Business Associate Notice (BA Notice) | ClinAdvize
HomeBusiness ConsultingClinAdvize MarketplaceDigital ProductsWebsite Diagnostics & DesignPeptide SystemMedical DirectorBlogFAQContactOur StoryTestimonials
← All store policies

Business Associate Notice (BA Notice)

CLINADVIZE BUSINESS ASSOCIATE TERMS NOTICE

Updated October 6, 2026

This Business Associate Notice (“BA Notice”) describes the HIPAA-related obligations and practices of ClinAdvize, LLC (“ClinAdvize”) when ClinAdvize provides services to a client that is a HIPAA Covered Entity and, in performing those services, creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of that client or is provided access to PHI in connection with the performance of such services.

This BA Notice is incorporated into and forms part of ClinAdvize’s Privacy Policy. However, this BA Notice does not independently create a Business Associate relationship where the services provided by ClinAdvize do not involve the creation, receipt, maintenance, or transmission of PHI on behalf of a Covered Entity or otherwise allow or require ClinAdvize to access PHI in connection with the performance of such services.

For purposes of this BA Notice, the applicable ClinAdvize client is referred to as the “Covered Entity” and ClinAdvize is referred to as the “Business Associate” (each a “Party” and collectively, the “Parties”), but only to the extent the relationship meets the requirements for a Business Associate relationship under HIPAA.

Engagement Process

As part of the process of retaining ClinAdvize, each client is required to electronically acknowledge and accept ClinAdvize’s Terms of Service, Subscription Policy, Privacy Policy, and Refund Policy, which collectively govern the client’s purchase and use of ClinAdvize’s services.

When a client engagement requires ClinAdvize to act as a Business Associate under HIPAA, ClinAdvize will also provide the applicable client or clinic with a separate, stand-alone Business Associate Agreement (“BAA”) for execution by both Parties. The executed BAA will govern the Parties’ respective HIPAA obligations with respect to PHI.

1. DEFINITIONS

Capitalized terms not otherwise defined in this BA Notice shall have the meanings assigned to them under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and the regulations promulgated thereunder, as amended from time to time, including 45 C.F.R. Parts 160 and 164 (collectively, the “HIPAA Rules”). Such terms include Breach, Designated Record Set, Disclosure, Electronic Protected Health Information (“ePHI”), Individual, Minimum Necessary, Protected Health Information (“PHI”), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

“Covered Entity” means a ClinAdvize client that is a covered entity under HIPAA and for which ClinAdvize performs services that may involve the creation, receipt, maintenance, or transmission of PHI on the client’s behalf, or that otherwise involve or require ClinAdvize to access PHI in connection with the performance of such services.

“Business Associate” means ClinAdvize, LLC, a New Hampshire limited liability company, to the extent ClinAdvize, in performing services for a Covered Entity, creates, receives, maintains, or transmits PHI on behalf of the Covered Entity, or is otherwise provided access to PHI in connection with the performance of such services, and the relationship meets the requirements for a Business Associate relationship under the HIPAA Rules.

2. PURPOSE AND SCOPE

This BA Notice is provided in advance of, and applies to the extent ClinAdvize is or will be acting as, a Business Associate of a Covered Entity under the HIPAA Rules. Nothing in this BA Notice independently creates a Business Associate relationship where the services performed by ClinAdvize do not involve the creation, receipt, maintenance, or transmission of PHI on behalf of a Covered Entity or otherwise involve or require ClinAdvize to access PHI in connection with the performance of such services.

Visitors to this website, and clients retaining ClinAdvize, are hereby notified that ClinAdvize, in connection with certain consulting, implementation, vendor coordination, technology, and related services, may create, receive, maintain, transmit, view, or otherwise access PHI as necessary to perform the services for which ClinAdvize has been retained. Such activities may include system setup and configuration, EMR/EHR implementation or migration, workflow and coding guidance, data migration or transfer, laboratory or third-party vendor integration, account setup, troubleshooting, or other consulting or support services.

ClinAdvize will access, Use, or Disclose PHI only to the extent reasonably necessary to perform such services and as otherwise permitted by the applicable BAA and HIPAA Rules.

