{"id":407,"date":"2025-11-29T12:14:37","date_gmt":"2025-11-29T12:14:37","guid":{"rendered":"https:\/\/healthymind.agencypartnerinteractive.com\/?page_id=407"},"modified":"2026-03-12T20:15:59","modified_gmt":"2026-03-12T20:15:59","slug":"business-associate-agreement","status":"publish","type":"page","link":"https:\/\/healthymind.agencypartnerinteractive.com\/?page_id=407","title":{"rendered":"Business Associate Agreement"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_section full_width=&#8221;stretch_row&#8221; el_class=&#8221;blogs-banner features-top-banner privacy-services-page&#8221;][vc_row full_width=&#8221;stretch_row_content_no_spaces&#8221; el_class=&#8221;blogs-banner-img&#8221;][vc_column][vc_single_image image=&#8221;29&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; css=&#8221;.vc_custom_1764067714666{margin-bottom: 0px !important;}&#8221;][\/vc_column][\/vc_row][vc_row equal_height=&#8221;yes&#8221; content_placement=&#8221;middle&#8221; el_class=&#8221;blogs-banner-content privacy_hero_banner&#8221;][vc_column width=&#8221;8\/12&#8243;][vc_custom_heading text=&#8221;Business Associate Agreement &#8211;<br \/>\nHealthy Mind Map&#8221; font_container=&#8221;tag:h1|text_align:left|color:%23000000&#8243; use_theme_fonts=&#8221;yes&#8221; css=&#8221;.vc_custom_1773346558052{margin-bottom: 0px !important;}&#8221;][vc_custom_heading text=&#8221;Please read the Business Associate Agreement carefully.&#8221; font_container=&#8221;tag:p|text_align:left|color:%23000000&#8243; use_theme_fonts=&#8221;yes&#8221; css_animation=&#8221;none&#8221; css=&#8221;&#8221;][vc_btn title=&#8221;App Store&#8221; css=&#8221;.vc_custom_1765462030104{background-image: url(https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2025\/11\/Store-download-button.png?id=112) !important;}&#8221; link=&#8221;url:https%3A%2F%2Fapps.apple.com%2Fus%2Fapp%2Fhealthy-mind-map-wellness-app%2Fid6737412082|target:_blank&#8221;][vc_btn title=&#8221;Goolge Play&#8221; css=&#8221;.vc_custom_1765462041513{background-image: url(https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2025\/11\/Store-download-button-1.png?id=113) !important;}&#8221; link=&#8221;url:https%3A%2F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3Fid%3Dcom.healthymindmap.mobile%26pcampaignid%3Dweb_share|target:_blank&#8221;][\/vc_column][vc_column width=&#8221;4\/12&#8243;][\/vc_column][\/vc_row][\/vc_section][vc_section el_class=&#8221;content_sec business-adreement-sec&#8221;][vc_row][vc_column width=&#8221;2\/3&#8243;][vc_custom_heading text=&#8221;EXHIBIT A&#8221; use_theme_fonts=&#8221;yes&#8221; css=&#8221;&#8221; el_class=&#8221;gradian-color&#8221;][vc_custom_heading text=&#8221;BUSINESS ASSOCIATE ADDENDUM&#8221; use_theme_fonts=&#8221;yes&#8221; css=&#8221;&#8221;][vc_column_text css=&#8221;.vc_custom_1764419618937{margin-bottom: 0px !important;}&#8221;]This Business Associate Addendum (the \u201c<strong>Addendum<\/strong>\u201d) is entered into by and between our Company (as used herein, the terms our \u201c<strong>Company<\/strong>,\u201d \u201c<strong>we,<\/strong>\u201d \u201c<strong>us<\/strong>\u201d or \u201c<strong>our<\/strong>\u201d refer to Healthy Mind Map, LLC, a Utah limited liability company), and the Covered Entity (defined below), if any, associated with your Account under the Terms of Service (the \u201c<strong>Underlying Agreement<\/strong>\u201d) to which this Addendum is attached and incorporated by reference. Unless otherwise defined herein, capitalized terms shall have the meanings given in the Underlying Agreement.[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764419634377{margin-bottom: 0px !important;}&#8221;]As used herein, \u201c<strong>Covered Entity<\/strong>\u201d means any health care provider (a person or organization who furnishes, bills, or is paid for health care in the normal course of business, such as physicians, licensed mental health care providers and other health care facilities) who transmits any health information in electronic form in connection with a transaction covered by the Privacy Standards (e.g., electronic transmission of health care claims or equivalent encounter information, inquiries regarding eligibility to receive health care under a health plan, pre-authorization requests).[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764419643712{margin-bottom: 0px !important;}&#8221;]In addition, if and to the extent that You are employed with, or contracted by, a Covered Entity (other than You individually), and You use the Services in providing health care items or services on behalf of such Covered Entity, \u201cCovered Entity\u201d as used herein includes both You and such Covered Entity, which shall be, and hereby is, expressly intended as a third-party beneficiary of our covenants and agreements in this Addendum relative to the confidentiality of PHI, with full rights to enforce our duties and obligations set forth in this Addendum as if such Covered Entity was a party to this Addendum.