Effective September 24, 2026
This Business Associate Agreement (“BAA”) is between Life Systems Software Inc., 2603 Camino Ramon, Suite 200, San Ramon, CA 94583 (“Business Associate”, “we”, “us”), and the practice that subscribes to ChiroPad (“Covered Entity”, “you”). It is signed electronically during onboarding and forms part of the ChiroPad Terms of Service (the “Services Agreement”).
It sets out how we protect the protected health information we create, receive, maintain, or transmit for you in providing ChiroPad. It is intended to satisfy the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 C.F.R. Parts 160 and 164 (“HIPAA”), as amended by the HITECH Act and the 2013 Omnibus Rule.
1. Definitions
Capitalized terms used but not defined here have the meaning HIPAA gives them, including Breach, Data Aggregation, Designated Record Set, Individual, Required by Law, Secretary, Security Incident, Subcontractor, and Unsecured Protected Health Information. “PHI” means protected health information, in any form, that we create, receive, maintain, or transmit on your behalf. It includes electronic PHI. A reference to a HIPAA section means that section as amended from time to time.
2. Permitted uses and disclosures
2.1 We may use and disclose PHI only:
- to provide ChiroPad and related support to you under the Services Agreement;
- for our proper management and administration, or to carry out our legal responsibilities, as permitted by 45 C.F.R. § 164.504(e)(4). Disclosures for these purposes must be Required by Law, or made to a recipient that gives us reasonable assurance it will keep the PHI confidential, use or disclose it only as Required by Law or for the purpose it was disclosed, and tell us of any breach of its confidentiality;
- to provide Data Aggregation services relating to your health care operations, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B);
- to report violations of law to federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1); and
- as otherwise Required by Law.
2.2 We will not use or disclose PHI in any way that would violate HIPAA if you did it. We will limit each use, disclosure, and request to the minimum necessary, following the Secretary’s guidance. We will not sell PHI or use it for marketing.
2.3 We have no ownership rights in PHI.
3. Our obligations
3.1 Safeguards. We will comply with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). We will maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI. The ChiroPad production environment runs on Microsoft Azure in the United States. PHI is encrypted in transit and at rest, and is not stored outside the United States.
3.2 Subcontractors. We use Subcontractors to provide ChiroPad, including Microsoft Azure for hosting. The current list is published on the Security page. Under 45 C.F.R. §§ 164.308(b)(2) and 164.502(e)(1)(ii), we will make sure that every Subcontractor that creates, receives, maintains, or transmits PHI for us first agrees in writing to the same restrictions, conditions, and requirements that apply to us under this BAA. We will give you at least 30 days’ notice before adding a new Subcontractor that handles PHI. If you object on reasonable grounds and we cannot resolve the objection, you may terminate the Services Agreement without penalty.
3.3 Reporting. We will report to you in writing:
- any use or disclosure of PHI not permitted by this BAA, including any Breach of Unsecured PHI; and
- any Security Incident of which we become aware,
without unreasonable delay, and no later than five business days after discovery. For a Breach of Unsecured PHI, our report will identify each Individual affected, so far as we can identify them, and will include the information you need to notify them under 45 C.F.R. § 164.410. We will supplement the report as more information becomes available. In no case will we notify you later than 60 calendar days after discovery.
This BAA serves as notice of the ongoing, unsuccessful attempts that do not lead to unauthorized access, use, or disclosure of PHI, such as pings, port scans, and blocked sign-in attempts. We do not need to report these individually.
3.4 Mitigation. We will take prompt action to mitigate, as far as practicable, any harmful effect of a use or disclosure of PHI by us or our Subcontractors that violates this BAA. We will also correct the deficiency that caused it.
3.5 Individual rights. For PHI in a Designated Record Set that we maintain, we will:
- make it available to you within 10 days of your request, so you can meet an Individual’s right of access under 45 C.F.R. § 164.524, including in electronic form;
- make amendments you direct within 10 days of your request, under 45 C.F.R. § 164.526; and
- document our disclosures and provide the information you need for an accounting of disclosures within 10 days of your request, under 45 C.F.R. § 164.528.
We keep that documentation for six years. In practice, ChiroPad lets you view, export, and amend patient records yourself. If an Individual contacts us directly with any of these requests, we will forward it to you within five business days.
3.6 Access by the Secretary. We will make our internal practices, books, and records relating to PHI available to the Secretary for the purpose of determining your compliance with HIPAA. Unless the law prohibits it, we will tell you when we do.
3.7 Your obligations we carry out. Where we carry out one of your obligations under the HIPAA Privacy Rule, we will comply with the requirements of the Privacy Rule that apply to you in carrying it out.
3.8 Training. We train our workforce on HIPAA privacy and security when they join and at least once a year after that.
3.9 Compliance review. On reasonable written request, and no more than once a year unless there has been a Breach, we will answer your security questionnaire. We will also provide evidence of our safeguards and of our hosting provider’s independent audit reports, such as Microsoft’s SOC 2 reports for Azure. Any other review will be at a mutually agreed scope, time, and place, and you will keep confidential any non-public information you see.
4. Your obligations
4.1 You will tell us about any limitation in your notice of privacy practices, any restriction you agree to under 45 C.F.R. § 164.522, and any change to or revocation of an Individual’s permission, to the extent it affects what we may do with PHI.
