This agreement is presented and accepted when a clinic or firm creates a MediLink organization. We are also glad to execute it by signature, or to review your own BAA form, on request.
Last updated: July 24, 2026
This Business Associate Agreement ("BAA") is entered into between the customer organization accepting it ("Covered Entity" or "Customer") and MediLink LLC ("Business Associate" or "MediLink"), and is incorporated into and made part of the MediLink Terms of Service. It is effective as of the date the Customer creates a MediLink organization account ("Effective Date"). In the event of a conflict between this BAA and the Terms of Service with respect to Protected Health Information ("PHI"), this BAA controls.
Capitalized terms used but not defined here have the meanings given in the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Rules"), including: Breach, Data Aggregation, Designated Record Set, Electronic PHI ("ePHI"), Individual, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, and Unsecured PHI. "PHI" here means only the PHI MediLink creates, receives, maintains, or transmits on behalf of Customer.
MediLink may use or disclose PHI only:
MediLink will not use or disclose PHI in any manner that would violate the HIPAA Rules if done by Customer, and will limit uses, disclosures, and requests to the minimum necessary.
MediLink will: (a) implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI as required by the Security Rule (45 C.F.R. Part 164, Subpart C), including encryption of ePHI in transit and at rest, role-based access controls, tenant isolation, and audit logging; (b) maintain written information security policies; and (c) train workforce members with access to PHI.
MediLink will report to Customer: (a) any use or disclosure of PHI not permitted by this BAA of which it becomes aware; (b) any Security Incident of which it becomes aware, except that this section serves as notice — no further reporting required — of routine unsuccessful attempts (e.g., pings, port scans, denied login attempts) that do not result in unauthorized access; and (c) any Breach of Unsecured PHI without unreasonable delay, and in no event later than ten (10) business days after discovery, including (to the extent known) the identities of affected Individuals and the information described in 45 C.F.R. § 164.404(c) so that Customer can meet its own notification obligations.
MediLink will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those in this BAA. MediLink's current subprocessors are listed at medilink.vip/subprocessors ; MediLink will update that list before adding a subprocessor that handles PHI.
To the extent MediLink holds PHI in a Designated Record Set, MediLink will, within fifteen (15) business days of Customer's written request, make PHI available to Customer as needed to satisfy an Individual's rights of access (§ 164.524) and amendment (§ 164.526), and will incorporate amendments Customer directs. MediLink will document disclosures and provide the information Customer needs to respond to a request for an accounting of disclosures (§ 164.528). If an Individual contacts MediLink directly, MediLink will forward the request to Customer rather than respond directly.
MediLink will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules.
Customer will: (a) not request or configure any use or disclosure that would violate the HIPAA Rules; (b) notify MediLink of any restriction on use or disclosure of PHI that Customer has agreed to or any change in, or revocation of, an Individual's permission, to the extent it affects MediLink's permitted uses; and (c) obtain any authorizations or consents required for disclosures Customer directs through the platform (including sharing with partnered organizations or a patient's legal representative).
This BAA is effective for as long as MediLink holds PHI on Customer's behalf. Either party may terminate this BAA (and the underlying services with respect to PHI) if the other materially breaches it and fails to cure within thirty (30) days of written notice. Upon termination of the services, MediLink will, at Customer's election exercised within sixty (60) days, return or destroy all PHI it maintains, if feasible. If return or destruction is infeasible, MediLink will extend the protections of this BAA to the retained PHI and limit further use or disclosure to the purposes that make return or destruction infeasible.
(a) The parties will amend this BAA as necessary to comply with changes in the HIPAA Rules; MediLink may update this BAA prospectively by posting a new version with a new version date and providing notice through the platform. (b) Nothing in this BAA confers rights on any third party. (c) Any ambiguity will be interpreted to permit compliance with the HIPAA Rules. (d) This BAA does not apply to customer organizations that are not Covered Entities or Business Associates under HIPAA (e.g., law firms acting on a patient's authorization).
---
*Accepted electronically at organization creation. MediLink records the acceptance timestamp and BAA version on the organization record. A copy of this document is available at medilink.vip/baa.*