Business Associate Agreement

This Business Associate Agreement governs how Vitality Medical Marketing Group handles Protected Health Information on behalf of healthcare clients, in compliance with HIPAA, HITECH, and 45 CFR Parts 160 and 164.

Agency: Efferent Media, Inc. d/b/a Vitality Medical Marketing Group  |  Address: 145 East Sunrise Highway, Suite 2, Lindenhurst, NY 11757  |  Phone: 631-919-0009

This Business Associate Agreement (“BAA”) is entered into by and between Efferent Media, Inc. d/b/a Vitality Medical Marketing Group (“Business Associate,” “Agency,” or “Vitality”) and the applicable covered entity client (“Covered Entity” or “Client”) and is incorporated by reference into the applicable Master Services Agreement (“MSA”), Order Form, Statement of Work, subscription agreement, or other agreement between the parties.

This BAA becomes effective as of the effective date of the applicable services agreement between the parties.

For purposes of this BAA, “commercially reasonable efforts” means efforts consistent with industry-standard practices for a digital marketing agency of comparable size and scope, and does not require extraordinary measures, unlimited expenditure, or compliance that is technically or commercially impracticable.

1. Purpose

The purpose of this BAA is to comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and related regulations codified at 45 CFR Parts 160 and 164.

To the extent Business Associate creates, receives, maintains, transmits, stores, or accesses Protected Health Information (“PHI”) on behalf of Covered Entity in connection with the Services, the parties agree to comply with the terms of this BAA.

Business Associate does not provide legal, regulatory, or HIPAA compliance advice unless expressly agreed in writing. Covered Entity is encouraged to consult independent legal counsel regarding its compliance obligations under applicable federal and state law.

2. Definitions

Capitalized terms not otherwise defined herein shall have the meanings assigned under HIPAA and HITECH, including but not limited to:

  • Protected Health Information (“PHI”)
  • Breach
  • Security Incident
  • Business Associate
  • Covered Entity
  • Unsecured PHI
  • Use
  • Disclosure

3. Permitted Uses and Disclosures

Business Associate may use and disclose PHI solely:

  • to perform the Services described in the applicable agreement, including operation and support of the RootLogic platform (CRM, automations, reporting), call tracking and recording where enabled, SMS, voice, email and messaging automations initiated by Client, and analytics, reporting, troubleshooting, and optimization;
  • to operate, maintain, support, and improve the Services;
  • for management and administration purposes;
  • to carry out legal responsibilities;
  • as otherwise permitted or required by HIPAA.

Business Associate shall not use or disclose PHI in a manner that would violate HIPAA if performed directly by Covered Entity, except as otherwise permitted by law.

4. Minimum Necessary Standard

Business Associate shall make commercially reasonable efforts to limit access to PHI to the minimum necessary information required to perform the Services.

Covered Entity acknowledges that certain Services, including the RootLogic platform, call tracking, text messaging, lead management, consultation workflows, reporting systems, and automated follow-up systems, may require limited operational access to identifiable patient information.

5. Safeguards

Business Associate shall implement commercially reasonable administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI, including where applicable:

  • encryption in transit and at rest;
  • role-based access restrictions;
  • password protection policies;
  • multi-factor authentication;
  • workforce confidentiality obligations;
  • audit logging;
  • device access restrictions;
  • secure backup procedures;
  • workforce training and access management procedures.

Business Associate does not warrant or guarantee that any system, software, platform, or communication method is completely immune from cyberattack, unauthorized access, or security incidents.

6. Workforce Members, Contractors, and Subprocessors

Business Associate may utilize employees, contractors, subcontractors, consultants, support personnel, staffing agency personnel, hosting providers, communication providers, software vendors, AI-assisted technologies, transcription providers, analytics providers, and cloud infrastructure providers in connection with the Services.

Staffing agency personnel includes individuals engaged through third-party staffing or contractor placement agencies who perform Services on behalf of Business Associate subject to confidentiality and security obligations consistent with this BAA.

