PHI UploaderSecure healthcare intake
Use CasesFeaturesSecurityPricing
Sign inStart free trial
Use CasesFeaturesSecurityPricingSign inStart free trial
Business Associate Agreement

PHI Uploader Business Associate Agreement

This page presents the complete current agreement text. The version and SHA-256 below identify the exact document offered in the Account signing flow.

Download Current PDFSecurity Overview
Exact document

Document Details

Status
Current executable version
Version
baa-v2-2026-07-13
Document date
2026-07-13
Business Associate
Codeless Consultant LLC
Notice address
1193 Cranberry Ct. Holland, MI 49423
Notice email
jared@codelessconsultant.com
SHA-256
cbca0e7045eb2326b140255f369fcbcb3663885afbcd3689ce7ad5ad72e38b46
Agreement text

PHI Uploader Business Associate Agreement

Version baa-v2-2026-07-13 · Document date 2026-07-13

1. Parties, Relationship, and Effective Date

This Business Associate Agreement ("BAA") is between Codeless Consultant LLC, which provides the PHI Uploader service ("Business Associate"), and the legal organization identified as Customer in the electronic signature certificate ("Customer"). Customer represents that it is a Covered Entity or Business Associate under the HIPAA Rules. If Customer is a Business Associate, Business Associate acts as Customer's Subcontractor, and the same restrictions, conditions, and requirements apply to the extent required by the HIPAA Rules.

This BAA supplements the service, order, pilot, subscription, or other written agreement governing Customer's use of PHI Uploader (the "Service Agreement"). It becomes effective on the electronic-signature date in the signature certificate (the "Effective Date"). The certificate, including the parties' names, signer identity and authority, Effective Date, document version, and document hash, is incorporated into this BAA. If this BAA conflicts with the Service Agreement concerning PHI privacy, security, Breach response, individual rights, Subcontractors, or return or destruction of PHI, this BAA controls.

2. Definitions

"HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as in effect or amended. The following terms have the meanings assigned by the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, Use, and Workforce.

"PHI" means Protected Health Information that Business Associate receives from or on behalf of Customer, or creates, receives, maintains, or transmits on Customer's behalf in connection with the Services, and includes Electronic Protected Health Information.

"Services" means the PHI Uploader document-request, recipient-submission, upload, malware-scanning, artifact-generation, Customer-authorized Google Drive delivery, authentication, administration, security, maintenance, recovery, audit, troubleshooting, and support functions described in the Service Agreement.

3. Permitted and Required Uses and Disclosures

Business Associate shall Use or Disclose PHI only as necessary to perform the Services and its obligations under this BAA; as directed in writing by Customer when the direction is permitted by the HIPAA Rules; for Business Associate's proper management and administration or legal responsibilities as permitted below; or as Required by Law.

Business Associate may Use PHI for its proper management and administration or to carry out its legal responsibilities. Business Associate may Disclose PHI for those purposes only if the Disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential, will be Used or further Disclosed only for the purpose for which it was provided or as Required by Law, and the recipient will notify Business Associate of any known breach of confidentiality.

Where the Minimum Necessary standard applies, Business Associate shall limit its Uses, Disclosures, and requests for PHI consistently with Customer's written Minimum Necessary policies supplied to Business Associate. Business Associate shall not Use or Disclose PHI in a manner that would violate 45 CFR Part 164, Subpart E if done by Customer, except for the management, administration, and legal-responsibility activities expressly permitted above.

Unless separately authorized by a written amendment, Business Associate shall not Use PHI for sale, advertising, marketing, independent product analytics or development, artificial-intelligence or machine-learning training, Data Aggregation, or de-identification.

4. Privacy and Security Obligations

Business Associate shall not Use or further Disclose PHI except as permitted or required by this BAA or as Required by Law. Business Associate shall maintain appropriate administrative, physical, and technical safeguards to prevent Uses or Disclosures not permitted by this BAA and shall comply with the applicable requirements of 45 CFR Part 164, Subpart C for Electronic Protected Health Information.

