SureAppoint Business Associate Agreement
Version: v1.0-2026-08-07<br> Effective date: August 7, 2026<br> Business Associate: Passport Informatics, LLC, doing business as SureAppoint ("Business Associate")<br> Covered Entity: [Practice legal name] ("Covered Entity")
1. Purpose and relationship of the parties
This Business Associate Agreement ("BAA") satisfies the applicable requirements of the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), including the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164 (the "HIPAA Rules"). The parties enter this BAA for the SureAppoint Services in which Business Associate creates, receives, maintains, or transmits Protected Health Information ("PHI") on behalf of Covered Entity. In those circumstances, Passport Informatics, LLC / SureAppoint acts as a Business Associate where applicable.
Business Associate is not a healthcare provider and does not make clinical decisions. Covered Entity controls its appointment policies, whether an appointment-policy violation occurred, fee decisions, and refunds or adjustments where applicable. This BAA does not replace the Commercial Agreement or authorize activity outside the Services.
2. Definitions
Capitalized terms not defined here have the meanings given in the HIPAA Rules.
- Breach, Business Associate, Covered Entity, Designated Record Set, Electronic Protected Health Information ("ePHI"), Individual, Minimum Necessary, Protected Health Information ("PHI"), Required by Law, Security Incident, Subcontractor, and Unsecured PHI have the meanings given in the HIPAA Rules, including 45 C.F.R. § 160.103 where applicable.
- Services means the SureAppoint platform and approved support services in the applicable customer agreement. The Services support Practice-authored appointment policies, Policy Requests, policy and maximum-fee evidence, secure-link delivery, acceptance evidence, Practice-authorized payment activity through Stripe, and related audit evidence.
- SureAppoint Data means the limited information the Services are designed to process, which may include a patient or responsible party name, contact details, appointment date and time, practice/provider context, policy and fee information, secure-link and delivery evidence, acceptance and authorization timestamps, limited payment-provider references and statuses, and audit evidence. It does not include a complete patient record by design.
3. Permitted uses and disclosures
Business Associate may use or disclose PHI only as necessary to perform the Services and its obligations under the applicable customer agreement; for its proper management and administration or to carry out its legal responsibilities when permitted by law; or as Required by Law, with notice to Covered Entity when legally permitted and practicable.
The Services include creating and presenting a Policy Request; transmitting an approved secure link through an enabled delivery method; preserving policy, fee, delivery, acceptance, payment-status, and audit evidence; and providing customer support, security, availability, reconciliation, and incident response. For a management, administration, or legal-responsibility disclosure, Business Associate will first obtain reasonable assurances that the recipient will keep PHI confidential, use or further disclose it only as Required by Law or for the stated purpose, and report a breach of confidentiality to Business Associate.
Business Associate will make requests for, uses of, and disclosures of PHI consistent with Covered Entity's minimum-necessary policies and the Minimum Necessary requirements of the HIPAA Rules. It will not use or disclose PHI in a manner that would violate 45 C.F.R. Part 164, Subpart E if done by Covered Entity, except for the limited management, administration, and legal-responsibility uses expressly permitted above.
This BAA grants no independent right to sell PHI, use PHI for marketing or fundraising, use PHI for unrelated product development, or provide Data Aggregation services. It also grants no independent right to re-identify or commercialize de-identified information. Any such future activity requires a separate lawful analysis and written agreement; it is not authorized by this BAA.
4. Business Associate obligations
Business Associate will:
- Use appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as permitted by this BAA, and implement the safeguards required by 45 C.F.R. Part 164, Subpart C for ePHI.
- Report to Covered Entity any use or disclosure of PHI not provided for by this BAA, including a Breach of Unsecured PHI, without unreasonable delay and in no case later than 60 calendar days after discovery.
- For a Breach, provide the information required by 45 C.F.R. § 164.410 to the extent known, including each affected Individual, a description of what happened and the PHI involved, and the information Covered Entity reasonably needs to meet its notification obligations.
