Read

BAA

Entered into pursuant to the Health Insurance Portability andAccountability Act of 1996, as amended.

This Business Associate Agreement (this "Agreement") is enteredinto by and between Merchant Pool, LLC doing business as RCM Fintech("Business Associate"), and the covered entity that executes thisAgreement or that enters into an Underlying Agreement incorporating thisAgreement by reference ("Covered Entity"). Business Associate andCovered Entity are referred to individually as a "Party" andcollectively as the "Parties." This Agreement is effective as of thedate of execution or, where incorporated by reference into an UnderlyingAgreement, as of the effective date of that Underlying Agreement (the "EffectiveDate").

Recitals

  1. Covered Entity is a covered     entity as that term is defined at 45 C.F.R. 160.103, or is a business     associate acting on behalf of a covered entity and entering into this     Agreement in that capacity.
  2. Business Associate provides     revenue cycle management, payment integrity, insurance underpayment     recovery, remittance and contract analysis, processing optimization,     recurring revenue protection, and related administrative, technical, and     financial services to Covered Entity under one or more separate written     agreements (each, an "Underlying Agreement").
  3. In the course of performing those     services, Business Associate may create, receive, maintain, or transmit     Protected Health Information on behalf of Covered Entity, and therefore     acts as a business associate as that term is defined at 45 C.F.R. 160.103.
  4. The HIPAA Rules require Covered     Entity to obtain satisfactory assurances that Business Associate will     appropriately safeguard Protected Health Information, and require Business     Associate to comply with specified provisions of those Rules directly.
  5. The Parties enter into this     Agreement to satisfy those requirements, to establish the permitted and     required uses and disclosures of Protected Health Information by Business     Associate, and to allocate responsibility and risk between them.

In consideration of the mutual promises below and the exchange ofinformation contemplated by the Underlying Agreement, the Parties agree asfollows.

Article 1. Definitions

1.1 Terms Defined by the HIPAA Rules. Capitalized terms used but not otherwise defined inthis Agreement have the meanings assigned to them in the HIPAA Rules, includingwithout limitation the terms Breach, Data Aggregation, Designated Record Set,Disclosure, Health Care Operations, Individual, Minimum Necessary, Payment,Required by Law, Secretary, Security Incident, Subcontractor, UnsecuredProtected Health Information, and Use.

1.2 Additional Definitions. For purposes of this Agreement, the following terms have the meanings setforth below.

  • "Confidential     Information" means non-public information of a Party disclosed to or observed by     the other Party, including Business Associate's security policies,     architecture, audit reports, questionnaire responses, pricing,     methodologies, and analytical models.
  • "Discovery" means, with respect to Business     Associate, the first day on which an impermissible use or disclosure,     Breach, or Successful Security Incident is known to, or by exercising     reasonable diligence would have been known to, a member of Business     Associate's workforce other than the individual committing the act giving     rise to it.
  • "Electronic Protected Health     Information" or "ePHI" means Protected Health     Information that is transmitted by or maintained in electronic media.
  • "HIPAA Rules" means the Privacy, Security,     Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160, 162,     and 164, as amended, together with the Health Information Technology for     Economic and Clinical Health Act and its implementing regulations.
  • "Protected Health     Information" or "PHI" means protected health     information as defined at 45 C.F.R. 160.103, but is limited for purposes     of this Agreement to protected health information created, received,     maintained, or transmitted by Business Associate from or on behalf of     Covered Entity in connection with the Services. Information that has been     de-identified in accordance with Section 3.5 is not PHI.
  • "Services" means the services Business     Associate performs for or on behalf of Covered Entity under one or more     Underlying Agreements.
  • "Unsuccessful Security     Incident" has the meaning given in Section 5.7.

Article 2. Scope and Relationship tothe Underlying Agreement

2.1 Scope. This Agreement governs only the creation, receipt, maintenance,transmission, use, and disclosure of PHI. It does not govern any other aspectof the relationship between the Parties.

2.2 Order of Precedence. In the event of a direct conflict between this Agreement and anUnderlying Agreement with respect to the handling of PHI, this Agreementcontrols solely as to the conflicting term. All other terms of the UnderlyingAgreement, including without limitation provisions governing fees, term,warranties and disclaimers, confidentiality, insurance, dispute resolution, andlimitation of liability, remain in full force and apply to this Agreementexcept as expressly modified by Article 9.

