Tern Notes Business Associate Agreement
1. Parties and effective date
This Business Associate Agreement (the "Agreement") is between Tern Notes ("Business Associate" or "Tern") and the practice named at sign-up ("Covered Entity" or the "Practice"). It supplements the Tern Notes Terms of Service (the "Terms").
The Agreement takes effect when the person who creates the Practice's workspace checks the acceptance box and selects "Create my practice". That person represents that they have the authority to bind the Practice.
Business Associate provides a clinical documentation service to Covered Entity (the "Service"). In providing the Service, Business Associate creates, receives, maintains, and transmits protected health information for Covered Entity. The parties enter this Agreement to comply with 45 CFR 164.502(e), 164.504(e), 164.308(b), and 164.314(a).
2. Definitions
"HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164.
"Protected Health Information" or "PHI" has the meaning given in 45 CFR 160.103, limited to the information Business Associate creates, receives, maintains, or transmits for Covered Entity. "Electronic PHI" is PHI in electronic form.
"Breach", "Security Incident", "Subcontractor", "Designated Record Set", "Secretary", and "Unsecured PHI" have the meanings given in the HIPAA Rules.
"Unsuccessful Security Incident" means an attempt that does not result in unauthorized access to, or use, disclosure, modification, or destruction of, Electronic PHI, such as a port scan, a blocked login attempt, or a rejected request.
"CMIA" means the California Confidentiality of Medical Information Act, California Civil Code section 56 and following.
3. Obligations of Business Associate
3.1 Uses and disclosures. Business Associate does not use or disclose PHI other than as this Agreement permits or requires, or as required by law.
3.2 Safeguards. Business Associate uses appropriate administrative, physical, and technical safeguards to prevent a use or disclosure of PHI other than as this Agreement provides. Business Associate complies with Subpart C of 45 CFR Part 164 (the Security Rule) for Electronic PHI.
3.3 Reporting. Business Associate reports to Covered Entity any use or disclosure of PHI not provided for by this Agreement, any Security Incident, and any Breach of Unsecured PHI. Business Associate gives an initial notice by email to Covered Entity's administrator address within 5 business days after discovery. The notice includes, to the extent known, the nature of the event, the PHI involved, the individuals affected, the steps individuals should take, and what Business Associate is doing about it. Business Associate provides more information as it becomes available. Business Associate reports Unsuccessful Security Incidents on request rather than one by one. This section is the notice required by 45 CFR 164.410 and 164.314(a)(2)(i)(C).
3.4 Subcontractors. Business Associate ensures that any Subcontractor that creates, receives, maintains, or transmits PHI for Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement, as 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2) require.
3.5 Access. Within 10 business days after a request from Covered Entity, Business Associate makes PHI in a Designated Record Set available to Covered Entity, so that Covered Entity can meet its obligations under 45 CFR 164.524. Business Associate provides an electronic copy when Covered Entity asks for one. If an individual asks Business Associate directly, Business Associate forwards the request to Covered Entity within 5 business days.
3.6 Amendment. Within 10 business days after a request from Covered Entity, Business Associate makes PHI in a Designated Record Set available for amendment and incorporates any amendment that Covered Entity directs, so that Covered Entity can meet its obligations under 45 CFR 164.526.
3.7 Accounting of disclosures. Business Associate records the disclosures of PHI that 45 CFR 164.528 requires an accounting of. Within 10 business days after a request from Covered Entity, Business Associate provides the information Covered Entity needs to give an individual an accounting. Business Associate keeps that information for 6 years.
3.8 Delegated obligations. To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164 (the Privacy Rule), Business Associate complies with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation.
3.9 Books and records. Business Associate makes its internal practices, books, and records about the use and disclosure of PHI available to the Secretary for the purpose of determining compliance with the HIPAA Rules.
3.10 Minimum necessary. Business Associate requests, uses, and discloses only the minimum PHI necessary to accomplish the purpose of the request, use, or disclosure.
3.11 No sale, no marketing. Business Associate does not sell PHI. Business Associate does not use or disclose PHI for marketing or fundraising.
3.12 No ownership. Business Associate has no ownership right in PHI. PHI stays the property of Covered Entity.
3.13 State law. Business Associate complies with the CMIA and with any other state law that applies to PHI and is more stringent than the HIPAA Rules.
3.14 Mitigation. Business Associate mitigates, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI by Business Associate in violation of this Agreement.
4. Permitted uses and disclosures
4.1 Business Associate may use and disclose PHI only as necessary to provide the Service to Covered Entity under the Terms, and as this Agreement otherwise permits.
4.2 Business Associate may use PHI for its proper management and administration, and to carry out its legal responsibilities.
