ClearPath Professional Services LLC

BUSINESS ASSOCIATE AGREEMENT

Effective Date: Upon execution by both Parties (see signature block below)

This Business Associate Agreement ("Agreement") is entered into between ClearPath Professional Services LLC, an Ohio limited liability company ("Business Associate" or "ClearPath"), and the undersigned provider ("Covered Entity"), collectively referred to as the "Parties."

This Agreement is required under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, "HIPAA Rules").

1. Definitions

Terms used in this Agreement shall have the same meaning as defined in the HIPAA Rules. Key terms include:

2. Obligations of Business Associate

ClearPath agrees to:

3. Permitted Uses and Disclosures by Business Associate

ClearPath may use or disclose PHI only as follows:

4. Obligations of Covered Entity

Covered Entity agrees to:

5. Subcontractors

ClearPath currently uses the following subcontractors that may have access to ePHI:

ClearPath shall ensure that any additional subcontractors or agents who create, receive, maintain, or transmit PHI on ClearPath's behalf agree to the same restrictions, conditions, and requirements that apply to ClearPath under this Agreement.

6. Term and Termination

6.1 Term

This Agreement is effective as of the date signed below and shall remain in effect until terminated by either Party or until the Services agreement between the Parties is terminated, whichever occurs first.

6.2 Termination for Cause

Either Party may terminate this Agreement upon written notice if the other Party materially breaches any provision of this Agreement and fails to cure such breach within 30 days of receiving written notice of the breach.

6.3 Effect of Termination

Upon termination of this Agreement for any reason:

7. Breach Notification

In the event of a Breach of Unsecured PHI, ClearPath shall notify Covered Entity without unreasonable delay and in no case later than 5 business days after discovery. Notification shall include, to the extent possible:

8. Ohio Breach Notification

In addition to ClearPath's obligations under 45 CFR § 164.410, ClearPath acknowledges that Ohio Rev. Code § 1349.19 imposes a separate breach notification obligation with a 45-day clock running from discovery — shorter than HIPAA's 60-day clock. ClearPath's internal breach response process is designed to satisfy the shorter of the two deadlines. The 5-business-day notice obligation in Section 7 above is designed to give Covered Entity sufficient time to meet both federal and Ohio state notification requirements.

9. ClearPath Indemnification

ClearPath shall indemnify, defend, and hold harmless Covered Entity and its officers, employees, and agents from and against any third-party claims, regulatory fines, penalties, breach-notification costs (including costs of notifying affected individuals and HHS), and reasonable attorneys' fees arising directly from: (a) ClearPath's breach of this Agreement or the HIPAA Rules with respect to PHI; or (b) ClearPath's negligent or wrongful handling of PHI. This obligation does not apply to claims arising from Covered Entity's own misuse of the platform, unauthorized entry of PHI prior to BAA execution, or any act or omission of Covered Entity.

10. Miscellaneous

10.1 Amendment

The Parties agree to amend this Agreement as necessary to comply with any changes in the HIPAA Rules or other applicable law. ClearPath will provide 30 days' written notice of any required amendments.

10.2 No Third-Party Beneficiaries

Nothing in this Agreement shall confer any rights or remedies upon any person or entity other than the Parties and their respective successors and permitted assigns.

10.3 Governing Law

This Agreement shall be governed by the laws of the State of Ohio and applicable federal law, including the HIPAA Rules.

10.4 Entire Agreement

This Agreement, together with the ClearPath Terms of Service and Privacy Policy, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements and understandings.

10.5 Interpretation

Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Rules.

11. Signatures

By signing below, the Parties agree to be bound by the terms of this Business Associate Agreement.

COVERED ENTITY (Provider):

Name: ___________________________________

Title: ___________________________________

Organization: ___________________________________

Date: ___________________________________

Signature: ___________________________________

BUSINESS ASSOCIATE (ClearPath Professional Services LLC):

Name: Jesi Bentley

Title: Owner / Authorized Representative

Organization: ClearPath Professional Services LLC

Date: ___________________________________

Signature: ___________________________________