2.3 No Expansion of Services. Nothing in this Agreement expands, alters, or creates any obligation ofBusiness Associate to perform services, provide deliverables, implementconfigurations, or dedicate personnel beyond what is expressly set forth in anUnderlying Agreement. Any additional service, technical configuration,reporting, remediation, or support requested by Covered Entity in connectionwith this Agreement is subject to a separate written statement of work and toadditional fees.

2.4 Single Instrument. This Agreement applies to all Underlying Agreements between the Parties,whether existing on the Effective Date or entered into afterward, andsupersedes any prior business associate agreement between the Parties.

2.5 Preprinted and Portal Terms Rejected. Any business associate terms, securityaddenda, or data protection terms contained in a purchase order, vendorregistration portal, supplier onboarding form, click-through interface,invoice, or other standard form issued by Covered Entity are expressly rejectedand have no force or effect, whether or not accepted or acknowledged by anyperson, unless separately signed by an authorized officer of Business Associatewith specific reference to this Section.

Article 3. Permitted Uses andDisclosures by Business Associate

3.1 Performance of Services. Business Associate may use and disclose PHI as necessary to perform theServices, provided that such use or disclosure would not violate the PrivacyRule if done by Covered Entity, except as otherwise permitted by Sections 3.2through 3.6. The Parties acknowledge that the Services constitute Paymentactivities, Health Care Operations, or both, within the meaning of 45 C.F.R.164.501.

3.2 Management and Administration. Business Associate may use PHI for the propermanagement and administration of Business Associate and to carry out its legalresponsibilities. Business Associate may disclose PHI for those purposes if thedisclosure is Required by Law, or if Business Associate obtains reasonableassurances from the recipient that the information will be held confidentiallyand used or further disclosed only as Required by Law or for the purpose forwhich it was disclosed, and that the recipient will notify Business Associateof any instance of which it becomes aware in which the confidentiality of theinformation has been breached.

3.3 Legal Compliance and Defense. Business Associate may use and disclose PHI asreasonably necessary to comply with applicable law, to respond to a lawfulinquiry, examination, audit, subpoena, or civil investigative demand from agovernmental authority or accreditation body, to obtain legal, accounting,insurance, or professional advice, and to establish, exercise, or defend alegal claim, including a claim involving Covered Entity. Business Associatewill seek reasonable protective measures where practicable and will limit anysuch disclosure to the Minimum Necessary.

3.4 Data Aggregation. Business Associate may use PHI to provide Data Aggregation servicesrelating to the Health Care Operations of Covered Entity as permitted by 45C.F.R. 164.504(e)(2)(i)(B).

3.5 De-identification and Use of De-identified Information. Business Associate may de-identify PHIin accordance with 45 C.F.R. 164.514(a) through (c) and may create Limited DataSets in accordance with 45 C.F.R. 164.514(e). Information properlyde-identified in accordance with the foregoing is not PHI, is not subject tothis Agreement, and is the property of Business Associate. Business Associatemay use, disclose, license, retain, and otherwise commercially exploitde-identified information and aggregate statistics derived from it for anylawful purpose, including benchmarking, payer performance analysis, industryresearch, quality improvement, model training, product development, andmarketing, provided that Business Associate does not attempt to re-identify theinformation and does not identify Covered Entity by name or by a descriptionfrom which Covered Entity is reasonably identifiable without Covered Entity'sprior written consent. The rights granted in this Section survive terminationor expiration of this Agreement and each Underlying Agreement.

3.6 Required by Law. Business Associate may use and disclose PHI as Required by Law.

3.7 Minimum Necessary. Business Associate will make reasonable efforts to limit PHI to theMinimum Necessary to accomplish the intended purpose, consistent with 45 C.F.R.164.502(b) and applicable guidance issued by the Secretary. Covered Entity issolely responsible for determining the Minimum Necessary amount of PHI ittransmits or makes accessible to Business Associate.

Article 4. Prohibited Uses andDisclosures

4.1 General Prohibition. Business Associate will not use or disclose PHI other than as permittedor required by this Agreement or as Required by Law.

