# BUSINESS ASSOCIATE AGREEMENT

**CUSTOMER AGREEMENT TEMPLATE - COMPLETE ALL BRACKETED FIELDS BEFORE SIGNATURE**

**Effective Date:** [[BAA EFFECTIVE DATE]]

This Business Associate Agreement (“BAA”) is entered into by and between **[[CUSTOMER LEGAL NAME]]** (“Covered Entity” or “Customer”) and **RSBB Group LLC**, an Ohio limited liability company doing business as **MyJourney** (“Business Associate”).

This BAA supplements and is incorporated into the Master Services Agreement, Order Form, or other written services agreement between the parties (collectively, the “Services Agreement”).

## 1. Purpose

Customer may disclose Protected Health Information (“PHI”) to Business Associate, and Business Associate may create, receive, maintain, or transmit PHI on Customer’s behalf in connection with the MyJourney software platform and related services.

The parties intend this BAA to satisfy the applicable requirements of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and their implementing regulations.

## 2. Definitions

Capitalized terms not otherwise defined in this BAA have the meanings assigned to them under HIPAA and its implementing regulations, including:

- **Breach**
- **Electronic Protected Health Information (“ePHI”)**
- **Individual**
- **Protected Health Information (“PHI”)**
- **Required by Law**
- **Security Incident**
- **Subcontractor**
- **Unsecured Protected Health Information**

“Services” means the MyJourney platform and related services provided to Customer under the Services Agreement.

## 3. Permitted Uses and Disclosures of PHI

Business Associate may use or disclose PHI only:

1. as necessary to provide the Services to Customer;
2. as expressly permitted by the Services Agreement and this BAA;
3. as Required by Law;
4. for Business Associate’s proper management and administration or to carry out its legal responsibilities, provided any disclosure is Required by Law or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and be used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality of which it becomes aware; and
5. for data aggregation relating to Customer’s health care operations, but only to the extent permitted by HIPAA and agreed by the parties.

Business Associate shall not use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Customer, except as expressly permitted for a business associate under HIPAA.

## 4. Prohibited Uses

Business Associate shall not:

- sell PHI;
- use PHI for targeted advertising or independent marketing;
- use Customer PHI to build or enrich unrelated commercial profiles;
- disclose PHI to a third party except as permitted by this BAA, the Services Agreement, or Required by Law; or
- use PHI or PHI-derived de-identified data for external publication, licensing, commercial data products, or AI model training outside the Services unless expressly authorized in writing by Customer and permitted by applicable law.

## 5. De-Identification and Data Aggregation

Business Associate may perform data aggregation relating to Customer’s health care operations only to the extent permitted by HIPAA, this BAA, and the Services Agreement.

Business Associate may create or use de-identified information derived from PHI only as necessary to provide, secure, maintain, or improve the Services, or as otherwise expressly authorized in writing by Customer. Any de-identification of PHI shall use a method recognized under HIPAA, such as Safe Harbor or Expert Determination, as applicable, and Business Associate shall document the method used. Business Associate shall not attempt to re-identify de-identified information except as permitted by law and expressly authorized in writing for validation, security, or compliance purposes.

## 6. Safeguards

Business Associate shall implement appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI and ePHI and to prevent uses or disclosures not permitted by this BAA.

Business Associate shall comply with the applicable requirements of the HIPAA Security Rule with respect to ePHI.

## 7. Minimum Necessary

To the extent applicable, Business Associate shall limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose, consistent with HIPAA and Customer’s reasonable instructions.

## 8. Reporting of Impermissible Uses, Disclosures, Breaches, and Security Incidents

Business Associate shall notify Customer of:

- any use or disclosure of PHI not permitted by this BAA;
- any Breach of Unsecured PHI; and
- any Security Incident involving unauthorized access, use, disclosure, modification, or destruction of ePHI of which Business Associate becomes aware,

in each case as required by HIPAA.

For a Breach of Unsecured PHI, Business Associate shall provide notice without unreasonable delay and, unless a shorter period is required by applicable law or the Services Agreement, no later than five (5) business days after Business Associate confirms that a Breach occurred. The notice shall include, to the extent known, the identification of affected Individuals and the information reasonably required for Customer to satisfy its breach-notification obligations.

