Business Associate Agreement
Version 2026-08-27-address-correction
Owner-adopted standard agreement.
The standard Business Associate Agreement (version 2026-08-27-address-correction) was formally adopted by the company owner on 2026-08-15 and is available for review and electronic acceptance. Version 2026-08-27-address-correction corrects Krasyn LLC's stated principal place of business to its address of record, 2489 N Side Saddle Lane, Post Falls, ID 83854; no other term changed. If your organization accepted an earlier version, that record is retained and an authorized representative needs to accept this corrected version here before real patient records resume. It has not been reviewed by outside legal counsel; independent counsel review is a registered follow-up milestone. Do not create, import, or update real patient records until a current agreement is executed for your organization. Contact info@krasyn.com.
BUSINESS ASSOCIATE AGREEMENT
Version: 2026-08-27-address-correction
This Business Associate Agreement ("BAA") is between the customer legal entity identified in
the immutable acceptance record ("Covered Entity") and Krasyn LLC, an Idaho
limited liability company with its principal place of business at 2489 N Side Saddle Lane,
Post Falls, ID 83854 ("Business Associate"). This
self-service form is only for a customer that has confirmed it is a Covered Entity. A customer
acting as a Business Associate must contact info@krasyn.com for a separately reviewed
subcontractor agreement.
This BAA is incorporated into the service relationship between the parties and governs
Business Associate's creation, receipt, maintenance, transmission, use, and disclosure of
Protected Health Information ("PHI") on behalf of Covered Entity.
1. DEFINITIONS. Terms not defined here have the meanings assigned by HIPAA, HITECH, and
45 CFR Parts 160 and 164, including: Breach, Data Aggregation, Designated Record Set,
Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy
Practices, Protected Health Information, Required by Law, Secretary, Security Incident,
Subcontractor, Unsecured Protected Health Information, and Use. "HIPAA Rules" means the
Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
2. PERMITTED AND REQUIRED USES AND DISCLOSURES. Business Associate may use or disclose PHI
only as necessary to perform the electronic medical record and related services in the
applicable service agreement, as permitted by this BAA, or as required by law. Business
Associate will not use or disclose PHI in any other manner and will not use or disclose PHI in
a way that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as
expressly permitted for a Business Associate by this Section. Business Associate may use PHI
for the proper management and administration of Business Associate or to carry out the legal
responsibilities of Business Associate, and may disclose PHI for those purposes if the
disclosure is required by law or Business Associate obtains reasonable assurances from the
person to whom the PHI is disclosed that it will remain confidential and be used or further
disclosed only as required by law or for the purposes for which it was disclosed to that
person, and that person notifies Business Associate of any instance of which it is aware in
which the confidentiality of the PHI has been breached. Business Associate may provide data
aggregation services relating to the health care operations of Covered Entity as permitted by
45 CFR 164.504(e)(2)(i)(B). Business Associate will not sell PHI and will not use or disclose
PHI for marketing, in each case except with a valid written authorization where permitted by
45 CFR 164.508. Business Associate will make uses and disclosures of, and requests for, PHI
consistent with the minimum necessary standard of 45 CFR 164.502(b) and with Covered Entity's
minimum necessary policies and procedures made known to Business Associate.
3. SAFEGUARDS AND SECURITY RULE. Business Associate will use appropriate administrative,
physical, and technical safeguards to prevent uses or disclosures of PHI not permitted by this
BAA and will comply with the applicable requirements of 45 CFR Part 164, Subpart C, with
respect to electronic PHI.
4. REPORTING AND BREACH NOTIFICATION. Business Associate will report to Covered Entity any
use or disclosure of PHI not provided for by this BAA of which it becomes aware and any
Security Incident of which it becomes aware. Business Associate will notify Covered Entity of
any Breach of Unsecured PHI without unreasonable delay and in no case later than five (5)
business days after discovery of the Breach, and in all events within the
time required by 45 CFR 164.410. The notification will include, to the extent known, the
information described in 45 CFR 164.410(c). The parties acknowledge that this Section
constitutes notice by Business Associate of the ongoing occurrence of attempted but
unsuccessful Security Incidents — such as pings, port scans, and denied access attempts — for
which no additional report is required unless they are material or indicate compromise.
Business Associate will mitigate, to the extent practicable, any harmful effect of a use or
disclosure of PHI by Business Associate that violates this BAA.
