Legal
Business Associate Agreement
AP Performance LLC (DBA Movra)
Version: baa-2026-07
This Business Associate Agreement (“Agreement” or “BAA”) is entered into as of the date last signed below (the “Effective Date”) by and between:
[CUSTOMER LEGAL NAME], a [STATE] [ENTITY TYPE], with principal offices at [ADDRESS] (“Covered Entity”), and
Movra, Inc., a [STATE OF INCORPORATION] [corporation], with principal offices at [MOVRA ADDRESS] (“Business Associate” or “Movra”).
Covered Entity and Business Associate are each a “Party” and collectively the “Parties.”
Recitals
A. The Parties have entered into one or more service agreements (collectively, the “Underlying Agreement”) under which Movra provides services that involve the creation, receipt, maintenance, or transmission of Protected Health Information on behalf of Covered Entity.
B. The Parties intend to comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and the regulations promulgated thereunder at 45 CFR Parts 160 and 164 (collectively, the “HIPAA Rules”).
C. This Agreement establishes the permitted uses and disclosures of Protected Health Information by Movra and the parties’ obligations under the HIPAA Rules.
1. Definitions
Capitalized terms used but not otherwise defined in this Agreement shall have the meanings ascribed to them in the HIPAA Rules. The following terms have the meanings set forth below:
- “Breach” has the meaning given at 45 CFR §164.402.
- “Business Associate” means Movra, as defined at 45 CFR §160.103.
- “Covered Entity” has the meaning given at 45 CFR §160.103.
- “Designated Record Set” has the meaning given at 45 CFR §164.501.
- “Electronic Protected Health Information” or “ePHI” has the meaning given at 45 CFR §160.103, limited to the information Movra creates, receives, maintains, or transmits on behalf of Covered Entity.
- “Individual” has the meaning given at 45 CFR §160.103 and includes a person who qualifies as a personal representative under 45 CFR §164.502(g).
- “Privacy Rule” means the Standards for Privacy of Individually Identifiable Health Information at 45 CFR Part 160 and Part 164, Subparts A and E.
- “Protected Health Information” or “PHI” has the meaning given at 45 CFR §160.103, limited to the information Movra creates, receives, maintains, or transmits on behalf of Covered Entity.
- “Required by Law” has the meaning given at 45 CFR §164.103.
- “Secretary” means the Secretary of the U.S. Department of Health and Human Services or the Secretary’s designee.
- “Security Incident” has the meaning given at 45 CFR §164.304.
- “Security Rule” means the Security Standards for the Protection of Electronic Protected Health Information at 45 CFR Part 160 and Part 164, Subparts A and C.
- “Subcontractor” has the meaning given at 45 CFR §160.103.
- “Unsecured PHI” has the meaning given at 45 CFR §164.402.
2. Permitted Uses and Disclosures by Business Associate
2.1 Performance of services
Movra may use and disclose PHI as necessary to perform the services set forth in the Underlying Agreement, provided that such use or disclosure would not violate the Privacy Rule if performed by Covered Entity or the minimum necessary policies and procedures of Covered Entity.
2.2 Movra’s own management and administration
Movra may use PHI for its own proper management and administration or to carry out its legal responsibilities. Movra may disclose PHI for its own proper management and administration or to carry out its legal responsibilities, provided that:
(a) the disclosure is Required by Law; or
(b) Movra obtains reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and the recipient notifies Movra of any instances of which it becomes aware in which the confidentiality of the PHI has been breached.
2.3 Data aggregation
Movra may provide Data Aggregation services relating to the health care operations of Covered Entity as permitted by 45 CFR §164.504(e)(2)(i)(B).
2.4 De-identification
Movra may de-identify PHI in accordance with 45 CFR §164.514(a)–(c). De-identified information is not subject to the restrictions of this Agreement.
2.5 Prohibited uses
Movra shall not:
(a) Use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as set forth in Sections 2.2–2.4 above;
(b) Use or disclose PHI for marketing purposes (as defined in 45 CFR §164.501) or sell PHI, except as expressly permitted under the HIPAA Rules and the Underlying Agreement.
3. Obligations of Covered Entity
3.1 Notice of Privacy Practices
Covered Entity shall notify Movra of any limitation in Covered Entity’s notice of privacy practices under 45 CFR §164.520, to the extent such limitation may affect Movra’s use or disclosure of PHI.
3.2 Changes in permission
Covered Entity shall notify Movra of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent such changes may affect Movra’s permitted uses or disclosures.
3.3 Restrictions
Covered Entity shall notify Movra of any restriction on the use or disclosure of PHI to which Covered Entity has agreed under 45 CFR §164.522, to the extent such restriction may affect Movra’s use or disclosure.
3.4 Permissible requests
Covered Entity shall not request Movra to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.
4. Obligations and Activities of Business Associate
4.1 Permitted uses
Movra shall not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law.
4.2 Safeguards
Movra shall use appropriate administrative, physical, and technical safeguards, and shall comply with the Security Rule with respect to ePHI, to prevent the use or disclosure of PHI other than as provided for by this Agreement.
4.3 Reporting
Movra shall report to Covered Entity:
(a) any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required at 45 CFR §164.410, without unreasonable delay and in no event later than [thirty (30)] calendar days after discovery;
(b) any Security Incident of which it becomes aware. Notwithstanding the foregoing, the Parties acknowledge and agree that this Section constitutes notice by Movra to Covered Entity of the ongoing existence and occurrence of attempted but unsuccessful Security Incidents (such as pings, port scans, and unsuccessful log-on attempts) for which no additional notice to Covered Entity shall be required.
