{"component": "clause", "props": {"groups": [{"size": 15, "snippet_links": [{"key": "business-associate-shall", "type": "definition", "offset": [0, 24]}, {"key": "the-requirements", "type": "clause", "offset": [43, 59]}, {"key": "security-rule", "type": "definition", "offset": [70, 83]}, {"key": "applicable-to", "type": "definition", "offset": [84, 97]}, {"key": "business-associates", "type": "definition", "offset": [99, 118]}, {"key": "in-case-of", "type": "clause", "offset": [167, 177]}, {"key": "this-agreement", "type": "clause", "offset": [199, 213]}, {"key": "service-agreements", "type": "definition", "offset": [218, 236]}], "snippet": "Business Associate shall fully comply with the requirements under the Security Rule applicable to \"Business Associates,\" as that term is defined in the Security Rule. In case of any conflict between this Agreement and Service Agreements, this Agreement shall govern.", "samples": [{"hash": "2mSlTui7AC6", "uri": "/contracts/2mSlTui7AC6#compliance-with-security-rule", "label": "Msa Agreement (American Well Corp)", "score": 34.8316230774, "published": true}, {"hash": "3xOOO26u887", "uri": "/contracts/3xOOO26u887#compliance-with-security-rule", "label": "Amendment", "score": 33.4303855896, "published": true}, {"hash": "I2TzmtvX0b", "uri": "/contracts/I2TzmtvX0b#compliance-with-security-rule", "label": "Hipaa Business Associate Agreement", "score": 31.8727054596, "published": true}], "hash": "087816c437bf841c09652096397544dd", "id": 1}, {"size": 13, "snippet_links": [{"key": "effective-april", "type": "clause", "offset": [5, 20]}, {"key": "business-associate-shall", "type": "definition", "offset": [31, 55]}, {"key": "the-hipaa-security-rule", "type": "definition", "offset": [68, 91]}, {"key": "the-standards", "type": "clause", "offset": [110, 123]}, {"key": "security-of-electronic-protected-health-information", "type": "clause", "offset": [128, 179]}, {"key": "part-164", "type": "clause", "offset": [226, 234]}, {"key": "as-amended", "type": "definition", "offset": [236, 246]}, {"key": "the-hitech-act", "type": "definition", "offset": [259, 273]}, {"key": "the-term", "type": "clause", "offset": [275, 283]}, {"key": "electronic-health-record", "type": "clause", "offset": [285, 309]}, {"key": "record-of", "type": "clause", "offset": [365, 374]}, {"key": "information-on", "type": "clause", "offset": [390, 404]}, {"key": "an-individual", "type": "clause", "offset": [405, 418]}, {"key": "health-care", "type": "clause", "offset": [483, 494]}], "snippet": "5.1. Effective April 20, 2005, Business Associate shall comply with the HIPAA Security Rule, which shall mean the Standards for Security of Electronic Protected Health Information at 45 C.F.R. Part 160 and Subparts A and C of Part 164, as amended by ARRA and the HITECH Act. The term \"Electronic Health Record\" or \"EHR\" as used in this BAA shall mean an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.", "samples": [{"hash": "lod0rJMjwyV", "uri": "/contracts/lod0rJMjwyV#compliance-with-security-rule", "label": "Service Agreement", "score": 29.7195320129, "published": true}, {"hash": "ifhi9KMs5F", "uri": "/contracts/ifhi9KMs5F#compliance-with-security-rule", "label": "Service Agreement", "score": 29.7195320129, "published": true}], "hash": "b18456c9cbe6fe89e8462963d7315441", "id": 2}, {"size": 3, "snippet_links": [{"key": "business-associate-agrees-to", "type": "clause", "offset": [0, 28]}, {"key": "security-rule", "type": "definition", "offset": [43, 56]}, {"key": "security-standards", "type": "definition", "offset": [58, 76]}, {"key": "set-out", "type": "definition", "offset": [80, 87]}, {"key": "technical-safeguards", "type": "definition", "offset": [155, 175]}, {"key": "availability-of", "type": "clause", "offset": [254, 269]}, {"key": "electronic-phi", "type": "definition", "offset": [274, 288]}, {"key": "on-behalf-of", "type": "definition", "offset": [356, 368]}, {"key": "covered-entity", "type": "definition", "offset": [373, 387]}], "snippet": "Business Associate agrees to