Business Associate Agreement
Effective January 1, 2026
This Business Associate Agreement ("BAA") is incorporated into the agreement between Vitalink Health, Inc. ("Business Associate") and each healthcare organization, practice, or independent clinician that uses the Vitalink platform as a "Covered Entity" under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the HITECH Act (collectively, "HIPAA"). It governs Vitalink's creation, receipt, maintenance, or transmission of Protected Health Information ("PHI") on behalf of Covered Entities using the Platform.
1. Permitted Uses and Disclosures of PHI
Vitalink may use or disclose PHI only as necessary to perform the scheduling, telehealth, documentation, e-prescribing, billing, and support functions of the Platform on behalf of the Covered Entity, as permitted by this BAA and the underlying services agreement, or as required by law. Vitalink Health will not use or disclose PHI for any purpose other than as permitted here, including marketing or sale of PHI, without the Covered Entity's prior written authorization.
2. Safeguards
Vitalink will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI, consistent with the HIPAA Security Rule, including:
- Encryption of PHI at rest and in transit.
- Role-based access control and unique user authentication for all workforce members.
- Audit logging of access to and modification of PHI.
- Automatic session timeout and account lockout policies.
- Annual security risk assessments and a documented incident response plan.
3. Subcontractors
Vitalink will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on Vitalink's behalf (e.g., cloud infrastructure, e-prescribing, or payment processing vendors) agrees in writing to restrictions and conditions at least as protective as those in this BAA.
4. Reporting of Breaches and Security Incidents
Vitalink will report to the Covered Entity any use or disclosure of PHI not permitted by this BAA, and any Breach of Unsecured PHI, without unreasonable delay and in no case later than sixty (60) days after discovery, as required by the HITECH Breach Notification Rule. Vitalink will also report security incidents affecting PHI on a periodic basis or upon request.
5. Individual Rights
Vitalink will make PHI available to the Covered Entity as necessary to satisfy the Covered Entity's obligations to provide individuals with access to, amendment of, and an accounting of disclosures of their PHI under 45 CFR §§ 164.524, 164.526, and 164.528.
6. Minimum Necessary
Vitalink will request, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose, consistent with the Platform's role-based access model, which restricts each user role (patient, clinician, organization administrator, platform administrator) to the PHI necessary for that role — including that platform-level administrators do not have access to patient-identifiable clinical data in the ordinary course of platform operation.
7. Term and Termination
This BAA is effective for as long as Vitalink maintains, creates, receives, or transmits PHI on behalf of the Covered Entity. Either party may terminate this BAA for a material breach that is not cured within thirty (30) days' written notice. Upon termination, Vitalink will, at the Covered Entity's election, return or destroy all PHI in its possession, or, if neither is feasible, extend the protections of this BAA to the retained PHI for as long as it is retained.
8. Access by the Secretary of HHS
Vitalink will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
9. Effect of Amendment
The parties agree to amend this BAA as necessary to comply with changes in HIPAA, HITECH, or their implementing regulations.
10. Contact
Organizations that require a fully executed, countersigned copy of this BAA for compliance records should reach out through Contact Support.