Skip to main content
VeriPrep
How It Works Pricing For Clinics Research Demo Guide
Get Started →
How It Works Pricing For Clinics Research Demo Guide Get Started →

Business Associate Agreement

Template version: August 15, 2026

This is the standard VeriPrep Business Associate Agreement template. It is published for reference. An actual BAA between VeriPrep and a Covered Entity is the specific document executed or electronically accepted by both parties — not this page.

This Business Associate Agreement (“BAA”) is entered into as of [Effective Date] by and between:

[Full Legal Name of Healthcare Organization], a [State and Entity Type] (“Covered Entity”), and

VeriPrep LLC, an Arizona limited liability company (“Business Associate” or “VeriPrep”).

Covered Entity and VeriPrep may each be referred to as a “Party” and together as the “Parties.”

This BAA supplements and is incorporated into the VeriPrep Services Agreement or other written agreement under which VeriPrep provides services to Covered Entity (the “Services Agreement”).

If there is a conflict between this BAA and the Services Agreement concerning PHI or HIPAA obligations, this BAA controls. Commercial provisions of the Services Agreement, including applicable limitations of liability, apply to this BAA to the extent permitted by law and except where this BAA expressly provides otherwise.

1. Purpose

Covered Entity uses VeriPrep to provide patients with guided healthcare preparation instructions, communications, engagement tracking, operational attention and triage tools, analytics, and related services (collectively, the “Services”).

In providing the Services, VeriPrep may create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity.

The Parties therefore enter into this BAA to satisfy applicable requirements of HIPAA, the HITECH Act, and their implementing regulations.

2. Covered Clinics

This BAA applies to Covered Entity and each clinic, facility, or location that:

  1. is operated as part of the same legal Covered Entity;
  2. is authorized by Covered Entity to use the Services; and
  3. uses the Services under Covered Entity's VeriPrep account.

If a clinic, affiliate, subsidiary, or other healthcare organization is a separate legal entity, this BAA applies to that entity only if Covered Entity has authority to bind that entity or the entity separately agrees in writing or electronically to be bound.

The addition of a new clinic location operated as part of the same Covered Entity does not by itself require execution of a new BAA.

3. Definitions

Capitalized terms not otherwise defined have the meanings assigned under HIPAA and its implementing regulations, including 45 C.F.R. Parts 160 and 164.

“Breach” has the meaning provided in 45 C.F.R. § 164.402.

“Designated Record Set” has the meaning provided in 45 C.F.R. § 164.501.

“Electronic Protected Health Information” or “ePHI” has the meaning provided in 45 C.F.R. § 160.103.

“Protected Health Information” or “PHI” has the meaning provided in 45 C.F.R. § 160.103 and is limited to PHI created, received, maintained, or transmitted by VeriPrep on behalf of Covered Entity.

“Security Incident” has the meaning provided in 45 C.F.R. § 164.304.

“Unsecured Protected Health Information” has the meaning provided in 45 C.F.R. § 164.402.

4. Permitted Uses and Disclosures

4.1 Provision of Services

VeriPrep may use or disclose PHI only as necessary to:

  • Perform the Services for Covered Entity;
  • Administer, operate, secure, maintain, support, and improve the Services as permitted by this BAA;
  • Perform data-aggregation services relating to Covered Entity's healthcare operations where permitted by HIPAA;
  • Fulfill VeriPrep's obligations under the Services Agreement and this BAA; or
  • Comply with applicable law.

VeriPrep will not use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if performed by Covered Entity, except where HIPAA expressly permits a Business Associate to do so.

4.2 Minimum Necessary

To the extent applicable, VeriPrep will limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose, consistent with HIPAA.

4.3 Management and Administration

VeriPrep may use PHI as necessary for the proper management and administration of VeriPrep or to carry out VeriPrep's legal responsibilities.

VeriPrep may disclose PHI for those purposes only if:

  1. The disclosure is required by law; or
  2. VeriPrep obtains reasonable assurances from the recipient that the PHI will remain confidential, will be used or further disclosed only for the purpose for which it was disclosed or as required by law, and the recipient will notify VeriPrep of any breach of confidentiality of which it becomes aware.

4.4 De-Identification

Covered Entity authorizes VeriPrep to de-identify PHI in accordance with 45 C.F.R. § 164.514.

