PUBLIC AGREEMENT REFERENCE
Business Associate Agreement
This public reference is based on the published master; personal contact names and signature fields are omitted. It is not an agreement signed by your practice. Practice-specific fields are completed during onboarding. Your accepted copies remain available in your account.
This website currently invites demo requests and pilot interest. These references do not enroll your practice in a trial or pilot; participation and any applicable fees must be agreed first.
Publication: remitguard-production-2026-10-06-v3. Blank fields below are intentional template fields.
RemitGuard Business Associate Agreement Template
Reusable master version 1.1 · October 3, 2026 · Unsigned
This agreement sets the permitted handling and protection of practice patient information by RemitGuard. Complete the practice setup sheet and obtain both parties’ authorized signatures for each engagement. Preparing this master does not execute an agreement or activate patient-data processing.
Practice setup sheet
Complete this sheet for each practice. The standard terms below apply unless the parties expressly agree a written variation. Confirm the parties’ legal identities before signing.
- Covered Entity legal name and entity type: [practice legal name and entity type]
- Address: [registered or principal business address]
- Participating entities and locations: [list legal entities and locations; attach a schedule if needed]
- Services Agreement title and date: [matching pilot/services agreement]
- Later agreed effective date, if any: [date or none; otherwise the last signature date]
- Practice privacy contact and alternate: [names, titles and direct contact details]
- Protected channel for PHI and incident details: The authenticated RemitGuard workspace for supported uploads and downloads. Contact support without patient information to arrange any sensitive incident evidence not supported by the workspace.
Use this template when the practice is a HIPAA Covered Entity. A billing company or other Business Associate requires an adapted subcontractor agreement. Separate legal entities must be expressly included and properly represented; a practice trade name alone does not bind unrelated entities.
Parties and effective date
This Business Associate Agreement (“BAA”) is between [practice legal name and entity type from setup sheet], with its address at [address] (“Covered Entity”), and RemitGuard, LLC, with its address at 101 North First Avenue, Suite 2325, Phoenix, AZ 85003, United States (“Business Associate”). The parties' services agreement is [title and date] (“Services Agreement”). This BAA takes effect on the date of the last authorized signature, or the later date expressly identified in the setup sheet.
1. Definitions and scope
“HIPAA Rules” means the applicable Privacy, Security, Breach Notification and Enforcement Rules in 45 CFR Parts 160 and 164, as amended. Terms including Protected Health Information (“PHI”), electronic PHI, Breach, Unsecured PHI, Security Incident, Designated Record Set, Individual, Secretary and Required by Law have their meanings under those rules.
This BAA applies to PHI Business Associate creates, receives, maintains or transmits on Covered Entity's behalf, including through subcontractors, while providing the agreed services. The services and approved processing arrangements are described in Schedule A.
2. Permitted uses and disclosures
Business Associate may use or disclose PHI only to provide the agreed services, as expressly permitted by this BAA, or as Required by Law. It will limit requests, access, use and disclosure to the minimum necessary where applicable. It will not use or disclose PHI in a manner that would violate the Privacy Rule if done by Covered Entity.
No independent advertising, sale of PHI, cross-customer data aggregation, general-purpose model training, or independent commercialization of de-identified customer data is authorized by this BAA. Any proposed additional purpose requires a separate lawful written agreement before it begins. AI-assisted processing is limited to the agreed service and approved vendors/configuration; AI output remains subject to authorized human review.
Covered Entity retains responsibility for its clinical and business decisions and for approving payer submissions. This does not reduce Business Associate's duties under this BAA.
3. Safeguards and workforce access
Business Associate will maintain appropriate administrative, physical and technical safeguards to prevent unauthorized use or disclosure and will comply with applicable provisions of the HIPAA Security Rule for electronic PHI. It will assign security responsibilities, limit access to authorized personnel, provide appropriate workforce training, and maintain incident and recovery procedures.
Business Associate will not place PHI in ordinary notification emails or unapproved support tools. Detailed incident evidence and patient records will be exchanged through an agreed protected method. This agreement does not represent a particular certification.
