Business Associate Agreement
Last Updated: June 9, 2026
This Business Associate Agreement ("BAA") supplements and is formally incorporated into the Master SaaS Agreement (the "Agreement") entered into by and between Better Speech LLC ("Business Associate") and the healthcare provider, educational agency, school district, or entity executing an Order Form referencing this BAA ("Covered Entity").
This BAA applies solely to the extent that Business Associate creates, receives, maintains, transmits, or processes Protected Health Information ("PHI") on behalf of Covered Entity in connection with the cloud-based speech therapy software, Medicaid tracking modules, or administrative logging tools provided by Better Speech LLC under the Agreement.
1. Definitions
-
"Breach" shall have the same meaning as the term defined in 45 C.F.R. § 164.402, limited strictly to the unauthorized acquisition, access, use, or disclosure of Unsecured PHI maintained within Business Associate's systems.
-
"Designated Record Set" shall have the same meaning as the term in 45 C.F.R. § 164.501, restricted to those administrative, billing, or clinical records utilized directly by Covered Entity to make medical or treatment decisions about individuals.
-
"Protected Health Information" ("PHI") shall have the same meaning as the term defined in 45 C.F.R. § 160.103, limited exclusively to information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity under an active Order Form.
-
"Security Incident" means any confirmed unauthorized access, acquisition, use, disclosure, modification, or destruction of PHI or electronic PHI (ePHI) within Business Associate's systems, consistent with 45 C.F.R. § 164.304. The parties agree that the following constitute "unsuccessful" Security Incidents and do not require individual reporting under this BAA: routine network pings, port scans, failed automated log-in attempts where no PHI was accessed, and other similar probes that result in no access to or disclosure of PHI. Business Associate shall track patterns of unsuccessful attempts and notify Covered Entity if such attempts reach a volume or sophistication suggesting a coordinated threat.
2. Permitted Uses and Disclosures by Business Associate
-
2.1 Scope of Service. Business Associate may use or disclose PHI solely as necessary to perform the software functions, clinical speech tracking, and operational tasks specified in the Agreement, or as otherwise required by applicable federal law.
-
2.2 Management and Administration. Business Associate may use or disclose PHI for its own proper internal management, administrative compliance, and legal obligations, provided that any third-party disclosures are contractually bound by matching confidentiality constraints.
-
2.3 Data Aggregation. Business Associate may use PHI to provide data aggregation services relating to the health care operations of the Covered Entity if requested or authorized under the operational scope of the platform.
3. Obligations of Business Associate
-
3.1 Appropriate Safeguards. Business Associate shall implement and maintain commercially reasonable administrative, physical, and technical safeguards in alignment with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) to protect the confidentiality, integrity, and availability of electronic PHI (ePHI).
-
3.2 Mitigation. Business Associate agrees to mitigate, to the extent operationally practicable, any harmful effects known to Business Associate resulting from an unauthorized use or disclosure of PHI in violation of this BAA.
-
3.3 Subcontractors. Business Associate shall ensure that any agents or subcontractors that create, receive, maintain, or transmit PHI on behalf of Better Speech LLC enter into a written agreement containing data protection requirements substantially identical to the privacy and security obligations imposed upon Business Associate under this BAA.
-
3.4 Minimum Necessary. Business Associate shall make reasonable efforts to limit its use or disclosure of PHI to the minimum necessary to accomplish the intended administrative or software purpose.
4. Security Incident and Breach Notification
-
4.1 Notice Window. Business Associate shall notify Covered Entity in writing without unreasonable delay, and in no event later than seventy-two (72) hours, following Business Associate's discovery of, or reasonable belief in the occurrence of, a Breach of Unsecured PHI. For purposes of this Section, a Breach shall be treated as discovered as of the first day on which the Breach is known to Business Associate, or by exercising reasonable diligence would have been known to Business Associate, consistent with 45 C.F.R. § 164.410(a)(2). If complete information is not available at the time of initial notification, Business Associate shall provide a preliminary notice and shall supplement it with additional information as it becomes reasonably available.
-
4.2 Content of Notice. To the extent the data is available during triage, the notification shall include: (a) a brief description of the incident; (b) the categories of PHI involved; and (c) the corrective steps Business Associate is taking to mitigate the security event.
