Skip to main content

Business Associate Agreement (BAA)

Effective April 15, 2026 · SignalEDI Inc.

HIPAA Business Associate terms for healthcare EDI workflows. Review alongside the Trust Center and Security overview — a fully executed BAA is required before transmitting PHI. A BAA is available on any paid plan via the HIPAA/BAA add-on (published rate on /pricing).

On this page

Important:This page describes SignalEDI’s BAA terms for informational purposes. A BAA must be fully executed before transmitting any PHI through SignalEDI. On plan choice, accept Terms + Privacy, then execute the BAA in checkout with the HIPAA/BAA add-on (included on Enterprise; published rate on /pricing). Custom redlines are a one-time legal pass and are not executed until countersigned. Seasonal and Starter can map and test without PHI. See /checkout, /pricing and /marketplace for the published add-on. Executed artifacts are stored on your workspace and retrievable from billing/trust.

1Purpose

This Business Associate Agreement (“BAA”) governs the use, disclosure, and safeguarding of Protected Health Information (“PHI”) when the customer signing this BAA (“Client”) uses SignalEDI Inc. (“Business Associate”) to process healthcare data, including HL7 v2.x, FHIR, and HIPAA-regulated EDI transactions such as 837, 835, 270/271, 276/277, and 999 transaction sets.

2Definitions

Capitalized terms not otherwise defined in this BAA have the meanings assigned to them in the HIPAA Rules. “HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as amended.

  • PHI (Protected Health Information): Individually identifiable health information transmitted or maintained in any form as defined by 45 CFR §160.103.
  • ePHI (Electronic PHI): PHI transmitted or maintained in electronic media.
  • Covered Entity: A health plan, health care clearinghouse, or health care provider that transmits health information electronically, as defined by HIPAA.
  • Business Associate: A person or entity that performs functions or activities on behalf of a Covered Entity involving the use or disclosure of PHI.
  • Client: The Covered Entity or upstream Business Associate entering this BAA. When Client is an upstream Business Associate, SignalEDI acts as its subcontractor, and references to Covered Entity in operational provisions include Client and its upstream Covered Entity as the context requires.
  • Breach: The acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule, as defined by 45 CFR §164.402.
  • Security Incident: The attempted or successful unauthorized access, use, disclosure, modification, or destruction of ePHI, as defined by 45 CFR §164.304.
  • Third-Party Service: Any vendor, supplier, subcontractor, cloud provider, clearinghouse, trading partner, payer, carrier, payment processor, telecommunications provider, or other third party whose systems, networks, or personnel are not owned or operated by Business Associate but may affect transmission, storage, or processing of PHI (including sub-processors engaged by Business Associate).
  • Force Majeure Event: An event beyond a party’s reasonable control, including natural disasters, acts of war or terrorism, civil unrest, pandemic, government order or embargo, widespread internet or power outage, or failure of a Third-Party Service outside that party’s reasonable control.

3Obligations of Business Associate (SignalEDI)

  • Not use or disclose PHI except as permitted by this BAA or as required by law.
  • Use appropriate safeguards and comply with the HIPAA Security Rule at 45 CFR Part 164, Subpart C, with respect to ePHI, including administrative, physical, and technical safeguards. SignalEDI’s current technical safeguards include AES-256 encryption at rest and TLS 1.3 encryption in transit.
  • Report to Covered Entity, without unreasonable delay, any use or disclosure of PHI not permitted by this BAA and any Security Incident of which Business Associate becomes aware. Routine unsuccessful security events such as network pings, port scans, blocked login attempts, and blocked malware are deemed reported through aggregate security reporting or upon reasonable request, unless an event results in unauthorized access, use, disclosure, modification, or destruction of ePHI.
  • Report Breaches of Unsecured PHI to Covered Entity without unreasonable delay and no later than 72 hours after discovery as defined by 45 CFR §164.410. An initial notice may contain the information then available and shall be supplemented without unreasonable delay as additional required information becomes available.
  • Make PHI in a Designated Record Set available in the time and manner reasonably requested by Covered Entity so it can satisfy 45 CFR §164.524; make PHI available for amendment and incorporate amendments as required by 45 CFR §164.526; and provide information needed for an accounting of disclosures under 45 CFR §164.528.
  • To the extent Business Associate carries out an obligation of Covered Entity under the HIPAA Privacy Rule, comply with the requirements of 45 CFR Part 164, Subpart E that apply to Covered Entity in performing that obligation.
  • Make internal practices, books, records, and compliance reports relating to PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules.
  • Return or destroy PHI upon termination, per Client’s election and Section 7.
  • Ensure each subcontractor that creates, receives, maintains, or transmits PHI on Business Associate’s behalf agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to that PHI, including compliance with the HIPAA Security Rule for ePHI.
  • Do not disclose PHI to an external AI provider unless that provider is authorized as a HIPAA-compliant subcontractor under this BAA and has executed the required written business associate terms. Business Associate may instead de-identify PHI in accordance with 45 CFR §164.514(a)-(c) before external processing. “Safe Harbor-style” or partial redaction alone is not treated as de-identification. Healthcare transaction sets require an executed BAA on file before upload.
  • Retain policies, procedures, required actions, assessments, and other documentation required by the HIPAA Rules for at least six years from creation or the date last in effect, whichever is later. Security and access audit records are retained under documented retention policies and applicable law.
  • Business Associate is not responsible for the acts, omissions, outages, or security failures of Third-Party Services except to the extent Business Associate failed to meet its vendor-management obligations under this BAA and applicable law.

