Privacy & Compliance

Business Associate Agreement

This agreement governs the handling of protected health information exchanged between Compass Healthcare LLC and the healthcare providers it serves, in accordance with HIPAA and the HITECH Act.

Form version: v1.1 Updated on 08/14/2026 Parties: Covered Entity & Compass Healthcare LLC Governed by 45 CFR Parts 160 & 164
Home Privacy Business Associate Agreement
About this template. This BAA is the standard form Compass Healthcare LLC offers to the covered entities it serves, based on standard HIPAA business-associate provisions. It is provided for review and is not legal advice. The version that governs is the one executed in writing by both parties; specific terms may be tailored in that executed agreement.

1Parties and purpose

This Business Associate Agreement ("Agreement") is entered into between a covered entity ("Covered Entity") and Compass Healthcare LLC ("Business Associate"). It takes effect on the date the parties execute it (the "Effective Date").

Business Associate provides services to Covered Entity — which may include medical billing, revenue cycle management, IT support, data collection, and the Clinical Outcome platform — that involve the creation, receipt, maintenance, or transmission of Protected Health Information ("PHI"). The parties enter into this Agreement to comply with the HIPAA Privacy, Security, and Breach Notification Rules.

2Definitions

Capitalized terms used but not defined here have the meaning given in the HIPAA Rules (45 CFR Parts 160 and 164).

PHI / ePHI — Protected Health Information, and its electronic form, as defined at 45 CFR §160.103, limited to information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
HIPAA Rules — the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164.
Breach — the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI, as defined at 45 CFR §164.402.

3Obligations of Business Associate

Business Associate agrees to:

4Permitted uses and disclosures

Business Associate may use or disclose PHI only:

Business Associate will make reasonable efforts to use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose.

5Safeguards for electronic PHI

Consistent with the HIPAA Security Rule, Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI. These include, where applicable, encryption of data in transit and at rest, role-based access controls, audit logging, and workforce security training.

How this maps to our products. The Clinical Outcome platform is designed with these safeguards in mind, including encryption and access controls for ePHI. See the Notice of Privacy Practices for how PHI is handled in practice.

6Subcontractors

In accordance with 45 CFR §§164.308(b)(2) and 164.502(e)(1)(ii), Business Associate will require any subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree in writing to restrictions and conditions at least as protective as those in this Agreement.

7Breach reporting

Business Associate will report to Covered Entity any Breach of unsecured PHI without unreasonable delay and no later than 3 calendar days after discovery. The report will include, to the extent known, the individuals affected, a description of what happened, the types of information involved, and the steps taken to mitigate and prevent recurrence.

8Term and termination

This Agreement is effective as of the Effective Date and continues until all PHI is returned or destroyed, or protections are extended to retained PHI. Covered Entity may terminate this Agreement if Business Associate materially breaches it and fails to cure within 30 days of written notice.

Upon termination, Business Associate will, where feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity. Where return or destruction is not feasible, Business Associate will extend the protections of this Agreement to such PHI and limit further uses and disclosures.