
Sample Business Associate Agreement_
Version: 1.0
Last updated: 31 July 2026
Business Associate: Surgical Performance Pty Ltd
Related: Privacy Policy · HIPAA & Security · Trust Center · Terms of Use
This is the current form of SurgicalPerformance’s Business Associate Agreement. For US locations, Covered Entity accepts this Agreement electronically when creating a US location (or when otherwise first required for a US location). Wet-ink execution is available on request.
Parties
This Business Associate Agreement (“Agreement”) is entered into as of the date of electronic acceptance, or [Effective Date] if executed by hand (“Effective Date”), between:
- Covered Entity: the licensed physician and/or practice entity identified in the SurgicalPerformance account accepting this Agreement; and
- Business Associate: Surgical Performance Pty Ltd,
together the “Parties.”
Recitals
Covered Entity and Business Associate have entered into, or intend to enter into, a subscription for the SurgicalPerformance outcomes-tracking and patient-reported outcome measures (PROMS) platform and related services (the “Services”). In connection with the Services, Business Associate may create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity.
The Parties intend this Agreement to satisfy applicable requirements of HIPAA, HITECH, and their implementing regulations at 45 CFR Parts 160 and 164, as amended (collectively, “HIPAA”), and agree as follows.
Definitions
Capitalized terms used but not otherwise defined have the meanings in 45 CFR §§ 160.103 and 164.501, including “Breach,” “Designated Record Set,” “Electronic Protected Health Information” (“ePHI”), “Protected Health Information” (“PHI”), “Required by Law,” “Secretary,” “Security Incident,” “Subcontractor,” and “Unsecured Protected Health Information.”
“Underlying Agreement” means the Terms of Use / subscription terms accepted by Covered Entity to access the Services.Obligations and Activities of Business Associate
Business Associate agrees to:
1) Permitted use only. Not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law.
2) Safeguards. Use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 (Security Rule) with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
3) Reporting. Report to Covered Entity, without unreasonable delay and in no event later than 10 business days after discovery, any use or disclosure of PHI not permitted by this Agreement, and any Security Incident of which it becomes aware, including any Breach of Unsecured Protected Health Information, in accordance with 45 CFR § 164.410.
The Parties acknowledge that this section constitutes notice of the ongoing existence of routine, unsuccessful attempts that do not result in unauthorized access, use, disclosure, modification, or destruction of PHI (for example pings, port scans, failed login attempts), and no further notice of such unsuccessful incidents is required.
4) Subcontractors. Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate (for example a cloud hosting provider or an SMS gateway used to deliver PROMS messages) agrees in writing to the same restrictions, conditions, and safeguards that apply to Business Associate under this Agreement with respect to such PHI.
5) Access. Make PHI maintained in a Designated Record Set available to Covered Entity, or at Covered Entity’s direction to an individual, within 15 business days of a request, to enable Covered Entity to meet 45 CFR § 164.524.
6) Amendment. Make amendments to PHI in a Designated Record Set as directed by Covered Entity under 45 CFR § 164.526, within 15 business days of the request.
7) Accounting. Maintain, and make available to Covered Entity, information required for an accounting of disclosures under 45 CFR § 164.528, for the six years prior to the request (or such shorter period as Covered Entity specifies).
8) Privacy Rule performance. To the extent Business Associate carries out an obligation of Covered Entity under the Privacy Rule, comply with Subpart E of 45 CFR Part 164 applicable to Covered Entity in performing that obligation.
9) HHS access. Make internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary as designated by the Secretary, for determining compliance with HIPAA.
10) Return or destruction. Upon termination of this Agreement, if feasible, return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity that Business Associate still maintains, and retain no copies. If return or destruction is not feasible, extend the protections of this Agreement to retained PHI and limit further uses and disclosures to purposes that make return or destruction infeasible, for as long as Business Associate retains the PHI.
