Legal  ·  BAA

Business Associate Agreement.

Stable public URL. Print-ready. Praktend signs one with each practice customer before PHI flows. A PDF copy is available on request. See below.

01  ·  What this is

Plain-English summary.

A Business Associate Agreement (BAA) is a contract required by HIPAA whenever a vendor handles protected health information (PHI) on behalf of a healthcare provider. It specifies what the vendor can and cannot do with that data, what security controls it maintains, and what happens if something goes wrong. Without a signed BAA, sharing PHI with a vendor is a HIPAA violation on your part and ours.

Praktend signs this agreement with every dental practice customer before any PHI touches our platform. The agreement runs for the life of the engagement and survives termination for as long as Praktend retains any PHI. When you offboard, we destroy all PHI and issue a written certificate confirming destruction.

The full legal text is below. Three things in this BAA are different from a generic template: (1) an explicit prohibition on using PHI to train AI models, (2) a subcontractor clause that names where PHI-processing AI inference runs, which agreement covers it, and where the current agreement status of each listed subprocessor is published, and (3) a 12-month technical safeguard verification commitment aligned to the Jan 6, 2025 HIPAA Security Rule NPRM. If your malpractice carrier or counsel needs a signed copy, email legal@praktend.care.

Download

PDF version available on request

A PDF version of this agreement is available at any time. Email legal@praktend.care with subject line "BAA Request - [Practice Name]" and we will return a copy within one business day, executed where an agreement is already on file with your practice. The URL of this page (https://praktend.com/legal/baa) is stable and may be submitted to vendor questionnaires, malpractice carriers, or HIPAA auditors directly.

Request BAA copy
02  ·  Agreement text

Business Associate Agreement. Full text.

Effective Date: [DATE]

This Business Associate Agreement ("Agreement") is entered into between [Covered Entity Name] ("Covered Entity") and Praktend Ops, a Colorado company ("Business Associate"), in connection with the services described in the underlying service agreement ("Service Agreement") between the parties.

1. Definitions

Terms used but not otherwise defined in this Agreement have the meaning assigned to them in 45 CFR Parts 160 and 164, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and the Health Information Technology for Economic and Clinical Health (HITECH) Act. Key terms used in this Agreement:

  • "PHI" means Protected Health Information as defined in 45 CFR 160.103.
  • "Electronic PHI" or "ePHI" means PHI that is created, received, maintained, or transmitted in electronic form.
  • "Breach" has the meaning assigned in 45 CFR 164.402.
  • "Subcontractor" means any third party engaged by Business Associate that creates, receives, maintains, or transmits PHI on behalf of Business Associate.

2. Permitted and required uses and disclosures

2.1. Business Associate may use and disclose PHI only (a) as necessary to perform the services described in the Service Agreement, (b) as required by law, or (c) as otherwise permitted by this Agreement.

2.2. Business Associate may use PHI for its own proper management and administration, or to carry out its legal responsibilities, provided that any such disclosure is required by law or Business Associate obtains reasonable assurances that the information will be held confidentially and used or further disclosed only as required by law or for the purpose for which it was disclosed.

2.3. Business Associate may use PHI to provide data aggregation services to Covered Entity relating to Covered Entity's health care operations, as defined in 45 CFR 164.501.

3. Limitations on use and disclosure

3.1. Business Associate will not use or disclose PHI in any manner that would violate the requirements of 45 CFR Part 164, Subpart E, if done by Covered Entity, except as permitted under this Agreement.

3.2. Business Associate will not disclose PHI to a third party except as permitted by this Agreement or required by law.

3.3. AI model training prohibition. Business Associate will not use PHI to fine-tune, pre-train, instruct-tune, evaluate, benchmark, or otherwise improve any machine learning or artificial intelligence model, and will not authorize or permit any Subcontractor to do so. Business Associate will contract for this restriction with each Subcontractor that processes PHI. This prohibition survives termination of this Agreement.

4. Subcontractors

4.1. Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement.

4.2. AI subprocessors and subprocessor disclosure. Artificial intelligence inference on PHI runs on Google Cloud Vertex AI, under the Google Cloud HIPAA Business Associate Agreement executed by Praktend on June 4, 2026. Google confirmed to Praktend in writing on that date that Anthropic Claude models served through Vertex AI Model Garden are covered by that agreement. Praktend holds no direct Business Associate Agreement with Anthropic and does not route PHI to the Anthropic direct API. Praktend publishes a list of its subprocessors, with the current Business Associate Agreement status of each, at praktend.com/trust, and will provide that list to Covered Entity on request at legal@praktend.care. The list marks which subprocessors are capable of handling PHI, including those for which a Business Associate Agreement is available and has not yet been executed. Business Associate will not add a new Subcontractor to a PHI-processing path until a compliant agreement covering that Subcontractor is in place, and will update the published list when a subprocessor's status changes.

4.3. If a Subcontractor cannot agree to the terms required by this Agreement, Business Associate will not route PHI through that Subcontractor unless and until a compliant agreement is in place.

5. Safeguards

5.1. Business Associate will implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI, in accordance with 45 CFR Part 164, Subpart C (the HIPAA Security Rule).

