the extent that such limitation may affect Business Associate's use or disclosure of PHI;
  2. Notify Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI;
  3. Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522;
  4. Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.

4. TERM AND TERMINATION

4.1 Term

This Agreement shall become effective on the Effective Date and shall continue in effect until the earlier of: (a) the date this Agreement is terminated; or (b) the date the underlying Service Agreement between the Parties is terminated.

4.2 Termination for Cause

Either Party may terminate this Agreement if it determines that the other Party has violated a material term of this Agreement and the breaching Party has not cured the violation within thirty (30) days of receiving written notice of such violation. If cure is not feasible, the non-breaching Party may terminate this Agreement immediately upon written notice.

4.3 Termination by Covered Entity

Covered Entity may terminate this Agreement and the underlying Service Agreement if Business Associate has breached a material term of this Agreement and cure is not possible, in accordance with 45 CFR 164.504(e)(1)(ii).

4.4 Effect of Termination

Upon termination of this Agreement for any reason, Business Associate shall:

  1. Return or destroy all PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form. This provision shall apply to PHI that is in the possession of Subcontractors of Business Associate;
  2. Retain only that PHI which is necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities;
  3. Continue to use appropriate safeguards and comply with the HIPAA Security Rule with respect to any retained PHI;
  4. Not use or disclose retained PHI other than for the purposes for which it was retained, and return or destroy retained PHI when it is no longer needed;
  5. Provide Covered Entity with a data export in a standard electronic format (CSV, JSON, or equivalent) within thirty (30) days of termination, at no additional charge.

5. DATA SECURITY SPECIFICATIONS

In addition to the general safeguards described in Section 2.2, Business Associate specifically represents and warrants that:

  1. Hosting: All PHI is hosted on Amazon Web Services (AWS) infrastructure located within the United States, using HIPAA-eligible services;
  2. Encryption: All ePHI is encrypted at rest (AES-256) and in transit (TLS 1.2 or higher);
  3. Access Controls: The Platform implements role-based access controls, unique user identification, and automatic session timeout;
  4. Audit Controls: The Platform maintains audit logs of all user access, modifications, and disclosures of PHI;
  5. Backup and Recovery: Business Associate maintains regular automated backups of all PHI with documented disaster recovery procedures;
  6. Workforce Training: Business Associate ensures that all workforce members with access to PHI receive appropriate HIPAA training;
  7. Incident Response: Business Associate maintains a written incident response plan that is tested and updated annually.

6. MISCELLANEOUS

6.1 Regulatory References

A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

6.2 Amendment

The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of the HIPAA Rules and any other applicable law. No amendment to this Agreement shall be effective unless in writing and signed by both Parties.

6.3 Survival

The respective rights and obligations of Business Associate under Sections 2.2, 2.3, 2.7, and 4.4 of this Agreement shall survive the termination of this Agreement.

6.4 Interpretation

Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules. In the event of a conflict between this Agreement and the underlying Service Agreement, the terms of this Agreement shall prevail with respect to PHI.

6.5 Governing Law

This Agreement shall be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of laws provisions, and applicable federal law including the HIPAA Rules.

6.6 Entire Agreement

This Agreement, together with the underlying Service Agreement, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, and communications, whether written or oral.

6.7 Notices

All notices required or permitted under this Agreement shall be in writing and shall be sent to:

Business Associate:
Dental Spaces LLC (d/b/a Ayla)
Email: privacy@ayladental.com

Covered Entity:
At the address or email on file with Business Associate's records.

6.8 No Third-Party Beneficiaries

Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than the Parties any rights, remedies, obligations, or liabilities whatsoever.

SIGNATURES

IN WITNESS WHEREOF, the Parties have executed this Business Associate Agreement as of the Effective Date.

COVERED ENTITY

Practice Name

Authorized Representative (Print)

Signature

Title

Date

BUSINESS ASSOCIATE

Dental Spaces LLC d/b/a Ayla

Authorized Representative (Print)

Signature

Title

Date