StatCura Medical
45 CFR Parts 160 & 164 Compliant

HIPAA Business Associate Agreement

Legally binding BAA governing the transmission, processing, and protection of Protected Health Information (PHI) between independent medical clinics and StatCura Medical.

AES-256 Encryption at Rest
TLS 1.3 in Transit
Direct Electronic Countersignature

Mandatory Compliance

Every clinic onboarded on StatCura executes this BAA electronically before a single claim or encounter is processed.

Zero PHI Sale

StatCura never sells, monetizes, or shares patient health data. PHI is utilized strictly for revenue cycle billing and reconciliation.

HITECH Incident Notice

Full compliance with 45 CFR § 164.410 breach notification rules within sixty days of discovery, backed by 24/7 audit logging.

Standard Business Associate Clauses

Compliant with the Office for Civil Rights (OCR) and US Department of Health and Human Services (HHS) model provisions.

statcura.com/baa
1.0

Definitions and Statutory Framework

This Business Associate Agreement ('BAA') is entered into by and between the healthcare entity utilizing the StatCura Medical platform ('Covered Entity' or 'Practice') and StatCura Medical Inc. ('Business Associate', operating via statcura.com).

Terms used but not otherwise defined in this BAA shall have the same meaning as those terms in the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164 (collectively referred to as the 'HIPAA Rules').

'Protected Health Information' or 'PHI' shall have the meaning given to such term under 45 CFR § 160.103, limited to the information created, received, maintained, or transmitted by Business Associate from or on behalf of Covered Entity in connection with autonomous revenue cycle management services.

2.0

Permitted Uses and Disclosures of PHI

Except as otherwise limited in this Agreement or Master Services Agreement, Business Associate may use or disclose PHI only to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the service documentation.

Specific permitted operations include: (a) pre-submission claim validation and National Correct Coding Initiative (NCCI) scrubbing; (b) EDI 837 claim transmission to authorized commercial and government clearinghouses and payers; (c) EDI 270/271 real-time eligibility verification; (d) automated clinical appeal generation for denied claims; and (e) automated Electronic Remittance Advice (ERA 835) reconciliation.

Business Associate may also use PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that disclosures are required by law or reasonable assurances are obtained regarding confidentiality.

Zero Commercialization Covenant: Business Associate shall never sell, rent, monetize, or commercialize PHI, nor use PHI for marketing, advertising, or unauthorized algorithmic data brokers.

3.0

Technical, Administrative, and Physical Safeguards

Business Associate agrees to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic PHI that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by Subpart C of 45 CFR Part 164.

Encryption Standards: All electronic Protected Health Information (ePHI) stored within StatCura systems is encrypted at rest using industry standard Advanced Encryption Standard with 256-bit keys (AES-256). All data transmitted over public networks is encrypted using Transport Layer Security (TLS 1.3 or higher).

Access Controls and Audit Logging: Business Associate enforces strict role-based access control (RBAC), multi-factor authentication (MFA) for all administrative interfaces, and immutable audit logging for every read, write, export, or transmission of PHI.

4.0

Breach Notification and Incident Response (45 CFR § 164.410)

Business Associate shall report to Covered Entity any unauthorized acquisition, access, use, or disclosure of Protected Health Information not permitted by this BAA or applicable law without unreasonable delay.

Statutory Sixty-Day Reporting Window: In the event of a confirmed Breach of Unsecured PHI as defined in 45 CFR § 164.402, Business Associate shall notify Covered Entity in writing without unreasonable delay and in no event later than sixty (60) calendar days after discovery of the Breach.

Incident Detail Specifications: The notification shall include, to the extent reasonably known: (a) identification of each individual whose unsecured PHI has been or is reasonably believed to have been breached; (b) a description of what occurred, including incident dates and discovery timestamps; (c) the categories of PHI involved; and (d) the remediation and containment steps implemented by Business Associate.

UK GDPR Incident Coordination: To the extent personal data governed by the UK GDPR is affected, Business Associate will assist Covered Entity without undue delay in notifying the Information Commissioner's Office (ICO) within 72 hours of becoming aware of a personal data breach.

5.0

Subcontractors and Downstream Business Associates

In accordance with 45 CFR § 164.502(e)(1)(ii) and § 164.308(b)(2), Business Associate ensures that any agent or downstream subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and safeguards that apply to Business Associate.

