Legal Document
BUSINESS ASSOCIATE AGREEMENT.
Governing the protection and handling of Protected Health Information (PHI) in accordance with HIPAA requirements.
At Built By Veterans, we are committed to maintaining the security and confidentiality of all Protected Health Information and sensitive client data entrusted to us in the course of delivering IT services. This Business Associate Agreement ("BAA" or "Agreement") governs the obligations of Built By Veterans LLC ("Business Associate," "we," "us," or "our") and the organization engaging our services ("Covered Entity" or "you") with respect to any Protected Health Information ("PHI") accessed, received, maintained, or transmitted by us in the performance of IT services. If you have any questions or concerns about this Agreement, or our practices with regards to the handling of PHI, please contact us at info@builtbyveterans.ai.
When you engage Built By Veterans to deliver software development, cloud engineering, managed support, or related IT services, we appreciate that you are trusting us with systems and data that may include sensitive personal and health information. We take that responsibility very seriously. This Agreement applies to all PHI processed through our Services, as well as any related support, maintenance, or operational activities. If there are any terms in this Agreement that you do not agree with, please discontinue use of our Services immediately.
Definitions
In short: The key terms that govern this Agreement and how they apply to our IT services.
For purposes of this Agreement, the following terms have the meanings set forth below. Where a term is not specifically defined, it carries the meaning assigned to it under HIPAA, HITECH, and applicable implementing regulations at 45 CFR Parts 160 and 164.
Business Associate refers to Built By Veterans LLC, a software development and cloud engineering firm providing IT services including custom software development, AWS cloud architecture, security-minded engineering, and managed technical support.
Covered Entity refers to any healthcare provider, health plan, healthcare clearinghouse, or other organization subject to HIPAA that has engaged Built By Veterans LLC for IT services under a written service agreement.
Protected Health Information (PHI) means individually identifiable health information transmitted or maintained by Built By Veterans LLC in any form — electronic, paper, or oral — in the performance of services for the Covered Entity, as defined under 45 CFR § 160.103.
Electronic PHI (ePHI) means PHI that is created, received, maintained, or transmitted in electronic form and subject to the HIPAA Security Rule at 45 CFR Part 164, Subpart C.
Services means any IT services provided by Built By Veterans LLC, including but not limited to web application development, API integrations, AWS infrastructure design and management, CI/CD pipeline configuration, security engineering, and ongoing managed technical support.
Breach means the acquisition, access, use, or disclosure of PHI in a manner not permitted by this Agreement or applicable law that compromises the security or privacy of such information, as defined under 45 CFR § 164.402.
Security Incident means any attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations in an information system, as defined under 45 CFR § 164.304.
Subcontractor means any third party engaged by Built By Veterans LLC to perform functions on its behalf that involve the creation, receipt, maintenance, or transmission of PHI on behalf of the Covered Entity.
Permitted Uses and Disclosures
In short: We use and disclose PHI only as necessary to deliver your IT services and as required by law — never for marketing or promotional purposes.
Built By Veterans LLC may use or disclose PHI only as necessary to perform contracted IT services for the Covered Entity and as otherwise permitted or required by law. Permitted activities include:
Services DeliveryWe may access and process PHI solely to develop, deploy, and maintain software systems; design and operate cloud infrastructure; provide technical support; and conduct security monitoring and incident response activities on systems that store or transmit PHI on behalf of the Covered Entity.
Data Management ActivitiesWe may use PHI to perform data processing, migration, backup, and integration tasks required by the Covered Entity to operate its systems. This includes database administration, system testing using de-identified or masked data where feasible, and infrastructure maintenance activities.
Legal and Regulatory RequirementsWe may disclose PHI as required by law, including in response to valid legal process, governmental requests, a judicial proceeding, court order, or legal process, to the extent required by 45 CFR § 164.512. We will make reasonable efforts to notify the Covered Entity prior to any such disclosure where permitted by law.
No PHI or personal information will be shared with third parties or affiliates for marketing or promotional purposes. All categories of information covered by this Agreement exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We will not use or disclose PHI for any purpose not expressly authorized under this Agreement or required by law, and all PHI access is limited to the minimum necessary standard.
Obligations of Built By Veterans
In short: We commit to protecting PHI through robust safeguards, strict access controls, and full compliance with HIPAA requirements.
In connection with any PHI received, maintained, or transmitted in the performance of IT services, Built By Veterans LLC agrees to the following obligations:
- Not use or disclose PHI other than as permitted or required by this Agreement or as required by applicable law.
- Implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI, including ePHI, in accordance with 45 CFR Part 164, Subpart C.
- Ensure that any agents or Subcontractors who create, receive, maintain, or transmit PHI on our behalf agree in writing to the same restrictions and conditions regarding PHI that apply to us under this Agreement.
- Report to the Covered Entity any use or disclosure of PHI not permitted under this Agreement, including any Breach of unsecured PHI, without unreasonable delay and in no case later than 60 calendar days following discovery, as required by 45 CFR § 164.410.
- Report to the Covered Entity any Security Incident of which we become aware, including patterns of unsuccessful attempts to access systems containing PHI, in a manner consistent with our internal security monitoring practices.
