top of page
carecode-ai_tagline.png

CARECODEAI™ BUSINESS ASSOCIATE AGREEMENT

Effective Date: The date a Covered Entity accesses, subscribes to, activates, or uses the CareCodeAI platform.

This Business Associate Agreement ("Agreement" or "BAA") is entered into between CompleteCare, Inc. ("CompleteCare" or "Business Associate"), owner and operator of the CareCodeAI platform, and the healthcare provider, healthcare organization, health system, or other Covered Entity utilizing CareCodeAI ("Covered Entity").

This Agreement is incorporated into and made part of the applicable CareCodeAI Terms of Service, Subscription Agreement, or Order Form, and is deemed accepted upon registration for, activation of, subscription to, access to, or use of CareCodeAI.

1. PURPOSE

This Agreement is intended to comply with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations, including 45 C.F.R. Parts 160 and 164.

CareCodeAI is an AI-powered coding intelligence platform that may create, receive, maintain, process, analyze, or transmit Protected Health Information ("PHI") on behalf of Covered Entities in connection with coding assistance, documentation review, coding validation, workflow support, healthcare operations, and related services.

2. DEFINITIONS

Unless otherwise defined herein, capitalized terms shall have the meanings assigned under HIPAA.

Protected Health Information (PHI)

Has the meaning assigned under 45 C.F.R. §160.103 and includes all individually identifiable health information maintained or transmitted in any form or medium.

 

Business Associate

CompleteCare, Inc., owner and operator of the CareCodeAI platform.

 

Covered Entity

Any healthcare provider, health plan, healthcare clearinghouse, or other entity subject to HIPAA that utilizes CareCodeAI.

Subcontractor

Any third party engaged by Business Associate that creates, receives, maintains, or transmits PHI on behalf of Business Associate.

Security Incident

Has the meaning assigned under HIPAA and includes attempted or successful unauthorized access, use, disclosure, modification, or destruction of information.

3. PERMITTED USES AND DISCLOSURES

Business Associate may use and disclose PHI solely as necessary to:

  • Provide CareCodeAI services.

  • Analyze clinical documentation.

  • Generate coding recommendations.

  • Generate CPT®, ICD-10, HCPCS, and modifier recommendations.

  • Provide coding rationale and coding validation insights.

  • Improve system performance, reliability, security, and functionality.

  • Troubleshoot technical issues.

  • Comply with legal and regulatory obligations.

  • Create de-identified information in accordance with 45 C.F.R. §164.514.

 

Business Associate shall not:

  • Sell PHI.

  • Use PHI for marketing purposes.

  • Use Covered Entity PHI to train public artificial intelligence models.

  • Disclose PHI except as permitted by this Agreement or required by law.

 

4. AI-ASSISTED PROCESSING

Covered Entity acknowledges and agrees that:

CareCodeAI utilizes artificial intelligence and machine learning technologies to analyze clinical documentation and generate coding-related recommendations.

CareCodeAI functions solely as a coding decision-support tool.

CareCodeAI does not:

  • Provide medical advice.

  • Diagnose medical conditions.

  • Recommend treatment.

  • Replace provider judgment.

  • Replace certified coding review.

 

All coding, billing, reimbursement, compliance, documentation, and clinical decisions remain solely the responsibility of Covered Entity.

Business Associate makes no guarantee regarding reimbursement outcomes, claim payment, audit results, coding outcomes, or regulatory compliance.

5. SAFEGUARDS

Business Associate shall implement reasonable and appropriate administrative, physical, and technical safeguards to protect PHI, including:

  • Access controls

  • Role-based permissions

  • User authentication

  • Encryption in transit where appropriate

  • Encryption at rest where appropriate

  • Audit logging

  • Secure system architecture

  • Workforce training

  • Security monitoring

  • Vulnerability management practices

 

Business Associate shall maintain safeguards designed to reasonably protect against unauthorized use or disclosure of PHI.

6. BREACH NOTIFICATION

Business Associate shall notify Covered Entity without unreasonable delay following discovery of a breach of unsecured PHI requiring notification under HIPAA.

Such notification shall include, to the extent known:

  • Nature of the incident

  • Categories of information involved

  • Corrective actions taken

  • Mitigation efforts undertaken

  • Contact information for follow-up

 

Business Associate shall cooperate with Covered Entity regarding legally required breach investigations and notifications.