[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764775310794{margin-bottom: 0px !important;}&#8221;]<\/p>\n<ol role=\"list\">\n<li id=\"question35\"><strong>Certain Definitions.<\/strong> Unless otherwise defined herein, capitalized terms shall have the meanings given in Section 16 below and, if not defined herein or therein, the meanings given in HIPAA or HITECH.<\/li>\n<li id=\"question36\"><strong>Compliance with Applicable Law.<\/strong> We shall comply with our obligations under this Addendum and with all obligations of a business associate under HIPAA, HITECH, the Confidentiality Requirements and other related laws and any implementing regulations, as they exist at the time this Addendum is executed and as they are amended.<\/li>\n<li id=\"question37\"><strong>Our Duties.<\/strong>\n<ol role=\"list\">\n<li>We shall not use or disclose (or permit the use or disclosure of) PHI in a manner that would violate the Confidentiality Requirements if the PHI were used or disclosed by Covered Entity in the same manner, except as otherwise permitted or required by this Addendum or as required by law.<\/li>\n<li>We shall use appropriate safeguards to prevent the use or disclosure of PHI other than as expressly permitted under this Addendum.<\/li>\n<li>We will implement Administrative Safeguards, Physical Safeguards and Technical Safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of the Electronic PHI that we create, receive, maintain or transmit on behalf of Covered Entity. We acknowledge that HITECH requires that we comply with 45 C.F.R. \u00a7\u00a7 164.308, 164.310, 164.312 and 164.316 as if our Company were a covered entity, and we agree to comply with these provisions of the Security Standards and all other applicable security provisions of HITECH.<\/li>\n<li>To the extent feasible, We will use commercially reasonable efforts to ensure that the Technical Safeguards used by our Company to secure PHI will render such PHI unusable, unreadable and indecipherable to individuals unauthorized to acquire or otherwise have access to such PHI in accordance with the Confidentiality Requirements.<\/li>\n<li>We will implement policies and procedures to identify and respond to suspected and known Security Incidents and promptly report to Covered Entity any successful Security Incident of which it becomes aware. At the request of Covered Entity, We shall identify (and provide reasonable updates to Covered Entity regarding): the date of the successful Security Incident, the scope of the successful Security Incident and our response to the successful Security Incident. For this purpose, We hereby notify Covered Entity (and Covered Entity acknowledges) that We experience attempted but unsuccessful security incidents in the ordinary course of business for which no additional notice to Covered Entity is required. For purposes of this Addendum, unsuccessful security incidents include activity such as pings and other broadcast attacks on our firewall, port scans, unsuccessful log-on attempts, denials of service, and any combination of the above, so long as no such incident results in unauthorized access, use, or disclosure of PHI.<\/li>\n<li>Except as otherwise required by law, We shall use PHI (i) only for the purpose of performing services for, or on behalf of, Covered Entity pursuant to the Underlying Agreement, and (ii) as necessary for the proper management and administration of our Company or to carry out our legal responsibilities, provided that such uses are permitted under applicable federal and state law.<\/li>\n<li>We may de-identify PHI in accordance with 45 CFR 164.514(a)-(c), and resulting De-Identified Data may be used or disclosed by our Company in a manner consistent with its business and affairs, as determined in our sole discretion (but which may include, without limitation, the creation or development of derivative works, reports, publications, models, guidelines, algorithms or other treatment protocols relative to the diagnosis, prevention or treatment of human disease or other medical conditions, as well as copying, distributing or publishing any of the foregoing), provided that such uses or disclosures are permitted under applicable laws. Subject to the foregoing limitations, our Company is, and shall be, the sole and exclusive owner of any De-Identified Data created or developed by it.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764775329282{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question37&#8243;]<\/p>\n<ul>\n<li><strong>Disclosure of PHI.