Business Associate Agreement (BAA)
Template for review by your attorney and the practice's compliance officer. Executed copies are countersigned via support.
This Business Associate Agreement ("Agreement") is entered into between the subscribing healthcare provider ("Covered Entity") and Wait Wall ("Business Associate") and applies to Protected Health Information ("PHI") as defined by HIPAA (45 CFR Parts 160 and 164) that Business Associate may receive on Covered Entity's behalf.
1. Intended use — minimal PHI
Wait Wall is a signage product. Covered Entity agrees not to upload patient names, images, or records. Staff/provider photos and credentials are workforce information, not PHI. To the extent any PHI is nonetheless processed, this Agreement governs.
2. Obligations of Business Associate
Business Associate shall: (a) not use or disclose PHI other than as permitted by this Agreement or required by law; (b) use appropriate administrative, physical, and technical safeguards, including encryption in transit, consistent with the HIPAA Security Rule; (c) report to Covered Entity any use or disclosure not provided for by this Agreement, including breaches of unsecured PHI, without unreasonable delay and within 30 days of discovery; (d) ensure subcontractors that handle PHI agree to the same restrictions; (e) make PHI available for access and amendment and provide an accounting of disclosures as required by 45 CFR 164.524, 164.526, and 164.528; and (f) make its practices available to the Secretary of HHS for determining compliance.
3. Permitted uses
Business Associate may use PHI only to provide the service, for its proper management and administration, and as required by law.
4. Term and termination
This Agreement terminates when the underlying service agreement ends. Upon termination, Business Associate will return or destroy all PHI, or, where infeasible, extend the protections of this Agreement to the retained PHI and limit further use.
5. Self-hosted deployments
Where Covered Entity purchases the self-hosted option and operates the software entirely on its own infrastructure, Business Associate does not receive PHI, and Covered Entity is solely responsible for HIPAA compliance of its deployment.
To execute this BAA, contact us via the support page with your organization's legal name and signatory.