3. PERMITTED USES AND DISCLOSURES OF PHI

ClinAdvize may Use or Disclose PHI only as necessary to perform the services for which it has been retained, as permitted by the applicable BAA, or as Required by Law. ClinAdvize shall not Use or Disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by the Covered Entity, except as expressly permitted for a Business Associate under the HIPAA Rules.

ClinAdvize may Use PHI for its proper management and administration or to carry out its legal responsibilities. ClinAdvize may Disclose PHI for those purposes only if the Disclosure is Required by Law or ClinAdvize obtains reasonable assurances from the recipient that the PHI will remain confidential, will be Used or further Disclosed only as Required by Law or for the purpose for which it was disclosed, and the recipient will notify ClinAdvize of any breach of confidentiality of which it becomes aware.

ClinAdvize shall limit its Uses, Disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose, to the extent the Minimum Necessary standard applies under the HIPAA Rules.

4. SAFEGUARDS AND SECURITY

ClinAdvize shall use appropriate administrative, physical, and technical safeguards to prevent Use or Disclosure of PHI other than as permitted by applicable law and the applicable BAA. With respect to ePHI, ClinAdvize shall comply with the applicable requirements of the HIPAA Security Rule, including 45 C.F.R. Part 164, Subpart C.

ClinAdvize shall maintain policies, procedures, and reasonable security measures appropriate to the nature of the PHI and ePHI it creates, receives, maintains, transmits, or otherwise accesses in connection with services performed for a Covered Entity.

5. REPORTING OF IMPERMISSIBLE USES, DISCLOSURES, SECURITY INCIDENTS, AND BREACHES

ClinAdvize shall report to the applicable Covered Entity any Use or Disclosure of PHI not permitted by the applicable BAA of which ClinAdvize becomes aware, including any Breach of Unsecured PHI as required by 45 C.F.R. § 164.410 and any Security Incident as required by the HIPAA Rules.

ClinAdvize shall provide notice of a Breach of Unsecured PHI without unreasonable delay and in no event later than sixty (60) calendar days after discovery, or within any shorter period required by applicable law or expressly agreed upon in the applicable BAA. The notice shall include, to the extent known, the information required by 45 C.F.R. § 164.410.

The Parties acknowledge that unsuccessful Security Incidents that do not result in unauthorized access, Use, Disclosure, modification, or destruction of ePHI—including routine pings, scans, unsuccessful login attempts, and similar events—may occur in the ordinary course. The applicable BAA may address notice regarding such routine unsuccessful Security Incidents.

6. SUBCONTRACTORS AND INDEPENDENT CONTRACTORS

ClinAdvize shall ensure that any Subcontractor, including any independent contractor acting as a Subcontractor, that creates, receives, maintains, or transmits PHI on behalf of ClinAdvize agrees in writing to the applicable restrictions, conditions, safeguards, and requirements imposed upon ClinAdvize with respect to such PHI, as required by the HIPAA Rules.

7. ACCESS TO PHI

To the extent ClinAdvize maintains PHI in a Designated Record Set, ClinAdvize shall make such PHI available to the Covered Entity, or as directed by the Covered Entity to an Individual, as necessary for the Covered Entity to satisfy its obligations under 45 C.F.R. § 164.524 and the applicable BAA.

8. AMENDMENT OF PHI

To the extent ClinAdvize maintains PHI in a Designated Record Set, ClinAdvize shall make PHI available for amendment and incorporate amendments as directed or agreed to by the Covered Entity as necessary for the Covered Entity to satisfy 45 C.F.R. § 164.526 and the applicable BAA.

9. ACCOUNTING OF DISCLOSURES

ClinAdvize shall document Disclosures of PHI and maintain information concerning such Disclosures as necessary for a Covered Entity to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528.

10. AVAILABILITY TO THE SECRETARY

ClinAdvize shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by ClinAdvize on behalf of, a Covered Entity available to the Secretary of the U.S. Department of Health and Human Services as required by the HIPAA Rules.

11. COVERED ENTITY OBLIGATIONS

A Covered Entity shall notify ClinAdvize of any limitation in the Covered Entity’s Notice of Privacy Practices to the extent such limitation may affect ClinAdvize’s permitted Use or Disclosure of PHI.

A Covered Entity shall notify ClinAdvize of any change in, or revocation of, an Individual’s authorization or permission to Use or Disclose PHI to the extent such change may affect ClinAdvize’s Use or Disclosure of PHI.