<\/strong>\n<ol role=\"list\">\n<li>Subject to any limitations in this Addendum, We may disclose PHI to any third party persons or entities as necessary to perform our obligations under the Underlying Agreement and as permitted or required by applicable federal or state law. Further, We may disclose PHI for the proper management and administration of our Company, provided that (i) such disclosures are required by law or (ii) We: (A) obtain reasonable assurances from any third party to whom the information is disclosed that it will be held confidential and further used and disclosed only as required by law or for the purpose for which it was disclosed to the third party and (B) agree to promptly notify Covered Entity of any instances of which We are aware that PHI is being used or disclosed for a purpose that is not otherwise provided for in this Addendum or for a purpose not expressly permitted by the Confidentiality Requirements.<\/li>\n<li>We will make reasonable efforts to limit any disclosures of PHI by our Company to any third party to the \u201cminimum necessary use and disclosure,\u201d i.e., only the minimum PHI that is necessary to accomplish the intended purpose may be disclosed. We shall comply with Section 13405(b) of HITECH, and any applicable regulations or guidance issued by Secretary concerning such provision, regarding the minimum necessary standard and the use and disclosure (if applicable) of Limited Data Sets.<\/li>\n<li>We agree to ensure that any agent or subcontractor, to whom We provide PHI, agrees in writing: (i) to restrictions and conditions with respect to use and disclosure of such PHI that are at least as restrictive as those that apply through this Addendum to our Company; and (ii) to implement Administrative Safeguards, Physical Safeguards and Technical Safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of the Electronic PHI that it creates, receives, maintains or transmits, directly or indirectly, on behalf of Covered Entity.<\/li>\n<li>We shall report to Covered Entity any use or disclosure of PHI not permitted by this Addendum, of which our Company becomes aware, such report to be made as soon as is practicable, but in any event within ten (10) business days of our Company becoming aware of such use or disclosure.<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764775408609{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question38&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Breach Notification.<\/strong> We agree to implement reasonable systems for the discovery and prompt reporting of any HIPAA Breach. The parties acknowledge and agree that 45 C.F.R. \u00a7 164.404 governs the determination of the date of a HIPAA Breach. We will, following the discovery of a HIPAA Breach, notify Covered Entity promptly and in no event later than ten (10) business days after We discover such HIPAA Breach, unless We are prevented from doing so by 45 C.F.R. \u00a7164.412 concerning law enforcement investigations. We shall provide Covered Entity with sufficient information to permit Covered Entity, as appropriate, to comply with the HIPAA Breach notification requirements set forth at 45 C.F.R. \u00a7164.400 et seq.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764775568794{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question39&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Designated Record Sets.<\/strong> If our Company maintains a Designated Record Set on behalf of Covered Entity that Covered Entity does not maintain, the following provisions shall apply:\n<ol role=\"list\">\n<li>We shall (i) provide access to, and permit inspection and copying of, PHI by Covered Entity or, if so requested in writing by Covered Entity, an individual who is the subject of the PHI under conditions and limitations required under 45 C.F.R. \u00a7 164.524, as it may be amended from time to time, and (ii) amend PHI maintained by our Company as requested by Covered Entity.<\/li>\n<li>We shall respond to a request from Covered Entity for access by an individual within five (5) business days of such request and shall make PHI in a Designated Record Set available for amendment and incorporate any amendments to PHI in accordance with 45 C.F.R. \u00a7164.526 requested by Covered Entity within ten (10) days of such request. Any information requested under this Section 6 shall be provided in the form or format requested, if it is readily producible in such form or format. We may charge a reasonable fee based upon our labor costs in responding to a request for electronic information (or a cost-based fee for the production of non-electronic media copies). Covered Entity shall determine whether a denial is appropriate or an exception applies.