Docs BAA Template (HIPAA)

Business Associate Agreement (BAA) — Template

Status: template. A BAA under HIPAA is mandatory if the Customer is a Covered Entity or Business Associate and intends to have Mockarty process, transmit, or store Protected Health Information (PHI). Tailor the blanks in {{braces}} and have the final text reviewed by HIPAA counsel before signing.

Strong recommendation: do not place real PHI into Mockarty. It is a test-tooling product, not a clinical system. Use synthetic or de-identified data (Safe Harbor per 45 CFR §164.514(b)(2)). This BAA covers the residual case where the Customer accepts the risk of using real PHI in mocks.


1. Parties

  • Covered Entity / upstream Business Associate (“Customer”): {{Customer legal entity}}, {{address}}, represented by {{name, title}}.
  • Business Associate (“Mockarty”): Mockarty OÜ (or local legal entity — substitute as applicable), {{vendor address}}, represented by {{name, title}}.

2. Definitions

Terms used but not otherwise defined in this BAA have the meaning given in the HIPAA Rules: the Privacy Rule, Security Rule, Breach Notification Rule, and HITECH Act, codified at 45 CFR Parts 160 and 164, as amended.

Protected Health Information (PHI): as defined in 45 CFR §160.103, limited to the PHI that the Customer elects to place into the Mockarty instance.

Services: the Customer’s licensed use of the Mockarty software, as described in the Principal Agreement.

3. Permitted uses and disclosures of PHI

Mockarty may use and disclose PHI only as necessary to provide the Services and as permitted or required by this BAA and the HIPAA Rules, including:

a. Performing the processing functions the Customer configures (storing, retrieving, transmitting the PHI that the Customer chooses to place into Mockarty);

b. Managing and administering the Mockarty software, including diagnostics, maintenance, and de-identified or aggregated usage statistics;

c. Carrying out Mockarty’s legal responsibilities.

Mockarty shall not use or disclose PHI in a manner that would violate the Privacy Rule if done by the Customer, except where specifically permitted by 45 CFR §164.504(e).

4. Prohibited activities

Mockarty shall not:

a. Sell PHI (45 CFR §164.502(a)(5)(ii));
b. Use or disclose PHI for marketing purposes (45 CFR §164.508);
c. Use PHI for its own benefit, except as permitted in Section 3(b) or as required by law.

5. Safeguards

Mockarty implements and maintains administrative, physical, and technical safeguards as required by the Security Rule (45 CFR §§164.308, 164.310, 164.312, 164.316). These include:

45 CFR Safeguard Mockarty control
§164.312(a)(1) Access Control RBAC with least-privilege roles; unique user IDs; automatic logoff via session timeout; optional PHI field-level AES-256-GCM
§164.312(a)(2)(iv) Encryption and decryption TLS 1.2+ in transit; optional AES-256-GCM envelope encryption at rest; HSM via PKCS#11
§164.312(b) Audit controls Immutable audit trail with legal-hold flag; RFC 5424 Syslog + ArcSight CEF export
§164.312(c)(1) Integrity Database CHECK constraints on audit action vocabulary; signed release binaries; SBOM per release
§164.312(d) Person or entity authentication OIDC/SAML/LDAP; MFA (TOTP RFC 6238); scoped API tokens
§164.312(e)(1) Transmission security TLS 1.2+; optional mTLS for gRPC
§164.308(a)(1)(ii)(D) Information system activity review Structured audit log, Prometheus metrics, SIEM ingestion
§164.308(a)(6) Security incident procedures Documented incident response hooks (see Section 7)
§164.308(a)(7)(ii)(A) Data backup plan DB-agnostic dumps, volume snapshot compatibility (Customer operates)
§164.310(c) Workstation security / §164.310(d)(1) Device and media controls Customer operates (on-premise)
§164.316 Policies, procedures, and documentation SECURITY_COMPLIANCE document, this BAA, DPA, SBOM, Trivy report

The Customer operates §164.310 physical safeguards (facility access, workstation use/security, media controls) because Mockarty runs in Customer-controlled infrastructure.

