Business Associate Agreement
Version 4 (v4) · Effective Date: June 1, 2026 · Last Updated: June 1, 2026
This Business Associate Agreement (“BAA” or “Agreement”) is entered into between TrueTime Health, Inc., a Delaware C-Corporation (“Business Associate” or “TrueTime”), and the healthcare agency, organization, or individual (“Covered Entity”) that accepts this Agreement through the TrueTime Health platform. This BAA governs the relationship between the parties with respect to Protected Health Information (“PHI”) shared or created in connection with TrueTime’s services, in compliance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and their implementing regulations at 45 CFR Parts 160 and 164.
1. Definitions
Terms used but not otherwise defined in this Agreement shall have the same meaning as those terms in 45 CFR Parts 160 and 164.
- Protected Health Information (“PHI”) means individually identifiable health information transmitted or maintained in any form or medium, as defined in 45 CFR §160.103, limited to the information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
- Electronic PHI (“ePHI”) means PHI that is transmitted by or maintained in electronic media, as defined in 45 CFR §160.103.
- Required by Law means a mandate contained in law that compels Business Associate to make a use or disclosure of PHI and that is enforceable in a court of law.
- Subcontractor means a person or entity that creates, receives, maintains, or transmits PHI on behalf of Business Associate.
- Security Incident means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
- Breach has the meaning set forth in 45 CFR §164.402, generally an impermissible use or disclosure of PHI that compromises the security or privacy of the information.
2. Permitted Uses and Disclosures of PHI
Business Associate may use or disclose PHI only as necessary to perform services on behalf of Covered Entity, as described in any applicable service agreement, and as permitted or required by this BAA or Required by Law. Permitted purposes include:
- Service Delivery. Business Associate may use and disclose PHI to perform eligibility verification, pre-claim review (PCR), additional documentation request (ADR) defense, chart review, quality assurance (QA), coding review, discharge readiness, authorization and benefit verification, survey readiness, and document intelligence (TrueTime Intel) services for Covered Entity.
- Management and Administration. Business Associate may use PHI for its own management, administration, and legal responsibilities, provided that any disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that (i) the PHI will be held confidentially, (ii) it will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and (iii) the recipient will notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
- Data Aggregation. Business Associate may use PHI to provide data aggregation services relating to the health care operations of Covered Entity, as permitted under 45 CFR §164.504(e)(2)(i)(B).
- De-identification. Business Associate may de-identify PHI in accordance with 45 CFR §164.514(b), after which such information is no longer subject to this Agreement.
3. Safeguards and Security of PHI (45 CFR Parts 160 and 164)
Business Associate agrees to implement and maintain appropriate administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI and ePHI, in compliance with 45 CFR Part 164 Subpart C (Security Rule). Specifically, Business Associate shall:
- Implement a security management process, including risk analysis and risk management, to protect against reasonably anticipated threats to the security of ePHI (45 CFR §164.308(a)(1)).
- Implement policies and procedures to prevent, detect, contain, and correct security violations, including access controls, audit controls, and integrity controls (45 CFR §§164.308–164.316).
- Encrypt ePHI in transit and at rest using industry-standard encryption protocols (AES-256 or equivalent), consistent with the NIST guidelines referenced in HITECH.
- Maintain a minimum-necessary standard: use, disclose, or request only the minimum amount of PHI necessary to accomplish the intended purpose (45 CFR §164.502(b)).
- Ensure that workforce members with access to PHI are trained on applicable policies and procedures, and impose appropriate disciplinary sanctions for violations.
- Maintain audit logs of access to PHI with a minimum six-year retention period, consistent with applicable HIPAA recordkeeping requirements.
4. Eligibility Verification Authorization (NPI and TIN)
Covered Entity authorizes Business Associate to use Covered Entity’s National Provider Identifier (“NPI”) and Tax Identification Number / Employer Identification Number (“TIN/EIN”) solely for the following purposes:
- Performing eligibility and benefit verification on behalf of Covered Entity with payers, Medicare Administrative Contractors (MACs), and other applicable entities.
- Submitting pre-claim review (PCR) requests and supporting documentation to Palmetto GBA or other applicable reviewers.
