HatchLink Health
LEGAL

Business Associate Agreement

By HatchLink Legal TeamLast Updated July 14, 2026

Last Updated: July 14, 2026

This Business Associate Agreement (“BAA”) applies if Customer is a HIPAA-covered entity or business associate and HatchLink will create, receive, maintain, or transmit Protected Health Information on Customer’s behalf through the HatchLink platform (the “Service”). This BAA is incorporated into and supplements the HatchLink Master Terms (the “Agreement”). Capitalized terms not defined here have the meanings given in the Agreement or in 45 C.F.R. Parts 160 and 164 (the “HIPAA Rules”).

1. Definitions

“Covered Entity” means Customer.

“Business Associate” means HatchLink Edu, LLC.

“PHI” means Protected Health Information created, received, maintained, or transmitted by HatchLink for or on behalf of Customer through the Service.

“Electronic PHI” or “ePHI” means PHI that is transmitted or maintained in electronic media.

“Security Incident” has the meaning given in 45 C.F.R. § 164.304.

“Breach” has the meaning given in 45 C.F.R. § 164.402.

2. Permitted Uses and Disclosures of PHI

HatchLink may use and disclose PHI only as follows:

  • To perform the services described in the Agreement and any Activation Form;
  • For HatchLink’s proper management and administration, or to carry out HatchLink’s legal responsibilities, provided that any disclosure for such purposes is either (a) required by law, or (b) made to a recipient that agrees in writing to confidentiality and breach-notification obligations at least as protective as those in this BAA and to use the information only for the purpose for which it was disclosed;
  • To provide data aggregation services relating to the health care operations of Customer, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B); and
  • To de-identify PHI in accordance with 45 C.F.R. § 164.514(b), after which the resulting data is no longer PHI and may be used by HatchLink for any lawful purpose.

HatchLink will not sell PHI as defined in the HITECH Act and will not use or disclose PHI for marketing, fundraising, or underwriting purposes except as expressly permitted by the HIPAA Rules and authorized in writing by Customer.

3. Safeguards

HatchLink will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, in compliance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) and the HITECH Act. HatchLink’s current security posture is described in the Security Overview.

HatchLink will, among other things:

  • Encrypt ePHI in transit (TLS 1.2 or higher) and at rest (AES-256);
  • Implement access controls limiting access to PHI to personnel who require it to perform services under the Agreement;
  • Maintain audit controls that record and examine access to ePHI; and
  • Conduct periodic risk assessments of its safeguards and remediate identified risks.

4. Reporting

4.1 Security Incidents

HatchLink will report to Customer any Security Incident of which it becomes aware. The parties acknowledge that unsuccessful security incidents—including pings, port scans, denial-of-service attempts that do not result in unauthorized access, and failed login attempts that do not result in compromise—occur routinely and do not require individual notification. This Section 4.1 serves as HatchLink’s advance notice of such unsuccessful incidents.

4.2 Breach of Unsecured PHI

HatchLink will notify Customer in writing of any Breach of Unsecured PHI without unreasonable delay, and in no case later than thirty (30) calendar days after discovery of the Breach. The notice will include, to the extent known at the time:

  • The nature of the Breach, including the types of PHI involved;
  • The individuals whose PHI is or is reasonably believed to have been affected;
  • A description of what HatchLink is doing to investigate, mitigate, and prevent recurrence; and
  • The information required by 45 C.F.R. § 164.410.

HatchLink will cooperate with Customer’s investigation and will bear the reasonable costs of investigation and remediation to the extent the Breach results from HatchLink’s acts or omissions.

4.3 Impermissible Uses or Disclosures

HatchLink will report to Customer any use or disclosure of PHI not permitted by this BAA without unreasonable delay after discovery.

5. Subcontractors

HatchLink will require any subcontractor that creates, receives, maintains, or transmits PHI on HatchLink’s behalf to agree in writing to restrictions and conditions at least as protective as those in this BAA, in accordance with 45 C.F.R. § 164.502(e)(1)(ii) and § 164.308(b)(2). A list of HatchLink’s current subprocessors is maintained at hatchlinkhealth.com/subprocessors.

