Legal

Business Associate Agreement

HIPAA requires a written agreement between your practice and any company that handles patient information for it. This is ours. It is part of the Service and you accepted it with the Terms of Service, so there is nothing extra for you to sign and nothing to request.

Last updated: August 12, 2026

1. What this agreement is, and how you accepted it

This Business Associate Agreement is part of your agreement with Practice Evolved, Inc. and takes effect on the first of these to happen: you accept the Terms of Service, you enter a setup code, or you connect a practice management system to the Service. It is a written contract for the purposes of 45 CFR 164.502(e) and 164.504(e). There is nothing further for you to sign and nothing for you to request. Clause 21 of the Terms makes your electronic acceptance your signature. Where you accepted on our website, we record the date, the time, the account, and the version of the document you accepted, and we can produce that record. This agreement applies from the moment we could receive protected health information from you, not from the moment we first do, and it applies whether or not you use every part of the Service. If your practice needs a countersigned paper copy for its own records, email support@practiceevolved.com and we will provide one; the protections below apply either way and do not wait for it.

2. The words used here

Protected health information, electronic protected health information, covered entity, business associate, subcontractor, breach, security incident, designated record set, individual, required by law, and unsecured protected health information have the meanings given to them in 45 CFR Parts 160 and 164, as amended, which this agreement calls HIPAA. In this agreement, you and your practice mean the covered entity that accepted it, we and us mean Practice Evolved, Inc. acting as your business associate, the Service means what the Terms of Service describe, and your patient information means protected health information that we create, receive, maintain, or transmit for you. Where a term is defined both here and in the Terms, the definition here governs for protected health information.

3. What we may use your patient information for

We may use and disclose your patient information only to provide and support the Service for your own practice as the Terms describe, to carry out our own proper management and administration, to carry out our legal responsibilities, and where the law requires it. We may disclose your patient information for our own management and administration only where the law requires the disclosure, or where we first obtain written assurances from the person receiving it that they will keep it confidential, use or further disclose it only as required by law or for the purpose we gave it to them, and tell us of any breach of its confidentiality. Apart from the uses for our own management and administration and to carry out our legal responsibilities that this clause permits, which 45 CFR 164.504(e)(4) expressly allows a business associate, any use or disclosure we make would be permitted under HIPAA if your practice made it. Nothing in this agreement asks you to permit a use we could not lawfully make.

4. What we will not do with it

We will not use or disclose your patient information other than as this agreement permits or the law requires. We will not sell it. We will not use it for marketing, for fundraising, or for advertising, ours or anyone else's. We do not provide data aggregation services and we do not combine your patient information with another practice's; if that ever changes we will amend this agreement first and tell you before it takes effect. We will not strip the identifiers out of your patient information to make a data set we use for our own purposes. We will not use it to train a general purpose model, and we do not permit a vendor we use to train on it. We will not use your patient information to produce anything shown to a different practice: every record we hold is scoped to the practice it came from, and where the Service compares your numbers to a benchmark, that benchmark is a published industry target and not a figure derived from other practices' data.

5. Only what is needed

When we use, disclose, or request your patient information, we limit it to the minimum necessary for the purpose, as 45 CFR 164.502(b) and 164.514(d) require. In practice this shapes the product and not only the paperwork. Our software reads your practice management system read only, and the single thing it can ever write is a note. On Open Dental, and only on Open Dental, it can add a comment to a claim or to a patient's record noting what your team did about that claim; this is on by default and your practice can turn it off at any time by telling us, and we will not turn it back on. On every other practice management system our software refuses the write outright rather than merely hiding the button. Because it writes into your patient's record, treat anything your team types into a claim comment as something that becomes part of that record. It never writes a balance, a claim status, a payment, an adjustment, or any calculated figure, and on every other practice management system we make no writes at all. We hold identifiers only where a task genuinely needs them, and our software reports counts rather than values when it records what it read.

