Business Associate Agreement
Version 1.0Last updated October 4, 2026
Addendum to the Credential Network Enterprise Service Agreement
This BUSINESS ASSOCIATE AGREEMENT (the "BAA") is between Credential Network, Inc., a Delaware corporation ("Business Associate"), and the customer identified in the applicable Order Form ("Covered Entity"), each a "Party" and together the "Parties." This BAA is an addendum to, and forms part of, the Enterprise Service Agreement between the Parties (available at https://credentialnetwork.com/enterprise-service-agreement) and the Order Form(s) executed thereunder (collectively, the "Agreement"). It is incorporated into the Agreement under Section 8.7 of the Enterprise Service Agreement and takes effect, without separate signature, on the date the Agreement first incorporates it under that Section (the "BAA Effective Date"). Capitalized terms used but not defined in this BAA have the meanings given in the Agreement or in the Privacy Rule, as applicable.
BACKGROUND
I. Covered Entity is either a “covered entity” or “business associate” of a covered entity as each are defined under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, as amended by the HITECH ACT (as defined below) and the related regulations promulgated by HHS (as defined below) (collectively, “HIPAA”) and, as such, is required to comply with HIPAA’s provisions regarding the confidentiality and privacy of Protected Health Information (as defined below);
II. The Parties have entered into the Credential Network Enterprise Service Agreement and one or more Order Forms thereunder (collectively, the "Agreement"), pursuant to which Business Associate provides Covered Entity access to its hosted credentialing platform and related Services;
III. In providing services pursuant to the Agreement, Business Associate may have access to Protected Health Information;
IV. By providing the services pursuant to the Agreement, Business Associate will become a “business associate” of the Covered Entity as such term is defined under HIPAA with respect to such Protected Health Information;
V. Both Parties are committed to complying with all federal and state laws governing confidentiality and privacy of health information, including, but not limited to, the Standards for Privacy of Individually Identifiable Health Information found at 45 CFR Part 160 and Part 164, Subparts A and E (collectively, the “Privacy Rule”); and
VI. Both Parties intend to protect the privacy and provide for the security of Protected Health Information disclosed to Business Associate pursuant to this Agreement, HIPAA and other applicable laws; and
VII. The Parties execute this BAA to address the processing of Protected Health Information, if any, that may be subject to HIPAA in connection with the Services. Where HIPAA requires a business associate agreement, that requirement does not depend on a Party’s request. The Parties acknowledge that not all data processed under the Agreement constitutes Protected Health Information under HIPAA, and this BAA governs only such information that meets the definition of Protected Health Information set forth herein.
AGREEMENT
NOW, THEREFORE, in consideration of the mutual covenants and conditions contained herein and the continued provision of PHI by Covered Entity to Business Associate under the Agreement in reliance on this BAA, the Parties agree as follows:
1. Definitions. For the purposes of this BAA, the Parties give the following meaning to each of the terms in this Section 1 below. Any capitalized term used in this BAA, but not otherwise defined, has the meaning given to that term in the Privacy Rule or pertinent law.
A. “Affiliate” means a subsidiary or affiliate of Covered Entity that is, or has been, considered a covered entity, as defined by HIPAA.
B. “Breach” means the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule which compromises the security or privacy of the PHI, as defined in 45 CFR § 164.402.
C. “Breach Notification Rule” means the portion of HIPAA set forth in Subpart D of 45 CFR Part 164.
D. “Data Aggregation” means, with respect to PHI created or received by Business Associate in its capacity as the “business associate” under HIPAA of Covered Entity, the combining of such PHI by Business Associate with the PHI received by Business Associate in its capacity as a business associate of one or more other “covered entity” under HIPAA, to permit data analyses that relate to the Health Care Operations (defined below) of the respective covered entities. The meaning of “data aggregation” in this BAA shall be consistent with the meaning given to that term in the Privacy Rule.