- Make available PHI in a Designated Record Set to the Covered Entity as necessary to fulfill obligations under 45 CFR § 164.524 (access), § 164.526 (amendment), and § 164.528 (accounting of disclosures).
- To the extent we carry out any obligation of the Covered Entity under the HIPAA Privacy Rule, comply with the requirements of the Privacy Rule that apply to the Covered Entity in the performance of such obligation.
- Make our internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance, as required under 45 CFR § 164.504(e)(2)(ii)(I).
Security Safeguards
In short: We apply technical and organizational security measures designed to protect the systems and data we manage on your behalf.
Built By Veterans LLC applies security-minded engineering practices across all client engagements involving ePHI. Safeguards we implement include:
Access Controls and AuthenticationWe enforce least-privilege access policies, role-based access management, multi-factor authentication, and regular access reviews to ensure that only authorized personnel access systems containing PHI.
EncryptionePHI transmitted over networks is encrypted using TLS 1.2 or higher. ePHI at rest is protected using AES-256 or equivalent industry-standard encryption methods to prevent unauthorized access in the event of a security incident.
Audit Controls and LoggingWe implement centralized audit logging of system access events, configuration changes, and security-relevant activity. Logs are stored in tamper-resistant environments and retained for a period of up to 24 months or longer as required by applicable law.
Credential and Secrets ManagementApplication secrets, API keys, database credentials, and sensitive configuration values are stored exclusively in dedicated secrets management systems such as AWS Secrets Manager. No credentials are stored in source code repositories or transmitted insecurely.
Despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security, and improperly collect, access, steal, or modify PHI. Although we will do our best to protect your PHI, transmission of data to and from our systems is at the Covered Entity's risk. You should only access our systems and services within a secure environment.
Obligations of the Covered Entity
In short: You agree to notify us of relevant privacy practice limitations and not request uses of PHI that would be impermissible under HIPAA.
The Covered Entity agrees to notify Built By Veterans LLC of any limitation in its Notice of Privacy Practices that may affect our ability to use or disclose PHI in the performance of services, of any changes in or revocation of individual authorization to use or disclose PHI that may affect our permitted uses, and of any restrictions agreed to under 45 CFR § 164.522 that may affect our use or disclosure of PHI.
The Covered Entity shall not request Built By Veterans LLC to use or disclose PHI in any manner that would not be permissible under the HIPAA Privacy Rule if done by the Covered Entity directly, except as authorized under this Agreement.
The Covered Entity is responsible for obtaining all necessary authorizations, consents, and approvals required to share PHI with Built By Veterans LLC in connection with the services, and for providing timely access to systems, documentation, and personnel required for us to fulfill our obligations under this Agreement.
Subcontractors
In short: Any subcontractor we engage to assist with your services is bound by the same data protection requirements as we are.
Built By Veterans LLC may engage Subcontractors to assist in the delivery of IT services. Where such Subcontractors create, receive, maintain, or transmit PHI in the performance of their functions, we will:
- Require all Subcontractors handling PHI to execute a written business associate agreement imposing the same restrictions and conditions regarding PHI that apply to us under this Agreement, in accordance with 45 CFR § 164.502(e)(1)(ii).
- Conduct reasonable due diligence to assess the security and privacy practices of Subcontractors prior to granting access to systems or data containing PHI.
- Limit Subcontractor access to the minimum PHI necessary to perform their specific contracted function.
- Remain directly responsible to the Covered Entity for the acts and omissions of our Subcontractors to the extent required by applicable law.
Cloud infrastructure services provided through Amazon Web Services (AWS) are subject to AWS's HIPAA eligibility program and AWS's Business Associate Agreement with Built By Veterans LLC. AWS maintains applicable compliance certifications including SOC 2 and ISO 27001. We may share your information with our affiliates and business partners as required to deliver services, in which case we will require those parties to honor the terms of this Agreement.
Breach Notification
In short: We will notify you promptly of any breach involving PHI and cooperate fully in your response and regulatory reporting obligations.
Built By Veterans LLC will notify the Covered Entity without unreasonable delay, and in no case later than 60 calendar days following discovery of a Breach of unsecured PHI, as required by 45 CFR § 164.410. Notification will include, to the extent reasonably available at the time:
- A description of the nature of the Breach, including what occurred and the date of the Breach and the date of discovery.
- The types of PHI involved, such as names, dates, Social Security numbers, health information, or other identifiers as defined under 45 CFR § 164.402.
- The identities of individuals affected, if known, or a reasonable estimate of the number of individuals affected.
- A description of the steps we are taking to investigate the Breach, mitigate harm to affected individuals, and prevent future occurrences.
- Contact information for the Covered Entity to ask questions or receive updates as the investigation progresses.
We will also report to the Covered Entity any Security Incidents involving unsuccessful attempts to access, use, disclose, modify, or destroy PHI or systems containing PHI, which we will report in summary form as part of our regular security communications or upon request.
We will preserve all relevant logs, forensic evidence, and records related to any Breach or Security Incident and cooperate fully with any investigation, regulatory inquiry, or breach notification process undertaken by the Covered Entity or required by the Department of Health and Human Services.