4.2 Sale of PHI. Business Associate will not directly or indirectly receive remunerationin exchange for any PHI except as permitted by 45 C.F.R. 164.502(a)(5)(ii) andunless Covered Entity has obtained a valid authorization from the Individual.For the avoidance of doubt, this Section does not restrict Business Associate'srights under Section 3.5, does not apply to information that is not PHI, anddoes not apply to the fees paid to Business Associate for the Services.

4.3 Marketing and Fundraising. Business Associate will not use or disclose PHI for marketing orfundraising purposes in a manner that would require an authorization under 45C.F.R. 164.508 unless Covered Entity has obtained that authorization and hasprovided a copy to Business Associate.

4.4 Psychotherapy Notes. Business Associate will not use or disclose psychotherapy notes except aspermitted by 45 C.F.R. 164.508(a)(2). Covered Entity will not transmitpsychotherapy notes to Business Associate.

4.5 Reproductive Health Care. Business Associate will not use or disclose PHI for a purpose prohibitedby 45 C.F.R. 164.502(a)(5)(iii). Covered Entity will notify Business Associateof any attestation requirement it believes applies to a disclosure requested ofBusiness Associate.

Article 5. Obligations of BusinessAssociate

5.1 Safeguards. Business Associate will use appropriate administrative, physical, andtechnical safeguards, and will comply with Subpart C of 45 C.F.R. Part 164 withrespect to ePHI, to prevent use or disclosure of PHI other than as provided forby this Agreement.

5.2 Security Rule Compliance. Business Associate will comply with 45 C.F.R. 164.308, 164.310, 164.312,and 164.316 with respect to ePHI. Consistent with the flexibility of approachpermitted by 45 C.F.R. 164.306(b), Business Associate determines which securitymeasures are reasonable and appropriate to its size, complexity, technicalinfrastructure, cost, and the risks identified in its own risk analysis.Covered Entity may not unilaterally impose specific security controls,technologies, or configurations on Business Associate absent a separate writtenagreement.

5.3 Workforce. Business Associate will train members of its workforce who handle PHI ontheir obligations under the HIPAA Rules, will bind them to writtenconfidentiality obligations at least as protective as this Agreement, and willapply appropriate sanctions for violations.

5.4 Mitigation. Business Associate will take reasonable steps to mitigate, to the extentpracticable, any harmful effect known to it of a use or disclosure of PHI inviolation of this Agreement.

5.5 Reporting Impermissible Use or Disclosure. Business Associate will report toCovered Entity any use or disclosure of PHI not permitted by this Agreement ofwhich it becomes aware, without unreasonable delay and in no event later thanthirty (30) calendar days after Discovery.

5.6 Breach Notification. Business Associate will notify Covered Entity of any Breach of UnsecuredPHI without unreasonable delay and in no event later than thirty (30) calendardays after Discovery. The notice will include, to the extent then known andreasonably available to Business Associate:

  1. the identification of each     Individual whose Unsecured PHI has been, or is reasonably believed to have     been, accessed, acquired, used, or disclosed;
  2. a brief description of what     occurred, including the date of the Breach and the date of Discovery, if     known;
  3. a description of the types of     Unsecured PHI involved; and
  4. a description of the steps     Business Associate has taken or will take to investigate the Breach,     mitigate harm, and protect against further breaches.

Business Associate will supplement its notice as additional informationbecomes available. The provision of notice under this Section is not, and willnot be construed as, an acknowledgment or admission by Business Associate offault, negligence, or liability, or that a Breach in fact occurred.

5.7 Security Incidents. Business Associate will report Successful Security Incidents inaccordance with Sections 5.5 and 5.6. The Parties acknowledge and agree thatthis Section constitutes notice of the ongoing occurrence of UnsuccessfulSecurity Incidents, and that no further notice of Unsuccessful SecurityIncidents is required. "Unsuccessful Security Incidents" meansSecurity Incidents that do not result in unauthorized access, use, disclosure,modification, or destruction of ePHI or interference with system operations inan information system containing ePHI, including without limitation pings andother broadcast attacks on a firewall, port scans, unsuccessful log-onattempts, denial of service attacks, phishing attempts that are not acted upon,and malware that is quarantined or blocked.

