Template version: 2026-10-04 · For questions: legal@rivon.health

Business Associate Agreement

This Business Associate Agreement ("Agreement") supplements and is made part of the underlying Subscription Agreement ("Underlying Agreement") between Rivon Health, Inc. ("Business Associate," "Rivon," or "we") and the customer entity identified in the Underlying Agreement ("Covered Entity," "you").

This Agreement is required by, and governed by, the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and the regulations promulgated thereunder at 45 CFR Parts 160, 162, and 164 (collectively, "HIPAA Rules").


1. Definitions

Capitalized terms used but not defined in this Agreement have the meanings set forth in the HIPAA Rules. Specifically:

  • "Breach" has the meaning given in 45 CFR § 164.402.
  • "Designated Record Set" has the meaning given in 45 CFR § 164.501.
  • "Electronic Protected Health Information" or "ePHI" has the meaning given in 45 CFR § 160.103.
  • "Individual" has the meaning given in 45 CFR § 160.103 and includes a person who qualifies as a personal representative under 45 CFR § 164.502(g).
  • "Protected Health Information" or "PHI" has the meaning given in 45 CFR § 160.103, limited to PHI created, received, maintained, or transmitted by Business Associate from or on behalf of Covered Entity.
  • "Required by Law" has the meaning given in 45 CFR § 164.103.
  • "Security Incident" has the meaning given in 45 CFR § 164.304.
  • "Subcontractor" has the meaning given in 45 CFR § 160.103.
  • "Unsecured PHI" has the meaning given in 45 CFR § 164.402.

2. Permitted Uses and Disclosures of PHI

2.1 Service Performance. Business Associate may use and disclose PHI as necessary to perform the services set forth in the Underlying Agreement.

2.2 Management and Administration. Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that any disclosure is Required by Law or made pursuant to the protections in Section 2.3.

2.3 Disclosures. Business Associate may disclose PHI for its own management, administration, or legal responsibilities only if (a) the disclosure is Required by Law, or (b) Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and the recipient notifies Business Associate of any breach of confidentiality.

2.4 Data Aggregation. Business Associate may use PHI to provide Data Aggregation services as defined in 45 CFR § 164.501 and as permitted by 45 CFR § 164.504(e)(2)(i)(B).

2.5 De-Identified Data. Business Associate may de-identify PHI in accordance with 45 CFR § 164.514(a)–(c) and use such de-identified data for any lawful purpose.

2.6 Minimum Necessary. Business Associate shall make reasonable efforts to use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose, consistent with 45 CFR § 164.502(b).

3. Obligations of Business Associate

3.1 Safeguards. Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI in accordance with the Security Rule (45 CFR Part 164, Subpart C). A detailed control inventory is published at https://app.rivon.health/security and includes, without limitation:

  • AES-256 encryption of sensitive fields at rest and TLS 1.2+ in transit
  • Multi-tenant isolation enforced at both the application and database (PostgreSQL Row-Level Security) layers
  • Role-based access control with least-privilege defaults
  • Tamper-evident audit logging on every data mutation
  • Multi-factor authentication available via SSO
  • Soft-delete with retention enabling restoration of accidentally deleted records
  • Continuous database vulnerability scanning

3.2 Reporting. Business Associate shall report to Covered Entity:

(a) Any use or disclosure of PHI not permitted by this Agreement of which it becomes aware, without unreasonable delay and in no event later than ten (10) business days after discovery.

(b) Any Security Incident involving ePHI of which it becomes aware. The parties acknowledge and agree that this Section constitutes notice of routine, low-impact unsuccessful Security Incidents (such as pings, port scans, denied access attempts) for which no further notice is required.

(c) Any Breach of Unsecured PHI as required by 45 CFR § 164.410, without unreasonable delay and in no event later than sixty (60) calendar days after discovery. Notification will include the identification of each Individual whose Unsecured PHI is reasonably believed to have been accessed, acquired, used, or disclosed during the Breach, to the extent known.

3.3 Subcontractors. Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions and conditions that apply to Business Associate with respect to such PHI. Business Associate's current Subcontractors are listed at https://app.rivon.health/security#subprocessors and Business Associate shall provide Covered Entity with at least thirty (30) days' notice prior to engaging a new Subcontractor that will have access to PHI.

3.4 Access by Individuals. Within fifteen (15) business days of a written request by Covered Entity, Business Associate shall provide access to PHI in a Designated Record Set to enable Covered Entity to meet its obligations under 45 CFR § 164.524.

3.5 Amendment of PHI. Within fifteen (15) business days of a written request by Covered Entity, Business Associate shall make any amendment to PHI in a Designated Record Set that Covered Entity directs, in accordance with 45 CFR § 164.526.

3.6 Accounting of Disclosures. Business Associate shall document and, within fifteen (15) business days of a written request by Covered Entity, make available the information required to provide an accounting of disclosures, in accordance with 45 CFR § 164.528.

3.7 HHS Access. Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Rules.

3.8 Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI by Business Associate in violation of this Agreement.

4. Obligations of Covered Entity

4.1 Covered Entity shall notify Business Associate of any limitations in its Notice of Privacy Practices to the extent that such limitations may affect Business Associate's use or disclosure of PHI.

4.2 Covered Entity shall notify Business Associate of any changes in, or revocation of, an Individual's permission to use or disclose PHI.

4.3 Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity.

4.4 Covered Entity shall obtain and maintain all consents, authorizations, and notices required by the HIPAA Rules and any applicable state law for the lawful use and disclosure of PHI by Business Associate.

5. Term and Termination

5.1 Term. This Agreement shall become effective on the date both parties execute the Underlying Agreement and shall remain in effect until terminated as provided herein, or until all PHI is returned or destroyed pursuant to Section 5.4.

5.2 Termination for Cause. Either party may terminate this Agreement (and the Underlying Agreement, as it applies to PHI) if the other party materially breaches this Agreement and fails to cure the breach within thirty (30) days after written notice. If cure is not feasible, the non-breaching party may terminate immediately.

5.3 Termination by Covered Entity. Covered Entity may terminate this Agreement immediately if Business Associate has violated a material term of this Agreement and Covered Entity reasonably determines cure is not feasible.

5.4 Return or Destruction of PHI. Upon termination, Business Associate shall return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity, and retain no copies, in accordance with 45 CFR § 164.504(e)(2)(ii)(J). If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible.

5.5 Survival. The obligations of Business Associate under this Section 5 shall survive termination of this Agreement.

6. Miscellaneous

6.1 Regulatory References. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

6.2 Amendment. The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the HIPAA Rules and any other applicable law.

6.3 Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the parties to comply with the HIPAA Rules.

6.4 No Third-Party Beneficiaries. Nothing in this Agreement shall confer upon any person other than the parties and their respective successors or assigns any rights, remedies, or obligations.

6.5 Order of Precedence. In the event of any conflict between this Agreement and the Underlying Agreement, the terms of this Agreement shall control with respect to PHI.

6.6 Notices. Notices required under this Agreement shall be in writing and sent to the addresses identified in the Underlying Agreement, with a copy to:


IN WITNESS WHEREOF, the parties have executed this Business Associate Agreement as of the dates set forth below.

Rivon Health, Inc. Covered Entity
Signature: ________________________ Signature: ________________________
Name: Name:
Title: Title:
Date: Date:

This template is provided as a starting point. We recommend Covered Entity have its legal counsel review prior to execution. To request a counter-signed copy on Rivon letterhead or to negotiate redlines, email legal@rivon.health.