CARECODEAI™ BUSINESS ASSOCIATE AGREEMENT
Effective Date: The date a Covered Entity accesses, subscribes to, activates, or uses the CareCodeAI platform.
This Business Associate Agreement ("Agreement" or "BAA") is entered into between CompleteCare, Inc. ("CompleteCare" or "Business Associate"), owner and operator of the CareCodeAI platform, and the healthcare provider, healthcare organization, health system, or other Covered Entity utilizing CareCodeAI ("Covered Entity").
This Agreement is incorporated into and made part of the applicable CareCodeAI Terms of Service, Subscription Agreement, or Order Form, and is deemed accepted upon registration for, activation of, subscription to, access to, or use of CareCodeAI.
1. PURPOSE
This Agreement is intended to comply with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations, including 45 C.F.R. Parts 160 and 164.
CareCodeAI is an AI-powered coding intelligence platform that may create, receive, maintain, process, analyze, or transmit Protected Health Information ("PHI") on behalf of Covered Entities in connection with coding assistance, documentation review, coding validation, workflow support, healthcare operations, and related services.
2. DEFINITIONS
Unless otherwise defined herein, capitalized terms shall have the meanings assigned under HIPAA.
Protected Health Information (PHI)
Has the meaning assigned under 45 C.F.R. §160.103 and includes all individually identifiable health information maintained or transmitted in any form or medium.
Business Associate
CompleteCare, Inc., owner and operator of the CareCodeAI platform.
Covered Entity
Any healthcare provider, health plan, healthcare clearinghouse, or other entity subject to HIPAA that utilizes CareCodeAI.
Subcontractor
Any third party engaged by Business Associate that creates, receives, maintains, or transmits PHI on behalf of Business Associate.
Security Incident
Has the meaning assigned under HIPAA and includes attempted or successful unauthorized access, use, disclosure, modification, or destruction of information.
3. PERMITTED USES AND DISCLOSURES
Business Associate may use and disclose PHI solely as necessary to:
-
Provide CareCodeAI services.
-
Analyze clinical documentation.
-
Generate coding recommendations.
-
Generate CPT®, ICD-10, HCPCS, and modifier recommendations.
-
Provide coding rationale and coding validation insights.
-
Improve system performance, reliability, security, and functionality.
-
Troubleshoot technical issues.
-
Comply with legal and regulatory obligations.
-
Create de-identified information in accordance with 45 C.F.R. §164.514.
Business Associate shall not:
-
Sell PHI.
-
Use PHI for marketing purposes.
-
Use Covered Entity PHI to train public artificial intelligence models.
-
Disclose PHI except as permitted by this Agreement or required by law.
4. AI-ASSISTED PROCESSING
Covered Entity acknowledges and agrees that:
CareCodeAI utilizes artificial intelligence and machine learning technologies to analyze clinical documentation and generate coding-related recommendations.
CareCodeAI functions solely as a coding decision-support tool.
CareCodeAI does not:
-
Provide medical advice.
-
Diagnose medical conditions.
-
Recommend treatment.
-
Replace provider judgment.
-
Replace certified coding review.
All coding, billing, reimbursement, compliance, documentation, and clinical decisions remain solely the responsibility of Covered Entity.
Business Associate makes no guarantee regarding reimbursement outcomes, claim payment, audit results, coding outcomes, or regulatory compliance.
5. SAFEGUARDS
Business Associate shall implement reasonable and appropriate administrative, physical, and technical safeguards to protect PHI, including:
-
Access controls
-
Role-based permissions
-
User authentication
-
Encryption in transit where appropriate
-
Encryption at rest where appropriate
-
Audit logging
-
Secure system architecture
-
Workforce training
-
Security monitoring
-
Vulnerability management practices
Business Associate shall maintain safeguards designed to reasonably protect against unauthorized use or disclosure of PHI.
6. BREACH NOTIFICATION
Business Associate shall notify Covered Entity without unreasonable delay following discovery of a breach of unsecured PHI requiring notification under HIPAA.
Such notification shall include, to the extent known:
-
Nature of the incident
-
Categories of information involved
-
Corrective actions taken
-
Mitigation efforts undertaken
-
Contact information for follow-up
Business Associate shall cooperate with Covered Entity regarding legally required breach investigations and notifications.
