Skip to content
Treat

Treat

Business Associate Agreement

Last updated

This Business Associate Agreement (the "BAA") supplements the Treat Subscription Services Agreement at https://www.alltreat.io/legal/terms (the "SSA") and each Order Form that references it (together, the "Underlying Agreement") between Treat Technologies LLC ("Treat") and the customer identified in the Order Form ("Customer"). Under the HIPAA Rules, Treat is the Business Associate and Customer is the Covered Entity.

Customer accepts this BAA by signing an Order Form that references it, by accepting it electronically, or by providing PHI to Treat through the Services. The person accepting represents that they are authorized to bind Customer. This BAA takes effect on the effective date of the Underlying Agreement.

This BAA is intended to satisfy the HIPAA Rules. The Underlying Agreement applies to this BAA except where this BAA says otherwise. If Customer and Treat have signed a separately negotiated business associate agreement, that agreement governs instead of this BAA.

1. Definitions

1.1 HIPAA terms. Capitalized terms used but not defined in this BAA have the meanings given in the HIPAA Rules. These include Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

1.2 "HIPAA Rules" means the Health Insurance Portability and Accountability Act of 1996, the HITECH Act, and the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, each as amended.

1.3 "PHI" means Protected Health Information, as defined in 45 C.F.R. § 160.103, that Treat creates, receives, maintains, or transmits on Customer's behalf through the Services. PHI includes Electronic Protected Health Information ("ePHI") and excludes Usage Data.

1.4 "Services" has the meaning given in the Underlying Agreement.

1.5 "Unsuccessful Security Incident" means a Security Incident that does not result in unauthorized access to, or Use, Disclosure, modification, or destruction of, PHI, or in material interference with system operations. Examples include pings and other broadcast attacks on firewalls, port scans, unsuccessful log-on attempts, and blocked denial-of-service attempts.

1.6 "Usage Data" means (a) information de-identified in accordance with 45 C.F.R. § 164.514(a)–(c), and (b) data about the use and performance of the Services that is not PHI.

2. Treat's Obligations

This Section contains the obligations HIPAA requires of a business associate. Treat has no other obligations regarding PHI except as this BAA or the Underlying Agreement expressly states.

2.1 Use and Disclosure. Treat will not Use or Disclose PHI other than as permitted or required by this BAA or the Underlying Agreement, or as Required by Law.

2.2 Safeguards. Treat will use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent Use or Disclosure of PHI other than as this BAA provides.

2.3 Reporting. Treat will report to Customer: (a) any Use or Disclosure of PHI not provided for by this BAA of which it becomes aware; (b) any Security Incident of which it becomes aware, other than Unsuccessful Security Incidents; and (c) any Breach of Unsecured PHI, as required by 45 C.F.R. § 164.410. Treat will report without unreasonable delay, and will report any Breach no later than sixty (60) calendar days after discovery.

2.4 Breach Report Contents. To the extent possible, a Breach report will identify each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, Used, or Disclosed. Treat will also provide other available information Customer needs to notify Individuals under 45 C.F.R. § 164.404(c), at the time of the report or as it becomes available.

2.5 Unsuccessful Security Incidents. This Section is notice of the ongoing occurrence of Unsuccessful Security Incidents, and no further report of them is required.

2.6 Subcontractors. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Treat will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to the same restrictions, conditions, and requirements that apply to Treat with respect to that PHI.

2.7 Designated Record Sets. Unless the Order Form states otherwise, Treat does not maintain a Designated Record Set for Customer; Customer's own record systems hold its Designated Record Sets. To the extent Treat does maintain PHI in a Designated Record Set, within fifteen (15) business days after Customer's written request it will: (a) make that PHI available to Customer as needed for Customer to meet 45 C.F.R. § 164.524; and (b) make it available for amendment and incorporate any amendments Customer directs or agrees to under 45 C.F.R. § 164.526.

2.8 Accounting of Disclosures. Treat will document its Disclosures of PHI as needed for Customer to provide an accounting under 45 C.F.R. § 164.528. It will provide that information within fifteen (15) business days after Customer's written request.

2.9 Requests from Individuals. Treat will forward to Customer any request it receives directly from an Individual for access, amendment, or an accounting. Customer is solely responsible for responding.

2.10 Customer's Privacy Obligations. To the extent Treat carries out any of Customer's obligations under Subpart E of 45 C.F.R. Part 164, it will comply with the requirements of Subpart E that apply to Customer in performing those obligations.

2.11 Books and Records. Unless protected from disclosure by privilege or other law, Treat will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining Customer's compliance with the HIPAA Rules.

3. Permitted Uses and Disclosures

3.1 Services. Treat may Use and Disclose PHI as necessary to provide the Services, perform the Underlying Agreement, and meet its obligations under this BAA, including Disclosures to Subcontractors that meet Section 2.6. Except as permitted by Sections 3.3 through 3.6, Treat will not Use or Disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Customer.

