Business Associate Agreement
Last Updated: September 29, 2026
This Business Associate Agreement ("Agreement" or "BAA") is entered into by and between STREAM ABA LLC ("Business Associate") and the healthcare provider or organization ("Covered Entity") that subscribes to and uses the Stream ABA platform.
IMPORTANT: By using Stream ABA to store, process, or transmit Protected Health Information (PHI), Covered Entity agrees to the terms of this Business Associate Agreement.
Recitals
WHEREAS, Covered Entity is a healthcare provider subject to the privacy and security requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH);
WHEREAS, Business Associate provides a cloud-based practice management platform for Applied Behavior Analysis (ABA) therapy practices;
WHEREAS, Covered Entity wishes to use Business Associate's services, which may involve the disclosure of PHI to Business Associate;
WHEREAS, the parties wish to enter into this Agreement to comply with HIPAA requirements governing business associate relationships;
NOW, THEREFORE, in consideration of the mutual promises below and the exchange of information pursuant to this Agreement, the parties agree as follows:
1. Definitions
Terms used but not otherwise defined in this Agreement shall have the same meaning as those terms in the HIPAA Rules (45 C.F.R. Parts 160 and 164).
1.1 "Protected Health Information" or "PHI"
Means individually identifiable health information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
1.2 "Electronic Protected Health Information" or "ePHI"
Means PHI that is transmitted or maintained in electronic media.
1.3 "HIPAA Rules"
Means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Part 160 and Part 164.
1.4 "Security Incident"
Means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
1.5 "Breach"
Means the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule which compromises the security or privacy of the PHI.
2. Obligations of Business Associate
2.1 Permitted Uses and Disclosures
Business Associate agrees to:
- Not use or disclose PHI other than as permitted or required by this Agreement or as required by law
- Use and disclose PHI only for the purposes of providing services to Covered Entity as described in the Service Agreement
- Not use or disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity
2.2 Safeguards
Business Associate agrees to:
- Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI
- Comply with the applicable requirements of the HIPAA Security Rule
- Ensure that any agent, including a subcontractor, to whom it provides PHI agrees to the same restrictions and conditions that apply to Business Associate
2.3 Reporting
Business Associate agrees to:
- Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including breaches of unsecured PHI
- Report to Covered Entity any Security Incident of which it becomes aware
- Provide such reports without unreasonable delay and in no case later than sixty (60) days after discovery
2.4 Breach Notification
In the event of a Breach of unsecured PHI, Business Associate agrees to:
- Notify Covered Entity without unreasonable delay and in no case later than sixty (60) days after discovery of the Breach
- Include in the notification: identification of each individual whose PHI has been or is reasonably believed to have been breached; a description of what happened; the types of PHI involved; steps individuals should take to protect themselves; what Business Associate is doing to investigate, mitigate harm, and prevent future breaches
- Cooperate with Covered Entity in investigating the Breach and meeting notification obligations
2.5 Subcontractors
Business Associate agrees to:
- Ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement
- Remain responsible for the actions of its subcontractors
2.6 Access to PHI
Business Associate agrees to:
- Make available PHI in a designated record set to Covered Entity or, as directed by Covered Entity, to an individual, to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524
- Provide such access within thirty (30) days of a request
2.7 Amendment of PHI
Business Associate agrees to:
- Make PHI available for amendment and incorporate any amendments to PHI as directed by Covered Entity
- Complete such amendments within thirty (30) days of a request
2.8 Accounting of Disclosures
Business Associate agrees to:
- Document disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request for an accounting of disclosures
- Make available to Covered Entity information necessary to provide an accounting of disclosures
- Provide such information within thirty (30) days of a request
2.9 Government Access
Business Associate agrees to:
- Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules
3. Permitted Uses and Disclosures by Business Associate
3.1 Service Functions
Business Associate may use and disclose PHI as necessary to perform the services described in the Service Agreement, including:
- Hosting and storing PHI on secure servers
- Providing technical support and maintenance
- Enabling features that require processing of PHI
- Generating reports and analytics for Covered Entity
3.2 Business Associate's Own Use
Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided the disclosure is required by law or Business Associate obtains reasonable assurances that the information will be held confidentially.
3.3 Data Aggregation
Business Associate may use PHI to provide data aggregation services relating to Covered Entity's healthcare operations.
3.4 De-identification
Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(b). De-identified information is no longer considered PHI and is not subject to this Agreement.
4. Obligations of Covered Entity
Covered Entity agrees to:
- Notify Business Associate of any limitations in Covered Entity's notice of privacy practices that may affect Business Associate's use or disclosure of PHI
- Notify Business Associate of any changes in, or revocation of, authorization by an individual to use or disclose PHI
- Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity
- Obtain any necessary consents, authorizations, or other permissions required under applicable law prior to disclosing PHI to Business Associate
5. Term and Termination
5.1 Term
This Agreement shall be effective as of the date Covered Entity first uses the Stream ABA platform and shall continue until all PHI provided by Covered Entity to Business Associate is destroyed or returned, or this Agreement is terminated.
5.2 Termination for Cause
Either party may terminate this Agreement if the other party materially breaches this Agreement and fails to cure the breach within thirty (30) days of receiving written notice of the breach.
5.3 Effect of Termination
Upon termination of this Agreement:
- Business Associate shall return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, if feasible
- If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible
- Business Associate shall retain PHI only as required by law or as necessary for ongoing legal obligations
5.4 Survival
The obligations of Business Associate under Section 5.3 shall survive termination of this Agreement.
6. Miscellaneous
6.1 Regulatory References
Any reference to a regulatory provision shall include any successor provision.
6.2 Amendment
This Agreement may not be amended except in writing signed by both parties. The parties agree to negotiate in good faith to amend this Agreement to comply with changes in HIPAA requirements.
6.3 Interpretation
Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.
6.4 No Third-Party Beneficiaries
Nothing in this Agreement shall confer any rights upon any person other than the parties and their respective successors and assigns.
6.5 Governing Law
This Agreement shall be governed by and construed in accordance with the laws of the State of North Carolina, without regard to conflict of law principles.
6.6 Entire Agreement
This Agreement, together with the Service Agreement and any attachments, constitutes the entire agreement between the parties with respect to the subject matter hereof.
7. Contact Information
For questions about this Business Associate Agreement:
8. Acceptance
By creating an account and using Stream ABA to store, process, or transmit Protected Health Information, Covered Entity acknowledges that it has read, understood, and agrees to be bound by this Business Associate Agreement.
For organizations requiring a signed copy of this BAA or a custom BAA, please contact us at [email protected].