5.2. Business Associate will implement reasonable and appropriate policies and procedures to protect ePHI in accordance with 45 CFR 164.530(i).

5.3. Annual safeguard verification. Aligned to the verification cadence contemplated by the January 6, 2025 HIPAA Security Rule Notice of Proposed Rulemaking (a proposed rule, not final as of the Effective Date), Business Associate will verify the adequacy of its technical safeguards at least every 12 months and will provide written attestation of that verification to Covered Entity on request. Covered Entity may request the most recent completed attestation by emailing legal@praktend.care.

5.4. Current technical safeguards include: AES-256 encryption at rest on PHI stored in Google Cloud (Google Cloud Storage, Firestore, and BigQuery default encryption; Google-managed keys are the default; customer-managed encryption keys (CMEK) are available on request), a TLS 1.2 floor in transit on Praktend's API endpoints with forward-secret cipher suites required and TLS 1.3 supported, role-based access control applying the principle of least privilege, and application-level audit logging of PHI access and modification events.

6. Reporting obligations

6.1. Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement within ten (10) business days of becoming aware of such use or disclosure.

6.2. Business Associate will report to Covered Entity any Security Incident (as defined in 45 CFR 164.304) of which it becomes aware within ten (10) business days. Business Associate will provide a summary of Security Incidents that did not result in unauthorized access, use, disclosure, modification, or destruction of PHI on an annual basis.

6.3. Breach notification. Business Associate will notify Covered Entity of a Breach of Unsecured PHI no later than thirty (30) calendar days after Business Associate discovers the Breach. This timeline is faster than the 60-day maximum permitted by 45 CFR 164.410(b). Notification will include, to the extent possible: (a) the identification of each individual whose PHI was or is reasonably believed to have been breached; (b) a description of what happened; (c) the types of PHI involved; (d) steps individuals should take to protect themselves; (e) a description of what Business Associate is doing to investigate the breach, mitigate harm, and prevent future occurrences.

7. Individual rights

7.1. Business Associate will make available PHI in a designated record set in accordance with 45 CFR 164.524 to enable Covered Entity to respond to requests for access by individuals.

7.2. Business Associate will make available PHI for amendment and will incorporate any amendments to PHI in accordance with 45 CFR 164.526.

7.3. Business Associate will make available the information required by Covered Entity to provide an accounting of disclosures of PHI in accordance with 45 CFR 164.528.

7.4. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary of Health and Human Services or the Secretary's designees for the purpose of determining Covered Entity's compliance with HIPAA.

8. Term and termination

8.1. This Agreement is effective as of the Effective Date and terminates when all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information in accordance with the termination provisions of this Agreement.

8.2. Either party may terminate this Agreement and the Service Agreement if the other party has violated a material term of this Agreement and has not cured the violation within thirty (30) days of receiving written notice. For violations that cannot be cured, termination is effective upon notice.

8.3. Upon termination, Business Associate will, at the direction of Covered Entity, either return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity. Business Associate will issue a written destruction certificate within fifteen (15) business days of completing destruction.

8.4. If Business Associate determines that returning or destroying PHI is infeasible, Business Associate will provide notice to Covered Entity of the reasons destruction is infeasible and will extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.

9. Indemnification

9.1. Each party agrees to indemnify, defend, and hold the other party harmless from and against any claims, losses, damages, penalties, and expenses (including reasonable legal fees) arising from that party's breach of this Agreement, violation of HIPAA, or negligent or wrongful acts or omissions in connection with PHI.

9.2. Business Associate's maximum aggregate liability under this Agreement is limited to the fees paid by Covered Entity to Business Associate in the twelve (12) months preceding the event giving rise to the claim. This limitation does not apply to breaches caused by Business Associate's willful misconduct or fraud.

10. Miscellaneous

10.1. Entire agreement. This Agreement, together with the Service Agreement, constitutes the entire agreement between the parties concerning the subject matter hereof and supersedes all prior agreements, representations, and understandings with respect to PHI and HIPAA compliance.

10.2. Amendment. This Agreement may be amended only by a written instrument signed by both parties. Business Associate may amend this Agreement as necessary to comply with changes in applicable law, provided it gives Covered Entity thirty (30) days advance written notice.

10.3. Governing law. This Agreement is governed by the laws of the State of Colorado and applicable federal law. Any dispute is subject to the exclusive jurisdiction of the state and federal courts located in El Paso County, Colorado.

10.4. Severability. If any provision of this Agreement is held unenforceable, the remaining provisions continue in full force and effect.

10.5. No third-party beneficiaries. Nothing in this Agreement creates rights in any third party, including any patient or plan member whose PHI is subject to this Agreement.

10.6. Covered entity may request a copy. Covered Entity may request a copy of the executed BAA at any time at legal@praktend.care.

11. Signature block

By signing below, both parties agree to be bound by the terms of this Agreement as of the Effective Date above.

Covered Entity
Entity name:
Authorized representative name:
Title:
Signature:
Date:
Praktend Ops (Business Associate)
Entity name: Praktend Ops
Authorized representative name: Chris Shannon
Title: Founder
Signature:
Date:

HIPAA questions? Email directly.

Written answers within one business day. BAA copy on request.

Email legal@praktend.care