Once information has been properly de-identified in accordance with HIPAA so that it is no longer PHI, VeriPrep may use that information for lawful purposes including:

  • Aggregate analytics;
  • Benchmarking;
  • Product performance measurement;
  • Statistical analysis;
  • Improvement and development of the Services; and
  • Generalized reporting and research.

VeriPrep will not represent information as de-identified merely because it has been aggregated, pseudonymized, or stripped of direct identifiers if the applicable HIPAA de-identification requirements have not been satisfied.

VeriPrep will not attempt to re-identify properly de-identified information except where expressly permitted by HIPAA for purposes such as evaluating a de-identification methodology.

Nothing in this Section permits VeriPrep to sell identifiable PHI or use identifiable PHI for targeted advertising or unrelated marketing.

5. VeriPrep Obligations

5.1 Permitted Use Only

VeriPrep will not use or disclose PHI except as permitted or required by this BAA, the Services Agreement, or applicable law.

5.2 Safeguards

VeriPrep will use appropriate administrative, physical, and technical safeguards to prevent the use or disclosure of PHI other than as permitted by this BAA.

With respect to ePHI, VeriPrep will comply with applicable requirements of the HIPAA Security Rule.

5.3 Reporting Impermissible Uses and Disclosures

VeriPrep will report to Covered Entity any use or disclosure of PHI not permitted by this BAA of which VeriPrep becomes aware.

5.4 Breach Notification

For purposes of this Section, a Breach will be treated as discovered in accordance with the discovery standard applicable to Business Associates under 45 C.F.R. § 164.410, including when the Breach is known or, through the exercise of reasonable diligence, would have been known to VeriPrep.

Following discovery of a Breach of Unsecured PHI involving PHI maintained by VeriPrep on behalf of Covered Entity, VeriPrep will notify Covered Entity:

without unreasonable delay and in no event later than ten (10) business days after discovery.

To the extent information is available, VeriPrep's notice will include:

  1. Identification of each individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed;
  2. A description of what occurred, including the date of the Breach and date of discovery, if known;
  3. The types of PHI involved;
  4. Corrective or mitigating actions taken or proposed by VeriPrep; and
  5. Other information reasonably available to VeriPrep that Covered Entity requires to fulfill applicable breach-notification obligations.

If all relevant information is not available when initial notice is provided, VeriPrep may provide additional information as it becomes available.

Nothing prevents VeriPrep from providing preliminary notice before its investigation is complete.

5.5 Security Incidents

VeriPrep will report to Covered Entity material or non-routine Security Incidents involving Covered Entity's ePHI of which VeriPrep becomes aware without unreasonable delay and in no event later than ten (10) business days after becoming aware of the Security Incident, unless a shorter period is required by applicable law.

The Parties acknowledge that routine unsuccessful attempts to gain unauthorized access to systems occur frequently. Examples include network probes, unsuccessful login attempts, automated scans, pings, and other unsuccessful attacks that do not result in unauthorized access, use, disclosure, modification, or destruction of PHI or material interference with system operations.

The Parties agree that this Section constitutes VeriPrep's notice of such routine unsuccessful Security Incidents and individual notification of each unsuccessful attempt is not required unless applicable law requires otherwise.

5.6 Mitigation

To the extent practicable, VeriPrep will mitigate known harmful effects resulting from a use or disclosure of PHI by VeriPrep in violation of this BAA.

5.7 Subcontractors

VeriPrep may use subcontractors to provide the Services.

VeriPrep will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on VeriPrep's behalf agrees in writing to restrictions, conditions, and safeguards applicable to the subcontractor that are consistent with VeriPrep's obligations under HIPAA and this BAA.

VeriPrep remains responsible for its own obligations under this BAA notwithstanding its use of subcontractors.

5.8 Access to PHI

To the extent VeriPrep maintains PHI in a Designated Record Set on behalf of Covered Entity, VeriPrep will make such PHI available to Covered Entity as reasonably necessary for Covered Entity to satisfy its obligations under 45 C.F.R. § 164.524.

Unless a shorter period is reasonably necessary to permit Covered Entity to comply with applicable law, VeriPrep will respond to a Covered Entity request under this Section within twenty (20) business days after VeriPrep receives the request.

Covered Entity's obligations concerning timely forwarding of applicable requests are stated in the Services Agreement.

