Business Associate Agreement

Version 2026-08-05

This Business Associate Agreement (“BAA”) is entered into between the practice or other legal entity identified during registration (“Customer”) and Bomi Health, Inc. (“Bomi”) and is effective upon Customer’s affirmative acceptance, whether by electronic or written signature, by checking an agreement box or other affirmative electronic acceptance, or by execution of an Order Form that expressly incorporates this BAA. To the extent Customer is a “Covered Entity” or “Business Associate” and Bomi creates, receives, maintains, or transmits PHI on Customer’s behalf, this BAA applies and Bomi acts as Customer’s “Business Associate” or “Subcontractor Business Associate,” as those terms apply under HIPAA. This BAA expressly replaces all prior Business Associate Agreements between the parties for all Bomi Products.

1. Purpose, Scope, and Definitions

This BAA supplements the Terms of Service, each managed-services or other services agreement between the parties, and every applicable Order Form (each a “Services Agreement”). “Bomi Products” means every software product or managed service that Customer orders from Bomi under a Services Agreement, including Bomi EHR, Bomi Managed Billing, Bomi Credentialing, their integrations, and separately ordered optional features. To the extent Bomi creates, receives, maintains, or transmits Protected Health Information (“PHI”) in connection with a Bomi Product for or on behalf of Customer, Bomi acts as Customer’s Business Associate or Subcontractor Business Associate.

This is a master BAA covering all Bomi Products, even when separate Services Agreements govern their commercial terms. PHI remains subject to this BAA when it is exchanged, copied, or otherwise processed across Bomi Products. This master scope does not make one Bomi Product part of another or change the products, fees, or services included in a particular Services Agreement.

“Breach,” “Designated Record Set,” “Disclosure,” “Discovery,” “Electronic Protected Health Information” (“ePHI”), “Individual,” “Required by Law,” “Security Incident,” “Subcontractor,” “Unsecured PHI,” and “Use” have the meanings assigned by the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164, as amended (collectively, “HIPAA”). “PHI” includes ePHI. Capitalized terms not defined here have the meanings in the applicable Services Agreement.

“Part 2” means the federal confidentiality regulations at 42 C.F.R. Part 2, as amended. “Part 2 Record” means a record subject to Part 2. When Customer is a Part 2 program and Bomi provides services involving Part 2 Records, Bomi is Customer’s qualified service organization (“QSO”) and, where applicable, its Business Associate or Subcontractor Business Associate. This BAA is also the parties’ written QSO agreement. Bomi acknowledges that, in receiving, storing, processing, or otherwise dealing with Part 2 Records from Customer, Bomi is fully bound by Part 2 and, if necessary, will resist in judicial proceedings any efforts to obtain access to patient-identifying Part 2 information except as Part 2 permits.

2. Permitted Uses and Disclosures

Bomi may use and disclose PHI only:

  • as necessary to provide the Bomi Products described in an applicable Services Agreement for or on behalf of Customer, including hosting, securing, backing up, transmitting, and displaying records to authorized users; operating Bomi EHR clinical, claims, billing, payment, Client Portal, support, and integration workflows; providing separately ordered Bomi Managed Billing and Bomi Credentialing services; and following Customer’s lawful instructions;
  • as expressly permitted by this BAA; or
  • as Required by Law.

Bomi will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Customer, except for uses and disclosures expressly permitted below for Bomi’s proper management and administration or legal responsibilities. Bomi will limit uses, disclosures, and requests for PHI to the minimum necessary where HIPAA’s minimum-necessary standard applies.

Bomi may use and disclose Part 2 Records only to provide the services described in the applicable Services Agreement, carry out Customer’s lawful instructions, or as otherwise permitted or required by Part 2. Where a valid consent permits treatment, payment, and health care operations, Bomi may process and redisclose Part 2 Records in its capacity as a Business Associate as Part 2 and HIPAA permit, subject to Customer’s notice of a written revocation or other restriction. Bomi will not use or disclose Part 2 Records in a civil, criminal, administrative, or legislative proceeding against a patient except with the patient’s specific written consent or a Part 2-compliant court order.

