Legal · HIPAA

Business Associate Agreement

Version: 2026-07-31

Important: this is a template we ask every organization to accept when creating an account, not a substitute for independent legal advice. If your organization has specific compliance requirements beyond this Agreement, contact us at hello@theralyn.co before storing client data with Theralyn.

This Business Associate Agreement ("Agreement") is entered into between Theralyn ("Business Associate") and the organization that accepts it when creating a Theralyn account ("Covered Entity"), and governs the creation, receipt, maintenance, and transmission of protected health information (PHI) by Business Associate on Covered Entity's behalf, supplementing our Terms of Service.

1. Definitions

“Business Associate” means Theralyn. “Covered Entity” means the therapy practice or organization that has created an account to store client data through Theralyn. “PHI” and “Breach” have the meanings given in HIPAA (the Health Insurance Portability and Accountability Act) and its implementing regulations, as amended from time to time.

2. Obligations of Business Associate

Business Associate agrees to: (a) not use or disclose PHI other than as permitted by this Agreement or required by law; (b) use appropriate administrative, technical, and physical safeguards to prevent unauthorized use or disclosure of PHI; (c) report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, and any Breach of unsecured PHI, without unreasonable delay; (d) ensure any subcontractor that creates, receives, maintains, or transmits PHI on Business Associate's behalf agrees to the same restrictions and conditions; (e) make PHI available to Covered Entity as needed to fulfill an individual's request for access, amendment, or an accounting of disclosures; (f) make internal practices, books, and records available to the Secretary of Health and Human Services for purposes of determining compliance; and (g) at termination of this Agreement, return or destroy all PHI, or if that is not feasible, extend the protections of this Agreement to the PHI retained and limit further uses and disclosures.

3. Permitted Uses and Disclosures

Business Associate may use and disclose PHI only: (a) to perform the services described in the underlying Terms of Service on behalf of Covered Entity; (b) for Business Associate's own proper management and administration, or to carry out its legal responsibilities; and (c) to report violations of law to appropriate authorities. Business Associate does not use PHI for its own marketing or advertising and does not sell PHI.

4. Obligations of Covered Entity

Covered Entity agrees to notify Business Associate of any limitation in its own notice of privacy practices, any change in or revocation of an individual's permission for Theralyn to use or disclose PHI, and any restriction on the use or disclosure of PHI that Covered Entity has agreed to, to the extent any of these affect Business Associate's use or disclosure of PHI. Covered Entity remains solely responsible for its own direct obligations to the individuals it treats, including providing its own Notice of Privacy Practices.

5. Subcontractors and Infrastructure

Business Associate may engage subcontractors (such as cloud hosting and infrastructure providers) that create, receive, maintain, or transmit PHI in the course of providing the service, and requires each such subcontractor to agree to protections at least as restrictive as those in this Agreement. Business Associate maintains a current list of subprocessors and will make it available on request.

6. Term and Termination

This Agreement is effective for as long as Business Associate creates, receives, maintains, or transmits PHI on behalf of Covered Entity under the underlying Terms of Service. Either party may terminate this Agreement for cause upon a material breach by the other party, if the breach is not cured within a reasonable time after written notice. Upon termination, Business Associate will, at Covered Entity's election, return or destroy all PHI still in its possession; if return or destruction is not feasible, this Agreement's protections will continue to apply to that PHI for as long as it is retained.

7. Breach Notification

Business Associate will notify Covered Entity of any Breach of unsecured PHI without unreasonable delay, and in no case later than required by HIPAA's Breach Notification Rule, so that Covered Entity can meet its own notification obligations to affected individuals, the Department of Health and Human Services, and, where applicable, the media.

8. Amendment

The parties agree to amend this Agreement as necessary for Business Associate to comply with HIPAA and its implementing regulations. Business Associate may update this Agreement from time to time; material changes will be communicated to Covered Entity's account administrator, and continued use of the service after such notice constitutes acceptance of the updated Agreement.

9. Interpretation and Survival

Any ambiguity in this Agreement will be resolved in favor of a meaning that permits compliance with HIPAA. The obligations of Business Associate under Section 2(g) and Section 6 regarding return, destruction, or continued protection of PHI survive termination of this Agreement for as long as Business Associate retains PHI.

10. No Third-Party Beneficiaries

Nothing in this Agreement confers any rights, remedies, or claims upon any third party, including any individual whose PHI is created, received, maintained, or transmitted under this Agreement.

11. Contact

Questions about this Agreement, or requests for a copy of our current subprocessor list: hello@theralyn.co

Get Started FreeBook demo →