5.9 Amendment of PHI

To the extent VeriPrep maintains PHI in a Designated Record Set, VeriPrep will make PHI available for amendment and incorporate amendments as reasonably directed by Covered Entity to allow Covered Entity to comply with 45 C.F.R. § 164.526.

Unless a shorter period is reasonably necessary to permit Covered Entity to comply with applicable law, VeriPrep will respond to a Covered Entity request under this Section within twenty (20) business days after VeriPrep receives the request.

Nothing in this Section requires VeriPrep to alter immutable historical, audit, security, or evidentiary records where doing so would be inappropriate or inconsistent with applicable law, provided VeriPrep reasonably assists Covered Entity in implementing any required correction or amendment.

5.10 Accounting of Disclosures

VeriPrep will maintain and make available information concerning disclosures of PHI as reasonably necessary for Covered Entity to fulfill applicable obligations under 45 C.F.R. § 164.528.

Unless a shorter period is reasonably necessary to permit Covered Entity to comply with applicable law, VeriPrep will respond to a Covered Entity request under this Section within twenty (20) business days after VeriPrep receives the request.

5.11 Government Access

VeriPrep will make its internal practices, books, and records relating to the use and disclosure of PHI received from, created for, or received on behalf of Covered Entity available to the Secretary of the United States Department of Health and Human Services as required for purposes of determining compliance with HIPAA.

6. Covered Entity Obligations

Covered Entity will:

  1. Disclose PHI to VeriPrep only as permitted by HIPAA and other applicable law;
  2. Provide VeriPrep only the PHI reasonably necessary for the Services;
  3. Notify VeriPrep of any limitation in Covered Entity's Notice of Privacy Practices that may affect VeriPrep's use or disclosure of PHI;
  4. Notify VeriPrep of any change in or revocation of an individual's authorization to use or disclose PHI to the extent the change may affect VeriPrep;
  5. Notify VeriPrep of any restriction on use or disclosure of PHI to which Covered Entity has agreed under 45 C.F.R. § 164.522 to the extent the restriction may affect VeriPrep;
  6. Forward requests requiring VeriPrep's assistance in accordance with the Services Agreement; and
  7. Not request or direct VeriPrep to use or disclose PHI in a manner that would violate HIPAA if performed by Covered Entity.

Covered Entity remains responsible for determining the information it is legally permitted to provide to VeriPrep and for its own compliance with HIPAA and other laws applicable to Covered Entity.

7. Patient Communications

Where the Services include communications with patients on Covered Entity's behalf, Covered Entity represents that it has legal authority to direct VeriPrep to send those communications and is responsible for consent, authorization, notice, or other legal requirements arising from Covered Entity's relationship with the patient and Covered Entity's use of the Services, except to the extent VeriPrep expressly assumes a specific obligation in writing.

Nothing in this Section excuses VeriPrep from responsibility for the lawful operation of communication mechanisms, consent language, or messaging behavior controlled by VeriPrep.

VeriPrep will use PHI in patient communications only as permitted by this BAA and applicable law.

8. Term and Termination

8.1 Term

This BAA becomes effective on the Effective Date and remains in effect for as long as VeriPrep creates, receives, maintains, or transmits PHI on behalf of Covered Entity.

8.2 Termination for Cause

If either Party becomes aware of a material breach of this BAA by the other Party, the non-breaching Party may:

  1. Provide the breaching Party a reasonable opportunity to cure the breach; and
  2. Terminate this BAA and affected Services if the breach is not cured within a reasonable period.

A Party may terminate immediately where a material breach cannot reasonably be cured or continued performance would require a violation of applicable law.

8.3 Return or Destruction of PHI

Upon termination of this BAA or the Services Agreement, VeriPrep will, within thirty (30) days to the extent feasible, return or destroy PHI maintained on behalf of Covered Entity that VeriPrep is not legally required or otherwise permitted by this BAA to retain.

If complete return or destruction within that period is not feasible, including because PHI remains in technically unavoidable backup, archival, security, or disaster-recovery systems or because retention is required by law, VeriPrep will:

  1. Continue to protect the retained PHI under this BAA;
  2. Limit further uses and disclosures to purposes that make return or destruction infeasible or to purposes required or permitted by law; and
  3. Not use retained PHI for a new or unrelated purpose.