<\/li>\n<li>We shall notify Covered Entity within five (5) business days of receipt of any request for access or amendment by an individual. Covered Entity shall determine whether to grant or deny any access or amendment requested by the individual. We shall have a process in place for receiving requests for amendments and for appending such requests to the Designated Record Set.<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776201305{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question40&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Accounting for Disclosures.<\/strong> We shall make available to Covered Entity in response to a request from an individual, information required for an accounting of disclosures of PHI with respect to the individual, in accordance with 45 C.F.R. \u00a7 164.528. We shall provide to Covered Entity such information necessary to provide an accounting within thirty (30) days of Covered Entity\u2019s request or such shorter time as may be required by applicable state or federal law. Such accounting must be provided without cost to the individual or to Covered Entity if it is the first accounting requested by an individual within any twelve (12) month period; however, a reasonable fee based on our labor costs in responding to a request for electronic information (or a cost-based fee for the production of non-electronic media copies) may be charged for subsequent accountings within the same twelve (12) month period so long as our Company informs Covered Entity and Covered Entity informs the individual in advance of the fee, and the individual is afforded an opportunity to withdraw or modify the request. Such accounting obligations shall survive termination of this Addendum and shall continue as long as our Company maintains PHI. We shall notify Covered Entity within five (5) business days of receipt of any request from an individual for an accounting of disclosures.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776207850{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question41&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Records.<\/strong> We shall make available to Secretary or its agents, our internal practices, books, and records relating to the use and disclosure of PHI accessed, created, or received by our Company on behalf of Covered Entity for the purpose of determining Covered Entity\u2019s compliance with the Confidentiality Requirements, such internal practices, books and records to be provided in the time and manner designated by Secretary and its agents. Except to the extent prohibited by law, our Company agrees to notify Covered Entity promptly upon receipt by our Company of any and all requests by or on behalf of any and all federal, state, and local government authorities served upon our Company for PHI subject to this Addendum.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776220866{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question42&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Effect of Termination of Agreement.<\/strong> Upon the termination of the Underlying Agreement or this Addendum for any reason, We shall return to Covered Entity, or, at Covered Entity\u2019s direction, destroy, all PHI received from Covered Entity that our Company maintains in any form, recorded on any medium, or stored in any storage system. If We elect to destroy the PHI, upon request We will certify in writing to Covered Entity that such PHI has been destroyed. This provision shall apply to PHI that is in the possession or control of our Company or any of our employees, agents or subcontractors. We shall retain no copies of the PHI. In the event that We determine that returning or destroying the PHI is infeasible, We shall extend the protections of this Addendum to such PHI and limit further use of the PHI to those purposes that make the return or destruction infeasible, for so long as We maintain such PHI. We shall remain bound by the provisions of this Addendum, even after termination of the Underlying Agreement or this Addendum until such time as all PHI has been returned, de-identified or otherwise destroyed as provided in this Section.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776235234{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question43&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Termination for Breach.<\/strong>\n<ol role=\"list\">\n<li>Either party may terminate this Addendum due to a pattern of activity or practice (rather than an isolated occurrence) constituting a material breach of this Addendum by the other party upon giving the other party thirty (30) days prior written notice; provided the breaching party does not cure the breach prior to the effective date of termination.<\/li>\n<li>In addition to any other rights Covered Entity or our Company may have under the Underlying Agreement, this Addendum or by operation of law or in equity, Covered Entity may terminate the Underlying Agreement if it terminates this Addendum pursuant to Section 10(a) above.