4. Reporting and cooperation
Business Associate will report to Covered Entity any use or disclosure not permitted by this BAA, any Security Incident of which it becomes aware, and any Breach of Unsecured PHI as required by 45 CFR 164.410.
Initial notice of a suspected or confirmed impermissible use or disclosure, Breach, or material Security Incident will be provided without unreasonable delay and no later than 72 hours after discovery. Discovery includes when the event is known, or through reasonable diligence would have been known, to Business Associate as provided by applicable law. An incomplete investigation does not postpone initial notice. Any earlier applicable legal deadline controls.
The parties agree that unsuccessful attempts that do not result in unauthorized access, use, disclosure, modification, destruction or interference with information systems may be reported in a monthly aggregate summary, provided within ten business days after month end. Examples include blocked scans and unsuccessful logins. An event involving actual or suspected compromise or service interference does not qualify for aggregate-only reporting. Other Security Incidents will be reported without unreasonable delay and no later than 72 hours after discovery.
An initial report may be preliminary. Business Associate will provide available facts and supplement promptly as more become known, including:
- Discovery and occurrence dates, if known, and the nature of the event.
- Affected Individuals and PHI categories to the extent known and required, using protected delivery.
- Known recipients or access, containment, mitigation and corrective measures.
- Information reasonably needed for Covered Entity to fulfill its notification duties.
Business Associate will cooperate with investigation and mitigation and preserve relevant evidence. The parties will document who provides notices to Individuals, HHS or others; Business Associate will not undertake notices on Covered Entity's behalf without written delegation, except where independently required by law. Approval processes must not cause an unlawful delay. Notice contacts are in Schedule B.
5. Subcontractors
Before a subcontractor creates, receives, maintains or transmits PHI on its behalf, Business Associate will obtain the applicable written agreement imposing the same restrictions, conditions and requirements for that PHI as apply to Business Associate, including required safeguards for electronic PHI.
Business Associate will maintain a current list of relevant subcontractors and service functions and provide it to Covered Entity on request. Business Associate will give 30 calendar days’ advance written notice before a new or replacement subcontractor materially changes PHI processing. Covered Entity may raise a reasonable data-protection objection during that period. The parties will seek an alternative; if none is reasonably available, Covered Entity may end the affected service before the change. An urgent change necessary to protect data or comply with law may occur sooner, with notice without unreasonable delay and an explanation. Required agreements and safeguards must be in place before PHI is provided to the subcontractor in every case.
6. Individual rights and HHS access
To the extent it holds PHI in a Designated Record Set, Business Associate will make that PHI available to Covered Entity as needed to satisfy 45 CFR 164.524, in an agreed usable format. It will make amendments directed or agreed to by Covered Entity, or take other necessary measures, under 45 CFR 164.526. It will maintain and provide information needed for an accounting of disclosures under 45 CFR 164.528.
Business Associate will respond to these requests within ten business days, or sooner as necessary for Covered Entity to meet an applicable legal deadline communicated to Business Associate. Business Associate will promptly forward Individual requests received directly to Covered Entity and will not independently deny or resolve them unless authorized or legally required. Any copying charges must comply with applicable law and the parties' agreement.
When carrying out a delegated Privacy Rule obligation, Business Associate will comply with the requirements applicable to that obligation. Business Associate will make relevant internal practices, books and records available to the Secretary for determining compliance with the HIPAA Rules.
7. Covered Entity instructions
Covered Entity will communicate relevant limitations in its privacy practices, changes or revocations of permissions, and applicable restrictions that affect Business Associate's permitted handling of PHI. It will provide lawful instructions and authorized contacts and will not request an impermissible use or disclosure. Business Associate will raise apparent conflicts promptly and seek clarification without expanding its permitted use.
8. Term and termination
This BAA continues while Business Associate holds PHI covered by it, subject to the continuing obligations below. Covered Entity may terminate for a material violation. Where cure is feasible and does not require immediate action, Covered Entity may provide ten calendar days after written notice to cure or end the violation. Covered Entity may terminate immediately where cure is not feasible or immediate action is reasonably necessary to protect PHI or comply with law. Ending or suspending services does not eliminate duties for retained PHI.
