Welcome to www.portals.care (the “Website”). This HIPAA Business Associate Agreement (“BAA”) is entered into by and between CarePortals LLC (“Business Associate, “CarePortals ”, “we”, “us”, or “our”) and you (“Customer”), and is made effective as of the date of electronic acceptance. This BAA sets forth each party’s respective obligations regarding the Services and represents the entire agreement between you and CarePortals concerning the subject matter hereof.
Your electronic acceptance of this BAA signifies that you have read, understood, acknowledged, and agreed to be bound by this BAA, along with our Master Subscription Agreement and our Privacy Policy, which are incorporated herein by this reference. Terms capitalized but not defined in this BAA have the meanings set out in the Master Subscription Agreement (MSA) and Privacy Policy, respectively.
The terms “you” or “your” shall refer to any individual or entity who accepts this BAA. Nothing in this BAA shall be deemed to confer any third-party rights or benefits.
We may change or modify this BAA at any time. Changes that do not materially reduce the protections afforded to PHI are effective upon posting to the Website. For any change that materially reduces those protections, we will provide at least thirty (30) days' notice by email to your account contact before it takes effect, and you may terminate the Services without penalty by written notice before the effective date. Changes required by applicable law or regulation are effective on the date required by law.
It is important that you keep your contact information current. We assume no liability or responsibility for your failure to receive an email notification if such failure results from an inaccurate email address.
The parties agree as follows:
For purposes of this BAA, any capitalized terms not otherwise defined herein will have the meaning given to them in the BAA and under HIPAA.
CarePortals and you will use appropriate safeguards designed to prevent against unauthorized use or disclosure of PHI, consistent with this BAA, and as otherwise required under the Security Rule, with respect to the Services.
CarePortals will notify you following the discovery of a breach resulting in the unauthorized use or disclosure of PHI in violation of this BAA without unreasonable delay, and in any event within ten (10) business days of discovery, subject to any delay requested by law enforcement or required by applicable law. CarePortals will use commercially reasonable efforts to mitigate any further harmful effects to the extent practicable, and will provide you with the information reasonably available to it that you require to meet your own notification obligations under 45 C.F.R. Part 164, Subpart D.
You hereby agree that any such report, notification or other notice made pursuant to this BAA may be provided electronically. For clarity, you and not CarePortals are responsible for managing whether your end users are authorized to create, receive, maintain or transmit PHI within the Services, and CarePortals will have no obligations relating thereto. This Section will be deemed as notice to you that CarePortals periodically receives unsuccessful attempts for unauthorized access, use, disclosure, modification or destruction of information or interference with the general operation of CarePortals ’s information systems and the Services and even if such events are defined as a Security Incident under HIPAA, CarePortals will not provide any further notice regarding such unsuccessful attempts.
Customer is solely responsible for: (a) obtaining and maintaining all necessary patient authorizations or consents; (b) ensuring that PHI uploaded or entered into the Services is accurate and lawfully collected; (c) configuring user roles, permissions, and access controls; and (d) using the Services in a manner consistent with HIPAA. CarePortals shall have no liability for any violation of HIPAA or other law arising from Customer’s actions or omissions.
CarePortals will take appropriate measures to ensure that any agents and subcontractors used by CarePortals to perform its obligations under the BAA that require access to PHI on behalf of CarePortals are bound by written obligations that provide the same material level of protection for PHI as this BAA. To the extent CarePortals uses agents and subcontractors in its performance of obligations hereunder, CarePortals will remain responsible for their performance as if performed by CarePortals itself under this BAA. CarePortals may engage subcontractors to perform Services involving PHI, provided such subcontractors are bound by written agreements requiring HIPAA-equivalent protections.
CarePortals will make available to you the PHI via the Services so you may fulfill your obligation to give individuals their rights of access, amendment, and accounting in accordance with the requirements under HIPAA. You are responsible for managing your use of the Services to appropriately respond to such individual requests.
To the extent required by law, and subject to applicable attorney client privileges, CarePortals will make its internal practices, books, and records concerning the use and disclosure of PHI received from you, or created or received by CarePortals on behalf of you, available to the Secretary of the U.S. Department of Health and Human Services (the “Secretary”) for the purpose of the Secretary determining compliance with this BAA.
Upon termination or expiration of the Agreement, CarePortals shall, upon Customer’s written request, make PHI available for export for thirty (30) days. After such period, CarePortals may securely destroy PHI in accordance with NIST 800-88 or equivalent data-destruction standards. CarePortals may retain copies of PHI as required by law, regulation, or for legitimate business or dispute-resolution purposes, subject to the continuing protections of this BAA.
This BAA will expire upon the earlier of: (i) the termination or expiration of the Services to which this BAA applies; or (ii) the effective date of an updated HIPAA business associate agreement that supersedes this BAA, determined in accordance with Section 1.
It is the parties’ intent that any ambiguity under this BAA be interpreted consistently with the intent to comply with applicable laws.
This BAA supersedes in its entirety any pre-existing HIPAA business associate agreement executed by CarePortals and you covering the same Services. Each covenant and agreement in this BAA shall be construed for all purposes to be a separate and independent covenant or agreement. If a court of competent jurisdiction holds any provision (or portion of a provision) of this BAA to be illegal, invalid, or otherwise unenforceable, the remaining provisions (or portions of provisions) of this BAA shall not be affected thereby and shall be found to be valid and enforceable to the fullest extent permitted by law. In the event there is a conflict between the provisions of this BAA and either the provisions of the Master Subscription Agreement or the Privacy Policy, the provisions of this BAA shall control.