<\/li>\n<li>Any dispute regarding any such alleged breach and\/or cure shall be resolved in accordance with the dispute resolution provisions of the Underlying Agreement, if any.<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776243858{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question44&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>No Third Party Rights.<\/strong> The terms of this Addendum are not intended, nor should they be construed, to grant any rights to any parties other than our Company and Covered Entity.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776252233{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question45&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Ownership of PHI.<\/strong> Under no circumstances shall our Company be deemed in any respect to be the owner of any PHI used or disclosed by or to our Company pursuant to the terms of the Underlying Agreement. Covered Entity shall retain all rights in the PHI not granted herein.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776266194{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question46&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Changes in the Law.<\/strong> The parties agree to enter into good faith negotiations to amend either the Underlying Agreement or this Addendum, as necessary and appropriate, to conform to any new or revised legislation, rules and regulations to which Covered Entity is subject now or in the future including, without limitation, HIPAA, HITECH, the Privacy Standards, Security Standards or Technical Standards.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776278530{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question47&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Judicial and Administrative Proceedings.<\/strong> In the event our Company receives a subpoena, court or administrative order or other discovery request or mandate for release of PHI, unless prohibited by applicable law We shall notify Covered Entity of the request as soon as reasonably practicable, but in any event within five (5) days of receipt of such request.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776290667{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question47&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Conflicts.<\/strong> If there is any direct conflict between the Underlying Agreement and this Addendum, the terms and conditions of this Addendum shall control.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776304795{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question49&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Definitions.<\/strong> For purposes of this Addendum, the following terms shall have the designated meanings. All other capitalized terms shall have the same meanings as in HIPAA or HITECH.\n<ol role=\"list\">\n<li>\u201c<strong>Administrative Safeguards<\/strong>\u201d shall mean administrative actions, policies and procedures to manage the selection, development, implementation and maintenance of security measures to protect Electronic PHI and to manage the conduct of our workforce in relation to the protection of that information, as contemplated by 45 C.F.R. \u00a7 164.308.<\/li>\n<li>\u201c<strong>Confidentiality Requirements<\/strong>\u201d means the Privacy Standards, Security Standards and HITECH, as applicable.<\/li>\n<li>\u201c<strong>De-Identified Data<\/strong>\u201d means Health Information that meets (i) the standard and implementation specifications for de-identification under the Privacy Standards such that it no longer identifies an individual and there is no reasonable basis to believe that the information can be used to identify an individual (as further contemplated by 45 C.F.R. \u00a7 164.514(a) \u2013 (c)) and (ii) is not Individually Identifiable Health Information.<\/li>\n<li>\u201c<strong>Designated Record Set<\/strong>\u201d shall mean Records maintained by or for Covered Entity, that are (i) the medical records and billing records about individuals maintained by or for Covered Entity, (ii) the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or (iii) used, in whole or in part, by Covered Entity to make decisions about individuals. As used herein, the term \u201cRecord\u201d means any item, collection, or grouping of information that includes PHI and is maintained, collected, used, or disseminated by or for Covered Entity.<\/li>\n<li>\u201c<strong>Electronic PHI<\/strong>\u201d shall mean PHI that is transmitted or maintained in electronic media.<\/li>\n<li>\u201c<strong>HIPAA<\/strong>\u201d shall mean the Health Insurance Portability and Accountability Act of 1996, and any amendments thereto.