Business Associate Agreement

Our HIPAA Business Associate Agreement

NexiumCare signs a Business Associate Agreement with every healthcare customer at no charge. The BAA establishes how we handle Protected Health Information on your behalf and is required by HIPAA before any PHI is uploaded.

Effective April 30, 2026

What is a Business Associate Agreement?

A Business Associate Agreement (BAA) is a written contract required by HIPAA between a covered entity (a healthcare provider, health plan, or clearinghouse) and a business associate (a third party that creates, receives, maintains, or transmits Protected Health Information on its behalf).

NexiumCare is a business associate to every healthcare practice that uses the Service. We sign a BAA with every customer at no charge before any Protected Health Information (PHI) is uploaded.

What our BAA covers

Our BAA establishes the obligations both parties have under HIPAA, including:

  • Permitted and required uses and disclosures of PHI by NexiumCare.
  • Safeguards we put in place to protect PHI (administrative, physical, technical).
  • Reporting of any use or disclosure not permitted by the BAA, including breach notification.
  • Subcontractor obligations — every NexiumCare subprocessor that handles PHI signs an equivalent BAA.
  • Customer's right to inspect, amend, and account for disclosures of PHI.
  • Customer's right to terminate the BAA upon material breach.
  • Return or destruction of PHI on termination of the agreement.

Subcontractors and subprocessors

NexiumCare engages subprocessors to provide hosting, monitoring, and support services. Every subprocessor with access to PHI signs a BAA with NexiumCare. A current list of subprocessors is provided to customers on request and updated whenever a new subprocessor is added.

Breach notification

NexiumCare will notify the customer of any breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery, in accordance with the HIPAA Breach Notification Rule. Notification will include:

  • Identification of each individual whose unsecured PHI was, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach.
  • The date of the breach and the date of discovery, if known.
  • The types of PHI involved.
  • Steps NexiumCare has taken to investigate, mitigate harm, and protect against further breaches.

How to request our BAA

NexiumCare signs the same BAA with every customer at no additional charge. There are three ways to obtain a counter-signed BAA:

  • Email request — send an email to [email protected]; we return a counter-signed BAA within one business day.
  • During account setup — practice admins are prompted to sign the BAA before activating PHI features.
  • Custom BAA review — for enterprise customers with their own BAA template, our legal team reviews and either accepts or proposes redlines within five business days.

A reference copy of our standard BAA is available on request. We do not post the BAA publicly because we adapt it for state-specific requirements (e.g., Texas HB 300, California CMIA) at signing.

Common questions

Do I need a BAA before I sign up? No. You can sign up and explore NexiumCare without uploading any PHI. The BAA is required before you turn on PHI-handling features (patient charts, e-prescribing, billing).

Can I use my organization's BAA template? Yes — for Business and Enterprise plans, we review and negotiate custom BAAs. Standard plans use our template.

Does the BAA cover all PHI I store in NexiumCare? Yes. The BAA covers all PHI created, received, maintained, or transmitted by NexiumCare on your behalf.

What happens to PHI when I cancel? You can export all data for 30 days after cancellation. After that period, NexiumCare destroys PHI in accordance with the BAA, subject to any legal retention obligations.

Related documents

Other agreements and policies you may need.

Questions about this document?

Our legal and compliance team responds within one business day.