Business Associate Agreement
Draft — attorney review pending.
Version 2026-09-01
This Business Associate Agreement ("Agreement") is entered into between the dental practice accepting it ("Covered Entity") and Tooth Fairy ("Business Associate"), and is effective on the date an authorized administrator of the Covered Entity accepts it in the Tooth Fairy application. It governs Business Associate's Creation, receipt, maintenance, and transmission of Protected Health Information ("PHI") on behalf of Covered Entity in connection with the Tooth Fairy service. The provisions below are based on the model language published by the U.S. Department of Health and Human Services.
1. Definitions
Terms used but not otherwise defined in this Agreement have the meanings given to them in the HIPAA Rules. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164. "Protected Health Information" or "PHI" is limited to PHI Created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
2. Obligations and Activities of Business Associate
Business Associate agrees to:
- Not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law.
- Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
- Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required by 45 CFR 164.410, and any Security Incident of which it becomes aware. Business Associate will report a Breach without unreasonable delay and in no case later than 60 calendar days after discovery, and will provide the information the Covered Entity needs to meet its own notification obligations.
- Ensure that any subcontractors that Create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such PHI.
- Make PHI available in a Designated Record Set to the extent and in the manner required to satisfy Covered Entity's obligations under 45 CFR 164.524 (individual access).
- Make available PHI for amendment and incorporate any amendments to PHI as required to satisfy Covered Entity's obligations under 45 CFR 164.526.
- Maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy Covered Entity's obligations under 45 CFR 164.528.
- To the extent Business Associate is to carry out one or more of Covered Entity's obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.
- Make its internal practices, books, and records available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules.
3. Permitted Uses and Disclosures by Business Associate
- Business Associate may only use or disclose PHI as necessary to perform the services described in the Tooth Fairy Terms of Service, or as Required by Law.
- Business Associate may use or disclose PHI as Required by Law.
- Business Associate agrees to make uses, disclosures, and requests for PHI consistent with Covered Entity's minimum necessary policies and procedures.
- Business Associate may not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except that Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, and may disclose PHI for those purposes only if the disclosure is Required by Law, or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
- Business Associate may use PHI to provide Data Aggregation services relating to the Health Care Operations of Covered Entity where permitted, and may de-identify PHI in accordance with 45 CFR 164.514(a)-(c).
4. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions
- Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.
- Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an individual to use or disclose their PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.
- Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.
5. Permissible Requests by Covered Entity
Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as set forth in Section 3.4 for Business Associate's management and administration and data aggregation and de-identification services.
6. Term and Termination
- Term. This Agreement is effective on acceptance and remains in effect until all PHI is destroyed or returned to Covered Entity, or, if return or destruction is infeasible, protections are extended to such PHI in accordance with Section 6.3.
- Termination for Cause. Covered Entity may terminate this Agreement and the underlying service if Business Associate materially breaches this Agreement and fails to cure the breach within a reasonable time, consistent with 45 CFR 164.504(e)(2)(iii).
- Obligations upon Termination. Upon termination, Business Associate shall, if feasible, return or destroy all PHI received from, or Created or received by Business Associate on behalf of, Covered Entity, and retain no copies. Where return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to the PHI, and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains the PHI.
- Survival. The obligations of Business Associate under this Section survive termination of this Agreement.
7. Miscellaneous
- Regulatory References. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.
- Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the HIPAA Rules. A new version will be published and re-acceptance required.
- Interpretation. Any ambiguity in this Agreement shall be resolved to permit compliance with the HIPAA Rules.
This Agreement is accepted electronically. A record of acceptance — including the accepting administrator, the covered practice, the date and time, the IP address, and this document version — is retained by Business Associate as the signed record of this Agreement.