PediaSync

Business Associate Agreement

Last updated September 1, 2026

This Agreement is entered into electronically: a practice's founding member accepts it on the practice's behalf when creating the practice's PediaSync account, and that acceptance — with the date and the accepting person's identity — is kept on file as the practice's signature. No separate paper copy is required, and PediaSync will provide a copy on request.

1. Parties and Purpose

This Business Associate Agreement ("Agreement") is between the practice creating a PediaSync account ("Covered Entity") and PediaSync ("Business Associate"), effective as of the date Covered Entity's founding member accepts it. It governs Business Associate's creation, receipt, maintenance, and transmission of Protected Health Information ("PHI") on Covered Entity's behalf through the PediaSync clinician portal and sync service (the "Service"), in accordance with the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations (collectively, "HIPAA"). Terms used but not defined here have the meanings HIPAA gives them.

2. Permitted Uses and Disclosures of PHI

Business Associate may use or disclose PHI only as necessary to perform the Service for Covered Entity, as otherwise permitted or required by this Agreement, or as required by law. Business Associate may not use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity, except that Business Associate may use PHI for its own proper management and administration, to carry out its legal responsibilities, or to provide data aggregation services relating to Covered Entity's health care operations, each as HIPAA permits a business associate to do.

3. Obligations of Business Associate

Business Associate agrees to:

  • use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure other than as this Agreement permits;
  • report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, and any security incident it becomes aware of, including a breach of unsecured PHI, without unreasonable delay and in any event within the time HIPAA requires;
  • ensure that any subcontractor that creates, receives, maintains, or transmits PHI on Business Associate's behalf agrees, in writing, to the same restrictions and conditions that apply to Business Associate under this Agreement;
  • make PHI available to Covered Entity as needed to satisfy Covered Entity's obligations to provide individuals access to, amendment of, and an accounting of disclosures of their PHI under 45 CFR §§ 164.524, 164.526, and 164.528;
  • make its internal practices, books, and records relating to its use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA; and
  • to the extent Business Associate carries out an obligation of Covered Entity under the HIPAA Privacy Rule, comply with the requirements that apply to Covered Entity in performing that obligation.

4. Obligations of Covered Entity

Covered Entity is responsible for its own HIPAA compliance, including obtaining any patient authorization or consent it needs, and for notifying Business Associate of any limitation on its own notice of privacy practices or any restriction it has agreed to, to the extent that limitation or restriction affects Business Associate's use or disclosure of PHI. Covered Entity will not request Business Associate to use or disclose PHI in a way that would not be permitted under HIPAA if done by Covered Entity itself.

5. Term and Termination

This Agreement is effective on acceptance and continues for as long as Covered Entity's account exists, or until either party terminates it for the other's material breach that remains uncured after reasonable notice. On termination, Business Associate will, if feasible, return or destroy all PHI it still holds; to the extent that is infeasible, Business Associate will extend this Agreement's protections to that PHI for as long as it retains it and limit further use or disclosure to the purposes that make return or destruction infeasible.

6. Miscellaneous

This Agreement is interpreted to permit compliance with HIPAA, and any ambiguity is resolved in favor of an interpretation that does. If a provision of this Agreement conflicts with the Terms of Service governing the Service, this Agreement controls as to PHI. This Agreement does not create any right for a third party. It is governed by the same law as the Terms of Service.

7. Contact

Questions about this Agreement, or a request for a countersigned copy, can be sent to [email protected].