Business Associate Agreement

Business Associate Agreement (“BAA”)

Last updated: July 20, 2026

This is a reference copy. The executed BAA is signed electronically during provider onboarding.

This Business Associate Agreement (“Agreement” or “BAA”) is entered into by and between the healthcare provider or covered entity accepting this Agreement (“Covered Entity”) and TrustRoom Connect, Inc. (“Business Associate” or “TrustRoom”).

This Agreement supplements and is made a part of the TrustRoom Terms of Service (“Terms”) and is effective as of the date the Covered Entity electronically accepts this Agreement during provider onboarding or by executing a separate written agreement.

1. Definitions

Unless otherwise defined herein, capitalized terms shall have the meanings set forth in the HIPAA Rules (45 C.F.R. Parts 160 and 164), as amended.

TermDefinition
HIPAAThe Health Insurance Portability and Accountability Act of 1996, as amended
HITECHThe Health Information Technology for Economic and Clinical Health Act (Title XIII of ARRA)
HIPAA RulesThe Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164
Protected Health Information (PHI)Individually identifiable health information transmitted or maintained by Business Associate on behalf of Covered Entity in any form or medium, including Electronic PHI
Electronic Protected Health Information (ePHI)PHI that is transmitted or maintained in electronic media
BreachThe acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule which compromises the security or privacy of the PHI, as defined in 45 C.F.R. § 164.402
Security IncidentThe attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system, as defined in 45 C.F.R. § 164.304
Unsecured PHIPHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through encryption or destruction, consistent with the guidance issued by HHS
IndividualThe person who is the subject of the PHI, including a person who qualifies as a personal representative under 45 C.F.R. § 164.502(g)
Required by LawA mandate contained in law that compels an entity to make a use or disclosure of PHI and that is enforceable in a court of law, as defined in 45 C.F.R. § 164.103
ServicesThe platform services provided by TrustRoom to Covered Entity as described in the Terms of Service, including secure messaging, care plan management, clinical analytics, AI-powered analysis, and related technology services
SubcontractorA person to whom Business Associate delegates a function, activity, or service involving the creation, receipt, maintenance, or transmission of PHI

2. Obligations of Business Associate

2.1 Permitted Uses and Disclosures

Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement, the Terms of Service, or as Required by Law. Specifically, Business Associate may:

  • (a) Use or disclose PHI solely to perform the Services described in the Terms of Service and as necessary to fulfill its obligations under this Agreement.
  • (b) Use or disclose PHI as Required by Law.
  • (c) Use PHI for the proper management and administration of Business Associate, provided that such uses are necessary for Business Associate's management and administration and are permitted under HIPAA.
  • (d) Disclose PHI for the proper management and administration of Business Associate, provided that: (i) the disclosure is Required by Law; or (ii) Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will be held confidentially and will not be further used or disclosed except as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
  • (e) Use PHI to de-identify information in accordance with 45 C.F.R. § 164.514(a)-(c), using the Safe Harbor method described in 45 C.F.R. § 164.514(b)(2). De-identified data is no longer PHI and is not governed by this Agreement.
  • (f) Use PHI to provide Data Aggregation services to Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).

2.2 Safeguards

Business Associate shall:

  • (a) Implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, as required by the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C).
  • (b) Comply with the requirements of the HIPAA Security Rule applicable to business associates, including 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316.
  • (c) Encrypt all ePHI at rest using AES-256 encryption (or equivalent) and in transit using TLS 1.2 or higher.
  • (d) Implement role-based access controls to ensure PHI is accessible only to authorized personnel.
  • (e) Maintain immutable audit logs recording all access to PHI, including user identification, date, time, and nature of access.
  • (f) Conduct periodic risk assessments in accordance with 45 C.F.R. § 164.308(a)(1)(ii)(A) and implement measures to address identified risks.

2.3 AI Processing

Business Associate uses artificial intelligence (“AI”) as part of the Services provided to Covered Entity. With respect to AI processing of PHI:

  • (a) All AI processing is performed within HIPAA-compliant cloud infrastructure covered by Business Associate Agreements between TrustRoom and its infrastructure providers.
  • (b) Business Associate's AI infrastructure provider does not retain PHI after processing. PHI is not used to train third-party AI models.
  • (c) AI is used solely to support Covered Entity's healthcare operations and treatment activities. AI does not make independent clinical decisions — all AI-generated outputs require review and approval by the Covered Entity's licensed clinicians.
  • (d) Covered Entity may disable AI processing for individual patients through the platform.
  • (e) Business Associate may retain de-identified data derived from AI processing for the purpose of improving service accuracy, subject to Section 2.1(e).

