Business Associate Agreement

The HIPAA contract between DARO Clinical and each practice that stores patient information in DARO. Version 2026-09-26.

1. Parties and purpose

This Business Associate Agreement ("Agreement") is entered into between the healthcare practice or organization that accepts it (the "Covered Entity") and HyGenesis LLC, a Florida limited liability company, doing business as DARO Clinical (the "Business Associate"). It takes effect on the date the Covered Entity accepts it inside DARO and remains in effect for as long as the Business Associate creates, receives, maintains or transmits Protected Health Information on the Covered Entity's behalf.

This Agreement is required by the Health Insurance Portability and Accountability Act of 1996, the HITECH Act, and their implementing regulations at 45 CFR Parts 160 and 164 (together, "HIPAA"). It is incorporated into, and governed by, the DARO Terms of Service. Where this Agreement and the Terms of Service conflict on the handling of Protected Health Information, this Agreement controls.

Capitalized terms not defined here have the meaning given to them in HIPAA. "Protected Health Information" or "PHI" means protected health information, as defined at 45 CFR 160.103, that the Business Associate creates, receives, maintains or transmits for the Covered Entity.

2. Permitted uses and disclosures

The Business Associate may use and disclose PHI only to perform the services described in the Terms of Service — hosting the clinical record, scheduling, intake, ambient note drafting and transcription, orders and results handling, coding and billing support, patient communications, reporting, and customer support — and only as this Agreement, the Terms of Service or law permits.

The Business Associate may use PHI for its own proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes only where the disclosure is required by law or where the Business Associate obtains reasonable assurances from the recipient that the information will be kept confidential, used only as required by law or for the purpose for which it was disclosed, and that the recipient will notify the Business Associate of any breach of confidentiality.

The Business Associate may de-identify PHI in accordance with 45 CFR 164.514(a)-(c) and use the resulting de-identified data to operate, support, secure and improve the service. De-identified data is no longer PHI.

The Business Associate will not sell PHI, will not use or disclose PHI for marketing or advertising, and will not use PHI to train general-purpose or third-party artificial intelligence models. Any use or disclosure not permitted by this Agreement is prohibited.

The Business Associate will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by the Covered Entity, except as permitted by 45 CFR 164.504(e)(4) for the Business Associate's management, administration and legal responsibilities.

3. Minimum necessary

The Business Associate will request, use and disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure, consistent with 45 CFR 164.502(b) and 164.514(d).

4. Safeguards

The Business Associate will use appropriate administrative, physical and technical safeguards, and will comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as this Agreement provides.

Those safeguards include: encryption of PHI in transit using industry-standard transport security and encryption at rest; logical separation of each practice's data; role-based access control with individually identified user accounts; multi-factor authentication for privileged and clinical roles; session locking; recorded break-glass access; audit logging of record access retained for at least six years; daily backups with point-in-time recovery and rehearsed restores; vulnerability management; and workforce training and confidentiality obligations.

5. Subcontractors and subprocessors

In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), the Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to the Business Associate under this Agreement.

The current list of subprocessors is published on the DARO Subprocessors page. The Business Associate will give the Covered Entity at least 30 days' notice before adding a subprocessor that will handle PHI.

6. Reporting and breach notification

The Business Associate will report to the Covered Entity any use or disclosure of PHI not permitted by this Agreement of which it becomes aware, including any Security Incident and any Breach of Unsecured PHI, as required by 45 CFR 164.410.

Notice of a Breach of Unsecured PHI will be given without unreasonable delay and in no case later than 5 business days after discovery. The notice will identify, to the extent known, the individuals affected, the nature of the information involved, what happened and when, what the Business Associate is doing in response, and any other information the Covered Entity reasonably needs to meet its own notification duties under 45 CFR 164.404 through 164.408. The Business Associate will supplement the notice as further information becomes available.

Unsuccessful Security Incidents that do not result in unauthorized access, use, disclosure, modification or destruction of PHI — such as routine port scans, blocked sign-in attempts and denied network traffic — are reported to the Covered Entity on request rather than individually.

The Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement.

7. Individual rights

Access. The Business Associate will make PHI in a Designated Record Set available to the Covered Entity so the Covered Entity can meet its obligations under 45 CFR 164.524, including electronic copies in a readable electronic form. The Covered Entity can export its complete record set from DARO at any time.

Amendment. The Business Associate will make PHI in a Designated Record Set available for amendment, and will incorporate amendments directed by the Covered Entity, as required by 45 CFR 164.526.

Accounting of disclosures. The Business Associate will document disclosures of PHI and related information as required for the Covered Entity to respond to a request for an accounting under 45 CFR 164.528, and will provide that information to the Covered Entity on request.

Restrictions and confidential communications. The Business Associate will honor restrictions on use or disclosure and requests for confidential communications that the Covered Entity records in DARO and communicates to the Business Associate.

Requests made directly to the Business Associate by an individual are referred to the Covered Entity. The Covered Entity remains responsible for responding to individuals.

8. Access to books and records

The Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining the Covered Entity's compliance with HIPAA. The Business Associate will notify the Covered Entity of any such request unless prohibited by law.

9. Obligations of the Covered Entity

The Covered Entity will obtain any consents, authorizations and notices required by law, including its own Notice of Privacy Practices, and will notify the Business Associate of any limitation in that notice, of any change in or revocation of an individual's permission, and of any restriction it has agreed to, to the extent any of these affect the Business Associate's use or disclosure of PHI.

The Covered Entity will not ask the Business Associate to use or disclose PHI in a way that would violate HIPAA if done by the Covered Entity. The Covered Entity is responsible for the accuracy of the records it maintains, for its own clinical and billing decisions, and for managing who on its workforce has access to DARO.

Demonstration, sample and sandbox practices in DARO contain fabricated patients only. The Covered Entity will not enter real patient information into them.

10. Term and termination

This Agreement begins on the date of acceptance and continues until all PHI is returned or destroyed, or protections are extended under this section.

The Covered Entity may terminate this Agreement and the underlying service if the Business Associate materially breaches this Agreement and does not cure the breach within 30 days of written notice, or immediately if cure is not possible.

On termination, the Business Associate will return or destroy all PHI it maintains for the Covered Entity, and will require its subcontractors to do the same. The Covered Entity has at least 90 days after termination to export its complete records. Where return or destruction is not feasible, the Business Associate will extend the protections of this Agreement to that PHI and limit further use and disclosure to the reasons that make return or destruction infeasible, for as long as it retains the information.

Sections covering permitted uses, safeguards, reporting, records access and termination obligations survive termination for as long as the Business Associate retains any PHI.

11. General terms

The parties agree to amend this Agreement as necessary to comply with changes in HIPAA or other applicable law. Any ambiguity is resolved to permit compliance with HIPAA.

This Agreement does not create any third-party beneficiary rights. It is governed by the laws of the State of Florida, without regard to conflict-of-laws rules, except where HIPAA or other federal law controls.

Nothing in this Agreement makes the Business Associate a provider of medical care. DARO is documentation, workflow and billing software; the clinician who signs a note is responsible for its content.

Notices under this Agreement may be given to the Business Associate at privacy@daroclinical.com, and to the Covered Entity at the administrative contact on its DARO account.

Acceptance inside DARO by an authorized representative of the Covered Entity constitutes execution of this Agreement. DARO records the signer's name, title, email, the date and time, the IP address and the browser used, and stores a copy of the exact text accepted.