VIAHLINK HIPAA BUSINESS ASSOCIATE AGREEMENT
Dental Laboratory / Customer Version
Effective Date: Date of Acceptance
This HIPAA Business Associate Agreement (“BAA”) is entered into between the dental laboratory, dental practice, healthcare provider, or other healthcare-related business accepting this Agreement (“Customer”) and Xviahlink Inc., 200 Gates Rd Suite D, Little Ferry, New Jersey 07643, United States (“Xviahlink”).
This BAA applies to the extent customer is a Covered Entity or Business Associate subject to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and Xviahlink creates, receives, maintains, or transmits Protected Health Information (“PHI”) on Customer’s behalf in connection with viahlink.com.
Where Customer receives PHI from a dental practice, dentist, or other Covered Entity and provides such PHI to Xviahlink for CAD design or related services, Xviahlink acts as a subcontractor Business Associate of Customer to the extent required by HIPAA.
1. Definitions
Capitalized terms not otherwise defined in this BAA have the meanings assigned under HIPAA, the HITECH Act, and regulations at 45 C.F.R. Parts 160 and 164 (“HIPAA Rules”).
“Protected Health Information” or “PHI,” “Breach,” “Security Incident,” “Covered Entity,” and “Business Associate” have the meanings assigned under the HIPAA Rules.
2. Permitted Uses and Disclosures
Xviahlink may use or disclose PHI only as necessary to provide CAD design and related services to customer, for the proper management and administration of Xviahlink, to carry out Xviahlink’s legal responsibilities, as required by law, or as otherwise permitted by this BAA and the HIPAA Rules.
Xviahlink shall not use or disclose PHI in a manner prohibited by the HIPAA Rules and shall apply applicable minimum-necessary principles.
3. Obligations of Xviahlink
Xviahlink shall use appropriate administrative, physical, and technical safeguards to protect PHI and shall comply with applicable HIPAA Security Rule requirements for electronic PHI (“ePHI”).
Xviahlink shall report impermissible uses or disclosures of PHI, applicable security incidents, and breaches as required by this BAA and the HIPAA Rules.
Xviahlink shall ensure that subcontractors that create, receive, maintain, or transmit PHI on its behalf agree in writing to restrictions and conditions that are at least as protective as those applicable to Xviahlink.
Xviahlink shall reasonably assist customer with applicable access, amendment, and accounting-of-disclosures obligations under the HIPAA Rules.
To the extent Xviahlink performs an obligation of customer under the HIPAA Privacy Rule, Xviahlink shall comply with the requirements applicable to that obligation.
Xviahlink shall make applicable internal practices, books, and records relating to PHI available to the Secretary of the U.S. Department of Health and Human Services as required by law.
4. CAD Design Services
Customer may submit PHI and dental case files to Xviahlink for CAD design and related services. Such information may include patient identifiers, digital dental scans, three-dimensional files, dental images, tooth information, implant information, and other case information.
Xviahlink may use case IDs, role-based access, and other technical and organizational measures intended to reduce unnecessary disclosure of patient-identifying information to Designers.
5. Subcontractors and Designers
Xviahlink may use qualified employees and independent service providers, including Xviah Inc, as well as authorized CAD designers, design companies, cloud providers, and other subcontractors in connection with the Service. The Korean service provider is a legally separate company and is not described as an affiliate solely because the companies may share management or ownership personnel.
Before any subcontractor creates, receives, maintains, or transmits PHI, Xviahlink shall enter into a written agreement imposing the same applicable restrictions, conditions, and safeguards required by this BAA and the HIPAA Rules. Xviahlink shall remain responsible for managing its contractual obligations to Customer.
6. Data Location and International Processing
Xviahlink’s primary service data and case files are hosted and stored on cloud infrastructure located in the Republic of Korea.
Authorized subcontractors or Designers may perform services from locations outside the United States, including the Republic of Korea and Vietnam.
Where such parties receive PHI and qualify as subcontractors under HIPAA, Xviahlink will require applicable contractual safeguards and security controls.
7. Security Incidents
Xviahlink shall report security incidents involving PHI as required by the HIPAA Rules.
Routine unsuccessful security events, such as blocked login attempts or unsuccessful automated scans that do not result in unauthorized access, acquisition, use, disclosure, modification, or destruction of PHI, may occur in ordinary internet operations and, to the extent permitted by law, are deemed reported by this provision.
8. Breach Notification
Xviahlink shall notify customer of a breach of unsecured PHI without unreasonable delay and in no event later than sixty (60) calendar days following discovery, consistent with applicable HIPAA requirements.
The notice shall include, to the extent reasonably available, information necessary to assist customer with its applicable notification obligations.
9. Access, Amendment, and Accounting
To the extent required by the HIPAA Rules, Xviahlink shall reasonably assist customer in making PHI available for applicable access requests, making applicable amendments to PHI, and maintaining information necessary for an accounting of applicable disclosures.
10. Customer Responsibilities
Customer represents that it has lawful authority to disclose applicable PHI to Xviahlink and that its use of the service complies with applicable law and any upstream agreement applicable to customer.
Where customer is a Business Associate of a dental practice, dentist, or other Covered Entity, customer is responsible for maintaining any Business Associate agreement or other authorization required between customer and that Covered Entity.
Customer shall not request Xviahlink to use or disclose PHI in a manner that would violate applicable law if performed by customer.
11. Data Retention and Termination
This BAA becomes effective when accepted by Customer and continues for as long as Xviahlink creates, receives, maintains, or transmits PHI on Customer’s behalf.
Upon termination of the applicable service relationship, Xviahlink shall return or destroy PHI where feasible and required by the HIPAA Rules. If return or destruction is infeasible, Xviahlink shall continue to protect the PHI and limit further use and disclosure to the purposes that make return or destruction infeasible.
Retention and deletion of case files will also be subject to Xviahlink’s then-current Privacy Policy and applicable legal requirements, provided that this BAA controls in the event of a conflict concerning PHI.
12. Termination for Cause
If Xviahlink materially violates this BAA, Customer may provide Xviahlink a reasonable opportunity to cure the violation and may terminate the applicable service relationship if the violation is not cured, to the extent required or permitted by the HIPAA Rules.
13. Regulatory Cooperation
Xviahlink shall reasonably cooperate with Customer and applicable governmental authorities concerning PHI as required by the HIPAA Rules.
14. Order of Precedence
If this BAA conflicts with the Terms of Service or Privacy Policy concerning PHI or HIPAA obligations, this BAA controls with respect to those matters.
15. Electronic Acceptance
This BAA may be accepted electronically. Electronic acceptance has the same effect as a physical signature to the extent permitted by applicable law.
Xviahlink may maintain the customer organization name, accepting representative, account identifier, BAA version, date and time of acceptance, and associated audit records.
16. Governing Law
To the extent not governed or preempted by federal law, this BAA is governed by the laws of the State of New Jersey, without regard to conflict-of-laws principles.
17. Contact
Xviahlink Inc
200 Gates Rd Suite D
Little Ferry, New Jersey 07643
United States
Website: viahlink.com
Customer: The organization accepting this BAA through viahlink.com.
Effective Date: Date of acceptance.
HIPAA / Privacy Contact Email: jinyongyoo@gmail.com