Bomi may use PHI for its proper management and administration or to carry out its legal responsibilities. Bomi may disclose PHI for those purposes only if Required by Law or if Bomi obtains reasonable written assurances from the recipient that the PHI will remain confidential, will be used or further disclosed only as Required by Law or for the purpose disclosed, and the recipient will notify Bomi of any known breach of confidentiality.

Bomi will not use or disclose PHI for Bomi’s or a third party’s marketing or fundraising and will not directly or indirectly receive remuneration in exchange for PHI. This does not prohibit ordinary fees Customer pays for Bomi Products or permitted Business Associate services that are not payment for a sale or disclosure of PHI to another person.

2.1 Legal Process

Unless prohibited by law, Bomi will promptly notify Customer of a subpoena, warrant, court order, civil investigative demand, or other compulsory legal process seeking Customer PHI or Part 2 Records, and of any investigative or otherwise non-routine payer demand for Customer PHI or Part 2 Records, and provide Customer a copy of the request. This provision does not apply to routine payer requests made in the ordinary course of treatment, payment, claims administration, audit, utilization review, or other health care operations that Bomi is engaged to handle under a Services Agreement; Bomi responds to those requests as part of the services without separate notice. Bomi will disclose only the minimum information legally required and reasonably cooperate with Customer’s efforts to seek a protective order or other appropriate relief. Bomi will preserve and assert all objections and court-order requirements applicable under Part 2. Nothing in this provision requires Bomi to violate law, waive a privilege, or delay compliance beyond a legally permitted period.

3. Safeguards and Security Rule Compliance

Bomi will use appropriate administrative, technical, and physical safeguards to prevent uses or disclosures of PHI not permitted by this BAA. Bomi will comply, where applicable, with Subpart C of 45 C.F.R. Part 164 with respect to ePHI and with 45 C.F.R. Part 162 when conducting a Standard Transaction for or on behalf of Customer.

Bomi will maintain formal policies and procedures and appropriate safeguards for Part 2 Records as required by Part 2. Part 2 Records do not need to be segregated or segmented from other records solely because they are subject to Part 2, and Bomi does not promise automatic Part 2 record classification, segmentation, consent validation, revocation enforcement, or disclosure approval. Customer must use available access controls and workflows consistently with its legal obligations.

4. Subcontractors

Bomi will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on Bomi’s behalf enters into a written agreement imposing the same restrictions, conditions, and requirements concerning PHI that apply to Bomi under this BAA, as required by 45 C.F.R. §§ 164.502(e), 164.504(e), and 164.308(b). If Bomi knows of a material pattern or practice by a Subcontractor that violates that agreement, Bomi will take reasonable steps to cure the violation or end it and, if unsuccessful, terminate the relationship where feasible.

Bomi will disclose Part 2 Records to a Subcontractor only when permitted by Part 2 and will bind the Subcontractor in writing to the applicable Part 2 restrictions and obligations. Bomi remains responsible for selecting and managing Subcontractors within the approved service boundary; this provision does not authorize a disclosure that Customer could not lawfully direct.

5. Reporting of Impermissible Uses, Disclosures, and Security Incidents

Bomi will report to Customer, without unreasonable delay and no later than five (5) business days after discovery, (i) a Breach of Customer’s Unsecured PHI, (ii) a Use or Disclosure of Customer’s PHI not permitted by this BAA, or (iii) a Material Security Incident affecting Customer ePHI. The initial notice may be preliminary, and Bomi may supplement it as additional information becomes available. A “Material Security Incident” means a successful or reasonably suspected unauthorized access, use, disclosure, modification, or destruction of Customer ePHI, or a material interference with system operations involving Customer ePHI. These contractual deadlines are additional requirements and do not extend any shorter deadline imposed by law.

Bomi will mitigate, to the extent practicable, any harmful effect known to Bomi resulting from a Use or Disclosure of PHI in violation of this BAA or from a Security Incident affecting Customer ePHI. Bomi will take reasonable steps to contain the event, preserve relevant evidence, and provide rolling updates.

