Business Associate Agreement (BAA)
Effective Date: January 1, 2026 | BRAINTMS LLC d/b/a MedBid
Preamble
This Business Associate Agreement ("BAA") is entered into by and between BRAINTMS LLC d/b/a MedBid ("Business Associate" or "MedBid") and the Covered Entity or Business Associate that executes or accepts this agreement ("Covered Entity") in connection with the MedBid platform. This BAA is intended to comply with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 C.F.R. Parts 160 and 164.
Definitions
Terms used but not otherwise defined herein shall have the same meaning as ascribed to them in 45 C.F.R. §§ 160.103 and 164.501. "Protected Health Information" or "PHI" has the meaning set forth in 45 C.F.R. § 160.103, as limited to PHI created, maintained, transmitted, or received by MedBid on behalf of Covered Entity.
Obligations of MedBid
- Not use or disclose PHI other than as permitted by this BAA or as required by law.
- Use appropriate safeguards, and comply with 45 C.F.R. Part 164 Subpart C regarding ePHI, to prevent use or disclosure of PHI other than as provided in this BAA.
- Report to Covered Entity any use or disclosure of PHI not provided for under this BAA, including any Breach of Unsecured PHI, within the time frames required by HIPAA.
- In accordance with 45 C.F.R. § 164.502(e)(1)(ii), ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of MedBid agree to the same restrictions and conditions that apply to MedBid.
- Make available PHI in accordance with 45 C.F.R. § 164.524.
- Document disclosures of PHI and information related to such disclosures as required by 45 C.F.R. § 164.528.
Permitted Uses and Disclosures
MedBid may use and disclose PHI only as necessary to perform its obligations under the Platform agreement with Covered Entity, and as permitted by this BAA. MedBid may use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity, and to de-identify PHI in accordance with 45 C.F.R. § 164.514(b).
Term and Termination
This BAA is effective upon acceptance and remains in effect until the Platform services agreement terminates or expires. Upon termination, MedBid shall destroy or return all PHI in its possession within 60 days, unless legally required to retain it.
Miscellaneous
This BAA is incorporated by reference into the MedBid Terms of Service. In the event of conflict between this BAA and the Terms of Service regarding PHI, this BAA controls. Nothing in this BAA shall create any third-party beneficiary rights. To execute this BAA or request a signed copy, contact legal@medbid.ai.