Notification under Section 4.3(a) shall include, to the extent known and available: a brief description of what happened, the date of the Breach and the date of discovery, the types of Unsecured PHI involved, the Individuals affected, and any steps Individuals should take to protect themselves.
4.4 Subcontractors
In accordance with 45 CFR §§164.502(e)(1)(ii) and 164.308(b)(2), Movra shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Movra agrees in writing to substantially the same restrictions, conditions, and requirements that apply to Movra under this Agreement.
Movra maintains a current list of Subcontractors that may have access to PHI. The list is available upon request and Movra will provide reasonable advance notice of material changes to the list of Subcontractors. As of the Effective Date, Movra’s principal Subcontractors include: [Google Cloud Platform; Amazon Web Services; list to be confirmed].
4.5 Access by Individuals
Movra shall provide access, at the request of Covered Entity, to PHI in a Designated Record Set held by Movra in the time and manner reasonably designated by Covered Entity to satisfy Covered Entity’s obligations under 45 CFR §164.524.
4.6 Amendment
Movra shall make any amendment(s) to PHI in a Designated Record Set held by Movra as directed or agreed to by Covered Entity pursuant to 45 CFR §164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR §164.526.
4.7 Accounting of disclosures
Movra shall maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 CFR §164.528.
4.8 Compliance with Covered Entity’s obligations
To the extent Movra is to carry out one or more of Covered Entity’s obligations under Subpart E of 45 CFR Part 164, Movra shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligations.
4.9 Availability to the Secretary
Movra shall make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
5. Mitigation
Movra shall mitigate, to the extent practicable, any harmful effect that is known to Movra of a use or disclosure of PHI by Movra in violation of this Agreement.
6. Term
This Agreement shall be effective as of the Effective Date and shall remain in effect until termination of the Underlying Agreement, or until terminated as provided herein, whichever is earlier.
7. Termination
7.1 Termination for cause
Upon Covered Entity’s knowledge of a material breach of this Agreement by Movra, Covered Entity shall provide an opportunity for Movra to cure the breach within [thirty (30)] days. If Movra does not cure the breach within the cure period, Covered Entity may terminate this Agreement and the Underlying Agreement.
7.2 Termination for convenience
Either Party may terminate this Agreement upon termination of the Underlying Agreement in accordance with its terms.
7.3 Effect of termination
Upon termination of this Agreement, Movra shall, at the election of Covered Entity and to the extent feasible, return or destroy all PHI received from, or created or received by Movra on behalf of, Covered Entity that Movra still maintains in any form. Movra shall retain no copies of the PHI.
If return or destruction is not feasible, Movra shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Movra maintains such PHI.
7.4 Survival
The obligations of Movra under Section 7.3 (Effect of Termination) shall survive termination of this Agreement.
8. Limitation of Liability and Indemnification
8.1 Liability cap
Each Party’s total aggregate liability arising out of or related to this Agreement shall be limited to the greater of (i) the fees paid or payable to Movra under the Underlying Agreement during the twelve (12) months immediately preceding the event giving rise to the claim, or (ii) [USD $______].
8.2 Excluded damages
In no event shall either Party be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, including lost profits, even if advised of the possibility of such damages.
8.3 Indemnification
Movra shall indemnify, defend, and hold Covered Entity harmless from and against any third-party claims, losses, liabilities, damages, fines, penalties, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to a Breach of Unsecured PHI to the extent caused by Movra’s negligent acts or omissions or material breach of this Agreement.
8.4 Insurance
Movra shall maintain commercially reasonable cyber liability insurance covering its obligations under this Agreement.
9. Miscellaneous
9.1 Governing law
This Agreement shall be governed by the laws of the State of [____________], without regard to its conflict-of-laws provisions, except where preempted by federal law.
9.2 Regulatory references
A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.
9.3 Amendment
The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Movra to comply with the requirements of the HIPAA Rules.
9.4 Survival
The respective rights and obligations of the Parties under Section 7.3, Section 8, and any other provisions intended by their nature to survive shall survive termination of this Agreement.
9.5 Interpretation
Any ambiguity in this Agreement shall be resolved to permit the Parties to comply with the HIPAA Rules.
9.6 No third-party beneficiaries
Nothing in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than the Parties and their respective successors and assigns any rights, remedies, obligations, or liabilities whatsoever.
9.7 Severability
If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall continue in full force and effect.
9.8 Entire agreement
This Agreement, together with the Underlying Agreement, constitutes the entire agreement between the Parties with respect to the subject matter hereof. In the event of a conflict between the terms of this Agreement and the Underlying Agreement with respect to PHI or HIPAA compliance, the terms of this Agreement shall control.
9.9 Notices
All notices under this Agreement shall be in writing and shall be sent to the addresses set forth above, or to such other address as a Party may designate in writing. Notices may be delivered electronically to: For Movra: security@movra.app · For Covered Entity: [____________]. Notices are deemed received upon confirmed delivery.
9.10 Counterparts; electronic signatures
This Agreement may be executed in counterparts, each of which shall be deemed an original. Electronic signatures (including DocuSign) shall be treated as originals.
Signatures
| COVERED ENTITY | BUSINESS ASSOCIATE — MOVRA, INC. |
|---|---|
| By: _________________________________ | By: _________________________________ |
| Name: _______________________________ | Name: _______________________________ |
| Title: ______________________________ | Title: ______________________________ |
| Date: _______________________________ | Date: _______________________________ |
Source language adapted from HHS Sample Business Associate Agreement Provisions (hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions). Movra-specific terms require legal review prior to execution.