<\/li>\n<li>\u201c<strong>HIPAA Breach<\/strong>\u201d shall mean the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Standards which compromises the security or privacy of such information, as contemplated by 45 C.F.R. \u00a7 164.402.<\/li>\n<li>\u201c<strong>HITECH<\/strong>\u201d shall mean the Health Information Technology for Economic and Clinical Health Act, which is Title XIII of the American Recovery and Reinvestment Act, and any amendments, regulations, rules and guidance issued thereto and the relevant dates for compliance.<\/li>\n<li>\u201c<strong>Individually Identifiable Health Information<\/strong>\u201d shall mean information that is a subset of health information, including demographic information collected from an individual and genetic information, and (i) is created or received by a healthcare provider, health plan, employer, or healthcare clearinghouse; and (ii) relates to the past, present, or future physical or mental health or condition of an individual; the provision of healthcare to an individual; or the past, present, or future payment for the provision of healthcare to an individual; and (A) identifies the individual, or (B) with respect to which there is a reasonable basis to believe the information can be used to identify the individual.<\/li>\n<li>\u201c<strong>PHI<\/strong>\u201d shall mean Individually Identifiable Health Information that is (i) transmitted by electronic media; (ii) maintained in any medium constituting electronic media; or (iii) transmitted or maintained in any other form or medium. \u201cPHI\u201d shall not include education records covered by the Family Educational Right and Privacy Act, as amended, 20 U.S.C. \u00a7 1232g, or records described in 20 U.S.C. \u00a7 1232g(a)(4)(B)(iv). For purposes of this Addendum, all references to \u201cPHI\u201d shall refer to PHI received from, or created or received by our Company on behalf of, Covered Entity in connection with the Underlying Agreement.<\/li>\n<li>\u201c<strong>Physical Safeguards<\/strong>\u201d shall mean physical measures, policies and procedures to protect our electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion, as contemplated by 45 C.F.R. \u00a7 164.310.<\/li>\n<li>\u201c<strong>Privacy Standards<\/strong>\u201d shall mean the Standards for Privacy of Individually Identifiable Health Information, 45 C.F.R. Parts 160 and 164.<\/li>\n<li>\u201c<strong>Secretary<\/strong>\u201d shall mean the Secretary of the United States Department of Health and Human Services.<\/li>\n<li>\u201c<strong>Security Incident<\/strong>\u201d shall mean the attempted or successful unauthorized access, use, disclosure, modification or destruction of information or interference with system operations in an information system.<\/li>\n<li>\u201c<strong>Security Standards<\/strong>\u201d shall mean the regulations with regard to security standards for health information, 45 C.F.R. Parts 160 and 164.<\/li>\n<li>\u201c<strong>Technical Safeguards<\/strong>\u201d shall mean the technology, and the policy and procedures for its use, that protects Electronic PHI and controls access to it, as contemplated by 45 C.F.R. \u00a7 164.312.<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776319057{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question50&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Entire Agreement.<\/strong> This Agreement contains the entire agreement of the parties with respect to the subject matter hereof, and there are no representations, warranties, covenants or other agreements except as stated or referred to herein.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764421010137{margin-bottom: 0px !important;}&#8221;]<\/p>\n<ul role=\"list\">\n<li><strong>Obligations of Covered Entity.<\/strong><\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776329434{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question51&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Compliance with Applicable Law.<\/strong> Covered Entity shall comply with its obligations under this Addendum and with all obligations of a covered entity under HIPAA, HITECH, the Confidentiality Requirements and other related laws and any implementing regulations, as they exist at the time this Addendum is executed and as they are amended.<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text css=&#8221;.vc_custom_1764776341377{margin-bottom: 0px !important;}&#8221; el_id=&#8221;question52&#8243;]<\/p>\n<ul role=\"list\">\n<li><strong>Minimum Necessary.<\/strong> Covered Entity shall only request, use or disclose the minimum necessary PHI to accomplish its obligations under the Underlying Agreement or this Addendum.\n<ol role=\"list\">\n<li>Permissible Requests. Covered Entity shall not request that we use or disclose PHI in any manner that would not be permissible under the Privacy Standards if done by a Covered Entity.