E. “Designated Record Set” has the meaning given to such term under the Privacy Rule including 45 CFR § 164.501.
F. “De-Identify” means to alter the PHI such that the resulting information meets the requirements described in 45 CFR §§164.514(a) and (b).
G. “Electronic PHI” means any PHI maintained in or transmitted by electronic media as defined in 45 CFR § 160.103.
H. “Health Care Operations” has the meaning given to that term in 45 CFR § 164.501.
I. “HHS” means the U.S. Department of Health and Human Services.
J. “HITECH Act” means the Health Information Technology for Economic and Clinical Health Act, enacted as part of the American Recovery and Reinvestment Act of 2009, Public Law 111-005.
K. “Individual” has the same meaning given to that term in 45 CFR § 160.103 and includes a person who qualifies as a personal representative in accordance with 45 CFR § 164.502(g).
L. “Privacy Rule” means that portion of HIPAA set forth in 45 CFR Part 160 and Part 164, Subparts A and E.
M. “Protected Health Information” or “PHI” has the meaning given to the term “protected health information” in 45 CFR § 160.103, limited to the information created or received by Business Associate from or on behalf of the Covered Entity.
N. “Security Incident” means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
O. “Security Rule” means the Security Standards for the Protection of Electronic Health Information provided in 45 CFR Part 160 & Part 164, Subparts A and C.
P. “Unsecured Protected Health Information” or “Unsecured PHI” means any “protected health information” as defined in 45 CFR § 160.103 that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the HHS Secretary in the guidance issued pursuant to the HITECH Act and codified at 42 USC § 17932(h).
Q. “Covered Entity” means the customer identified in the introductory paragraph of this BAA, whether that customer acts as a covered entity or as an upstream business associate under HIPAA with respect to the PHI. When that customer acts as an upstream business associate, Business Associate acts as its subcontractor business associate.
Throughout this BAA, contractual notices, reports, requests, and assistance directed to Covered Entity are directed to that customer. Obligations concerning Individual rights and Privacy Rule requirements will be performed through that customer to support the applicable underlying covered entity’s compliance, except where applicable law requires otherwise. Covered Entity’s obligations under Section 13 include communicating applicable limitations, permissions, and restrictions received from its upstream parties.
This definition does not change either Party’s legal status under HIPAA. Covered Entity represents that it has authority to provide the PHI and grant the permissions in this BAA. When Covered Entity acts as an upstream business associate, permissions under Sections 2.F and 2.G apply only to the extent authorized by applicable law and its upstream agreements. Covered Entity will communicate applicable restrictions before providing the affected PHI.
2. Use and Disclosure of PHI.
A. Except as otherwise provided in this BAA, Business Associate may use or disclose PHI as reasonably necessary to provide the services described in the Agreement to Covered Entity, and to undertake other activities of Business Associate permitted or required of Business Associate by this BAA or as required by law.
B. Except as otherwise limited by this BAA or federal or state law, Covered Entity authorizes Business Associate to use the PHI in its possession for the proper management and administration of Business Associate’s business and to carry out its legal responsibilities. Business Associate may disclose PHI for its proper management and administration, provided that (i) the disclosures are required by law; or (ii) Business Associate obtains, in writing, prior to making any disclosure to a third party (a) reasonable assurances from this third party that the PHI will be held confidential as provided under this BAA and used or further disclosed only as required by law or for the purpose for which it was disclosed to this third party and (b) an agreement from this third party to notify Business Associate immediately of any breaches of the confidentiality of the PHI, to the extent it has knowledge of the breach.
C. Business Associate will use or disclose PHI only as permitted or required by this BAA or as required by law, and will comply with the applicable requirements of the Privacy Rule. Business Associate will use or disclose PHI, to the extent practicable, as a limited data set or limited to the minimum necessary amount of PHI to carry out the intended purpose of the use or disclosure, in accordance with Section 13405(b) of the HITECH ACT (codified as 42 USC § 17935(b)) and any of the act’s implementing regulations adopted by HHS, for each use or disclosure of PHI.