- Report Security Incidents to Covered Entity without unreasonable delay and in no case later than 60 calendar days after discovery. This BAA constitutes notice of routine unsuccessful Security Incidents that do not compromise the confidentiality, integrity, or availability of ePHI, such as pings, port scans, unsuccessful log-in attempts, denial-of-service attacks, or other unsuccessful attempts to penetrate systems containing ePHI.
- Mitigate, to the extent practicable, known harmful effects of an impermissible use or disclosure of PHI caused by Business Associate or its Subcontractor.
- Make its internal practices, books, and records relating to its use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services ("HHS") for purposes of determining Covered Entity's compliance with the HIPAA Rules.
- Not receive, maintain, or use full payment-card numbers, bank credentials, Stripe passwords, or identity-document images through the Services. Stripe hosts payment-method entry and processes payment activity under its own service relationship and terms.
5. Subcontractors and service providers
Business Associate may use Subcontractors to provide the Services. Where a Subcontractor creates, receives, maintains, or transmits PHI on Business Associate's behalf and HIPAA requires it, Business Associate will obtain appropriate written downstream Business Associate protections requiring that Subcontractor to comply with the restrictions, conditions, and requirements applicable to Business Associate with respect to the PHI.
Business Associate may add or replace Subcontractors without obtaining each Practice's individual approval, provided it meets the foregoing obligation. Business Associate will not select another database or use a provider as a Subcontractor for PHI merely because it is available.
The current product architecture identifies these provider categories. The table is an operational review list, not a representation that a provider has executed a BAA or may receive PHI. PHI may flow to a provider only after Business Associate has determined the provider's role and obtained applicable safeguards and written assurances.
| Provider or category | Current product role | PHI review required | | -------------------------------------- | ----------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | | Vercel | Application hosting and related infrastructure | Confirm applicable safeguards and downstream contractual protections. | | Neon | Managed PostgreSQL database infrastructure | Confirm applicable safeguards, backup handling, and downstream contractual protections. | | Resend, when email delivery is enabled | Transactional delivery of secure links | Confirm whether message content or identifiers are PHI and, if so, protections and retention treatment. | | Twilio, when SMS delivery is enabled | Transactional secure-link delivery and STOP/HELP handling | Confirm whether message content or identifiers are PHI and, if so, protections, messaging configuration, and retention treatment. | | Stripe | Connected-account onboarding, payment-method storage, payment processing, refunds, and disputes | Determine whether PHI is transmitted and the correct contractual role; this BAA does not state that Stripe is a Business Associate or Subcontractor. |
6. Individual rights support
To the extent Business Associate maintains PHI in a Designated Record Set and the HIPAA Rules require it, Business Associate will make PHI available to Covered Entity within a reasonable period so Covered Entity can respond to an Individual's access request under 45 C.F.R. § 164.524.
Business Associate will make PHI available to Covered Entity for amendment and accounting-of-disclosures obligations under 45 C.F.R. §§ 164.526 and 164.528, to the extent required and applicable to the Services. This does not require Business Associate to alter an immutable policy, fee, acceptance, authorization, delivery, payment, or audit event. If an approved correction is needed, the original evidence will be preserved and a separate correction or response recorded consistent with applicable law, the Data Retention Policy, and any legal hold.
Covered Entity remains responsible for the complete patient record, clinical record, scheduling record, attendance determination, and any obligation that does not apply to the limited PHI maintained by the Services.
7. Covered Entity obligations
Covered Entity will:
- Provide only PHI that is lawful and reasonably necessary for the Services.
- Maintain its scheduler or electronic medical record as the authoritative system of record for appointments, clinical information, attendance, and the complete patient record.
- Notify Business Associate of a change in or revocation of permission, a restriction, or its notice of privacy practices when it affects Business Associate's permitted use or disclosure of PHI and the HIPAA Rules require Covered Entity to communicate it.
