This Business Associate Agreement (the “BAA”) is entered into as of the date of the last signature below (the “Effective Date”), by and between the entity or person identified as the customer in the applicable order form (“Covered Entity”) and Maven Clinic Co., together with its subsidiaries and affiliates (including DCW Providers P.L.L.C and Maven Clinic Administrators, a third-party administrator, collectively referred to herein as “Maven”) . Covered Entity and Maven are each a Party to this BAA and collectively the Parties.
WHEREAS, pursuant to that certain Order Form and Maven Management Agreement executed between the Parties (the “Underlying Agreement”), Maven’s services under the Underlying Agreement may require Maven to process PHI received from Covered Entity and this BAA applies to the extent that processing qualifies Maven as Covered Entity’s Business Associate;
WHEREAS, the Parties desire to comply with their respective obligations under HIPAA;
NOW THEREFORE, for and in consideration of the recitals above and the mutual covenants and conditions herein contained, Covered Entity and Maven enter into this BAA to provide a full statement of their respective responsibilities.
1.1 Scope. The Parties agree that this BAA applies only to the extent the eligibility files provided by Covered Entity to Maven contain PHI and Maven is processing that PHI in its capacity as Covered Entity’s Business Associate. The Parties further acknowledge that Covered Entity may be acting as a Business Associate of an upstream entity and in that event Maven shall be acting as its sub-Business Associate. For avoidance of doubt, this BAA does not apply to Member Data.
1.2 Definitions. The following terms used (whether capitalized or not) in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use. Additionally, the following specific definitions apply:
“Privacy Rule” - The term “Privacy Rule” shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 CFR Part 160 and Part 164, Subparts A and E.
“Security Rule” - The term “Security Rule” shall mean the Security Standards for the Protection of Electronic Protected Health Information at 45 CFR Part 160 and Part 164, Subparts A and C.
“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
1.3 Any other capitalized terms not defined under HIPAA or herein shall have the same meaning as in the Underlying Agreement.
2.1 Restricted Use and Disclosure. Maven shall only Use and Disclose PHI as permitted by this BAA or as Required by Law.
2.2 Safeguards. In accordance with 45 CFR Part 164, Subpart C, Maven shall develop, implement, maintain and use appropriate administrative, technical and physical safeguards to prevent the use or disclosure of PHI other than as provided for by this BAA.
2.3 Reporting Obligations
2.5 Use of Subcontractors. Maven agrees to ensure that any agent and/or Subcontractor, to whom it provides PHI received from, or created or received by Maven, on behalf of Covered Entity, and who creates, maintains, or transmits PHI on behalf of Maven, adheres to the same restrictions and conditions that apply to Maven under HIPAA with respect to such PHI.
2.6 Access to PHI. It is not anticipated that Maven will maintain records on behalf of the Covered Entity, but if applicable, Maven agrees to provide access to PHI in a Designated Record Set in order to meet the requirements under 45 CFR §164.524. In the event that Maven, in connection with the services, uses or maintains an Electronic Health Record of information of or about an Individual, then Maven shall upon request by Covered Entity or the Individual provide an electronic copy of the PHI to the Covered Entity or to the Individual or a third party designated by the Individual, all in accordance with 45 CFR §164.524(c)(2)(ii).
2.7 Amendments by Maven. It is not anticipated that Maven will maintain records on behalf of the Covered Entity, but if applicable, Maven agrees to make available for amendment and incorporate any amendment(s) to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 CFR §164.526.
2.8 Access by the Secretary. Maven agrees to make its internal practices, books and records including policies and procedures and PHI relating to the use and disclosure of PHI received from, or created or received by Maven on behalf of, Covered Entity available to the Secretary for the purposes of the Secretary determining Covered Entity’s and Maven’s compliance with the HIPAA Rules.
2.9 Accounting of Disclosures. Maven agrees to document disclosures of PHI and information related to such disclosures and to make an accounting of disclosures available to Covered Entity, or take other measures as reasonably necessary to satisfy Covered Entity’s obligations under 45 CFR §164.528.