Business Associate shall limit PHI access to Workforce members who require it for authorized duties, apply appropriate Workforce controls, and keep operational logs and ordinary support channels free of PHI except through an expressly approved secure process.

Business Associate shall take reasonable steps to mitigate, to the extent practicable, harmful effects of any Use or Disclosure of PHI by Business Associate that violates this BAA. To the extent Business Associate performs a Customer obligation under 45 CFR Part 164, Subpart E, Business Associate shall comply with the requirements that would apply to Customer when performing that obligation.

5. Impermissible Uses, Security Incidents, and Breaches

Business Associate shall report to Customer every Use or Disclosure of PHI not permitted by this BAA and every Security Incident of which Business Associate becomes aware, without unreasonable delay and no later than ten calendar days after discovery. Routine unsuccessful Security Incidents may be reported in aggregate or on a schedule agreed in writing, provided that this does not delay reporting a Breach, an impermissible Use or Disclosure, a successful Security Incident, or an incident that materially interferes with PHI or the Services.

Following discovery of a Breach of Unsecured PHI, Business Associate shall notify Customer as required by 45 CFR 164.410, without unreasonable delay and in no event later than sixty calendar days after discovery. The earlier incident report may serve as preliminary notice, and Business Associate shall not delay available notice solely because its investigation is incomplete.

To the extent possible, notice shall identify each Individual whose Unsecured PHI was or is reasonably believed to have been accessed, acquired, Used, or Disclosed and shall provide the information Customer needs for notices under 45 CFR 164.404(c). Business Associate shall promptly supplement the notice as information becomes available and reasonably cooperate with Customer's investigation, risk assessment, mitigation, and legally required notifications. Business Associate shall not notify Individuals, the Secretary, or the media on Customer's behalf unless Customer authorizes it in writing or notification is Required by Law.

6. Subcontractors

Before permitting a Subcontractor to create, receive, maintain, or transmit PHI on Business Associate's behalf, Business Associate shall enter into a written agreement requiring the Subcontractor to accept the same restrictions, conditions, and requirements that apply to Business Associate under this BAA. A Subcontractor handling Electronic Protected Health Information must also agree to comply with the applicable requirements of 45 CFR Part 164, Subpart C.

If Business Associate becomes aware of a pattern or practice by a Subcontractor that materially violates those obligations, Business Associate shall take reasonable steps to cure the violation or end the practice and, if those steps are unsuccessful, terminate the Subcontractor relationship if feasible.

Production PHI processing shall remain within approved, BAA-covered infrastructure and Customer-authorized destination services. Any Subcontractor change-notice or objection process offered to Customer shall be stated in the Service Agreement or a maintained Subcontractor schedule.

7. Access, Amendment, Accounting, and Delegated Duties

Upon Customer's written request, Business Associate shall make PHI in a Designated Record Set that it maintains available to Customer in the form and format reasonably requested, as necessary for Customer to satisfy 45 CFR 164.524. Business Associate shall provide available PHI within ten business days, or sooner when reasonably necessary for Customer to meet a legal deadline.

Business Associate shall make amendments to PHI in a Designated Record Set as directed or agreed to by Customer, or take other necessary measures to support Customer's obligations under 45 CFR 164.526, within ten business days after receiving Customer's direction.

Business Associate shall maintain and make available the information needed for Customer to provide an accounting of Disclosures under 45 CFR 164.528. Business Associate shall provide that information within ten business days after Customer's request and retain required accounting information for at least six years from the applicable Disclosure, unless a longer period is Required by Law.

If Business Associate receives a request directly from an Individual concerning access, amendment, or an accounting, Business Associate shall forward it to Customer promptly and ordinarily within two business days. Business Associate shall not independently grant or deny the request unless Customer directs it to do so or action is Required by Law.

8. Secretary Access and Compliance Records

Business Associate shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received on behalf of, Customer available to the Secretary at the time and in the manner designated by the Secretary for purposes of determining compliance with the HIPAA Rules. Where legally permitted, Business Associate shall notify Customer of such a request and provide Customer with copies of materials supplied.

