WeLiveOn Health, Inc. ("WeLiveOn") and you, the healthcare provider ("Covered Entity"), enter into this Business Associate Agreement ("BAA") in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH).
1. Permitted Uses. WeLiveOn may use and disclose Protected Health Information (PHI) only as necessary to provide remote patient monitoring services, generate billing reports, and support clinical care coordination on your behalf.
2. Safeguards. WeLiveOn agrees to implement appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI. This includes encryption in transit and at rest, audit logging, and access controls.
3. Breach Notification. WeLiveOn will notify you of any breach of unsecured PHI without unreasonable delay and no later than 60 calendar days of discovery of the breach.
4. Subcontractors. WeLiveOn will ensure that any subcontractors who create, receive, maintain, or transmit PHI on its behalf agree to the same restrictions and conditions.
5. Minimum Necessary. WeLiveOn will make reasonable efforts to use, disclose, and request only the minimum amount of PHI necessary to accomplish the intended purpose.
6. Patient Rights. WeLiveOn will accommodate reasonable requests for access, amendment, and accounting of disclosures of PHI as required by HIPAA.
7. Termination. Either party may terminate this agreement immediately if the other party materially breaches a provision of this BAA and fails to cure within 30 days of written notice.
By accepting, you confirm that you are authorized to bind your organization to this agreement, and that your use of WeLiveOn complies with all applicable federal and state laws governing protected health information.