2.10 Carrying Out Obligations of Covered Entity. Covered Entity is not delegating to Maven any of its obligations under 45 CFR Part 164. The parties acknowledge that Maven is not expected to carry out any of Covered Entity’s obligations under 45 CFR Part 164, Subpart E. However, to the extent Maven does carry out any such obligation on behalf of Covered Entity, Maven shall comply with the applicable requirements of each Subpart in the performance of such obligations.
2.11 Audit. Upon the Covered Entity’s annual request, Maven shall provide its latest SOC 2 Type II report, proof of its HITRUST certification, or equivalent report (“Audit Materials”) in order to demonstrate compliance with this BAA. Covered Entity shall treat the Audit Materials as Maven’s Confidential Information (as defined in the Underlying Agreement) and not further disclose the Audit Materials absent Maven’s prior written consent.
3.1 General. Maven may use or disclose PHI as permitted by the Underlying Agreement, as permitted by this BAA, and as Required by Law.
3.2 Specific. Maven may use or disclose PHI:
3.3 Minimum Necessary. Maven shall request, use or disclose only the minimum amount of PHI necessary to accomplish the applicable purpose.
4.1 Permissible Requests. Covered Entity shall not request Maven to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity including any Use or Disclosure that does not comply with the minimum necessary principle.
4.2 Permissions; Restrictions. Covered Entity represents and warrants that it has obtained or will obtain any consents, authorizations and/or other legal permissions required under HIPAA and other applicable law for the disclosure of PHI to Maven. Covered Entity shall notify Maven of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes may affect Maven’s use of disclosure of PHI. Covered Entity shall not agree to any restriction on the use of disclosure of PHI under 45 CFR 164.522 that restricts Maven’s use or disclosure of PHI under the Underlying Agreement unless such restriction is Required by Law or Maven grants its written consent.
4.3 Notice of Privacy Practices. Except as Required by Law, with Maven’s consent, or this BAA, Covered Entity shall not include any limitation in the Covered Entity’s notice of privacy practices that limits Maven’s use or disclosure of PHI under any other agreement between the parties.
5.1 Term. This BAA shall be effective as of the Effective Date and shall terminate upon the first occurrence of either the termination of the Underlying Agreement or for cause under section 5.2 below.
5.2 Termination for Cause. Either Party may terminate this BAA for cause if the terminating party determined the other Party materially breached the terms of this BAA and the other Party was unable to cure within ninety (90) days of receiving notice from the terminating Party.
5.3 Effect of Termination.
5.3.1 In the event of termination of this BAA, Maven shall destroy the PHI within the scope of this BAA within ninety (90) days of the date of termination. If Maven determines that destruction is infeasible, Maven shall notify Covered Entity including the conditions rendering destruction infeasible. Maven shall continue to apply the same safeguards to such PHI as required by this BAA while limiting further uses and disclosures of such PHI to those purposes that make the destruction infeasible, for as long as Maven retains such PHI.
6.1 Notices. Except as otherwise provided herein, notices under this BAA shall be sent to the contact information provided in the Underlying Agreement or applicable order form.
6.2 Conflicts. In the event that there is a conflict between the terms of this BAA and the terms of the Underlying Agreement, the BAA shall prevail insofar as PHI is concerned and otherwise the Underlying Agreement shall prevail.
6.3 Construction. This BAA shall be construed as broadly as necessary to implement and comply with the HIPAA Rules. The Parties agree that any ambiguity in this BAA shall be resolved in favor of a meaning that allows the Parties to comply with the HIPAA Rules.
6.4 Modification of BAA. This BAA shall not be amended, or modified in any way, in whole or in part, except as agreed in writing between the Parties. The Parties recognize that this BAA may need to be modified from time to time to comply with modifications to the HIPAA Rules and applicable law. The Parties agree to execute any amendments to this BAA as reasonably necessary for the Parties to comply with the HIPAA Rules. The Parties shall act in good faith to comply with any applicable modifications of the HIPAA Rules prior to executing such an amendment.
Last updated: October 6, 2026