Caspio logo Try Free
  • Platform
    • Why Caspio
      Why Caspio
      • Platform Overview
      • What is Low Code
      • Visual App Builder
      • Database
      • Identity Management
      • Automations
      • AI Capabilities
      • Integrations
      • Customer Stories
    • shield-check
      Security & Compliance
      • HIPAA Compliance
      • SOC 2 Compliance
      • FERPA Compliance
      • WCAG Compliance
      • Compliance Overview
      • Trust Center
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Solutions
    • Industries
      By Industry
      • Healthcare
      • Education
      • Government
      • Financial Services
      • Energy and Utilities
      • Nonprofits
      • Media
      • Consulting
    • Use Case
      By Use Case
      • HIPAA Compliant Apps
      • Custom CRM
      • Excel to Web
      • Finance Management
      • Asset Management
      • Patient Portal
      • Web Dashboard
      • MS Access to Cloud
    • document-generation
      App Templates
      • Custom CRM
      • Patient Portal
      • Knowledge Base
      • Project Management
      • Support Ticketing System
      • Contact Management
      • Task Management
      • View All
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Build
    • mouse-click-icon
      Build It Yourself
      • Tutorials
      • Starter Apps
      • Caspio Academy
    • professional_services_icon
      Work With Experts
      • Professional Services
      • Managed Application Services
      • Work With a Partner
      • Onboarding
      • Expert Sessions
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Resources
    • book
      Learn
      • Caspio Academy
      • Get Certified
    • signed-BAA_icon
      Explore
      • Blogs
      • Podcast
      • Events
      • Customer Stories
      • View All
    • store_icon
      Marketplace
      • Starter Apps
      • App Blocks
      • Extensions
      • Customizations
      • Vertical Solutions
      • View All
    • Launch-faster-icon
      Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Pricing
    • Money-on-palm-icon
      Pricing Plans
      • Standard Plans
      • Caspio HIPAA Edition
      • Compliance Edition
    • Launch-faster-icon
      Getting Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • High Contrast
  • search
  • Contact Sales
  • Support
    • Online Help
    • Community Forum
    • Contact Support
  • Log in
Get a Demo Try Free

Caspio Business Associate Agreement

This Business Associate Agreement (“BAA”) is made between Caspio Inc., a Delaware corporation (“Caspio”) and _____________________________ (“CE”), the registered holder of the HIPAA Account (defined below).

This BAA is effective as of ___________________ (“Effective Date”), which is the date when both parties have completed signing this BAA.

This BAA may be incorporated as an attachment with the Caspio Platform Terms of Service available at https://www.caspio.com/legal/caspio-platform-terms-of-service/ or other agreement between you and Caspio governing your use of Caspio Services (“Agreement”).

This BAA may be electronically signed by the parties in accordance with the terms of the electronic signature service provider.

RECITALS

  1. CE is a “covered entity” under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191 (“HIPAA”) and 45 CFR Part 160.103. The CE represents that as a covered entity, it is required to enter into so-called “business associate” contracts with certain contractors that may have access to certain health- related personal information regulated by HIPAA. If the CE does not qualify as a covered entity as outlined above, the terms of this agreement shall be null and void.
  2. Pursuant to the Agreement, Caspio provides certain services to CE, including the provision of the Account and the services accessible within that Account. To facilitate Caspio’s provision of such services, CE wishes to transfer certain information to Caspio from time to time, some of which may constitute Protected Health Information (defined below).
  3. Any account which collects, transfers or deals with any PHI (defined below) must have a fully executed BAA with Caspio on file, and as such, be a subscriber of Caspio’s HIPAA compliant infrastructure in order for the data in the account to be considered as PHI and for the Account to be considered as a covered entity.
  4. CE and Caspio acknowledge that Caspio provides a platform and toolset that may enable CE to build HIPAA compliant applications. However, it is the sole responsibility of the CE to utilize the tools provided by Caspio in the correct manner in order to ensure that the resulting application built within the Caspio platform does comply with all of the requirements of HIPAA. Further, it is acknowledged herein that certain features of the standard Caspio platform are modified or disabled inside of the Caspio HIPAA environment due to their inability to conform to HIPAA requirements.
  5. CE and Caspio desire to protect the privacy, and provide for the security, of Protected Health Information within the Account in compliance with HIPAA, the Health Information Technology for Economic and Clinical Health Act of 2009, Public Law 111-005 (“HITECH Act”), and HIPAA Regulations (defined below) promulgated thereunder by the U.S. Department of Health and Human Services and other applicable laws, including without limitation state patient privacy laws, as such laws may be amended from time to time.
  6. As part of the HIPAA Regulations, the Privacy Rule and the Security Rule (each defined below) require CE to enter into a contract with Caspio containing specific requirements prior to the disclosure of Protected Health Information, as set forth in, but not limited to, Title 45, s 164.314(a), 164.502(e) and 164.504(e) of the Code of Federal Regulations (“C.F.R.”) and contained in this BAA.

