Back to Compliance

RepLogix Business Associate Agreement (BAA) Template

Effective Date: August 8, 2026

This Business Associate Agreement (BAA) template is provided for organizations that require HIPAA compliance. RepLogix is prepared to execute a BAA with covered entities or business associates when RepLogix's services will be used in a manner that involves Protected Health Information (PHI). This template is provided for reference; the final agreement will be customized to the specific relationship.

1. Purpose

This BAA template establishes the obligations of RepLogix ("Business Associate") and the covered entity or its business associate ("Covered Entity") when RepLogix processes, stores, or transmits Protected Health Information (PHI) on behalf of the Covered Entity, as required under the HIPAA Privacy and Security Rules (45 CFR Parts 160 and 164).

2. Definitions

  • "PHI" means Protected Health Information as defined under HIPAA — individually identifiable health information transmitted or maintained in any form.
  • "Covered Entity" means the organization that engages RepLogix to perform services involving PHI.
  • "Business Associate" means RepLogix, acting on behalf of the Covered Entity.
  • "Breach" means the acquisition, access, use, or disclosure of PHI not permitted under HIPAA.

3. Obligations of RepLogix (Business Associate)

RepLogix agrees to:

  • Use and disclose PHI only as permitted by this Agreement or as required by law
  • Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI
  • Use safeguards equivalent to those required under the HIPAA Security Rule (45 CFR §164.308, §164.310, §164.312)
  • Ensure that any subcontractors that receive PHI agree to the same restrictions and conditions
  • Report any Breach of unsecured PHI to the Covered Entity without unreasonable delay and no later than 60 days after discovery
  • Make available PHI for amendment and account for disclosures as required by the Covered Entity
  • Comply with the HIPAA Security Rule with respect to electronic PHI (ePHI)
  • Return or destroy all PHI upon termination of this Agreement, where feasible

4. Permitted Uses and Disclosures

RepLogix may use or disclose PHI only as necessary to perform the services described in the underlying service agreement, or as required by law. RepLogix will not use or disclose PHI for any independent purpose not authorized by the Covered Entity.

5. Security Safeguards

RepLogix implements the following safeguards for ePHI:

  • Administrative: Risk assessments, workforce training, incident response procedures, access management
  • Physical: Managed by Base44 infrastructure (SOC 2 Type II, ISO 27001 certified data centers, US-based)
  • Technical: TLS 1.2+ encryption in transit, encryption at rest, RBAC, MFA for privileged access, audit logging

6. Breach Notification

In the event of a Breach of unsecured PHI:

  • RepLogix will notify the Covered Entity without unreasonable delay and no later than 60 days after discovery
  • Notification will include the nature of the Breach, types of information involved, affected individuals (if known), steps taken to mitigate, and steps the Covered Entity can take
  • RepLogix will cooperate with the Covered Entity's breach notification obligations

7. Term and Termination

  • This BAA is effective as of the date of execution and remains in effect until termination of the underlying service agreement
  • Upon termination, RepLogix will return or destroy all PHI, where feasible
  • If return or destruction is not feasible, RepLogix will extend the protections of this BAA to the retained PHI and limit further uses and disclosures

8. Audit Rights

The Covered Entity may, upon reasonable notice, audit RepLogix's compliance with this BAA. RepLogix will make available relevant records and documentation. Alternatively, RepLogix may provide third-party audit reports (e.g., SOC 2) to satisfy audit requirements.

9. Limitation of Liability

RepLogix's liability under this BAA is limited to the liability provisions of the underlying service agreement. Nothing in this BAA limits either party's liability as required by applicable law.

10. Execution

To request a fully executed BAA, contact RepLogix. The BAA will be customized to the specific relationship, signed by authorized representatives of both parties, and retained as a formal agreement.