On termination, Business Associate will, where feasible, return or destroy covered PHI, including applicable subcontractor copies, and retain no copies. Schedule C governs the export method, disposition schedule and confirmation. If return or destruction is infeasible, Business Associate will document the reason and affected categories, continue this BAA's protections, and restrict further use or disclosure to the purposes making return or destruction infeasible for as long as the PHI is retained. It will return or destroy that PHI when the condition ends and disposition becomes feasible.
Backup retention is not a blanket exemption from these obligations. Retained recovery copies must remain protected and unavailable for ordinary use. A restoration must reapply applicable disposition instructions and preservation holds. Automatic expiration must not override a valid hold. Business Associate will provide written disposition confirmation or documented remaining exceptions to the authenticated practice contact under Schedule B, with sensitive details provided only through the protected channel.
9. Interpretation and relationship to other agreements
For PHI-handling obligations, this BAA controls over inconsistent Services Agreement terms. The parties will amend it as necessary to comply with applicable law. Provisions concerning retained PHI survive termination. This BAA does not create an independent right for third parties to enforce it, except as applicable law requires.
Federal law governs the HIPAA obligations. To the extent not preempted, the governing law and dispute forum expressly agreed in the Services Agreement apply. If that agreement is silent, Arizona law applies without its conflict-of-laws rules, and the parties consent to courts of competent jurisdiction in Maricopa County, Arizona. This clause does not limit regulatory jurisdiction or mandatory applicable law.
No separate liability cap, indemnity, insurance commitment or waiver is created by this BAA. Any such commercial allocation must be expressly agreed in the Services Agreement and cannot eliminate a duty imposed by applicable law. Amendments require written acceptance by authorized representatives of both parties. An unenforceable provision does not invalidate the remaining provisions to the extent permitted by law. A failure to enforce a provision is not a waiver.
Electronic signatures and counterparts may be used. Each signer must have authority to bind the identified party. RemitGuard’s signature must be applied by its authorized owner or a separately authorized signing process; a practice’s acceptance alone does not constitute RemitGuard’s countersignature. Each party receives the complete signed version. A change to a published template does not alter an already executed agreement.
Schedule A Services and processing
The authorized services are receiving and processing electronic remittances; extracting and reviewing contract information; comparing approved payment terms; organizing evidence and follow-up records; preparing payer letter and packet drafts; and maintaining the records and recovery copies needed for those services. The Services Agreement identifies the subscribed features and participating practice scope. Creating a packet does not authorize RemitGuard to submit it to a payer.
Business Associate may engage contracted providers for hosting, storage, database and authentication, document extraction and contract interpretation, subject to section 5. A current list of PHI-handling subcontractors and their functions is available on request. Ordinary email is limited to account and service notices without PHI. This schedule does not expand the uses permitted in section 2.
PHI processing for the authorized services may begin after both parties execute this BAA and the Services Agreement and the practice workspace becomes available through onboarding. No separate written activation is required. The permitted data is limited to records the practice is authorized to share and that are reasonably necessary for the supported services. RemitGuard remains responsible for maintaining the applicable vendor agreements, project controls and operational safeguards. Contract interpretation remains subject to human verification; no guaranteed recovery or automatic payer submission is promised.
Schedule B Contacts and notices
RemitGuard’s responsible contact is RemitGuard, LLC, at info@remitguardhealth.com. The business address is the address stated above. RemitGuard is owner-operated; routine support is checked each business day, excluding United States federal holidays. No continuously staffed support desk or general response-time SLA is promised. This does not extend the incident-reporting deadlines in section 4.
Covered Entity’s notice contacts are those on the setup sheet. Each party will keep its contact details current. Ordinary legal and operational notices may be sent to the designated email address without PHI; the sender must follow up through another established route if delivery fails. A notice is received on acknowledged receipt or confirmed successful delivery without a failure notification. Time-sensitive incident notification must not be delayed while awaiting a complete report or routine support hours.