To the extent known, an initial notice will describe the impermissible Use or Disclosure, Security Incident, or Breach; awareness, Discovery, and occurrence dates as applicable; affected systems; types of PHI; affected customers and Individuals; containment and mitigation; and known or anticipated impact. Bomi will provide rolling written updates as material facts become available, preserve relevant evidence consistent with law, reasonably cooperate with Customer’s investigation, and provide information required for notifications under 45 C.F.R. § 164.410.

For a Breach of Unsecured Part 2 Records, the parties will also perform the breach-notification duties applicable under Part 2. Bomi will provide Customer the information reasonably available to Bomi that Customer needs to make required patient, HHS, state, or other notices, without extending any shorter deadline in this Section or applicable law.

Customer controls legally required notices to Individuals, HHS, state regulators, and media unless Customer expressly directs Bomi in writing to provide a notice and the parties agree on its content and delivery, except to the extent Bomi is independently required by applicable law to provide a notice or report. In that case, Bomi will, where legally permitted, coordinate with Customer and will not unreasonably delay either party’s compliance. Allocation of reasonable response costs is governed by the Services Agreement and responsibility for the event.

The parties acknowledge and agree that unsuccessful pings, port scans, failed authentication attempts, blocked malware, firewall events, and similar unsuccessful events that do not result in unauthorized access, Use, Disclosure, modification, destruction, or material interference are deemed reported upon acceptance of this BAA and require no separate notice unless they become part of a reportable pattern or result in an adverse event.

6. Individual Rights and Delegated Duties

If Bomi receives a request directly from an Individual concerning Customer-controlled PHI, Bomi will promptly forward it to Customer and will not approve or deny it unless Customer has expressly delegated that authority in writing.

Bomi will make PHI maintained in a Designated Record Set available to Customer, or to the Individual or designee as directed by Customer, as reasonably necessary for Customer to satisfy 45 C.F.R. § 164.524.

Bomi will make PHI in a Designated Record Set available for amendment and will incorporate amendments to PHI or take other measures as directed or agreed to by Customer, as reasonably necessary for Customer to satisfy its obligations under 45 C.F.R. § 164.526. Bomi will document disclosures of PHI and make available the information under its control that Customer reasonably needs to provide an accounting of disclosures under 45 C.F.R. § 164.528, as reasonably necessary for Customer to meet its deadlines.

To the extent Bomi carries out an obligation of Customer under HIPAA, Bomi will comply with the requirements of HIPAA that apply to Covered Entity in performing that obligation. Bomi will make its internal practices, books, and records relating to PHI available to the Secretary of HHS for determining compliance with HIPAA.

Bomi will provide reasonable assistance, as directed by Customer, for Part 2 patient requests and accountings that concern Part 2 Records maintained by Bomi. Customer remains responsible for determining the patient’s rights and for approving or denying a request unless Customer expressly delegates that decision to Bomi in writing.

7. Deidentification, Analytics, and AI

Bomi may use PHI to provide contracted analytics and health care operations services for or on behalf of Customer.

Customer authorizes Bomi to create information deidentified in accordance with 45 C.F.R. § 164.514(b) (“De-Identified Data”) from PHI in accordance with this Section. Bomi will use either a documented Expert Determination or HIPAA’s Safe Harbor method, including the required removal of identifiers and absence of actual knowledge that remaining information can identify an Individual. Bomi will address small groups, rare conditions, unusual combinations, and other reidentification risks through the applicable methodology. Neither Bomi nor a recipient acting for Bomi may attempt to reidentify an Individual or attribute De-Identified Data to Customer.

Bomi may use De-Identified Data for analytics, benchmarking, research, security, product improvement, and development of insights and tools. Bomi may not use PHI for independent research without a separate lawful basis and required documentation. Bomi will not sell PHI or identifiable Customer or patient information.

