Business Associate Agreement
Reference version 2026-08-09
This Business Associate Agreement (the “Agreement”) is entered into as of (the “Effective Date”) by and between , a (“Covered Entity”), and RxRecon Pro LLC, a New Jersey limited liability company with a business address at 301 Plainfield Road, Edison, New Jersey 08820 (“Business Associate”). Covered Entity and Business Associate may each be a “Party” and together the “Parties.”
1. Purpose and relationship
Covered Entity may disclose Protected Health Information (“PHI”) to Business Associate, and Business Associate may create, receive, maintain, or transmit PHI on Covered Entity’s behalf, solely to provide the RxRecon Pro reconciliation and related support services described in the Parties’ applicable service agreement. The Parties intend this Agreement to satisfy the applicable requirements of the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations, each as amended (“HIPAA”).
2. Definitions
Terms including Breach, Designated Record Set, Electronic Protected Health Information (“ePHI”), Individual, Minimum Necessary, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use and Disclosure have the meanings assigned by HIPAA. “Approved Location” means a pharmacy location owned or operated by Covered Entity that Business Associate has verified and approved in writing for use of the service.
3. Permitted uses and disclosures
- Business Associate may use or disclose PHI only as necessary to perform services for Covered Entity, as permitted by this Agreement, or as Required by Law. Business Associate shall not use or disclose PHI in a manner that would violate HIPAA if done by Covered Entity, except as expressly permitted for a business associate.
- Business Associate may use PHI for its proper management and administration or to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only if Required by Law or after obtaining reasonable written assurances that the recipient will hold the information confidentially, use or further disclose it only as Required by Law or for the stated purpose, and notify Business Associate of any known breach of confidentiality.
- Business Associate may provide data aggregation services relating to Covered Entity’s health care operations when authorized in writing. Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514. Information is not treated as de-identified merely because direct names are omitted.
- Business Associate shall not sell PHI, use PHI for marketing, or use PHI for any independent commercial purpose unless expressly authorized by Covered Entity and permitted by law.
- Business Associate shall limit uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose.
4. Business Associate obligations
- Safeguards. Business Associate shall use appropriate administrative, physical, and technical safeguards to prevent uses or disclosures not permitted by this Agreement and shall comply with the applicable provisions of the HIPAA Security Rule with respect to ePHI.
- Incident reporting. Business Associate shall report to Covered Entity any use or disclosure not permitted by this Agreement, any Breach of Unsecured PHI, and any material Security Incident of which Business Associate becomes aware, without unreasonable delay and no later than ten (10) calendar days after discovery. Routine unsuccessful security events that do not result in unauthorized access, use, disclosure, modification, or destruction may be reported in summary form unless Covered Entity reasonably requests otherwise.
- Breach details. To the extent known, Business Associate’s report shall include the identity of affected Individuals, the information reasonably required for Covered Entity’s assessment and notifications, a description of what occurred, relevant dates, the types of PHI involved, mitigation performed, and corrective actions taken or planned. Business Associate shall supplement the report as additional information becomes available.
- Mitigation. Business Associate shall mitigate, to the extent practicable, harmful effects of an impermissible use or disclosure caused by Business Associate or its workforce.
- Workforce access. Business Associate shall limit PHI access to workforce members who require it for authorized duties, apply appropriate confidentiality obligations and training, and terminate access when no longer required.
- Subcontractors. Business Associate shall not permit a Subcontractor to create, receive, maintain, or transmit PHI on its behalf unless the Subcontractor provides written assurances imposing the same material restrictions, conditions, and safeguards that apply to Business Associate. Infrastructure and hosting providers may qualify as Subcontractors even when no individual contractor is engaged.
- Access and amendment. If Business Associate maintains PHI in a Designated Record Set, it shall make that PHI available for access and amendment in the time and manner reasonably requested by Covered Entity and required by 45 C.F.R. §§ 164.524 and 164.526.
- Accounting. Business Associate shall document and provide information about disclosures as needed for Covered Entity to respond under 45 C.F.R. § 164.528.
- Secretary access. Business Associate shall make its internal practices, books, and records relating to PHI available to the Secretary for determining compliance with HIPAA.
- Cooperation. Business Associate shall reasonably cooperate with Covered Entity’s investigation, risk assessment, legally required notices, mitigation, and response concerning a Breach or material Security Incident attributable to Business Associate.
5. Service-specific safeguards and limits
- The service is designed to parse supported source reports in the authorized user’s browser, keep direct patient and prescriber identifiers and local re-association data in browser memory, and transmit only a versioned, allowlisted analytical projection with run-scoped opaque tokens to protected compute.
- Business Associate shall not intentionally retain uploaded pharmacy reports or direct patient and prescriber identifiers as part of the hosted reconciliation service. Account, entitlement, security, legal-acceptance, billing, and minimum usage records may be maintained as permitted by the service agreement and applicable law.
- Client-controlled values and analytical combinations may still constitute PHI. The local-processing design is a data-minimization safeguard and is not, by itself, a legal determination that every transmitted value is de-identified.
- Covered Entity shall not send PHI through the public Request Access form, Stripe checkout, ordinary support email, or any other channel that Business Associate has not expressly approved for PHI.
6. Covered Entity obligations
- Covered Entity shall notify Business Associate of relevant limitations in its Notice of Privacy Practices, revoked permissions, or agreed restrictions that may affect Business Associate’s use or disclosure of PHI.
- Covered Entity shall not request Business Associate to use or disclose PHI in a manner that would be impermissible if performed by Covered Entity, except as HIPAA permits for a business associate.
- Covered Entity is responsible for lawful authority to provide PHI, minimum-necessary use, endpoint and source-system security, unique authorized users, workforce training, accurate source records, and promptly reporting suspected unauthorized access.
