Legal · Business Associate Agreement

Business Associate Agreement

Version v1.0 · Effective 2026-06-28 · Immutable copy

This is a permanent, version-pinned copy and will never change. The current version always lives at /legal/baa. The healthcare Order Form incorporates this exact version by URL; signing the Order Form executes it. PHI liability is capped at $1,000,000 (§6.6).

EXHIBIT C – BUSINESS ASSOCIATE AGREEMENT

MULHOLLAND, INC.

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement (“BAA”) is entered into as of [EFFECTIVE DATE] by and between [INSERT CUSTOMER NAME] (“Covered Entity”) and Mulholland, Inc., a Delaware corporation (“Business Associate”). This BAA supplements and is incorporated into the Master Services Agreement between the Parties (the “MSA”) and applies where Business Associate creates, receives, maintains, or transmits (“process/es”) Protected Health Information on behalf of Covered Entity in its provision of the Platform services Business Associate provides under the MSA (the “Services”). To the extent of any conflict between this BAA and the MSA or any related addenda regarding Protected Health Information subject to HIPAA Rules, this BAA controls. For clarity, in the event Business Associate is a subcontractor and “Covered Entity” is a “business associate” (as such term is defined under 45 C.F.R. § 164.103), then all terms will be read the same and any references to “Business Associate” shall be read as “Subcontractor” and all references to “Covered Entity” shall be read as “Business Associate”. 

RECITALS

Covered Entity is, or acts on behalf of, a covered entity or business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the HITECH Act (collectively, “HIPAA”). Business Associate provides services to Covered Entity that involve the use or disclosure of Protected Health Information. Covered Entity agrees this BAA only applies to the portions of the Platform Business Associate has indicated as subject to the BAA in an Order Form. Covered Entity agrees not to submit PHI to Business Associate as part of Customer Data except as explicitly permitted under an Order Form executed by the parties. The Parties enter into this BAA to comply with the requirements of HIPAA, including 45 C.F.R. § 164.504(e), as applicable to each respective party.

1. Definitions

Capitalized terms used but not defined in this BAA have the meanings given to them in HIPAA. The following terms have the meanings set out below:

“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Part 160 and Part 164.

“Subcontractor” means a person to whom Business Associate delegates a function, activity, or service to process PHI in its provision of the Platform, other than a member of Business Associate’s workforce.

The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information (including ePHI) (“PHI”), Required By Law, Secretary, Security Incident, Unsecured Protected Health Information, and Use.

The following terms used in this Agreement shall have the same meaning as those terms in the MSA: “Platform” and “Services”.  

For any other capitalized term not defined in this BAA, such shall have the meaning set forth in the following order of precedence: (1) HIPAA Rules; and (2) the MSA.

2. Obligations and Activities of Business Associate

Business Associate agrees to:

(a) not use or disclose PHI other than as permitted or required by this BAA, including to provide the services under the MSA, or as Required by Law;

(b) use appropriate safeguards, and comply, where applicable, with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this BAA;

(c) report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including any confirmed Security Incident of which it becomes aware; and report any Breach of Unsecured PHI as soon as practicable, in any event within the period required by 45 C.F.R. § 164.410. The Parties agree that this BAA constitutes notice of the ongoing occurrence of unsuccessful Security Incidents (such as but not limited to routine, unsuccessful access attempts and pings, attempts to log on to a system with an invalid password or username, malware, and denial-of-service attacks that do not result in a server being taken off-line) for which no further notice is required;

(d) in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate with respect to PHI under this BAA; 

(e) make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.524, to the extent Business Associate maintains such PHI;

(f) make any amendment(s) to PHI in a Designated Record Set as directed or agreed by Covered Entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations, to the extent Business Associate maintains such PHI;

(g) maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.528;

(h) to the extent Business Associate is to carry out one or more of Covered Entity’s obligations under Subpart E of 45 C.F.R. Part 164 (the Privacy Rule), comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s);

(i) make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules; and

(j) request, use, and disclose only the minimum necessary PHI to accomplish the intended purpose of the use, disclosure, or request, consistent with 45 C.F.R. § 164.502(b).

