Business Associate Agreement
Last updated
This is a template, not an executed agreement. Publishing it unsigned is deliberate — it lets you and your compliance counsel read the terms before asking for it. It takes effect only when both parties sign a copy. Creating an account on The Arsenal does not put a BAA in place.
To request execution, email judewakim@wakimworks.com with your legal entity name and signatory.
Do you actually need one?
Often, no — and it's worth knowing why before you ask.
HIPAA applies to covered entities: health plans, health care providers who transmit electronically, and clearinghouses. Life insurance is an "excepted benefit" and is excluded from HIPAA's definition of a health plan (45 C.F.R. § 160.103). A producer who sells only life products is therefore generally not a covered entity, Wakim Works is generally not a business associate, and a BAA is generally not legally required — even though The Arsenal holds detailed medical information.
You likely do want one if:
- you also sell Medicare Advantage, Medicare Supplement, health, dental, vision, or other products that make you a covered entity or a business associate of one;
- you receive protected health information from a carrier, plan, or provider that is itself a covered entity; or
- your agency, upline, or a carrier requires one as a condition of doing business, regardless of whether the statute compels it.
Regardless of whether a BAA is in place, your handling of client health and financial information is governed by the Gramm-Leach-Bliley Act and your state's insurance privacy and data-security rules, and the protections described in the Privacy Policy and Section 6 of the Terms apply to every account.
Template
This Business Associate Agreement ("Agreement") is entered into by and between _______________________________ ("Covered Entity") and Wakim Works LLC, a Florida limited liability company ("Business Associate"), effective as of _______________ (the "Effective Date"). It supplements and is incorporated into the Terms of Service between the parties (the "Underlying Agreement").
1. Definitions
Terms used but not defined here have the meaning given in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 C.F.R. Parts 160, 162, and 164, as amended by the HITECH Act and the Omnibus Rule ("HIPAA Rules"). "PHI" means Protected Health Information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
2. Permitted uses and disclosures
Business Associate may use or disclose PHI only:
- to perform the services described in the Underlying Agreement — hosting, storing, encrypting, transmitting, and displaying records at Covered Entity's direction;
- as required by law;
- for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any disclosure to a third party is either required by law or made with reasonable assurances of confidentiality and of notice to Business Associate of any breach; and
- to provide data aggregation services relating to Covered Entity's health care operations, if requested.
Business Associate will not use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, and will not sell PHI or use it for marketing. Business Associate will limit uses, disclosures, and requests to the minimum necessary.
3. Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to electronic PHI, to prevent use or disclosure other than as provided by this Agreement. The measures in place are described in the Privacy Policy and include envelope encryption of sensitive fields backed by a managed key service, encryption in transit and at rest, mandatory multi-factor authentication, server-enforced per-account access control, and a tamper-evident change log.
4. Reporting
Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement of which it becomes aware, any Security Incident, and any Breach of Unsecured PHI. Notification of a Breach will be made without unreasonable delay and in no case later than thirty (30) calendar days after discovery, and will include the information reasonably available to Business Associate under 45 C.F.R. § 164.410(c). Unsuccessful Security Incidents that do not result in unauthorised access — such as routine scans, pings, and blocked login attempts — are reported on request rather than individually.
5. Subcontractors
Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement, in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2). Business Associate's infrastructure subcontractors are listed in the Privacy Policy.
6. Individual rights
Business Associate will:
- make PHI in a Designated Record Set available to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524 (access), including in electronic form where requested;
- make amendments to PHI in a Designated Record Set as directed by Covered Entity under 45 C.F.R. § 164.526;
- maintain and make available the information required to provide an accounting of disclosures under 45 C.F.R. § 164.528; and
- to the extent Business Associate carries out any of Covered Entity's obligations under Subpart E, comply with the requirements that apply to Covered Entity in performing them.
Requests received by Business Associate directly from an individual will be forwarded to Covered Entity rather than answered.
7. Availability to the Secretary
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Rules.
8. Term and termination
This Agreement takes effect on the Effective Date and continues until terminated or until all PHI is returned or destroyed. Covered Entity may terminate this Agreement and the Underlying Agreement if Business Associate materially breaches this Agreement and fails to cure within thirty (30) days of written notice.
On termination, Business Associate will return or destroy all PHI it maintains, and will require the same of its subcontractors. Where return or destruction is infeasible — for example PHI residing in encrypted backups pending their scheduled expiry, or in the tamper-evident change log whose integrity depends on not being selectively altered — Business Associate will extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it is retained.
9. Miscellaneous
The parties will amend this Agreement as necessary for the parties to comply with the HIPAA Rules. Any ambiguity is resolved in favour of a meaning that permits compliance with the HIPAA Rules. Except as expressly modified here, the Underlying Agreement remains in full force; in the event of conflict regarding PHI, this Agreement controls. This Agreement is governed by the laws of the State of Florida, except where preempted by federal law. There are no third-party beneficiaries.
10. Signatures
This template is not executed and creates no obligations until signed by both parties.
- Covered Entity
- Name: _____________________ Title: _____________________ Date: ____________
- Business Associate
- Wakim Works LLC By: _____________________ Title: _____________________ Date: ____________
Requesting execution
- judewakim@wakimworks.com
- Include
- Your legal entity name, the signatory's name and title, and whether your compliance team requires changes to this template
© 2026 Wakim Works LLC.
Also see the Terms of Service, the Privacy Policy, and the Beta Supplement.