KAITALK
🏥 HIPAA Compliance

HIPAA Business Associate Agreement

Document version: 1.0  ·  May 2026

Legal Notice: This template is provided as a starting point for healthcare clients requiring a HIPAA Business Associate Agreement with KAITALK. Review with qualified legal counsel before execution. This document does not constitute legal advice.

1. Parties

This HIPAA Business Associate Agreement ("Agreement") is entered into as of   ("Effective Date"), between:

Covered Entity:   ("Covered Entity"), a   organized under the laws of  , and

Business Associate: KAITALK, a product of Polsia Inc., a Delaware corporation, with its principal place of business at the address on file ("Business Associate" or "BA").

Covered Entity and Business Associate are referred to herein individually as a "Party" and collectively as the "Parties."

This Agreement is incorporated into and made a part of the underlying service agreement between the Parties (the "Service Agreement"). In the event of a conflict between this Agreement and the Service Agreement regarding the subject matter herein, this Agreement shall control.

2. Definitions

Capitalized terms used but not otherwise defined herein shall have the meanings ascribed to them under HIPAA.

2.1 Breach

"Breach" means the acquisition, access, use, or disclosure of Protected Health Information in a manner not permitted under the HIPAA Privacy Rule which compromises the security or privacy of the PHI, as defined in 45 C.F.R. § 164.402.

2.2 Business Associate

"Business Associate" shall have the meaning given to such term under the Privacy Rule, the Security Rule, and the Breach Notification Rule, including, without limitation, 45 C.F.R. § 160.103.

2.3 Electronic Protected Health Information (ePHI)

"Electronic Protected Health Information" or "ePHI" means Protected Health Information that is transmitted by, or maintained in, electronic media, as defined in 45 C.F.R. § 160.103.

2.4 HIPAA

"HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009, and all regulations promulgated thereunder, including the Privacy Rule (45 C.F.R. Parts 160 and 164), the Security Rule (45 C.F.R. Parts 160 and 164), and the Breach Notification Rule (45 C.F.R. Parts 160 and 164).

2.5 Privacy Rule

"Privacy Rule" means the Standards for Privacy of Individually Identifiable Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and E.

2.6 Protected Health Information (PHI)

"Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form or medium, as defined in 45 C.F.R. § 160.103, limited to the PHI that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.

2.7 Security Rule

"Security Rule" means the Security Standards for the Protection of Electronic Protected Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and C.

2.8 Subcontractor

"Subcontractor" means a person or entity who acts on behalf of the Business Associate, other than in the capacity of a member of the Business Associate's workforce, as defined in 45 C.F.R. § 160.103.

3. Permitted Uses and Disclosures by Business Associate

3.1 Scope of Permitted Uses

Business Associate may use or disclose PHI only as necessary to perform the services described in the Service Agreement on behalf of Covered Entity, and only in a manner consistent with this Agreement and the requirements of HIPAA. Specifically, Business Associate may:

  • Use PHI to provide the AI customer care and call-handling services contracted by Covered Entity under the Service Agreement;
  • Disclose PHI to Subcontractors that have agreed in writing to the same restrictions and conditions on the use and disclosure of PHI as apply to Business Associate under this Agreement;
  • Use PHI to perform data aggregation services related to the healthcare operations of Covered Entity, to the extent permitted under 45 C.F.R. § 164.504(e)(2)(i)(B);
  • Use PHI to report violations of law to appropriate federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1);
  • Disclose PHI as required by law, including disclosures required to comply with a judicial or administrative proceeding, or to a government entity as required by law.

3.2 Minimum Necessary

Business Associate shall use, disclose, or request only the minimum PHI necessary to accomplish the intended purpose of the use, disclosure, or request.

3.3 Use for Management and Administration

Business Associate may use PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that disclosures are required by law or Business Associate obtains reasonable assurances that the information will remain confidential and that any breaches will be promptly reported.