D. Upon request, Business Associate will make available to Covered Entity any of Covered Entity’s PHI that Business Associate or any of its agents or subcontractors have in their possession.
E. Business Associate may use PHI to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR §164.502(j)(1).
F. De-Identification. Covered Entity authorizes Business Associate to use PHI to create de-identified information in accordance with 45 CFR §§ 164.514(a) and (b), using either the Expert Determination or Safe Harbor method. Business Associate will document the basis for determining that the applicable requirements have been satisfied. PHI used in the de-identification process remains subject to this BAA until those requirements are met.
Information properly de-identified under this Section is no longer PHI. Subject to Section 14 and applicable law, Business Associate may retain, use, and disclose that information for lawful business purposes, including analytics, benchmarking, research, and the development, training, validation, and improvement of products, services, and statistical or machine-learning models. Business Associate will not attempt to identify individuals from information used or disclosed under this permission and will require recipients to agree not to attempt such identification or permit further disclosure without equivalent restrictions. This permission does not authorize otherwise impermissible use of PHI for model training. Any material that contains PHI remains subject to this BAA.
G. Data Aggregation. Covered Entity authorizes Business Associate to use PHI to provide Data Aggregation services relating to the Health Care Operations of the respective covered entities, consistent with 45 CFR §§ 164.501 and 164.504(e)(2)(i)(B). When Covered Entity acts as an upstream business associate, those operations are the Health Care Operations of the underlying covered entities on whose behalf it provides PHI. Aggregated information remains PHI unless it is De-Identified under Section 2.F. This permission does not independently authorize disclosure of one covered entity’s PHI to another covered entity.
3. Safeguards Against Misuse of PHI. Business Associate will use appropriate safeguards to prevent the use or disclosure of PHI other than as provided by the Agreement or this BAA and Business Associate agrees to comply with the applicable requirements of the Security Rule and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic PHI that it creates, receives, maintains, or transmits on behalf of Covered Entity. Business Associate agrees to take reasonable steps, including providing adequate training to its employees to ensure compliance with this BAA and to ensure that the actions or omissions of its employees or agents do not cause Business Associate to breach the terms of this BAA. To the extent Business Associate is to carry out one or more of Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of such obligations.
4. Reporting Disclosures of PHI and Security Incidents. Business Associate will report to Covered Entity in writing any use or disclosure of PHI not provided for by this BAA of which it becomes aware and Business Associate agrees to report to Covered Entity any Security Incident affecting Electronic PHI of Covered Entity of which it becomes aware. Business Associate agrees to report any such event within 30 calendar days of becoming aware of the event. Routine unsuccessful Security Incidents, including unsuccessful log-in attempts, pings, port scans, and blocked denial-of-service attempts, may be reported in aggregate within that same deadline, provided they result in no unauthorized access, acquisition, use, disclosure, modification, or destruction of Electronic PHI and no interference with systems maintaining or transmitting Electronic PHI. Incidents or patterns presenting a material threat to the confidentiality, integrity, or availability of Electronic PHI must be reported separately under this Section. Business Associate will continue to identify, respond to, and document Security Incidents as required by the Security Rule. This paragraph does not limit or delay notification required under Section 5.
5. Reporting Breaches of Unsecured PHI. Business Associate will notify Covered Entity in writing without unreasonable delay upon the discovery of any Breach of Unsecured PHI in accordance with the requirements set forth in 45 CFR § 164.410, but in no case later than 30 calendar days after the discovery of a Breach. Business Associate will reimburse Covered Entity for any costs incurred by it in complying with the requirements of Subpart D of 45 CFR §164 that are imposed on Covered Entity as a result of a Breach committed by Business Associate. Business Associate's reimbursement obligations under this Section 5 are subject to the limitation of liability set forth in the Agreement.
6. Mitigation of Disclosures of PHI. Business Associate will take reasonable measures to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of any use or disclosure of PHI by Business Associate or its agents or subcontractors in violation of the requirements of this BAA.
