← ClearPath Compliance
ClearPath Professional Services LLC
BUSINESS ASSOCIATE AGREEMENT
Effective Date: Upon execution by both Parties (see signature block below)
This Business Associate Agreement ("Agreement") is entered into between ClearPath Professional Services LLC, an Ohio limited liability company ("Business Associate" or "ClearPath"), and the undersigned provider ("Covered Entity"), collectively referred to as the "Parties."
This Agreement is required under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and their implementing regulations at 45 CFR Parts 160 and 164 (collectively, "HIPAA Rules").
1. Definitions
Terms used in this Agreement shall have the same meaning as defined in the HIPAA Rules. Key terms include:
- "Protected Health Information" or "PHI" means any individually identifiable health information transmitted or maintained in any form or medium, as defined in 45 CFR § 160.103, that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.
- "Electronic PHI" or "ePHI" means PHI that is created, received, maintained, or transmitted in electronic form.
- "Breach" has the meaning set forth in 45 CFR § 164.402.
- "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations.
- "Services" means the ClearPath provider documentation platform and related services provided to Covered Entity.
2. Obligations of Business Associate
ClearPath agrees to:
- Not use or disclose PHI other than as permitted or required by this Agreement or as required by law
- Use appropriate administrative, physical, and technical safeguards, and comply with the HIPAA Security Rule (45 CFR Part 164, Subpart C) with respect to ePHI, to prevent unauthorized use or disclosure of PHI
- Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which ClearPath becomes aware, including breaches of unsecured PHI as required by 45 CFR § 164.410, without unreasonable delay and in no case later than 5 business days after discovery
- Report to Covered Entity any Security Incident of which ClearPath becomes aware
- Ensure that any subcontractors or agents that create, receive, maintain, or transmit PHI on behalf of ClearPath agree to restrictions and conditions at least as stringent as those in this Agreement
- Make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations to provide individuals with access to their PHI under 45 CFR § 164.524
- Make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations to amend PHI under 45 CFR § 164.526
- Maintain and make available the information required to provide an accounting of disclosures as required by 45 CFR § 164.528
- To the extent ClearPath carries out one or more of Covered Entity's obligations under the Privacy Rule, comply with the requirements of the Privacy Rule that apply to Covered Entity in performance of those obligations
- Make its internal practices, books, and records available to the Secretary of Health and Human Services for purposes of determining Covered Entity's or ClearPath's compliance with the HIPAA Rules
3. Permitted Uses and Disclosures by Business Associate
ClearPath may use or disclose PHI only as follows:
- To perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the ClearPath Terms of Service, provided such use or disclosure would not violate the HIPAA Rules if done by Covered Entity
- For ClearPath's proper management and administration, provided that (a) such uses are permitted by law; or (b) ClearPath obtains reasonable assurances that the information will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed
- To provide data aggregation services relating to the health care operations of Covered Entity, using only de-identified data
- As required by law
4. Obligations of Covered Entity
Covered Entity agrees to:
- Notify ClearPath of any limitations in Covered Entity's Notice of Privacy Practices that may affect ClearPath's use or disclosure of PHI
- Notify ClearPath of any changes in, or revocation of, permission by an individual to use or disclose PHI, if such changes affect ClearPath's permitted or required uses and disclosures
- Not request that ClearPath use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity
- Not enter any PHI into the ClearPath platform until this Agreement has been fully executed by both Parties
- Ensure that all staff and agents who use ClearPath on behalf of Covered Entity are aware of and comply with the terms of this Agreement
5. Subcontractors
ClearPath currently uses the following subcontractors that may have access to ePHI:
- Supabase, Inc. — database hosting and authentication (operating under a HIPAA Business Associate Agreement with ClearPath)
- Vercel, Inc. — application hosting and deployment (operating under applicable data processing agreements)
- Anthropic, PBC — used only for optional AI-assisted features (such as reading an expiration date from a certification photo). Certification images transmitted to Anthropic may contain PHI (such as a name or date of birth visible on a license or certification card). ClearPath has executed a Business Associate Agreement with Anthropic covering this use. Only the specific certification image submitted through the AI-assisted feature is transmitted; client records, Medicaid numbers, and other platform data are not sent to Anthropic. Covered Entity shall not submit any image or file that contains PHI beyond what is visible on the certification card itself through an AI-assisted feature.