-
4.3 Notification Burden. Covered Entity shall retain sole statutory responsibility for determining whether regulatory reporting is required and for executing all required public, state, or individual notifications. Business Associate shall not communicate directly with any patient or individual consumer regarding a Breach unless expressly directed to do so in writing by Covered Entity.
5. Individual Rights Management
-
5.1 Access and Amendment Requests. Because the platform functions as an automated administrative tool, Covered Entity shall retain the primary interface for managing individual patient or student access rights. If an individual requests access to or amendment of their records directly from Business Associate, Business Associate shall forward such request to Covered Entity within ten (10) business days.
-
5.2 Designated Record Set Disclaimer. The parties acknowledge that Business Associate's software platform is not the primary system of record for clinical decisions; Covered Entity retains administrative control over the clinical records used to make treatment decisions. To the extent that any information maintained within Business Associate's platform is determined to constitute a "Designated Record Set" under 45 C.F.R. § 164.501, Business Associate shall cooperate with Covered Entity to facilitate individual access and amendment requests as required by applicable HIPAA regulations, including providing Covered Entity with data extracts necessary to fulfill such requests.
6. Term and Termination
-
6.1 Term. This BAA shall remain effective concurrently with the underlying Master SaaS Agreement and shall terminate automatically when all related Order Forms expire or are terminated.
-
6.2 Termination for Cause. If either party determines that the other party has committed a material breach of a structural provision of this BAA, the non-breaching party may terminate the Agreement and this BAA for cause if the breaching party fails to cure the default within thirty (30) days of receiving written notice.
-
6.3 Return or Destruction of PHI. Upon termination or expiration of the Agreement, Business Associate shall, at Covered Entity’s written option, within thirty (30) days return or securely destroy all PHI in its possession. If destruction or return is infeasible due to system architecture or backup rotation protocols, Business Associate shall extend all HIPAA privacy and security protections to such residual data and limit further uses to those that make the return or destruction infeasible.
7. Disclaimer of Professional Services
-
7.1 Administrative Tooling Only. Business Associate is purely a software-as-a-service vendor. The provision of data fields, clinical logging formats, or Medicaid billing code selections within the software does not constitute medical advice, clinical oversight, or validation of healthcare reimbursement claims.
-
7.2 Covered Entity Responsibility. Covered Entity is exclusively responsible for verifying the accuracy of all medical data, confirming the licensing credentials of its clinical providers, and validating the medical necessity of any claims submitted to insurance or state Medicaid offices.
8. Limitation of Liability and Miscellaneous
-
8.1 Integration of Caps. NOTWITHSTANDING ANY PROVISION TO THE CONTRARY IN THIS BAA, ANY MANDATED ADDENDUM, OR THE UNDERLYING AGREEMENT, BUSINESS ASSOCIATE’S TOTAL AGGREGATE FINANCIAL LIABILITY FOR ALL CLAIMS, LOSSES, DATA BREACHES, STATUTORY VIOLATIONS, SECURITY INCIDENTS, OR INDEMNIFICATION OBLIGATIONS ARISING OUT OF OR RELATED TO THIS BAA SHALL BE STRICTLY GOVERNED BY AND LIMITED TO THE LIABILITY CAPS ESTABLISHED IN SECTION 14 OF THE MASTER SAAS AGREEMENT WITH BETTER SPEECH LLC.
-
8.2 No Third-Party Beneficiaries. Nothing expressed or implied in this BAA is intended to confer, nor shall it confer, any legal rights, remedies, or causes of action upon any third party, including individual patients, guardians, students, or healthcare consumers.
-
8.3 Amendment. The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for Covered Entity or Business Associate to comply with the requirements of the HIPAA Rules and the HITECH Act.
9. Operational Assent and Effectiveness
-
9.1 Incorporation by Reference. This BAA is executed, validated, and rendered legally binding on both parties via incorporation by reference. Customer's execution of a transactional Order Form or Master SaaS Agreement referencing the canonical URL www.streamline-sped.com/legal/business-associate-agreement constitutes definitive, legally binding assent to all terms and conditions contained herein. No physical countersignature or standalone execution block is required to render this Addendum effective under federal HIPAA or HITECH Act guidelines.
SOLUTIONS
Copyright © 2025 Streamline | All Rights Reserved | Legal
