Back to Home
HIPAA

Business Associate Agreement

Between you as Covered Entity and Cognivolt as Business Associate. Accepted at signup and binding for as long as we hold patient information for you.

HIPAA requires a written agreement whenever a healthcare provider lets an outside service handle patient information. This is that agreement, in plain language. It sets out what we may do with patient data, how we protect it, what happens if something goes wrong, and what we need from you in return.

1. What this agreement is

This Business Associate Agreement ("Agreement") is between you — the clinician, practice or organisation using Cognivolt ("Covered Entity") — and Cognivolt ("Business Associate", "we", "us").

It exists because United States law (HIPAA) requires it. When a healthcare provider lets an outside service handle patient information, the two sides must have a written agreement setting out how that information may be used and protected. This is that agreement.

It applies whenever we handle Protected Health Information ("PHI") on your behalf. PHI means health information that identifies a patient, or could reasonably be used to identify one. Terms not defined here carry the meaning given to them in the HIPAA Rules at 45 CFR Parts 160 and 164.

This Agreement takes effect when you accept it during signup, and continues for as long as we hold PHI for you.

2. What we may do with patient information

We may use and disclose PHI only for these purposes:

To provide the service you signed up for — transcribing consultations, producing clinical notes and documentation, and the related features you turn on.

For our own proper management and administration, and to meet our own legal obligations.

To provide data aggregation services relating to your healthcare operations, where permitted by 45 CFR §164.504(e)(2)(i)(B).

We will not use or disclose PHI in any other way unless this Agreement permits it, you instruct us to, or the law requires it. We will not sell PHI, and we will not use it for marketing.

Where we disclose PHI for our own management or legal obligations, we will do so only if the disclosure is required by law, or we obtain reasonable assurances from the recipient that it will be kept confidential, used only as intended, and that we are told of any breach of it.

When we use or disclose PHI, we will limit it to the minimum reasonably necessary for the purpose, in line with 45 CFR §164.502(b).

3. How we protect it

We will use appropriate administrative, physical and technical safeguards to protect PHI, and we will comply with the HIPAA Security Rule (45 CFR Part 164, Subpart C) with respect to electronic PHI.

In practice that includes encryption of PHI in transit and at rest, access controls limiting who can reach patient data, audit logging of access to records, and staff who handle PHI being bound to confidentiality.

We will require anyone working under us who receives PHI to apply at least the same protections this Agreement places on us.

4. People who work for us

We use subcontractors and service providers — for example cloud hosting and infrastructure — to deliver the service. Where any of them handles PHI on our behalf, HIPAA requires them to be bound in writing to restrictions and conditions at least as protective as those in this Agreement, and we bind them accordingly.

We remain responsible to you for PHI handled by anyone acting on our behalf.

We do not list those providers here, so that we can change or add one without re-papering this Agreement with every customer. A current list is available on request.

5. Telling you when something goes wrong

If we discover a breach of unsecured PHI, we will notify you without unreasonable delay, and in any event within 30 calendar days of discovery. A breach is treated as discovered on the first day we know of it, or would have known of it by exercising reasonable diligence.

Our notice will include, to the extent known at the time and as it becomes available afterwards: what happened and when, the categories of PHI involved, the individuals affected or likely affected, what we have done in response, and what we are doing to mitigate harm and prevent recurrence.

We will also report to you any use or disclosure of PHI not permitted by this Agreement, and any successful Security Incident, on the same timeline.

Unsuccessful Security Incidents — such as blocked login attempts, port scans, pings and other routine traffic that does not result in unauthorised access to PHI — happen continuously against any internet-facing service. This paragraph serves as notice of them, and we will not report each one individually. We will provide a summary on reasonable request.

You remain responsible for notifying affected individuals, the Secretary of Health and Human Services, and any others the law requires. We will give you the information you reasonably need to do that.

