Skip to the content
The operating system for desk work that lives in files
Try a sample
Legal · effective 2026-09-23

Business Associate Agreement

Effective 2026-09-23.

How to request this agreement

Some BaseLoom tools work on healthcare documents, such as claims, chargemasters and pharmacy rebate files. If you are a HIPAA covered entity or business associate and want to use those tools with protected health information (PHI), you need a Business Associate Agreement ("BAA") with us first.

  • To request one, email legal@baseloom.app with your organization's legal name, address, the tools you plan to use, and a signatory's name and title.
  • We countersign a BAA only after our hosting provider's business associate agreement (Microsoft Azure) is in place for our account. If it is not yet in place when you ask, we will tell you and will not sign until it is.
  • We will send the agreement below for signature. We do not accept changes to it except where required by law; we will consider reasonable requests.
  • You must not upload PHI to any tool until this BAA has been signed by both parties. Until then, use only de-identified data (as defined in 45 CFR 164.514) or the free sample data. The health tools ask you to confirm this before you upload a file.
  • A BAA covers PHI in files you process in the tools. It does not cover support emails. Please do not send PHI to support, in the body of an email or as an attachment.

The template follows.


Business Associate Agreement

This Business Associate Agreement ("Agreement") is between the organization named in the signature block ("Covered Entity", which includes a business associate acting for its own covered entity) and BaseLoom, a sole proprietorship based in India ("Business Associate"). The proprietor is named on the signed copy.

It supplements the BaseLoom Terms of Service and Data Processing Addendum ("Underlying Agreement").

1. Definitions

1.1 Terms used but not defined here have the meanings in the HIPAA Rules, including: Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information ("PHI"), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured PHI, and Use.

1.2 HIPAA Rules means the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164, as amended, including by the HITECH Act.

1.3 PHI in this Agreement means PHI that Business Associate creates, receives, maintains or transmits on behalf of Covered Entity.

2. How PHI is processed

2.1 Business Associate processes PHI only in server memory, for the duration of the browser session in which Covered Entity uses a tool. PHI is not written to disk, not stored in a database, not included in backups, and not sent to any AI model provider or other third party other than the hosting provider named in section 5.3.

2.2 When the session ends, PHI is released from memory. Business Associate keeps no copy.

3. Permitted uses and disclosures

3.1 Business Associate may use and disclose PHI only as needed to perform the services in the Underlying Agreement, namely running the tools Covered Entity chooses on files Covered Entity provides, and as Required by Law.

3.2 Business Associate will not use or disclose PHI in a way that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity.

3.3 Business Associate will limit its uses and disclosures of PHI to the Minimum Necessary.

3.4 Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, and may disclose it for those purposes only if the disclosure is Required by Law, or Business Associate obtains reasonable assurances from the recipient that it will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality. Given section 2, Business Associate does not expect to make such uses.

3.5 Business Associate will not perform Data Aggregation services, de-identify PHI for its own purposes, or sell PHI, and will not use PHI for marketing.

4. Obligations of Business Associate

4.1 No other use. Business Associate will not use or further disclose PHI other than as permitted or required by this Agreement or as Required by Law.

4.2 Safeguards. Business Associate will use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 (the Security Rule) for Electronic PHI, to prevent use or disclosure of PHI other than as provided by this Agreement. The safeguards in place are described in Annex II of the Data Processing Addendum.

4.3 Reporting. Business Associate will report to Covered Entity:

  • (a) any use or disclosure of PHI not provided for by this Agreement of which it becomes aware;
  • (b) any Breach of Unsecured PHI, as required by 45 CFR 164.410;
  • (c) any Security Incident of which it becomes aware.

4.4 Timing and content of Breach notice. Business Associate will notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and in any case within 72 hours of discovery, which is within the 60-calendar-day maximum in 45 CFR 164.410. The notice will include, to the extent possible, the identity of each Individual affected and the other information Covered Entity needs to give notice under 45 CFR 164.404, supplemented as further information becomes available.

4.5 Unsuccessful Security Incidents. The parties agree that this section is notice of the ongoing existence of unsuccessful Security Incidents, such as pings, port scans, blocked log-in attempts and denial of service attempts that do not result in unauthorized access, use or disclosure of PHI. No further notice of those is required.

