Legal

Business Associate Agreement

Version 2026-09-15.v1 — executes upon acceptance of the Terms of Service

Su Information Technologies LLC, doing business as Suithera

This Business Associate Agreement (“Agreement”) is entered into between Su Information Technologies LLC, a Colorado limited liability company (d/b/a “Suithera”) (“Business Associate” or “Suithera”) and the covered-entity customer accepting these terms (“Covered Entity”), effective on the date Covered Entity accepts Suithera’s Terms of Service (“Effective Date”). It governs Business Associate’s Use and Disclosure of Protected Health Information on Covered Entity’s behalf.

1. Definitions

Terms used but not defined here have the meaning in the HIPAA Rules (45 CFR Parts 160 and 164). “PHI” means Protected Health Information created, received, maintained, or transmitted by Business Associate for Covered Entity. “HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules.

2. Permitted uses and disclosures of PHI

Business Associate may Use or Disclose PHI only:

  • to perform the services in the Terms of Service (clinical documentation, scheduling, billing, telehealth, and related practice operations);
  • as Required By Law;
  • for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any such Disclosure is Required By Law, or Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially and used or further disclosed only as required by law or for the purposes for which it was disclosed to that recipient, and that the recipient will notify Business Associate of any instance of which it is aware in which the confidentiality of the information has been breached;
  • to provide Data Aggregation services relating to Covered Entity’s health care operations, if applicable.

Business Associate will not Use or Disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted above for management, administration, and data aggregation. Business Associate will request, Use, and Disclose only the minimum necessary PHI to accomplish the intended purpose, consistent with 45 CFR 164.502(b).

2.1 AI and de-identified data. Business Associate will not Use PHI to train, fine-tune, or improve any machine-learning model. Clinical AI processing occurs only through subcontractors covered by a business associate agreement, and Business Associate will not transmit PHI to any subcontractor lacking one. Business Associate may create de-identified data from PHI in accordance with 45 CFR 164.514(a)–(b) and use it for its lawful business purposes (including service improvement and aggregate benchmarking); Business Associate will not attempt to re-identify de-identified data and will prohibit its recipients from doing so.

3. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with the Security Rule (Subpart C of 45 CFR Part 164), to prevent Use or Disclosure of PHI other than as provided by this Agreement. This includes encryption of PHI at rest and in transit, access controls, and an append-only audit log of PHI access.

4. Reporting

Business Associate will report to Covered Entity:

  • any Use or Disclosure of PHI not provided for by this Agreement of which it becomes aware;
  • any Security Incident of which it becomes aware; and
  • any Breach of Unsecured PHI as required by 45 CFR 164.410, without unreasonable delay and no later than five (5) business days after Discovery, or sooner where applicable law requires earlier notice to Covered Entity, including (to the extent known) the identification of affected Individuals and the information described in 45 CFR 164.410(c).

4.1 Unsuccessful security incidents. The parties acknowledge that Business Associate’s systems are subject to routine unsuccessful attempts at unauthorized access — such as pings, port scans, denial-of-service attempts without PHI access, failed log-in attempts, and malware blocked at the perimeter — that do not result in unauthorized access to, or acquisition, Use, or Disclosure of, PHI. Such Unsuccessful Security Incidents are hereby deemed reported by this Section, without further individual notice.

4.2 Breach notification roles and costs. As between the parties, Covered Entity is responsible for determining whether notification of Individuals, HHS, or the media is required under 45 CFR 164.404–164.408 and for making such notifications. Business Associate will provide the information reasonably required for Covered Entity to meet those obligations and will reasonably cooperate. Where the Breach arises from Business Associate’s (or its subcontractors’) acts or omissions, Business Associate will reimburse Covered Entity’s reasonable, documented costs of legally required notifications and industry-standard credit monitoring, subject to and as part of Section 10.3(a).

5. Subcontractors (flow-down)

In accordance with 45 CFR 164.502(e)(1)(ii), 164.308(b)(2), and 164.314(a)(2)(i)(B), Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing, through a contract or other arrangement that itself complies with 45 CFR 164.314(a) and 164.504(e), to the same restrictions, conditions, and requirements that apply to Business Associate. A current list of subprocessors is maintained in the Privacy Policy’s subprocessors section.

5.1 Subcontractor non-compliance. Consistent with 45 CFR 164.504(e)(1)(iii), if Business Associate knows of a pattern of activity or practice of a subcontractor that constitutes a material breach or violation of the subcontractor’s obligations with respect to PHI, Business Associate will take reasonable steps to cure the breach or end the violation and, if those steps are unsuccessful, will terminate the contract or arrangement with that subcontractor if feasible.