4. Prohibited Uses and Disclosures

Business Associate shall not:

  1. Use or disclose PHI in any manner that would violate the requirements of the Privacy Rule if done by Covered Entity;
  2. Use or disclose PHI for marketing purposes as defined under 45 C.F.R. § 164.501, without written authorization from the individual whose PHI is at issue;
  3. Engage in the sale of PHI as defined under 45 C.F.R. § 164.502(a)(5)(ii), without explicit written authorization from Covered Entity and the applicable individual;
  4. Disclose PHI in a manner that would violate 45 C.F.R. § 164.502(a)(5) (restrictions on certain disclosures);
  5. Use or disclose PHI in a way that would require an authorization from the individual under the Privacy Rule, unless such authorization is obtained;
  6. Use or disclose PHI to create a product or service that directly or indirectly competes with services of Covered Entity.

5. Obligations of Business Associate

5.1 Safeguards

Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI (including ePHI) that it creates, receives, maintains, or transmits on behalf of Covered Entity, in accordance with the requirements of the Security Rule (45 C.F.R. §§ 164.308, 164.310, 164.312).

5.2 Reporting of Breaches and Security Incidents

Business Associate shall report to Covered Entity:

  • Breach of Unsecured PHI: Any Breach of Unsecured PHI without unreasonable delay and in no case later than 60 calendar days following discovery of such Breach, as required by 45 C.F.R. § 164.410. The notification shall include, to the extent possible, the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the Breach;
  • Security Incidents: Any Security Incident (as defined in 45 C.F.R. § 164.304) of which it becomes aware, including breaches of its security systems that do not result in a Breach of Unsecured PHI, without unreasonable delay.

Notice shall be provided to Covered Entity's designated Privacy Officer at the contact information provided by Covered Entity.

5.3 Mitigation

Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of this Agreement.

5.4 Subcontractors

Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees, in writing, to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement, pursuant to 45 C.F.R. § 164.504(e)(2)(ii)(D) and § 164.308(b). Business Associate remains liable for the acts and omissions of its Subcontractors to the same extent as it would be for its own acts and omissions.

5.5 Access to PHI

To the extent Business Associate maintains PHI in a designated record set, Business Associate shall make such PHI available to Covered Entity as necessary for Covered Entity to fulfill its obligations to provide individuals with access to their PHI pursuant to 45 C.F.R. § 164.524. If an individual requests access to PHI directly from Business Associate, Business Associate shall promptly forward such request to Covered Entity.

5.6 Amendment of PHI

To the extent Business Associate maintains PHI in a designated record set, Business Associate shall make such PHI available for amendment and shall incorporate any amendments to PHI as directed by Covered Entity pursuant to 45 C.F.R. § 164.526.

5.7 Accounting of Disclosures

Business Associate shall document and make available to Covered Entity the information required for Covered Entity to respond to an individual's request for an accounting of disclosures of PHI as required by 45 C.F.R. § 164.528. Business Associate shall maintain such records for a minimum of six (6) years from the date of the disclosure.

5.8 Books and Records

Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary of the U.S. Department of Health and Human Services (HHS) for purposes of determining Covered Entity's compliance with HIPAA, pursuant to 45 C.F.R. § 164.504(e)(2)(ii)(H).

5.9 Workforce Training and Compliance

Business Associate shall implement and maintain appropriate workforce training programs on HIPAA compliance policies and procedures, and shall take appropriate disciplinary action against workforce members who violate this Agreement or HIPAA requirements.

6. Obligations of Covered Entity

Covered Entity shall:

  1. Notify Business Associate of any limitation(s) in Covered Entity's Notice of Privacy Practices under 45 C.F.R. § 164.520 to the extent that such limitation may affect Business Associate's use or disclosure of PHI;
  2. Notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent that such changes may affect Business Associate's permitted or required uses and disclosures;
  3. Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 C.F.R. § 164.522, to the extent such restriction may affect Business Associate's use or disclosure of PHI;
  4. Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity, except as permitted under this Agreement.

7. Term and Termination

7.1 Term

This Agreement shall be effective as of the Effective Date and shall remain in effect until terminated as provided herein or until the Service Agreement expires or is terminated, whichever is earlier.

