Business Associate Agreement

Business Associate Agreement Template

WardLens executes a Business Associate Agreement (BAA) with every covered entity before processing any protected health information. Below is our standard BAA template for review.

Template version: April 2026


📜

What is a BAA?

A Business Associate Agreement is a HIPAA-required contract between a covered entity (your hospital) and a business associate (WardLens) that establishes permitted uses and safeguards for PHI.

🏥

WardLens as Business Associate

WardLens creates, receives, maintains, and transmits PHI on behalf of your facility through body camera footage management, AI clinical documentation, and incident tracking.

Getting Started

Review the template below, then contact us to initiate your BAA. We can accommodate reasonable modifications to meet your legal team's requirements.

Download the BAA Template

Get a copy of our standard Business Associate Agreement for your legal team's review. Available for download as a text document.

ℹ️

Note: This is a template for reference purposes. The executed BAA between WardLens and your organization may contain modifications agreed upon by both parties. This template does not constitute legal advice — please consult your legal counsel.

Business Associate Agreement

This Business Associate Agreement ("Agreement") is entered into by and between the healthcare organization identified on the signature page ("Covered Entity") and WardLens ("Business Associate"), effective as of the date of last signature ("Effective Date").

This Agreement is entered into in connection with the services provided by Business Associate to Covered Entity under the applicable service agreement ("Service Agreement"), and to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), and their implementing regulations (collectively, the "HIPAA Rules").

1. Definitions

Terms used but not defined in this Agreement shall have the meanings ascribed to them in the HIPAA Rules. The following definitions apply:

2. Permitted Uses and Disclosures

2.1 Service Performance

Business Associate may use and disclose PHI solely to perform services for Covered Entity as specified in the Service Agreement, provided that such use or disclosure would not violate the HIPAA Rules if done by Covered Entity. Such services include:

  1. Storing, organizing, and managing body camera footage from clinical interactions
  2. Processing transcriptions and generating AI-assisted clinical documentation (SOAP notes, progress notes, ICD-10 code suggestions)
  3. Managing incident reports related to workplace safety events
  4. Providing audit trails, access logs, and compliance reporting
  5. Providing technical support and system maintenance

2.2 Management and Administration

Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities, provided that any disclosure is required by law or Business Associate obtains reasonable assurances that the information will be held confidentially.

2.3 Aggregate and De-identified Data

Business Associate may de-identify PHI in accordance with 45 CFR 164.514 and may use de-identified data for research, analytics, and product improvement purposes. Business Associate may create aggregate data sets that do not contain individually identifiable health information.

3. Obligations of Business Associate

3.1 Safeguards

Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, in accordance with 45 CFR Part 164, Subpart C. These safeguards include but are not limited to:

3.2 Reporting

Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including any Security Incident or Breach, without unreasonable delay and in no case later than sixty (60) calendar days after discovery.

3.3 Subcontractors

Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of the Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to the Business Associate under this Agreement.

3.4 Access to PHI

Business Associate shall make PHI maintained in a Designated Record Set available to Covered Entity in a timely manner to enable Covered Entity to fulfill its obligations under 45 CFR 164.524 (individual's right of access).

3.5 Amendment of PHI

Business Associate shall make PHI available for amendment and incorporate amendments to PHI in a Designated Record Set as directed by Covered Entity pursuant to 45 CFR 164.526.

3.6 Accounting of Disclosures

Business Associate shall make available the information required to provide an accounting of disclosures in accordance with 45 CFR 164.528.

3.7 Government Access

Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules.

4. Breach Notification

In the event of a Breach of unsecured PHI, Business Associate shall:

  1. Notify Covered Entity in writing within sixty (60) calendar days of discovery of the Breach
  2. Include in such notification: identification of the individuals affected, a description of the types of information involved, the date of the Breach and date of discovery, a description of what Business Associate is doing to investigate and mitigate the Breach, and contact information for inquiries
  3. Cooperate with Covered Entity in providing notification to affected individuals, the Secretary of HHS, and media outlets as required by 45 CFR 164.404-408
  4. Take immediate steps to mitigate any harmful effects of the Breach to the extent practicable
  5. Document all Breaches and maintain records for a minimum of six (6) years

5. Term and Termination

5.1 Term

This Agreement is effective as of the Effective Date and shall remain in effect for the duration of the Service Agreement, unless earlier terminated as provided herein.

5.2 Termination for Cause

Either party may terminate this Agreement if it determines that the other party has materially breached a provision of this Agreement and the breach is not cured within thirty (30) calendar days of written notice.

5.3 Effect of Termination

Upon termination of this Agreement, Business Associate shall:

  1. Cease all uses and disclosures of PHI
  2. Return or destroy all PHI in its possession, including all copies in any form
  3. Certify in writing to Covered Entity that all PHI has been returned or destroyed
  4. If return or destruction is not feasible, extend the protections of this Agreement to the remaining PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible

6. General Provisions

6.1 Amendments

This Agreement may not be modified except by written agreement signed by both parties. The parties agree to negotiate in good faith any amendments necessary to comply with changes to the HIPAA Rules.

6.2 Survival

The obligations of Business Associate under Sections 3 and 4 of this Agreement shall survive termination of this Agreement to the extent that Business Associate retains any PHI.

6.3 Interpretation

Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits compliance with the HIPAA Rules.

6.4 No Third-Party Beneficiaries

Nothing in this Agreement shall confer upon any person other than the parties and their respective successors or assigns any rights, remedies, obligations, or liabilities.