# Helo Echo Business Associate Agreement **Effective date:** The date of the last signature below This Business Associate Agreement (the **“BAA”**) is between the healthcare provider or practice identified in the signature block (**“Covered Entity”**) and the person or entity identified as the Helo Echo service provider in the signature block (**“Business Associate”**). It supplements the agreement under which Business Associate provides Helo Echo to Covered Entity (the **“Service Agreement”**). If this BAA conflicts with the Service Agreement regarding Protected Health Information, this BAA controls. ## 1. Definitions Capitalized terms not defined here have the meanings given in the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164 (the **“HIPAA Rules”**), including *Breach*, *Designated Record Set*, *Electronic Protected Health Information*, *Individual*, *Protected Health Information* (**“PHI”**), *Required by Law*, *Secretary*, *Security Incident*, *Subcontractor*, *Unsecured Protected Health Information*, *Use*, and *Disclosure*. ## 2. Scope and permitted uses Business Associate may Use or Disclose PHI only: 1. to provide, secure, support, maintain, back up, and improve the reliability of Helo Echo for Covered Entity, including authorized clinical documentation, client collaboration, forms, bilateral-stimulation tools, transcription, export, and recovery functions; 2. as directed in writing by Covered Entity, provided the direction is permitted by the HIPAA Rules; 3. for Business Associate’s proper management and administration or to carry out its legal responsibilities, if permitted by 45 C.F.R. § 164.504(e)(4); or 4. as Required by Law. Business Associate will not sell PHI, use PHI for advertising, or use PHI to train a general-purpose artificial-intelligence model. Business Associate will limit Uses, Disclosures, and requests for PHI to the minimum necessary, when that standard applies. Business Associate will not Use or Disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except for a Use or Disclosure expressly permitted by this BAA. ## 3. Business Associate duties Business Associate will: 1. comply with the applicable requirements of the HIPAA Security Rule for Electronic PHI and maintain reasonable administrative, physical, and technical safeguards; 2. mitigate, to the extent practicable, harmful effects known to it from an impermissible Use or Disclosure; 3. report to Covered Entity any impermissible Use or Disclosure, successful unauthorized access to PHI, or Breach of Unsecured PHI without unreasonable delay and no later than **10 calendar days after discovery**; 4. include in a Breach report, to the extent known, the identities of affected Individuals, the nature of the PHI involved, what occurred, mitigation taken, and other information reasonably needed for Covered Entity’s notices; Business Associate may supplement the report as facts develop; 5. report Security Incidents without unreasonable delay; routine unsuccessful attempts such as blocked scans, pings, or failed logins are reported through aggregate security information or on reasonable request unless they materially affect PHI; 6. ensure each Subcontractor that creates, receives, maintains, or transmits PHI for Business Associate agrees in writing to substantially the same restrictions and safeguards; 7. make PHI in a Designated Record Set available to Covered Entity in the form maintained by Helo Echo within **10 business days** of a written request so Covered Entity can meet 45 C.F.R. § 164.524; 8. incorporate an amendment or make PHI available for amendment within **10 business days** of a written request under 45 C.F.R. § 164.526; 9. document Disclosures required for an accounting and provide available accounting information within **20 business days** of a written request under 45 C.F.R. § 164.528; 10. if performing a Covered Entity obligation under the Privacy Rule, comply with the requirements that apply to that obligation; and 11. make its relevant internal practices, books, and records available to the Secretary for determining Covered Entity’s HIPAA compliance. Covered Entity remains responsible for responding to Individuals unless the parties expressly agree otherwise in writing. ## 4. Covered Entity duties Covered Entity will: 1. use Helo Echo only through authorized users and apply appropriate role, device, workforce, and access controls; 2. provide only the PHI reasonably necessary for the services and not direct Business Associate to violate the HIPAA Rules; 3. notify Business Associate of a relevant limitation in its Notice of Privacy Practices, change or revocation of an Individual’s permission, or agreed restriction that affects Business Associate’s handling of PHI; 4. maintain its own legal record-retention policy, client notices, authorizations, risk analysis, contingency plan, and procedures for access, amendment, accounting, and breach response; and 5. promptly notify Business Associate of suspected unauthorized account access or compromised credentials. ## 5. Data return, deletion, and retention The Helo Echo Data Retention Schedule, incorporated into this BAA, governs ordinary retention and destruction. Each covered document is automatically and permanently destroyed from active storage when its configured period after creation expires, regardless of whether the associated account is active, archived, deleted, or unlinked. Business Associate will attempt an advance email notice approximately 30 days before destruction to the available client portal and Covered Entity account addresses, but failed or unread notice does not extend retention. A valid legal or preservation hold is the sole exception. Covered Entity is responsible for selecting a period that satisfies its state, profession, payer, contract, program, and litigation requirements; maintaining current email addresses; exporting any copy it must retain; and notifying Business Associate of a required hold before destruction. On termination, Covered Entity may export its available PHI before account closure. Business Associate will then return or destroy PHI it maintains, if feasible, and direct its applicable Subcontractors to do the same. PHI remaining in protected backup rotation will not be restored except for disaster recovery and will be deleted as the rotation expires. If return or destruction is infeasible, Business Associate will continue to protect the retained PHI and limit further Uses and Disclosures to the reason return or destruction is infeasible. ## 6. Term and termination This BAA begins on its Effective Date and continues while Business Associate creates, receives, maintains, or transmits PHI for Covered Entity. Covered Entity may terminate the Service Agreement and this BAA for Business Associate’s material breach if Business Associate does not cure the breach within 30 days after written notice, or sooner if cure is not possible. Obligations concerning retained PHI survive termination. ## 7. General terms The parties will interpret this BAA to permit compliance with the HIPAA Rules and amend it as necessary to comply with changes in applicable law. A waiver must be in writing and applies only to the specific instance. If a provision is unenforceable, the remainder remains effective. Notices under this BAA must be sent to the contacts below; security notices to Business Associate must also be sent to **info@heloecho.com**. Electronic signatures and counterparts are permitted. This BAA does not make either party the agent of the other. ## Signatures **Covered Entity legal name:** __________________________________________ Address: ______________________________________________________________ By / title: ____________________________________________________________ Email for privacy and security notices: _________________________________ Signature: __________________________________ Date: ___________________ **Business Associate legal name (the operator of Helo Echo):** ___________ Business form and jurisdiction (for example, individual/LLC and state): ___ Address: ______________________________________________________________ By / title: ____________________________________________________________ Email for privacy and security notices: **info@heloecho.com** Signature: __________________________________ Date: ___________________