7.2 Termination for Cause

Either Party may terminate this Agreement, and the Service Agreement, if the other Party materially breaches any provision of this Agreement. The non-breaching Party shall provide written notice of such breach to the breaching Party. The breaching Party shall have 30 calendar days from receipt of such notice to cure the breach. If the breach is not cured within the 30-day period, the non-breaching Party may immediately terminate this Agreement and the Service Agreement upon written notice to the breaching Party.

If termination is not feasible, the non-breaching Party shall report the problem to the Secretary of HHS.

7.3 Effect of Termination — Return or Destruction of PHI

Upon expiration or termination of this Agreement for any reason:

  • Business Associate shall, at the direction of Covered Entity, return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, that Business Associate maintains in any form. This includes directing Subcontractors to return or destroy all PHI held by them;
  • If Business Associate determines that return or destruction is not feasible, Business Associate shall provide written notice to Covered Entity of the conditions making return or destruction infeasible, and shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, for as long as Business Associate maintains such PHI;
  • Business Associate shall certify in writing to Covered Entity that PHI has been returned, destroyed, or that return/destruction is infeasible within 30 calendar days following the termination date.

8. Miscellaneous

8.1 Liability

Each Party shall be responsible for and shall indemnify, defend, and hold harmless the other Party from and against any and all claims, losses, damages, penalties, fines, and expenses (including reasonable attorneys' fees) arising out of or relating to that Party's own violations of HIPAA, this Agreement, or applicable law. Neither Party shall be liable for the other Party's violations.

8.2 Regulatory Changes

The Parties agree to take such action as is necessary to amend this Agreement from time to time as necessary for compliance with the requirements of HIPAA, the Privacy Rule, the Security Rule, and any other applicable law. Business Associate shall promptly implement any modifications required by regulatory changes and shall notify Covered Entity of material changes that affect obligations under this Agreement.

8.3 Governing Law

This Agreement shall be governed by and construed in accordance with the applicable provisions of Federal law, including HIPAA and the HITECH Act, and, where not preempted by Federal law, the laws of the state in which the Covered Entity is organized, without giving effect to any choice of law or conflict of law rules or provisions.

8.4 Entire Agreement

This Agreement, together with the Service Agreement and any exhibits or schedules attached hereto, constitutes the entire agreement of the Parties with respect to its subject matter and supersedes all prior and contemporaneous negotiations, representations, warranties, and agreements of the Parties with respect to such subject matter.

8.5 Amendment

No amendment, modification, or supplement to this Agreement shall be effective unless set forth in a written instrument duly executed by authorized representatives of both Parties.

8.6 Severability

If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect, and the invalid or unenforceable provision shall be modified to the minimum extent necessary to make it valid and enforceable.

8.7 No Third-Party Beneficiaries

Nothing in this Agreement, express or implied, is intended to or shall confer upon any person or entity (other than the Parties and their respective successors and permitted assigns) any legal or equitable right, benefit, or remedy of any nature whatsoever under or by reason of this Agreement.

8.8 Survival

The respective rights and obligations of Business Associate under Sections 4, 5.7, 5.8, 7.3, and 8.1 of this Agreement shall survive the termination of this Agreement.

8.9 Counterparts; Electronic Signatures

This Agreement may be executed in one or more counterparts, each of which shall constitute an original, and all of which together shall constitute one and the same Agreement. Electronic signatures shall be deemed valid and enforceable to the same extent as original signatures.

9. Execution

The Parties have executed this Agreement as of the Effective Date first written above. Each signatory represents that he or she is duly authorized to execute this Agreement on behalf of the respective Party.

Covered Entity

Authorized Signature
Printed Name
Title
Date
Organization Name

Business Associate — KAITALK (Polsia Inc.)

Authorized Signature
Printed Name
Title
Date
Polsia Inc. (KAITALK)
KAITALK
Trust|Privacy|Terms|NOM-024|LFPDPPP|HIPAA
© 2026 KAITALK — a Q Bridge product.
KAITALK
Trust|Privacy|Terms|NOM-024|LFPDPPP|HIPAA
© 2026 KAITALK — a Q Bridge product.