(To use this software application with patients, you must acknowledge and agree to the HIPAA Business Associate Agreement.)
This Business Associate Agreement (“Agreement”) is made between:
- RITE Mobile App Co. (“Business Associate”)
- Therapist, Life Coach, or other user, using the Health Professional side of RITE (“Covered Entity”)
- Effective as of the date of acceptance, this Agreement ensures compliance with the Health Insurance Portability and Accountability Act (HIPAA) regarding the handling of Protected Health Information (PHI).
Definitions
- Business Associate: RITE, which provides relationship tracking and analytics services to Covered Entities.
- Covered Entity: A therapist or healthcare provider using RITE for professional purposes.
- Protected Health Information (PHI): Any identifiable health-related information processed by RITE.
- HIPAA: The Health Insurance Portability and Accountability Act and its associated regulations.
Obligations of Business Associate
- Business Associate agrees to use, disclose, and protect PHI in compliance with HIPAA regulations.
- Business Associate will not use or disclose PHI except as permitted under this Agreement or as required by law.
- Business Associate will implement administrative, physical, and technical safeguards to prevent unauthorized access to PHI.
- Business Associate will report any security breaches involving PHI to the covered entity within 72 hours of discovery.
- Business Associate will provide access to PHI at the request of the Covered Entity in accordance with HIPAA regulations.
Obligations of Covered Entity
- Covered Entity shall only share PHI with Business Associate as necessary for the intended services.
- Covered Entity is responsible for obtaining patient authorization if required before using RITE services.
- Covered Entity must notify Business Associate if PHI is incorrect or requires updates.
Permitted Uses and Disclosures
- Business Associate may use PHI for analytics, reporting, and insights as authorized by Covered Entity.
- Business Associate will not sell or share PHI with third parties without prior consent.
- Business Associate may de-identify PHI for research and analysis purposes in compliance with HIPAA regulations.
Security & Compliance Measures
- Business Associate will encrypt PHI both in transit and at rest.
- Business Associate will maintain audit logs of PHI access and modifications.
- Business Associate will conduct annual HIPAA compliance assessments.
Breach Notification & Mitigation
- Business Associate must notify the Covered Entity within 72 hours of a confirmed PHI breach.
- Business Associate will assist in breach investigations and provide remediation plans.
Termination & Data Retention
- Either party may terminate this Agreement with 30 days written notice.
- Upon termination, Business Associate will return or destroy all PHI unless legally required to retain it.
Governing Law & Dispute Resolution
- This Agreement shall be governed by the laws of Salt Lake City, Utah.
- Any disputes shall be resolved through binding arbitration under the rules of the American Arbitration Association (AAA).
Acceptance & Execution
- Click-to-Accept Agreement:
- By checking the box or clicking “I Accept,” the Covered Entity acknowledges that they have read, understood, and agreed to this Business Associate Agreement.
- The Covered Entity further acknowledges that continued use of RITE constitutes acceptance of this Agreement.
- Optional Signed Agreement:
- If the Covered Entity requires a signed version of this Agreement, they may request a copy by contacting privacy@ritemobileappco.com.
- A manually signed BAA must be returned to RITE before PHI-related features can be accessed, if required by the Covered Entity.
- Covered Entity Responsibility for Profile Accuracy:
- By accepting this Business Associate Agreement (BAA), the Covered Entity acknowledges that all information provided in their profile is accurate and up to date.
- The Covered Entity is solely responsible for reviewing and updating their profile information, including but not limited to business name, contact details, and licensure status, before accepting this Agreement.
- If the Covered Entity identifies any incorrect or outdated information, they must correct it before signing this Agreement.
- Failure to provide accurate information does not void the obligations under this Agreement, and the Covered Entity assumes responsibility for any consequences arising from incorrect or outdated details.
- RITE shall not be held liable for any compliance issues, miscommunications, or data-related concerns resulting from inaccurate or outdated information provided by the Covered Entity.
- By accepting this Agreement, the parties acknowledge and agree to the terms set forth above.