← HL Patient Portal
Business Associate Agreement
Version 2026-09-02 · Effective September 2, 2026
This Business Associate Agreement ("BAA") is entered into between the clinic, medical spa, pharmacy or practice identified in its HL Patient Portal account ("Covered Entity") and HL Patient Portal ("Business Associate"). It is part of, and accepted together with, the Terms of Service, and applies whenever Business Associate creates, receives, maintains or transmits protected health information on Covered Entity's behalf in the course of providing the Platform (the "Services").
1. Definitions
Capitalized terms not defined here have the meanings given in the HIPAA Rules. "HIPAA Rules" means the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164. "PHI" means protected health information as defined in 45 CFR 160.103, limited to the information Business Associate creates, receives, maintains or transmits on behalf of Covered Entity. "Breach", "Security Incident", "Subcontractor", "Unsecured PHI" and "Secretary" have the meanings given in 45 CFR 160.103 and 164.402.
2. Obligations of Business Associate
Business Associate agrees to:
- not use or disclose PHI other than as permitted or required by this BAA or as required by law;
- use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this BAA, including encryption of PHI in transit and at rest, role-based access controls, and audit logging of access to PHI;
- report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including Breaches of Unsecured PHI as required by 45 CFR 164.410, and any Security Incident, without unreasonable delay and in no case later than ten (10) business days after discovery. The report will include the information Covered Entity needs to meet its own notification obligations under 45 CFR 164.404, to the extent known. Unsuccessful Security Incidents, such as pings, port scans, blocked sign-in attempts and other attempts that do not result in unauthorized access to PHI, are reported by this paragraph and no further notice of them is required;
- in accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions and requirements that apply to Business Associate with respect to that information. The current Subcontractors are listed in Schedule A and in Covered Entity's dashboard (Settings → Legal), and Business Associate will update that list before a new Subcontractor handles PHI;
- make PHI available to Covered Entity, or as directed by Covered Entity to an individual, as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524 (right of access). The Platform provides patient data export in the patient portal and the clinic dashboard for this purpose;
- make PHI available for amendment and incorporate any amendments to PHI as directed by Covered Entity under 45 CFR 164.526;
- maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy 45 CFR 164.528;
- to the extent Business Associate carries out one or more of Covered Entity's obligations under Subpart E of 45 CFR Part 164 (the Privacy Rule), comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations;
- make its internal practices, books and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Covered Entity available to the Secretary for purposes of determining compliance with the HIPAA Rules;
- train its workforce on PHI handling and limit workforce access to PHI to what is needed to provide and support the Services;
- request, use and disclose only the minimum necessary PHI to accomplish the intended purpose, consistent with 45 CFR 164.502(b).
3. Permitted uses and disclosures by Business Associate
- Business Associate may use and disclose PHI as necessary to perform the Services described in the Terms of Service, namely hosting Covered Entity's patient portal, intake, ordering and fulfillment, treatment tracking, reminders and notifications, messaging, rewards, reporting to Covered Entity, and technical support, and as otherwise permitted by this BAA.
- Business Associate may use or disclose PHI as required by law.
- Business Associate may not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except for the specific uses and disclosures set out in paragraphs (d) and (e).
- Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, and may disclose PHI for those purposes if the disclosure is required by law, or if Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially and used or further disclosed only as required by law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any instance of which it is aware in which the confidentiality of the information has been breached.
- Business Associate may provide data aggregation services relating to the health care operations of Covered Entity, and may de-identify PHI in accordance with 45 CFR 164.514(a)–(c). De-identified information is not PHI and may be used by Business Associate to operate, measure and improve the Services.
- Business Associate will make disclosures at Covered Entity's direction. When Covered Entity connects a third-party system to its account (for example its CRM, its own Stripe account, a pharmacy or a shipping account), Business Associate transmits the data Covered Entity has configured to that system on Covered Entity's instruction. Those systems are Covered Entity's own vendors or business associates, not Subcontractors of Business Associate, and Covered Entity is responsible for its agreements with them.
