What is a Business Associate Agreement?
A Business Associate Agreement (BAA) is a written contract required by HIPAA between a covered entity (a healthcare provider, health plan, or clearinghouse) and a business associate (a third party that creates, receives, maintains, or transmits Protected Health Information on its behalf).
NexiumCare is a business associate to every healthcare practice that uses the Service. We sign a BAA with every customer at no charge before any Protected Health Information (PHI) is uploaded.
What our BAA covers
Our BAA establishes the obligations both parties have under HIPAA, including:
- Permitted and required uses and disclosures of PHI by NexiumCare.
- Safeguards we put in place to protect PHI (administrative, physical, technical).
- Reporting of any use or disclosure not permitted by the BAA, including breach notification.
- Subcontractor obligations — every NexiumCare subprocessor that handles PHI signs an equivalent BAA.
- Customer's right to inspect, amend, and account for disclosures of PHI.
- Customer's right to terminate the BAA upon material breach.
- Return or destruction of PHI on termination of the agreement.
Subcontractors and subprocessors
NexiumCare engages subprocessors to provide hosting, monitoring, and support services. Every subprocessor with access to PHI signs a BAA with NexiumCare. A current list of subprocessors is provided to customers on request and updated whenever a new subprocessor is added.
Breach notification
NexiumCare will notify the customer of any breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery, in accordance with the HIPAA Breach Notification Rule. Notification will include:
- Identification of each individual whose unsecured PHI was, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach.
- The date of the breach and the date of discovery, if known.
- The types of PHI involved.
- Steps NexiumCare has taken to investigate, mitigate harm, and protect against further breaches.
How to request our BAA
NexiumCare signs the same BAA with every customer at no additional charge. There are three ways to obtain a counter-signed BAA:
- Email request — send an email to [email protected]; we return a counter-signed BAA within one business day.
- During account setup — practice admins are prompted to sign the BAA before activating PHI features.
- Custom BAA review — for enterprise customers with their own BAA template, our legal team reviews and either accepts or proposes redlines within five business days.
A reference copy of our standard BAA is available on request. We do not post the BAA publicly because we adapt it for state-specific requirements (e.g., Texas HB 300, California CMIA) at signing.
Common questions
Do I need a BAA before I sign up? No. You can sign up and explore NexiumCare without uploading any PHI. The BAA is required before you turn on PHI-handling features (patient charts, e-prescribing, billing).
Can I use my organization's BAA template? Yes — for Business and Enterprise plans, we review and negotiate custom BAAs. Standard plans use our template.
Does the BAA cover all PHI I store in NexiumCare? Yes. The BAA covers all PHI created, received, maintained, or transmitted by NexiumCare on your behalf.
What happens to PHI when I cancel? You can export all data for 30 days after cancellation. After that period, NexiumCare destroys PHI in accordance with the BAA, subject to any legal retention obligations.