VeriPrep will delete or destroy retained copies when the reason preventing destruction no longer applies, where feasible.

The obligations of this Section survive termination.

9. Ownership and Sale of PHI

As between the Parties, Covered Entity retains all rights it has in PHI provided to or created by VeriPrep on Covered Entity's behalf.

VeriPrep does not acquire ownership of PHI by providing the Services.

VeriPrep will not sell PHI except where expressly authorized by Covered Entity and permitted by HIPAA.

Nothing in this Section restricts VeriPrep's use of information properly de-identified in accordance with Section 4.4.

10. Changes in Law

The Parties intend this BAA to comply with HIPAA, the HITECH Act, and applicable implementing regulations.

If a change in applicable law requires modification of this BAA, the Parties will cooperate in good faith to amend this BAA as reasonably necessary to maintain compliance.

If a provision conflicts with a mandatory requirement of HIPAA, the mandatory requirement controls and the affected provision will be interpreted, where possible, to comply with that requirement.

11. No Third-Party Beneficiaries

This BAA is for the benefit of Covered Entity and VeriPrep only.

Nothing in this BAA is intended to create rights, remedies, claims, or causes of action in any patient or other third party except to the extent applicable law expressly requires otherwise.

12. Relationship to Services Agreement

Except as modified by this BAA, the Services Agreement remains in effect.

Commercial terms of the Services Agreement—including disclaimers, dispute-resolution provisions, governing-law provisions, and limitations of liability, including the aggregate liability limitation expressly applicable to the BAA—apply to this BAA to the extent permitted by applicable law.

Nothing in this Section reduces or eliminates a HIPAA obligation that applicable law does not permit the Parties to waive or contractually limit.

13. Interpretation

Any ambiguity in this BAA will be interpreted to permit the Parties to comply with HIPAA.

References to statutes and regulations include amendments and successor provisions.

Headings are for convenience only.

14. Entire BAA; Amendment

This BAA constitutes the Parties' agreement concerning handling of PHI in connection with the Services and supersedes prior agreements between the Parties concerning the same subject matter.

This BAA may be amended by a written or electronic agreement accepted by authorized representatives of both Parties.

An update to VeriPrep's website Terms of Use or Privacy Policy does not amend this BAA.

15. Electronic Acceptance

This BAA may be executed electronically, through an electronic acceptance workflow, or in counterparts.

An authorized representative may accept this BAA through an affirmative electronic action presented with access to the BAA.

Electronic acceptance is intended to have the same effect as a manual signature to the extent permitted by applicable law.

VeriPrep may retain evidence of acceptance including:

  • The BAA version;
  • The accepted document or reliable record identifying the exact version accepted;
  • Covered Entity's legal name;
  • The VeriPrep account;
  • Clinics and locations covered by the BAA;
  • Signer's name and title;
  • Signer's authority representation;
  • Date and time;
  • User or account identifier;
  • IP address;
  • Acceptance method; and
  • Other records reasonably necessary to establish execution.

16. Notices

HIPAA, privacy, security, or BAA notices to VeriPrep should be sent to:

VeriPrep LLC
1615 E Georgia Ave #140
Phoenix, AZ 85016
United States
privacy@veriprep.health

Notices to Covered Entity should be sent to the notice contact identified in its VeriPrep Services Agreement or account records.

Either Party may update notice information by written notice without formally amending this BAA.

Signatures

The signature blocks below may be used for manual or electronic-signature-service execution. They are not required where this BAA is validly accepted through VeriPrep's electronic acceptance workflow.

Covered Entity

Legal Name: __________________________________________

Authorized Representative: _____________________________

Title: ________________________________________________

Signature: ____________________________________________

Date: _________________________________________________

VeriPrep LLC

By: Philip Palmer

Title: Founder / Authorized Representative

Signature: ____________________________________________

Date: _________________________________________________

VeriPrep

Guided steps. Better outcomes.

VeriPrep LLC · Arizona
hello@veriprep.health
Privacy PolicyTerms of UseServices AgreementBAA
Built for HIPAA compliance · BAA available with every clinic plan · No PHI in SMS · Encrypted at rest and in transit
© 2026 VeriPrep LLC. All rights reserved.
VeriPrep delivers protocol-configured prep guidance on behalf of healthcare practices. VeriPrep does not provide medical advice. Always follow your healthcare provider's instructions.