HIPAA compliance

Business Associate Agreement.

We sign a BAA with every covered entity customer. It is not an optional add-on. It is a foundational part of every paid subscription, because protecting PHI is a federal obligation.


What a Business Associate Agreement is

A Business Associate Agreement, or BAA, is a contract required under HIPAA. It must be executed between a covered entity and any business associate that creates, receives, maintains, or transmits PHI on behalf of that covered entity.

HaloPT operates as a business associate. When a covered entity such as a physical therapy clinic, hospital system, or health plan uses our platform to manage patient data, we process PHI on their behalf. The BAA establishes the legal framework that governs how we handle that data.

Why a BAA matters

Without a valid BAA, a covered entity cannot lawfully share PHI with a vendor. Signing a BAA means both parties acknowledge their respective responsibilities under HIPAA: permitted uses, required safeguards, breach notification, and patient privacy through the entire data lifecycle.

The BAA is required by the HIPAA Privacy Rule at 45 CFR §164.502(e). Failure to execute a BAA before exchanging PHI can result in significant civil monetary penalties for both the covered entity and the business associate.

What our BAA covers

The HaloPT BAA addresses each requirement in the HIPAA Privacy Rule and Security Rule. Below is a summary of the key provisions in every BAA we execute.

Permitted uses and disclosures of PHI

Our BAA defines the specific purposes for which HaloPT may use or disclose PHI. We process PHI only as necessary to perform the services in the subscription agreement or as required by law. Any use outside the scope of the agreement is prohibited.

Safeguards for PHI

We commit to implementing appropriate administrative, physical, and technical safeguards in accordance with the HIPAA Security Rule. This includes encryption in transit and at rest, access controls, audit logging, and workforce security training.

Breach notification

If HaloPT discovers a breach of unsecured PHI, the affected covered entity will be notified without unreasonable delay and no later than 60 days after discovery, with detail on scope and recommended mitigation.

Subcontractor requirements

Any subcontractor that creates, receives, maintains, or transmits PHI on behalf of HaloPT is bound by a written BAA that imposes the same restrictions and requirements that apply to HaloPT under this BAA.

Audit rights

The Secretary of HHS has the right to audit HaloPT to determine compliance with the BAA and applicable HIPAA regulations. Covered-entity customers may request information about our compliance practices.

Data return and destruction

On termination of the BAA, HaloPT will, if feasible, return or destroy all PHI received from or created on behalf of the covered entity, with continuing protections for any PHI that cannot be returned or destroyed.

How to get a BAA

Getting a BAA with HaloPT is straightforward. There is no separate application process and no additional cost.

01

Automatic with every paid subscription

On any HaloPT paid plan, a BAA is included automatically. No separate request needed. Terms are incorporated into the subscription agreement at signup.

02

No additional cost

There is no separate fee for a BAA. HIPAA compliance and the BAA are part of the standard offering for every covered-entity customer. Compliance is a baseline, not a premium.

03

Signed at onboarding

The BAA is presented and executed during onboarding. Authorized representatives of both parties sign before any PHI is processed on the platform.

Request a BAA

If you are evaluating HaloPT and want a copy of the BAA before subscribing, or you need a BAA for an existing account, fill out the form below. Our team will follow up within one business day.

Contact

For questions about this BAA, our HIPAA practices, or to request a copy of the full document, contact our legal team.

For security inquiries, including suspected vulnerabilities or incidents, contact security@halopt.com.