- Covered Entity shall use the service only for Approved Locations and shall not share credentials or submit information belonging to another legal entity or unapproved pharmacy location.
- Covered Entity shall maintain a current HIPAA risk analysis and risk-management program; secure and patch its devices, browsers, networks, source systems, and backups; use unique accounts, access controls, screen locks, and device encryption where appropriate; train and sanction its workforce; and disable access promptly when no longer authorized.
- Covered Entity shall not place PHI in filenames, free-text fields, the Request Access form, Stripe, ordinary email, support messages, or any channel not expressly approved in writing for PHI. Covered Entity is responsible for PHI retained in or exposed through its browser, device, clipboard, downloads, screenshots, printing, local storage, source systems, or workforce practices.
- Covered Entity shall notify Business Associate at ADMIN@RXRECONPRO.COM without unreasonable delay and no later than twenty-four (24) hours after discovering suspected credential compromise, unauthorized service access, or an impermissible submission involving the service, and shall preserve relevant evidence and reasonably cooperate with containment.
- Covered Entity remains responsible for clinical and professional judgment, authoritative records, legal notices to Individuals or regulators except where law assigns the duty to Business Associate, and all acts or omissions of its workforce and agents. Business Associate is not responsible for a Security Incident caused solely by Covered Entity's systems, credentials, instructions, or failure to perform these obligations, except to the extent Business Associate caused or contributed to the incident.
7. Term, termination, and cure
- This Agreement begins on the Effective Date and continues until all PHI provided by Covered Entity or created or received on its behalf is returned or destroyed, or—if return or destruction is infeasible—the protections of this Agreement continue to apply.
- If either Party learns of a material breach by the other Party, it shall provide written notice and a reasonable opportunity to cure when cure is possible. If cure is not possible or is not timely completed, the non-breaching Party may terminate this Agreement and the affected services. A Party shall report the matter to the Secretary when required by law.
- Business Associate may immediately suspend access when reasonably necessary to prevent or contain unauthorized use, disclosure, or security risk.
8. Return or destruction
At termination, Business Associate shall, if feasible, return or destroy all PHI received from Covered Entity or created, maintained, or received on its behalf and retain no copies. If return or destruction is infeasible, Business Associate shall explain the basis in writing, extend this Agreement’s protections to the retained PHI, and limit further uses and disclosures to the purposes that make return or destruction infeasible. PHI remaining in protected backups shall not be restored except for disaster recovery or legal necessity and shall be destroyed through the ordinary secure backup lifecycle.
9. Approved and future locations
This Agreement applies to the Approved Locations listed in Schedule A and to future pharmacy locations that are owned or operated by the same Covered Entity legal entity and later approved in writing by Business Associate. No amendment is required solely to add such a location. A location owned by a different corporation, limited liability company, or other legal entity requires its own agreement or a written amendment signed by the Parties.
10. Documentation retention
Each Party shall retain this Agreement, amendments, signature evidence, and documentation required by HIPAA for at least six (6) years from creation or from the date the document was last in effect, whichever is later, and longer when required by applicable New Jersey or other law, contractual duty, or legal hold.
11. Execution and activation
- After verifying Covered Entity and its authorized signer, Business Associate sends the pharmacy-specific Agreement and completed Schedule A through DocuSign to Covered Entity's signer email.
- Covered Entity signs first. Business Associate countersigns only after confirming the signer, legal entity, Approved Location, and agreement version. The DocuSign completion certificate and envelope identifier are part of the execution record.
- The Agreement becomes effective when both authorized representatives have signed. Payment, provisioning, invitation, or PHI use may not occur before the fully executed envelope is recorded. Business Associate separately confirms when the Approved Location is activated for production PHI use.
12. General provisions
- Regulatory references. References to HIPAA provisions mean those provisions as amended. The Parties shall amend this Agreement as necessary to comply with changes in applicable law.
- Interpretation. Any ambiguity shall be resolved to permit compliance with HIPAA. If this Agreement conflicts with the service agreement concerning PHI privacy or security, this Agreement controls.
- No third-party beneficiaries. This Agreement does not create rights in any person other than the Parties, except as applicable law requires.
- No agency. This Agreement does not create a partnership, joint venture, or agency relationship beyond the status imposed by applicable law.
- Governing law. This Agreement is governed by the laws of the State of New Jersey, without regard to conflict-of-law principles, except to the extent federal law controls.
- Notices. Notices to Business Associate shall be sent to RxRecon Pro LLC, 301 Plainfield Road, Edison, NJ 08820, and ADMIN@RXRECONPRO.COM. Covered Entity’s notice information appears in Schedule A.
- Entire agreement; amendments. This Agreement and its signed schedules constitute the entire agreement on the Parties’ HIPAA business-associate relationship. Amendments must be in writing and signed by authorized representatives, except for future Approved Locations added under Section 9.
- Electronic signatures. Electronic signatures and counterparts are effective as originals. The completed DocuSign certificate and envelope record form part of the execution evidence.
Covered Entity
Legal name:
By:
Name:
Title:
Date:
Business Associate
RxRecon Pro LLC
By:
Name: Mr. Subba Nageli
Title: Manager Member
Date:
Schedule A — Covered Entity and Approved Locations
Covered Entity legal name:
Entity type and state:
Notice address:
Notice email:
Authorized signer name and title:
Initially approved pharmacy location
DBA/store name:
Physical address:
NPI: NABP/NCPDP:
Additional locations owned or operated by the same Covered Entity become covered only after written approval by RxRecon Pro LLC.
Reference basis: HHS Sample Business Associate Agreement Provisions and 45 C.F.R. §§ 164.308, 164.316, 164.410, and 164.504. Only the pharmacy-specific DocuSign envelope completed by both parties is an executed agreement.