5.8 Notification of Individuals and Allocation of Costs. As between the Parties, Covered Entityretains sole responsibility and sole discretion for determining whether aBreach requiring notification has occurred and for providing any requirednotification to Individuals, the Secretary, and the media under 45 C.F.R.164.404 through 164.408. Business Associate will cooperate reasonably and willnot make notification directly to Individuals unless expressly directed to doso in writing by Covered Entity. Where a Breach results solely from BusinessAssociate's negligence, willful misconduct, or material breach of thisAgreement, Business Associate will reimburse Covered Entity for the reasonable,documented, direct out-of-pocket costs of legally required notification,subject to Article 9. Business Associate is not responsible for costsattributable to Covered Entity's acts or omissions, for credit monitoring,identity protection, call center services, remediation, or other remedies thatexceed what applicable law requires, or for any notification Covered Entity electsto make in the absence of a legal obligation, unless Business Associate hasagreed to those costs in writing in advance.

5.9 Subcontractors. Business Associate may engage Subcontractors that create, receive,maintain, or transmit PHI on its behalf without the prior approval of CoveredEntity. Business Associate will require each such Subcontractor, by writtenagreement, to agree to restrictions and conditions that are at least asstringent as those that apply to Business Associate under this Agreement, inaccordance with 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2). BusinessAssociate may permit Subcontractors located outside the United States to accessPHI provided the foregoing flow-down requirements are satisfied and appropriatesafeguards are in place. Business Associate will provide a list ofSubcontractors that access PHI upon reasonable written request, which list isBusiness Associate's Confidential Information. Business Associate remainsresponsible for the acts and omissions of its Subcontractors with respect toPHI to the same extent as for its own acts and omissions, subject in all casesto Article 9.

5.10 Access to PHI. To the extent Business Associate maintains PHI in a Designated Record Seton behalf of Covered Entity, Business Associate will, within fifteen (15)business days of a written request from Covered Entity, make that PHI availableto Covered Entity in the format reasonably requested so that Covered Entity maymeet its obligations under 45 C.F.R. 164.524. Business Associate will notrespond directly to an Individual's request for access and will forward anysuch request it receives to Covered Entity within ten (10) business days.

5.11 Amendment of PHI. To the extent Business Associate maintains PHI in a Designated Record Seton behalf of Covered Entity, Business Associate will make that PHI availablefor amendment and will incorporate any amendment directed by Covered Entityunder 45 C.F.R. 164.526 within twenty (20) business days of written request.Business Associate will forward any amendment request received directly from anIndividual to Covered Entity within ten (10) business days.

5.12 Accounting of Disclosures. Business Associate will maintain and, within twenty (20) business days ofa written request from Covered Entity, make available the information requiredfor Covered Entity to provide an accounting of disclosures under 45 C.F.R.164.528. Business Associate is not required to account for disclosures madebefore the Effective Date, for disclosures excepted under 45 C.F.R.164.528(a)(1), or for any period exceeding six (6) years before the request.Business Associate will forward any accounting request received directly froman Individual to Covered Entity within ten (10) business days.

5.13 Restrictions and Confidential Communications. Business Associate will comply withrestrictions on the use or disclosure of PHI agreed to by Covered Entity under45 C.F.R. 164.522 and with requests for confidential communications, only tothe extent that Covered Entity notifies Business Associate of the restrictionor request in writing and in advance, the restriction is within the scope ofthe Services, and Business Associate has the technical capability to implementit. Business Associate has no liability for failing to honor a restriction orrequest of which it was not so notified.

5.14 Access to Books and Records. Business Associate will make its internal practices,books, and records relating to the use and disclosure of PHI available to theSecretary for purposes of determining Covered Entity's compliance with thePrivacy Rule. Disclosure to the Secretary does not waive any attorney-client,work product, or other privilege. Business Associate will notify Covered Entityof any such request promptly unless prohibited from doing so.

5.15 Obligations of Covered Entity Carried Out by Business Associate. To the extent Business Associate isexpressly delegated in writing to carry out an obligation of Covered Entityunder Subpart E of 45 C.F.R. Part 164, Business Associate will comply with therequirements of Subpart E that apply to Covered Entity in the performance ofthat obligation. No such delegation is effective unless set forth in anUnderlying Agreement or a written amendment signed by both Parties.