4Obligations of Client

  • Obtain necessary consents and authorizations before transmitting PHI to SignalEDI.
  • Not request SignalEDI to use or disclose PHI in any manner that would violate HIPAA.
  • Notify SignalEDI of any restrictions on the use or disclosure of PHI.
  • Notify SignalEDI of limitations in Covered Entity’s Notice of Privacy Practices, and of changes in or revocation of an individual’s permission, to the extent either may affect Business Associate’s use or disclosure of PHI.
  • Ensure the minimum necessary standard is applied when transmitting PHI.
  • Apply minimum-necessary PHI in all uploads and avoid placing PHI in unstructured fields or optional free-text inputs when structured EDI, HL7, or FHIR transaction paths are available.
  • Maintain connectivity, credentials, and compliance with trading partners, payers, clearinghouses, suppliers, and other Third-Party Services outside Business Associate’s platform; Business Associate is not responsible for partner-side rejections, delays, or outages beyond the SignalEDI service boundary.

5Permitted Uses & Disclosures

Business Associate may use and disclose PHI as necessary to perform services on behalf of the Covered Entity, including:

  • Uses and disclosures necessary to perform the services described in the applicable service agreement, including treatment, payment, and healthcare operations as permitted by HIPAA.
  • Data aggregation services related to the healthcare operations of the Covered Entity.
  • De-identify PHI in accordance with 45 CFR §164.514(a)-(c), and use or disclose the resulting de-identified information for analytics and service improvement.
  • Management and administration of the Business Associate, provided disclosures are required by law or Business Associate obtains reasonable assurances of confidentiality.
  • Make uses, disclosures, and requests for PHI consistent with Covered Entity’s communicated minimum-necessary policies and the HIPAA minimum-necessary standard.

6Breach Notification

  • Business Associate shall notify Covered Entity without unreasonable delay and no later than 72 hours after discovery of a Breach of Unsecured PHI, as discovery is defined by 45 CFR §164.410.
  • To the extent known, notification shall identify each affected individual or provide the information reasonably needed for Covered Entity to identify them, and include the nature and extent of the Breach, dates, types of PHI involved, investigative and mitigation steps, corrective actions, and a contact for follow-up. Business Associate shall supplement the notice without unreasonable delay as additional information becomes available.
  • Business Associate shall cooperate in good faith with the Covered Entity’s breach response and notification obligations.
  • Breach response costs: Each party bears its own internal response costs. Business Associate bears reasonable third-party forensic, containment, and notification-support costs directly attributable to a Breach caused by Business Associate’s breach of this BAA or failure of systems within Business Associate’s control. Covered Entity bears regulatory notification costs owed by Covered Entity under HIPAA (including individual, HHS, and media notices where applicable). Costs arising primarily from a Third-Party Service or Force Majeure Event are allocated under Section 9. Nothing in this Section limits either party’s obligations under applicable law.

7Term & Termination

  • This BAA is effective upon execution and remains in effect until terminated or until the underlying service agreement expires.
  • Covered Entity may terminate this BAA and the affected services if it determines Business Associate has violated a material term and Business Associate does not cure the violation within 30 days after notice. Covered Entity may terminate immediately when cure is not possible.
  • Upon termination for any reason, Business Associate shall, at Covered Entity’s election, return or destroy all PHI received from Covered Entity or created, maintained, or received on its behalf, and shall retain no copies except as stated below. Covered Entity bears reasonable costs of custom formatting, export, or transfer beyond standard platform export capabilities.
  • If return or destruction is not feasible, protections shall extend to retained PHI and further uses and disclosures shall be limited to purposes that make return or destruction infeasible.
  • Business Associate may retain archival backups in the ordinary course of business, subject to the protections of this BAA, where return or destruction is infeasible or until backups expire per applicable retention policies.
  • The return, destruction, retained-PHI safeguards, and use-and-disclosure restrictions in this Section survive termination of this BAA.

8Restoration Commitment

Business Associate commits to use commercially reasonable efforts to restore critical systems within Business Associate’s control that affect the availability of ePHI following a disruption. This includes restoration of access to electronic PHI, re-establishment of secure processing capabilities, and verification of data integrity post-restoration.