7. Agreements with Agents or Subcontractors. Business Associate will ensure that each agent or subcontractor that creates, receives, maintains, or transmits PHI on its behalf enters into a written agreement, before undertaking those activities, imposing the same applicable restrictions and conditions concerning PHI as this BAA and requiring compliance with the applicable requirements of the Security Rule with respect to Electronic PHI. Business Associate shall notify Covered Entity of all subcontracts and agreements relating to the Agreement, where the subcontractor or agent received PHI as described in section 1.M of this BAA. Such notification shall occur within 30 calendar days of the execution of the subcontract by posting notice on Business Associate’s subprocessor list at https://credentialnetwork.com/subprocessors. Business Associate shall ensure that all subcontracts and agreements provide the same level of privacy and security as this BAA. Business Associate maintains business associate agreements with its in-scope subservice organizations that may have access to PHI, including its cloud infrastructure, hosting, database, and AI model providers, as identified on that subprocessor list and in Business Associate's then-current SOC 2 system description.
8. Audit Report. Upon request, Business Associate will provide Covered Entity with a copy of its most recent independent SOC 2 Type II report covering the systems used to provide the Services. The Parties may agree in writing to accept an available independent HIPAA compliance examination report, HITRUST certification, or other independent third-party audit report as an alternative. This Section does not require Business Associate to obtain an alternative report or certification.
Reports provided under this Section are Business Associate’s Confidential Information and are subject to applicable auditor restrictions on use and distribution. Subject to those restrictions, Covered Entity may share a report with its professional advisers and, when acting as a business associate, its applicable upstream business associates and underlying covered entities, provided those recipients have a legitimate compliance-review need and are bound by confidentiality obligations. Other disclosure requires Business Associate’s written consent, except as required by law. This Section does not limit Section 12.
9. Access to PHI by Individuals.
A. Upon request, Business Associate agrees to furnish Covered Entity with copies of the PHI maintained by Business Associate in a Designated Record Set in the time and manner designated by Covered Entity to enable Covered Entity to respond to an Individual’s request for access to PHI under 45 CFR §164.524.
B. In the event any Individual or personal representative requests access to the Individual’s PHI directly from Business Associate, Business Associate within 10 business days, will forward that request to Covered Entity. Any disclosure of, or decision not to disclose, the PHI requested by an Individual or a personal representative and compliance with the requirements applicable to an Individual’s right to obtain access to PHI shall remain the responsibility of Covered Entity, except to the extent Business Associate is to perform such obligations under this BAA or another written agreement between the Parties, or has duties directly imposed by applicable law. Business Associate’s performance of any delegated Privacy Rule obligation remains subject to Section 3.
10. Amendment of PHI.
A. Upon request and instruction from Covered Entity, Business Associate will amend PHI or a record about an Individual in a Designated Record Set that is maintained by, or otherwise within the possession of, Business Associate as directed by Covered Entity in accordance with procedures established by 45 CFR §164.526. Any request by Covered Entity to amend such information will be completed by Business Associate within 15 business days of Covered Entity’s request.
B. In the event that any Individual requests that Business Associate amend such Individual’s PHI or record in a Designated Record Set, Business Associate within 10 business days will forward this request to Covered Entity. Any amendment of, or decision not to amend, the PHI or record as requested by an Individual and compliance with the requirements applicable to an Individual’s right to request an amendment of PHI will remain the responsibility of Covered Entity, except to the extent Business Associate is to perform such obligations under this BAA or another written agreement between the Parties, or has duties directly imposed by applicable law. Business Associate’s performance of any delegated Privacy Rule obligation remains subject to Section 3.
11. Accounting of Disclosures.
A. Business Associate will document any disclosures of PHI made by it to account for such disclosures as required by 45 CFR §164.528(a). Business Associate also will make available information related to such disclosures as would be required for Covered Entity to respond to a request for an accounting of disclosures in accordance with 45 CFR §164.528. At a minimum, Business Associate will furnish Covered Entity the following with respect to any covered disclosures by Business Associate: (i) the date of disclosure of PHI; (ii) the name of the entity or person who received PHI, and, if known, the address of such entity or person; (iii) a brief description of the PHI disclosed; and (iv) a brief statement of the purpose of the disclosure which includes the basis for such disclosure.