2.4 Reporting

Business Associate shall:

  • (a) Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including Breaches of Unsecured PHI as required by 45 C.F.R. § 164.410.
  • (b) Report to Covered Entity any Security Incident of which Business Associate becomes aware. Reports of attempted but unsuccessful Security Incidents (such as pings, port scans, or unsuccessful log-in attempts) shall be provided upon Covered Entity's written request.

2.5 Subcontractors

  • (a) In accordance with 45 C.F.R. § 164.502(e)(1)(ii) and 45 C.F.R. § 164.308(b)(2), Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement by entering into a written agreement containing substantially similar terms.
  • (b) Business Associate maintains Business Associate Agreements with all Subcontractors that access, create, receive, maintain, or transmit PHI in the course of providing the Services, including cloud infrastructure providers, AI processing providers, and integrated third-party platforms.

2.6 Access to PHI

  • (a) Business Associate shall make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524 (Individual's Right of Access), within thirty (30) days of a request by Covered Entity.
  • (b) Business Associate shall make available PHI for amendment and incorporate any amendments to PHI in a Designated Record Set as directed or agreed to by Covered Entity, in accordance with 45 C.F.R. § 164.526, within thirty (30) days of a request by Covered Entity.
  • (c) Business Associate shall make available the information required to provide an accounting of disclosures in accordance with 45 C.F.R. § 164.528, within thirty (30) days of a request by Covered Entity.

2.7 Government Access

Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for the purpose of determining compliance with the HIPAA Rules.

2.8 Minimum Necessary

Business Associate shall, to the extent practicable, limit its use, disclosure, or request of PHI to the minimum amount necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.502(b) and the HIPAA Minimum Necessary Rule.

3. Obligations of Covered Entity

3.1 Notice of Privacy Practices

Covered Entity shall provide Business Associate with a copy of its Notice of Privacy Practices produced in accordance with 45 C.F.R. § 164.520, as well as any changes to that notice.

3.2 Permissions and Restrictions

Covered Entity shall notify Business Associate of:

  • (a) Any changes in, or revocation of, authorizations by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.
  • (b) Any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

3.3 Permissible Requests

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Covered Entity.

4. Breach Notification

4.1 Discovery and Notification

  • (a) Business Associate shall report to Covered Entity any Breach of Unsecured PHI without unreasonable delay and in no case later than thirty (30) calendar days after discovery of such Breach, to the extent required by 45 C.F.R. § 164.410.
  • (b) A Breach shall be treated as discovered by Business Associate as of the first day on which such Breach is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate.

4.2 Content of Notification

Business Associate's notification to Covered Entity shall include, to the extent reasonably available:

  • (a) The identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the Breach;
  • (b) A description of the nature of the Breach, including:
    • The types of Unsecured PHI involved in the Breach (e.g., date of birth, diagnosis, treatment information, health information);
    • The date of the Breach and the date of its discovery;
    • A description of what Business Associate is doing to investigate the Breach, mitigate harm to Individuals, and protect against further Breaches;
  • (c) The name and contact information of Business Associate's designated privacy or security officer.

4.3 Cooperation

Business Associate shall cooperate with Covered Entity in:

  • (a) Investigating the Breach;
  • (b) Meeting Covered Entity's obligations for breach notifications to Individuals, HHS, and the media (if applicable) under 45 C.F.R. §§ 164.404, 164.406, and 164.408;
  • (c) Mitigating, to the extent practicable, any harmful effect of the Breach that is known to Business Associate.

Business Associate shall cooperate with Covered Entity to meet all applicable state and federal breach notification requirements.

5. 42 CFR Part 2 — Substance Use Disorder Records

5.1 Applicability

If Covered Entity is a Part 2 program, or if substance use disorder (“SUD”) treatment records are disclosed to Business Associate, the following additional protections apply in accordance with 42 CFR Part 2, as amended effective February 16, 2026:

  • (a) Business Associate shall not use or disclose SUD records except as permitted by 42 CFR Part 2 and consistent with the Individual's consent.
  • (b) SUD records received by Business Associate are subject to the anti-discrimination prohibitions of 42 CFR § 2.12, which prohibit the use of such records to initiate or substantiate any criminal charges or to conduct any investigation of the Individual.
  • (c) SUD records shall not be further disclosed by Business Associate without the Individual's written consent, except as expressly permitted by 42 CFR Part 2 (e.g., medical emergencies, qualifying audits, or qualifying court orders under Subpart E).
  • (d) Business Associate shall include the Part 2 re-disclosure notice with any permitted disclosure of SUD records:
“This record which has been disclosed to you is protected by Federal confidentiality rules (42 CFR Part 2). The Federal rules prohibit you from making any further disclosure of information in this record that identifies a patient as having or having had a substance use disorder either directly, by reference to publicly available information, or through verification of such identification by another person unless further disclosure is expressly permitted by the written consent of the individual whose information is being disclosed or as otherwise permitted by 42 CFR Part 2. A general authorization for the release of medical or other information is NOT sufficient for this purpose (see § 2.31). The Federal rules restrict any use of the information to investigate or prosecute with regard to a crime any patient with a substance use disorder, except as provided at §§ 2.12(c)(5) and 2.65.”