3. Permitted Uses and Disclosures by Business Associate

3.1 Service Performance. Except as otherwise limited by this BAA, Business Associate may use and disclose PHI to provide the Platform and perform the Services for Covered Entity, provided such use or disclosure would not violate the HIPAA Rules if done by Covered Entity.

3.2 Management and Administration. Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities. Business Associate may disclose PHI for such purposes only if the disclosure is Required by Law, or Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.

3.3 Data Aggregation. Business Associate may use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity.

3.4 De-identification. Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c).

4. Obligations of Covered Entity

4.1 Notice and Authorizations. Covered Entity will promptly notify Business Associate of any limitation(s) in its notice of privacy practices, any changes in or revocation of permission by an individual to use or disclose PHI, and any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, in each case to the extent such limitation, change, revocation, or restriction may affect Business Associate’s use or disclosure of PHI.

4.2 Permissible Requests. Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as permitted under Sections 3.2 (Management and Administration), 3.3 (Data Aggregation), and subject to any legal responsibilities of the Business Associate.

4.3 Consents. Covered Entity will obtain all required authorizations and consents required under applicable law, including state and local laws, for Business Associate’s processing of PHI as permitted herein.

5. Term and Termination

5.1 Term. This BAA is effective as of the Effective Date and remains in effect until all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned, or, if return or destruction is infeasible, protections are extended in accordance with Section 5.3.

5.2 Termination for Cause. If Covered Entity determines that Business Associate has materially breached this BAA, Covered Entity may provide an opportunity to cure within thirty (30) days and, if Business Associate does not cure, terminate this BAA and any related services agreement; or, if cure is not possible, terminate this BAA.

5.3 Effect of Termination. On termination, Business Associate will, if feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity that Business Associate (and its Subcontractors) maintains, and retain no copies. If return or destruction is not feasible, Business Associate will extend the protections of this BAA to the retained PHI, limit further uses and disclosures to those purposes that make return or destruction infeasible, and continue these protections for as long as it retains the PHI. 

5.4 Termination of PHI Processing. Business Associate may suspend or terminate the processing of PHI if it reasonably determines it can no longer comply with its obligations herein, and the Parties will cooperate in good faith to transition or wind down such processing.

6. Miscellaneous

6.1 Regulatory References. A reference to a section in the HIPAA Rules means the section as in effect or as amended.

6.2 Amendment. The Parties will take such action as is necessary to amend this BAA from time to time as is necessary for compliance with the HIPAA Rules and other applicable law.

6.3 Interpretation. Any ambiguity in this BAA will be resolved to permit the Parties to comply with the HIPAA Rules.

6.4 Survival. Business Associate’s obligations under Section 5.3 survive termination.

6.5 No Third-Party Beneficiaries. Nothing in this BAA confers any rights on any person other than the Parties.

6.6 Relationship to MSA. The MSA remains in full force except as expressly modified by this BAA. Each Party’s liability arising out of or relating to this BAA is subject to the limitations of liability set forth in the MSA, except to the extent prohibited by applicable law; provided that each Party’s aggregate liability arising out of or relating to Protected Health Information will not exceed One Million Dollars ($1,000,000).

6.7 Notices. Any notice under this BAA must be in writing and sent to the receiving Party at the contact below, or to another address a Party later designates in writing, and is deemed given on receipt. Reports of a Breach or Security Incident under Section 2(c) must be sent to the Covered Entity contact below by email without undue delay. For Business Associate (Mulholland, Inc.): legal@mulholland.ai. For Covered Entity (CUSTOMER NAME): [name, title, and email to be completed].

6.8 Permitted Use; MSA Use Restrictions. Notwithstanding Sections 2.2(e) and 2.2(g) of the MSA, Covered Entity is permitted to use the Platform to process Protected Health Information solely for operational and business analytics on Customer Data that may contain Protected Health Information, subject to this BAA. This BAA does not authorize use of Output to provide clinical, diagnostic, or treatment advice.

6.9 Limitation of Liability. The limitation of liability set forth in the MSA applies to this BAA.

IN WITNESS WHEREOF, the parties have executed this BAA as of the Effective Date.

MULHOLLAND, INC.

By: ____________________________________

Name: ____________________________________

Title: ____________________________________

Date: ____________________________________

[CUSTOMER NAME]

By: ____________________________________

Name: ____________________________________

Title: ____________________________________

Date: ____________________________________