maven logo link
Confidential

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement (the “BAA”) is entered into as of the date of the last signature below (the “Effective Date”), by and between the entity or person identified as the customer in the applicable order form (“Covered Entity”) and Maven Clinic Co., together with its subsidiaries and affiliates (including DCW Providers P.L.L.C and Maven Clinic Administrators, a third-party administrator, collectively referred to herein as “Maven”) . Covered Entity and Maven are each a Party to this BAA and collectively the Parties.

WHEREAS, pursuant to that certain Order Form and Maven Management Agreement executed between the Parties (the “Underlying Agreement”), Maven’s services under the Underlying Agreement may require Maven to process PHI received from Covered Entity and this BAA applies to the extent that processing qualifies Maven as Covered Entity’s Business Associate;

WHEREAS, the Parties desire to comply with their respective obligations under HIPAA;

NOW THEREFORE, for and in consideration of the recitals above and the mutual covenants and conditions herein contained, Covered Entity and Maven enter into this BAA to provide a full statement of their respective responsibilities.

SECTION I – APPLICABILITY AND DEFINITIONS

1.1 Scope. The Parties agree that this BAA applies only to the extent the eligibility files provided by Covered Entity to Maven contain PHI and Maven is processing that PHI in its capacity as Covered Entity’s Business Associate. The Parties further acknowledge that Covered Entity may be acting as a Business Associate of an upstream entity and in that event Maven shall be acting as its sub-Business Associate. For avoidance of doubt, this BAA does not apply to Member Data.

1.2 Definitions. The following terms used (whether capitalized or not) in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use. Additionally, the following specific definitions apply:

“Privacy Rule” - The term “Privacy Rule” shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 CFR Part 160 and Part 164, Subparts A and E.

“Security Rule” - The term “Security Rule” shall mean the Security Standards for the Protection of Electronic Protected Health Information at 45 CFR Part 160 and Part 164, Subparts A and C.

“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.

1.3 Any other capitalized terms not defined under HIPAA or herein shall have the same meaning as in the Underlying Agreement.

SECTION II - OBLIGATIONS AND ACTIVITIES OF MAVEN

2.1 Restricted Use and Disclosure. Maven shall only Use and Disclose PHI as permitted by this BAA or as Required by Law.

2.2 Safeguards. In accordance with 45 CFR Part 164, Subpart C, Maven shall develop, implement, maintain and use appropriate administrative, technical and physical safeguards to prevent the use or disclosure of PHI other than as provided for by this BAA.

2.3 Reporting Obligations

  • Breach of Unsecured PHI. Maven will report to Covered Entity any Breach of Unsecured PHI as required by 45 CFR §164.410, and in no case later than thirty (30) calendar days after discovery. To the extent practical, Maven agrees to mitigate any harmful effect that is known to Maven.
  • Security Incidents. Maven shall promptly notify Covered Entity of any successful Security Incident of which it becomes aware, in accordance with 45 CFR §164.314. Such notification shall include, to the extent known at the time of notification, a description of the Security Incident, the PHI involved, and the corrective actions taken or proposed to mitigate harm. Notwithstanding, Covered Entity agrees that this section provides sufficient notice of previous and future immaterial Security Incidents including but not limited to pings, port scans, unsuccessful log-in attempts, denial of service attacks. .
  • Maven shall send notifications under this section to the Covered Entity’s email provided on the applicable order form. Maven will include all details within the notification as available to Maven to allow Covered Entity to fulfill its obligations under 45 CFR § 164.404. The Parties acknowledge and agree that Maven may not have all necessary information available at the time of its initial notices and Maven may send supplemental notices as necessary.

2.5 Use of Subcontractors. Maven agrees to ensure that any agent and/or Subcontractor, to whom it provides PHI received from, or created or received by Maven, on behalf of Covered Entity, and who creates, maintains, or transmits PHI on behalf of Maven, adheres to the same restrictions and conditions that apply to Maven under HIPAA with respect to such PHI.

2.6 Access to PHI. It is not anticipated that Maven will maintain records on behalf of the Covered Entity, but if applicable, Maven agrees to provide access to PHI in a Designated Record Set in order to meet the requirements under 45 CFR §164.524. In the event that Maven, in connection with the services, uses or maintains an Electronic Health Record of information of or about an Individual, then Maven shall upon request by Covered Entity or the Individual provide an electronic copy of the PHI to the Covered Entity or to the Individual or a third party designated by the Individual, all in accordance with 45 CFR §164.524(c)(2)(ii).

2.7 Amendments by Maven. It is not anticipated that Maven will maintain records on behalf of the Covered Entity, but if applicable, Maven agrees to make available for amendment and incorporate any amendment(s) to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 CFR §164.526.

2.8 Access by the Secretary. Maven agrees to make its internal practices, books and records including policies and procedures and PHI relating to the use and disclosure of PHI received from, or created or received by Maven on behalf of, Covered Entity available to the Secretary for the purposes of the Secretary determining Covered Entity’s and Maven’s compliance with the HIPAA Rules.

2.9 Accounting of Disclosures. Maven agrees to document disclosures of PHI and information related to such disclosures and to make an accounting of disclosures available to Covered Entity, or take other measures as reasonably necessary to satisfy Covered Entity’s obligations under 45 CFR §164.528.

2.10 Carrying Out Obligations of Covered Entity. Covered Entity is not delegating to Maven any of its obligations under 45 CFR Part 164. The parties acknowledge that Maven is not expected to carry out any of Covered Entity’s obligations under 45 CFR Part 164, Subpart E. However, to the extent Maven does carry out any such obligation on behalf of Covered Entity, Maven shall comply with the applicable requirements of each Subpart in the performance of such obligations.