A Covered Entity shall notify ClinAdvize of any restriction on the Use or Disclosure of PHI to which the Covered Entity has agreed under 45 C.F.R. § 164.522 to the extent such restriction may affect ClinAdvize.

A Covered Entity shall not request ClinAdvize to Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if performed by the Covered Entity, except to the extent a Business Associate is expressly permitted to do so.

12. PERFORMANCE OF COVERED ENTITY OBLIGATIONS

To the extent ClinAdvize is expressly retained and authorized to carry out one or more of a Covered Entity’s obligations under the HIPAA Privacy Rule, ClinAdvize shall comply with the requirements of the Privacy Rule applicable to the Covered Entity in the performance of those delegated obligations.

13. TERM AND TERMINATION

The HIPAA-related obligations described in this BA Notice apply for so long as ClinAdvize is acting as a Business Associate of a Covered Entity. The specific effective date, term, termination rights, and obligations of the Parties shall be governed by the applicable stand-alone BAA.

Upon termination of the applicable Business Associate relationship, ClinAdvize shall, if feasible and as required by the applicable BAA and HIPAA Rules, return to the Covered Entity or destroy PHI received from the Covered Entity or created, maintained, or received by ClinAdvize on its behalf.

If return or destruction is infeasible, ClinAdvize shall continue to protect the retained PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible, consistent with the HIPAA Rules and applicable BAA.

14. STATE LAW AND MORE STRINGENT REQUIREMENTS

The Parties shall comply with applicable federal and state privacy, confidentiality, security, and breach-notification laws governing the PHI at issue. To the extent applicable state law provides greater privacy protection or affords an Individual greater rights than HIPAA and is not preempted, the more protective applicable requirement shall control.

15. NO SALE OR UNAUTHORIZED MARKETING OF PHI

ClinAdvize will not sell PHI or receive remuneration in exchange for PHI.

ClinAdvize will not Use or Disclose PHI for ClinAdvize’s own marketing purposes. ClinAdvize may assist a Covered Entity with communications or marketing activities involving PHI only when such services are within the scope of ClinAdvize’s engagement and are permitted by the applicable BAA, the HIPAA Rules, and other applicable law.

16. REGULATORY CHANGES

ClinAdvize may update this BA Notice as reasonably necessary to reflect changes in HIPAA, HITECH, implementing regulations, or other applicable privacy and security laws.

Any executed BAA between ClinAdvize and a Covered Entity shall be amended as reasonably necessary to maintain compliance with applicable law.

17. INTERPRETATION; SURVIVAL

This BA Notice is intended to describe ClinAdvize’s practices and obligations when acting as a Business Associate and shall be interpreted consistently with the HIPAA Rules.

Obligations concerning PHI that are required by HIPAA or an applicable BAA to continue following termination of a Business Associate relationship shall survive termination as required by law or the applicable BAA.

Nothing in this BA Notice is intended to create rights in any third party except as required by applicable law.

18. RELATIONSHIP TO CLINADVIZE TERMS AND STAND-ALONE BAA

This BA Notice is incorporated into ClinAdvize’s Privacy Policy and should be read together with ClinAdvize’s Terms of Service and other applicable website policies.

This BA Notice does not expand the scope of services ClinAdvize has agreed to provide, require ClinAdvize to receive or access PHI when PHI is unnecessary to the services being provided, or authorize either Party to Use or Disclose PHI beyond what is permitted by applicable law.

When ClinAdvize will act as a Business Associate in connection with a client engagement, ClinAdvize will provide the applicable client or clinic with a separate, stand-alone BAA for execution by both Parties. The executed BAA will govern the Parties’ specific obligations concerning PHI and will control over this BA Notice in the event of a conflict concerning HIPAA or PHI.

19. CONTACT

Questions regarding this Business Associate Notice or requests concerning ClinAdvize’s stand-alone Business Associate Agreement may be directed to Support@clinadvize.com.

Effective: 2026-10-06 · Last updated: 2026-10-09

HomeConsultingDigital ProductsVendor MarketplaceWebsite Diagnostics & DesignPeptide SystemMedical DirectorFree PlaybookLicensing RequirementsMed Spa Business PlanOur StoryBlogFAQContactTerms of ServiceSubscription PolicyPrivacy PolicyRefund PolicyBusiness Associate Notice