Business Associate Agreement
Effective date: June 26, 2026
This Business Associate Agreement (“BAA”) supplements and is incorporated into the Terms of Service or other written agreement (the “Agreement”) between Convey, Inc. (“Business Associate” or “Convey”) and the customer that is a covered entity or business associate under HIPAA (“Covered Entity” or “Customer”). It governs the parties’ obligations with respect to Protected Health Information and is entered into to comply with the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including the Privacy, Security, and Breach Notification Rules, as amended by the HITECH Act (collectively, “HIPAA”).
In the event of a conflict between this BAA and the Agreement with respect to Protected Health Information, this BAA controls.
1. Definitions
Capitalized terms used but not defined in this BAA have the meanings given to them in HIPAA. “Protected Health Information” or “PHI” means individually identifiable health information that Convey creates, receives, maintains, or transmits on behalf of Customer in connection with the Service. “Electronic PHI” or “ePHI” means PHI maintained or transmitted in electronic form.
2. Permitted Uses and Disclosures by Business Associate
- Convey may use and disclose PHI only as necessary to perform the services described in the Agreement, as permitted or required by this BAA, or as Required by Law.
- Convey may use PHI for the proper management and administration of Convey or to carry out its legal responsibilities.
- Convey may disclose PHI for its proper management and administration or to carry out its legal responsibilities only if the disclosure is Required by Law, or if Convey obtains reasonable assurances from the recipient that the PHI will be held confidentially and used or disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Convey of any breach of confidentiality.
- Convey may provide Data Aggregation services relating to the health care operations of Customer and may de-identify PHI in accordance with HIPAA, each as permitted by HIPAA.
3. Obligations of Business Associate
Convey agrees to:
- not use or disclose PHI other than as permitted or required by this BAA or as Required by Law;
- use appropriate administrative, physical, and technical safeguards, and comply with the HIPAA Security Rule with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this BAA;
- apply the minimum necessary standard to its uses, disclosures, and requests for PHI;
- report to Customer any use or disclosure of PHI not provided for by this BAA of which it becomes aware, any Security Incident, and any Breach of Unsecured PHI, without unreasonable delay and as further described in Section 6;
- in accordance with HIPAA, ensure that any subcontractors that create, receive, maintain, or transmit PHI on Convey’s behalf agree in writing to restrictions and conditions at least as protective as those that apply to Convey under this BAA;
- make available PHI in a Designated Record Set as necessary to satisfy Customer’s obligations regarding individual access under 45 C.F.R. § 164.524;
- make available PHI for amendment and incorporate amendments as necessary to satisfy Customer’s obligations under 45 C.F.R. § 164.526;
- maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy Customer’s obligations under 45 C.F.R. § 164.528;
- to the extent Convey carries out a Customer obligation under the Privacy Rule, comply with the requirements of the Privacy Rule that apply to Customer in the performance of that obligation; and
- make its internal practices, books, and records relating to the use and disclosure of PHI available to the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
4. Obligations of Covered Entity
- Customer will notify Convey of any limitation in its notice of privacy practices, any changes in or revocation of an individual’s permission to use or disclose PHI, and any restriction on the use or disclosure of PHI that Customer has agreed to or is required to abide by, to the extent any of these may affect Convey’s use or disclosure of PHI.
- Customer will not request that Convey use or disclose PHI in any manner that would not be permitted under HIPAA if done by Customer, except as permitted under Section 2 for Convey’s management, administration, legal responsibilities, or Data Aggregation.
- Customer is responsible for obtaining any consents, authorizations, and legal bases required for Convey to receive and process PHI through the Service.
5. Safeguards and Security
Convey will implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI as required by the HIPAA Security Rule, including access controls, encryption of ePHI in transit and at rest, audit logging, and workforce safeguards. Further detail about Convey’s security program is available on our Security page.
6. Reporting and Breach Notification
Convey will report to Customer, without unreasonable delay and in any event within the timeframes required by HIPAA, any use or disclosure of PHI not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI of which Convey becomes aware. The report will include, to the extent known and as it becomes available, the information necessary for Customer to meet its breach-notification obligations under 45 C.F.R. § 164.404. The parties acknowledge that this Section constitutes notice of the ongoing occurrence of unsuccessful Security Incidents (such as pings, port scans, and unsuccessful log-in attempts) for which no additional notice will be required.
7. Term and Termination
7.1 Term
This BAA is effective as of the date the Agreement takes effect and remains in effect until the Agreement terminates or all PHI is returned or destroyed in accordance with Section 7.3, whichever is later.
7.2 Termination for cause
If Customer determines that Convey has materially breached this BAA, Customer may provide written notice of the breach and an opportunity to cure within a reasonable period; if Convey does not cure, Customer may terminate the Agreement and this BAA.
7.3 Effect of termination
Upon termination, Convey will, if feasible, return or destroy all PHI it maintains in any form and retain no copies, or make PHI available for export as described in the Agreement. If return or destruction is not feasible, Convey will extend the protections of this BAA to the PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as Convey retains the PHI.
8. Miscellaneous
- Regulatory references are to the section of HIPAA in effect or as amended.
- Amendment. The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for compliance with HIPAA and other applicable law.
- Interpretation. Any ambiguity in this BAA will be resolved to permit the parties to comply with HIPAA.
- No third-party beneficiaries. Nothing in this BAA confers any rights upon any person other than the parties and their respective successors and permitted assigns.
- Survival. Obligations that by their nature should survive termination, including those in Section 7.3, will survive.
9. Contact
Questions about this BAA, or requests to execute a countersigned copy, may be directed to legal@convey.care, or by mail to Convey, Inc., 10776 N 112th Pl, Scottsdale, AZ 85259.