Business Associate Agreement (BAA)

HIPAA-compliant BAA terms for hospital networks, clinic networks, and private clinical practices.

PatientIQ operates under HIPAA-compliant standards. A signed BAA is executed automatically during hospital onboarding and is integrated into our SaaS database.

1. Scope and definitions

This Business Associate Agreement (BAA) applies to all transactions where PatientIQ (the Business Associate) stores, processes, or transmits Protected Health Information (PHI) on behalf of registered healthcare clinics, hospitals, or private practices (the Covered Entity).

2. Permitted Uses and Disclosures

PatientIQ will only use or disclose PHI as required to perform dashboard analytics, database storage, SOAP dictation note mapping, secure messaging synchronization, and related clinical SaaS actions requested by the Covered Entity, or as required by law.

3. Safeguards & Security Audits

We agree to implement administrative, physical, and technical safeguards that reasonably protect the confidentiality, integrity, and availability of electronic PHI (ePHI). Every record check, file access, and credential verification event is registered in the Security Audit log viewer with IP tracking.

4. Breach Notification

PatientIQ will notify the Covered Entity within twenty-four (24) hours of discovering any unauthorized access, use, or disclosure of PHI (a Security Incident or Breach) to ensure federal notification thresholds are satisfied.

To request a countersigned PDF version of this BAA, please contact our HIPAA officer at compliance@patientiq.com.