Covered Entity may trigger offboarding by: (a) exporting Patient Data then closing the account; (b) requesting deletion via [email protected] or an in-product control when available; or (c) allowing subscription expiry/termination, after which Business Associate will apply return/destruction (or continued protection if not immediately feasible) as above. Product self-serve controls may evolve; email [email protected] if in-product options are unavailable.Permitted Uses and Disclosures by Business Associate
Except as otherwise provided in this Agreement, Business Associate may use or disclose PHI only as necessary to perform the Services described in the Underlying Agreement, provided such use or disclosure would not violate HIPAA if done by Covered Entity, and specifically may:
1) Use and disclose PHI for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided disclosures are Required by Law, or Business Associate obtains reasonable assurances from the recipient that it will keep the PHI confidential and notify Business Associate of any breach of that confidentiality.
2) Use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity where offered by the Services (for example benchmarking a surgeon’s outcomes against de-identified peer data).
3) De-identify PHI in accordance with 45 CFR § 164.514(a)–(c), after which the resulting information is no longer PHI and may be used by Business Associate for benchmarking, product improvement, and research as described in the Privacy Policy, provided it can no longer identify Covered Entity or any patient without authorization where required.
4) Not sell PHI, and not use or disclose PHI for marketing or fundraising purposes, without a valid authorization under 45 CFR § 164.508 where required.
Business Associate will make uses and disclosures and requests for PHI consistent with minimum necessary requirements under HIPAA.Obligations of Covered Entity
Covered Entity agrees to:
1) Notify Business Associate of any limitation(s) in its notice of privacy practices under 45 CFR § 164.520, to the extent such limitation may affect Business Associate’s use or disclosure of PHI.
2) Notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent it may affect Business Associate’s use or disclosure of PHI.
3) Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR § 164.522, to the extent it may affect Business Associate’s use or disclosure of PHI.
4) Not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except for the limited purposes permitted under Section 3.
Enter only PHI that Covered Entity is authorized to provide to Business Associate, and configure patient communications (including PROMS) in accordance with applicable law.Term and Termination
1) Term. This Agreement is effective as of the Effective Date and continues until terminated as provided herein or when the Underlying Agreement ends and Business Associate no longer maintains PHI for Covered Entity (subject to Section 2.10).
2) Termination for cause. Covered Entity may terminate this Agreement if it determines Business Associate has violated a material term, and Business Associate has not cured the breach or ended the violation within 30 days of written notice where the breach is curable.
3) Effect of termination. Obligations under Section 2.10 survive termination. Provisions that by their nature should survive (including confidentiality and surviving HIPAA obligations) survive.
4) Relationship to Underlying Agreement. A material breach of this Agreement may constitute a material breach of the Underlying Agreement. Termination mechanics for the subscription are governed by the Underlying Agreement except where HIPAA requires return/destruction of PHI.Miscellaneous
1) Regulatory references. A reference to a section of the HIPAA Rules means that section as in effect or as amended.
2) Amendment. The Parties will take action as necessary to amend this Agreement from time to time for compliance with HIPAA and other applicable law. Business Associate may update the standard form of this Agreement for new acceptances; material changes affecting existing customers will be handled as required by law and the Underlying Agreement.
3) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with HIPAA.
4) No third-party beneficiaries. Nothing in this Agreement confers rights on any person other than the Parties, except as required by HIPAA (including HHS).
5) Entire agreement on HIPAA. This Agreement, together with the Underlying Agreement, constitutes the Parties’ agreement regarding PHI. In the event of conflict regarding PHI/HIPAA obligations, this Agreement controls.
6) Governing law. Except to the extent preempted by HIPAA or other applicable US federal law, this Agreement is governed by the laws of Australia and the State of Queensland, without prejudice to Covered Entity’s rights under HIPAA.
7) Notices. Notices under this Agreement may be sent to the email associated with Covered Entity’s account and to Business Associate at [email protected].
Acceptance
Electronic acceptance
By checking “I agree” (or equivalent) when creating a US location (or when otherwise first required for a US location), Covered Entity accepts this Agreement effective as of that date and time, which will be logged (including Agreement version) and made available to Covered Entity on request.
Signature
Covered Entity: [Surgeon’s name / practice legal name]
By: _______________________________ Date: ______________
Name / Title: _______________________________
Business Associate: Surgical Performance Pty Ltd
By: _______________________________ Date: ______________
Name / Title: _______________________________
Version: 1.0
Last updated: 31 July 2026
Business Associate: Surgical Performance Pty Ltd
Related: Privacy Policy · HIPAA & Security · Trust Center · Terms of Use
This is the current form of SurgicalPerformance’s Business Associate Agreement. For US locations, Covered Entity accepts this Agreement electronically when creating a US location (or when otherwise first required for a US location). Wet-ink execution is available on request.
Parties
This Business Associate Agreement (“Agreement”) is entered into as of the date of electronic acceptance, or [Effective Date] if executed by hand (“Effective Date”), between:
- Covered Entity: the licensed physician and/or practice entity identified in the SurgicalPerformance account accepting this Agreement; and
- Business Associate: Surgical Performance Pty Ltd,
together the “Parties.”
Recitals
Covered Entity and Business Associate have entered into, or intend to enter into, a subscription for the SurgicalPerformance outcomes-tracking and patient-reported outcome measures (PROMS) platform and related services (the “Services”). In connection with the Services, Business Associate may create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity.
The Parties intend this Agreement to satisfy applicable requirements of HIPAA, HITECH, and their implementing regulations at 45 CFR Parts 160 and 164, as amended (collectively, “HIPAA”), and agree as follows.
Definitions
Capitalized terms used but not otherwise defined have the meanings in 45 CFR §§ 160.103 and 164.501, including “Breach,” “Designated Record Set,” “Electronic Protected Health Information” (“ePHI”), “Protected Health Information” (“PHI”), “Required by Law,” “Secretary,” “Security Incident,” “Subcontractor,” and “Unsecured Protected Health Information.”
“Underlying Agreement” means the Terms of Use / subscription terms accepted by Covered Entity to access the Services.Obligations and Activities of Business Associate
Business Associate agrees to:
1) Permitted use only. Not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law.
2) Safeguards. Use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 (Security Rule) with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
3) Reporting. Report to Covered Entity, without unreasonable delay and in no event later than 10 business days after discovery, any use or disclosure of PHI not permitted by this Agreement, and any Security Incident of which it becomes aware, including any Breach of Unsecured Protected Health Information, in accordance with 45 CFR § 164.410.
The Parties acknowledge that this section constitutes notice of the ongoing existence of routine, unsuccessful attempts that do not result in unauthorized access, use, disclosure, modification, or destruction of PHI (for example pings, port scans, failed login attempts), and no further notice of such unsuccessful incidents is required.
4) Subcontractors. Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate (for example a cloud hosting provider or an SMS gateway used to deliver PROMS messages) agrees in writing to the same restrictions, conditions, and safeguards that apply to Business Associate under this Agreement with respect to such PHI.
5) Access. Make PHI maintained in a Designated Record Set available to Covered Entity, or at Covered Entity’s direction to an individual, within 15 business days of a request, to enable Covered Entity to meet 45 CFR § 164.524.
6) Amendment. Make amendments to PHI in a Designated Record Set as directed by Covered Entity under 45 CFR § 164.526, within 15 business days of the request.
7) Accounting. Maintain, and make available to Covered Entity, information required for an accounting of disclosures under 45 CFR § 164.528, for the six years prior to the request (or such shorter period as Covered Entity specifies).
8) Privacy Rule performance. To the extent Business Associate carries out an obligation of Covered Entity under the Privacy Rule, comply with Subpart E of 45 CFR Part 164 applicable to Covered Entity in performing that obligation.
9) HHS access. Make internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary as designated by the Secretary, for determining compliance with HIPAA.
10) Return or destruction. Upon termination of this Agreement, if feasible, return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity that Business Associate still maintains, and retain no copies. If return or destruction is not feasible, extend the protections of this Agreement to retained PHI and limit further uses and disclosures to purposes that make return or destruction infeasible, for as long as Business Associate retains the PHI.
