What a Business Associate Agreement is
A Business Associate Agreement, or BAA, is a contract required under HIPAA. It must be executed between a covered entity and any business associate that creates, receives, maintains, or transmits PHI on behalf of that covered entity.
HaloPT operates as a business associate. When a covered entity such as a physical therapy clinic, hospital system, or health plan uses our platform to manage patient data, we process PHI on their behalf. The BAA establishes the legal framework that governs how we handle that data.
Without a valid BAA, a covered entity cannot lawfully share PHI with a vendor. Signing a BAA means both parties acknowledge their respective responsibilities under HIPAA: permitted uses, required safeguards, breach notification, and patient privacy through the entire data lifecycle.
The BAA is required by the HIPAA Privacy Rule at 45 CFR §164.502(e). Failure to execute a BAA before exchanging PHI can result in significant civil monetary penalties for both the covered entity and the business associate.
What our BAA covers
The HaloPT BAA addresses each requirement in the HIPAA Privacy Rule and Security Rule. Below is a summary of the key provisions in every BAA we execute.
Permitted uses and disclosures of PHI
Our BAA defines the specific purposes for which HaloPT may use or disclose PHI. We process PHI only as necessary to perform the services in the subscription agreement or as required by law. Any use outside the scope of the agreement is prohibited.
Safeguards for PHI
We commit to implementing appropriate administrative, physical, and technical safeguards in accordance with the HIPAA Security Rule. This includes encryption in transit and at rest, access controls, audit logging, and workforce security training.
Breach notification
If HaloPT discovers a breach of unsecured PHI, the affected covered entity will be notified without unreasonable delay and no later than 60 days after discovery, with detail on scope and recommended mitigation.
Subcontractor requirements
Any subcontractor that creates, receives, maintains, or transmits PHI on behalf of HaloPT is bound by a written BAA that imposes the same restrictions and requirements that apply to HaloPT under this BAA.
Audit rights
The Secretary of HHS has the right to audit HaloPT to determine compliance with the BAA and applicable HIPAA regulations. Covered-entity customers may request information about our compliance practices.
Data return and destruction
On termination of the BAA, HaloPT will, if feasible, return or destroy all PHI received from or created on behalf of the covered entity, with continuing protections for any PHI that cannot be returned or destroyed.
How to get a BAA
Getting a BAA with HaloPT is straightforward. There is no separate application process and no additional cost.
Automatic with every paid subscription
On any HaloPT paid plan, a BAA is included automatically. No separate request needed. Terms are incorporated into the subscription agreement at signup.
No additional cost
There is no separate fee for a BAA. HIPAA compliance and the BAA are part of the standard offering for every covered-entity customer. Compliance is a baseline, not a premium.
Signed at onboarding
The BAA is presented and executed during onboarding. Authorized representatives of both parties sign before any PHI is processed on the platform.
Request a BAA
If you are evaluating HaloPT and want a copy of the BAA before subscribing, or you need a BAA for an existing account, fill out the form below. Our team will follow up within one business day.
Contact
For questions about this BAA, our HIPAA practices, or to request a copy of the full document, contact our legal team.
Legal team
legal@halopt.comFor security inquiries, including suspected vulnerabilities or incidents, contact security@halopt.com.