<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/3&#8243; el_class=&#8221;sticky_col&#8221;][vc_row_inner el_class=&#8221;left_box&#8221;][vc_column_inner][vc_custom_heading text=&#8221;Table of Content&#8221; font_container=&#8221;tag:h4|text_align:left&#8221; use_theme_fonts=&#8221;yes&#8221; css=&#8221;&#8221;][vc_column_text css=&#8221;&#8221; el_class=&#8221;scroll_selector scrollable&#8221;]<a class=\"active\" href=\"#question35\">Certain Definitions<\/a><\/p>\n<p><a href=\"#question36\">Compliance with Applicable Law<\/a><\/p>\n<p><a href=\"#question37\">Our Duties<\/a><\/p>\n<p><a href=\"#question38\">Breach Notification<\/a><\/p>\n<p><a href=\"#question39\">Designated Record Sets<\/a><\/p>\n<p><a href=\"#question40\">Accounting for Disclosures<\/a><\/p>\n<p><a href=\"#question41\">Records<\/a><\/p>\n<p><a href=\"#question42\">Effect of Termination of Agreement<\/a><\/p>\n<p><a href=\"#question43\">Termination for Breach.<\/a><\/p>\n<p><a href=\"#question44\">No Third Party Rights<\/a><\/p>\n<p><a href=\"#question45\">Ownership of PHI<\/a><\/p>\n<p><a href=\"#question46\">Changes in the Law<\/a><\/p>\n<p><a href=\"#question47\">Judicial and Administrative Proceedings<\/a><\/p>\n<p><a href=\"#question48\">Conflicts<\/a><\/p>\n<p><a href=\"#question49\">Definitions<\/a><\/p>\n<p><a href=\"#question50\">Entire Agreement<\/a><\/p>\n<p><a href=\"#question51\">Compliance with Applicable Law<\/a><\/p>\n<p><a href=\"#question52\">Minimum Necessary<\/a>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][\/vc_section][vc_row el_class=&#8221;business-agreement-cta&#8221;][vc_column][vc_column_text css=&#8221;.vc_custom_1764422126330{margin-bottom: 0px !important;}&#8221;][vc_section el_class=\"cta_banner_sec\"][vc_row][vc_column][vc_single_image image=\"95\" img_size=\"full\" css=\"\"][\/vc_column][\/vc_row][vc_row content_placement=\"middle\" el_class=\"cta_content\"][vc_column width=\"1\/2\" el_class=\"cta_content_col\"][vc_custom_heading text=\"Ready to Start Feeling More in Control?\" font_container=\"tag:h2|text_align:left|color:%23FFFFFF\" use_theme_fonts=\"yes\" css=\"\"][vc_custom_heading text=\"Join Healthy Mind Map today. Your first step toward understanding your mental health.\" font_container=\"tag:p|text_align:left|color:%23FFFFFF\" use_theme_fonts=\"yes\" css=\"\"][vc_btn title=\"App Store\" css_animation=\"fadeInUp\" css=\".vc_custom_1765461674036{background-image: url(https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2025\/11\/app-store.png?id=27) !important;}\" link=\"url:https%3A%2F%2Fapps.apple.com%2Fus%2Fapp%2Fhealthy-mind-map-wellness-app%2Fid6737412082|target:_blank\" el_class=\"app_store_btn margin_right_12\"][vc_btn title=\"Google Play\" css_animation=\"fadeInUp\" css=\".vc_custom_1765461691091{background-image: url(https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2025\/11\/google_play.png?id=28) !important;}\" link=\"url:https%3A%2F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3Fid%3Dcom.healthymindmap.mobile%26pcampaignid%3Dweb_share|target:_blank\" el_class=\"google_play_btn\"][\/vc_column][vc_column width=\"1\/2\"][vc_single_image image=\"96\" img_size=\"full\" alignment=\"center\" css=\"\"][\/vc_column][\/vc_row][\/vc_section][\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_section full_width=&#8221;stretch_row&#8221; el_class=&#8221;blogs-banner features-top-banner privacy-services-page&#8221;][vc_row full_width=&#8221;stretch_row_content_no_spaces&#8221; el_class=&#8221;blogs-banner-img&#8221;][vc_column][vc_single_image image=&#8221;29&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; css=&#8221;.vc_custom_1764067714666{margin-bottom: 0px !important;}&#8221;][\/vc_column][\/vc_row][vc_row equal_height=&#8221;yes&#8221; content_placement=&#8221;middle&#8221; el_class=&#8221;blogs-banner-content privacy_hero_banner&#8221;][vc_column width=&#8221;8\/12&#8243;][vc_custom_heading text=&#8221;Business Associate Agreement &#8211; Healthy Mind Map&#8221; font_container=&#8221;tag:h1|text_align:left|color:%23000000&#8243; use_theme_fonts=&#8221;yes&#8221; css=&#8221;.vc_custom_1773346558052{margin-bottom: 0px !important;}&#8221;][vc_custom_heading text=&#8221;Please read the Business Associate Agreement carefully.