Bomi will not use PHI or other identifiable Customer Data to train, fine-tune, evaluate, or improve any general-purpose, cross-customer, product-specific, or customer-specific artificial-intelligence or machine-learning model unless Customer has expressly agreed in an applicable Order Form or other feature-specific writing and all required legal bases and individual authorizations have been obtained. This restriction does not prohibit Bomi’s permitted use of De-Identified Data under this Section, provided it remains deidentified and cannot reasonably be linked to an Individual or Customer.

Bomi may process identifiable Customer Data through an approved model solely for ordinary inference, customer-specific retrieval, summarization, transcription, or workflow processing needed to provide a Customer-specific feature expressly ordered by Customer and governed by an applicable Order Form or other feature-specific written terms. Each applicable model provider must be bound by appropriate privacy and security obligations, including a downstream BAA when required, and contractually prohibited from retaining inputs or outputs beyond the permitted processing or using them to train, fine-tune, evaluate, or improve its own or any third party’s models.

AI-generated output is draft output, may be incomplete or inaccurate, and must be reviewed and approved by an appropriately qualified authorized user before it is used for clinical care, documentation, coding, claims, or patient communications.

The applicable Order Form or other feature-specific written terms will address recording and transcription consent; model and provider identity; prompt, transcript, and output retention; clinician review; prohibited autonomous decisions and patient-facing communications; state-specific restrictions; incident handling; and whether the feature is beta or production.

Customer may opt out of future use of its source data in cross-customer product-improvement analytics by written notice. The opt-out becomes effective within thirty days and survives termination. Bomi may continue customer-specific analytics. Previously created De-Identified Data, statistics, and non-reversible aggregate results may be retained, but Bomi will not create new cross-customer analytics from Customer’s source data after the effective date. Customer may opt back in by written notice.

8. Customer Obligations

Customer will:

  • notify Bomi of limitations in its Notice of Privacy Practices that affect Bomi’s permitted uses or disclosures;
  • notify Bomi of changes in an Individual’s permission, revocations, agreed restrictions, and confidential-communication requirements that affect Bomi’s processing;
  • determine whether Customer is a Part 2 program and which records are Part 2 Records; provide any required Part 2 notice of privacy practices; obtain, document, and honor required consents and written revocations; and give Bomi timely, lawful disclosure instructions;
  • supply any consent copy, clear explanation of consent scope, or accompanying Part 2 notice required for a Customer-directed disclosure through Bomi, unless the applicable Services Agreement expressly assigns that delivery step to Bomi;
  • identify SUD counseling notes separately from other Part 2 Records and obtain any separate written consent required before directing Bomi to disclose those notes;
  • not request a use or disclosure that Customer could not lawfully make itself, except as expressly permitted for a Business Associate;
  • ensure it has authority to provide PHI to Bomi and direct its processing, administer Authorized Users, and promptly disable unauthorized access; and
  • remain responsible for approving or denying Individual requests unless decision-making authority is expressly delegated to Bomi in writing.

9. Term, Material Breach, and Termination

This BAA begins upon Customer’s affirmative acceptance and remains effective while Bomi creates, receives, maintains, or transmits Customer’s PHI or until all such PHI is returned or destroyed in accordance with this BAA.

Customer may terminate this BAA as to an affected Bomi Product and the applicable Services Agreement if Bomi materially breaches this BAA and, where cure is reasonably possible, fails to cure or end the violation within five (5) business days after Customer’s written notice, or another reasonable period appropriate to the circumstances. Customer may terminate immediately as to the affected Bomi Product if the breach cannot reasonably be cured or creates a continuing material risk. Customer may suspend further disclosures of PHI where reasonably necessary to protect PHI or comply with law. Bomi may terminate an affected Bomi Product if Customer materially breaches this BAA and fails to cure within the same framework, subject to Bomi’s patient-access, return, and offboarding duties.

10. Return, Export, Retention, and Destruction

On termination, Bomi will provide the transition and export access stated in the Services Agreement and will return or destroy Customer’s PHI as Customer directs, where feasible. Available exports will be provided in reasonably accessible and usable electronic formats. Reasonable additional migration assistance may be provided under the Services Agreement at rates disclosed in advance.

