Business Associate Agreement
Version 2026-08-19.d1 · between the accepting organization ("Covered Entity") and Navix Health ("Business Associate")
Draft for review. This document is a plain-language draft pending legal counsel review; the version identifier above will change when the reviewed text is finalized.
Purpose
Covered Entity uses NavixPulse to process health information for its care and wellness operations. This agreement satisfies the parties' obligations under HIPAA (45 CFR Parts 160 and 164) with respect to Protected Health Information ("PHI") that Business Associate creates, receives, maintains, or transmits on Covered Entity's behalf.
Business Associate will
- Use and disclose PHI only to provide the NavixPulse service to Covered Entity, as permitted by this agreement, or as required by law.
- Apply administrative, physical, and technical safeguards that reasonably and appropriately protect PHI, including database-level tenant isolation, role-based access, encryption in transit and at rest, and audit logging.
- Report to Covered Entity any use or disclosure not permitted by this agreement, including breaches of unsecured PHI as required by 45 CFR §164.410, without unreasonable delay and within the timeframes required by law.
- Ensure subcontractors that handle PHI on its behalf (infrastructure and messaging providers) agree to equivalent restrictions.
- Make PHI available for access and amendment, and provide an accounting of disclosures, as required by 45 CFR §§164.524–528.
- Make its practices available to the Secretary of Health and Human Services for compliance determination.
Covered Entity will
- Use the platform's consent flows for individuals it enrolls, and not request uses or disclosures beyond those HIPAA permits.
- Notify Business Associate of restrictions or revocations that affect permitted uses.
De-identification
Business Associate may de-identify PHI in accordance with 45 CFR §164.514. De-identified data is no longer PHI; its use for the community algorithm additionally requires the Covered Entity's separate Data Contribution Agreement opt-in.
Term and termination
This agreement runs while Covered Entity uses NavixPulse. On termination, Business Associate returns Covered Entity's data by export and then destroys remaining PHI, except where retention is required by law, in which case protections continue for as long as the PHI is retained. Either party may terminate for material breach not cured within thirty days of notice.
Acceptance
This agreement is accepted electronically by an authorized representative of the Covered Entity; the signer's name, title, timestamp, and organization are recorded and a copy is available to the organization's administrators at any time.