Legal · Version 2026-08-04

Business Associate Agreement

This Business Associate Agreement ("Agreement" or "BAA") is entered into by and between the covered entity practice identified during Get Started or otherwise in an order form or services agreement (the "Covered Entity") and Maps Health Network, LLC, a limited liability company doing business as GLP-1 Receptionist and Grace (the "Business Associate"). Covered Entity and Business Associate are each a "Party" and together the "Parties."

By checking the acceptance box during Get Started, confirming acceptance with a Grace sales agent, or otherwise indicating assent to this Agreement, an authorized representative of Covered Entity agrees to the terms below. Acceptance is logged with timestamp, version identifier, channel, and acceptor identity.

This Agreement supplements any underlying services agreement, order form, or terms of service between the Parties (the "Services Agreement") under which Business Associate provides voice receptionist, scheduling assistance, messaging, practice operations tooling, and related services that may involve Protected Health Information (the "Services").

1. Definitions

Capitalized terms used but not defined in this Agreement have the meanings set forth in the Health Insurance Portability and Accountability Act of 1996, as amended, and the regulations promulgated thereunder, including the Privacy Rule (45 C.F.R. Part 160 and Subparts A and E of Part 164), the Security Rule (45 C.F.R. Part 160 and Subparts A and C of Part 164), and the Breach Notification Rule (45 C.F.R. Part 160 and Subparts A and D of Part 164) (collectively, "HIPAA").

2. Obligations of Business Associate

Business Associate agrees to:

  1. Not use or disclose PHI other than as permitted or required by this Agreement, the Services Agreement, or as Required by Law.
  2. Use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
  3. Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including Breaches of Unsecured PHI as required by 45 C.F.R. § 164.410, and any Security Incident of which Business Associate becomes aware. Notices will be provided without unreasonable delay and in no case later than sixty (60) days after discovery, or sooner if Required by Law. Routine unsuccessful attempts to access systems (such as pings, port scans, and failed login attempts) that do not result in unauthorized access to PHI need not be reported individually.
  4. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such PHI.
  5. Make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524 (individual access), within the timeframes reasonably requested by Covered Entity and Required by Law.
  6. Make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under that section.
  7. Maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.528.
  8. To the extent Business Associate is to carry out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligations.
  9. Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.

3. Permitted Uses and Disclosures by Business Associate

  1. Business Associate may use or disclose PHI as necessary to perform the Services for or on behalf of Covered Entity as described in the Services Agreement and this Agreement, provided that such use or disclosure would not violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except for the specific uses and disclosures set forth below.
  2. Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities.
  3. Business Associate may disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that (a) the disclosures are Required by Law, or (b) Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and be used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
  4. Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B), where such services are part of the Services.
  5. Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c). De-identified information is not PHI and may be used or disclosed for any lawful purpose, including to improve, secure, and operate the Services, provided it does not identify Covered Entity's patients and is not combined with other information to re-identify individuals.
  6. Business Associate will not use or disclose PHI for marketing or sale of PHI except as expressly permitted by HIPAA and authorized in writing by Covered Entity.
  7. Business Associate will not use PHI to train general-purpose artificial intelligence models in a manner that discloses PHI to third parties outside Business Associate's Subcontractors bound by this Agreement, except as expressly authorized by Covered Entity in writing or as otherwise permitted by HIPAA.

4. Minimum Necessary

When using, disclosing, or requesting PHI, Business Associate will make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b) and Covered Entity's applicable minimum-necessary policies communicated to Business Associate in writing.

5. Obligations of Covered Entity

Covered Entity agrees to:

  1. Notify Business Associate of any limitation(s) in its notice of privacy practices under 45 C.F.R. § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.
  2. Notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's permitted uses or disclosures.
  3. Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.
  4. Not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted under Section 3 of this Agreement.
  5. Ensure that only authorized workforce members instruct Business Associate regarding PHI, and that Covered Entity remains responsible for clinical decisions, medical advice, diagnosis, and treatment. Grace is an administrative receptionist and related operations tool; it is not a clinician.

6. Term and Termination

  1. Term. This Agreement is effective as of the date of Covered Entity's acceptance (the "Effective Date") and continues until terminated as provided herein or until all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity (or, if return or destruction is not feasible, protections are extended as provided below).
  2. Termination for cause. Either Party may terminate this Agreement and the related Services if the other Party has materially breached this Agreement and fails to cure such breach within thirty (30) days after receiving written notice describing the breach in reasonable detail; provided that if cure is not reasonably possible within thirty (30) days, the breaching Party shall commence cure within that period and diligently pursue completion. Covered Entity may terminate immediately if cure is not possible and Required by Law.
  3. Effect of termination. Upon termination of this Agreement for any reason, Business Associate shall, if feasible, return to Covered Entity or destroy all PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form. Business Associate shall retain no copies of such PHI. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, for as long as Business Associate maintains such PHI. For clarity, encrypted backups and archival logs retained solely for disaster recovery, security, or legal compliance may be infeasible to destroy immediately; such materials remain subject to this Agreement until securely overwritten in the ordinary course.

7. Security

Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI as required by the Security Rule. Business Associate will ensure that any agent, including a Subcontractor, to whom it provides ePHI agrees to implement reasonable and appropriate safeguards to protect such information.

8. Miscellaneous

  1. Regulatory references. A reference in this Agreement to a section in HIPAA means the section as in effect or as amended.
  2. Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with HIPAA and other applicable law. Business Associate may update this Agreement by publishing a new version at this URL and updating the version identifier used in Get Started; continued acceptance of a new version (via clickwrap or sales-agent confirmation) is required before go-live or continued processing under that version. Material changes will not apply retroactively to prior logged acceptances of earlier versions.
  3. Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with HIPAA.
  4. No third-party beneficiaries. Nothing in this Agreement confers upon any person other than the Parties and their respective successors or assigns any rights, remedies, obligations, or liabilities whatsoever.
  5. Relationship to Services Agreement. In the event of a conflict between this Agreement and the Services Agreement with respect to the use or disclosure of PHI, this Agreement controls. All other terms of the Services Agreement remain in effect.
  6. Governing law. This Agreement is governed by the laws of the United States and the State of Wyoming, without regard to conflict-of-law principles, except to the extent preempted by HIPAA or other federal law.
  7. Notices. Legal notices to Business Associate under this Agreement may be sent to [email protected] with a copy to Maps Health Network, LLC, Attn: Privacy / BAA, or such other address as Business Associate publishes. Notices to Covered Entity will be sent to the contacts provided during Get Started or in the Covered Entity's account.
  8. Entire agreement. This Agreement, together with the Services Agreement and any order form, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes prior BAAs between the Parties concerning the same Services, except that logged acceptances of prior versions remain valid historical records for the periods they governed.
  9. Counterparts / electronic acceptance. Electronic acceptance (including checkbox clickwrap and recorded voice confirmation by an authorized representative) constitutes execution of this Agreement and is intended to have the same legal effect as a handwritten signature.

Questions about this Agreement: [email protected]
Maps Health Network, LLC · GLP-1 Receptionist / Grace · Version 2026-08-04