This Business Associate Agreement ("Agreement") is entered into as of the date executed below by and between:
Covered Entity: [RCM Agency / Telehealth Practice Name], a [State] [entity type] ("Covered Entity")
Business Associate: Conduit Catalyst LLC, operating BillerBrain Shield™ (built by AI X Ray Lab), a Mississippi limited liability company ("Business Associate")
The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
(a) Business Associate. "Business Associate" shall mean Conduit Catalyst LLC (Registered Office Address: 270 Trace Colony Park, STE B, Ridgeland, MS 39157), the legal entity that owns and operates BillerBrain Shield™, which is built and powered by AI X Ray Lab, providing AI-powered denial intelligence and claims analysis services to the Covered Entity.
(b) Covered Entity. "Covered Entity" shall mean the RCM agency, telehealth practice, billing director, or healthcare organization named above that is engaging BillerBrain Shield™ services.
(c) HIPAA Rules. "HIPAA Rules" shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
(d) Services. "Services" shall mean the denial intelligence analysis performed by BillerBrain Shield™, which includes ingesting de-identified or limited PHI contained in denied 835 ERA files, EOBs, or claim exports, processing such data through a multi-model AI consensus engine to generate denial root cause verdicts, and delivering a client-ready Denial Intelligence Report (PDF) to the Covered Entity.
Business Associate agrees to:
(a) Use Limitation. Not use or disclose Protected Health Information other than as permitted or required by this Agreement or as required by law.
(b) Appropriate Safeguards. Use appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement. This includes:
(c) Breach Reporting. Report to Covered Entity any use or disclosure of Protected Health Information not provided for by this Agreement within 72 hours of discovery.
(d) Subcontractors. Ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions that apply to Business Associate under this Agreement.
(e) HHS Access. Make its internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance with the HIPAA Rules.
(a) Authorized Purpose. Business Associate may only use or disclose PHI as necessary to perform the following services:
(b) No Data Aggregation for Third Parties. Business Associate shall not use PHI for data aggregation, benchmarking, training of external AI models, or sale to any third party.
(c) Minimum Necessary. Business Associate agrees to request, use, and disclose only the minimum necessary PHI to perform the Services.
(a) Term. This Agreement shall remain in effect until terminated by either party with 30 days written notice.
(b) Termination for Cause. Covered Entity may terminate immediately if Business Associate has materially violated any term and has not cured the violation within 15 business days of written notice.
(c) Obligations Upon Termination. Business Associate shall confirm in writing that all PHI has been permanently deleted from all systems within 5 business days of termination.
(a) Governing Law. This Agreement shall be governed by the laws of the State of Mississippi and applicable federal law including the HIPAA Rules.
(b) Entire Agreement. This Agreement constitutes the entire agreement between the parties with respect to HIPAA compliance and supersedes all prior agreements.
(c) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.
By executing below, the parties agree to be bound by the terms of this Agreement.