Skipper

Business Associate Agreement

Last updated: June 1, 2026

This Business Associate Agreement ("BAA" or "Agreement") is entered into by and between the entity identified as the customer on the applicable service agreement ("Covered Entity") and Skipper Software, LLC, doing business as Skipper ("Business Associate"), collectively referred to as the "Parties."

This BAA supplements and is made part of the service agreement between the Parties (the "Underlying Agreement") and is effective as of the date the Underlying Agreement is executed.

1. Definitions

The following terms shall have the meanings set forth below. Capitalized terms not otherwise defined in this BAA shall have the meanings assigned to them under HIPAA (as defined below).

  • "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), and their implementing regulations, including the Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164) and the Security Rule (45 CFR Part 160 and Subparts A and C of Part 164).

  • "Business Associate" means Skipper Software, LLC, which creates, receives, maintains, or transmits Protected Health Information on behalf of the Covered Entity in connection with the Service.

  • "Covered Entity" means the customer that is a Covered Entity as defined under HIPAA, or a Business Associate that engages Skipper as a subcontractor.

  • "Protected Health Information" or "PHI" means individually identifiable health information that is transmitted or maintained in any form or medium, as defined under 45 CFR 160.103.

  • "Electronic Protected Health Information" or "ePHI" means PHI that is transmitted by or maintained in electronic media, as defined under 45 CFR 160.103.

  • "Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the PHI, as defined in 45 CFR 164.402.

  • "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system, as defined under 45 CFR 164.304.

  • "Required by Law" means a mandate contained in law that compels an entity to make a use or disclosure of PHI, as defined under 45 CFR 164.103.

2. Obligations of Business Associate

Business Associate agrees to the following obligations:

  • Not use or disclose PHI other than as permitted or required by this BAA or as Required by Law.

  • Use appropriate safeguards, including administrative, physical, and technical safeguards, to prevent use or disclosure of PHI other than as provided by this BAA.

  • Comply with the HIPAA Security Rule with respect to ePHI.

  • Report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which Business Associate becomes aware, including any Breach of Unsecured PHI as required by 45 CFR 164.410.

  • In accordance with 45 CFR 164.502(e)(1)(ii), require that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions and conditions that apply to Business Associate under this BAA.

  • Make available PHI in a Designated Record Set to the Covered Entity or, as directed by the Covered Entity, to an individual, in order to meet the requirements of 45 CFR 164.524.

  • Make available PHI for amendment and incorporate any amendments to PHI in accordance with 45 CFR 164.526.

  • Maintain and make available the information required to provide an accounting of disclosures in accordance with 45 CFR 164.528.

  • Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.

  • To the extent Business Associate is to carry out any of the Covered Entity's obligations under the HIPAA Privacy Rule, comply with the requirements of the Privacy Rule that apply to the Covered Entity in the performance of such obligations.

3. Permitted Uses and Disclosures

Business Associate may use or disclose PHI only as follows:

  • As necessary to perform services for, or on behalf of, the Covered Entity as specified in the Underlying Agreement, provided that such use or disclosure would not violate the HIPAA Privacy Rule if done by the Covered Entity.

  • For the proper management and administration of Business Associate, provided that (a) the disclosures are Required by Law, or (b) Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and the person agrees to notify Business Associate of any instances of which it becomes aware in which the confidentiality of the information has been breached.

  • To provide data aggregation services relating to the healthcare operations of the Covered Entity, as permitted by 45 CFR 164.504(e)(2)(i)(B).

  • To de-identify PHI in accordance with 45 CFR 164.514(a)-(c).

4. Safeguards

Business Associate shall implement and maintain appropriate safeguards to protect the confidentiality, integrity, and availability of PHI, including:

  • Administrative safeguards: workforce training on HIPAA requirements, designated privacy and security officers, access management policies, and regular risk assessments.

  • Physical safeguards: facility access controls, workstation security, and device and media controls for systems that store or process ePHI.