ClearPath shall ensure that any additional subcontractors or agents who create, receive, maintain, or transmit PHI on ClearPath's behalf agree to the same restrictions, conditions, and requirements that apply to ClearPath under this Agreement.
6. Term and Termination
6.1 Term
This Agreement is effective as of the date signed below and shall remain in effect until terminated by either Party or until the Services agreement between the Parties is terminated, whichever occurs first.
6.2 Termination for Cause
Either Party may terminate this Agreement upon written notice if the other Party materially breaches any provision of this Agreement and fails to cure such breach within 30 days of receiving written notice of the breach.
6.3 Effect of Termination
Upon termination of this Agreement for any reason:
- ClearPath shall return or destroy all PHI received from, or created or received by ClearPath on behalf of, Covered Entity that ClearPath maintains in any form
- If return or destruction is not feasible, ClearPath shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make the return or destruction of the PHI infeasible
- Covered Entity is solely responsible for exporting its data prior to account termination, pursuant to the ClearPath Terms of Service
7. Breach Notification
In the event of a Breach of Unsecured PHI, ClearPath shall notify Covered Entity without unreasonable delay and in no case later than 5 business days after discovery. Notification shall include, to the extent possible:
- A description of what happened, including the date of the Breach and the date of discovery
- A description of the types of unsecured PHI involved
- Any steps individuals should take to protect themselves from potential harm
- A brief description of what ClearPath is doing to investigate the Breach and mitigate harm
- Contact information for ClearPath
8. Ohio Breach Notification
In addition to ClearPath's obligations under 45 CFR § 164.410, ClearPath acknowledges that Ohio Rev. Code § 1349.19 imposes a separate breach notification obligation with a 45-day clock running from discovery — shorter than HIPAA's 60-day clock. ClearPath's internal breach response process is designed to satisfy the shorter of the two deadlines. The 5-business-day notice obligation in Section 7 above is designed to give Covered Entity sufficient time to meet both federal and Ohio state notification requirements.
9. ClearPath Indemnification
ClearPath shall indemnify, defend, and hold harmless Covered Entity and its officers, employees, and agents from and against any third-party claims, regulatory fines, penalties, breach-notification costs (including costs of notifying affected individuals and HHS), and reasonable attorneys' fees arising directly from: (a) ClearPath's breach of this Agreement or the HIPAA Rules with respect to PHI; or (b) ClearPath's negligent or wrongful handling of PHI. This obligation does not apply to claims arising from Covered Entity's own misuse of the platform, unauthorized entry of PHI prior to BAA execution, or any act or omission of Covered Entity.
10. Miscellaneous
10.1 Amendment
The Parties agree to amend this Agreement as necessary to comply with any changes in the HIPAA Rules or other applicable law. ClearPath will provide 30 days' written notice of any required amendments.
10.2 No Third-Party Beneficiaries
Nothing in this Agreement shall confer any rights or remedies upon any person or entity other than the Parties and their respective successors and permitted assigns.
10.3 Governing Law
This Agreement shall be governed by the laws of the State of Ohio and applicable federal law, including the HIPAA Rules.
10.4 Entire Agreement
This Agreement, together with the ClearPath Terms of Service and Privacy Policy, constitutes the entire agreement between the Parties with respect to the subject matter hereof and supersedes all prior agreements and understandings.
10.5 Interpretation
Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Rules.
11. Signatures
By signing below, the Parties agree to be bound by the terms of this Business Associate Agreement.
COVERED ENTITY (Provider):
Name: ___________________________________
Title: ___________________________________
Organization: ___________________________________
Date: ___________________________________
Signature: ___________________________________
BUSINESS ASSOCIATE (ClearPath Professional Services LLC):
Name: Jesi Bentley
Title: Owner / Authorized Representative
Organization: ClearPath Professional Services LLC
Date: ___________________________________
Signature: ___________________________________