After the applicable transition period, Bomi will delete PHI from active production systems, active replicas, and the systems of Subcontractors that maintain the relevant PHI, under documented procedures and applicable contractual controls, except where retention is Required by Law or subject to a legal hold. PHI in protected backups, archives, and logs will be isolated from ordinary product use, remain protected by this BAA, and become inaccessible or be overwritten through the ordinary documented retention cycle. Upon written request, Bomi will certify completion of deletion, subject to disclosed lawful retention, Subcontractor confirmation where applicable, and protected backup, archive, and log cycles.

If Bomi determines that return or destruction of PHI is infeasible, Bomi will notify Customer in writing of the conditions that make it infeasible, extend the protections of this BAA to retained PHI, and limit further uses and disclosures to the purposes that make return or destruction infeasible for as long as Bomi maintains the PHI.

11. Amendment and Order of Precedence

The parties will amend this BAA as necessary to comply with HIPAA or other applicable law. Bomi may present an amended BAA for signature or affirmative electronic reacceptance by Customer’s authorized representative. An electronic record of acceptance has the same effect as a signed writing and must be retainable and accurately reproducible. If a change is Required by Law, it will become effective after notice to the minimum extent and on the date legally required even if Customer does not reaccept it. Any other amendment requires signature or affirmative reacceptance; no posting alone amends a BAA previously accepted by Customer.

If this BAA conflicts with a Services Agreement concerning PHI, this BAA controls for every affected Bomi Product. If the parties later execute a written BAA that expressly replaces this BAA or expressly governs identified Bomi Products or PHI, the later, more specific BAA controls only for that stated scope and only to the extent of a conflict; this BAA remains effective for all other Bomi Products and PHI. Except as expressly modified here, each Services Agreement remains in effect, including its governing-law, notices, assignment, dispute, indemnification, and limitation-of-liability provisions to the extent they do not prevent either party from complying with HIPAA.

12. Notices

All notices under this BAA must be in writing and may be delivered personally, by nationally recognized overnight courier, by certified mail with return receipt requested, or by email; notice is effective upon receipt. Notices to Bomi must be sent to Bomi Health, Inc., Attn: Legal, 1710 Mullikin Dr, Champaign, IL 61822, or by email to [email protected]. Notices to Customer must be sent to the mailing address or email address associated with Customer’s account or designated in writing by Customer.

Notwithstanding Section 11 or any notice provision of a Services Agreement, this Section governs every notice concerning this BAA, PHI, or a Breach or Security Incident. For every other notice to Bomi under a Services Agreement, the address and email in this Section replace any different Bomi notice address stated in that Services Agreement, and the remainder of that Services Agreement’s notice provision continues to apply.

13. Interpretation, No Third-Party Beneficiaries, and Survival

Any ambiguity will be interpreted to permit both parties to comply with HIPAA and other applicable law. This BAA creates no third-party beneficiaries.

Provisions concerning PHI retained after termination, confidentiality, permitted uses of De-Identified Data, cooperation regarding incidents occurring during the Term, and provisions that by their nature should survive will survive termination.

Acceptance

This BAA may be accepted by electronic signature, by checking an agreement box, by execution of an Order Form that expressly incorporates this BAA, or by another affirmative electronic acceptance method presented by Bomi. The individual accepting represents that they are authorized to bind Customer. Bomi will not create, receive, maintain, or transmit PHI for Customer before this BAA or another applicable written BAA is effective.

Bomi will maintain an acceptance record appropriate to the method used, including the accepted document version, Customer legal name, account and organization identifiers, acceptance method, signatory name and email, timestamp, and available IP address and user agent. Bomi will maintain an accurately reproducible copy of the accepted version and make a downloadable copy available to Customer. Bomi will retain each accepted version of this BAA and evidence of acceptance for at least six years after the later of the date the record was created or the date the accepted version was last in effect, or longer where required by applicable law.

Business Associate: Bomi Health, Inc., 1710 Mullikin Dr, Champaign, IL 61822.