B. Business Associate will furnish to Covered Entity information collected in accordance with this Section 11, within 10 business days after written request by Covered Entity, to permit Covered Entity to make an accounting of disclosures as required by 45 CFR §164.528, or in the event that Covered Entity elects to provide an Individual with a list of its business associates, Business Associate will provide an accounting of its disclosures of PHI upon request if the Individual, if and to the extent that such accounting is required under the HITECH ACT or under HHS regulations adopted in connection with the HITECH ACT.
C. In the event an Individual delivers the initial request for an accounting directly to Business Associate, Business Associate will, within 10 business days, forward such request to Covered Entity.
12. Availability of Books and Records. Business Associate will make available its internal practices, books, agreements, records, and policies and procedures relating to the use and disclosure of PHI, upon request, to the Secretary of HHS for purposes of determining Covered Entity's and Business Associate's compliance with HIPAA, and this BAA.
13. Responsibilities of Covered Entity. With regard to the use and/or disclosure of Protected Health Information by Business Associate, Covered Entity agrees to:
A. Notify Business Associate of any limitation(s) in its notice of privacy practices in accordance with 45 CFR §164.520, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
B. Notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, to the extent that such changes may affect Business Associate’s use or disclosure of PHI.
C. Notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR §164.522, to the extent that such restriction may affect Business Associate’s use or disclosure of PHI.
D. Except for data aggregation or management and administrative activities of Business Associate, Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
14. Data Ownership and De-Identified Information. Business Associate’s data stewardship does not confer ownership rights in PHI or other source data provided under the Agreement.
Notwithstanding contrary ownership, use, or return-and-destruction provisions in the Agreement, Covered Entity grants Business Associate a nonexclusive, perpetual, royalty-free right to retain, use, and disclose information lawfully De-Identified under Section 2.F before termination, for the purposes and subject to the conditions stated in that Section and applicable law. This right survives termination of the Agreement and this BAA. Disclosure under this permission must not identify Covered Entity or reveal its other Confidential Information without its written consent. This Section does not authorize retention of PHI after termination solely to create de-identified information.
15. Term and Termination.
A. This BAA will become effective on the BAA Effective Date and will continue in effect until all obligations of the Parties have been met under the Agreement and under this BAA.
B. Covered Entity may terminate this BAA, the Agreement, and any other related agreements if Covered Entity makes a determination that Business Associate has breached a material term of this BAA and Business Associate has failed to cure that material breach, to Covered Entity’s reasonable satisfaction, within 30 days after written notice from Covered Entity. Covered Entity may report the problem to the Secretary of HHS if termination is not feasible.
C. If Business Associate determines that Covered Entity has breached a material term of this BAA, then Business Associate will provide Covered Entity with written notice of the existence of the breach and shall provide Covered Entity with 30 days to cure the breach. Covered Entity’s failure to cure the breach within the 30-day period will be grounds for immediate termination of the Agreement and this BAA by Business Associate. Business Associate may report the breach to the HHS.
D. Section 10.4 of the Enterprise Service Agreement, including any applicable Archived Year and Long-Term Archive Service terms, governs PHI retention only to the extent consistent with this BAA and applicable law. Any continuing archive Services involving PHI must remain covered by an effective business associate agreement. Upon termination of this BAA, or when all authorized Services involving PHI have ended, Business Associate will return to Covered Entity or securely destroy all PHI received from, or created or received on behalf of, Covered Entity, including copies held by its agents or subcontractors, and retain no copies, except to the extent return or destruction is infeasible or retention is required by applicable law. Any retained PHI remains subject to the protections and limitations stated below. Section 15.D does not require Business Associate to return or destroy a copy of a record that Covered Entity has disclosed, as HIPAA permits, to the individual who is the subject of that record through CredWallet, and that the individual holds in a personal CredWallet account under the Credential Network Terms of Use; that copy is held for the individual, not on behalf of Covered Entity. All other PHI Business Associate holds on behalf of Covered Entity, including the copy in Covered Entity’s account, remains subject to this Section 15.D.