implement the Security Rule (security standards as set out in 45 C.F.R. parts 160, 162 and 164), Administrative, Physical and Technical Safeguards that reasonably and appropriately protect the Confidentiality, Integrity, and Availability of the electronic PHI that Business Associate creates, receives, maintains, or transmits on behalf of the Covered Entity.", "samples": [{"hash": "9kEoVnIumXX", "uri": "/contracts/9kEoVnIumXX#compliance-with-security-rule", "label": "Business Associate Agreement", "score": 33.2716789246, "published": true}, {"hash": "axakMzw0tdQ", "uri": "/contracts/axakMzw0tdQ#compliance-with-security-rule", "label": "Onecare Provider Agreement", "score": 32.5133666992, "published": true}, {"hash": "dwywWnb7PnW", "uri": "/contracts/dwywWnb7PnW#compliance-with-security-rule", "label": "Risk Bearing Participant & Preferred Provider Agreement", "score": 30.4795036316, "published": true}], "hash": "c533560d653ccc991cf3c02cd36478f2", "id": 3}, {"size": 3, "snippet_links": [{"key": "business-associate-shall", "type": "definition", "offset": [4, 28]}, {"key": "the-hipaa-security-rule", "type": "definition", "offset": [41, 64]}, {"key": "the-term", "type": "clause", "offset": [66, 74]}, {"key": "electronic-health-record", "type": "clause", "offset": [76, 100]}, {"key": "record-of", "type": "clause", "offset": [156, 165]}, {"key": "information-on", "type": "clause", "offset": [181, 195]}, {"key": "an-individual", "type": "clause", "offset": [196, 209]}, {"key": "health-care", "type": "clause", "offset": [274, 285]}], "snippet": "5.1 Business Associate shall comply with the HIPAA Security Rule. The term \"Electronic Health Record\" or \"EHR\" as used in this BAA shall mean an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.", "samples": [{"hash": "c6YanPh0lDq", "uri": "/contracts/c6YanPh0lDq#compliance-with-security-rule", "label": "Business Associate Agreement", "score": 34.7935943604, "published": true}, {"hash": "2oHb7URZYYL", "uri": "/contracts/2oHb7URZYYL#compliance-with-security-rule", "label": "Business Associate Agreement", "score": 34.7470588684, "published": true}, {"hash": "3lv0VjejxrN", "uri": "/contracts/3lv0VjejxrN#compliance-with-security-rule", "label": "Business Associate Agreement", "score": 34.5286598206, "published": true}], "hash": "54d0964ee46345c6f12143c021a3c860", "id": 4}, {"size": 3, "snippet_links": [{"key": "business-associate-shall", "type": "definition", "offset": [0, 24]}, {"key": "security-rule", "type": "definition", "offset": [61, 74]}, {"key": "at-all-times", "type": "clause", "offset": [75, 87]}, {"key": "to-covered-entity", "type": "clause", "offset": [101, 118]}], "snippet": "Business Associate shall comply with the requirements of the Security Rule at all times with respect to Covered Entity\u2019s PHI.", "samples": [{"hash": "4PjZHo7Wsk2", "uri": "/contracts/4PjZHo7Wsk2#compliance-with-security-rule", "label": "Hipaa Business Associate Agreement", "score": 31.4358615875, "published": true}, {"hash": "4cSCs7PkqfC", "uri": "/contracts/4cSCs7PkqfC#compliance-with-security-rule", "label": "Hipaa Business Associate Agreement", "score": 27.258638382, "published": true}], "hash": "12060ca64b4e1dfec1591a602af0d3e1", "id": 5}, {"size": 3, "snippet_links": [{"key": "compliance-with-the", "type": "clause", "offset": [16, 35]}, {"key": "hipaa-security-standards", "type": "definition", "offset": [36, 60]}, {"key": "protection-of", "type": "definition", "offset": [69, 82]}, {"key": "part-164", "type": "clause", "offset": [112, 120]}, {"key": "security-rule", "type": "definition", "offset": [145, 158]}, {"key": "with-respect-to", "type": "clause", "offset": [162, 177]}, {"key": "covered-by", "type": "definition", "offset": [183, 193]}, {"key": "the-contract", "type": "clause", "offset": [194, 206]}, {"key": "this-agreement", "type": "clause", "offset": [211, 225]}], "snippet": "BA shall ensure compliance with the HIPAA Security Standards for the Protection of EPHI, 45 C.F.R. Part 160 and Part 164, Subparts A and C (the \"Security