&#8221; font_container=&#8221;tag:p|text_align:left|color:%23000000&#8243; use_theme_fonts=&#8221;yes&#8221; css_animation=&#8221;none&#8221; css=&#8221;&#8221;][vc_btn title=&#8221;App Store&#8221; css=&#8221;.vc_custom_1765462030104{background-image: url(https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2025\/11\/Store-download-button.png?id=112) !important;}&#8221; link=&#8221;url:https%3A%2F%2Fapps.apple.com%2Fus%2Fapp%2Fhealthy-mind-map-wellness-app%2Fid6737412082|target:_blank&#8221;][vc_btn title=&#8221;Goolge Play&#8221; css=&#8221;.vc_custom_1765462041513{background-image: url(https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2025\/11\/Store-download-button-1.png?id=113) !important;}&#8221; link=&#8221;url:https%3A%2F%2Fplay.google.com%2Fstore%2Fapps%2Fdetails%3Fid%3Dcom.healthymindmap.mobile%26pcampaignid%3Dweb_share|target:_blank&#8221;][\/vc_column][vc_column width=&#8221;4\/12&#8243;][\/vc_column][\/vc_row][\/vc_section][vc_section el_class=&#8221;content_sec [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-407","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Advanced Therapy Solutions &amp; Compliance Standards<\/title>\n<meta name=\"description\" content=\"Review compliance details supporting advanced therapy solutions for providers. Build trust, stay secure, and download the app to enhance care.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Advanced Therapy Solutions &amp; Compliance Standards\" \/>\n<meta property=\"og:description\" content=\"Review compliance details supporting advanced therapy solutions for providers. Build trust, stay secure, and download the app to enhance care.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/\" \/>\n<meta property=\"og:site_name\" content=\"Healthy Mind Map\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Healthy-Mind-Map\/61558319261421\/\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-12T20:15:59+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"17 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Advanced Therapy Solutions & Compliance Standards","description":"Review compliance details supporting advanced therapy solutions for providers. Build trust, stay secure, and download the app to enhance care.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/","og_locale":"en_US","og_type":"article","og_title":"Advanced Therapy Solutions & Compliance Standards","og_description":"Review compliance details supporting advanced therapy solutions for providers. Build trust, stay secure, and download the app to enhance care.","og_url":"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/","og_site_name":"Healthy Mind Map","article_publisher":"https:\/\/www.facebook.com\/people\/Healthy-Mind-Map\/61558319261421\/","article_modified_time":"2026-03-12T20:15:59+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/","url":"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/","name":"Advanced Therapy Solutions & Compliance Standards","isPartOf":{"@id":"https:\/\/healthymind.agencypartnerinteractive.com\/#website"},"datePublished":"2025-11-29T12:14:37+00:00","dateModified":"2026-03-12T20:15:59+00:00","description":"Review compliance details supporting advanced therapy solutions for providers. Build trust, stay secure, and download the app to enhance care.","breadcrumb":{"@id":"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/healthymind.agencypartnerinteractive.com\/business-associate-agreement\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/healthymind.agencypartnerinteractive.com\/"},{"@type":"ListItem","position":2,"name":"Business Associate Agreement"}]},{"@type":"WebSite","@id":"https:\/\/healthymind.agencypartnerinteractive.com\/#website","url":"https:\/\/healthymind.agencypartnerinteractive.com\/","name":"Healthy Mind Map","description":"Calculating Infinity","publisher":{"@id":"https:\/\/healthymind.agencypartnerinteractive.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/healthymind.agencypartnerinteractive.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/healthymind.agencypartnerinteractive.com\/#organization","name":"Healthy Mind Map","url":"https:\/\/healthymind.agencypartnerinteractive.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/healthymind.agencypartnerinteractive.com\/#\/schema\/logo\/image\/","url":"https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2026\/02\/image-1-3.png","contentUrl":"https:\/\/healthymind.agencypartnerinteractive.com\/wp-content\/uploads\/2026\/02\/image-1-3.png","width":434,"height":110,"caption":"Healthy Mind Map"},"image":{"@id":"https:\/\/healthymind.agencypartnerinteractive.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Healthy-Mind-Map\/61558319261421\/"]}]}},"_links":{"self":[{"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=\/wp\/v2\/pages\/407","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=407"}],"version-history":[{"count":24,"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=\/wp\/v2\/pages\/407\/revisions"}],"predecessor-version":[{"id":742,"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=\/wp\/v2\/pages\/407\/revisions\/742"}],"wp:attachment":[{"href":"https:\/\/healthymind.agencypartnerinteractive.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=407"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}