DrinCloud

Home → Business Associate Agreement

Business Associate Agreement

Last updated: August 29, 2026

This is the model Business Associate Agreement ("BAA") that Massive Bionics LLC signs with every DrinCloud customer. It is included in every plan at no extra cost and is executed electronically when you subscribe. We publish it here so you can read it, and have your counsel read it, before you sign anything.

1. Parties and purpose

This Agreement is entered into between the subscribing practice (the "Covered Entity") and Massive Bionics LLC (the "Business Associate"), and governs the Protected Health Information ("PHI") that the Covered Entity stores in DrinCloud. It is intended to satisfy 45 CFR 164.504(e) of the HIPAA Privacy and Security Rules.

2. Permitted uses and disclosures

Business Associate may use and disclose PHI only to provide, maintain and support the DrinCloud service as described in the Terms of Service, as required by law, or as expressly authorized in writing by Covered Entity. Business Associate does not sell PHI, does not use it for advertising and does not use it to train artificial intelligence models.

3. Safeguards

Business Associate maintains administrative, physical and technical safeguards that comply with the HIPAA Security Rule: encryption of PHI in transit and at rest, role-based access control, an audit log of every access and change, daily backups in two geographic locations, and hosting on Microsoft Azure.

4. Breach notification

Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, and any Breach of Unsecured PHI, without unreasonable delay and in no case later than ten (10) business days after discovery, including the information Covered Entity needs to meet its own notification obligations under 45 CFR 164.404.

5. Subcontractors

Business Associate ensures that any subcontractor that creates, receives, maintains or transmits PHI on its behalf (such as cloud hosting) agrees in writing to restrictions and conditions at least as protective as those in this Agreement.

6. Individual rights

Business Associate will make PHI available to Covered Entity as needed to satisfy an individual's right of access under 45 CFR 164.524, incorporate amendments under 45 CFR 164.526, and provide the information required for an accounting of disclosures under 45 CFR 164.528. In practice, the export tools built into DrinCloud let Covered Entity handle most of these requests directly.

7. Minimum necessary and government access

Business Associate limits its use, disclosure and requests of PHI to the minimum necessary, and will make its internal practices, books and records relating to PHI available to the Secretary of Health and Human Services for purposes of determining compliance.

8. Term, termination and return of data

This Agreement remains in effect for as long as the subscription. Covered Entity may terminate the subscription if Business Associate materially breaches this Agreement and does not cure the breach within thirty (30) days of written notice. Upon termination, Business Associate will make all PHI available for export at no cost during the retention period and will then destroy it, or, where return or destruction is infeasible, will extend the protections of this Agreement to that PHI for as long as it is retained.

9. Miscellaneous

Nothing in this Agreement creates rights in third parties. Any ambiguity shall be interpreted to permit compliance with HIPAA. This Agreement is governed by the laws of the State of Florida, United States.

This is the published model of the agreement. The signed copy you receive at subscription is the binding version. This page is not legal advice; have your own counsel review it before you sign.

Any of this unclear?

Ask us before you sign anything. Explaining it twice costs us nothing.