- Completing authorization and benefit verification workflows with payers, as directed by Covered Entity.
- Identifying Covered Entity in communications with government agencies, payers, and accrediting bodies solely as required to perform the contracted services.
Business Associate shall not use Covered Entity’s NPI or TIN/EIN for any purpose beyond the scope of services described in this Agreement, and shall not disclose such identifiers to third parties except as necessary to perform authorized services or as Required by Law.
5. Support for Individual-Rights Obligations
To the extent Business Associate maintains a Designated Record Set on behalf of Covered Entity, Business Associate shall, in a timely manner:
- Access. Make PHI available to Covered Entity (and, if directed by Covered Entity, to the Individual) in accordance with 45 CFR §164.524 within thirty (30) days of a request (or within sixty (60) days if Business Associate extends the period as permitted).
- Amendment. Incorporate any amendments to PHI directed by Covered Entity pursuant to 45 CFR §164.526.
- Accounting of Disclosures. Maintain and provide to Covered Entity an accounting of disclosures of PHI as required under 45 CFR §164.528, including the date, recipient, and purpose of each disclosure, for a period of six (6) years from the date of disclosure.
- Restriction Requests. Implement any agreed-upon restrictions on the use or disclosure of PHI consistent with 45 CFR §164.522.
- Confidential Communications. Accommodate reasonable requests by Individuals for confidential communications of PHI as directed by Covered Entity.
6. Breach Notification and Subcontractor Requirements
6.1 Breach Notification to Covered Entity
Business Associate shall notify Covered Entity without unreasonable delay, and in no case later than sixty (60) calendar days after discovery of a Breach of Unsecured PHI, in accordance with 45 CFR §164.410. The notification shall include, to the extent possible:
- A description of the Breach, including the date of the Breach and the date of discovery
- The types of PHI involved (e.g., name, SSN, diagnosis, financial information)
- The number of Individuals affected
- A description of steps Individuals should take to protect themselves from potential harm
- Steps Business Associate is taking to investigate, mitigate harm, and prevent future Breaches
- Contact information for individuals to ask questions or obtain additional information
Business Associate shall also notify Covered Entity of any Security Incidents involving ePHI, including attempted unauthorized access, within five (5) business days of discovery. Routine low-level Security Incidents that do not result in unauthorized access, acquisition, use, or disclosure of ePHI shall be reported on a periodic basis as agreed by the parties.
6.2 Subcontractor Requirements
Business Associate shall enter into a written agreement with any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate, requiring the Subcontractor to comply with the same HIPAA obligations and restrictions that apply to Business Associate under this Agreement (45 CFR §164.504(e)(5)). Business Associate shall:
- Ensure Subcontractors implement appropriate safeguards to protect the confidentiality, integrity, and availability of PHI.
- Require Subcontractors to report any Breach or Security Incident involving PHI to Business Associate promptly, and in no event later than thirty (30) days after discovery.
- Maintain a list of current Subcontractors with access to PHI and make this list available to Covered Entity upon reasonable written request.
Current cloud infrastructure Subcontractors include Google LLC (Google Cloud Platform, which is covered under a HIPAA BAA with Google), Anthropic PBC (AI processing, covered under a BAA), and Resend, Inc. (transactional email, no PHI transmitted). TrueTime maintains current BAAs with all Subcontractors that handle PHI.
7. Return or Destruction of PHI When the Agreement Ends
Upon termination of this Agreement or the underlying service relationship for any reason, Business Associate shall, at the direction of Covered Entity, either:
- Return. Return all PHI received from, or created or received by Business Associate on behalf of, Covered Entity to Covered Entity in a mutually agreed secure format within sixty (60) days of termination; or
- Destroy. Destroy all such PHI in a manner consistent with NIST SP 800-88 guidelines for media sanitization, such that PHI cannot be reconstructed, within sixty (60) days of termination, and certify in writing to Covered Entity that such destruction has occurred.