6. Workforce, agents, and subcontractors

Mockarty ensures that any agent or subcontractor that creates, receives, maintains, or transmits PHI on behalf of Mockarty agrees in writing to the same restrictions, conditions, and requirements that apply to Mockarty under this BAA (45 CFR §164.502(e)(1)(ii), §164.308(b)(2)).

Default deployment: no Mockarty agent or subcontractor touches PHI, because the software runs entirely in the Customer’s environment and Mockarty has no runtime access to Customer data.

7. Breach and security incident reporting

a. Breach of unsecured PHI (45 CFR §§164.402, 164.410): Mockarty reports to the Customer without unreasonable delay and in any event no later than thirty (30) calendar days after discovery, providing the information required by §164.410(c) to the extent known.

b. Security incidents (as defined in §164.304): non-Breach security incidents (e.g., blocked intrusion attempts, failed logins) are aggregated and reported on reasonable request; the Customer’s SIEM already receives real-time audit and authentication events via the built-in export.

c. Because Mockarty does not host PHI in the default deployment, the primary breach detection and notification duty rests with the Customer. Mockarty assists with investigation, root-cause analysis, and remediation.

8. Access, amendment, and accounting of disclosures

a. Access (45 CFR §164.524): Customer administrators use Mockarty’s built-in export features to retrieve PHI from the Customer’s instance. Mockarty provides technical documentation and reasonable support.

b. Amendment (45 CFR §164.526): Customer performs amendments using Mockarty’s update API or UI.

c. Accounting of disclosures (45 CFR §164.528): Mockarty’s audit log records data access; Customer exports the relevant rows to satisfy accounting requests.

d. If Mockarty directly receives a data subject request, it forwards it to the Customer without undue delay and does not respond substantively except as directed by the Customer.

9. Compliance with the Customer’s obligations

To the extent Mockarty carries out an obligation of the Customer under the Privacy Rule, Mockarty complies with the requirements of the Privacy Rule that apply to the Customer in the performance of such obligation.

10. Secretary access

Mockarty makes its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, the Customer available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining the Customer’s compliance with the HIPAA Rules (45 CFR §164.504(e)(2)(ii)(I)).

11. Term and termination

a. Term: this BAA is effective on the last signature date and remains in force for as long as the Services involve PHI.

b. Termination for cause (45 CFR §164.504(e)(2)(iii)): if a Party determines that the other has materially breached this BAA, the non-breaching Party shall (i) provide an opportunity to cure within thirty (30) days, (ii) terminate this BAA and the Principal Agreement if the breach is not cured, or (iii) if neither cure nor termination is feasible, report the breach to the HHS Secretary.

c. Effect of termination: on termination, Mockarty — if it holds any PHI — returns or destroys all PHI received from or created on behalf of the Customer, to the extent feasible. If infeasible, Mockarty extends the protections of this BAA to such PHI and limits further use/disclosure to the purposes making return or destruction infeasible. As Mockarty typically holds no PHI (Customer-operated deployment), this clause is usually a no-op.

12. Miscellaneous

a. Interpretation: any ambiguity is resolved in favour of a meaning that permits compliance with the HIPAA Rules.

b. Amendment: the Parties agree to negotiate amendments necessary to comply with subsequent changes to the HIPAA Rules.

c. Survival: the respective rights and obligations relating to PHI under Sections 7, 8, 10, and 11(c) survive termination.

d. No third-party beneficiaries: nothing in this BAA creates any rights in any third party.

e. Precedence: in the event of conflict between this BAA and the Principal Agreement, this BAA prevails for matters relating to PHI.

13. Signatures

Party Name Title Signature Date
Customer {{...}} {{...}}
Mockarty {{...}} {{...}}