4. Obligations of Covered Entity
- Covered Entity will notify Business Associate of any limitation in its notice of privacy practices under 45 CFR 164.520, to the extent the limitation may affect Business Associate's use or disclosure of PHI.
- Covered Entity will notify Business Associate of any change in, or revocation of, an individual's permission to use or disclose their PHI, to the extent the change may affect Business Associate's use or disclosure of PHI.
- Covered Entity will notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent the restriction may affect Business Associate's use or disclosure of PHI.
- Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted in Section 3(d) and 3(e).
- Covered Entity is responsible for the content it and its workforce send through the Platform, for the third-party systems it chooses to connect, and for using the Platform's role, access and security features (including two-factor authentication and staff account management) appropriately.
- Covered Entity will obtain any consents or authorizations from individuals that are required for the features it configures, including patient communications and marketing features it turns on.
5. Term and termination
- Term. This BAA takes effect when accepted and continues for as long as Business Associate provides the Services to Covered Entity, or until terminated under this Section, whichever is later.
- Termination for cause. Covered Entity may terminate this BAA and the Services if Business Associate has violated a material term of this BAA and has not cured the violation within thirty (30) days of written notice. Business Associate may likewise terminate if Covered Entity's material violation of this BAA is not cured within thirty (30) days of written notice.
- Effect of termination. On termination, Business Associate will, at Covered Entity's written request made within thirty (30) days, provide an export of Covered Entity's data, including PHI, in a commonly used electronic format, and will then destroy the PHI it holds, except for PHI that it must retain by law or that is contained in audit and security logs required for compliance (retained for six years under 45 CFR 164.316(b)(2) and then deleted). To the extent return or destruction is infeasible, Business Associate will extend the protections of this BAA to the retained PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it retains the PHI. The obligations in this Section survive termination.
6. General
- Regulatory references. A reference in this BAA to a section of the HIPAA Rules means the section as in effect or as amended.
- Amendment. The parties agree to take the action necessary to amend this BAA as needed for compliance with the HIPAA Rules and other applicable law. Business Associate may publish an updated version of this BAA. Material changes will be notified to Covered Entity's account owner and presented for acceptance in the dashboard, and the previously accepted version continues to apply until the new one is accepted.
- Interpretation. Any ambiguity in this BAA will be resolved to permit compliance with the HIPAA Rules. If this BAA conflicts with the Terms of Service regarding PHI, this BAA controls.
- Notices. Notices to Business Associate go to support@hlpatientportal.com. Notices to Covered Entity go to the account owner's email address on file.
- No third-party beneficiaries. Nothing in this BAA confers rights on anyone other than the parties and their successors.
- Electronic acceptance. This BAA is accepted electronically by the individual who checks the acceptance box on behalf of Covered Entity, who represents that they are authorized to bind Covered Entity. Business Associate accepts by making the Services available. The acceptance record (version, name, email, date and network address) is kept by Business Associate and is available, together with a completed copy of this BAA, from Settings → Legal in Covered Entity's dashboard. Electronic acceptance has the same effect as a signature.
Schedule A — Subcontractors handling PHI
Business Associate maintains written agreements with the following Subcontractors as required by 45 CFR 164.502(e). The current list is also shown in Covered Entity's dashboard under Settings → Legal.
| Subcontractor | Purpose | Data |
| Amazon Web Services (AWS) | Hosting and infrastructure: application servers, file storage, content delivery, secrets management | All Platform data, including PHI, in US regions |
| MongoDB Atlas | Managed database | All Platform records, including PHI, encrypted in transit and at rest |
| Stripe | Payment processing for the clinic's connected Stripe account and platform billing | Payment details, order amounts and descriptions, patient name and email |
| EasyPost | Shipping labels and package tracking | Recipient name, shipping address, package details, tracking events |
| Resend | Transactional email delivery: account, order and shipping notices | Name, email address, message content |
| Expo | Push notification delivery to the patient app | Device push tokens and notification text (notifications carry no clinical detail by policy) |
For clinics: this BAA is accepted together with the Terms of Service when you create
your clinic account. Your completed copy, with your clinic's details and the acceptance record filled
in, is available any time from Settings → Legal in your dashboard.