4.6 Mitigation. Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement.

4.7 Subcontractors. Under 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate. See section 5.3.

4.8 Access. Within 15 business days of a request by Covered Entity, Business Associate will make available PHI in a Designated Record Set as needed for Covered Entity to meet 45 CFR 164.524. Because Business Associate holds no PHI after a session ends, it will normally confirm in writing that it holds none.

4.9 Amendment. Within 15 business days of a request, Business Associate will make any amendment to PHI in a Designated Record Set that Covered Entity directs under 45 CFR 164.526, or confirm that it holds none.

4.10 Accounting. Business Associate will document disclosures of PHI, and within 15 business days of a request provide the information Covered Entity needs to give an accounting of disclosures under 45 CFR 164.528.

4.11 Covered Entity's obligations. To the extent Business Associate carries out any of Covered Entity's obligations under Subpart E of 45 CFR Part 164, it will comply with the requirements of Subpart E that apply to Covered Entity in performing them.

4.12 Books and records. Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary for determining compliance with the HIPAA Rules.

5. Location and subcontractors

5.1 Business Associate is a sole proprietorship run by one individual located in India. PHI is processed on servers in the United States (Microsoft Azure, East US 2 (United States)). Business Associate may access those servers from India for administration, but does not view or copy PHI except as needed to fix a fault at Covered Entity's written request.

5.2 Covered Entity acknowledges these locations and agrees to them.

5.3 The only Subcontractor that handles PHI is Microsoft Corporation (Microsoft Azure), as hosting provider, under Microsoft's own business associate agreement with Business Associate. Business Associate will give Covered Entity at least 30 days' notice before adding another Subcontractor that would handle PHI, and Covered Entity may terminate under section 8 if it objects.

6. Obligations of Covered Entity

6.1 Covered Entity will tell Business Associate of any limitation in its Notice of Privacy Practices, any change or revocation of an Individual's permission, and any restriction on use or disclosure it has agreed to, to the extent it may affect Business Associate's use or disclosure of PHI.

6.2 Covered Entity will not ask Business Associate to use or disclose PHI in any way that would not be permitted under Subpart E of 45 CFR Part 164 if done by Covered Entity.

6.3 Covered Entity will upload only the PHI needed for the tool used, and will use the tools listed in its BAA request.

7. Term

7.1 This Agreement starts when signed by both parties and continues until the Underlying Agreement ends, unless terminated earlier under section 8.

8. Termination

8.1 For breach. If Covered Entity determines that Business Associate has violated a material term of this Agreement, Covered Entity may either give Business Associate 30 days to cure and terminate if it does not, or terminate immediately if cure is not possible.

8.2 By Business Associate. Business Associate may terminate this Agreement if Covered Entity breaches a material term and does not cure it within 30 days of notice. Covered Entity must then stop uploading PHI.

8.3 Effect. Termination of this Agreement ends Covered Entity's right to upload PHI. If Covered Entity keeps using health tools, it must use de-identified data only.

9. Return or destruction of PHI

9.1 On termination, Business Associate will return or destroy all PHI it still maintains in any form and keep no copies.

9.2 Because PHI is processed only in memory for a session (section 2), Business Associate expects to hold no PHI at termination, and will confirm this in writing on request.

9.3 If return or destruction is ever not feasible, Business Associate will extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it maintains the PHI.

10. Miscellaneous

10.1 Interpretation. Any ambiguity is resolved to permit compliance with the HIPAA Rules.

10.2 Amendment. The parties will amend this Agreement as needed to comply with changes in the HIPAA Rules.

10.3 Survival. Sections 4.1, 4.2, 4.3, 4.12 and 9 survive termination.

10.4 No third-party beneficiaries. Nothing here gives any right to anyone other than the parties.

10.5 Precedence. If this Agreement conflicts with the Underlying Agreement on PHI, this Agreement prevails.

10.6 Liability. Liability under this Agreement is subject to the limitations in the Terms of Service, except where law does not allow them.

10.7 Notices to Business Associate go to legal@baseloom.app. The postal address for notices is on the signed copy.

Signatures

Covered EntityBusiness Associate
Legal name:BaseLoom, a sole proprietorship
Signature:Signature:
Name and title:Name and title: the Proprietor (named on the signed copy)
Date:Date: