Legal
Business Associate Agreement
Effective: 2026-05-30
This summary describes our standard Business Associate Agreement (“BAA”), entered into with every Customer who is a Covered Entity (or Business Associate of one) under HIPAA, prior to any Protected Health Information being processed on the platform.
Why we sign a BAA
45 CFR §164.504(e) requires that Covered Entities obtain “satisfactory assurances” from their Business Associates that PHI will be appropriately safeguarded. The BAA is that assurance.
Permitted uses and disclosures
- To provide the Services described in the MSA / Order Form.
- To perform proper management and administration of WeConsult Rx.
- To carry out our legal responsibilities.
- For data aggregation services (de-identified) as permitted by §164.504(e)(2)(i)(B).
Safeguards
We implement administrative, physical, and technical safeguards that reasonably and appropriately protect PHI as required by the Security Rule (§164.308 / .310 / .312). See our HIPAA controls page.
Subcontractors
We will require any subcontractor that creates, receives, maintains, or transmits PHI on our behalf to sign a BAA with terms substantially equivalent to those in our BAA with Customer. See /subprocessors.
Breach notification
We will notify Customer of any Breach of unsecured PHI within the timeframes required by §164.410, and in no event later than sixty (60) calendar days from discovery.
Term and termination
The BAA terminates on termination of the underlying Service. Upon termination, we will return or destroy all PHI received, created, or maintained on behalf of Customer, where feasible.
Request a countersigned BAA
Email [email protected] with the legal entity name and authorized signatory. We countersign within one business day.