Certain authorized workforce members or subcontractors may be located outside the United States, subject to confidentiality and security obligations consistent with applicable HIPAA requirements. Business Associate will maintain a list of international subprocessors with access to PHI and will make such list available to Covered Entity upon reasonable written request.

Business Associate shall require workforce members and applicable subcontractors with PHI access to maintain reasonable confidentiality and security obligations consistent with applicable HIPAA requirements.

7. Third-Party Platforms, Tracking Technologies, and Advertising Services

Covered Entity acknowledges that certain Services may involve integration with or utilization of third-party advertising, analytics, tracking, communication, or marketing platforms, including but not limited to:

  • Amazon DSP;
  • analytics and tag management providers;
  • Apple Search Ads;
  • call tracking providers, including CallRail, CallTrackingMetrics, Lead Connector, and Twilio;
  • connected television and streaming video platforms;
  • CRM and marketing automation platforms, including GoHighLevel, HubSpot, and Zoho;
  • email marketing platforms, including ActiveCampaign, Klaviyo, and Mailchimp;
  • Google, including Google Ads, Google Analytics, and YouTube;
  • healthcare directory and review platforms, including Healthgrades, PatientPop, RealSelf, Vitals, WebMD, and Zocdoc;
  • Meta, including Facebook and Instagram;
  • Microsoft, including Bing Ads and LinkedIn;
  • native advertising platforms, including Outbrain and Taboola;
  • Nextdoor;
  • Pinterest;
  • programmatic demand-side platforms, including Basis, Google DV360, and The Trade Desk;
  • Reddit;
  • reputation management platforms, including Birdeye and Podium;
  • SMS and messaging infrastructure providers, including Twilio;
  • Snapchat;
  • Spotify;
  • TikTok;
  • workflow automation connectors, including Make and Zapier;
  • and related technologies.

Covered Entity understands and acknowledges that certain third-party advertising or analytics platforms may not offer HIPAA-specific contractual protections or Business Associate Agreements.

Prior to deploying any tracking technology on patient-facing pages, Business Associate shall notify Covered Entity of the specific technology to be deployed and its intended purpose. Covered Entity’s written approval — provided via email, executed Order Form, Statement of Work, or other written authorization — is required before deployment on patient-facing properties. Such written approval constitutes Covered Entity’s direction and authorization for purposes of this Section. Business Associate shall maintain records of such approvals and make them available to Covered Entity upon request.

Covered Entity remains solely responsible for:

  • determining whether deployment of such technologies complies with applicable law, including HHS guidance on tracking technologies;
  • obtaining any necessary patient consents or authorizations;
  • maintaining a consent mechanism on its website or patient-facing properties where required by applicable law or HHS guidance;
  • reviewing and approving advertising campaigns;
  • and ensuring compliance with applicable privacy, consumer protection, and healthcare marketing laws, including applicable state health data privacy laws.

Business Associate does not warrant or guarantee that any third-party advertising or analytics platform is HIPAA compliant.

8. Call Recordings, SMS, and Communications

Covered Entity acknowledges that Services may include:

  • call tracking;
  • call recordings;
  • SMS messaging;
  • voicemail systems;
  • automated communications;
  • consultation workflows;
  • and communication automation systems.

Covered Entity is solely responsible for:

  • obtaining any legally required call recording consents or disclosures;
  • ensuring compliance with federal and state wiretap laws;
  • ensuring compliance with TCPA and related communication laws;
  • obtaining any required patient communication consents;
  • and determining the appropriateness of communications sent through the Services.

Business Associate provides communication systems solely as operational tools and does not provide legal compliance advice regarding communication laws.

9. AI-Assisted Tools and Transcription Services

Business Associate may utilize AI-assisted technologies, automation systems, analytics tools, or transcription providers in connection with the Services.

