Business Associate Agreement

EvidenceMD Inc.

Last Updated: September 3, 2026

This Business Associate Agreement ("BAA") forms part of the EvidenceMD Terms of Use available at https://evidencemd.ai/terms-of-use (the "Services Agreement") between EvidenceMD Inc., a Delaware corporation with an address at 2810 N Church St STE 89233, Wilmington, Delaware 19802 USA ("Business Associate" or "EvidenceMD"), and the individual clinician or practice that accepted the Services Agreement and to which this BAA applies under Section 7 ("Covered Entity" or "Client"). This BAA is effective as of the date it is accepted in accordance with Section 7 (the "Effective Date"). Business Associate and Covered Entity are each a "Party" and together the "Parties."

This BAA applies to Client’s use of EvidenceMD’s individual subscription plans, including the Free, Individual, and Max tiers. Enterprise customers are covered by a separately negotiated business associate agreement, and the terms of this BAA do not apply to them.


1. Scope; Definitions

1.1 This BAA is effective to the extent Business Associate performs Services that require it to create, receive, maintain, or transmit PHI on behalf of Covered Entity under the Services Agreement.

1.2 Capitalized terms used but not defined in this BAA have the meaning given to them in the HIPAA Rules or the Services Agreement, as applicable. In the event of a conflict between defined terms, the HIPAA Rules control.

1.3 The following terms have the meanings set out below:

(a) "Business Associate" has the meaning given to "business associate" at 45 CFR §160.103 and, in reference to a Party, means EvidenceMD Inc.

(b) "Covered Entity" has the meaning given to "covered entity" at 45 CFR §160.103 and, in reference to a Party, means the clinician or practice that accepted the Services Agreement and to which this BAA applies under Section 7.

(c) "Electronic Protected Health Information" or "ePHI" has the general meaning given to "electronic protected health information" at 45 CFR §160.103, limited for purposes of this BAA to ePHI created, received, transmitted, or maintained by Business Associate for or on behalf of Covered Entity.

(d) "HIPAA Rules" means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164, each as amended from time to time.

(e) "Protected Health Information" or "PHI" has the general meaning given to "protected health information" at 45 CFR §160.103, limited for purposes of this BAA to PHI created, received, transmitted, or maintained by Business Associate for or on behalf of Covered Entity.

(f) "Services" means the services Business Associate provides to Covered Entity under the Services Agreement.

(g) "Subcontractor" has the meaning given to that term at 45 CFR §160.103.

(h) "Unsuccessful Security Incidents" means, without limitation, pings and other broadcast attacks on Business Associate’s firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and malware that is blocked or quarantined, and any combination of the foregoing, so long as no such incident results in unauthorized access, Use, or Disclosure of Covered Entity’s ePHI.


2. Obligations and Activities of Business Associate

Business Associate agrees to:

(a) Not Use or Disclose PHI other than as permitted by this BAA, the Services Agreement, or as Required by Law.

(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided for by this BAA and the Services Agreement.

(c) Report to Covered Entity any Use or Disclosure of PHI not provided for by this BAA of which it becomes aware, including a Breach of Unsecured PHI as required under 45 CFR §164.410, and any Security Incident of which it becomes aware. Business Associate will make any report of a Breach of Unsecured PHI without unreasonable delay and in no event later than sixty (60) calendar days after discovery of the Breach. The Parties acknowledge that this Section 2(c) constitutes notice by Business Associate to Covered Entity of the ongoing existence, occurrence, or attempts of Unsuccessful Security Incidents, for which no additional notice is required.

(d) In accordance with 45 CFR §§164.502(e)(1)(ii) and 164.308(b)(2), obtain from any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate reasonable written assurances that the Subcontractor will adhere to restrictions and conditions at least as restrictive as those that apply to Business Associate under this BAA.

(e) Make available, at Covered Entity’s request, PHI maintained in a Designated Record Set (if any) as necessary to allow Covered Entity to satisfy its obligations under 45 CFR §164.524.

(f) Make amendments to PHI maintained in a Designated Record Set (if any) as requested by Covered Entity pursuant to 45 CFR §164.526, or take other measures reasonably necessary to enable Covered Entity to satisfy its obligations under that section.

(g) Maintain and make available to Covered Entity the information required to provide an accounting of Disclosures, as reasonably necessary to satisfy Covered Entity’s obligations under 45 CFR §164.528.

(h) Take reasonable steps to mitigate, to the extent practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI in violation of this BAA.

(i) To the extent Business Associate carries out any of Covered Entity’s obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.

(j) Make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of HHS for purposes of determining compliance with the HIPAA Rules.

For clarity, with respect to Sections 2(e) through 2(g), Business Associate is in no case responsible for responding directly to any Individual who submits a request to Business Associate under 45 CFR §§164.524–164.528; Business Associate will promptly forward any such request to Covered Entity.


3. Permitted Uses and Disclosures by Business Associate

(a) Business Associate may Use or Disclose PHI as necessary to perform the Services or as Required by Law.

(b) Business Associate may Use PHI for its proper management and administration or to carry out its legal responsibilities.

(c) Business Associate may Disclose PHI for its proper management and administration or to carry out its legal responsibilities, provided the Disclosure is (i) Required by Law, or (ii) Business Associate obtains reasonable assurances from the recipient that the information will remain confidential and be Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed, and that the recipient will notify Business Associate of any breach of confidentiality of which it becomes aware.

(d) Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity.