5.16 Designated Record Set. The Parties acknowledge that Business Associate does not create ormaintain a Designated Record Set on behalf of Covered Entity unless expresslyagreed in writing. Sections 5.10 through 5.12 apply only to the extent BusinessAssociate in fact maintains PHI in a Designated Record Set.

5.17 Documentation. Business Associate will maintain the policies, procedures, anddocumentation required by 45 C.F.R. 164.316 for the period required by thatsection.

Article 6. Obligations andRepresentations of Covered Entity

6.1 Notice of Privacy Practices. Covered Entity will notify Business Associate inwriting of any limitation in its notice of privacy practices under 45 C.F.R.164.520, and of any change to that notice, to the extent the limitation orchange affects Business Associate's permitted use or disclosure of PHI.

6.2 Authorizations and Revocations. Covered Entity will notify Business Associate inwriting of any changes in, or revocation of, an Individual's permission to useor disclose PHI, to the extent it affects Business Associate's permitted use ordisclosure.

6.3 Restrictions. Covered Entity will notify Business Associate in writing and in advanceof any restriction on the use or disclosure of PHI to which Covered Entity hasagreed under 45 C.F.R. 164.522, to the extent it affects Business Associate.

6.4 Permissible Requests. Covered Entity will not request Business Associate to use or disclose PHIin any manner that would not be permissible under the Privacy Rule if done byCovered Entity, except as permitted under Sections 3.2 through 3.5.

6.5 Minimum Necessary and Scope of Transmission. Covered Entity will transmit or makeaccessible to Business Associate only the Minimum Necessary PHI reasonablyrequired for the Services. Covered Entity will not transmit PHI outside thescope of the Underlying Agreement, and Business Associate has no obligationwith respect to, and no liability arising from, PHI transmitted outside thatscope. If Covered Entity transmits PHI outside that scope, Business Associatemay return, delete, or quarantine it without further obligation.

6.6 Authority, Consents, and Accuracy. Covered Entity represents and warrants that it hasobtained all rights, authorizations, consents, and approvals necessary toprovide PHI to Business Associate and to permit Business Associate to use anddisclose PHI as contemplated by this Agreement and the Underlying Agreement,including with respect to any Subcontractor and any offshore processing.Covered Entity is solely responsible for the accuracy, completeness, and legalsufficiency of the PHI and other data it provides.

6.7 Secure Transmission. Covered Entity will transmit PHI to Business Associate only through thechannels, portals, protocols, and interfaces designated by Business Associate,and will encrypt PHI in transit in accordance with guidance issued by theSecretary under Section 13402(h)(2) of the HITECH Act. Business Associate hasno responsibility or liability for PHI transmitted by Covered Entity throughunsecured or non-designated channels, including unencrypted electronic mail,consumer file sharing services, or facsimile to an unverified number.

6.8 Covered Entity Systems and Credentials. Covered Entity is solely responsiblefor the security, configuration, patching, and monitoring of its own systems,networks, electronic health record platforms, clearinghouses, and interfaces,and for the issuance, monitoring, and timely deprovisioning of any accesscredentials it grants to Business Associate's workforce. Business Associate hasno responsibility or liability for vulnerabilities in, or compromises of,systems it does not own or control, including third-party systems CoveredEntity directs Business Associate to access.

6.9 Individual Requests. Covered Entity is solely responsible for responding to requests fromIndividuals for access, amendment, accounting, restriction, or confidentialcommunications. Business Associate owes no duty directly to any Individualunder this Agreement.

6.10 Cooperation. Covered Entity will cooperate reasonably and promptly with BusinessAssociate in the investigation of any suspected impermissible use ordisclosure, Breach, or Security Incident, including by providing informationwithin its possession or control.

Article 7. Security Documentation andAssessment

7.1 Documentation in Lieu of Audit. Upon written request, not more than once in any twelve(12) month period, Business Associate will provide Covered Entity with itsthen-current third-party security attestation or certification, such as a SOC 2Type II report, HITRUST certification, or comparable independent assessment,or, if none is then available, its completed responses to a standardizedindustry security questionnaire. Delivery of that documentation satisfiesBusiness Associate's obligation to provide assurances regarding its safeguards.