4.3 Business Associate may disclose PHI for its proper management and administration only if the disclosure is required by law, or if Business Associate gets reasonable written assurance from the recipient that the recipient keeps the PHI confidential, uses or discloses it only as required by law or for the purpose of the disclosure, and notifies Business Associate of any breach of confidentiality.
4.4 Business Associate may use PHI to provide data aggregation services relating to the health care operations of Covered Entity only if Covered Entity asks in writing.
4.5 Business Associate does not de-identify PHI for its own use without the written consent of Covered Entity.
4.6 Business Associate may use and disclose PHI as required by law.
4.7 Business Associate does not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as sections 4.2 and 4.3 permit.
5. Subcontractors and data location
5.1 Business Associate uses Google LLC ("Google") as a Subcontractor under the Google Cloud Business Associate Agreement. Google provides hosting, database, storage, key management, logging, identity, Vertex AI, Speech-to-Text, and Document AI services for the Service. Business Associate uses only Google Cloud products that Google lists as covered by that agreement, and only generally available features of those products, with PHI.
5.2 Business Associate's transactional email carries no PHI. Notifications contain a link to the Service and no patient information. Business Associate's email provider is not a Subcontractor under this Agreement.
5.3 Business Associate stores and processes PHI in the United States.
5.4 Business Associate keeps a current list of Subcontractors that handle PHI and gives it to Covered Entity on request.
6. Obligations of Covered Entity
6.1 Covered Entity notifies Business Associate of any limitation in its notice of privacy practices under 45 CFR 164.520, to the extent the limitation affects Business Associate's use or disclosure of PHI.
6.2 Covered Entity notifies Business Associate of any change in, or revocation of, an individual's permission to use or disclose PHI, to the extent the change affects Business Associate's use or disclosure of PHI.
6.3 Covered Entity notifies Business Associate of any restriction on the use or disclosure of PHI that Covered Entity agreed to or must comply with under 45 CFR 164.522, to the extent the restriction affects Business Associate's use or disclosure of PHI.
6.4 Covered Entity does not request Business Associate to use or disclose PHI in a manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as sections 4.2 to 4.4 permit.
6.5 Covered Entity manages its own users of the Service and their access to PHI.
7. Term and termination
7.1 Term. This Agreement takes effect on acceptance and lasts while Covered Entity has an account for the Service, and after that while Business Associate holds any PHI.
7.2 Termination for cause. Either party may terminate this Agreement and the Terms if the other party breaks a material term of this Agreement and does not cure the breach within 30 days after written notice. Covered Entity may terminate at once if a cure is not possible.
7.3 Return or destruction. On termination, Covered Entity may export its records from the Service for 30 days. After that period, Business Associate destroys all PHI that Business Associate or its Subcontractors hold, including the Practice's database and file storage. Backup copies expire within 30 more days. Business Associate certifies the destruction in writing on request.
7.4 Infeasible return or destruction. If return or destruction of some PHI is not feasible, Business Associate tells Covered Entity the conditions that make it infeasible, extends the protections of this Agreement to that PHI, and limits further uses and disclosures to the purposes that make return or destruction infeasible, for as long as Business Associate holds it.
7.5 Survival. The obligations of Business Associate under this Agreement survive termination for as long as Business Associate holds any PHI.
8. General
8.1 Amendment. The parties amend this Agreement as necessary to comply with changes in the HIPAA Rules or other applicable law. Business Associate publishes an amendment as a new version of this Agreement. A new version takes effect for Covered Entity when Covered Entity accepts it. The version accepted stays available to read at any time.
8.2 Interpretation. Any ambiguity in this Agreement is resolved to permit compliance with the HIPAA Rules.
8.3 No third-party beneficiaries. Nothing in this Agreement gives any right or remedy to a person other than the parties and their permitted successors and assigns.
8.4 Assignment. Business Associate may assign this Agreement to a successor entity that takes over the Service and assumes this Agreement in writing, on written notice to Covered Entity. Covered Entity consents in advance to that assignment. The assignment releases the assigning party from obligations that arise after the assignment date. Covered Entity may not assign this Agreement without Business Associate's written consent.
8.5 Governing law. This Agreement is governed by the laws of the State of California, and by the HIPAA Rules where they apply.
8.6 Notices. Notices under this Agreement go by email to the Practice's administrator address and to Tern's support address.
8.7 Regulatory references. A reference in this Agreement to a section of the Code of Federal Regulations means the section as in effect or as amended.
9. Acceptance
By checking the acceptance box and selecting "Create my practice", the person named at sign-up accepts this Agreement for Covered Entity and represents that they have the authority to do so.