5. SUBCONTRACTORS. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business
Associate will ensure that each subcontractor that creates, receives, maintains, or transmits
PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions,
and requirements that apply to Business Associate with respect to such PHI.
6. INDIVIDUAL RIGHTS AND ACCOUNTING. Business Associate will make PHI in a designated record
set available to Covered Entity as necessary for Covered Entity to satisfy its obligations
under 45 CFR 164.524; make PHI in a designated record set available for amendment and
incorporate amendments as directed or agreed to by Covered Entity pursuant to 45 CFR 164.526;
and maintain and make available to Covered Entity the information required to provide an
accounting of disclosures as necessary for Covered Entity to satisfy its obligations under
45 CFR 164.528.
7. DELEGATED PRIVACY RULE DUTIES. To the extent Business Associate is to carry out one or
more of Covered Entity's obligations under 45 CFR Part 164, Subpart E, Business Associate will
comply with the requirements of Subpart E that apply to Covered Entity in the performance of
such obligations.
8. HHS ACCESS. Business Associate will make its internal practices, books, and records
relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of
determining compliance with the HIPAA Rules.
9. COVERED ENTITY OBLIGATIONS. Covered Entity will notify Business Associate of any
limitation in its notice of privacy practices under 45 CFR 164.520, any change in or
revocation of an individual's permission to use or disclose PHI, and any restriction on the
use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under
45 CFR 164.522, in each case to the extent it may affect Business Associate's use or
disclosure of PHI. Covered Entity will not request Business Associate to use or disclose PHI
in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by
Covered Entity, except as permitted for Business Associate's management and administration or
data aggregation services under Section 2.
10. TERM AND TERMINATION. This BAA is effective upon acceptance recorded in the immutable
acceptance record and remains in effect while Business Associate provides services involving
PHI to Covered Entity, unless terminated earlier under this Section. Covered Entity may
terminate this BAA if Covered Entity determines that Business Associate has violated a
material term of this BAA and Business Associate has not cured the breach or ended the
violation within thirty (30) days of written notice, or immediately upon
written notice if cure is not possible.
11. RETURN OR DESTRUCTION. Upon termination of this BAA for any reason, Business Associate
will return or destroy all PHI received from Covered Entity, or created, maintained, or
received by Business Associate on behalf of Covered Entity, that Business Associate still
maintains in any form, if feasible. If return or destruction is infeasible, Business Associate
will extend this BAA's protections to the retained PHI, limit further uses and disclosures to
the purposes that make return or destruction infeasible, and continue to comply with 45 CFR
Part 164, Subpart C, with respect to retained electronic PHI for as long as it is retained.
Upon written request made before termination, Business Associate will make Covered Entity's
patient data available for export in a standard interoperable format (FHIR R4 or C-CDA) for
thirty (30) days following termination. The obligations of Business Associate under this
Section survive termination of this BAA.
12. LIABILITY. Except for a party's violation of law, each party's total aggregate liability
arising out of or relating to this BAA is limited to the fees paid or payable by Covered
Entity for the services in the twelve (12) months preceding the first event giving rise to the
claim. This BAA intentionally contains no indemnification clause.
13. ELECTRONIC EXECUTION. The parties consent to electronic signatures and
electronic records for this BAA. The individual accepting this BAA represents that they are
authorized to bind Covered Entity and intend the electronic acceptance recorded in the
immutable acceptance record to have the same effect as a handwritten signature.
14. MISCELLANEOUS. A reference in this BAA to a section in the HIPAA Rules means the section
as in effect or as amended. The parties agree to take such action as is necessary to amend
this BAA from time to time as is necessary for compliance with the requirements of the HIPAA
Rules and any other applicable law. Any ambiguity in this BAA shall be interpreted to permit
compliance with the HIPAA Rules. Nothing in this BAA confers any rights or remedies on any
individual patient or other third party. If this BAA conflicts with the applicable service
agreement with respect to PHI, this BAA controls. This BAA is governed by applicable federal
law (HIPAA/HITECH) and, where not preempted, by the laws of the State of Idaho, without
regard to conflict-of-laws principles. Legal notices to Business Associate may be sent to
info@krasyn.com.
Agreement support
Covered Entities seeking an agreement, and organizations acting as Business Associates that need a subcontractor agreement, should email info@krasyn.com.