StudyRun · Selby Labs · HIPAA BAA

Business Associate Agreement

Version 1.0  ·  Effective date: [DATE OF EXECUTION]  ·  Applies to: US Customers processing PHI
This Business Associate Agreement ("BAA") is provided to US Customers who are Covered Entities or Business Associates under the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH and their implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, "HIPAA"). This BAA is not auto-accepted at registration: it must be expressly accepted by the Customer (either by electronic clickwrap or by signed counterpart; see Section 2) before any Protected Health Information is uploaded to the Platform.
Until this BAA is in force, the StudyRun Platform may not be used to Create, Receive, Maintain, or Transmit Protected Health Information. Uploading PHI without a BAA in force is a breach of the StudyRun Terms of Service and may expose both parties to HIPAA enforcement action.
How this agreement is formed: two paths.

Path 1 (default, electronic). Tick the "I am a HIPAA Covered Entity and accept the BAA" option in the StudyRun dashboard and type your full legal name where prompted. The BAA becomes effective on the date and time of that acceptance. Selby Labs records your name, the timestamp, your IP address, and the version of this BAA in force at the time. Electronic acceptance under the E-SIGN Act (15 U.S.C. §7001) and applicable state UETA provisions is legally equivalent to a handwritten signature.

Path 2 (on request, signed PDF). If your institution's procurement or compliance office requires a countersigned paper (or PDF) BAA, email support@studyrun.org with "BAA request" in the subject line. Selby Labs will return a countersigned version within 5 business days using the signature blocks at the end of this document. The BAA becomes effective on the later of the two signature dates.

Either path is sufficient. You do not need both.

1. Parties

Business Associate: Selby Labs Pty Ltd, ABN 50 697 107 083, Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000, Australia. Email: support@studyrun.org

Covered Entity (Customer): The researcher or institution identified in the StudyRun account registration (for electronic acceptance) or in the signature block at the foot of this BAA (for signed-counterpart acceptance).

2. Acceptance and Effective Date

This BAA becomes effective when either of the following occurs:

The Customer warrants that the individual accepting this BAA has the authority to bind the Covered Entity. The Customer must not enable any HIPAA-related study configuration, or upload any PHI, until acceptance has occurred via one of these paths.

If this authority warranty is subsequently shown to be false, Business Associate will, on Covered Entity's written notice, (i) treat the acceptance as ineffective from the date of acceptance, (ii) delete or return any PHI already uploaded under the Underlying Services Agreement at Covered Entity's option, and (iii) continue to treat any such information as PHI for HIPAA purposes during the intervening period and until deletion or return completes.

3. Definitions

Capitalised terms used but not otherwise defined in this BAA have the meanings given in HIPAA. For clarity:

4. Permitted Uses and Disclosures by Business Associate

4.1 Services

Business Associate may Use or Disclose PHI only as necessary to perform the services set forth in the Underlying Services Agreement (namely, the technical operation of the StudyRun research data-collection platform on behalf of Covered Entity) or as otherwise permitted by this BAA.

4.2 Management, administration, and legal responsibilities

Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities. Business Associate may Disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities only if the Disclosure is Required By Law, or Business Associate obtains reasonable assurances from the recipient that (a) the information will be held confidentially and Used or further Disclosed only as Required By Law or for the purpose for which it was Disclosed, and (b) the recipient notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

4.3 Data aggregation

Business Associate may Use PHI to provide Data Aggregation services to Covered Entity as permitted by 45 C.F.R. §164.504(e)(2)(i)(B), only where the Covered Entity has specifically requested such services in writing.

4.4 De-identification

Business Associate may de-identify PHI in accordance with 45 C.F.R. §164.514(a)-(c). De-identified information is no longer PHI and may be Used by Business Associate for any lawful purpose.

4.5 Prohibited uses

Business Associate will not: (a) Use or Disclose PHI other than as permitted by this BAA or required by law; (b) Sell PHI or receive remuneration in exchange for PHI except as permitted by 45 C.F.R. §164.502(a)(5)(ii); (c) Use or Disclose PHI for marketing or fundraising purposes.

5. Obligations of Business Associate

5.1 Appropriate safeguards

Business Associate will implement administrative, physical, and technical safeguards, including compliance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) with respect to ePHI, that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI.

5.2 Mitigation

Business Associate will mitigate, to the extent practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI in violation of this BAA.

5.3 Reporting

Business Associate will report to Covered Entity, without unreasonable delay and in any event within 72 hours of discovery: (a) any Use or Disclosure of PHI not permitted by this BAA; (b) any Security Incident (as defined in 45 C.F.R. §164.304) of which Business Associate becomes aware; and (c) any Breach of Unsecured PHI. This 72-hour SLA is aligned with the breach-notification SLAs in Selby Labs's International, EU, and Australian DPAs, so that a single breach produces a single notification clock regardless of which agreement or which jurisdiction applies to the Customer. For a Breach, the report will include the information required by 45 C.F.R. §164.410 to the extent known. Business Associate and Covered Entity acknowledge that routine, unsuccessful Security Incidents (for example, pings, port scans, failed login attempts, and denial-of-service attempts that do not result in access to or use of PHI) occur regularly and Business Associate's reporting obligation is satisfied by the security logs it maintains; no per-event report is required for such unsuccessful incidents.

5.4 Subcontractors

In accordance with 45 C.F.R. §§164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor to whom it provides PHI agrees in writing to the same restrictions and conditions that apply through this BAA.

