Draft — pending legal review

This document is a structural placeholder, not final legal text. It has not been reviewed by an attorney and should not be relied on or published to real customers until it has.

Business Associate Agreement

This document has no effective date yet — see the notice above.

Purpose

A practice that is a HIPAA Covered Entity is generally required to have a signed Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. This page describes the intended scope of that agreement; it is not itself an executed BAA.

Permitted uses and disclosures of PHI

Alcove will use and disclose PHI only as necessary to provide the service to a practice, as permitted by the executed agreement, or as required by law.

Safeguards

Alcove maintains administrative, technical, and physical safeguards appropriate to the PHI it handles — see our Security page for the technical controls currently in place.

Subcontractors

Any subcontractor that receives PHI on Alcove's behalf will be bound by terms at least as protective as those in the executed BAA — see Subprocessors.

Breach notification

Alcove will notify an affected practice without unreasonable delay following discovery of a breach of unsecured PHI, consistent with HIPAA's breach notification requirements.

Term and termination

The agreement remains in effect for as long as Alcove maintains PHI on a practice's behalf, with return or destruction of PHI on termination where feasible.

Executing this agreement

A signed BAA is required before any real PHI is processed under this agreement. Contact us to request one.