Business Associate Agreement
Our standard HIPAA BAA, published so you can read it before you talk to us rather than after.
Last updated 2 August 2026
Why this exists
In short: Your agency is a covered entity. We handle PHI for you, which makes us your business associate, and HIPAA requires a written agreement.
The moment you record a client's name against a care visit, you are handling protected health information. Insync Agency LLC, trading as CareVerify, processes that information on your behalf, which makes us your business associate under the HIPAA Privacy and Security Rules.
We publish this template rather than hiding it behind a sales call. Read it, send it to your attorney, and tell us what needs changing. To execute it, email legal@getcareverify.com.
Defined terms used here, including Protected Health Information, Breach, Required By Law and Security Incident, carry the meanings given in 45 CFR Parts 160 and 164.
1. Permitted uses and disclosures
In short: We use PHI only to run the service for you, and for nothing else.
We may use or disclose PHI only:
- To provide, maintain and support the service as described in our terms of service and as you direct
- For the proper management and administration of our business
- To carry out our legal responsibilities, or where Required By Law
- For data aggregation services relating to your health care operations, where you ask for them
We will not use or disclose PHI in any way you could not yourself under the Privacy Rule, except as permitted for our own management and administration or as Required By Law. We will not sell PHI, use it for marketing, or use it to train machine learning models.
Where we disclose PHI to a third party for our own management and administration, we will obtain reasonable assurances that it remains confidential and that the recipient notifies us of any breach.
2. Minimum necessary
In short: We limit ourselves to the minimum PHI needed to do the job.
We will make reasonable efforts to use, disclose and request only the minimum necessary PHI to accomplish the purpose in question. Staff access is role-restricted, and access to a customer environment for support is limited to those who need it.
3. Safeguards
In short: Encryption in transit and at rest, database-level tenant isolation, role-based access, session timeouts and a full audit log.
We will use appropriate administrative, physical and technical safeguards, and comply with the Security Rule with respect to electronic PHI. In concrete terms that includes:
- Encryption of PHI in transit and at rest
- Tenant isolation enforced at the database layer through row level security, not in application code
- Role-based access control and automatic session timeouts
- An audit log of every read and write to a client record, retained for 6 years
- Exclusion of PHI from error reports, analytics events, log lines and push notification bodies by design
Our security page describes these in more detail.
4. Subcontractors
In short: Every subcontractor that touches PHI is bound by terms at least as strict as these, and the list is public.
We will ensure that any subcontractor that creates, receives, maintains or transmits PHI on our behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to us under this agreement.
Our current subcontractors, what each does and whether it touches PHI, are published at getcareverify.com/legal/subprocessors. We will give you at least 30 days' notice before adding a new subcontractor that will handle PHI, and you may object.
5. Reporting and breach notification
In short: We tell you about a suspected breach without unreasonable delay and no later than 5 business days after we discover it.
We will report to you any use or disclosure of PHI not permitted by this agreement, any Security Incident, and any Breach of Unsecured PHI, of which we become aware.
For a Breach of Unsecured PHI, we will notify you without unreasonable delay and in no case later than 5 business days after discovery. That is deliberately shorter than the 60 days HIPAA allows, because you need time to meet your own notification duties.
Our notification will include, to the extent known at the time:
- What happened and when we discovered it
- The individuals affected and the types of PHI involved, so far as we can identify them
- What we have done to investigate, contain and remediate
- Contact details for follow-up questions
We will supplement that information as our investigation continues, rather than waiting until we have a complete picture.
Unsuccessful Security Incidents that do not result in unauthorized access, such as routine port scans and blocked login attempts, are reported on request rather than individually.
To report a suspected security issue to us, email security@getcareverify.com.
6. Individual rights
In short: We help you answer access, amendment and accounting requests from your clients.
Because we hold PHI in a designated record set on your behalf, we will:
- Make PHI available to you so you can meet an individual's right of access under 45 CFR 164.524, within 10 business days of your request
- Make PHI available for amendment and incorporate amendments you direct, under 45 CFR 164.526
- Provide the information you need to give an accounting of disclosures under 45 CFR 164.528
- Make our internal practices, books and records relating to PHI available to the Secretary of Health and Human Services for determining compliance
Requests that come to us directly from an individual will be referred to you rather than answered by us.
7. Term and termination
In short: It runs as long as we hold your PHI. You can terminate for a breach we fail to cure.
This agreement takes effect when you begin using the service and continues until all PHI is returned or destroyed.
You may terminate it if we materially breach it and fail to cure within 30 days of written notice, or immediately if cure is not possible.
8. Return or destruction of PHI
In short: On termination you export everything, then we delete it.
On termination we will return or destroy all PHI we hold, including PHI held by subcontractors, and retain no copies, to the extent feasible.
You will have an export window to retrieve your records before deletion, set out in our data retention policy. Where return or destruction is not feasible, we will extend the protections of this agreement to that PHI and limit further uses and disclosures to the reasons that make return or destruction infeasible.
Audit log records are retained for 6 years as HIPAA requires, and remain protected under this agreement for that period.
9. Miscellaneous
In short: The BAA wins over the general terms wherever PHI is concerned.
Where this agreement conflicts with our terms of service on the handling of PHI, this agreement controls. Both parties will amend it as necessary to comply with changes to HIPAA or the HITECH Act.
ATTORNEY REVIEW: indemnities, insurance requirements, allocation of breach notification costs and the interaction with the liability cap in the terms of service are not addressed above and need deciding with counsel.
How to execute
In short: Email legal@getcareverify.com and we will send a signable copy.
Email legal@getcareverify.com with your agency's legal name and we will send a copy for signature. We do not charge for a BAA and we do not restrict it to larger plans.
Other policies: Privacy, Terms, BAA, Subprocessors, Data retention, Cookies, Acceptable use, Accessibility, Refunds