Do not send patient records, claim identifiers, passwords, sign-in codes or detailed incident evidence through ordinary email. Use the authenticated RemitGuard workspace for supported uploads and downloads. If sensitive incident evidence or an export cannot be exchanged through the workspace, contact support without patient information to arrange a verified, access-controlled delivery channel. Contact replacements must be verified through an established route. Account-recovery contacts are internal operational arrangements and are not parties, signers or designated incident responders under this agreement.
Schedule C Retention return and destruction
The following schedule applies unless applicable law, an express signed variation or a documented preservation requirement controls. A calendar day is intended unless stated otherwise. RemitGuard is not the practice’s medical-record system of record. The practice remains responsible for maintaining its own required records.
- Original remittances and parsing artifacts, saved packet versions, and associated source files: retain while processing or linked follow-up is active, then 90 days after all linked work closes, subject to the dependency rule below.
- Contracts, extracted text, AI results, accepted reviews and schedule versions: retain while active or referenced by retained work, then 90 days after both retirement and closure of the last dependency.
- Unlinked failed or abandoned uploads: retain 30 days after terminal failure or practice-confirmed abandonment, with notice before disposal and a check for downstream records or pending retries.
- Case, comparison and receipt records: retain during service while needed for the agreed reporting and history purpose; apply the termination process below when service ends.
- Application access and change audit events: 12 months. Routine operational diagnostics: 90 days. Ordinary support records without PHI: 12 months after closure. Preserve only the minimum necessary evidence for a valid incident, dispute or legal obligation.
- Required compliance documentation: retain for the applicable legally required period, including six years from creation or last effective date, whichever is later, where the HIPAA Security Rule requires it. This is not a general six-year retention period for all patient files.
- Temporary authorized export or troubleshooting copies: delete within seven days after verified delivery or task completion and no later than 30 days after creation, unless a documented lawful exception requires preservation.
A source record must not be deleted while a retained comparison, case, receipt, review or packet requires it. This dependency can extend the source periods above; it does not authorize indefinite retention after termination. RemitGuard will review unresolved retention exceptions monthly and record the basis and release condition.
On termination, disable routine processing and unnecessary access. Authenticate the practice administrator and provide a 30-day administrative window to request return/export, unless an earlier lawful obligation controls. This window does not extinguish mandatory access or return rights for retained PHI. Nonpayment or suspension of paid application features will not prevent legally required access to or return of PHI; an authenticated protected delivery route must remain available. The export includes retained practice source files in their available original formats and structured practice records in a usable machine-readable format, with the supporting relationships needed to understand them. Deliver through the verified protected channel; ordinary email attachments are not an approved PHI export method. One standard termination export is included without an additional export fee. Any requested custom conversion requires a separately agreed fee and cannot prevent a legally required disclosure.
Delete eligible live PHI no later than 60 days after termination, following return/export and lawful hold checks, unless an earlier applicable obligation controls or return/destruction is infeasible under section 8. Identify every remaining protected copy and the reason it cannot yet be destroyed. Recovery copies follow a rolling retention period of no more than 35 days after capture; residual copies may therefore expire up to 35 days after live deletion. Maintain and verify the configured retention for all recovery systems used to process PHI. Any legally required or infeasible exception remains subject to section 8 and must have a documented review and disposition date.
Recovery copies are unavailable for ordinary processing. Restore procedures must reapply applicable deletion and hold instructions before ordinary use resumes. RemitGuard will verify relevant subcontractor disposition and provide a written disposition record within ten business days after the live-deletion deadline, identifying completed deletion, remaining copies, expected expiration and documented exceptions. Confirm completion when those remaining copies expire or are lawfully destroyed.
These terms do not promise a restoration-time or maximum-data-loss SLA. Any such service commitment must be separately agreed and supported by verified capability.
Signature fields are omitted from this public reference. Agreements are signed electronically during onboarding; your executed copies are emailed to you and saved in your account.