Rule\"), with respect to EPHI covered by the Contract and this Agreement.", "samples": [{"hash": "859RNM5lppr", "uri": "/contracts/859RNM5lppr#compliance-with-security-rule", "label": "Dental Services Contract", "score": 26.7768650055, "published": true}], "hash": "29eef328d4845deb7729083691363ce7", "id": 6}, {"size": 2, "snippet_links": [{"key": "provider-shall", "type": "clause", "offset": [5, 19]}, {"key": "the-hipaa-security-rule", "type": "definition", "offset": [32, 55]}, {"key": "the-standards", "type": "clause", "offset": [74, 87]}, {"key": "security-of-electronic-protected-health-information", "type": "clause", "offset": [92, 143]}, {"key": "part-164", "type": "clause", "offset": [190, 198]}, {"key": "as-amended", "type": "definition", "offset": [200, 210]}, {"key": "the-hitech-act", "type": "definition", "offset": [223, 237]}, {"key": "the-term", "type": "clause", "offset": [239, 247]}, {"key": "electronic-health-record", "type": "clause", "offset": [249, 273]}, {"key": "record-of", "type": "clause", "offset": [330, 339]}, {"key": "information-on", "type": "clause", "offset": [355, 369]}, {"key": "an-individual", "type": "clause", "offset": [370, 383]}, {"key": "health-care", "type": "clause", "offset": [448, 459]}], "snippet": "6.1. Provider shall comply with the HIPAA Security Rule, which shall mean the Standards for Security of Electronic Protected Health Information at 45 C.F.R. Part 160 and Subparts A and C of Part 164, as amended by ARRA and the HITECH Act. The term \u201cElectronic Health Record\u201d or \u201cEHR\u201d as used in this HCCA shall mean an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.", "samples": [{"hash": "cs3Mv7fDjy1", "uri": "/contracts/cs3Mv7fDjy1#compliance-with-security-rule", "label": "Software as a Service (Saas) License Agreement", "score": 34.0972595215, "published": true}, {"hash": "deSSpWT9mmV", "uri": "/contracts/deSSpWT9mmV#compliance-with-security-rule", "label": "Software as a Service (Saas) License Agreement", "score": 27.6830940247, "published": true}], "hash": "438e10b35f079605e40a5837b99df1c3", "id": 7}, {"size": 2, "snippet_links": [{"key": "compliance-with-the", "type": "clause", "offset": [16, 35]}, {"key": "hipaa-security-standards", "type": "definition", "offset": [36, 60]}, {"key": "protection-of", "type": "definition", "offset": [69, 82]}, {"key": "part-164", "type": "clause", "offset": [112, 120]}, {"key": "security-rule", "type": "definition", "offset": [145, 158]}, {"key": "with-respect-to", "type": "clause", "offset": [162, 177]}, {"key": "covered-by", "type": "definition", "offset": [183, 193]}, {"key": "the-contract", "type": "clause", "offset": [194, 206]}, {"key": "this-agreement", "type": "clause", "offset": [211, 225]}, {"key": "risk-analysis", "type": "clause", "offset": [292, 305]}, {"key": "potential-risks", "type": "clause", "offset": [313, 328]}, {"key": "availability-of", "type": "clause", "offset": [388, 403]}], "snippet": "BA shall ensure compliance with the HIPAA Security Standards for the Protection of EPHI, 45 C.F.R. Part 160 and Part 164, Subparts A and C (the \u201cSecurity Rule\u201d), with respect to EPHI covered by the Contract and this Agreement. Further, at least once every three (3) years, BA shall conduct a risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of EPHI.", "samples": [{"hash": "d78Ga5Tb6hm", "uri": "/contracts/d78Ga5Tb6hm#compliance-with-security-rule", "label": "Business Associate Agreement", "score": 24.0581798553, "published": true}], "hash": "a9eaf974bdc3fdaba0884e015b8315e5", "id": 8}, {"size": 2, "snippet_links": [{"key": "business-associate-shall", "type": "definition", "offset": [0, 24]}, {"key": "technical-safeguards", "type": "definition", "offset": [65, 85]}, {"key": "availability-of", "type": "clause", "offset": [180, 195]}, {"key": "to-covered-entity", "type": "clause", "offset": [234, 251]}, {"key": "security-incidents", "type": "clause", "offset": [252, 270]}, {"key": "security-rule", "type": "definition", "offset": [378, 