4.2 You will obtain any consents and authorizations the law requires for the uses and disclosures you direct us to make.
4.3 You will not ask us to use or disclose PHI in any way that would violate HIPAA if you did it.
4.4 You are responsible for managing your users’ access to ChiroPad, including removing access for staff who leave.
5. Term and termination
5.1 Term. This BAA takes effect when your ChiroPad subscription starts. It continues until the Services Agreement ends and we have returned or destroyed all PHI under section 5.4.
5.2 Termination for breach. If either party knows of a pattern of activity or practice of the other that is a material breach of this BAA, it will give the other 30 days to cure the breach. If the breach is not cured, it may terminate this BAA and the Services Agreement. If a cure is not possible, it may terminate immediately.
5.3 Termination for violation. You may terminate this BAA and the Services Agreement immediately if we are named as a defendant in a criminal proceeding for a violation of HIPAA, or if a final finding in an administrative or civil proceeding establishes that we violated HIPAA.
5.4 Return or destruction of PHI. For 30 days after the Services Agreement ends, you may export your data or ask us to provide a copy. After that, we will destroy all PHI we and our Subcontractors hold and keep no copies. Backup copies are destroyed as our backup rotation expires them, no later than 90 days after that, and stay protected under this BAA until then. On request, we will confirm the destruction in writing. If returning or destroying any PHI is not feasible, we will tell you why. We will keep protecting that PHI under this BAA, and limit further use and disclosure to the purposes that make return or destruction infeasible, for as long as we hold it.
5.5 Survival. Our obligations under sections 3.3, 3.4, and 5.4, and any other provision that by its nature should survive, survive termination for as long as we hold PHI.
6. General
6.1 Indemnity.
(a) What we cover. We will defend, indemnify, and hold harmless you and your owners, officers, employees, and agents against Losses that arise from:
- our breach of this BAA or of HIPAA;
- a Breach of Unsecured PHI, or a Security Incident that compromises PHI, caused by us or by one of our Subcontractors; or
- any other use or disclosure of PHI by us or our Subcontractors that this BAA does not permit.
For this purpose, we are responsible for our Subcontractors, including our hosting provider, as if their acts and omissions were our own.
(b) Losses. “Losses” means:
- amounts paid to third parties under a judgment or a settlement we approve;
- civil money penalties, fines, and amounts paid under a resolution agreement imposed by the Secretary, a state attorney general, or another regulator;
- the reasonable costs of investigating a Breach and of notifying affected Individuals, the Secretary, and the media where HIPAA or state law requires it;
- the reasonable costs of a call center and of credit monitoring and identity-protection services for affected Individuals, where such services are required by law or customary for the type of Breach; and
- reasonable attorneys’ fees and costs.
(c) Where we are not responsible. We are not responsible for Losses to the extent they result from:
- your own breach of this BAA or of HIPAA;
- the negligence or misconduct of you or your workforce, including sharing or failing to protect login credentials, or failing to remove access for staff who leave; or
- a use or disclosure of PHI that you directed us to make.
Where both parties contributed to a Loss, each is responsible for its share.
(d) Procedure. You will notify us promptly in writing of any claim or regulatory inquiry for which you seek indemnity. A delay relieves us of our obligation only to the extent it prejudices our defense. We will control the defense and settlement using counsel reasonably acceptable to you, and you will cooperate at our expense. You may take part with your own counsel at your own cost. We will not settle a claim in a way that admits fault on your behalf, or imposes any obligation on you other than payment, without your written consent. You will not unreasonably withhold that consent.
(e) Cap. Our total liability under this BAA, including this section, and under the Services Agreement combined is limited to the fees you paid us under the Services Agreement in the twelve months before the event giving rise to the claim. This is a single aggregate cap shared with the Services Agreement, not an additional one. The exclusion of indirect and consequential damages in the Services Agreement does not apply to the Losses listed in (b). This section survives termination.
(f) Injunctive relief. We acknowledge that an unauthorized use or disclosure of PHI by us could cause you irreparable harm, and that you may seek injunctive relief in addition to any other remedy.
6.2 Amendment. The parties will amend this BAA as necessary to comply with changes in HIPAA or other applicable law. If a change in law requires an amendment, we will send you the amendment on 30 days’ notice, and it takes effect when that notice period ends. Any other amendment must be in writing and agreed by both parties.
6.3 Other laws. Where a state privacy or security law is more protective of Individuals than HIPAA and applies to us, we will comply with it too.
6.4 Interpretation. Any ambiguity in this BAA will be resolved in favor of a meaning that complies with HIPAA. If this BAA and the Services Agreement conflict on anything to do with PHI, this BAA controls. Our liability under this BAA is limited by the combined cap in section 6.1(e).
6.5 Relationship and third parties. The parties are independent contractors. Nothing in this BAA gives any right or remedy to anyone other than the parties and their permitted successors.
6.6 Notices. Notices under this BAA must be in writing. Send notices to us at support@LifeSystemsSoftware.com, or by mail to Life Systems Software Inc., 2603 Camino Ramon, Suite 200, San Ramon, CA 94583. We will send notices to the email address and practice address on your account. Email notices take effect when sent, and mailed notices three business days after mailing.
6.7 Severability and waiver. If any provision of this BAA is found unenforceable, the rest remains in effect. Not enforcing a right does not waive it.
Questions
To request a signed copy of this BAA, or with questions about it, email support@LifeSystemsSoftware.com or call 973.625.3716.