Covered Entity may trigger offboarding by: (a) exporting Patient Data then closing the account; (b) requesting deletion via [email protected] or an in-product control when available; or (c) allowing subscription expiry/termination, after which Business Associate will apply return/destruction (or continued protection if not immediately feasible) as above. Product self-serve controls may evolve; email [email protected] if in-product options are unavailable.Permitted Uses and Disclosures by Business Associate
Except as otherwise provided in this Agreement, Business Associate may use or disclose PHI only as necessary to perform the Services described in the Underlying Agreement, provided such use or disclosure would not violate HIPAA if done by Covered Entity, and specifically may:
1) Use and disclose PHI for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided disclosures are Required by Law, or Business Associate obtains reasonable assurances from the recipient that it will keep the PHI confidential and notify Business Associate of any breach of that confidentiality.
2) Use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity where offered by the Services (for example benchmarking a surgeon’s outcomes against de-identified peer data).
3) De-identify PHI in accordance with 45 CFR § 164.514(a)–(c), after which the resulting information is no longer PHI and may be used by Business Associate for benchmarking, product improvement, and research as described in the Privacy Policy, provided it can no longer identify Covered Entity or any patient without authorization where required.
4) Not sell PHI, and not use or disclose PHI for marketing or fundraising purposes, without a valid authorization under 45 CFR § 164.508 where required.
Business Associate will make uses and disclosures and requests for PHI consistent with minimum necessary requirements under HIPAA.Obligations of Covered Entity
Covered Entity agrees to:
1) Notify Business Associate of any limitation(s) in its notice of privacy practices under 45 CFR § 164.520, to the extent such limitation may affect Business Associate’s use or disclosure of PHI.
2) Notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent it may affect Business Associate’s use or disclosure of PHI.
3) Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR § 164.522, to the extent it may affect Business Associate’s use or disclosure of PHI.
4) Not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except for the limited purposes permitted under Section 3.
Enter only PHI that Covered Entity is authorized to provide to Business Associate, and configure patient communications (including PROMS) in accordance with applicable law.Term and Termination
1) Term. This Agreement is effective as of the Effective Date and continues until terminated as provided herein or when the Underlying Agreement ends and Business Associate no longer maintains PHI for Covered Entity (subject to Section 2.10).
2) Termination for cause. Covered Entity may terminate this Agreement if it determines Business Associate has violated a material term, and Business Associate has not cured the breach or ended the violation within 30 days of written notice where the breach is curable.
3) Effect of termination. Obligations under Section 2.10 survive termination. Provisions that by their nature should survive (including confidentiality and surviving HIPAA obligations) survive.
4) Relationship to Underlying Agreement. A material breach of this Agreement may constitute a material breach of the Underlying Agreement. Termination mechanics for the subscription are governed by the Underlying Agreement except where HIPAA requires return/destruction of PHI.Miscellaneous
1) Regulatory references. A reference to a section of the HIPAA Rules means that section as in effect or as amended.
2) Amendment. The Parties will take action as necessary to amend this Agreement from time to time for compliance with HIPAA and other applicable law. Business Associate may update the standard form of this Agreement for new acceptances; material changes affecting existing customers will be handled as required by law and the Underlying Agreement.
3) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with HIPAA.
4) No third-party beneficiaries. Nothing in this Agreement confers rights on any person other than the Parties, except as required by HIPAA (including HHS).
5) Entire agreement on HIPAA. This Agreement, together with the Underlying Agreement, constitutes the Parties’ agreement regarding PHI. In the event of conflict regarding PHI/HIPAA obligations, this Agreement controls.
6) Governing law. Except to the extent preempted by HIPAA or other applicable US federal law, this Agreement is governed by the laws of Australia and the State of Queensland, without prejudice to Covered Entity’s rights under HIPAA.
7) Notices. Notices under this Agreement may be sent to the email associated with Covered Entity’s account and to Business Associate at [email protected].
Acceptance
Electronic acceptance
By checking “I agree” (or equivalent) when creating a US location (or when otherwise first required for a US location), Covered Entity accepts this Agreement effective as of that date and time, which will be logged (including Agreement version) and made available to Covered Entity on request.
