Legal

Business Associate Agreement

Version 2026-08-07

This Business Associate Agreement (the “Agreement”) is entered into between Reyma LLC (“Business Associate”) and the practice or individual clinician that accepts it (“Covered Entity”). It takes effect on the date Covered Entity accepts it during account creation, and it governs all Protected Health Information Business Associate creates, receives, maintains, or transmits on Covered Entity’s behalf.

1. Definitions

Terms used but not defined here have the meanings given to them in the HIPAA Rules. “HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164. “Protected Health Information” (“PHI”) has the meaning given at 45 CFR 160.103, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity.

2. Permitted Uses and Disclosures

Business Associate may use or disclose PHI only as necessary to perform the services described in the Terms of Service, as required by law, or as otherwise permitted by this Agreement. Business Associate may use PHI for its own proper management and administration, and to carry out its legal responsibilities.

Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity. Business Associate does not sell PHI, does not use PHI for marketing, and does not use PHI to train machine learning models for any purpose other than delivering the Service to Covered Entity.

Business Associate may disclose PHI for its own proper management and administration, or to carry out its legal responsibilities, only where the disclosure is required by law, or where Business Associate first obtains reasonable assurances from the person to whom the PHI is disclosed that the PHI will be held confidentially and used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the person will notify Business Associate of any instance of which it is aware in which the confidentiality of the PHI has been breached. This condition is required by 45 CFR 164.504(e)(4)(ii).

3. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. These include encryption of PHI in transit and at rest, role-based and consent-scoped access controls, and audit logging of read and write access to PHI.

4. Reporting

Business Associate will report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including any Security Incident and any Breach of Unsecured PHI. Business Associate will make that report without unreasonable delay and in no case later than ten (10) calendar days after discovery, and will include the information Covered Entity reasonably needs to meet its own notification obligations under 45 CFR 164.404 through 164.410.

5. Subcontractors

In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement. Business Associate maintains a current list of such subcontractors on its HIPAA page and will provide notice of material changes.

6. Individual Rights

Business Associate will make PHI in a Designated Record Set available to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.524 (access), will make such PHI available for amendment and incorporate amendments as directed under 45 CFR 164.526, and will maintain and make available the information required to provide an accounting of disclosures under 45 CFR 164.528. Business Associate will act on any such request within fifteen (15) calendar days of receiving it from Covered Entity.

7. Obligations of Covered Entity

Covered Entity is responsible for obtaining any patient consent or authorization required before enabling monitoring for an individual, for the accuracy of the clinical information it enters, and for all coding, claim submission, and billing decisions. Reyma produces billing-support documentation. It does not submit claims and does not determine medical necessity. Covered Entity will notify Business Associate of any limitation in its notice of privacy practices or any restriction on the use or disclosure of PHI that affects Business Associate’s performance.

8. Availability to the Secretary

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules.

9. Term and Termination

This Agreement takes effect on acceptance and continues until all PHI is returned or destroyed, or until terminated. Covered Entity may terminate this Agreement if Business Associate materially breaches it and fails to cure within thirty (30) days of written notice.

On termination, Business Associate will return or destroy all PHI it maintains for Covered Entity, and will retain no copies, except where return or destruction is infeasible. Where infeasible, Business Associate will extend the protections of this Agreement to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible. PHI retained as part of a billing or audit trail is retained under this provision.

10. Miscellaneous

A reference to a section of the HIPAA Rules means that section as it may be amended. The parties will amend this Agreement as needed to remain compliant with the HIPAA Rules. Nothing in this Agreement creates rights in any third party. This Agreement controls over any conflicting term in the Terms of Service with respect to PHI.

Questions about this Agreement can be sent to privacy@reymacare.com.