Business Associate shall use commercially reasonable efforts to minimize unnecessary exposure of PHI when utilizing such technologies. Business Associate shall not permit third-party AI providers to use PHI for model training, fine-tuning, or improvement of third-party AI systems without the express written authorization of Covered Entity.

Covered Entity acknowledges that certain AI or automation providers may not offer HIPAA-specific contractual protections unless expressly stated in writing.

10. Breach Notification

Business Associate shall notify Covered Entity without unreasonable delay following Business Associate’s discovery of a Breach of Unsecured PHI, and in no event later than sixty (60) calendar days after the date of Business Associate’s discovery of such Breach, consistent with 45 CFR § 164.410.

Such notification shall include, to the extent reasonably available at the time of notification:

  • the nature of the Breach;
  • the categories of PHI involved;
  • corrective actions taken;
  • mitigation efforts;
  • and additional information reasonably necessary for Covered Entity’s compliance obligations.

Business Associate may provide initial notification as soon as practicable and supplement with additional details as they become available within the sixty (60) day window.

11. Security Incidents

Business Associate shall report known material Security Incidents involving unauthorized access to PHI.

The parties acknowledge that unsuccessful security incidents occur routinely and shall not constitute reportable incidents unless resulting in unauthorized access, acquisition, use, or disclosure of PHI. Examples include:

  • port scans;
  • pings;
  • failed login attempts;
  • malware attempts blocked by security systems;
  • denial-of-service attacks;
  • and similar routine network activity.

12. Client Responsibilities

Covered Entity remains solely responsible for:

  • HIPAA compliance obligations applicable to Covered Entity;
  • lawful disclosure of PHI;
  • Notice of Privacy Practices obligations;
  • patient authorizations and consents;
  • advertising compliance;
  • call recording disclosures;
  • SMS communication compliance;
  • TCPA compliance;
  • federal and state privacy law compliance, including without limitation applicable state health data privacy laws;
  • staff training, access permissions, and internal HIPAA compliance;
  • what PHI is entered into the RootLogic platform or transmitted through messaging;
  • and written approval of all marketing, automation, tracking, and communication activities prior to deployment.

Covered Entity acknowledges that Business Associate does not provide legal advice regarding healthcare compliance, advertising compliance, or regulatory obligations unless expressly agreed in writing.

13. Access, Export, Return, and Destruction of PHI

During the term of the Services, Covered Entity may export or retrieve Client data using available system tools or through commercially reasonable assistance requests.

Upon termination of the applicable Services Agreement, Business Associate shall use commercially reasonable efforts to provide Covered Entity with an opportunity to export Client data prior to permanent deletion where feasible.

Business Associate may retain archival or backup copies as required by law, backup procedures, audit obligations, security procedures, or legitimate business continuity requirements, subject to continued protection under this BAA.

To the extent required by HIPAA, Business Associate will assist Covered Entity with responding to requests for access to PHI, amendments of PHI, and accounting of disclosures. Such assistance may be subject to reasonable fees if it requires work outside standard Services.

14. Suspension of Services

Business Associate reserves the right to suspend Services for nonpayment or material breach of the applicable Services Agreement. Such suspension may include restriction of:

  • RootLogic platform functionality;
  • campaign management;
  • automations;
  • forms;
  • landing pages;
  • communication systems;
  • or related Services.

Where commercially reasonable, Business Associate shall provide Covered Entity with an opportunity to retrieve or export Client data prior to permanent termination of access.

15. Limitation of Liability

To the fullest extent permitted by law, Business Associate shall not be liable for:

  • acts or omissions of Covered Entity;
  • Client-approved tracking technologies;
  • third-party platform actions or outages;
  • advertising platform policy changes;
  • cyberattacks beyond commercially reasonable safeguards;
  • improper Client configuration or use of the Services;
  • or Covered Entity’s failure to comply with applicable laws.

In no event shall Business Associate’s aggregate liability under this BAA exceed the total fees paid by Covered Entity to Business Associate in the three (3) calendar months immediately preceding the incident giving rise to the claim.