Signature
Covered Entity: [Surgeon’s name / practice legal name]
By: _______________________________ Date: ______________
Name / Title: _______________________________
Business Associate: Surgical Performance Pty Ltd
By: _______________________________ Date: ______________
Name / Title: _______________________________
Version: 1.0
Last updated: 31 July 2026
Business Associate: Surgical Performance Pty Ltd
Related: Privacy Policy · HIPAA & Security · Trust Center · Terms of Use
This is the current form of SurgicalPerformance’s Business Associate Agreement. For US locations, Covered Entity accepts this Agreement electronically when creating a US location (or when otherwise first required for a US location). Wet-ink execution is available on request.
Parties
This Business Associate Agreement (“Agreement”) is entered into as of the date of electronic acceptance, or [Effective Date] if executed by hand (“Effective Date”), between:
- Covered Entity: the licensed physician and/or practice entity identified in the SurgicalPerformance account accepting this Agreement; and
- Business Associate: Surgical Performance Pty Ltd,
together the “Parties.”
Recitals
Covered Entity and Business Associate have entered into, or intend to enter into, a subscription for the SurgicalPerformance outcomes-tracking and patient-reported outcome measures (PROMS) platform and related services (the “Services”). In connection with the Services, Business Associate may create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity.
The Parties intend this Agreement to satisfy applicable requirements of HIPAA, HITECH, and their implementing regulations at 45 CFR Parts 160 and 164, as amended (collectively, “HIPAA”), and agree as follows.
Definitions
Capitalized terms used but not otherwise defined have the meanings in 45 CFR §§ 160.103 and 164.501, including “Breach,” “Designated Record Set,” “Electronic Protected Health Information” (“ePHI”), “Protected Health Information” (“PHI”), “Required by Law,” “Secretary,” “Security Incident,” “Subcontractor,” and “Unsecured Protected Health Information.”
“Underlying Agreement” means the Terms of Use / subscription terms accepted by Covered Entity to access the Services.Obligations and Activities of Business Associate
Business Associate agrees to:
1) Permitted use only. Not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law.
2) Safeguards. Use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 CFR Part 164 (Security Rule) with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement.
3) Reporting. Report to Covered Entity, without unreasonable delay and in no event later than 10 business days after discovery, any use or disclosure of PHI not permitted by this Agreement, and any Security Incident of which it becomes aware, including any Breach of Unsecured Protected Health Information, in accordance with 45 CFR § 164.410.
The Parties acknowledge that this section constitutes notice of the ongoing existence of routine, unsuccessful attempts that do not result in unauthorized access, use, disclosure, modification, or destruction of PHI (for example pings, port scans, failed login attempts), and no further notice of such unsuccessful incidents is required.
4) Subcontractors. Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate (for example a cloud hosting provider or an SMS gateway used to deliver PROMS messages) agrees in writing to the same restrictions, conditions, and safeguards that apply to Business Associate under this Agreement with respect to such PHI.
5) Access. Make PHI maintained in a Designated Record Set available to Covered Entity, or at Covered Entity’s direction to an individual, within 15 business days of a request, to enable Covered Entity to meet 45 CFR § 164.524.
6) Amendment. Make amendments to PHI in a Designated Record Set as directed by Covered Entity under 45 CFR § 164.526, within 15 business days of the request.
7) Accounting. Maintain, and make available to Covered Entity, information required for an accounting of disclosures under 45 CFR § 164.528, for the six years prior to the request (or such shorter period as Covered Entity specifies).
8) Privacy Rule performance. To the extent Business Associate carries out an obligation of Covered Entity under the Privacy Rule, comply with Subpart E of 45 CFR Part 164 applicable to Covered Entity in performing that obligation.
9) HHS access. Make internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary as designated by the Secretary, for determining compliance with HIPAA.
10) Return or destruction. Upon termination of this Agreement, if feasible, return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity that Business Associate still maintains, and retain no copies. If return or destruction is not feasible, extend the protections of this Agreement to retained PHI and limit further uses and disclosures to purposes that make return or destruction infeasible, for as long as Business Associate retains the PHI.