391]}, {"key": "to-the-extent", "type": "clause", "offset": [392, 405]}, {"key": "required-by", "type": "definition", "offset": [406, 417]}], "snippet": "Business Associate shall implement administrative, physical, and technical safeguards that are designed to reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI. Business Associate shall report to Covered Entity Security Incidents and HIPAA Breaches of which Business Associate becomes aware, and Business Associate shall comply with the Security Rule to the extent required by HITECH.", "samples": [{"hash": "2ywAiAAeArN", "uri": "/contracts/2ywAiAAeArN#compliance-with-security-rule", "label": "Business Associate Agreement", "score": 28.1718006134, "published": true}], "hash": "5500e7a6adb420087631413cb9afd28f", "id": 9}, {"size": 1, "snippet_links": [{"key": "effective-april", "type": "clause", "offset": [6, 21]}, {"key": "consultant-shall", "type": "clause", "offset": [32, 48]}, {"key": "the-hipaa-security-rule", "type": "definition", "offset": [61, 84]}, {"key": "the-standards", "type": "clause", "offset": [103, 116]}, {"key": "security-of-electronic-protected-health-information", "type": "clause", "offset": [121, 172]}, {"key": "part-164", "type": "clause", "offset": [219, 227]}, {"key": "as-amended", "type": "definition", "offset": [229, 239]}, {"key": "the-hitech-act", "type": "definition", "offset": [252, 266]}, {"key": "the-term", "type": "clause", "offset": [268, 276]}, {"key": "electronic-health-record", "type": "clause", "offset": [278, 302]}, {"key": "record-of", "type": "clause", "offset": [357, 366]}, {"key": "information-on", "type": "clause", "offset": [382, 396]}, {"key": "an-individual", "type": "clause", "offset": [397, 410]}, {"key": "health-care", "type": "clause", "offset": [475, 486]}], "snippet": "\u200c\n6.1 Effective April 20, 2005, Consultant shall comply with the HIPAA Security Rule, which shall mean the Standards for Security of Electronic Protected Health Information at 45 C.F.R. Part 160 and Subparts A and C of Part 164, as amended by ARRA and the HITECH Act. The term \"Electronic Health Record\" or \"EHR\" as used in this CA shall mean an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.", "samples": [{"hash": "aLYCZzPr19m", "uri": "/contracts/aLYCZzPr19m#compliance-with-security-rule", "label": "Sales Consultant Agreement", "score": 22.5195064545, "published": true}], "hash": "03b1772c2dbe0059835f9d38cef356ac", "id": 10}], "next_curs": "CmYSYGoVc35sYXdpbnNpZGVyY29udHJhY3RzckILEhZDbGF1c2VTbmlwcGV0R3JvdXBfdjU2IiZjb21wbGlhbmNlLXdpdGgtc2VjdXJpdHktcnVsZSMwMDAwMDAwYQyiAQJlbhgAIAA=", "clause": {"size": 54, "parents": [["obligations-and-activities-of-business-associate", "OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE"], ["special-terms-and-conditions", "Special Terms and Conditions"], ["general-provisions", "General Provisions"], ["general", "General"], ["definitions", "Definitions"]], "title": "Compliance with Security Rule", "children": [["reporting-security-incidents", "Reporting Security Incidents"], ["safeguards-for-protected-health-information", "Safeguards for Protected Health Information"], ["subcontractors-and-other-agents", "Subcontractors and Other Agents"]], "id": "compliance-with-security-rule", "related": [["compliance-with-sec-rules", "COMPLIANCE WITH SEC RULES", "COMPLIANCE WITH SEC RULES"], ["compliance-with-securities-act", "Compliance with Securities Act", "Compliance with Securities Act"], ["compliance-with-rule-144", "Compliance with Rule 144", "Compliance with Rule 144"], ["compliance-with-\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587-\u2587\u2587\u2587\u2587\u2587-act", "Compliance with \u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587-\u2587\u2587\u2587\u2587\u2587 Act", "Compliance with \u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587-\u2587\u2587\u2587\u2587\u2587 Act"], ["compliance-with-ofac", "Compliance with OFAC", "Compliance with OFAC"]], "related_snippets": [], "updated": "2025-07-23T06:00:56+00:00"}, "json": true, "cursor": ""}}