6. Individual rights

Business Associate will:

  • make PHI in a Designated Record Set available to Covered Entity (or the Individual) to satisfy access rights under 45 CFR 164.524, and, as required by 45 CFR 164.502(a)(4)(ii), disclose PHI to Covered Entity, the Individual, or the Individual’s designee as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.524(c)(2)(ii) and (c)(3)(ii) with respect to an Individual’s request for an electronic copy of PHI;
  • make PHI available for amendment and incorporate amendments per 45 CFR 164.526;
  • maintain and make available the information required for an accounting of disclosures per 45 CFR 164.528.

Timeframe: within 15 business days of a written request.

7. Availability to HHS

Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of HHS for determining Covered Entity’s compliance with the HIPAA Rules.

8. Return or destruction at termination

On termination, Business Associate will, if feasible, return or destroy all PHI and retain no copies. Where return or destruction is infeasible, Business Associate will extend the protections of this Agreement to such PHI and limit further Uses and Disclosures to the purposes that make return or destruction infeasible, for as long as it retains the PHI. Business Associate will provide a copy or export of Covered Entity’s records in a usable, machine-readable format before destruction; for at least ninety (90) days after termination, Covered Entity retains read-only access to export its records (per-client and practice-wide export), after which destruction proceeds subject to legal holds and the retention periods required by law.

9. Term and termination

(a) Term — effective on the Effective Date and continuing until the later of (i) termination of the Terms of Service and (ii) the date all PHI is returned or destroyed (or, where return/destruction is infeasible, for as long as Business Associate retains PHI under Section 8).

(b) Termination for cause — if Covered Entity determines that Business Associate has violated a material term of this Agreement, Covered Entity may terminate this Agreement, and may (but need not) first provide Business Associate an opportunity to cure. Because the services under the Terms of Service cannot be performed without this Agreement in effect, termination of this Agreement under this paragraph also terminates the Terms of Service, and Section 8 then applies.

10. Liability, indemnification, and injunctive relief

10.1 Limitation of liability. Except as provided in Section 10.2, and notwithstanding anything to the contrary in this Agreement or the underlying services agreement, each party’s total cumulative liability to the other arising out of or relating to this Agreement (in contract, tort including negligence, strict liability, or otherwise) shall not exceed the Fee Measure. The “Fee Measure” means the total fees paid or payable by Covered Entity for the twelve (12) months immediately preceding the event giving rise to the claim; where this Agreement has been in effect for less than twelve (12) months, the Fee Measure is instead the fees that would be payable over twelve (12) months at the rate in effect when the event occurred, so that the limit does not turn on how recently Covered Entity subscribed. Except as provided in Section 10.2, neither party shall be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or lost profits or revenue, even if advised of the possibility.

10.2 Exclusions from the limitation (carve-outs). Section 10.1 shall not apply to, and shall not limit, liability arising from: (a) Business Associate’s unauthorized use or disclosure of PHI, or any Breach of Unsecured PHI or Security Incident, caused by Business Associate or its subcontractors; (b) a party’s breach of confidentiality obligations; (c) indemnification obligations under Section 10.3; (d) gross negligence, willful misconduct, or fraud; and (e) violation of applicable law (HIPAA, HITECH, or state law). Notwithstanding the foregoing, liability arising under Sections 10.2(a)–(c) shall not exceed three (3) times the Fee Measure. Liability under Sections 10.2(d)–(e) remains uncapped.

10.3 Mutual indemnification. (a) Business Associate shall defend, indemnify, and hold harmless Covered Entity and its owners, employees, and agents from any third-party claims, actions, liabilities, losses, damages, fines, civil monetary penalties, regulatory assessments, settlements, and reasonable costs and expenses (including reasonable attorneys’ fees and the reasonable costs of Breach notification, credit monitoring, and regulatory response) (“Losses”) to the extent arising out of (i) its breach of this Agreement, (ii) its negligence, gross negligence, or willful misconduct, or (iii) any Breach of Unsecured PHI or Security Incident caused by Business Associate or its subcontractors. (b) Covered Entity shall defend, indemnify, and hold harmless Business Associate and its officers, employees, and agents from any Losses to the extent arising out of (i) its breach of this Agreement, (ii) its negligence, gross negligence, or willful misconduct, or (iii) its instructions, uses, or disclosures of PHI not permitted by HIPAA or that Business Associate implemented in good-faith reliance on Covered Entity’s written direction. (c) The indemnified party shall promptly notify the indemnifying party (failure to give prompt notice relieves the indemnifying party only to the extent actually prejudiced); the indemnifying party controls defense and settlement but may not settle in a manner imposing non-indemnified liability or an admission of fault on the indemnified party without prior written consent (not unreasonably withheld). This Section 10.3 survives termination.

