Business Associate Agreement
AppFrunk · Version 2026-07-08 · Part of the AppFrunk Terms of Service
This Business Associate Agreement ("BAA") is included in, and forms part of, the AppFrunk Terms of Service. It is entered into and becomes effective when Customer accepts the Terms of Service at signup — no separate signature is required. Accepting the Terms records Customer's acceptance of this BAA at the version in force on that date. It is between Techomated LLC (doing business as "AppFrunk"), which operates the AppFrunk platform ("Business Associate"), and the customer organization that accepts it ("Covered Entity," and where the customer is itself a business associate, "Subcontractor"), and governs Protected Health Information that Business Associate creates, receives, maintains, or transmits for Customer in connection with the AppFrunk services.
1. Definitions
Capitalized terms used but not defined here carry the meaning given to them in the HIPAA Rules (45 CFR Parts 160 and 164), including Protected Health Information ("PHI"), Electronic PHI, Breach, Security Incident, Required by Law, and the Minimum Necessary standard. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules as amended.
2. Permitted uses and disclosures
Business Associate may use and disclose PHI only (a) to perform the AppFrunk services for Customer as described in the Terms of Service, (b) for Business Associate's proper management and administration or to carry out its legal responsibilities, provided any such disclosure is Required by Law or made under written assurances of confidentiality and breach notification from the recipient, (c) to provide data aggregation services relating to Customer's health care operations where applicable, and (d) as Required by Law. Business Associate will not use or disclose PHI other than as permitted here or as would violate the HIPAA Rules if done by Customer, and will limit uses, disclosures, and requests to the Minimum Necessary.
3. Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with the Security Rule with respect to Electronic PHI, to prevent use or disclosure of PHI other than as this BAA provides. This includes tenant isolation so one customer's data is never combined with another's, encryption in transit and at rest, access controls, and audit logging of access to PHI.
4. Reporting
Business Associate will report to Customer, without unreasonable delay, any use or disclosure of PHI not permitted by this BAA of which it becomes aware, any Security Incident (with routinely occurring unsuccessful attempts that do not compromise PHI reported on an aggregate basis on request), and any Breach of Unsecured PHI, together with the information reasonably available to Business Associate to enable Customer to meet its notification obligations. Notification of a Breach of Unsecured PHI will be made without unreasonable delay and in no case later than 60 calendar days after Business Associate discovers the Breach, consistent with 45 CFR §164.410.
5. Subcontractors
In accordance with 45 CFR §164.502(e)(1)(ii) and §164.308(b)(2), Business Associate will require each subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA. AppFrunk processes PHI only on infrastructure and services that are themselves covered by a business associate agreement.
6. Individual rights
To the extent Business Associate maintains PHI in a Designated Record Set, it will, within reasonable timeframes: make PHI available to enable Customer to meet access requests under 45 CFR §164.524; incorporate amendments under §164.526; and provide information needed for an accounting of disclosures under §164.528. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for determining Customer's compliance.
7. Customer obligations
Customer will not request Business Associate to use or disclose PHI in any manner that would not be permitted under the HIPAA Rules if done by Customer, except where the services expressly provide for such use as permitted above. Customer is responsible for obtaining any necessary authorizations and for the accuracy of the data it submits.
8. Term and termination
This BAA is effective on acceptance and continues while Business Associate maintains PHI for Customer. If either party materially breaches this BAA, the other may provide an opportunity to cure and, if not cured, terminate the services. Upon termination, Business Associate will return or destroy all PHI it maintains for Customer where feasible, and where return or destruction is not feasible, extend the protections of this BAA to that PHI and limit further use or disclosure, consistent with 45 CFR §164.504(e)(2)(ii)(J), subject to legal retention requirements.
9. Interpretation and amendment
Any ambiguity in this BAA is resolved to permit compliance with the HIPAA Rules. This BAA may be updated to reflect changes in law or services; the version in force is published here and identified by version date, and Customer's continued use constitutes acceptance of the then-current version.