3.2 Required by Law. Treat may Use or Disclose PHI as Required by Law.

3.3 Management, Administration, and Improvement. Treat may Use PHI for its proper management and administration, including internal analytics, quality assurance, security monitoring, and improving the Services, and to carry out its legal responsibilities. To the extent permitted by the HIPAA Rules, this includes Use of PHI within artificial intelligence and machine learning systems and models that Treat uses to provide, secure, or improve the Services.

3.4 Disclosures for Administration. Treat may Disclose PHI for its proper management and administration or to carry out its legal responsibilities if: (a) the Disclosure is Required by Law; or (b) Treat obtains reasonable assurances from the recipient that the PHI will remain confidential and be Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed, and the recipient agrees to notify Treat of any instance it knows of in which the PHI's confidentiality has been breached.

3.5 Data Aggregation. Treat may Use PHI to provide Data Aggregation services relating to the Health Care Operations of Customer, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). This includes combining it with PHI Treat receives from other covered entities to produce benchmarks and comparative analyses relating to their Health Care Operations.

3.6 De-identification and Usage Data. Treat may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c). Treat may Use and Disclose Usage Data for any lawful purpose, during and after the term, including developing and training AI models, creating industry benchmarks, and building new products. As between the parties, Treat owns all Usage Data.

3.7 Customer-Directed Disclosures. When Customer directs Treat to send PHI to, or connect the Services with, a third-party system or application that is not Treat's Subcontractor, Treat makes that Disclosure on Customer's behalf and at its direction. That third party is not Treat's Subcontractor, and Treat is not responsible for its handling of PHI.

4. Customer Responsibilities

4.1 Privacy Notices and Restrictions. Customer will notify Treat in writing of: (a) any limitation in its Notice of Privacy Practices under 45 C.F.R. § 164.520; (b) any change in or revocation of an Individual's permission to Use or Disclose PHI; and (c) any restriction on the Use or Disclosure of PHI that Customer has agreed to under 45 C.F.R. § 164.522. This applies to the extent the item may affect Treat's Use or Disclosure of PHI. Treat is not bound by any restriction it has not agreed to in writing.

4.2 Permissible Requests. Customer will not ask Treat to Use or Disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Customer, except as permitted by Sections 3.3 through 3.6.

4.3 Minimum Necessary. Customer will provide, and will configure the Services to share, only the PHI reasonably necessary for the Services.

4.4 Consents and Authorizations. Customer is responsible for obtaining all consents, authorizations, and notices required by law for Treat to perform the Services, including under HIPAA and state privacy laws.

4.5 Customer's Own Compliance. Customer is solely responsible for its own compliance with the HIPAA Rules, including its risk analysis, policies, workforce training, Notice of Privacy Practices, and responses to Individuals. Using the Services does not by itself make Customer compliant. Customer has reviewed the Services' security features and determined they are appropriate for its needs.

4.6 Customer's Users and Systems. Customer is responsible for its users, credentials, devices, networks, integrations, and configuration of the Services, and for promptly removing access for departing workforce members. Treat is not responsible for any Security Incident or Breach caused by Customer's users, credentials, systems, or configurations. Customer will promptly notify Treat of any suspected unauthorized access to its account.

4.7 Substance Use Disorder Records. Customer will not provide Treat any records subject to 42 C.F.R. Part 2 unless Treat has agreed in writing in advance.

5. Breach Response and Costs

5.1 Notification Decisions. As the Covered Entity, Customer decides whether notice of a Breach must be given to Individuals, the Secretary, the media, or regulators, and gives any such notice. Treat will not notify Individuals or regulators on Customer's behalf unless the law requires it or the parties agree in writing.

5.2 Notification Costs. Customer will bear all costs of notices it gives or is required to give, including mailing, call-center, credit-monitoring, and regulatory-response costs. Customer will also reimburse Treat's reasonable costs of any notice the law requires Treat to give, unless the Breach was caused solely and directly by Treat's gross negligence or willful misconduct.

5.3 Customer-Caused Incidents. If a Security Incident or Breach results from Customer's users, credentials, devices, systems, or configurations, Customer will reimburse Treat's reasonable costs of investigating and responding to it.

5.4 No Admission. A report or notice under this BAA is not an admission of fault or liability by Treat.

5.5 Public Statements. Customer will not name Treat in any notice to Individuals, press release, or other public statement about a Security Incident or Breach without Treat's prior written approval, except as required by law.

6. Term, Termination, and Suspension

6.1 Term. This BAA begins on the effective date of the Underlying Agreement and continues until the Underlying Agreement ends and all PHI has been returned, destroyed, or retained as provided in Section 6.5.

6.2 Termination for Breach. Either party may terminate this BAA on thirty (30) days' written notice if the other party materially breaches it and does not cure the breach within that notice period.

6.3 Termination for Changes in Law or Restrictions. Treat may terminate this BAA and the affected Services on thirty (30) days' written notice if a change in the HIPAA Rules or other law, or a restriction Customer has agreed to, would cause Treat unanticipated compliance costs or regulatory risk to continue performing.

