Business Associate Agreement
This document has no effective date yet — see the notice above.
Purpose
A practice that is a HIPAA Covered Entity is generally required to have a signed Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. This page describes the intended scope of that agreement; it is not itself an executed BAA.
Permitted uses and disclosures of PHI
Alcove will use and disclose PHI only as necessary to provide the service to a practice, as permitted by the executed agreement, or as required by law.
Safeguards
Alcove maintains administrative, technical, and physical safeguards appropriate to the PHI it handles — see our Security page for the technical controls currently in place.
Subcontractors
Any subcontractor that receives PHI on Alcove's behalf will be bound by terms at least as protective as those in the executed BAA — see Subprocessors.
Breach notification
Alcove will notify an affected practice without unreasonable delay following discovery of a breach of unsecured PHI, consistent with HIPAA's breach notification requirements.
Term and termination
The agreement remains in effect for as long as Alcove maintains PHI on a practice's behalf, with return or destruction of PHI on termination where feasible.
Executing this agreement
A signed BAA is required before any real PHI is processed under this agreement. Contact us to request one.