2.11 Audit. Upon the Covered Entity’s annual request, Maven shall provide its latest SOC 2 Type II report, proof of its HITRUST certification, or equivalent report (“Audit Materials”) in order to demonstrate compliance with this BAA. Covered Entity shall treat the Audit Materials as Maven’s Confidential Information (as defined in the Underlying Agreement) and not further disclose the Audit Materials absent Maven’s prior written consent.

SECTION III - PERMITTED USES AND DISCLOSURES BY MAVEN

3.1 General. Maven may use or disclose PHI as permitted by the Underlying Agreement, as permitted by this BAA, and as Required by Law.

3.2 Specific. Maven may use or disclose PHI:

  • for the proper management and administration of Maven or to carry out its legal responsibilities;
  • disclose PHI to third parties provided that Maven obtains reasonable assurances from the recipient to whom the PHI is disclosed that the PHI will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the recipient, and the recipient notifies Maven of any instances of which it is aware in which the confidentiality of the information has been breached;
  • to provide Data Aggregation services to Covered Entity as permitted by 45 CFR §164.504(e)(2)(i)(B);
  • to de-identify PHI provided that the de-identification conforms to the requirements of 45 CFR § 164.514; and
  • to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR §164.502(j)(1).

3.3 Minimum Necessary. Maven shall request, use or disclose only the minimum amount of PHI necessary to accomplish the applicable purpose.

SECTION IV – OBLIGATIONS OF COVERED ENTITY

4.1 Permissible Requests. Covered Entity shall not request Maven to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity including any Use or Disclosure that does not comply with the minimum necessary principle.

4.2 Permissions; Restrictions. Covered Entity represents and warrants that it has obtained or will obtain any consents, authorizations and/or other legal permissions required under HIPAA and other applicable law for the disclosure of PHI to Maven. Covered Entity shall notify Maven of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes may affect Maven’s use of disclosure of PHI. Covered Entity shall not agree to any restriction on the use of disclosure of PHI under 45 CFR 164.522 that restricts Maven’s use or disclosure of PHI under the Underlying Agreement unless such restriction is Required by Law or Maven grants its written consent.

4.3 Notice of Privacy Practices. Except as Required by Law, with Maven’s consent, or this BAA, Covered Entity shall not include any limitation in the Covered Entity’s notice of privacy practices that limits Maven’s use or disclosure of PHI under any other agreement between the parties.

SECTION V - TERM/TERMINATION

5.1 Term. This BAA shall be effective as of the Effective Date and shall terminate upon the first occurrence of either the termination of the Underlying Agreement or for cause under section 5.2 below.

5.2 Termination for Cause. Either Party may terminate this BAA for cause if the terminating party determined the other Party materially breached the terms of this BAA and the other Party was unable to cure within ninety (90) days of receiving notice from the terminating Party.

5.3 Effect of Termination.

5.3.1 In the event of termination of this BAA, Maven shall destroy the PHI within the scope of this BAA within ninety (90) days of the date of termination. If Maven determines that destruction is infeasible, Maven shall notify Covered Entity including the conditions rendering destruction infeasible. Maven shall continue to apply the same safeguards to such PHI as required by this BAA while limiting further uses and disclosures of such PHI to those purposes that make the destruction infeasible, for as long as Maven retains such PHI.

SECTION VI - MISCELLANEOUS

6.1 Notices. Except as otherwise provided herein, notices under this BAA shall be sent to the contact information provided in the Underlying Agreement or applicable order form.

6.2 Conflicts. In the event that there is a conflict between the terms of this BAA and the terms of the Underlying Agreement, the BAA shall prevail insofar as PHI is concerned and otherwise the Underlying Agreement shall prevail.

6.3 Construction. This BAA shall be construed as broadly as necessary to implement and comply with the HIPAA Rules. The Parties agree that any ambiguity in this BAA shall be resolved in favor of a meaning that allows the Parties to comply with the HIPAA Rules.

6.4 Modification of BAA. This BAA shall not be amended, or modified in any way, in whole or in part, except as agreed in writing between the Parties. The Parties recognize that this BAA may need to be modified from time to time to comply with modifications to the HIPAA Rules and applicable law. The Parties agree to execute any amendments to this BAA as reasonably necessary for the Parties to comply with the HIPAA Rules. The Parties shall act in good faith to comply with any applicable modifications of the HIPAA Rules prior to executing such an amendment.

Last updated: October 6, 2026

Rejoignez Maven

Employeurs
Régimes d'assurance maladie
Consultants
Ecosystem Partners
Particuliers
Devenez un fournisseur Maven

Programmes Maven

Fertilité et développement familial
Soins de maternité et du nouveau-né
Maven Milk
Parentalité et pédiatrie
Ménopause et santé à la quarantaine
Portefeuille Maven
Avantages gérés par Maven

Entreprise

À propos de nous
Carrières
Nous embauchons !
Appuyez sur
Solutions
Tarifs
Réserver une démo

Ressources

Parcours des membres Maven
NOUVEAU
Centre de ressources
Clinical Research Institute
Webinaires
Blog
Études de cas
Partagez votre moment Maven

Retrouvez-nous sur

Inscrivez-vous à notre newsletter

© 2025 Maven Clinic Co. Tous droits réservés.
Conditions Confidentialité Sécurité Cookie Policy Avis de pratiques de confidentialité Consumer Health Data Privacy NoticeSafety Information
Your Privacy Choices
© 2026 Maven Clinic Co. All rights reserved.
Verify Approval for www.mavenclinic.com