Legal
Business Associate Agreement
Effective date: July 9, 2026 ยท Version 2026-07-09
1. Parties and purpose
This Business Associate Agreement ("BAA") is between the customer organization identified in the applicable ImgVlt tenant account, order form, or invoice ("Customer") and the ImgVlt service provider identified in the applicable order form, invoice, or account record ("ImgVlt"). It becomes effective when an authorized Customer representative electronically accepts it or when the parties otherwise execute it.
Customer may be a Covered Entity or another Business Associate. ImgVlt is Customer's Business Associate or subcontractor Business Associate to the extent ImgVlt creates, receives, maintains, or transmits Protected Health Information ("PHI") for Customer in providing the ImgVlt Service. This BAA supplements the Terms of Service and any order form (collectively, the "Service Agreement").
2. Definitions
Capitalized terms not defined here have the meanings assigned in the Health Insurance Portability and Accountability Act of 1996 and its implementing Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Rules"). "Breach," "Business Associate," "Covered Entity," "Designated Record Set," "Electronic PHI," "Individual," "Security Incident," "Subcontractor," and "Unsecured PHI" have their HIPAA meanings.
3. Permitted uses and disclosures
ImgVlt may use and disclose PHI only as necessary to provide, host, secure, maintain, support, troubleshoot, and administer the Service; as expressly authorized by this BAA; as required by law; or as otherwise permitted by the HIPAA Rules and the Service Agreement. ImgVlt will not use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Customer, except for uses expressly permitted for a Business Associate's proper management and administration, legal responsibilities, or data aggregation.
ImgVlt will limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose, consistent with Customer's instructions and applicable law.
4. Express authorization to de-identify PHI
Customer expressly authorizes and directs ImgVlt to de-identify PHI in accordance with 45 C.F.R. 164.514(a)-(c), using Safe Harbor or Expert Determination as appropriate. ImgVlt may remove or transform identifiers in structured fields, free text, reports, DICOM headers, file metadata, burned-in annotations, image pixels, audio, video, and documents and may create non-identifying codes consistent with the HIPAA Rules.
Once information has been properly de-identified so that it neither identifies nor provides a reasonable basis to identify an individual, it is no longer PHI under HIPAA. ImgVlt may use, retain, combine, and disclose that de-identified information for service analytics, quality assurance, security, benchmarking, product development, scientific and operational research, and the development, training, testing, validation, and improvement of machine-learning and artificial-intelligence systems, as further described in the Terms and Privacy Policy.
Any vendor or research collaborator receiving de-identified information must be subject to written restrictions prohibiting re-identification or attempted re-identification, patient contact, patient-level advertising, sale of patient profiles, combining data for re-identification, and use outside the approved purpose. ImgVlt will not disclose any re-identification key or mechanism and will not use de-identified information to make treatment, eligibility, employment, insurance, or credit decisions about an identifiable person.
5. ImgVlt safeguards and obligations
ImgVlt will:
- not use or disclose PHI other than as permitted by this BAA or required by law;
- use appropriate safeguards and comply with the HIPAA Security Rule provisions applicable to Electronic PHI;
- mitigate, to the extent practicable, harmful effects known to ImgVlt from an impermissible use or disclosure;
- report to Customer any impermissible use or disclosure, Breach of Unsecured PHI, or material Security Incident of which ImgVlt becomes aware without unreasonable delay and no later than 10 business days after discovery, unless a shorter period is required by law or a signed order form;
- ensure that Subcontractors that create, receive, maintain, or transmit PHI for ImgVlt agree in writing to the same applicable restrictions, conditions, and safeguards;
- make PHI in a Designated Record Set available to Customer as reasonably necessary for Customer to satisfy 45 C.F.R. 164.524;
- make amendments to PHI as directed by Customer and reasonably necessary under 45 C.F.R. 164.526;
- maintain information required for Customer to provide an accounting of disclosures under 45 C.F.R. 164.528;
- comply with Privacy Rule requirements that apply when ImgVlt performs a Customer obligation under the Privacy Rule; and
- make relevant internal practices, books, and records available to the Secretary of the U.S. Department of Health and Human Services for determining HIPAA compliance.
Routine unsuccessful security events, including pings, scans, blocked login attempts, and rejected connections, need not be reported individually unless they result in unauthorized access, use, disclosure, modification, destruction, or material interference.
6. Breach information and cooperation
A report of a Breach will include, to the extent known, the identities of affected Individuals; the nature of the PHI involved; what happened; known or reasonably suspected recipients; mitigation completed or planned; and other information reasonably needed for Customer's notification obligations. ImgVlt will supplement the report as additional material information becomes available and reasonably cooperate with Customer's investigation and legally required notices.
7. Customer obligations
Customer will notify ImgVlt of any limitation in Customer's Notice of Privacy Practices, any change or revocation of an Individual's permission, and any agreed restriction under 45 C.F.R. 164.522 that may affect ImgVlt's use or disclosure of PHI. Customer will not request ImgVlt to use or disclose PHI in a manner that would violate HIPAA if done by Customer, except where the HIPAA Rules permit a Business Associate to do so.
Customer represents that it has authority to provide PHI to ImgVlt, direct the processing described in the Service Agreement, and authorize the de-identification and post-de-identification uses in Section 4. Customer is responsible for its users, role assignments, endpoint security, privacy notices, patient restrictions, and lawful configuration and use of the Service.
8. Individual requests
If ImgVlt receives a request from an Individual concerning access, amendment, restriction, confidential communications, or accounting of PHI controlled by Customer, ImgVlt may direct the Individual to Customer and will reasonably assist Customer as required by law and the Service Agreement. ImgVlt will not independently make clinical-record determinations reserved to Customer.
9. Term and termination
This BAA remains effective while ImgVlt maintains PHI for Customer. Customer may terminate this BAA and the affected Service for ImgVlt's material breach if ImgVlt does not cure the breach within a reasonable period specified by Customer, unless immediate termination is required by law or cure is not possible. If termination is not feasible, the parties will report the issue as required by the HIPAA Rules.
10. PHI after termination
Upon termination, ImgVlt will return or destroy PHI that ImgVlt maintains for Customer when feasible and as directed by the Service Agreement. If return or destruction is infeasible, including for legally required retention or protected backup media, ImgVlt will retain only the PHI necessary for that purpose, continue the safeguards and use restrictions in this BAA, and not use or disclose retained PHI for another purpose. ImgVlt will destroy retained PHI when the reason for retention ends and destruction becomes feasible.
This section does not require deletion of information that was properly de-identified under Section 4 before termination. De-identified information remains subject to the anti-re-identification and purpose restrictions in this BAA and the Terms.
11. Regulatory changes and interpretation
References to the HIPAA Rules mean those provisions as amended. The parties will amend this BAA as reasonably necessary to comply with changes in applicable law. Any ambiguity will be interpreted to permit compliance with the HIPAA Rules.
12. Order of precedence and survival
If this BAA conflicts with the Service Agreement regarding PHI, this BAA controls. More protective privacy or security obligations in a signed agreement remain effective. ImgVlt's obligations concerning retained PHI, de-identified-information restrictions, confidentiality, and regulatory cooperation survive termination.
13. Electronic acceptance
Electronic acceptance identifies Customer through its tenant account and the authorized accepting user. The parties agree that the recorded acceptance, document version, cryptographic document hash, date and time, user identity, IP address, and user agent constitute an electronic signature and reliable evidence of agreement. ImgVlt accepts this BAA by making the HIPAA-regulated Service available after Customer's acceptance and payment activation.
14. Contact
BAA and privacy notices may be sent to [email protected] for secure routing. Do not include PHI in ordinary email.