7.2 Limited Assessment Right. If the documentation provided under Section 7.1 discloses a materialdeficiency that Business Associate has not remediated within a reasonableperiod, or following a Breach determined to have been caused by BusinessAssociate, Covered Entity may conduct one assessment of Business Associate'ssafeguards applicable to Covered Entity's PHI in any twelve (12) month period.Any such assessment is subject to the following conditions:

  1. at least thirty (30) days prior     written notice, and scheduling at a mutually agreeable time during normal     business hours;
  2. conduct at Covered Entity's sole     cost and expense, in a manner that does not unreasonably disrupt Business     Associate's operations;
  3. compliance with Business     Associate's security, safety, and confidentiality policies, and execution     of a nondisclosure agreement by Covered Entity and any assessor;
  4. no access to the data, records,     or systems of Business Associate's other clients, to source code, to     proprietary analytical models, to shared infrastructure, or to information     the disclosure of which would violate law or a third-party obligation; and
  5. no assessor that is a competitor     of Business Associate, and no penetration testing, vulnerability scanning,     or other intrusive testing without Business Associate's prior written     consent.

7.3 Confidentiality of Results. All information obtained under this Article, including reports, findings,and questionnaire responses, is Business Associate's Confidential Informationand may be used by Covered Entity solely to evaluate Business Associate'scompliance with this Agreement.

7.4 No Transfer of Responsibility. The exercise or non-exercise of rights under thisArticle does not relieve Business Associate of its obligations under thisAgreement, does not constitute approval of Business Associate's safeguards, anddoes not transfer any liability to Covered Entity.

Article 8. Term and Termination

8.1 Term. This Agreement begins on the Effective Date and continues until the laterof the termination or expiration of all Underlying Agreements and the date onwhich all PHI is returned or destroyed, or, where return or destruction isinfeasible, indefinitely as to PHI retained under Sections 8.4 and 8.5.

8.2 Termination for Cause. If either Party knows of a pattern of activity or practice of the otherParty that constitutes a material breach or violation of the other Party'sobligations under this Agreement, the non-breaching Party will provide writtennotice describing the breach in reasonable detail. If the breaching Party failsto cure within thirty (30) days of that notice, the non-breaching Party mayterminate this Agreement and any Underlying Agreement to which the PHI at issuerelates. If cure is not possible, the non-breaching Party may terminateimmediately upon written notice. If neither cure nor termination is feasible,the non-breaching Party will report the violation to the Secretary.

8.3 Return or Destruction of PHI. Upon termination or expiration of this Agreement,Business Associate will, within sixty (60) days and subject to Sections 8.4 and8.5, return or destroy all PHI that Business Associate still maintains in anyform and retain no copies. Business Associate may elect between return anddestruction in its sole discretion and will select a commercially reasonablemethod of destruction consistent with guidance issued by the Secretary.Business Associate will cause its Subcontractors to do the same. Business Associatewill provide written certification of destruction upon Covered Entity's writtenrequest. Any return of PHI in a format other than Business Associate's standardexport format, or any extraction, migration, or transformation servicesrequested by Covered Entity, is subject to a separate written statement of workand additional fees.

8.4 Infeasibility. Where return or destruction of PHI is infeasible, Business Associate willnotify Covered Entity of the conditions that make it infeasible, will extendthe protections of this Agreement to the retained PHI, and will limit furtheruses and disclosures of the retained PHI to those purposes that make return ordestruction infeasible, for so long as Business Associate maintains it. TheParties agree that return or destruction is infeasible with respect to PHIcontained in archival backups, disaster recovery media, immutable storage,transaction and audit logs, and systems from which selective deletion is nottechnically practicable, and with respect to PHI that Business Associate isrequired to retain by law.

8.5 Permitted Retention. Notwithstanding Section 8.3, Business Associate may retain PHI to theextent Required by Law and as reasonably necessary for its record retention,tax, accounting, audit, insurance, quality assurance, and legal defensepurposes, and for the duration of any pending or reasonably anticipated claim,investigation, or proceeding. Retained PHI remains subject to the protectionsof this Agreement for so long as it is retained and will be used and disclosedonly for the purposes described in this Section.