Of the sub-processors listed in Section 7 of the International DPA, only Amazon Web Services (AWS) receives, stores, or processes PHI. Business Associate processes PHI on AWS HIPAA-Eligible Services only, under the terms of the AWS Business Associate Addendum executed between Selby Labs and AWS. The remaining sub-processors do not receive, store, or process PHI under this BAA:

Business Associate will provide Covered Entity, on request, with a copy of the AWS Business Associate Addendum and any other Subcontractor agreement that will handle PHI. If Business Associate ever proposes to expand the PHI-handling Subcontractor chain beyond AWS, it will notify Covered Entity at least 30 days in advance and provide an executable subcontractor BAA for the new Subcontractor before any PHI is transmitted.

5.5 Access

On written request from Covered Entity, Business Associate will provide access to PHI in a Designated Record Set it maintains in order to meet Covered Entity's obligations under 45 C.F.R. §164.524. Because Business Associate does not currently operate a self-serve access endpoint for PHI, responses are prepared manually; Business Associate will respond within 10 business days of the written request. Where an individual makes the access request directly to Business Associate, Business Associate will forward it to Covered Entity within 5 business days without responding directly.

5.6 Amendment

On written request from Covered Entity, Business Associate will make an amendment to PHI in a Designated Record Set that Covered Entity directs pursuant to 45 C.F.R. §164.526. Because amendments are executed manually, Business Associate will respond within 10 business days of the written request.

5.7 Accounting of disclosures

Business Associate will document Disclosures of PHI and information related to such Disclosures as would be required for Covered Entity to respond to a request for an accounting of Disclosures under 45 C.F.R. §164.528. Accountings are prepared manually from audit records; Business Associate will provide the information to Covered Entity within 10 business days of a written request.

5.8 Availability of books and records

Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining Covered Entity's compliance with the HIPAA Rules.

5.9 Minimum necessary

Business Associate will limit its Use, Disclosure, and Request of PHI, to the extent practicable, to the Limited Data Set or, if needed, to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. §164.502(b).

6. Obligations of Covered Entity

6.1 Notice of Privacy Practices

Covered Entity will provide Business Associate with a copy of the Notice of Privacy Practices Covered Entity produces in accordance with 45 C.F.R. §164.520, and any limitation(s) in that Notice that affect Business Associate's Use or Disclosure of PHI.

6.2 Notification of restrictions and authorisation changes

Covered Entity will notify Business Associate of any changes in, or revocation of, the permission by an individual to Use or Disclose their PHI, and of any restriction on Use or Disclosure that Covered Entity has agreed to in accordance with 45 C.F.R. §164.522.

6.3 No requests violating HIPAA

Covered Entity will not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as permitted by Sections 4.2 and 4.3 above.

7. Term and Termination

7.1 Term

This BAA is effective on the Effective Date determined under Section 2 (Acceptance and Effective Date) and continues until all PHI in Business Associate's possession has been returned to Covered Entity or destroyed.

7.2 Termination for breach

Either party may terminate this BAA and the Underlying Services Agreement for cause if it determines that the other party has materially breached this BAA and has not cured the breach within 30 days after written notice.

7.3 Return or destruction of PHI

On termination, Business Associate will, if feasible, return or destroy all PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity. Destruction will follow the retention schedule in Section 9 of the International DPA: 7-day export grace period, then primary-database deletion, then purge from backups on the next 7-day backup rotation (no later than 14 days after termination). If return or destruction is not feasible, Business Associate will extend the protections of this BAA to the PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible, for so long as Business Associate retains the PHI. Business Associate will certify destruction in writing on Covered Entity's request.

8. Miscellaneous

8.1 Regulatory references

A reference in this BAA to a section in the HIPAA Rules means the section as in effect or amended from time to time.

8.2 Amendment

The parties agree to take such action as is necessary to amend this BAA from time to time for compliance with the requirements of the HIPAA Rules and any other applicable law.

8.3 Interpretation

Any ambiguity in this BAA will be resolved to permit Covered Entity and Business Associate to comply with the HIPAA Rules.

8.4 Relationship to Underlying Services Agreement

This BAA supplements the Underlying Services Agreement. In the event of any conflict between this BAA and the Underlying Services Agreement with respect to PHI, this BAA controls. For all other matters, the Underlying Services Agreement and the International DPA continue to apply.

8.5 No third-party beneficiaries

Nothing in this BAA is intended to create any rights or remedies in any third party (including individuals whose PHI is the subject of this BAA), other than the rights expressly granted by the HIPAA Rules.

8.6 Governing law

This BAA is governed by the laws of the State in which Covered Entity is principally located in the United States, without regard to conflict-of-law principles, except that HIPAA and other applicable US federal law govern the interpretation of HIPAA-defined terms.

Signatures (Path 2: signed counterpart only)

The blocks below are used only where the Customer has requested a signed counterpart under Section 2, Path 2. Customers accepting this BAA electronically (Path 1) do not need to complete this section; the electronic acceptance record is their signature.

Business Associate: Selby Labs Pty Ltd

Signature:

Name (print):

Title:

Date:

Covered Entity:

Legal entity name:

Signature:

Name (print):

Title:

Date:

Contact

Selby Labs Pty Ltd  ·  ABN 50 697 107 083

Suite 329/98-100 Elizabeth Street, Melbourne VIC 3000

Email: support@studyrun.org