Business Associate Agreement
This Business Associate Agreement (“BAA”) is entered into by and between the Covered Entity or Business Associate customer identified in the applicable services agreement, order form, or signature block (“Covered Entity” or “Customer”) and Dealsparrow Limited, trading as NeuroClo (“Business Associate” or “NeuroClo”).
This BAA applies only where NeuroClo creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of Customer in connection with the NeuroClo Services, and only to the extent the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively, “HIPAA”) apply. This BAA does not replace the Data Processing Agreement for UK/EU GDPR processing.
1. Definitions
Capitalised terms not defined in this BAA have the meanings in HIPAA, including 45 C.F.R. Parts 160 and 164. For convenience:
- Breach has the meaning in 45 C.F.R. § 164.402.
- Designated Record Set has the meaning in 45 C.F.R. § 164.501.
- Electronic PHI or ePHI means PHI transmitted or maintained in electronic media.
- Individual has the meaning in 45 C.F.R. § 160.103.
- Protected Health Information or PHI has the meaning in 45 C.F.R. § 160.103, limited to PHI NeuroClo creates, receives, maintains, or transmits on behalf of Customer.
- Required by Law has the meaning in 45 C.F.R. § 164.103.
- Security Incident has the meaning in 45 C.F.R. § 164.304.
- Services means the NeuroClo platform and related services described in the parties’ underlying services agreement (“Agreement”).
- Subcontractor means a person to whom NeuroClo delegates a function involving PHI, other than as a workforce member.
- Unsecured PHI has the meaning in 45 C.F.R. § 164.402.
2. Permitted uses and disclosures
NeuroClo may use or disclose PHI only as permitted or required by this BAA or as Required by Law, and only to perform the Services for Customer.
Without limiting the foregoing, NeuroClo may:
- (a) use PHI as necessary for proper management and administration of NeuroClo or to carry out NeuroClo’s legal responsibilities;
- (b) disclose PHI for NeuroClo’s proper management and administration or to carry out legal responsibilities, if (i) the disclosure is Required by Law, or (ii) NeuroClo obtains reasonable assurances from the recipient that PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and the recipient will notify NeuroClo of any Breach of which it becomes aware; and
- (c) provide data aggregation services relating to the health care operations of Customer, if offered under the Agreement.
NeuroClo will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Customer, except for the uses and disclosures set forth in (a)–(c) above.
NeuroClo will not use PHI to train publicly available AI models unless Customer expressly authorises that use in writing. The same restriction applies to Customer Content processed in connection with AI-assisted features.
3. Obligations of Business Associate
NeuroClo shall:
- (a) not use or disclose PHI other than as permitted or required by this BAA or as Required by Law;
- (b) use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this BAA;
- (c) report to Customer any use or disclosure of PHI not provided for by this BAA of which NeuroClo becomes aware, including Breaches of Unsecured PHI as required by 45 C.F.R. § 164.410, and any Security Incident of which NeuroClo becomes aware (routine unsuccessful attempts such as pings and firewall scans need not be reported individually if summarised periodically as mutually agreed);
- (d) in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of NeuroClo agree to the same restrictions and conditions that apply to NeuroClo with respect to such PHI, including a written BAA where required;
- (e) make available PHI in a Designated Record Set to Customer as necessary to satisfy Customer’s obligations under 45 C.F.R. § 164.524, within a reasonable time of Customer’s written request;
- (f) make available PHI for amendment and incorporate amendments as directed by Customer under 45 C.F.R. § 164.526;
- (g) make available information required to provide an accounting of disclosures under 45 C.F.R. § 164.528;
- (h) to the extent NeuroClo is to carry out Customer’s obligation under Subpart E of 45 C.F.R. Part 164, comply with the requirements that apply to Customer in performance of that obligation;
- (i) make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA; and
- (j) upon termination of this BAA for any reason, if feasible, return or destroy all PHI received from Customer or created, maintained, or received by NeuroClo on behalf of Customer that NeuroClo still maintains in any form, and retain no copies, or if return or destruction is infeasible, extend the protections of this BAA to the PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible.