8.6 Survival. Article 1, Sections 3.3, 3.5, 5.14, 8.3 through 8.6, Article 9, andArticle 10 survive termination or expiration of this Agreement, together withany other provision that by its nature is intended to survive.

Article 9. Allocation of Risk

9.1 Indemnification by Business Associate. Subject to Sections 9.4 and 9.5,Business Associate will defend and indemnify Covered Entity against third-partyclaims, and against civil monetary penalties imposed on Covered Entity by theSecretary, to the extent arising directly from Business Associate's materialbreach of this Agreement, gross negligence, or willful misconduct resulting inan impermissible use or disclosure of PHI.

9.2 Indemnification by Covered Entity. Covered Entity will defend and indemnify BusinessAssociate against all claims, losses, liabilities, penalties, fines, judgments,settlements, and reasonable attorneys' fees arising from or relating to:

  1. Covered Entity's breach of this     Agreement or of the HIPAA Rules;
  2. Covered Entity's negligence or     willful misconduct;
  3. PHI provided to Business     Associate without the rights, authorizations, or consents required by     Section 6.6, or in violation of applicable law;
  4. Covered Entity's failure to     notify Business Associate of a limitation, restriction, authorization     change, or revocation as required by Sections 6.1 through 6.3;
  5. Covered Entity's instructions or     directions to Business Associate that result in an impermissible use or     disclosure;
  6. Covered Entity's transmission of     PHI in violation of Section 6.5 or Section 6.7; and
  7. any compromise of, or     vulnerability in, Covered Entity's systems, credentials, or third-party     platforms as described in Section 6.8.

9.3 Indemnification Procedure. The Party seeking indemnification will provide prompt written notice ofthe claim, will tender sole control of the defense and settlement to theindemnifying Party, and will cooperate reasonably at the indemnifying Party'sexpense. Failure to provide prompt notice relieves the indemnifying Party ofits obligations to the extent it is prejudiced. The indemnifying Party will notsettle any claim in a manner that imposes a non-indemnified obligation or anadmission of fault on the indemnified Party without that Party's prior writtenconsent, not to be unreasonably withheld.

9.4 Limitation of Liability. Except in the case of a Party's fraud or willful misconduct, each Party'stotal aggregate liability arising out of or relating to this Agreement, whetherbased in contract, tort, statute, indemnity, or any other theory, will notexceed the limitation of liability set forth in the applicable UnderlyingAgreement. If the applicable Underlying Agreement contains no limitation ofliability, that liability will not exceed the total fees paid by Covered Entityto Business Associate under that Underlying Agreement during the twelve (12)months immediately preceding the first event giving rise to the claim. Thislimitation applies in the aggregate to all claims under this Agreement and theapplicable Underlying Agreement taken together, and is not cumulative with anylimitation in that Underlying Agreement.

9.5 Exclusion of Certain Damages. Except in the case of a Party's fraud or willfulmisconduct, neither Party is liable for any indirect, incidental, special,consequential, exemplary, or punitive damages, or for lost profits, lostrevenue, lost data, loss of goodwill, reputational harm, or businessinterruption, arising out of or relating to this Agreement, even if advised ofthe possibility of such damages and regardless of whether the claim is based incontract, tort, or any other theory. Breach notification and remediation costsare recoverable only to the limited extent expressly provided in Section 5.8and subject to Section 9.4.

9.6 Regulatory Penalties. Each Party is solely responsible for civil monetary penalties, correctiveaction plan obligations, and other sanctions assessed against it by theSecretary or a state authority for its own acts or omissions. Neither Party isliable for penalties assessed against the other Party arising from that Party'sindependent violations of the HIPAA Rules.

9.7 Insurance. Business Associate will maintain, at its own expense, commerciallyreasonable cyber liability and technology errors and omissions insurance withlimits of not less than [AMOUNT] per claim and in the aggregate, and willprovide a certificate of insurance upon reasonable written request. Theexistence, limits, or scope of any insurance does not expand BusinessAssociate's liability beyond the limits set forth in Sections 9.4 and 9.5, andthe failure of any insurer to pay does not create liability that would nototherwise exist.

Article 10. General Provisions

10.1 Regulatory References. A reference in this Agreement to a section of the HIPAA Rules means thatsection as in effect on the Effective Date or as subsequently amended, andincludes any successor provision.