  • Technical safeguards: access controls (unique user identification, role-based permissions), audit controls, integrity controls, transmission security (encryption via HTTPS/TLS), and authentication mechanisms.

  • Encryption of ePHI at rest and in transit using industry-standard encryption algorithms.

  • Regular testing and monitoring of security systems and processes.

  • Maintaining documentation of security policies and procedures as required by 45 CFR 164.316.

5. Breach Notification

In the event of a Breach of Unsecured PHI, Business Associate shall:

  • Notify the Covered Entity of the Breach without unreasonable delay, and in no case later than sixty (60) calendar days after discovery of the Breach.

  • Include in the notification, to the extent available: (a) the identification of each individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the Breach; (b) a description of the nature of the Breach, including the types of PHI involved; (c) a description of what Business Associate is doing to investigate the Breach, mitigate harm, and protect against future Breaches; and (d) contact information for individuals to ask questions or obtain additional information.

  • Cooperate with the Covered Entity in the investigation and mitigation of the Breach and in meeting any obligations of the Covered Entity to provide notifications under 45 CFR 164.404 (notification to individuals), 45 CFR 164.406 (notification to media), and 45 CFR 164.408 (notification to the Secretary of HHS).

  • Maintain records of all Breaches and Security Incidents as required by HIPAA.

6. Term and Termination

This BAA shall be effective as of the effective date of the Underlying Agreement and shall remain in effect until all PHI provided by the Covered Entity to Business Associate, or created or received by Business Associate on behalf of the Covered Entity, is destroyed or returned, or if return or destruction is infeasible, protections are extended in accordance with this Section.

  • Termination for Cause: Either party may terminate this BAA if the other party materially breaches any provision of this BAA and fails to cure such breach within thirty (30) days of receiving written notice of the breach.

  • Effect of Termination: Upon termination of this BAA, Business Associate shall, at the direction of the Covered Entity, return or destroy all PHI received from the Covered Entity, or created or received by Business Associate on behalf of the Covered Entity. If return or destruction is not feasible, Business Associate shall extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for as long as Business Associate maintains such PHI.

  • Survival: The obligations of Business Associate under this Section shall survive the termination of this BAA.

7. Return or Destruction of PHI

Upon termination of the Underlying Agreement or this BAA, or upon request of the Covered Entity, Business Associate shall:

  • Return to the Covered Entity or destroy all PHI received from, or created or received on behalf of, the Covered Entity that Business Associate maintains in any form.

  • Retain no copies of the PHI except as necessary for Business Associate's proper management and administration or to carry out its legal responsibilities.

  • For any PHI that Business Associate determines is infeasible to return or destroy, extend the protections of this BAA to such information and limit further uses and disclosures to those purposes that make the return or destruction infeasible.

  • Certify in writing to the Covered Entity that all PHI has been returned or destroyed, or that return or destruction is infeasible and protections have been extended.

8. Miscellaneous

  • Regulatory References: Any reference in this BAA to a section of HIPAA or its implementing regulations means the section as in effect or as amended from time to time.

  • Amendment: The Parties agree to take such action as is necessary to amend this BAA from time to time to comply with the requirements of HIPAA and any other applicable law.

  • Interpretation: Any ambiguity in this BAA shall be interpreted to permit compliance with HIPAA.

  • No Third-Party Beneficiaries: Nothing in this BAA shall confer upon any person other than the Parties and their respective successors or assigns any rights, remedies, obligations, or liabilities whatsoever.

  • Entire Agreement: This BAA, together with the Underlying Agreement, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements and understandings, both written and oral.

  • Governing Law: This BAA shall be governed by and construed in accordance with the laws of the State of California, to the extent not preempted by federal law.

  • Notices: All notices required or permitted under this BAA shall be in writing and shall be delivered to the addresses specified in the Underlying Agreement.

To execute a Business Associate Agreement with Skipper, or if you have any questions about this template, please contact us at:

Skipper Software, LLC

legal@skippernemt.com

Back to home