All clearinghouse partners, secure cloud hosting providers, and encrypted database infrastructure utilized by StatCura are bound by signed Business Associate Agreements conforming to HIPAA and UK GDPR Article 28 data processor standards.

6.0

Individual Rights to Access, Amendment, and Accounting

Access to Designated Record Sets: Within ten (10) business days of receiving a written request from Covered Entity, Business Associate shall make available PHI in a Designated Record Set to Covered Entity to satisfy Covered Entity obligations under 45 CFR § 164.524.

Amendment of PHI: Business Associate shall promptly incorporate any amendments to PHI in a Designated Record Set as directed by Covered Entity pursuant to 45 CFR § 164.526.

Accounting of Disclosures: Business Associate shall document disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an individual for an accounting of disclosures pursuant to 45 CFR § 164.528.

7.0

Term, Termination, and Cryptographic Disposal

Term: This BAA takes effect upon Client registration on the StatCura platform at statcura.com and shall terminate when all PHI provided by Covered Entity is destroyed or returned.

Termination for Cause: Upon Covered Entity knowledge of a material breach by Business Associate, Covered Entity may immediately terminate the Master Services Agreement if Business Associate fails to cure the breach within thirty (30) days of receiving written notice.

Return or Cryptographic Destruction: Upon termination for any reason, Business Associate shall, if feasible, return or destroy all PHI received from Covered Entity. Where return or destruction is infeasible (such as maintaining regulatory audit trails required by CMS timely filing rules and False Claims Act retention periods), Business Associate shall extend the protections of this Agreement to such information and limit further uses to those statutory purposes.

8.0

Transatlantic Cross-Border Infrastructure & UK Safeguards

Covered Entity acknowledges that Business Associate maintains an integrated transatlantic engineering and operational team operating under United States and United Kingdom legal jurisdictions.

Under 45 CFR § 164.502(e), foreign technology entities are legally authorized to serve as HIPAA Business Associates for United States Covered Entities provided they execute this binding BAA and maintain administrative, technical, and physical safeguards meeting or exceeding HIPAA Security Rule specifications.

UK GDPR Article 28 Alignment: When processing personal data subject to UK data protection legislation, Business Associate acts as a Data Processor adhering strictly to Article 28 UK GDPR requirements, including Standard Contractual Clauses (SCCs) and UK International Data Transfer Addendum mechanisms.

All production data repositories storing PHI reside within SOC 2 Type II and HIPAA compliant cloud facilities, and all international personnel accessing technical systems are bound by background verification and non-disclosure covenants.

9.0

Covered Entity Clinical Warranty & False Claims Hold Harmless

Clinical Accuracy Certification: Covered Entity represents and warrants that all clinical encounter records, ICD-10 diagnosis codes, CPT procedure codes, and modifiers submitted to Business Associate reflect authentic healthcare services actually rendered to bona fide patients by licensed personnel.

False Claims Act Indemnification: Covered Entity covenants that no data submitted violates the False Claims Act (31 U.S.C. §§ 3729-3733) or Anti-Kickback Statute (42 U.S.C. § 1320a-7b). Covered Entity agrees to defend, indemnify, and hold harmless Business Associate against any regulatory investigations, whistleblower actions, recoupments, or penalties arising from fraudulent or inaccurate clinical coding submitted by Covered Entity.

10.0

Regulatory Amendments, Arbitration & Electronic Execution

Regulatory Conformance: The parties agree to take such action as is necessary to amend this BAA from time to time as required for Covered Entity or Business Associate to comply with the requirements of HIPAA, HITECH, the UK GDPR, and other applicable laws.

Binding Arbitration: Any controversy or claim arising out of or relating to this BAA shall be resolved exclusively through the confidential binding individual arbitration procedures set forth in Section 9.0 of the StatCura Master Services Agreement.

Electronic Execution under E-SIGN: By completing clinic onboarding on the StatCura platform at statcura.com, Covered Entity and Business Associate agree that digital acceptance constitutes a valid, legally enforceable signature under the Electronic Signatures in Global and National Commerce Act (E-SIGN Act).

Health and Human Services (HHS) Rule Integration

This agreement satisfies all required Business Associate provisions under the HIPAA Privacy, Security, and Breach Notification Rules codified at 45 CFR Parts 160 and 164. A signed, stamped copy with your practice NPI and digital countersignature is available for download in your Clinic Staff Portal under Practice Settings at any time.

Need a countersigned BAA for your compliance binder?
Our operations team provides instant verified PDF certificates.