The parties may document routine unsuccessful security events that do not result in unauthorized access, use, disclosure, modification, or destruction of ePHI as reported on an aggregate basis or otherwise addressed through the Services Agreement.

## 9. Subcontractors

Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions, conditions, and safeguards that are at least as protective as those applicable to Business Associate under this BAA, including applicable HIPAA Security Rule requirements.

Business Associate shall maintain an appropriate process for evaluating and managing Subcontractors that handle PHI. Business Associate shall maintain a list of material Subcontractors that handle PHI and make that list available to Customer upon request or as otherwise specified in the Services Agreement.

## 10. Access to PHI

To the extent Business Associate maintains PHI in a Designated Record Set on behalf of Customer, Business Associate shall make such PHI available to Customer, or as directed by Customer to an Individual, as necessary for Customer to satisfy its obligations under 45 C.F.R. § 164.524.

Business Associate may require that requests from Individuals be routed through Customer unless otherwise required by law or agreed in writing.

## 11. Amendment of PHI

To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make PHI available for amendment and incorporate amendments as directed by Customer in accordance with 45 C.F.R. § 164.526.

## 12. Accounting of Disclosures

Business Associate shall document and make available to Customer information regarding disclosures of PHI as necessary for Customer to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528.

## 13. Customer Privacy Rule Obligations Performed by Business Associate

To the extent Business Associate is expressly delegated responsibility to carry out one or more of Customer’s obligations under the HIPAA Privacy Rule, Business Associate shall comply with the requirements of the Privacy Rule that apply to Customer in the performance of those obligations.

## 14. Government Access

Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Customer available to the U.S. Department of Health and Human Services as required for determining compliance with HIPAA.

## 15. Customer Obligations

Customer shall:

- use the Services in compliance with applicable law;
- configure user access and permissions appropriately;
- provide Business Associate only the PHI reasonably necessary for the Services;
- not request Business Associate to use or disclose PHI in a manner that would violate HIPAA if done by Customer;
- notify Business Associate of relevant restrictions, revocations, or changes to permissions that affect Business Associate’s permitted use or disclosure of PHI; and
- maintain its own policies, notices, authorizations, consents, and legal bases required for its use of the Services.

## 16. Term and Termination

This BAA begins on the BAA Effective Date and continues for so long as Business Associate creates, receives, maintains, or transmits PHI on behalf of Customer.

Customer may terminate the Services Agreement for a material violation of this BAA if Business Associate fails to cure the violation within thirty (30) days after written notice, if cure is possible. Customer may terminate earlier if cure is not possible or if applicable law requires earlier termination.

If termination is not feasible, the parties shall take reasonable steps consistent with HIPAA to address the violation.

## 17. Return or Destruction of PHI

Upon termination of the Services Agreement, Business Associate shall, if feasible, return or destroy PHI received from Customer or created, maintained, or received on Customer’s behalf within the timeframe specified in the Services Agreement or, if none is specified, within thirty (30) days after the applicable export or transition period. Business Associate shall retain no copies, except to the extent retention is Required by Law or return or destruction is infeasible.

If return or destruction is infeasible or retention is legally required, Business Associate shall continue to protect the retained PHI under this BAA and limit further uses and disclosures to the purpose that makes return or destruction infeasible or legally required.

## 18. Interpretation

Any ambiguity in this BAA shall be interpreted to permit the parties to comply with HIPAA.

If a provision of the Services Agreement conflicts with this BAA regarding the use, disclosure, or safeguarding of PHI, this BAA controls with respect to PHI.

## 19. Regulatory Changes

The parties shall amend this BAA as reasonably necessary to comply with material changes in applicable HIPAA requirements.

## 20. No Third-Party Beneficiaries

Except as required by applicable law, this BAA does not create rights in any person or entity other than the parties.

## 21. Governing Law

Except to the extent preempted by federal law, this BAA is governed by the law specified in the Services Agreement.

---

## SIGNATURES

### COVERED ENTITY / CUSTOMER

**Legal Name:** [[CUSTOMER LEGAL NAME]]

**By:** ______________________________________

**Name:** ____________________________________

**Title:** _____________________________________

**Date:** _____________________________________

### BUSINESS ASSOCIATE

**RSBB Group LLC d/b/a MyJourney**

**By:** ______________________________________

**Name:** Ronald S. Baer

**Title:** Sole Member / Authorized Representative

**Date:** _____________________________________