6. Term and Termination

6.1 Term

This Agreement shall be effective as of the Effective Date and shall terminate when all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information, in accordance with Section 6.3.

6.2 Termination for Cause

  • (a) Either party may terminate this Agreement if the other party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) calendar days after receiving written notice of the breach.
  • (b) Covered Entity may immediately terminate this Agreement if Business Associate has breached a material term and cure is not possible.
  • (c) Termination of this Agreement shall also terminate the Terms of Service and any related agreements, as Business Associate cannot perform the Services without processing PHI.

6.3 Effect of Termination

(a) Upon termination of this Agreement, Business Associate shall, at the direction of Covered Entity:

  • Return all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, within sixty (60) calendar days; OR
  • Destroy all such PHI within sixty (60) calendar days and provide written certification of such destruction to Covered Entity.

(b) If Business Associate determines that return or destruction of PHI is infeasible, Business Associate shall:

  • Provide to Covered Entity notification of the conditions that make return or destruction infeasible;
  • Extend the protections of this Agreement to such PHI;
  • Limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible.

(c) The obligations of Business Associate under this Section 6.3 shall survive the termination of this Agreement.

7. Indemnification

7.1 By Business Associate

Business Associate shall indemnify, defend, and hold harmless Covered Entity and its officers, directors, employees, and agents from and against any and all claims, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or related to:

  • (a) Any material breach of this Agreement by Business Associate;
  • (b) Any negligent or wrongful act or omission of Business Associate, its employees, agents, or Subcontractors relating to the use or disclosure of PHI.

7.2 By Covered Entity

Covered Entity shall indemnify, defend, and hold harmless Business Associate and its officers, directors, employees, and agents from and against any and all claims, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or related to:

  • (a) Any material breach of this Agreement by Covered Entity;
  • (b) Any negligent or wrongful act or omission of Covered Entity relating to instructions provided to Business Associate concerning the use or disclosure of PHI;
  • (c) Any use or disclosure of PHI by Business Associate that was authorized or directed by Covered Entity in a manner not permitted by this Agreement or applicable law.

8. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT EXCEED THE TOTAL AMOUNT PAID OR PAYABLE BY COVERED ENTITY TO BUSINESS ASSOCIATE UNDER THE TERMS OF SERVICE DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE LIABILITY.

THIS LIMITATION SHALL NOT APPLY TO: (A) BREACHES OF CONFIDENTIALITY OBLIGATIONS; (B) LIABILITY ARISING FROM GROSS NEGLIGENCE OR WILLFUL MISCONDUCT; OR (C) LIABILITY THAT CANNOT BE LIMITED UNDER APPLICABLE LAW.

9. Miscellaneous

9.1 Regulatory References

Any reference in this Agreement to a section of the HIPAA Rules means the section as in effect or as amended, and for which compliance is required.

9.2 Amendment

The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of HIPAA, the HIPAA Rules, and any other applicable law. No amendment to this Agreement shall be effective unless it is agreed to in writing by both parties.

9.3 Survival

The respective rights and obligations of Business Associate under Section 6.3 (Effect of Termination) shall survive the termination of this Agreement.

9.4 Interpretation

Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.

9.5 Governing Law

This Agreement shall be governed by and construed in accordance with the federal laws of the United States applicable to HIPAA and, to the extent not preempted, the laws of the State of California, without regard to its conflict of law provisions.

9.6 No Third-Party Beneficiaries

Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than the parties and the respective successors or assigns of the parties, any rights, remedies, obligations, or liabilities whatsoever.

9.7 Entire Agreement

This Agreement, together with the Terms of Service and any exhibits or addenda, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements and understandings, both written and oral, between the parties with respect to the subject matter hereof.

9.8 Severability

If any provision of this Agreement is held invalid, illegal, or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable.

9.9 Electronic Acceptance

This Agreement may be accepted electronically through the TrustRoom platform during provider onboarding. Electronic acceptance shall have the same legal force as a handwritten signature.

9.10 Notices

All notices required or permitted under this Agreement shall be in writing and shall be delivered by email to the addresses specified in the Terms of Service or to such other addresses as a party may designate in writing.

Business Associate's designated contact for BAA-related matters:
Email: compliance@trustroomconnect.com

Contact Information

For questions about this Agreement:

TrustRoom Connect, Inc.

Email: compliance@trustroomconnect.com

Mailing Address: 21241 Ventura Blvd. Ste #177, Woodland Hills, CA 91364