AbilityOS

Legal · HIPAA

Business Associate Agreement

Last updated August 13, 2026 · Grandgrowth LLC (AbilityOS)

This Business Associate Agreement ("Agreement") is entered into between Grandgrowth LLC, a North Dakota limited liability company doing business as AbilityOS ("Business Associate"), and the healthcare organization or covered entity that has accepted the AbilityOS Terms of Service ("Covered Entity"). This Agreement is incorporated into and forms part of the AbilityOS Terms of Service and is effective as of the date the Covered Entity first accesses or uses the AbilityOS platform.

Business Associate contact information:
Grandgrowth LLC (AbilityOS)
4200 James Ray Drive, Grand Forks, ND 58202
Phone: 701-470-5437
Email: hello@abilityos.net

1. Definitions

Unless otherwise defined herein, capitalized terms shall have the meanings ascribed to them under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations, including the HIPAA Privacy Rule (45 CFR Part 164, Subparts A and E), the Security Rule (45 CFR Part 164, Subparts A and C), and the Breach Notification Rule (45 CFR Part 164, Subpart D), as each may be amended from time to time (collectively,"HIPAA Rules").

  • "Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form or medium, as defined at 45 CFR §160.103, that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.
  • "Electronic Protected Health Information" or "ePHI" means PHI that is created, received, maintained, or transmitted in electronic form.
  • "Breach" has the meaning given at 45 CFR §164.402.
  • "Security Incident" has the meaning given at 45 CFR §164.304.
  • "Subcontractor" means a person or entity that Business Associate delegates a function, activity, or service to, other than in the capacity of a member of Business Associate's workforce.

2. Permitted Uses and Disclosures by Business Associate

Business Associate may use or disclose PHI only as necessary to perform the services described in the Terms of Service and as permitted or required by this Agreement or as required by law. Specifically, Business Associate may:

  • Use and disclose PHI as necessary to provide the AbilityOS platform, including hosting, data storage, processing, and technical support services;
  • Use PHI for the proper management and administration of Business Associate's operations or to carry out its legal responsibilities;
  • Disclose PHI for the proper management and administration of Business Associate, provided that (a) the disclosure is required by law, or (b) Business Associate obtains reasonable assurances from the recipient that it will be held confidentially and used or further disclosed only as required by law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any instances of which it is aware in which confidentiality has been breached;
  • Use PHI to provide data aggregation services relating to the health care operations of Covered Entity;
  • De-identify PHI in accordance with 45 CFR §164.514(b) and use de-identified information for product improvement, analytics, and research without restriction.

Business Associate shall not use or disclose PHI in a manner that would violate the Privacy Rule if done by Covered Entity, except as provided in this Section 2.

3. Obligations of Business Associate

With respect to PHI, Business Associate agrees to:

  • Safeguards. Implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, in accordance with 45 CFR §§164.308, 164.310, and 164.312.
  • No impermissible use or disclosure. Not use or disclose PHI other than as permitted or required by this Agreement or as required by law.
  • Reporting of impermissible use or disclosure. Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including breaches of Unsecured PHI as required by 45 CFR §164.410, and any Security Incidents of which it becomes aware. Business Associate shall provide such notice without unreasonable delay and in no case later than 30 calendar days after discovery of the Breach. The notice shall include, to the extent possible, the information required by 45 CFR §164.410(c).
  • Mitigation. Take reasonable steps to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of this Agreement.
  • Subcontractors. In accordance with 45 CFR §§164.308(b)(2) and 164.502(e)(1)(ii), ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such PHI.
  • Access to PHI. To the extent Business Associate holds PHI in a Designated Record Set, make PHI available to Covered Entity and, where directed by Covered Entity, to an Individual, in order to meet the requirements of 45 CFR §164.524. If an Individual requests access directly to Business Associate, Business Associate shall notify Covered Entity within 10 business days.
  • Amendment of PHI. To the extent Business Associate holds PHI in a Designated Record Set, make PHI available for amendment and incorporate any amendments directed by Covered Entity, in accordance with 45 CFR §164.526.
  • Accounting of disclosures. Maintain and make available the information required to provide an accounting of disclosures to Covered Entity or, at Covered Entity's direction, to an Individual, as necessary to satisfy Covered Entity's obligations under 45 CFR §164.528.
  • Internal practices. Make its internal practices, books, and records available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's and Business Associate's compliance with the HIPAA Rules.
  • Minimum Necessary. To the extent practicable, limit requests for and uses and disclosures of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 CFR §164.502(b) and §164.514(d).

