Clinic Agreement
Business Associate Agreement
BAA template for clinic onboarding before ePHI processing starts.
Last updated May 31, 2026
Status: Draft for legal review Document key: businessAssociateAgreement Version: 2026-05-31 Use: Clinic onboarding before ePHI processing
This Business Associate Agreement is a draft template for review by counsel. It should be finalized for each customer relationship and aligned with the main service agreement.
1. Parties
This Business Associate Agreement is entered into by and between:
- Covered Entity: the dental practice, clinic, professional entity, or customer identified in the applicable order form.
- Business Associate: Happy Light Tech, provider of Happy Light AI.
2. Purpose
Covered Entity may disclose Protected Health Information to Business Associate, or Business Associate may create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity, so Business Associate can provide AI receptionist, call handling, scheduling assistance, call logs, follow-up workflows, support, and related services.
3. Definitions
Terms including Breach, Business Associate, Covered Entity, Designated Record Set, Electronic Protected Health Information, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, Use, and Disclosure have the meanings assigned under HIPAA and implementing regulations.
4. Permitted Uses and Disclosures
Business Associate may use or disclose PHI only:
- to provide services described in the applicable service agreement or order form;
- as permitted by this BAA;
- as Required by Law;
- for proper management and administration of Business Associate, subject to HIPAA restrictions;
- to carry out legal responsibilities of Business Associate, subject to HIPAA restrictions; and
- to de-identify information according to applicable law.
Business Associate may not use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity, unless expressly permitted by HIPAA and this BAA.
5. Minimum Necessary
Business Associate will request, use, and disclose only the minimum necessary PHI needed to perform the services, except where an exception applies under HIPAA.
6. Safeguards
Business Associate will use reasonable and appropriate administrative, technical, and physical safeguards to protect PHI and ePHI. These safeguards may include encryption in transit, access controls, audit logging, tenant and branch scoping, private storage, secure credential management, role-based access, PHI-aware logging controls, and workforce access limitations.
7. Reporting
Business Associate will report to Covered Entity:
- any use or disclosure of PHI not permitted by this BAA of which Business Associate becomes aware;
- any Breach of Unsecured PHI of which Business Associate becomes aware; and
- any Security Incident involving ePHI of which Business Associate becomes aware.
The parties should define specific notice timing in the final agreement. Counsel should confirm whether a fixed deadline, such as without unreasonable delay and no later than a specified number of days, is appropriate.
8. Subcontractors
Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to substantially similar restrictions and safeguards.
9. Access, Amendment, and Accounting
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will reasonably assist Covered Entity with requests for access, amendment, and accounting of disclosures as required by HIPAA.
Happy Light AI is primarily an administrative workflow system and may not be the system of record for all patient data. Covered Entity remains responsible for patient record requests and final record determinations.
10. Availability to Secretary
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services as required by law.
11. Return or Destruction
Upon termination of the underlying service agreement, Business Associate will return or destroy PHI if feasible. If return or destruction is not feasible, Business Associate will continue to protect the PHI and limit further use or disclosure to the purpose that makes return or destruction infeasible.
12. Term and Termination
This BAA begins when the underlying service agreement begins or when Business Associate first creates, receives, maintains, or transmits PHI on behalf of Covered Entity, whichever is earlier.
Covered Entity may terminate the agreement if Business Associate materially breaches this BAA and fails to cure the breach within a reasonable cure period, unless immediate termination is required by law or patient safety risk.
13. No Third-Party Beneficiaries
Nothing in this BAA creates third-party beneficiary rights.
14. Order of Precedence
If this BAA conflicts with another agreement between the parties regarding PHI, this BAA controls with respect to PHI obligations.
15. Counsel Notes
Counsel should finalize:
- exact breach notice deadline;
- whether indemnity is included here or only in the master terms;
- state law requirements;
- subcontractor list approval mechanics;
- retention periods;
- whether call recordings and transcripts are part of a Designated Record Set; and
- call recording consent obligations.
