Draft HIPAA Business Associate Addendum.
Illustrative BAA negotiation text based on the HIPAA business-associate contract concepts. Yabby’s current MVP is not offered for protected health information (PHI); do not send PHI until a separate service review, security assessment, and signed BAA are complete.
DO NOT SEND PHI TO THE MVP. This draft is not an executed BAA, does not make Yabby a Business Associate, and does not establish HIPAA compliance or a required Security Rule safeguard. Counsel and qualified security professionals must review the actual service before any PHI processing.
1. Parties and permitted service
[Covered Entity / Business Associate] and [Yabby legal entity] enter this addendum effective [date] under [master agreement]. If executed, Yabby may provide only the specifically described services involving electronic PHI: [service and minimum necessary data]. The current public reverse-proxy MVP is excluded until the parties amend this scope.
2. Permitted uses and disclosures
Yabby may use or disclose PHI only as necessary to perform the contracted service, as documented by the Covered Entity, or as required by law. Yabby must not sell PHI, use it for advertising, or use it for an independent purpose. Minimum-necessary scope, approved hostnames, data classes, and prohibited routes must be attached before signature.
3. Safeguards
Yabby will implement the agreed administrative, physical, and technical safeguards for ePHI, including access control, workforce confidentiality, authentication, audit logging, incident response, encryption decisions, backup handling, vulnerability management, and availability controls. The parties must attach a control matrix and evidence obligations; this draft does not claim those controls currently exist.
4. Reporting
Yabby will report unauthorized uses or disclosures, security incidents, and breaches of unsecured PHI without undue delay through [security contact and deadline]. The parties will define investigation cooperation, evidence preservation, regulatory coordination, and responsibility for individual, HHS, and media notifications.
5. Individual rights and HHS access
To the extent Yabby holds PHI needed for the Covered Entity’s duties, Yabby will provide reasonable assistance with access, amendment, accounting, and other applicable obligations. Yabby will make relevant internal practices, records, and PHI available to the Secretary of HHS as required by the HIPAA Rules.
6. Subcontractors, termination, and destruction
Yabby will require subcontractors with PHI access to accept equivalent restrictions. On termination, Yabby will return or destroy PHI where feasible and retain it only as required by law, continuing protections for retained data. The Covered Entity may terminate for material breach that is not cured.
7. References and limits
This draft references the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules, including 45 CFR 164.504(e), but is not a substitute for the regulations, a risk analysis, a security programme, or legal advice. HHS sample provisions state that sample language alone may not create a binding contract under state law. See HHS sample BAA provisions and HHS Security Rule overview.