4. Obligations of Covered Entity

Covered Entity agrees to:

  • Notify Business Associate of any limitation in Covered Entity's Notice of Privacy Practices, to the extent such limitation may affect Business Associate's use or disclosure of PHI;
  • Notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent such changes may affect Business Associate's permitted or required uses and disclosures;
  • Notify Business Associate of any restriction agreed to by Covered Entity on the use or disclosure of PHI under 45 CFR §164.522, to the extent such restriction may affect Business Associate's permitted or required uses and disclosures;
  • Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity;
  • Obtain any consent or authorization that may be required by applicable federal or state law prior to furnishing Business Associate with PHI;
  • Ensure that all workforce members who access PHI through AbilityOS are trained on and comply with applicable HIPAA requirements and Covered Entity's privacy and security policies.

5. Permissible Requests by Covered Entity

Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity, except that Business Associate may use or disclose PHI for data aggregation or management and administration purposes of Business Associate, as provided in Section 2.

6. Security Rule Compliance

With respect to ePHI, Business Associate shall comply with the applicable requirements of the Security Rule (45 CFR Part 164, Subparts A and C). Business Associate shall implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, and other requirements of the Security Rule, taking into account the factors in 45 CFR §164.306(b). Business Associate's current security practices include, without limitation: encryption of ePHI in transit and at rest, role-based access controls, audit logging, multi-factor authentication, and regular security assessments.

7. Breach Notification

In the event of a Breach of Unsecured PHI, Business Associate shall notify Covered Entity without unreasonable delay, and in any event no later than 30 calendar days after Business Associate discovers the Breach. Notification shall include, to the extent possible:

  • The identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed;
  • A brief description of what happened, including the date of the Breach and the date of discovery;
  • A description of the types of Unsecured PHI involved;
  • Any steps Individuals should take to protect themselves from potential harm;
  • A brief description of what Business Associate is doing to investigate the Breach, to mitigate harm to Individuals, and to protect against future Breaches;
  • Contact information for individuals to ask questions or learn additional information.

Breaches should be reported to Covered Entity's designated privacy or security contact. Business Associate may also be reached at hello@abilityos.net or 701-470-5437.

8. Term and Termination

Term. This Agreement shall be effective as of the date Covered Entity first uses or accesses the AbilityOS platform and shall remain in effect until terminated as provided herein or until the underlying Terms of Service terminate or expire.

Termination for Cause. Either party may terminate this Agreement and the underlying Terms of Service, effective immediately, if the other party has materially breached a provision of this Agreement and has not cured such breach within 30 days of written notice specifying the nature of the breach.

Effect of Termination. Upon termination or expiration of this Agreement for any reason, Business Associate shall, at the election of Covered Entity: (a) return to Covered Entity all PHI received from or created or received by Business Associate on behalf of Covered Entity that Business Associate still maintains in any form; or (b) destroy all PHI and retain no copies in any form. If Business Associate determines that return or destruction is infeasible, Business Associate shall provide Covered Entity with written notification of the conditions that make return or destruction infeasible and shall extend the protections of this Agreement to such PHI for as long as Business Associate maintains such PHI.

Survival. Business Associate's obligations under this Section 8 shall survive the termination or expiration of this Agreement.

9. Miscellaneous

Amendment. Business Associate may amend this Agreement from time to time to comply with changes in applicable law or regulation. Business Associate will provide notice of material amendments via the platform or to the email address on file. Continued use of the platform following such notice constitutes acceptance of the amended Agreement.

Interpretation. This Agreement shall be interpreted as broadly as necessary to implement and comply with HIPAA, the HITECH Act, and their implementing regulations. The parties agree that any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Rules.

No Third-Party Beneficiaries. Nothing in this Agreement shall confer any rights, remedies, obligations, or liabilities whatsoever upon any person or entity other than Covered Entity and Business Associate and their respective successors and permitted assigns.

Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the State of North Dakota and applicable federal law, without regard to its conflict of law provisions.

Entire Agreement. This Agreement, together with the AbilityOS Terms of Service, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous understandings, agreements, representations, and warranties regarding the subject matter.

Severability. If any provision of this Agreement is found to be unenforceable, the remaining provisions shall continue in full force and effect.

10. Execution and Acceptance

By accessing or using the AbilityOS platform, the Covered Entity acknowledges that it has read, understood, and agrees to be bound by this Business Associate Agreement. If you require a separately executed BAA, please contact us:

Grandgrowth LLC (AbilityOS)
4200 James Ray Drive
Grand Forks, ND 58202
Phone: 701-470-5437
Email: hello@abilityos.net

This Business Associate Agreement template is provided for informational purposes. AbilityOS recommends that covered entities consult with legal counsel to ensure compliance with all applicable HIPAA requirements and state law.

← Return to AbilityOSGrandgrowth LLC · Grand Forks, ND