6. Individual Rights

6.1 Access

Within fifteen (15) business days of Customer’s written request, HatchLink will make PHI in a Designated Record Set available to Customer (or, as directed by Customer, to the individual) in an electronic format readily producible by the Service, to facilitate Customer’s obligations under 45 C.F.R. § 164.524.

6.2 Amendment

HatchLink will incorporate amendments to PHI in a Designated Record Set as directed by Customer in accordance with 45 C.F.R. § 164.526, within fifteen (15) business days of Customer’s written request.

6.3 Accounting of Disclosures

HatchLink will maintain and make available to Customer information required to provide an accounting of disclosures in accordance with 45 C.F.R. § 164.528. HatchLink will provide such information within thirty (30) days of Customer’s written request.

6.4 Restrictions and Confidential Communications

HatchLink will accommodate reasonable requests by Customer to restrict uses or disclosures of PHI or to direct confidential communications to the extent required by the HIPAA Rules, provided that such requests are technically feasible within the Service.

7. Access by HHS

HatchLink will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules, subject to applicable legal privileges.

8. Term and Termination

8.1 Term

This BAA is effective on the Effective Date of the Agreement and continues until the earlier of (a) termination of the Agreement, or (b) the date on which all PHI has been returned or destroyed in accordance with Section 8.3.

8.2 Termination for Material Breach

If either party knows of a pattern of activity or practice of the other party that constitutes a material breach of this BAA, it will provide written notice and a thirty (30) day opportunity to cure. If the breach is not cured within the cure period, the non-breaching party may terminate the Agreement. Notwithstanding the foregoing, no cure period applies to a Breach of Unsecured PHI; in such event, the non-breaching party may terminate the Agreement immediately upon written notice.

8.3 Return or Destruction of PHI

On termination of the Agreement, HatchLink will:

  • Make PHI available for Customer export for forty-five (45) days after the termination date;
  • After the export period, securely destroy all PHI in its possession, including PHI held by subcontractors, using industry-standard methods; and
  • Certify destruction in writing on Customer’s request.

If return or destruction is not feasible (for example, because PHI is embedded in backup media that cannot be selectively purged), HatchLink will continue to protect the PHI under this BAA, limit further use and disclosure to those purposes that make return or destruction infeasible, and allow the data to age out of backup systems in the ordinary course.

9. Minimum Necessary

HatchLink will, to the extent required by the HIPAA Rules, limit its use, disclosure, and request of PHI to the minimum necessary to accomplish the intended purpose, except as otherwise permitted under 45 C.F.R. § 164.502(b)(2).

10. Miscellaneous

This BAA will be interpreted to permit compliance with the HIPAA Rules, including the HIPAA Privacy Rule, Security Rule, Breach Notification Rule, and the Enforcement Rule, as amended from time to time, including amendments under the HITECH Act (42 U.S.C. §§ 17921–17954) and successor laws. To the extent that any provision of this BAA is ambiguous, it will be interpreted in a manner consistent with the HIPAA Rules.

In the event of a conflict between this BAA and the Master Terms with respect to the use, disclosure, or protection of PHI, this BAA controls.

Any amendment to the HIPAA Rules that materially changes the obligations of either party under this BAA will be incorporated automatically upon the applicable compliance date, and the parties will cooperate in good faith to update this BAA as necessary.

11. Governing Law and Dispute Resolution

This BAA is governed by the laws of the State of Texas, without regard to its conflict-of-laws principles. Any dispute arising out of or relating to this BAA that is not resolved through good-faith negotiation will be brought exclusively in the state or federal courts located in Travis County, Texas, and each party consents to the personal jurisdiction and venue of such courts.

Governing Agreement. This BAA is part of the HatchLink Master Terms. For questions about this BAA or HatchLink’s HIPAA compliance program, contact privacy@hatchlinkhealth.com.