6.4 Suspension. Treat may suspend processing of PHI or access to the Services, without liability, if it reasonably believes Customer's use of the Services violates this BAA, the HIPAA Rules, or other law, or creates a security risk.

6.5 Effect of Termination. For thirty (30) days after the Underlying Agreement ends, Customer may request an export of its PHI, provided it has paid all amounts owed; additional fees may apply. After that period, Treat will return or destroy the PHI it still maintains, except that it may retain PHI: (a) needed for its proper management and administration or to carry out its legal responsibilities; (b) held in backups, until overwritten in the ordinary course; or (c) whose return or destruction is infeasible. Treat will continue to protect retained PHI under this BAA and will Use or Disclose it only for the purposes that required its retention, for as long as it retains the PHI. Usage Data is not subject to return or destruction.

6.6 Survival. Sections 3.6, 5, 6.5, 7, and 9, and Treat's obligations for any retained PHI, survive the end of this BAA.

7. Disclaimers, Limitation of Liability, and Indemnification

7.1 Disclaimer. EXCEPT AS EXPRESSLY STATED IN THIS BAA, TREAT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, ABOUT THE SERVICES OR THE SECURITY OF PHI. TREAT DOES NOT WARRANT THAT THE SERVICES WILL BE FREE OF SECURITY INCIDENTS OR THAT CUSTOMER'S USE OF THE SERVICES WILL SATISFY CUSTOMER'S LEGAL OBLIGATIONS.

7.2 Excluded Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, TREAT WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, OR GOODWILL, ARISING OUT OF OR RELATING TO THIS BAA, EVEN IF ADVISED OF THEIR POSSIBILITY.

7.3 Liability Cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, TREAT'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THIS BAA AND THE UNDERLYING AGREEMENT, COMBINED, WILL NOT EXCEED THE FEES CUSTOMER PAID TREAT IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. THIS CAP APPLIES TO ALL CLAIMS IN THE AGGREGATE, INCLUDING CLAIMS RELATING TO SECURITY INCIDENTS AND BREACHES.

7.4 Indemnification by Customer. Customer will defend, indemnify, and hold harmless Treat and its affiliates, officers, employees, and contractors from all claims, losses, damages, fines, penalties, costs, and expenses, including reasonable attorneys' fees, to the extent arising from: (a) Customer's breach of this BAA or violation of the HIPAA Rules or other law; (b) PHI or other data Customer or its users provide, including any missing consent or authorization; (c) Customer's users, credentials, systems, integrations, or configurations; or (d) Disclosures made at Customer's direction.

7.5 No Indemnity by Treat. Treat has no obligation to indemnify Customer under this BAA.

7.6 Time Limit on Claims. To the extent permitted by law, any claim arising out of or relating to this BAA must be brought within one (1) year after it accrues, or it is permanently barred.

7.7 Allocation of Risk. Customer agrees that this Section reflects a reasonable allocation of risk, is an essential basis of the parties' bargain, and is reflected in Treat's fees.

8. Updates to this BAA

8.1 Updates. Treat may update this BAA by posting a new version at https://www.alltreat.io/legal/baa with a new "Last updated" date. For material changes, Treat will notify Customer by email at least thirty (30) days before they take effect. Changes required by law may take effect immediately on notice.

8.2 Acceptance of Updates. Customer's continued use of the Services after an update takes effect constitutes acceptance. If Customer does not accept an update, its sole remedy is to stop using the Services and terminate the Underlying Agreement.

8.3 Prior Versions. On request, Treat will provide the version of this BAA in effect on any given date.

9. General Terms

9.1 Regulatory References. A reference to a section of the HIPAA Rules means that section as in effect or as amended.

9.2 Interpretation. Any ambiguity in this BAA will be resolved to permit compliance with the HIPAA Rules.

9.3 Order of Precedence. If this BAA conflicts with the Underlying Agreement regarding PHI, this BAA controls. Section 7 applies in addition to any limits in the SSA; where both apply, the terms that more limit Treat's liability control.

9.4 Independent Contractors. Treat is an independent contractor and not Customer's agent. Nothing in this BAA creates an agency, partnership, or joint venture.

9.5 No Third-Party Beneficiaries. Nothing in this BAA gives any right or remedy to anyone other than the parties, including Individuals.

9.6 Governing Law and Disputes. This BAA is governed by the laws of the State of Utah, except to the extent federal law applies. Disputes will be resolved as the SSA provides, including any arbitration and class-action waiver terms.

9.7 Electronic Acceptance. This BAA may be accepted electronically, and electronic acceptance has the same effect as a handwritten signature.

9.8 Assignment. Customer may not assign this BAA without Treat's prior written consent. Treat may assign it without consent, including in a merger, acquisition, or sale of assets.

9.9 Severability. If any provision of this BAA is held unenforceable, it will be limited to the minimum extent necessary, and the rest of this BAA will remain in effect.

9.10 Notices. Treat may give notices to Customer by email to the contact in the Order Form or Customer's account. Customer must send notices to Treat at legal@alltreat.io.