Business Associate Agreement
Last updated: September 13, 2026
How this BAA takes effect. This is Field Nine's standard Business Associate Agreement. When you agree to it during account creation, it takes effect between Field Nine and you or your organization (the Covered Entity) as of that date. If your organization needs a countersigned copy, or has its own BAA it requires vendors to sign, email support@field9.ai. If a separately executed BAA exists between us, that executed agreement controls.
This Business Associate Agreement (this "Agreement") is entered into as of the Effective Date, by and between the Covered Entity accepting this Agreement ("Covered Entity"), and Field Nine, Inc., a Delaware corporation with offices at 4277 E Meadowview Dr, Gilbert, AZ 85298 ("Business Associate" or "Field Nine"). Covered Entity and Business Associate may each be referred to as a "Party" and together as the "Parties".
Recitals
A. Covered Entity is a "covered entity" as defined in the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (collectively, "HIPAA"), including the Privacy Rule, Security Rule, and Breach Notification Rule at 45 C.F.R. Parts 160 and 164.
B. Business Associate provides services to Covered Entity that involve the use or disclosure of Protected Health Information ("PHI") as part of Field Nine's clinical documentation platform, which captures audio and video of therapy sessions through wearable devices and generates clinical documentation using artificial intelligence (the "Services").
C. The Parties intend to enter into this Agreement to comply with HIPAA, including 45 C.F.R. §§ 164.502(e) and 164.504(e), and to establish the permitted and required uses and disclosures of PHI by Business Associate.
NOW, THEREFORE, in consideration of the mutual promises set forth in this Agreement and the underlying services agreement (if any), the Parties agree as follows:
1. Definitions
Capitalized terms used but not defined in this Agreement have the meanings given to them under HIPAA. Without limiting the foregoing:
- "Breach" has the meaning set forth in 45 C.F.R. § 164.402.
- "Electronic PHI" or "ePHI" means PHI that is transmitted by or maintained in electronic media as defined in 45 C.F.R. § 160.103.
- "Protected Health Information" or "PHI" means individually identifiable health information, as defined in 45 C.F.R. § 160.103, that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.
- "Security Incident" has the meaning set forth in 45 C.F.R. § 164.304.
- "Subcontractor" means any person or entity, other than a member of Business Associate's workforce, to whom Business Associate delegates a function, activity, or service that involves the creation, receipt, maintenance, or transmission of PHI on behalf of Business Associate.
2. Obligations of Business Associate
Business Associate agrees to:
- Not use or disclose PHI other than as permitted or required by this Agreement, as required by law, or as authorized in writing by Covered Entity.
- Use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent the use or disclosure of PHI other than as provided for by this Agreement.
- Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including any Breach of Unsecured PHI and any Security Incident, without unreasonable delay and in no case later than thirty (30) calendar days after discovery.
- In accordance with 45 C.F.R. § 164.502(e)(1)(ii), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information.
- Make PHI in a Designated Record Set available to Covered Entity (or, as directed by Covered Entity, to an individual) as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524, within fifteen (15) business days of a written request.
- Make any amendment(s) to PHI in a Designated Record Set as directed by Covered Entity, or take other measures as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.526, within thirty (30) business days of a written request.
- Maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.528, within thirty (30) business days of a written request.
- To the extent Business Associate is to carry out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s).
- Make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.
3. Permitted Uses and Disclosures by Business Associate
- Business Associate may use or disclose PHI to perform the Services, provided that such use or disclosure would not violate HIPAA if done by Covered Entity.
- Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities.
- Business Associate may disclose PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that the disclosure is required by law, or Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will remain confidential, used only as required by law or for the purposes for which it was disclosed, and that the person will notify Business Associate of any breach of confidentiality.
- Business Associate may use PHI to provide Data Aggregation services to Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
- Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c) and use such de-identified information for any lawful purpose, including improvement of Business Associate's products and services.
4. Subcontractors and AI Processing
Covered Entity acknowledges that Business Associate uses third-party cloud and artificial intelligence services to process PHI in the course of providing the Services, including without limitation Google Cloud Platform and Google Vertex AI (the "AI Processors"). Business Associate represents that it has entered into a HIPAA-compliant business associate agreement with each AI Processor, and that AI Processors will not use PHI to train foundation models or for any purpose other than providing services to Business Associate.
5. Obligations of Covered Entity
- Covered Entity will notify Business Associate of any limitation(s) in its Notice of Privacy Practices that may affect Business Associate's use or disclosure of PHI.
- Covered Entity will notify Business Associate of any changes in, or revocation of, an individual's authorization to use or disclose PHI.
- Covered Entity will notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522.
- Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except as expressly permitted under Section 3 of this Agreement.
- Covered Entity is responsible for obtaining all necessary authorizations and consents from individuals (including, where applicable, parents and legal guardians of minor learners) for the recording of therapy sessions and the use and disclosure of PHI as contemplated by this Agreement and the Services.
6. Term and Termination
6.1 Term.
This Agreement is effective as of the Effective Date and continues until terminated as provided herein or until the underlying services arrangement between the Parties is terminated, whichever is later.
6.2 Termination for Material Breach.
Either Party may terminate this Agreement upon thirty (30) days' written notice to the other Party if such other Party has materially breached this Agreement and failed to cure the breach within the notice period. If cure is not feasible, the non-breaching Party may terminate immediately. If neither cure nor termination is feasible, the non-breaching Party may report the breach to the Secretary of the U.S. Department of Health and Human Services.
6.3 Effect of Termination.
Upon termination of this Agreement for any reason, Business Associate will, at Covered Entity's direction, return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity that Business Associate still maintains in any form. If return or destruction is infeasible, Business Associate will extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible. Business Associate will provide written certification of return or destruction within sixty (60) days of termination.
7. General Provisions
7.1 Regulatory References.
A reference in this Agreement to a section in HIPAA means the section as in effect or as amended.
7.2 Amendment.
The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of HIPAA and any other applicable law.
7.3 Survival.
The respective rights and obligations of Business Associate under Section 6.3 will survive termination of this Agreement.
7.4 Interpretation.
Any ambiguity in this Agreement will be resolved in favor of a meaning that permits Covered Entity to comply with HIPAA.
7.5 Governing Law.
This Agreement is governed by the laws of the State of Arizona, without regard to its conflicts of laws principles, except to the extent preempted by federal law.
7.6 No Third-Party Beneficiaries.
Nothing in this Agreement is intended to create, nor will it be construed to create, any rights in any third party.
7.7 Entire Agreement.
This Agreement, together with any underlying services agreement between the Parties, constitutes the entire agreement between the Parties with respect to the subject matter hereof. In the event of any conflict between this Agreement and any other agreement between the Parties with respect to PHI, this Agreement will control.
7.8 Counterparts; Electronic Signatures.
This Agreement may be executed in counterparts, each of which is deemed an original, and all of which together constitute one and the same agreement. Electronic signatures are valid and enforceable, and acceptance of this Agreement during Field Nine account creation constitutes a valid electronic signature by Covered Entity.
Signatures
Accepted electronically. Checking the agreement box during Field Nine account creation executes this Agreement on behalf of Covered Entity as of that date, signed for Business Associate by Ben Rakozy, COO, Field Nine, Inc. Organizations that prefer a wet-ink or countersigned copy can request one at support@field9.ai.