6. Patient rights we help you honour

Patients have rights over their records, and you are the one who must answer them. Where we hold PHI in a Designated Record Set, we will help you do so:

Access — we will make PHI available to you so you can meet a request under 45 CFR §164.524.

Amendment — we will make PHI available for amendment, and incorporate amendments you direct, under 45 CFR §164.526.

Accounting of disclosures — we will keep the information needed, and make it available to you, so you can answer a request under 45 CFR §164.528.

Restrictions — we will comply with restrictions on use or disclosure that you have agreed to, once you tell us about them.

If a patient contacts us directly with such a request, we will refer them to you rather than answer it ourselves, and tell you promptly. You are the holder of the clinical relationship, and you decide.

To the extent we are to carry out one of your obligations under HIPAA Subpart E, we will comply with the requirements that apply to you in performing it.

7. Regulators

We will make our internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for the purpose of determining compliance with HIPAA.

If a court or government agency demands PHI we hold for you, we will — unless legally prohibited from doing so — tell you at least 10 business days before we hand anything over, so that you can object or seek a protective order.

8. What we need from you

This agreement only works if the information reaching us is lawfully collected. You agree that:

You have obtained any patient consent, authorisation or notice your own law requires before recording a consultation or sending us patient information.

Your Notice of Privacy Practices permits the uses and disclosures contemplated here, and you will tell us of any change to it, or to a patient permission or restriction, that affects how we may handle PHI.

You will not ask us to use or disclose PHI in a way that would breach HIPAA if you did it yourself.

You will not send us PHI you do not need us to have, and you will not use the service to transmit categories of data it is not designed for.

You keep your account credentials secure and are responsible for what is done through your account.

Clinical decisions remain entirely yours. Cognivolt produces documentation and decision support; it does not practise medicine, and nothing it outputs is medical advice. You are responsible for reviewing anything it generates before it enters a patient record or informs a decision.

9. Ending this agreement

If either of us materially breaches this Agreement, the other may give written notice of it. If the breach is not cured within 45 days, the other may terminate this Agreement and the service. If a cure is not possible, the non-breaching party may terminate immediately.

On termination, we will return or destroy all PHI we hold for you, and keep no copies, within 60 days — subject to the paragraph below. You are responsible for exporting anything you want to keep before that period ends; the service provides export tools for this.

Where returning or destroying PHI is not feasible — for example where it sits in backups that expire on a fixed cycle, or where law requires us to retain it — we will tell you, and we will continue to protect it under this Agreement and limit further use and disclosure to whatever makes return or destruction infeasible, for as long as we hold it.

The obligations in this section survive termination.

10. Limits of our liability

Neither of us is liable to the other for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue or data, arising out of this Agreement, even if told such damages were possible.

Except for our obligations of confidentiality and our breach-notification duties above, our total liability arising out of this Agreement is limited to the fees you paid us in the twelve months before the event giving rise to the claim.

Nothing in this section limits either party's obligations under HIPAA itself, or excludes liability that cannot lawfully be excluded.

You are responsible for your own acts and omissions, including the accuracy of what you enter, the lawfulness of your collection of it, and your clinical decisions. We are responsible for ours.

11. General

If HIPAA changes in a way that requires a change to this Agreement, both parties will negotiate in good faith to amend it. Where an amendment is necessary for us to remain compliant, we may make it on notice to you, and continuing to use the service after it takes effect means you accept it.

Any ambiguity in this Agreement will be resolved in favour of an interpretation that permits compliance with HIPAA.

The handling of Protected Health Information under this Agreement is governed by HIPAA and the HIPAA Rules at 45 CFR Parts 160 and 164, together with any other health-privacy law applicable to you as Covered Entity.

This Agreement is between you and us alone. It creates no rights for any third party, including patients.

If any part of this Agreement is held unenforceable, the rest remains in force.

Need this countersigned, or have questions?

We can provide a signed copy for your compliance records.

Contact Us