FaxTerra

Business Associate Agreement

This is the agreement every account that adds HIPAA compliance executes, as it reads today. The executed copy, with the signer’s name, title, organization and the time of execution, is stored in the account and emailed to the signer when it is signed.

Version 2026-10-09.1

This Business Associate Agreement ("Agreement") is entered into between the customer organization identified in the execution block below ("Covered Entity") and Developing Media LLC, operating as FaxTerra ("Business Associate"), and is effective as of the date of electronic execution. This Agreement governs Business Associate's creation, receipt, maintenance, and transmission of Protected Health Information on behalf of Covered Entity in the course of providing online facsimile transmission, receipt, and storage services (the "Services").

1. Definitions

Terms used but not otherwise defined in this Agreement have the same meaning as those terms in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164, as amended (the "HIPAA Rules"), including "Breach," "Data Aggregation," "Designated Record Set," "Disclosure," "Health Care Operations," "Individual," "Minimum Necessary," "Notice of Privacy Practices," "Protected Health Information" ("PHI"), "Required by Law," "Secretary," "Security Incident," "Subcontractor," "Unsecured Protected Health Information," and "Use."

For purposes of this Agreement, PHI is limited to the Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity through the Services.

2. Obligations and Activities of Business Associate

(a) Business Associate shall not Use or Disclose PHI other than as permitted or required by this Agreement or as Required by Law.

(b) Business Associate shall use appropriate safeguards, and shall comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to electronic PHI, to prevent Use or Disclosure of PHI other than as provided for by this Agreement. These safeguards include encryption of PHI in transit (TLS 1.2 or higher) and at rest (storage-level encryption plus per-document AES-256-GCM application-layer encryption for documents stored under an account on which HIPAA compliance is active).

(c) Business Associate shall report to Covered Entity any Use or Disclosure of PHI not provided for by this Agreement of which it becomes aware, any Security Incident of which it becomes aware, and any Breach of Unsecured PHI as required by 45 CFR § 164.410, without unreasonable delay and in no case later than thirty (30) calendar days after discovery. Such report shall include, to the extent known, the identity of each Individual whose Unsecured PHI was or is reasonably believed to have been involved and the other information required by 45 CFR § 164.410(c). With respect to unsuccessful Security Incidents (such as pings, port scans, and login attempts that do not result in unauthorized access to PHI), the parties agree this paragraph constitutes notice, and no further reporting of such unsuccessful incidents is required.

(d) In accordance with 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement, including compliance with the Security Rule with respect to electronic PHI.

(e) To the extent PHI in a Designated Record Set is maintained through the Services, Business Associate shall make such PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.524. The Services provide Covered Entity direct self-service access to its stored documents, which the parties agree satisfies this obligation.

(f) Business Associate shall make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 CFR § 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.526.

(g) Business Associate shall maintain and make available to Covered Entity the information required to provide an accounting of Disclosures as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.528.

(h) Business Associate shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary for purposes of determining compliance with the HIPAA Rules.

(i) Business Associate shall, to the extent practicable, limit its Uses, Disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose.

3. Permitted Uses and Disclosures by Business Associate

(a) Business Associate may Use and Disclose PHI as necessary to perform the Services for Covered Entity: transmitting outbound facsimile documents to recipients designated by Covered Entity, receiving inbound facsimile documents addressed to Covered Entity's fax number(s), and storing such documents for Covered Entity's retrieval subject to the retention settings on Covered Entity's account.

(b) Business Associate may Use or Disclose PHI as Required by Law.

(c) Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, and may Disclose PHI for such purposes only if the Disclosure is Required by Law or Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will be held confidentially, used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and that the person will notify Business Associate of any instances of which it is aware in which the confidentiality of the PHI has been breached.

(d) Business Associate shall not Use or Disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 (the Privacy Rule) if done by Covered Entity, except as permitted under paragraph (c) of this Section.

(e) Business Associate does not de-identify PHI, sell PHI, or use PHI for marketing purposes.

4. Obligations of Covered Entity

(a) Covered Entity shall notify Business Associate of any limitation(s) in its Notice of Privacy Practices under 45 CFR § 164.520, to the extent that such limitation may affect Business Associate's Use or Disclosure of PHI.

(b) Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an Individual to Use or Disclose PHI, to the extent that such changes may affect Business Associate's Use or Disclosure of PHI.

(c) Covered Entity shall notify Business Associate of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's Use or Disclosure of PHI.

(d) Covered Entity shall not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted under Section 3(c).

5. Term and Termination

(a) Term. This Agreement is effective as of the date of electronic execution and shall terminate when HIPAA compliance ends on Covered Entity's account, whether by its removal or by the end of Covered Entity's subscription, or when all PHI is destroyed or returned to Covered Entity in accordance with paragraph (c), whichever is later.

(b) Termination for Cause. Either party may terminate this Agreement (and the underlying Services for Covered Entity's account) if the other party has materially breached this Agreement and has not cured the breach within thirty (30) days of written notice.

(c) Obligations at Termination. Upon termination of this Agreement for any reason, Business Associate shall return or destroy all PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form. Covered Entity may retrieve its stored documents through the Services before its account closes; document deletion follows the account's retention settings and account-deletion process. If return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further Uses and Disclosures to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.

6. Miscellaneous

(a) Regulatory References. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

(b) Amendment. The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of the HIPAA Rules. Business Associate may amend this Agreement prospectively by notice to Covered Entity where required for HIPAA compliance; continued use of the Services after notice constitutes acceptance.

(c) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.

(d) No Third-Party Beneficiaries. Nothing in this Agreement confers any rights upon any person other than the parties and their respective successors.

(e) Electronic Execution. This Agreement is executed electronically. Covered Entity's acceptance through the Services, recorded with the signer's name, title, organization, timestamp, and network address, constitutes a valid and binding execution.

HIPAA Service Terms

Eligibility and scope

You represent that your organization is a Covered Entity or a Business Associate under HIPAA, and that the individual executing the BAA is authorized to bind the organization.

HIPAA protections (per-document encryption, PHI-free notifications, the executed BAA) apply to your account only while HIPAA compliance is active on it. Do not transmit PHI through the Services before HIPAA compliance is active on your account or after it ends.

Your responsibilities

Verify recipient fax numbers before sending. A fax delivered to the number you entered is a completed transmission, even if the number was entered in error.

Do not include PHI in support requests, account profile fields, cover-page sender/recipient name fields, or any other free-text field outside a fax document itself. Support channels are not a PHI-safe environment.

Notification emails are PHI-free by design; the email addresses on your account control who receives them. Keep those addresses limited to your workforce.

The Services are a transmission and short-term storage tool, not a medical record system of record. Configure your document retention settings to match your organization's policies, and export documents you need to retain.

Agreement version 2026-10-09.1

How each control the agreement names is implemented is on the HIPAA controls page, and the add-on that executes it is the HIPAA compliance add-on. Back to the Trust Center.