Business Associate Agreement
Effective 28 August 2026
This Agreement is between you (Covered Entity) and LYNT-X GLOBAL TECH LIMITED (Business Associate). It governs Protected Health Information that Business Associate creates, receives, maintains or transmits for Covered Entity. It must be executed before any PHI is collected.
1Definitions
Terms used here have the meanings given in 45 CFR Parts 160 and 164 — including Breach, Designated Record Set, Individual, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor and Unsecured PHI. HIPAA Rules means the Privacy, Security, Breach Notification and Enforcement Rules.
2Obligations of Business Associate
Business Associate shall:
- Not use or disclose PHI other than as permitted by this Agreement or as Required by Law.
- Use appropriate administrative, physical and technical safeguards, and comply with the Security Rule with respect to electronic PHI, to prevent use or disclosure other than as this Agreement provides.
- Report to Covered Entity any use or disclosure not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required by 45 CFR 164.410, and any Security Incident of which it becomes aware.
- Ensure that any Subcontractor creating, receiving, maintaining or transmitting PHI on its behalf agrees in writing to the same restrictions and conditions that apply to Business Associate.
- Make PHI in a Designated Record Set available to Covered Entity as necessary to satisfy 45 CFR 164.524.
- Make any amendment to PHI in a Designated Record Set as directed by Covered Entity, or take other measures as necessary to satisfy 45 CFR 164.526.
- Maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy 45 CFR 164.528.
- To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164, comply with the requirements that apply to Covered Entity in performing it.
- Make its internal practices, books and records available to the Secretary for determining Covered Entity's compliance with the HIPAA Rules.
- Request, use and disclose only the minimum necessary PHI to accomplish the purpose of the request, use or disclosure.
3Timing of notifications
Business Associate shall notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and no later than fifteen (15) calendar days after discovery, and shall include the information required by 45 CFR 164.410(c) to the extent then known, supplementing it as further information becomes available.
Unsuccessful Security Incidents — such as broadly targeted scans, pings and failed log-in attempts that result in no unauthorised access to PHI — are reported in aggregate on request rather than individually.
4Permitted uses and disclosures
Business Associate may use or disclose PHI only:
- To perform the services described in the Terms of Service, on Covered Entity's instructions.
- For its own proper management and administration, or to carry out its legal responsibilities.
- To provide data aggregation services relating to Covered Entity's health care operations, where requested.
- As Required by Law.
Where Business Associate discloses PHI to a third party for its own management and administration, it shall obtain reasonable assurances in writing that the information will be held confidentially, used only as permitted, and that the recipient will notify Business Associate of any breach.
Business Associate shall not use or disclose PHI to train machine-learning models, for its own product development, or for marketing of any kind. It shall not de-identify PHI except where Covered Entity instructs it in writing.
5Obligations of Covered Entity
- Notify Business Associate of any limitation in its Notice of Privacy Practices, of changes to or revocation of an Individual's permission, and of any restriction agreed under 45 CFR 164.522, to the extent these affect Business Associate's use or disclosure of PHI.
- Obtain any consent or authorisation required before PHI is collected through the Platform.
- Not request that Business Associate use or disclose PHI in a manner that would breach the HIPAA Rules if done by Covered Entity, except as permitted by section 4.
6Term and termination
This Agreement takes effect on the date it is executed and continues until all PHI is returned or destroyed under this section.
Covered Entity may terminate on written notice if Business Associate materially breaches this Agreement and fails to cure within thirty days.
On termination, Business Associate shall return or destroy all PHI it still holds, and shall retain no copies. Where return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to that PHI and limit further uses and disclosures to the reasons that make return or destruction infeasible, for so long as it retains it.
Destruction is effected by destroying the encryption key unique to Covered Entity, after which the remaining ciphertext is unreadable by any party, including Business Associate, and cannot be reconstructed from backups. Business Associate will confirm destruction in writing on request.
7Miscellaneous
A reference to a section of the HIPAA Rules means that section as amended from time to time. The parties shall amend this Agreement as necessary for Covered Entity to comply with the HIPAA Rules. Any ambiguity shall be resolved in favour of a meaning that permits compliance with the HIPAA Rules. Sections 2, 3, 4 and 6 survive termination.
Start by finding out what your websites are leaking.
A free scan of any practice site tells you in ninety seconds which trackers are loading on pages that collect patient information. No account, no card.