10.4 Injunctive relief. Each party acknowledges that any actual or threatened unauthorized use or disclosure of PHI, or breach of the confidentiality or data-security obligations, may cause irreparable harm for which monetary damages are inadequate. The non-breaching party may seek injunctive or other equitable relief to prevent or restrain such breach, without posting a bond or proving actual damages, in any court of competent jurisdiction, in addition to (not in lieu of) any other cumulative remedies at law or equity.

11. State law and 42 CFR Part 2 (substance-use-disorder records)

11.1 Colorado mental-health confidentiality. Business Associate acknowledges that Covered Entity’s records may be protected not only by HIPAA but by Colorado law, including the confidentiality provisions governing mental-health services and records (C.R.S. § 12-245-220), the record-confidentiality provisions of the Colorado behavioral-health care-and-treatment statutes (C.R.S. § 27-65-123), and the general medical-records confidentiality statutes (C.R.S. § 25-1-1201 et seq.). To the extent any such provision affords the Individual greater protection, or imposes stricter conditions on Use or Disclosure, than the HIPAA Rules, Business Associate will comply with the more protective provision when acting on Covered Entity’s behalf. Business Associate will not Use or Disclose such records except as directed by Covered Entity consistent with these laws or as Required By Law.

11.2 Colorado Privacy Act. To the extent the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) and its rules apply to any data that is not otherwise exempt as PHI or as records governed by Section 11.1, Business Associate will process such data only as a processor acting on Covered Entity’s documented instructions and will provide reasonable assistance with data-subject requests and security obligations.

11.3 42 CFR Part 2 (conditional). (a) The federal confidentiality rules at 42 CFR Part 2 apply to records of a “program” as defined in 42 CFR 2.11 and 2.12, and continue to apply to those records in the hands of a lawful holder that receives them from a program. Covered Entity represents at account creation whether it is such a program, and will inform Business Associate promptly if it later becomes one. (b) If Covered Entity is not a Part 2 program, this Section imposes no Part 2 program obligations on either party, and the parties rely on that representation. (c) If Covered Entity is a Part 2 program, it must not use the service until Suithera has confirmed Part 2 program support in writing; Part 2 program support is not yet available at self-serve signup. (d) If Covered Entity, not being a Part 2 program, receives Part 2 records from a program under a patient consent, Covered Entity may mark those records as Part 2-protected in the service. For records so marked, Business Associate will apply the service’s Part 2 protections — per-client protection, a recorded Part 2 disclosure consent before any insurance claim the service prepares for that client, and exclusion from AI processing — and will not disclose them except as directed by Covered Entity or as Required By Law. Covered Entity remains responsible for its own obligations as a lawful holder, including marking such records when received, the notice that must accompany a disclosure (42 CFR 2.32), and the limits on redisclosure and use (42 CFR 2.33).

12. Miscellaneous

  • Regulatory references are to the section as in effect or amended.
  • Amendment — the parties will amend this Agreement as needed to comply with the HIPAA Rules; Business Associate may update this Agreement by posting a new version and requiring re-acceptance for material changes.
  • Interpretation — ambiguity is resolved to permit compliance with the HIPAA Rules.
  • No third-party beneficiaries.
  • Governing law — Colorado, except where preempted by federal law.
  • Order of precedence — for any conflict concerning PHI, this Agreement controls over the Terms of Service and any other agreement between the parties.
  • Notices — notices under this Agreement are given in writing: to Covered Entity, at the account owner’s email address on file (deemed given when sent); to Business Associate, at support@suithera.com and Su Information Technologies LLC, 3605 Table Mesa Dr. T332, Boulder, CO 80305.
  • Assignment — Covered Entity may not assign this Agreement without Business Associate’s consent (not unreasonably withheld). Business Associate may assign this Agreement in connection with a merger, acquisition, or sale of substantially all assets, provided the assignee assumes its obligations and Covered Entity is notified.
  • Non-retaliation — consistent with 45 CFR 160.316, Business Associate will not threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action against any Individual or other person for filing a complaint with the Secretary of HHS, testifying or assisting in an investigation, compliance review, proceeding, or hearing, or opposing any act or practice made unlawful by the HIPAA Rules.
  • Survival — Sections 4, 8, 10, 11, 12, and 13 survive termination to the extent of retained PHI or accrued claims.

13. Covered Entity obligations carried out by Business Associate

To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164 — including, without limitation, generating Covered Entity’s Notice of Privacy Practices, responding to an Individual’s request for access to or a copy of PHI, and producing a Good Faith Estimate — Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation.

Acceptance

By accepting Suithera’s Terms of Service at account creation, Covered Entity executes this Agreement. Suithera records the acceptance (version, timestamp, user, IP) in its immutable audit log. This page is the permanent, viewable copy of the agreement; the version accepted by your account is shown in Settings.