10.2 Amendment for Compliance. The Parties will negotiate in good faith to amend this Agreement asnecessary for either Party to comply with a change in the HIPAA Rules or otherapplicable law. If the Parties are unable to agree on an amendment within sixty(60) days after either Party requests one, either Party may terminate thisAgreement and the affected Underlying Agreements upon thirty (30) days writtennotice.

10.3 Interpretation. Any ambiguity in this Agreement will be resolved to permit the Parties tocomply with the HIPAA Rules. This Agreement will not be construed againsteither Party as drafter. Section headings are for convenience only. The words"including" and "includes" mean including withoutlimitation.

10.4 No Third-Party Beneficiaries. Nothing in this Agreement confers any right, benefit,remedy, obligation, or cause of action on any person other than the Parties andtheir permitted successors and assigns, including any Individual whose PHI issubject to this Agreement.

10.5 Independent Contractor. Business Associate is an independent contractor. Nothing in thisAgreement creates a partnership, joint venture, agency, employment, orfiduciary relationship between the Parties. Neither Party has authority to bindthe other.

10.6 Assignment. Neither Party may assign this Agreement without the prior written consentof the other Party, except that either Party may assign it without consent to asuccessor in connection with a merger, acquisition, reorganization, or sale ofall or substantially all of its assets or of the business line to which thisAgreement relates. Any purported assignment in violation of this Section isvoid.

10.7 Notices. Notices under this Agreement must be in writing and delivered to thenotice addresses set forth in the applicable Underlying Agreement, or, if noneis designated, to Business Associate at the address published on this websiteand to Covered Entity at its principal place of business, by personal delivery,nationally recognized overnight courier, or certified mail, return receiptrequested. Notices under Sections 5.5 through 5.7 may additionally be deliveredby electronic mail to the address designated by the receiving Party for thatpurpose, effective upon confirmed transmission. Either Party may change itsnotice address upon written notice.

10.8 Governing Law and Venue. This Agreement is governed by the laws of the State of [STATE], withoutregard to its conflict of laws principles, except to the extent preempted byfederal law. The Parties consent to the exclusive jurisdiction and venue of thestate and federal courts located in [COUNTY], [STATE], and each Party waivesany objection to that venue and any right to trial by jury.

10.9 Severability. If any provision of this Agreement is held invalid or unenforceable, thatprovision will be modified to the minimum extent necessary to make itenforceable, and the remaining provisions will continue in full force andeffect.

10.10 Waiver. No failure or delay in exercising any right under this Agreement operatesas a waiver, and no single or partial exercise precludes any further exercise.A waiver is effective only if in writing and signed by the waiving Party.

10.11 Force Majeure. Neither Party is liable for any failure or delay in performance underthis Agreement, other than an obligation to pay money, caused by an eventbeyond its reasonable control, including acts of God, natural disaster,epidemic, war, terrorism, civil unrest, labor disruption, utility ortelecommunications failure, governmental action, or a widespread attack oninternet infrastructure, provided the affected Party gives prompt notice anduses commercially reasonable efforts to resume performance.

10.12 Entire Agreement. This Agreement, together with the Underlying Agreements, constitutes theentire agreement between the Parties with respect to the subject matter of thisAgreement and supersedes all prior and contemporaneous agreements, businessassociate agreements, proposals, and understandings, whether written or oral,on that subject.

10.13 Published Version and Incorporation by Reference. Business Associate publishes thecurrent form of this Agreement on this page. Where an Underlying Agreementincorporates this Agreement by reference, the version published as of theeffective date of that Underlying Agreement governs. Business Associate mayrevise the published form prospectively to reflect changes in law or itsoperations, effective upon thirty (30) days written notice to Covered Entity.No revision applies retroactively or to PHI created or received before therevision takes effect. Covered Entity's continued transmission of PHI toBusiness Associate after the notice period constitutes acceptance of therevised form.

10.14 Execution. This Agreement takes effect upon the earlier of (a) execution of anUnderlying Agreement that incorporates this Agreement by reference and (b)execution of a separate counterpart of this Agreement by both Parties. Acountersigned counterpart, including one executed through an electronicsignature platform or delivered in portable document format, is available uponrequest and has the same effect as an original. Counterparts togetherconstitute one instrument.