Covered Entity may trigger offboarding by: (a) exporting Patient Data then closing the account; (b) requesting deletion via [email protected] or an in-product control when available; or (c) allowing subscription expiry/termination, after which Business Associate will apply return/destruction (or continued protection if not immediately feasible) as above. Product self-serve controls may evolve; email [email protected] if in-product options are unavailable.Permitted Uses and Disclosures by Business Associate
Except as otherwise provided in this Agreement, Business Associate may use or disclose PHI only as necessary to perform the Services described in the Underlying Agreement, provided such use or disclosure would not violate HIPAA if done by Covered Entity, and specifically may:
1) Use and disclose PHI for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided disclosures are Required by Law, or Business Associate obtains reasonable assurances from the recipient that it will keep the PHI confidential and notify Business Associate of any breach of that confidentiality.
2) Use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity where offered by the Services (for example benchmarking a surgeon’s outcomes against de-identified peer data).
3) De-identify PHI in accordance with 45 CFR § 164.514(a)–(c), after which the resulting information is no longer PHI and may be used by Business Associate for benchmarking, product improvement, and research as described in the Privacy Policy, provided it can no longer identify Covered Entity or any patient without authorization where required.
4) Not sell PHI, and not use or disclose PHI for marketing or fundraising purposes, without a valid authorization under 45 CFR § 164.508 where required.
Business Associate will make uses and disclosures and requests for PHI consistent with minimum necessary requirements under HIPAA.Obligations of Covered Entity
Covered Entity agrees to:
1) Notify Business Associate of any limitation(s) in its notice of privacy practices under 45 CFR § 164.520, to the extent such limitation may affect Business Associate’s use or disclosure of PHI.
2) Notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent it may affect Business Associate’s use or disclosure of PHI.
3) Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR § 164.522, to the extent it may affect Business Associate’s use or disclosure of PHI.
4) Not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except for the limited purposes permitted under Section 3.
Enter only PHI that Covered Entity is authorized to provide to Business Associate, and configure patient communications (including PROMS) in accordance with applicable law.Term and Termination
1) Term. This Agreement is effective as of the Effective Date and continues until terminated as provided herein or when the Underlying Agreement ends and Business Associate no longer maintains PHI for Covered Entity (subject to Section 2.10).
2) Termination for cause. Covered Entity may terminate this Agreement if it determines Business Associate has violated a material term, and Business Associate has not cured the breach or ended the violation within 30 days of written notice where the breach is curable.
3) Effect of termination. Obligations under Section 2.10 survive termination. Provisions that by their nature should survive (including confidentiality and surviving HIPAA obligations) survive.
4) Relationship to Underlying Agreement. A material breach of this Agreement may constitute a material breach of the Underlying Agreement. Termination mechanics for the subscription are governed by the Underlying Agreement except where HIPAA requires return/destruction of PHI.Miscellaneous
1) Regulatory references. A reference to a section of the HIPAA Rules means that section as in effect or as amended.
2) Amendment. The Parties will take action as necessary to amend this Agreement from time to time for compliance with HIPAA and other applicable law. Business Associate may update the standard form of this Agreement for new acceptances; material changes affecting existing customers will be handled as required by law and the Underlying Agreement.
3) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with HIPAA.
4) No third-party beneficiaries. Nothing in this Agreement confers rights on any person other than the Parties, except as required by HIPAA (including HHS).
5) Entire agreement on HIPAA. This Agreement, together with the Underlying Agreement, constitutes the Parties’ agreement regarding PHI. In the event of conflict regarding PHI/HIPAA obligations, this Agreement controls.
6) Governing law. Except to the extent preempted by HIPAA or other applicable US federal law, this Agreement is governed by the laws of Australia and the State of Queensland, without prejudice to Covered Entity’s rights under HIPAA.
7) Notices. Notices under this Agreement may be sent to the email associated with Covered Entity’s account and to Business Associate at [email protected].
Acceptance
Electronic acceptance
By checking “I agree” (or equivalent) when creating a US location (or when otherwise first required for a US location), Covered Entity accepts this Agreement effective as of that date and time, which will be logged (including Agreement version) and made available to Covered Entity on request.
Signature
Covered Entity: [Surgeon’s name / practice legal name]
By: _______________________________ Date: ______________
Name / Title: _______________________________
Business Associate: Surgical Performance Pty Ltd
By: _______________________________ Date: ______________
Name / Title: _______________________________

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