6. How we protect it

We use appropriate administrative, physical, and technical safeguards to prevent any use or disclosure of your patient information that this agreement does not permit, and we comply with Subpart C of 45 CFR Part 164, the Security Rule, with respect to electronic protected health information, as 45 CFR 164.314(a) and 164.504(e)(2)(ii)(B) require. Your patient information is encrypted in transit everywhere it travels, and in our systems it is encrypted at rest, with the database encrypted using a key we manage. Access is restricted to the people who need it to run the Service, and every record is scoped to your practice. One thing is worth stating plainly rather than leaving to be discovered: our software running on your own computer keeps a small working file there so it does not have to read the same records again every time, and that file sits inside your own network on a machine you control, protected by your own security rather than by ours. It holds nothing your practice management system on that same machine does not already hold. We do not write patient identifiers or note text into our application logs, our email, or our audit trails. Where the Service displays your information to your staff, it does so inside your own authenticated dashboard.

7. The people and companies we use

We may use subcontractors to help provide the Service. Where a subcontractor creates, receives, maintains, or transmits your patient information on our behalf, we will first enter into a written agreement with it that imposes the same restrictions and conditions that this agreement imposes on us, as 45 CFR 164.502(e)(1)(ii) and 164.308(b) require, and we remain responsible to you for what it does with that information. Our infrastructure runs on Amazon Web Services under an executed business associate agreement with Amazon, using services Amazon designates as HIPAA eligible. We will not route your patient information through a vendor that will not sign a business associate agreement. If you ask us in writing, we will tell you which subcontractors currently handle your patient information.

8. Telling you when something goes wrong

We will report to you any use or disclosure of your patient information that this agreement does not permit, any security incident affecting it, and any breach of unsecured protected health information, as 45 CFR 164.504(e)(2)(ii)(C) and 164.410 require. For a breach of unsecured protected health information we will tell you without unreasonable delay and in any event no later than ten business days after we discover it, which is well inside the outer limit HIPAA sets and is meant to leave your practice time to meet its own notification duties. Our report will identify each individual whose information we believe was involved, and will give you the other information HIPAA requires you to include in your own notice, to the extent we have it or can obtain it. We will tell you what happened, what we have done, and what we are doing to reduce the harm and to stop it happening again, and we will keep you updated as we learn more rather than waiting until we know everything. Attempted and unsuccessful security incidents that do not result in unauthorized access, use, disclosure, modification, or destruction, such as scans, pings, port probes, blocked traffic, and failed log in attempts, are reported to you by this sentence and we will not send a separate notice for each one.

9. A patient's own rights

Your practice, not us, holds the designated record set for your patients, and we hold a copy of part of it in order to run the Service. To the extent we hold your patient information in a designated record set, we will make it available to you so that you can meet your obligations under 45 CFR 164.524 when a patient asks for access, we will make it available for amendment and will incorporate any amendment you direct so that you can meet 45 CFR 164.526, and we will make available the information you need to give a patient an accounting of disclosures under 45 CFR 164.528. We will do each of those within ten business days of your written request, or sooner where the deadline you are working to requires it, and we will tell you promptly if we cannot. If a patient comes to us directly with one of these requests we will not answer it ourselves; we will forward it to you and tell the patient we have done so.

10. Where we carry out your obligations

To the extent we agree to carry out one of your obligations under Subpart E of 45 CFR Part 164, the Privacy Rule, we will comply with the requirements of Subpart E that apply to you when you carry out that obligation, as 45 CFR 164.504(e)(2)(ii)(H) requires. We do not otherwise take on your obligations, and nothing in this agreement or in the Terms makes us responsible for your practice's own compliance.

11. Making our records available to the government

We will make our internal practices, books, and records relating to the use and disclosure of your patient information available to the Secretary of the United States Department of Health and Human Services for the purpose of determining your practice's compliance with HIPAA, as 45 CFR 164.504(e)(2)(ii)(I) requires. We will tell you when we do, unless the law prevents us from telling you.

