Business Associate Agreement
Effective Date: 28 September, 2025
Last Updated: July 29, 2025
This Business Associate Agreement (“BAA”) is entered into by and between Easy VOB LLC, a California limited liability company (“Business Associate”), and the customer or client accepting this agreement via electronic acknowledgment or by using the Humbear tool Easy VOB insurance verification service (“Covered Entity”). Each party may be referred to individually as a “Party” and collectively as the “Parties.”
RECITALS
WHEREAS, Business Associate provides technology and services, including but not limited to, insurance verification, benefit discovery, and patient data processing, on behalf of Covered Entity;
WHEREAS, Covered Entity may disclose or permit access to Protected Health Information (PHI) to Business Associate pursuant to HIPAA and HITECH regulations;
WHEREAS, both Parties desire to ensure compliance with HIPAA and all applicable rules, including 45 C.F.R. Parts 160 and 164, and, where applicable, 42 C.F.R. Part 2;
NOW, THEREFORE, the Parties agree as follows:
1. DEFINITIONS
- Business Associate: As defined by 45 CFR § 160.103, refers to Easy VOB LLC.
- Covered Entity: A healthcare provider, billing service, treatment center, or entity that discloses PHI to Easy VOB LLC.
- PHI: Protected Health Information as defined under HIPAA.
- All other capitalized terms shall have the same meaning as those in the HIPAA Rules and HITECH.
2. SCOPE & PURPOSE
This BAA governs Business Associate’s Use and Disclosure of PHI received from or on behalf of Covered Entity as required for the performance of the insurance verification and related services provided by Easy VOB LLC.
3. OBLIGATIONS OF BUSINESS ASSOCIATE
Business Associate agrees to:
- Use and disclose PHI only as permitted by this BAA or Required by Law.
- Use appropriate administrative, technical, and physical safeguards to protect the confidentiality, integrity, and availability of PHI.
- Mitigate any harmful effects of a known unauthorized use or disclosure.
- Report to Covered Entity any security incident or breach involving PHI within ten (10) business days of discovery.
- Ensure subcontractors or agents agree in writing to the same restrictions and conditions.
- Make PHI available for access, amendment, or accounting as required by 45 C.F.R. §§ 164.524, 164.526, and 164.528.
- Comply with the minimum necessary standard as defined under HIPAA.
4. PERMITTED USES & DISCLOSURES
Business Associate may:
- Use PHI to provide insurance verification and billing services to or on behalf of the Covered Entity.
- Disclose PHI to subcontractors solely to perform such services, subject to equivalent safeguards.
- Create de-identified data or limited data sets for internal analytics, product improvements, and legal compliance.
- Use PHI for proper management, legal obligations, and data aggregation purposes in compliance with 45 C.F.R. § 164.504(e)(2)(i)(B).
5. OBLIGATIONS OF COVERED ENTITY
Covered Entity agrees to:
- Notify Business Associate of any limitations, revocations, or changes to permissions regarding PHI.
- Not request Business Associate to use or disclose PHI in a way that would violate HIPAA.
- Obtain all necessary consents and authorizations required under HIPAA prior to disclosing PHI to Business Associate.
6. TERM & TERMINATION
- Term: This BAA is effective upon execution and remains in effect until terminated by either Party.
- Termination for Cause: Either Party may terminate this BAA upon knowledge of a material breach by the other Party.
- Effect of Termination: Upon termination, Business Associate shall return or destroy all PHI or, if not feasible, continue to protect the PHI per this BAA.
7. 42 C.F.R. PART 2 COMPLIANCE (If Applicable)
If Covered Entity is subject to 42 C.F.R. Part 2 (substance use disorder treatment data):
- Business Associate shall comply with all related privacy regulations;
- Business Associate shall resist disclosure of such data unless authorized by law or court order.
8. MISCELLANEOUS
- No Ownership Rights: PHI remains the property of Covered Entity.
- Amendments: This BAA may be amended in writing by mutual agreement.
- Governing Law: Governed by the laws of the State of California.
- Entire Agreement: This BAA supersedes any prior agreements related to PHI sharing between the Parties.
- Survival: All terms related to PHI protection survive termination.
- Notice: Notices will be sent to the address on file with Business Associate or:
Easy VOB LLC
Attn: Legal Compliance
7400 Center Avenue, Huntington Beach, CA, 92647
Support@easyvob.com
9. AUTHORIZATION
By executing or electronically accepting this Agreement, the Parties acknowledge that they have read and understood this BAA and agree to be legally bound.