Restoration timelines do not apply to outages, delays, or data unavailability caused by Third-Party Services, trading partners, payers, suppliers, Force Majeure Events, scheduled maintenance (with advance notice), issues caused by Covered Entity actions or configurations, or third-party infrastructure failures (including cloud hosting, database, CDN, email, payment, and telecommunications providers). Incident response targets for paid plans are described in the Service Level Agreement.

9Third-Party Dependencies & Force Majeure

SignalEDI operates as part of a broader healthcare and cloud ecosystem. Many failures that affect PHI processing originate outside Business Associate’s direct control.

  • Third-Party Services. Business Associate is not liable for delay, failure, unavailability, data loss, security incident, or Breach arising from a Third-Party Service (including sub-processors, hosting providers, AI vendors, clearinghouses, VANs, payers, trading partners, suppliers, carriers, or internet/telecom providers) except to the extent caused by Business Associate’s failure to meet its subcontractor and vendor-management obligations under this BAA and applicable law.
  • Trading partner and payer connectivity. Covered Entity is responsible for partner enrollment, certification, credentials, acknowledgments, and compliance on systems outside the SignalEDI platform. Business Associate does not guarantee partner acceptance, turnaround times, or uptime of external networks.
  • Force Majeure. Neither party is liable for failure or delay in contractual performance to the extent caused by a Force Majeure Event, provided the affected party uses commercially reasonable efforts to resume performance and notifies the other party without undue delay. This provision does not excuse or extend any duty that cannot lawfully be limited, including mandatory HIPAA reporting, safeguarding, or retained-PHI obligations.
  • Cooperation. Upon a Third-Party Service failure affecting PHI, the parties will cooperate in good faith to reroute, restore, or contain impact. Business Associate will use commercially reasonable efforts to work with its sub-processors and vendors to mitigate harm.

10Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:

  • Neither party shall be liable to the other for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, revenue, data, business opportunities, goodwill, or anticipated savings, arising out of or relating to this BAA or PHI processed under it, regardless of the theory of liability, even if advised of the possibility of such damages.
  • Business Associate’s total aggregate liability for direct damages arising out of or relating to this BAA shall not exceed the total fees actually paid by Covered Entity to Business Associate during the twelve (12) months immediately preceding the event giving rise to the claim.
  • Business Associate shall have no liability for claims arising primarily from Third-Party Services, trading partner systems, payer networks, supplier or carrier failures, Covered Entity misconfiguration, or Force Majeure Events, except to the extent directly caused by Business Associate’s breach of this BAA or willful misconduct.
  • Non-BAA claims relating to the Service remain subject to the Terms of Service. In the event of conflict regarding PHI-specific obligations, this BAA governs PHI handling; regarding monetary caps on PHI-related direct damages, this Section 10 governs to the extent permitted by law.
  • Nothing in this BAA limits either party’s regulatory, reporting, or compliance obligations under HIPAA, HITECH, or other applicable law where such limitations are prohibited.

11Regulatory Construction

  • References to the HIPAA Rules mean those provisions as in effect or as amended.
  • The parties shall amend this BAA as necessary to comply with changes in the HIPAA Rules or other applicable law.
  • Any ambiguity in this BAA shall be interpreted to permit compliance with the HIPAA Rules.
  • This BAA does not by itself authorize the receipt, use, or disclosure of substance use disorder patient records governed by 42 CFR Part 2. The parties must confirm applicable consent, notice, redisclosure, and legal-proceeding restrictions before such records are processed.

12How to Execute

Execute the BAA in-flow when you choose a paid plan and indicate you will send PHI: accept Terms of Service and Privacy Policy, attach the HIPAA/BAA add-on (included on Enterprise; published rate on /pricing), and complete BAA execution at /checkout. Signed artifacts (body + SHA-256) are stored on your tenant and retrievable from billing/trust via /api/legal/agreements.

Custom BAA redlines remain a one-time legal pass and are not executed until countersigned. For redline review, contact compliance@signaledi.com. A BAA must be fully executed — and the HIPAA/BAA add-on active — before transmitting Protected Health Information through SignalEDI.

SignalEDI’s Business Associate signature appears below. The Covered Entity completes the counterpart block via in-checkout execution (standard) or a countersigned PDF (custom redline), and retains the executed artifact for compliance records.

Business Associate

SignalEDI Inc.

Chris Rosecrans signature, SignalEDI Inc.

Chris Rosecrans

Founder and CEO, SignalEDI Inc.

Date: April 15, 2026

Client / Covered Entity or Business Associate

[Legal entity name]

Signature: _______________________________

Name: _______________________________

Title: _______________________________

Date: _______________________________

© 2026 SignalEDI Inc. All rights reserved.

© 2026 SignalEDI Inc. All rights reserved.