(e) Business Associate may Use PHI to create de-identified information in accordance with 45 CFR §164.514(a)–(c). Information that has been de-identified in accordance with those provisions is not PHI and is not subject to this BAA.

(f) Business Associate may Use PHI to report violations of law to appropriate federal and state authorities, consistent with 45 CFR §164.502(j)(1).

(g) Business Associate may Use and Disclose PHI as otherwise authorized by Covered Entity in the Services Agreement, to the extent such Use or Disclosure is permitted under the HIPAA Rules.


4. Obligations of Covered Entity

During the term of this BAA, Covered Entity will:

(a) Notify Business Associate of any limitation in its notice of privacy practices under 45 CFR §164.520, to the extent the limitation may affect Business Associate’s Use or Disclosure of PHI.

(b) Notify Business Associate of any change in, or revocation of, permission by an Individual to Use or Disclose PHI, to the extent the change may affect Business Associate’s Use or Disclosure of PHI.

(c) Notify Business Associate of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to under 45 CFR §164.522, to the extent the restriction may affect Business Associate’s Use or Disclosure of PHI.

(d) Not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, other than as permitted under Sections 3(b) through 3(g).

(e) Obtain and maintain all consents, authorizations, permissions, and waivers, and make all notices, required under applicable federal and state law for Business Associate to provide the Services and to exercise the rights granted to it under this BAA and the Services Agreement, including any consent required for the audio recording of patient encounters where the Services include ambient documentation, and including in jurisdictions requiring all-party consent to recording.

(f) Be solely responsible for the accuracy, adequacy, and clinical appropriateness of PHI it submits to the Services, and for the review, verification, and clinical use of any output generated by the Services. The Services support, and do not replace, the independent professional judgment of a licensed clinician.

(g) Comply with all requirements of the HIPAA Rules applicable to Covered Entity.


5. Term and Termination

5.1 Term. This BAA commences on the Effective Date and, except for rights and obligations expressly surviving termination, terminates upon termination or expiration of the Services Agreement, unless earlier terminated for cause under this Section 5.

5.2 Termination by Covered Entity. Covered Entity may terminate this BAA if it determines, in good faith and after reasonable investigation, that Business Associate has violated a material term of this BAA and Business Associate has failed to cure that breach within thirty (30) days of written notice.

5.3 Termination by Business Associate. Business Associate may terminate this BAA and the Services Agreement if (i) it determines, in good faith and after reasonable investigation, that Covered Entity has violated a material term of this BAA and Covered Entity has failed to cure that breach within thirty (30) days of written notice; or (ii) Covered Entity agrees to a restriction under 45 CFR §164.522, or becomes subject to a legal requirement, that materially affects Business Associate’s ability to perform the Services or the cost of performance.

5.4 Effect of termination. Upon termination or expiration of this BAA for any reason, Business Associate will:

(a) Retain only that PHI which is necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities;

(b) Return to Covered Entity or destroy the remaining PHI that Business Associate maintains in any form and that is not necessary to carry out Section 5.4(a);

(c) Continue to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to any retained ePHI, for as long as Business Associate retains it;

(d) Not Use or Disclose retained PHI other than for the purposes for which it was retained, subject to the same conditions set out in Sections 3(b) and 3(c); and

(e) Return to Covered Entity or destroy retained PHI when it is no longer needed for Business Associate’s proper management and administration or to carry out its legal responsibilities.

For the avoidance of doubt, this Section 5.4 does not apply to information that has been de-identified in accordance with Section 3(e), which is not PHI.


6. General

6.1 Change in law. If a change in the HIPAA Rules or other applicable federal or state law requires the Parties to amend this BAA, the Parties will negotiate the amendment in good faith, provided that either Party may terminate this BAA on written notice if the Parties are unable to agree.

6.2 Conflicts. This BAA forms part of and is subject to the Services Agreement, except that to the extent any term of this BAA conflicts with the Services Agreement with respect to the treatment of PHI, this BAA controls. Nothing in this Section limits any right granted to Business Associate under the Services Agreement to the extent that right is permitted under the HIPAA Rules, and no provision of this BAA will be construed to revoke or narrow any such right.

6.3 Amendment. Business Associate may update this BAA from time to time. Business Associate will provide Covered Entity with notice of any material change at least thirty (30) days before it takes effect, and Covered Entity may terminate the Services Agreement and this BAA during that period if it does not accept the change. Continued use of the Services after the change takes effect constitutes acceptance.

6.4 No third-party rights. Except as expressly stated in this BAA or as provided by law, this BAA does not create any rights in favor of any third party.

6.5 Regulatory references. A reference in this BAA to a section of the HIPAA Rules means that section as in effect or as amended at the relevant time.

6.6 Governing law. This BAA is governed by the laws of the State of Delaware, without regard to its conflict of laws principles, except to the extent the Services Agreement specifies otherwise and except where the mandatory law of another jurisdiction applies. Nothing in this Section limits the application of federal law or of any state health information privacy law applicable to Covered Entity or to the Individuals whose information is processed.

6.7 Notices. Notices under this BAA will be given as provided in the Services Agreement, and may be given to Covered Entity at the email address associated with Covered Entity’s account. Notices to Business Associate may also be sent to krishnakumar@evidencemd.ai and to the address set out above.


7. Acceptance

This BAA is accepted electronically, and no signature is required. It applies to Client from the earlier of the date Client accepts the Services Agreement and opts in to this BAA, or the date Client first uses the Services to create, receive, maintain, or transmit PHI.

[END OF BUSINESS ASSOCIATE AGREEMENT]

Individual Business Associate Agreement | EvidenceMD