12. What happens to your information at the end

When this agreement ends, we will return or destroy all of your patient information that we still hold, including any held by a subcontractor, and keep no copies, as far as it is feasible to do so. We will do that within thirty days of the end of your use of the Service, or within thirty days of a later written request from you, whichever is later. A written request while you are still using the Service does not end it. One part of this is not immediately feasible and we would rather say so than write a promise we cannot keep: encrypted backups are written on a rolling schedule and expire on their own cycle, so a copy of your patient information can remain in a backup for a period after the live data is deleted. For as long as any such copy exists, this agreement continues to apply to it, we will not use or disclose it for any purpose other than the one that makes returning or destroying it infeasible, and we will destroy it when the backup expires. If you ask, we will tell you the current backup retention period in writing.

13. What your practice is responsible for

You will tell us of any limitation in your notice of privacy practices, of any change in or revocation of a patient's permission to use or disclose their information, and of any restriction on use or disclosure that you have agreed to under 45 CFR 164.522, in each case to the extent it affects what we may do. You will not ask us to use or disclose your patient information in a way that would not be permitted under HIPAA if your practice did it itself. You are responsible for the lawfulness of the data you connect or make available to us, for having the authority to connect it, and for your own obligations as a covered entity, including your notice of privacy practices, your workforce training, your patients' requests about their own records, and the security of your own systems, equipment, and accounts.

14. How long it lasts, and ending it

This agreement starts when clause 1 says it starts and continues until all of your patient information has been returned or destroyed under clause 12, or, for information we cannot feasibly return or destroy, for as long as we hold it. If either of us materially breaches this agreement, the other may give written notice describing the breach, and if it is not cured within thirty days the party who gave the notice may terminate this agreement and your use of the Service. Nothing in that mechanic limits your right as the covered entity to terminate this agreement and your use of the Service immediately if you determine that we have violated a material term of it, which is the right 45 CFR 164.504(e)(2)(iii) requires this agreement to give you, and you do not have to wait out a cure period to exercise it. Where a cure is not possible, either of us may terminate immediately. Every clause of this agreement continues to apply to any of your patient information we still hold after termination, for as long as we hold it, as clause 12 provides; clauses 2, 4, 6, 8, 9, 11, 12, 15, 16, and this clause survive in any event.

15. How liability works for this agreement

The cap in clause 17 of the Terms of Service is the greater of the fees you paid us in the last twelve months or one hundred dollars. That cap does not apply to a claim arising from our breach of clause 4 or clause 6 of this agreement, or from our own negligence or willful misconduct in handling your patient information, and it does not apply to the costs described in the next sentence. Where a breach of unsecured protected health information is caused by our act or omission, we will bear the reasonable and documented cost of the notification your practice is required to make because of it, including notifying the affected individuals, notifying the Secretary and the media where HIPAA requires it, and the credit monitoring you reasonably offer. The indemnity you give us in clause 18 of the Terms does not extend to a claim arising from our breach of this agreement, our negligence, or our willful misconduct, and we say so here so that neither of us has to argue about it later. We carry insurance appropriate to this Service and will confirm our current coverage in writing on request.

16. How this agreement fits with the others

This agreement controls over the Terms of Service and the End User License Agreement as to protected health information, and those documents govern everything else. Nothing in this agreement creates a right for any third party, and no patient or other person is a third party beneficiary of it. Any ambiguity in this agreement is resolved in favor of the meaning that complies with HIPAA. If HIPAA changes in a way that requires a change here, we will amend this agreement to comply, we will publish the amended version with a new version identifier and a new last updated date, and we will tell you before it takes effect; if you do not accept an amendment that the law requires, either of us may terminate under clause 14. A reference to a section of HIPAA includes any successor to that section.

If your practice needs a countersigned copy

Some practices keep a signed paper copy of every business associate agreement in their compliance file. Email support@practiceevolved.com and we will send one. The protections above already apply either way and do not wait for it.

Read this alongside our Terms of Service and End User License Agreement. (c) 2026 Practice Evolved, Inc. All rights reserved.