During any period that Business Associate retains PHI following termination, Business Associate will continue to extend the protections of this BAA to such PHI and will limit further uses and disclosures to those purposes that make retention necessary, until such PHI is returned to Covered Entity or destroyed. If return or destruction of PHI is not feasible, Business Associate will furnish Covered Entity with written notification of the conditions that make return or destruction infeasible, and the Parties will work in good faith to address such conditions. The Parties understand that this Section 15.D. will survive any termination of this BAA.
16. Effect of BAA.
A. This BAA is an addendum to, and forms part of, the Agreement. In the event of any conflict between this BAA and any other part of the Agreement (including the Enterprise Service Agreement and any Order Form) with respect to the use, disclosure, or protection of Protected Health Information, the terms of this BAA will govern with respect to that subject matter. For all other matters, the terms of the Agreement will govern.
B. Except as expressly stated in this BAA or as provided by law, this BAA will not create any rights in favor of any third party.
17. Regulatory References. A reference in this BAA to a section in HIPAA means the section as in effect or as amended at the time.
18. Notices. All notices, requests, demands, or other communications to be given under this BAA will be delivered in writing to the addresses set forth below, consistent with the notice provisions of the Agreement. Routine notices may be delivered by electronic mail. Notices relating to a Breach of Unsecured PHI, a material breach of this BAA, or termination must also be delivered by nationally recognized overnight courier or by certified or registered mail, return receipt requested, to the physical address listed below. Either Party may change its notice addresses by written notice to the other Party.
A. If to Covered Entity, to the notice contact and address in the most recently executed Order Form.
B. If to Business Associate, to:
Credential Network, Inc.
Attn: Legal
2818 N. Sullivan Rd., Suite 1159
Spokane Valley, WA 99216
Phone: (509) 262-5788
Email: legal@credentialnetwork.com
Security incidents: security@credentialnetwork.com
19. Amendments and Waiver. This BAA may not be modified, nor will any provision be waived or amended, except in writing duly signed by authorized representatives of the Parties or as provided in Section 21 (Versions). A waiver with respect to one event shall not be construed as continuing, or as a bar to or waiver of any right or remedy as to subsequent events.
20. HITECH ACT Compliance. Changes in Law. Each Party agrees to comply with the applicable requirements of HIPAA, including the HITECH Act and applicable implementing regulations. The Parties will negotiate in good faith any amendment to this BAA reasonably necessary to comply with changes in those requirements by the applicable compliance date.
If the Parties cannot agree on a necessary amendment, either Party may terminate this BAA and the portions of the Agreement involving the creation, receipt, maintenance, transmission, use, or disclosure of PHI upon 30 days’ prior written notice. If those Services cannot reasonably be separated from the remaining Services, the Agreement will terminate in its entirety.
This BAA remains in effect during the notice period. The Parties must suspend any affected activity sooner if necessary to avoid violating applicable law. Upon termination, the affected Services must cease unless a replacement business associate agreement satisfying applicable law takes effect without a gap in coverage. PHI retained for return, destruction, or other lawful retention remains subject to Section 15.D, and the applicable protections and restrictions of this BAA survive for as long as that PHI is retained.
21. Versions. Business Associate publishes this BAA at https://credentialnetwork.com/business-associate-agreement with a version number and keeps prior versions available there. The version named in the applicable Order Form governs that Order Form; if the Order Form names none, the version named in Section 8.7 of the Enterprise Service Agreement governs. When the Parties execute an Order Form that names a later version, that version governs from the Order Form’s effective date and replaces the prior version for all Order Forms then in effect between the Parties, consistent with Section 16.4 of the Enterprise Service Agreement. No revised version will reduce the protections this BAA gives PHI below what HIPAA requires.