Individual Rights
In short: We will support your ability to respond to individual requests for access, amendment, and accounting of disclosures of their PHI.
To the extent Built By Veterans LLC maintains PHI in a Designated Record Set on behalf of the Covered Entity, we will assist the Covered Entity in meeting its obligations to individuals under the HIPAA Privacy Rule, including:
Right of AccessWe will make available to the Covered Entity any PHI in a Designated Record Set necessary for the Covered Entity to fulfill its obligations under 45 CFR § 164.524, enabling individuals to inspect and obtain copies of their PHI upon request.
Right to AmendWe will make PHI available for amendment and incorporate any amendments to PHI directed or agreed to by the Covered Entity pursuant to 45 CFR § 164.526, to enable the Covered Entity to correct inaccurate or incomplete health information.
Accounting of DisclosuresWe will maintain and provide to the Covered Entity information relating to disclosures of PHI made by us that are not otherwise exempt, as necessary to enable the Covered Entity to provide an accounting of disclosures to individuals pursuant to 45 CFR § 164.528.
If you would at any time like to review, update, or request deletion of personal information we hold, please contact us using the information in Section 13 of this Agreement.
Information Storage and Retention
In short: We keep PHI only for as long as necessary to perform services or as required by law — no longer than 24 months.
We will only retain PHI for as long as it is necessary for the purposes set out in this Agreement, unless a longer retention period is required or permitted by law, such as for tax, accounting, audit, regulatory, or legal defense requirements. No purpose under this Agreement will require us to keep PHI for longer than 24 months following the termination of the applicable service engagement.
When we have no ongoing legitimate business need to process or retain PHI, we will either return or securely destroy the PHI in accordance with Section 10 of this Agreement. If immediate return or destruction is not possible — for example, because PHI has been stored in encrypted backup archives — then we will securely store and isolate that PHI from any further processing until return or destruction is possible.
Data Return and Destruction
In short: At the end of our engagement, we will return or securely destroy all PHI and provide written certification of destruction.
Upon termination or expiration of the service engagement, or upon written request by the Covered Entity, Built By Veterans LLC will, within 60 days, either return all PHI in a structured portable format agreed upon by both parties, or securely destroy all copies of PHI in our possession — including copies held by Subcontractors — using NIST SP 800-88 compliant media sanitization procedures. We will provide written certification of destruction to the Covered Entity upon completion.
If the return or destruction of any portion of PHI is not feasible — for example, because PHI has been stored in backup archives that cannot be selectively purged — we will notify the Covered Entity in writing, extend the protections of this Agreement to the retained PHI, and limit any further use or disclosure of that PHI to those purposes that make return or destruction infeasible, and for no other purpose.
Term and Termination
In short: This Agreement remains in effect for the duration of our services and includes provisions for termination for cause or convenience.
This Agreement is effective upon the commencement of IT services between Built By Veterans LLC and the Covered Entity and remains in effect for the duration of the service engagement unless terminated earlier as provided in this section.
Termination for CauseThe Covered Entity may terminate this Agreement if Built By Veterans LLC has materially violated a material term and has failed to cure such violation within 30 days of receiving written notice. Where cure is not possible, the Covered Entity may report the violation to the Secretary of Health and Human Services pursuant to 45 CFR § 164.504(e)(1)(ii).
Termination for ConvenienceEither party may terminate this Agreement upon 30 days' prior written notice, subject to any applicable terms of the underlying service agreement. Termination of this Agreement does not automatically terminate the underlying service agreement unless expressly agreed in writing.
Effect of TerminationUpon any termination of this Agreement, Section 10 (Data Return and Destruction) shall apply immediately. Obligations that by their nature survive termination — including those relating to PHI received or created prior to the termination date — shall survive until all PHI in our possession has been returned or destroyed in accordance with this Agreement.
Agreement Updates
In short: Yes, we will update this Agreement as necessary to stay compliant with HIPAA, HITECH, and other applicable laws.
We may update this Business Associate Agreement from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this Agreement, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Agreement frequently to be informed of how we are protecting your information and fulfilling our compliance obligations under applicable law.
Continued use of Built By Veterans' IT services following the effective date of an amended Agreement constitutes the Covered Entity's acceptance of the updated terms. If you do not agree to any amendment, you may terminate the service engagement pursuant to Section 11 of this Agreement. Any amendment must be made in writing to be binding, and no verbal amendments to this Agreement are effective.
Contact Information
In short: Reach out to us with any questions or concerns about this Agreement or our data handling practices.
If you have questions or comments about this Agreement, wish to execute a countersigned copy, or need to discuss custom BAA terms for your organization's specific compliance requirements, please contact us at:
Built By Veterans LLC
Email: info@builtbyveterans.ai
Website: https://builtbyveterans.ai/
Based on applicable laws, you or the individuals whose PHI we process may have the right to request access to that information, request that it be corrected or amended, or request its deletion in certain circumstances. To request to review, update, or delete protected health information we hold, please submit a request by emailing us at info@builtbyveterans.ai.