Lorem ipsum dolor sit amet
Lorem ipsum dolor sit amet wegew wegweg wegweg
Last Modified: August 3, 2026
These HIPAA Business Associate Terms (these "Business Associate Terms") apply to the extent that Customer, on behalf of an applicable health plan, flexible spending account, health reimbursement arrangement, or other covered entity under HIPAA (the "Plan"), intends to treat certain services provided by Benepass, Inc. ("Benepass" or "Business Associate") under the applicable services agreement, order form, or other written agreement between Benepass and Customer (the "Agreement") as services provided to or on behalf of the Plan.
The Plan is intended to be treated as a "covered entity" within the meaning of the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations, including the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Rules").
Accordingly, these Business Associate Terms apply only to the extent Benepass creates, receives, maintains, or transmits Protected Health Information, including Electronic Protected Health Information, on behalf of the Plan in connection with the Services. Customer Data that does not constitute Protected Health Information is governed by the Agreement, any applicable data processing terms, and applicable privacy terms.
Capitalized terms used but not defined in these Business Associate Terms have the meanings given to those terms under the HIPAA Rules. "Protected Health Information" includes Electronic Protected Health Information where applicable.
Business Associate agrees to:
(a) not use or disclose Protected Health Information other than as permitted or required by these Business Associate Terms or as Required By Law;
(b) use appropriate safeguards and comply, where applicable, with Subpart C of 45 C.F.R. Part 164 with respect to Electronic Protected Health Information to prevent use or disclosure of Protected Health Information other than as provided for by these Business Associate Terms;
(c) report to the Plan any use or disclosure of Protected Health Information not provided for by these Business Associate Terms of which Business Associate becomes aware, including any Breach of Unsecured Protected Health Information as required by 45 C.F.R. § 164.410 and any Security Incident of which Business Associate becomes aware, without unreasonable delay and in no event later than ten (10) business days after discovery;
(d) provide, and the Plan hereby acknowledges receipt of, notice of unsuccessful attempts at unauthorized access, use, disclosure, modification, or destruction of Electronic Protected Health Information, such as pings, broadcast attacks, denial-of-service attacks, port scans, unsuccessful login attempts, or interception of encrypted information where the key is not compromised, provided that no such incident results in unauthorized access to, or use or disclosure of, the Plan's Electronic Protected Health Information;
(e) ensure that any subcontractor that creates, receives, maintains, or transmits Protected Health Information on behalf of Business Associate agrees to substantially the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information, in accordance with 45 C.F.R. § 164.502(e)(1)(ii) and § 164.308(b)(2);
(f) make available Protected Health Information in a Designated Record Set to the Plan as necessary to satisfy the Plan's obligations under 45 C.F.R. § 164.524;
(g) make any amendment to Protected Health Information in a Designated Record Set as directed or agreed to by the Plan pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy the Plan's obligations under 45 C.F.R. § 164.526;
(h) maintain and make available information required to provide an accounting of disclosures to the Plan as necessary to satisfy the Plan's obligations under 45 C.F.R. § 164.528;
(i) to the extent Business Associate is to carry out one or more of the Plan's obligations under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to the Plan in the performance of such obligations;
(j) make its internal practices, books, and records relating to the use and disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of, the Plan available to the Secretary for purposes of determining compliance with the HIPAA Rules; and
(k) comply with 42 C.F.R. Part 2 to the extent Business Associate receives records subject to 42 C.F.R. Part 2 in connection with the Services.
Business Associate may use or disclose Protected Health Information to perform functions, activities, or services for, or on behalf of, the Plan as specified in the Agreement, provided that such use or disclosure would not violate the HIPAA Rules if done by the Plan.
Business Associate may use Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate.
Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that the disclosure is Required By Law or Business Associate obtains reasonable assurances from the recipient that the information will remain confidential, will be used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and the recipient will notify Business Associate of any instances of which it becomes aware in which the confidentiality of the information has been breached.
Business Associate may use Protected Health Information to provide Data Aggregation services to the Plan as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
Business Associate may use or disclose Protected Health Information as Required By Law.
Business Associate may de-identify Protected Health Information in accordance with 45 C.F.R. § 164.514 and may use and disclose de-identified information for any lawful purpose.
Business Associate will use reasonable efforts to limit Protected Health Information, when making uses, disclosures, and requests, to the Minimum Necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.502(b).