9. Customer Responsibilities

Customer shall notify Business Associate of any limitation in Customer's Notice of Privacy Practices, change or revocation of an Individual's permission, or restriction under 45 CFR 164.522 that may affect Business Associate's permitted Uses or Disclosures. Customer shall not direct Business Associate to Use or Disclose PHI in a way that would violate 45 CFR Part 164, Subpart E if performed by Customer, except for activities expressly permitted under Section 3.

Customer is responsible for the lawfulness of the PHI and workflow submitted to the Services, required notices and authorizations, authorized Workforce access, account security, accurate routing instructions, and its Google Workspace and Drive configuration. Customer shall maintain appropriate HIPAA contractual coverage for any Customer-controlled Google Workspace destination that receives PHI and shall not send PHI through public support forms, ordinary email, or another unapproved channel.

Customer's failure to perform these responsibilities does not relieve Business Associate of its independent obligations under this BAA or the HIPAA Rules.

10. Term and Termination for Cause

This BAA begins on the Effective Date and continues while Business Associate creates, receives, maintains, or transmits PHI for Customer, unless earlier terminated under this Section. Business Associate authorizes Customer to terminate this BAA and the affected Services if Customer determines that Business Associate has violated a material term. Customer may terminate immediately or, at Customer's option when cure is feasible, provide a written cure period not exceeding thirty days.

Following termination of this BAA, Business Associate shall cease accepting new PHI for Customer except as necessary to complete the return, transfer, or destruction required below. Either party may suspend PHI processing when reasonably necessary to prevent an unlawful Disclosure or address a material security risk, subject to the Service Agreement and this BAA.

11. Return or Destruction of PHI

Upon termination for any reason, Business Associate shall, if feasible and as directed by Customer, return to Customer or securely destroy all PHI received from Customer or created, received, maintained, or transmitted on Customer's behalf that Business Associate or its Subcontractors still maintain in any form. Business Associate shall retain no copies.

If return or destruction of particular PHI is infeasible, Business Associate shall notify Customer in writing, identify the affected PHI, and explain the basis for infeasibility. Business Associate shall retain only the PHI for which return or destruction is infeasible, continue all protections required by this BAA and the Security Rule, limit further Uses and Disclosures to the purpose that makes return or destruction infeasible, and return or destroy the PHI when that basis no longer exists. Upon Customer's request, Business Associate shall certify completion of return or destruction.

The obligations in this Section survive termination.

12. Regulatory Changes, Other Law, Notices, and Electronic Execution

Regulatory references mean the cited provision as currently effective or later amended. The parties shall take action reasonably necessary to amend this BAA when required for compliance with the HIPAA Rules or other applicable law. A material amendment shall be identified by a new document version and content hash and shall become effective only through acceptance by authorized representatives; merely posting revised language does not replace an executed version.

Nothing in this BAA authorizes conduct prohibited by a more stringent applicable law. Before intentionally using the Services for records subject to 42 CFR Part 2 or another specialized confidentiality regime, Customer shall notify Business Associate through a no-PHI channel, and the parties shall confirm any required supplemental terms and workflow controls.

Notices to Business Associate under this BAA shall be sent to jared@codelessconsultant.com and, when formal written notice is required, to 1193 Cranberry Ct. Holland, MI 49423. Notices to Customer shall be sent to Customer's designated privacy or security contact, or if none is designated, to an organization owner or the signer email recorded in the certificate, using a secure method appropriate to the information.

Any ambiguity shall be interpreted to permit compliance with the HIPAA Rules. Commercial matters not addressed here remain governed by the Service Agreement.

The parties consent to electronic records and signatures. Customer's authorized electronic signature and Business Associate's issuance of the signature certificate constitute execution of the exact version and hash identified in that certificate. Customer may review and retain a readable copy of the complete agreement before execution, and both parties shall retain the executed agreement.

Execution and retention

An organization owner must review this complete document in Account and accept the exact version and hash before signing. The signed PDF remains available from the organization's Account archive.

PHI UploaderSecure document requests for healthcare workflows.
FeaturesPricingContactHelpSecurityTermsPrivacyBAA