Last updated: September 2026
Business Associate Agreement
This Business Associate Agreement ("BAA") governs the handling of Protected Health Information (PHI) by Aventra Wellness when a tenant is a Covered Entity or Business Associate under HIPAA. It applies to medical and IV-clinic verticals only. Execution is completed by countersignature; contact us to execute.
1. Parties & effective date
This BAA is between the tenant ("Covered Entity") and Aventra Wellness ("Business Associate") and takes effect on the date the tenant activates a medical or IV-clinic vertical workspace, or upon countersignature, whichever is earlier.
2. Definitions
- PHI / ePHI — Protected Health Information in any form, including electronic PHI as defined under 45 CFR Part 160 and Part 164, Subparts A and E.
- Breach — an unauthorized acquisition, access, use, or disclosure of PHI not permitted under HIPAA.
- Subcontractor — a person or entity that creates, receives, maintains, or transmits PHI on behalf of the Business Associate.
3. Permitted uses & obligations of the Business Associate
Aventra may use and disclose PHI only as permitted by the tenant's instructions, to provide the service, and as Required by Law. Aventra will:
- Not use or disclose PHI except as permitted by this BAA or HIPAA.
- Implement administrative, physical, and technical safeguards that reasonably protect PHI (45 CFR 164.308, 164.310, 164.312, 164.316).
- Ensure any agents or subcontractors to whom PHI is disclosed agree to the same restrictions and conditions.
- Report any Breach of unsecured PHI to the Covered Entity without unreasonable delay, and no later than 60 calendar days after discovery, including the identification of affected individuals where available (45 CFR 164.410).
- Maintain a designated security contact and make available internal practices records upon reasonable request.
4. Use & disclosure by the Covered Entity
The Covered Entity will not request Aventra to use or disclose PHI in a manner not permitted by HIPAA. The Covered Entity is responsible for notifying Aventra of any limitation in a Notice of Privacy Practices that may affect Aventra's use or disclosure.
5. Subcontractors & sub-processors
Aventra engages sub-processors for hosting, payment processing, and delivery. PHI is processed only by infrastructure covered by this BAA and bound by flow-down obligations. Aventra remains liable for the acts and omissions of its subcontractors to the same extent it would be liable for its own.
6. Access, amendment & accounting
Aventra will, where applicable and within the timeframes required by HIPAA, make available PHI for access and amendment, provide an accounting of disclosures, and make available a record of disclosures for the Covered Entity's use. Where Aventra maintains a Designated Record Set, the Covered Entity may access and amend records through the platform.
7. Term & termination
This BAA terminates when the underlying service agreement terminates, or upon either party's material breach not cured within 60 days. Upon termination, Aventra will, at the Covered Entity's option, return or destroy PHI that it still maintains in any form, retaining only a copy where Required by Law and continuing to protect it under this BAA.
8. Audit rights
The Covered Entity may, no more than once per calendar year and upon reasonable notice, obtain confirmation of Aventra's safeguards through a third-party audit report (e.g., SOC 2 Type II) or equivalent. On-site audits are subject to a separate agreement.
9. Miscellaneous
This BAA supplements, and in case of conflict as to PHI governs over, the Terms of Service. It is governed by the same law as the Terms. Survival of confidentiality and security obligations continues beyond termination.
Questions about this document? Email legal@aventrawellness.com.