4. Minimum necessary
NeuroClo will make reasonable efforts to use, disclose, and request only the minimum PHI necessary to accomplish the intended purpose of the use, disclosure, or request, consistent with 45 C.F.R. § 164.502(b) and NeuroClo’s role in providing the Services.
5. Breach notification
Following discovery of a Breach of Unsecured PHI, NeuroClo will notify Customer without unreasonable delay and in no case later than sixty (60) calendar days after discovery (or sooner if required by the Agreement). Notification will include, to the extent known:
- identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed;
- a brief description of what happened, including the date of the Breach and discovery date;
- a description of the types of Unsecured PHI involved;
- any steps Individuals should take to protect themselves;
- a brief description of what NeuroClo is doing to investigate, mitigate, and protect against further Breaches; and
- contact procedures for questions.
NeuroClo will supplement the notice as additional information becomes available. Customer remains responsible for determining whether notification to Individuals, HHS, or the media is required, except where law assigns that duty to NeuroClo.
6. Subcontractors
NeuroClo may engage Subcontractors that create, receive, maintain, or transmit PHI in connection with the Services, including Amazon Web Services and other vendors listed in NeuroClo’s Subprocessor List, provided NeuroClo has appropriate BAAs or equivalent contractual safeguards in place where required. NeuroClo remains responsible for Subcontractor compliance with this BAA to the extent required by HIPAA.
7. Obligations of Covered Entity
Customer shall:
- (a) not request NeuroClo to use or disclose PHI in a manner that would not be permissible under HIPAA if done by Customer (except as permitted under Section 2);
- (b) notify NeuroClo of any limitation(s) in Customer’s notice of privacy practices under 45 C.F.R. § 164.520, to the extent such limitation may affect NeuroClo’s use or disclosure of PHI;
- (c) notify NeuroClo of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent such changes may affect NeuroClo’s permitted uses or disclosures;
- (d) notify NeuroClo of any restriction on the use or disclosure of PHI that Customer has agreed to under 45 C.F.R. § 164.522, to the extent such restriction may affect NeuroClo; and
- (e) not provide NeuroClo with PHI unless reasonably necessary for the Services.
Customer remains solely responsible for its own HIPAA compliance as a Covered Entity (or upstream Business Associate), including patient relationships, authorisations, notices, and clinical decisions. NeuroClo does not provide healthcare services and does not practice medicine.
8. Term and termination
This BAA is effective as of the Effective Date (or the date PHI is first provided to NeuroClo under the Agreement, if later) and continues until all PHI is returned or destroyed, or if infeasible, until protections continue as required by Section 3(j).
Upon Customer’s knowledge of a material breach of this BAA by NeuroClo, Customer may:
- provide an opportunity to cure and terminate if NeuroClo does not cure within a reasonable time; or
- terminate this BAA and the applicable Services if cure is not possible; or
- report the breach to the Secretary if neither termination nor cure is feasible.
NeuroClo may terminate this BAA if Customer commits a material breach and fails to cure within a reasonable time after notice, or if cure is not feasible.
9. Amendment for law changes
The parties agree to amend this BAA as reasonably necessary to comply with changes in HIPAA or related guidance. If an amendment cannot be agreed and is required for HIPAA compliance, either party may terminate the Services that require this BAA upon reasonable notice.
10. No third-party beneficiaries; interpretation
Nothing in this BAA confers rights on any person other than the parties and their permitted successors. Any ambiguity shall be resolved to permit compliance with HIPAA. References to regulations include successor provisions.
11. Relationship to other agreements
In the event of conflict regarding PHI under HIPAA, this BAA controls over the Agreement, Privacy Policy, and Terms of Service for HIPAA matters. The DPA controls UK/EU GDPR processor obligations to the extent both apply to the same data. Liability under this BAA is subject to the limitations in the Agreement except where prohibited by law.
12. Contact
Dealsparrow Limited (trading as NeuroClo)
- Email: hello@neuroclo.com
- Registered Office / Service Address: 395 Clapham Road, London, SW9 9BT, United Kingdom
- Company Number: 07415063