Business Associate may not use or disclose Protected Health Information in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Plan, except for the specific uses and disclosures permitted by this Section 3.
(a) The Plan will notify Business Associate of any limitation in the Plan's Notice of Privacy Practices under 45 C.F.R. § 164.520 to the extent the limitation may affect Business Associate's use or disclosure of Protected Health Information.
(b) The Plan will notify Business Associate of any change in, or revocation of, permission by an Individual to use or disclose Protected Health Information to the extent the change may affect Business Associate's use or disclosure of Protected Health Information.
(c) The Plan will notify Business Associate of any restriction on the use or disclosure of Protected Health Information that the Plan has agreed to or is required to abide by under 45 C.F.R. § 164.522 to the extent the restriction may affect Business Associate's use or disclosure of Protected Health Information.
(d) The Plan and Customer will not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under Subpart E of 45 C.F.R. Part 164 if done by the Plan, except for uses or disclosures permitted for Data Aggregation, Business Associate's proper management and administration, or Business Associate's legal responsibilities.
(e) Customer is responsible for determining whether any Services involve a Plan, Covered Entity, or Protected Health Information and for providing Benepass only the information reasonably necessary for Benepass to provide the Services.
The term of these Business Associate Terms begins when these Business Associate Terms apply under the Agreement and terminates upon termination or expiration of the Agreement, or on the date the Plan terminates these Business Associate Terms for cause as authorized below, whichever is sooner.
Business Associate authorizes termination of these Business Associate Terms by the Plan if the Plan determines that Business Associate has violated a material term of these Business Associate Terms and Business Associate has not cured the breach or ended the violation within the time specified by the Plan.
Upon termination of these Business Associate Terms for any reason, Business Associate, with respect to Protected Health Information received from the Plan or created, maintained, or received by Business Associate on behalf of the Plan, will:
(a) retain only that Protected Health Information necessary for Business Associate to continue its proper management and administration, carry out its legal responsibilities, satisfy legal, regulatory, archival, compliance, or dispute-resolution obligations, or as otherwise permitted by the Agreement;
(b) return to the Plan or destroy all remaining Protected Health Information that Business Associate still maintains in any form;
(c) continue to use appropriate safeguards and comply with Subpart C of 45 C.F.R. Part 164 with respect to Electronic Protected Health Information to prevent use or disclosure of retained Protected Health Information other than as provided in this Section 5;
(d) not use or disclose retained Protected Health Information other than for the purposes for which it was retained and subject to the same protections applicable before termination; and
(e) return to the Plan or destroy retained Protected Health Information when it is no longer needed by Business Associate for the purposes described above, unless return or destruction is infeasible or prohibited by law.
If Business Associate determines that return or destruction of Protected Health Information is infeasible, Business Associate will extend the protections of these Business Associate Terms to such information and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as Business Associate maintains such information.
Business Associate's obligations under this Section 5 survive termination of these Business Associate Terms.
Regulatory References. A reference in these Business Associate Terms to a section of the HIPAA Rules means the section as in effect or as amended and for which compliance is required.
Amendment. Benepass may amend these Business Associate Terms from time to time as reasonably necessary to comply with the HIPAA Rules or other applicable law. Any updated Business Associate Terms will apply in accordance with the Agreement and applicable law.
Interpretation. Any ambiguity in these Business Associate Terms will be interpreted to permit compliance with the HIPAA Rules.
Integration. These Business Associate Terms apply only to the subject matter addressed herein. If Benepass and Customer, the Plan, or another applicable covered entity enter into a separately negotiated business associate agreement covering the same Protected Health Information, that separately negotiated business associate agreement will supersede these Business Associate Terms with respect to such Protected Health Information.
Assignment. These Business Associate Terms are binding on, and inure to the benefit of, the Plan, Customer, Business Associate, and their respective legal representatives, successors, and permitted assigns.
Conflicts. To the extent required under the HIPAA Rules, these Business Associate Terms control if they conflict with the Agreement, but only with respect to Business Associate's use, disclosure, maintenance, creation, receipt, or transmission of Protected Health Information. The Agreement and any applicable data processing terms govern Customer Data that is not Protected Health Information.
Liability. Except to the extent separately agreed in writing, the parties' liability and indemnification obligations relating to these Business Associate Terms are governed by the Agreement.
No Third-Party Beneficiaries. Nothing in these Business Associate Terms is intended to confer any rights, remedies, obligations, or liabilities on any person other than the parties and their respective successors and permitted assigns.