- Not request or cause Business Associate to use or disclose PHI in a manner not permitted by the HIPAA Rules or this BAA.
- Remain responsible for its policies, patient communications, appointment facts, clinical and attendance determinations, billing decisions, and applicable patient-rights responses.
8. Term, termination, and return or destruction
This BAA begins on the effective date and continues until termination of the applicable customer agreement and the return or destruction of all PHI received from Covered Entity, or created, received, maintained, or transmitted by Business Associate on Covered Entity's behalf, if feasible.
Covered Entity may terminate this BAA and the applicable customer agreement if it determines that Business Associate has violated a material term of this BAA. If termination is not feasible, Covered Entity will report the problem to the Secretary as required by the HIPAA Rules.
At termination, Business Associate will, if feasible and legally permitted, return or destroy PHI it still maintains in active systems. If return or destruction is infeasible, including PHI in backups until normal rotation, immutable evidence retained for a lawful security, accounting, dispute, or legal-hold purpose, or PHI that must be retained by law, Business Associate will:
- Continue to protect that PHI under this BAA;
- Limit further uses and disclosures to those purposes that make return or destruction infeasible; and
- Return, destroy, or de-identify the PHI when the applicable retention or legal-hold obligation ends, subject to applicable law.
No fixed retention period is created by this BAA. Retention, backup, destruction, and legal-hold practices must remain consistent with applicable HIPAA requirements and the Data Retention Policy.
9. No clinical-record, EMR, or decision-making expansion
Nothing in this BAA changes the limited role of the Services. SureAppoint is not an electronic medical record, scheduler, patient portal, clinical decision tool, general practice-management system, collections platform, or complete patient-record repository. Business Associate does not determine attendance, clinical facts, whether a policy applies, or whether a fee should be charged.
This BAA does not authorize Covered Entity to submit additional clinical, insurance, or patient-record data merely because the parties have executed a BAA. Covered Entity must continue to minimize data to the information the Services request and require.
10. Relationship to other SureAppoint documents
For PHI privacy, security, and data-processing obligations governed by this BAA, this BAA controls to the extent necessary to satisfy applicable HIPAA requirements. Otherwise, the Commercial Agreement, Terms of Service, Privacy Policy, Acceptable Use Policy, and Data Retention Policy remain in effect under their existing framework.
This BAA does not alter the Practice's control of its appointment policies, violation determinations, fee decisions, or refunds/adjustments. Nor does it alter Stripe's payment role or authorize SureAppoint to store full card data.
11. Electronic execution and records
The parties may execute this BAA electronically, including during practice onboarding. A recorded electronic acceptance is execution only if the execution record identifies and permanently retains:
- the Covered Entity/practice or business;
- the exact BAA version and effective date;
- the authorized accepting user;
- the timestamp of acceptance; and
- an immutable audit event and retained executed copy or immutable acceptance record.
Covered Entity represents that its accepting user is authorized to accept this BAA for the Covered Entity. A completed onboarding applicability question is not, by itself, BAA acceptance. A valid electronic acceptance under this Section is the parties' execution evidence.
12. Governing law, venue, and amendments
The governing-law, venue, and dispute-resolution framework of the controlling Commercial Agreement is incorporated by reference. This BAA creates no separate or conflicting governing-law or venue provision.
The parties will amend this BAA as necessary to comply with applicable HIPAA requirements. Any amendment must be in writing and executed or accepted by authorized representatives through the applicable execution process.
13. Survival
Business Associate's obligations under Section 8 survive termination for as long as Business Associate retains PHI.
14. Signature blocks
COVERED ENTITY<br> Legal name: [Practice legal name]<br> By: ______________________________<br> Name and title: ______________________________<br> Date: ______________________________
BUSINESS ASSOCIATE<br> Passport Informatics, LLC, doing business as SureAppoint<br> By: ______________________________<br> Name and title: ______________________________<br> Date: ______________________________