7. SUBCONTRACTORS AND THIRD-PARTY SERVICE PROVIDERS
Business Associate may utilize subcontractors and service providers in connection with CareCodeAI, including cloud hosting providers, infrastructure providers, software vendors, analytics providers, payment processors, and artificial intelligence technology providers.
8. Artificial Intelligence Processing
Business Associate may utilize artificial intelligence technologies in connection with providing the CareCodeAI services.
Business Associate shall not use Covered Entity PHI to train public or third-party artificial intelligence models.
Any de-identified information used for internal product improvement shall be created in accordance with HIPAA de-identification standards and shall not identify any individual or Covered Entity.
Business Associate shall ensure that any subcontractor with access to PHI is bound by written agreements requiring protections substantially equivalent to those contained in this Agreement.
9. ACCESS, AMENDMENT, AND ACCOUNTING
To the extent applicable under HIPAA, Business Associate shall:
-
Make PHI available to Covered Entity.
-
Support requests for amendment of PHI.
-
Provide information necessary for accounting of disclosures.
Business Associate may satisfy such obligations through functionality made available within the CareCodeAI platform or through reasonable administrative processes.
11. RESPONSIBILITIES OF COVERED ENTITY
Covered Entity agrees to:
-
Provide only the minimum necessary PHI required for CareCodeAI services.
-
Obtain all required authorizations, consents, and permissions.
-
Not request Business Associate to use or disclose PHI in violation of HIPAA.
-
Maintain responsibility for all coding and billing decisions.
-
Review and validate all coding recommendations before use.
-
Notify Business Associate of any restrictions affecting use or disclosure of PHI.
12. DATA RETENTION AND DESTRUCTION
Business Associate shall retain PHI only for as long as necessary to provide services, comply with legal obligations, maintain backups, support disaster recovery processes, and satisfy contractual requirements.
Upon termination of services, Business Associate shall:
-
Securely destroy PHI when feasible; or
-
Continue to protect PHI if return or destruction is infeasible.
Any retained PHI shall remain subject to the protections of this Agreement.
13. TERM AND TERMINATION
This Agreement shall remain in effect for as long as Business Associate maintains PHI on behalf of Covered Entity.
Either Party may terminate this Agreement upon written notice if the other Party materially breaches this Agreement and fails to cure such breach within thirty (30) days following notice.
Upon termination, the obligations relating to confidentiality, security, breach notification, and protection of PHI shall survive.
14. INDEMNIFICATION
Each Party shall be responsible for its own acts and omissions.
Each Party agrees to indemnify and hold harmless the other Party from claims, damages, penalties, costs, or expenses arising directly from that Party's breach of this Agreement, HIPAA, or other applicable privacy laws.
15. LIMITATION OF LIABILITY
CareCodeAI is intended to assist healthcare professionals by providing coding intelligence and workflow support.
Business Associate shall not be liable for:
-
Coding selections made by users;
-
Billing decisions;
-
Reimbursement outcomes;
-
Audit findings;
-
Regulatory actions;
-
Medical decisions;
-
Clinical outcomes; or
-
Reliance upon recommendations without independent review.
Covered Entity remains solely responsible for all final coding, billing, documentation, reimbursement, and clinical decisions.
16. GOVERNING LAW
This Agreement shall be governed by the laws of the State of Arkansas without regard to conflict-of-law principles.
Venue for any dispute arising under this Agreement shall lie exclusively in Pulaski County, Arkansas.
17. ENTIRE AGREEMENT
This Agreement constitutes the entire agreement between the Parties regarding HIPAA and PHI obligations relating to CareCodeAI.
This Agreement supersedes prior discussions concerning PHI handling for CareCodeAI and may only be amended by a written agreement executed by authorized representatives of both Parties.
18. ACCEPTANCE
Covered Entity agrees that this Agreement is incorporated into the CareCodeAI Terms of Service and becomes legally binding upon registration for, activation of, subscription to, access to, or use of the CareCodeAI platform.
No separate signature shall be required unless otherwise requested by either Party.
COMPLETECARE, INC.
Owner and Operator of CareCodeAI™
8529 Riverwood Drive
North Little Rock, Arkansas 72113
Phone: (501) 753-6800
Website: www.completecare.com
