Homebase Business Associate Agreement

Business Associate: SLRiches LLC, doing business as Sober Living Riches and Homebase ("Homebase")

This BAA is entered into electronically between Homebase and the customer legal entity identified in the acceptance record ("Customer"). It is effective when an authorized representative accepts it. If Customer is a business associate rather than a covered entity, Homebase acts as its subcontractor business associate.

1. Scope

This BAA applies only to PHI Homebase creates, receives, maintains, or transmits for Customer. HIPAA and HITECH definitions apply. Part 2 records are addressed separately below.

2. Permitted uses and disclosures

Homebase may use or disclose PHI only for contracted services, lawful Customer instructions, or as legally required. It will not otherwise use or disclose PHI. Minimum necessary applies where required. Management or administration disclosures require a legal mandate or confidentiality assurances, purpose limitations, and a recipient duty to report breaches of confidentiality. Homebase will not sell PHI, advertise with it, or train general-purpose models with it. No use is authorized that would violate the Privacy Rule if performed by Customer, except legally permitted management and administration activities. De-identification for unrelated research, marketing, or commercial licensing requires separate lawful authorization.

3. Safeguards

Homebase will implement reasonable and appropriate administrative, physical, and technical safeguards; comply with applicable Security Rule requirements for ePHI; protect against unauthorized use or disclosure; train and authorize applicable workforce; maintain incident procedures; assess risk; and retain required compliance documentation.

4. Reporting

Homebase will notify Customer of unauthorized uses or disclosures, Security Incidents, and Breaches of Unsecured PHI without unreasonable delay and within 30 calendar days of discovery, or sooner when applicable law requires. Discovery includes what reasonable diligence would reveal and workforce or agent knowledge as defined in 45 CFR 164.410. The initial report need not await a completed investigation. Homebase will supplement it promptly with affected individuals when known, the nature and dates of the incident, information involved, mitigation and investigation steps, and contact details reasonably needed for legally required notices. Homebase will mitigate known harmful effects to the extent practicable and cooperate with Customer's response. Customer handles individual, media, and regulator notices unless separately agreed or Homebase is independently required to notify. The parties may agree in writing to aggregate routine unsuccessful incidents; this never exempts an actual unauthorized disclosure or reportable breach.

5. Subcontractors

Homebase will require subcontractors that create, receive, maintain, or transmit PHI to accept written restrictions, safeguards, reporting, and termination duties at least as protective as Homebase's duties and will use covered services within their applicable agreements.

6. Individual rights

Homebase will make designated-record-set PHI available for access under 45 CFR 164.524, incorporate directed amendments under 164.526, and maintain and supply disclosure-accounting information under 164.528. It will respond to Customer without unreasonable delay, ordinarily within ten business days, and cooperate with any shorter applicable deadline. Direct individual requests will be forwarded promptly to Customer. When performing a delegated Privacy Rule duty, Homebase will comply with the rules applicable to that duty. Customer determines the legal response and verifies identity unless otherwise agreed.

7. Customer duties

Customer will notify Homebase of relevant privacy-notice limits, changed permissions, and restrictions; will not instruct an unlawful use or disclosure; will authorize users and apply minimum necessary; will protect exports and devices; and will promptly end unnecessary access.

8. Government and audit support

Homebase will make applicable practices, books, and records available to the Secretary of HHS to determine compliance and will provide Customer reasonable safeguard evidence, subject to security, confidentiality, and third-party restrictions.

9. Termination

Customer may terminate the service agreement for a material BAA violation by Homebase. If cure is possible, Customer may allow a reasonable cure period; it need not continue an incurable violation. Homebase will address known material subcontractor violations and end the relationship if necessary and feasible. On termination, Homebase will return or destroy all PHI, including subcontractor-held copies, where feasible, and retain no copies. If infeasible, it will explain why, continue protection, and limit use to that reason until destruction becomes feasible. Routine backup practices do not excuse feasible return or destruction. These duties survive termination.

10. 42 CFR Part 2

If Customer provides Part 2 records, Customer must identify the applicable program and configure legally sufficient notices, consents, and disclosure instructions. Homebase will process those records only for the contracted purpose and will not use or disclose them in proceedings against the patient except as law permits. The parties will execute additional Part 2 terms if required.

11. Interpretation and electronic execution

This BAA will be interpreted to permit HIPAA and HITECH compliance. When it conflicts with the service agreement about PHI protection, the more protective applicable term controls unless prohibited by law. The authorized representative's acceptance is Customer's electronic signature. Homebase stores the customer legal name, tenant, signer identity and title, authority confirmation, version and hash, exact text, and timestamp.