If Business Associate determines that returning or destroying all PHI is infeasible (e.g., because PHI is embedded in backup media or is retained pursuant to legal hold), Business Associate shall:
- Notify Covered Entity of the conditions that make return or destruction infeasible
- Extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make return or destruction infeasible, for as long as Business Associate maintains the PHI
Notwithstanding the foregoing, Business Associate may retain PHI for the minimum period required by applicable law or regulation (including HIPAA’s six-year documentation retention requirement under 45 CFR §164.530(j)) and shall destroy such PHI promptly upon expiration of such required retention period.
8. Obligations of Covered Entity
Covered Entity shall:
- Notify Business Associate of any limitation in its Notice of Privacy Practices that would affect Business Associate’s use or disclosure of PHI.
- Notify Business Associate of any changes in, or revocation of, permission by Individuals to use or disclose PHI, to the extent that such changes may affect Business Associate’s permitted uses or disclosures.
- Notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR §164.522.
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity.
- Obtain all consents, authorizations, and permissions from Individuals as required by applicable law before transmitting PHI to Business Associate.
9. Term and Termination
9.1 Term
This Agreement shall be effective as of the date accepted by Covered Entity through the TrueTime Health platform and shall remain in effect until terminated as provided herein or until the underlying service relationship between the parties terminates.
9.2 Termination for Cause
If either party discovers a material breach by the other party of a provision of this Agreement, the non-breaching party shall:
- Provide written notice to the breaching party, specifying the nature of the breach; and
- Afford the breaching party thirty (30) calendar days from receipt of the notice to cure the breach, if cure is possible.
If the breach is not cured within thirty (30) days, or if cure is not possible, the non-breaching party may terminate this Agreement and the underlying service relationship immediately upon written notice.
If termination is not feasible (e.g., no other means of providing the required services exist), the party discovering the breach shall report the breach to the Secretary of the U.S. Department of Health and Human Services in accordance with 45 CFR §164.504(e)(1)(ii).
10. Miscellaneous
10.1 Regulatory Compliance
The parties agree to amend this Agreement as necessary to comply with applicable federal and state privacy and security laws and regulations, including any amendments to HIPAA, HITECH, or implementing regulations promulgated by HHS. Each party shall comply with any guidance issued by the Secretary of HHS regarding HIPAA compliance.
10.2 No Third-Party Beneficiaries
This Agreement is for the benefit of the parties only. Nothing in this Agreement shall confer any rights or remedies upon any third party, including Individuals whose PHI is handled under this Agreement.
10.3 Interpretation
This Agreement shall be construed as broadly as necessary to implement and comply with HIPAA, the HIPAA Regulations, and applicable state law. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the parties to comply with HIPAA and the HIPAA Regulations.
10.4 Governing Law and Venue
This Agreement shall be governed by the laws of the State of Delaware, without regard to conflict-of-law principles. Disputes shall be resolved in accordance with the dispute resolution procedures set forth in the TrueTime Health Terms of Service, incorporated herein by reference.
10.5 Entire Agreement; Order of Precedence
This Agreement, together with any applicable service agreement between the parties, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior oral or written communications concerning the handling of PHI. In the event of a conflict between this Agreement and any service agreement, the more protective provision for PHI shall control.
10.6 Survival
The obligations of this Agreement with respect to the use, disclosure, and safeguarding of PHI shall survive termination of this Agreement and the underlying service relationship for so long as Business Associate retains any PHI subject to this Agreement.
10.7 Electronic Acceptance
The parties agree that electronic acceptance of this Agreement through the TrueTime Health platform constitutes a legally binding signature for purposes of this Agreement and applicable law. An electronic record of acceptance, including the signer’s name, title, NPI, TIN, IP address, and timestamp, is maintained in TrueTime’s audit log and is made available to Covered Entity upon request.
Contact — Privacy and Compliance
Questions about this Agreement, data handling, or HIPAA compliance should be directed to:
TrueTime Health, Inc.
Privacy Officer
Email: privacy@truetime.health
General: admin@truetime.health
Document version: v4 — superseded by v5 on September 29, 2026; shown for reference. TrueTime Health reserves the right to update this BAA; material changes will increment the version number and require re-acceptance by Covered Entity. Prior versions are available upon written request to privacy@truetime.health.
© 2026 TrueTime Health, Inc. All rights reserved.