7. SUBCONTRACTORS AND THIRD-PARTY SERVICE PROVIDERS

Business Associate may utilize subcontractors and service providers in connection with CareCodeAI, including cloud hosting providers, infrastructure providers, software vendors, analytics providers, payment processors, and artificial intelligence technology providers.

8. Artificial Intelligence Processing

Business Associate may utilize artificial intelligence technologies in connection with providing the CareCodeAI services.

Business Associate shall not use Covered Entity PHI to train public or third-party artificial intelligence models.

Any de-identified information used for internal product improvement shall be created in accordance with HIPAA de-identification standards and shall not identify any individual or Covered Entity.

Business Associate shall ensure that any subcontractor with access to PHI is bound by written agreements requiring protections substantially equivalent to those contained in this Agreement.

9. ACCESS, AMENDMENT, AND ACCOUNTING

To the extent applicable under HIPAA, Business Associate shall:

  • Make PHI available to Covered Entity.

  • Support requests for amendment of PHI.

  • Provide information necessary for accounting of disclosures.

 

Business Associate may satisfy such obligations through functionality made available within the CareCodeAI platform or through reasonable administrative processes.

11. RESPONSIBILITIES OF COVERED ENTITY

Covered Entity agrees to:

  • Provide only the minimum necessary PHI required for CareCodeAI services.

  • Obtain all required authorizations, consents, and permissions.

  • Not request Business Associate to use or disclose PHI in violation of HIPAA.

  • Maintain responsibility for all coding and billing decisions.

  • Review and validate all coding recommendations before use.

  • Notify Business Associate of any restrictions affecting use or disclosure of PHI.

 

12. DATA RETENTION AND DESTRUCTION

Business Associate shall retain PHI only for as long as necessary to provide services, comply with legal obligations, maintain backups, support disaster recovery processes, and satisfy contractual requirements.

Upon termination of services, Business Associate shall:​

  • Securely destroy PHI when feasible; or

  • Continue to protect PHI if return or destruction is infeasible.

Any retained PHI shall remain subject to the protections of this Agreement.

 

13. TERM AND TERMINATION

This Agreement shall remain in effect for as long as Business Associate maintains PHI on behalf of Covered Entity.

Either Party may terminate this Agreement upon written notice if the other Party materially breaches this Agreement and fails to cure such breach within thirty (30) days following notice.

Upon termination, the obligations relating to confidentiality, security, breach notification, and protection of PHI shall survive.

14. INDEMNIFICATION

Each Party shall be responsible for its own acts and omissions.

Each Party agrees to indemnify and hold harmless the other Party from claims, damages, penalties, costs, or expenses arising directly from that Party's breach of this Agreement, HIPAA, or other applicable privacy laws.

15. LIMITATION OF LIABILITY

CareCodeAI is intended to assist healthcare professionals by providing coding intelligence and workflow support.

Business Associate shall not be liable for:

  • Coding selections made by users;

  • Billing decisions;

  • Reimbursement outcomes;

  • Audit findings;

  • Regulatory actions;

  • Medical decisions;

  • Clinical outcomes; or

  • Reliance upon recommendations without independent review.

Covered Entity remains solely responsible for all final coding, billing, documentation, reimbursement, and clinical decisions.

16. GOVERNING LAW

This Agreement shall be governed by the laws of the State of Arkansas without regard to conflict-of-law principles.

Venue for any dispute arising under this Agreement shall lie exclusively in Pulaski County, Arkansas.

17. ENTIRE AGREEMENT

This Agreement constitutes the entire agreement between the Parties regarding HIPAA and PHI obligations relating to CareCodeAI.

This Agreement supersedes prior discussions concerning PHI handling for CareCodeAI and may only be amended by a written agreement executed by authorized representatives of both Parties.

18. ACCEPTANCE

Covered Entity agrees that this Agreement is incorporated into the CareCodeAI Terms of Service and becomes legally binding upon registration for, activation of, subscription to, access to, or use of the CareCodeAI platform.

No separate signature shall be required unless otherwise requested by either Party.

COMPLETECARE, INC.

Owner and Operator of CareCodeAI™

8529 Riverwood Drive
North Little Rock, Arkansas 72113

Phone: (501) 753-6800
Website: www.completecare.com

bottom of page