HIPAA

Business Associate Agreement

The standard HIPAA Business Associate Agreement offered by SessionSteps LLC to eligible healthcare customers.

Last updated October 5, 2026

Important: acceptance

This BAA becomes binding only when an authorized customer accepts it through SessionSteps' contracting or account process, or both parties sign it. Publishing this page alone does not execute a BAA. “Covered Entity” means the accepting customer and “Business Associate” means SessionSteps LLC.

1. Definitions

Capitalized terms not defined here have the meanings assigned by HIPAA, including the Privacy, Security, Breach Notification, and Enforcement Rules. “PHI” includes electronic PHI received, created, maintained, or transmitted by Business Associate for Covered Entity. “Services Agreement” means the Terms, order, or other agreement governing SessionSteps.

2. Permitted uses and disclosures

Business Associate may use or disclose PHI only to perform the services, as permitted by this BAA, or as Required by Law. Business Associate may use PHI for proper management and administration or legal responsibilities only where HIPAA permits and appropriate assurances are obtained. Business Associate will not sell PHI, use it for advertising, or use it in a manner that would violate HIPAA if done by Covered Entity.

3. Safeguards

Business Associate will implement appropriate administrative, physical, and technical safeguards and comply with applicable Security Rule requirements to protect the confidentiality, integrity, and availability of electronic PHI. Business Associate will mitigate harmful effects of an impermissible use or disclosure to the extent practicable.

4. Reporting

Business Associate will report to Covered Entity any use or disclosure not permitted by this BAA, Security Incident, or Breach of Unsecured PHI of which it becomes aware, without unreasonable delay and no later than the time required by applicable law. Reports will include available information reasonably needed for Covered Entity's obligations. Routine unsuccessful security events that do not result in unauthorized access are reported in the aggregate unless a material event requires specific notice.

5. Subcontractors

Business Associate will require subcontractors that create, receive, maintain, or transmit PHI on its behalf to agree to restrictions and safeguards at least as protective as those applicable to Business Associate. Current providers are described in the public Subprocessor List.

6. Individual rights and government access

To the extent applicable to the services, Business Associate will make PHI available to Covered Entity for access, amendment, and accounting-of-disclosures obligations within a reasonable time; maintain information needed for those obligations; and make internal practices, books, and records relating to PHI available to the U.S. Department of Health and Human Services as required by law.

7. Covered Entity responsibilities

Covered Entity will notify Business Associate of limitations in privacy notices, authorization changes, and agreed restrictions that affect use of PHI. Covered Entity will not ask Business Associate to use or disclose PHI in a way that would violate HIPAA if done by Covered Entity, and will configure access, users, integrations, and content appropriately.

8. Minimum necessary

Each party will limit uses, disclosures, and requests for PHI to the minimum necessary as required by HIPAA and will use limited data sets where appropriate and practicable.

9. Term, termination, and return or destruction

This BAA begins when validly accepted and remains in effect while Business Associate maintains PHI for Covered Entity. A material breach not cured within a reasonable period is grounds for termination. At termination, Business Associate will return or destroy PHI when feasible. If infeasible, it will extend this BAA's protections and limit further use or disclosure to the reason return or destruction is infeasible.

10. Interpretation and conflict

This BAA will be interpreted to permit compliance with HIPAA. If it conflicts with the Services Agreement on PHI, this BAA controls. Regulatory references include later amendments. Obligations intended to survive termination will survive.

11. Contacts

Legal and BAA questions: legal@sessionsteps.com. Security incident reports: security@sessionsteps.com. Do not include PHI in unencrypted email.