Business Associate Agreement (template)
Version 2026-09-28
This Business Associate Agreement ("Agreement") is between the customer that accepts it ("Covered Entity") and OrcLink ("Business Associate"). It applies when Covered Entity uses the OrcLink server-side conversions service (the "Service") and the Service creates, receives, maintains or transmits Protected Health Information on its behalf.
1. Definitions
Terms used but not defined here have the meanings given in the HIPAA Rules (45 C.F.R. Parts 160 and 164), including "Breach," "Designated Record Set," "Individual," "Minimum Necessary," "Protected Health Information" ("PHI"), "Required by Law," "Secretary," "Security Incident," "Subcontractor" and "Unsecured PHI." "HIPAA Rules" means the Privacy, Security, Breach Notification and Enforcement Rules, as amended by the HITECH Act.
2. Permitted uses and disclosures
- Business Associate may use or disclose PHI only to perform the Service: to record conversions, match them to ad clicks, and relay de-identified or minimized conversion signals to advertising platforms that Covered Entity configures.
- Business Associate will apply the Minimum Necessary standard. In HIPAA mode the Service replaces event names with opaque labels, hashes email and phone with SHA-256 before storage, and removes URLs, page titles, referrers and IP addresses from every outbound payload.
- Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, as permitted by 45 C.F.R. § 164.504(e)(4).
- Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, and will not sell PHI.
3. Safeguards
- Business Associate will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164, to protect electronic PHI.
- Safeguards include encryption of credentials at rest (AES-256-GCM), encryption in transit (TLS), role-based access control, and an append-only egress log of every payload sent to a third party.
- Business Associate will make its internal practices, books and records relating to PHI available to the Secretary to determine compliance with the HIPAA Rules.
4. Reporting and breach notification
- Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, and any Security Incident of which it becomes aware.
- Business Associate will notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and in no case later than ten (10) business days after discovery, and in all cases within the sixty (60) calendar day limit of 45 C.F.R. § 164.410.
- The notice will include, to the extent known, the identity of each affected Individual and the other information Covered Entity needs to meet its obligations under 45 C.F.R. § 164.404.
- Unsuccessful attempts (such as pings, port scans or blocked log-in attempts) that do not result in unauthorized access need no further notice under this section.
5. Subcontractors
In line with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate. Advertising platforms that receive minimized conversion signals at Covered Entity's direction are Covered Entity's own vendors, not Subcontractors of Business Associate; Covered Entity is responsible for its agreements with them.
6. Individual rights
To the extent Business Associate holds PHI in a Designated Record Set, it will, within fifteen (15) business days of a request from Covered Entity, make PHI available for access (45 C.F.R. § 164.524), make amendments (§ 164.526), and provide information for an accounting of disclosures (§ 164.528).
7. Obligations of Covered Entity
- Covered Entity will not ask Business Associate to use or disclose PHI in a way that the HIPAA Rules do not permit.
- Covered Entity is responsible for its configuration of the Service, including which advertising platforms receive data and whether HIPAA mode is on.
- Covered Entity will tell Business Associate of any restriction or revoked authorization that affects its use of PHI.
8. Term and termination
- This Agreement starts when both parties sign and ends when the Service ends, unless terminated earlier.
- If either party determines that the other has materially breached this Agreement, it will give written notice and thirty (30) days to cure. If the breach is not cured, the non-breaching party may terminate this Agreement and the Service, as described in 45 C.F.R. § 164.504(e)(2)(iii).
9. Return or destruction of PHI
On termination, Business Associate will return or destroy all PHI it holds for Covered Entity, and keep no copies, as required by 45 C.F.R. § 164.504(e)(2)(ii)(J). If return or destruction is not feasible (for example, records in the append-only egress log that must be kept to demonstrate compliance), Business Associate will extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it keeps the PHI.
10. Miscellaneous
- Any ambiguity will be resolved to permit compliance with the HIPAA Rules.
- The parties will amend this Agreement as needed to comply with changes to the HIPAA Rules.
- Nothing in this Agreement gives any third party any rights or remedies.
- Sections 4, 9 and 10 survive termination.