16. Indemnification

Covered Entity agrees to indemnify and hold harmless Business Associate from claims, damages, losses, and expenses arising out of:

  • Covered Entity’s failure to comply with HIPAA or other applicable laws;
  • Covered Entity’s misuse of the RootLogic platform, messaging systems, or call tracking;
  • actions, permissions, or patient communications of Covered Entity’s staff;
  • tracking technologies approved or directed by Covered Entity;
  • and advertising or marketing activities approved by Covered Entity.

This indemnification does not apply to breaches caused by Business Associate’s material violation of this BAA.

17. PHI Minimization Policy

Business Associate structures its workflows and systems to minimize PHI exposure wherever operationally feasible. Specifically:

  • Access to PHI is limited to workforce members who require it to perform their assigned functions in connection with the Services;
  • Workforce members are prohibited from inputting PHI into unauthorized tools, including general-purpose AI systems, consumer AI assistants, or any platform not covered by a written data processing agreement consistent with applicable HIPAA requirements;
  • PHI is not used for advertising targeting, audience building, or campaign optimization beyond what is expressly authorized by Covered Entity in writing;
  • Business Associate will use de-identified or aggregated data for reporting and analytics wherever such data is sufficient to perform the Services;
  • and role-based access controls are implemented to restrict PHI access to the minimum number of authorized personnel.

Business Associate shall provide workforce members with HIPAA awareness training applicable to their role and shall update such training as operationally warranted.

18. Patient Imagery, Testimonials, and Communications

Business Associate may use patient images, before/after photographs, video content, testimonials, reviews, and similar materials (“Patient Content”) solely in connection with marketing Services authorized by Covered Entity.

Covered Entity represents and warrants that:

  • all Patient Content provided to Business Associate or approved by Covered Entity for use in marketing materials is accompanied by valid, signed patient consent covering the intended scope of use, including but not limited to website publication, paid advertising, social media, email, and print;
  • such consent was obtained in compliance with applicable federal and state law, including HIPAA, and any applicable state-specific requirements governing the use of patient likenesses;
  • Covered Entity holds the consent documentation and will make it available upon request in the event of a dispute, regulatory inquiry, or patient complaint;
  • and Covered Entity has the right to authorize Business Associate to use such Patient Content for the purposes described.

Business Associate shall not independently verify the validity or scope of patient consents. Covered Entity bears sole responsibility for ensuring consent adequacy prior to supplying or approving Patient Content for use.

Consent revocation is the sole responsibility of Covered Entity. If a patient revokes consent for use of their image or likeness, Covered Entity shall notify Business Associate in writing within five (5) business days of receiving such revocation. Business Associate shall use commercially reasonable efforts to remove the applicable Patient Content from active marketing materials following receipt of written notice. Business Associate shall not be liable for continued publication of Patient Content on third-party platforms during the period prior to receiving written notice of revocation from Covered Entity.

Business Associate is not responsible for Patient Content that is independently published, shared, or distributed by Covered Entity or Covered Entity’s staff through channels outside Business Associate’s control.

19. Term and Termination

This BAA shall remain in effect for so long as Business Associate maintains PHI on behalf of Covered Entity.

Either party may terminate this BAA upon material breach by the other party if such breach is not cured within thirty (30) days following written notice.

Upon termination, Business Associate will, where feasible, return or destroy PHI, except where retention is required by law, backup procedures, or as otherwise permitted under Section 13.

20. Governing Law

This BAA is governed by the laws of the State of New York, without regard to conflict-of-law principles. Any disputes arising under this BAA shall be venued in Suffolk County, New York.

21. Entire Agreement

This BAA is incorporated into and governed by the applicable MSA and related agreements between the parties.

In the event of conflict between this BAA and the MSA, this BAA shall govern solely with respect to HIPAA-related obligations.

Last updated: May 27, 2026