NOW, THEREFORE, in consideration of the mutual promises below and the exchange of information pursuant to this BAA, CE and Caspio agree as follows:

1. Definitions

Capitalized terms not otherwise defined in this BAA shall have the meanings assigned to such terms under HIPAA, the HITECH Act, and the HIPAA Regulations (collectively, “Privacy Laws”), as applicable.

The following terms shall have the following meanings in this BAA:

“Account” is a Caspio Platform account (i) that is designated by Caspio as a HIPAA compatible account on Exhibit A; (ii) that uses only the HIPAA Eligible features to store and transmit any “Protected Health Information” as defined below; and (iii) to which you have applied HIPAA compliant processes and controls. For the purposes of this BAA, the “Account” refers to your HIPAA compliant account subscription.

“EPHI” means Protected Health Information that is maintained in or transmitted by electronic media.

“HIPAA Regulations” means, collectively, the Privacy, Security, Breach Notification and Enforcement Rules at 45 CFR Parts 160 and 164.

“Privacy Rule” means the HIPAA Regulation that is codified at 45 C.F.R. Parts 160 and 164, Subparts A and E.

“Protected Health Information” or “PHI” shall have the same meaning as 45 C.F.R. §160.103.

“Protected Information” means PHI provided by CE to Caspio or created or received by Caspio Platform application users on CE’s behalf in connection with the Account provided by Caspio pursuant to the Platform Terms of Service.

“Security Rule” means the HIPAA Regulation that is codified at 45 C.F.R. Parts 160 and 164, Subparts A and C.

“Suspended HIPAA Account” refers to the Account when it has been suspended pursuant to Section 6(b) (Suspension Events).

“Suspension Period” means the maximum period of time for which Caspio is obligated to maintain a Suspended HIPAA Account before closing it, given a specific reason for the suspension. Suspension Periods exist to provide CE with an opportunity to export or back up its Account data before the closure of the Account. For purposes of this BAA, the Suspension Period shall be for thirty (30) days from the date that Caspio notifies CE that their account has been suspended.

“Unsecured PHI” has the meaning given to such term under 42 U.S.C. § 17932(h), 45 C.F.R. § 164.402 and guidance issued pursuant to the HITECH Act including, but not limited to that issued on April 17, 2009 and published in 74 Federal Register 19006 (April 27, 2009), by the Secretary of the U.S. Department of Health and Human Services (“Secretary”).

2. Applicability

This BAA applies only to HIPAA Accounts. you acknowledge that this BAA does not apply to any other accounts you may have now or in the future, and that any of your accounts that do not satisfy all of the HIPAA Account requirements are not subject to this BAA. HIPAA eligible services include Caspio Platform with its data management and application authoring capabilities excluding Caspio FileStor, non-secure DataHub connections and certain messaging services. It also includes password-protected application deployment through SSL. Non-SSL deployment is not available. Caspio may, in its sole discretion, from time to time add or remove Services to the HIPAA Eligible Services.

3. Obligations of Caspio

  1. Permitted Access, Use or Disclosure. Caspio may not use or disclose PHI in a manner that would violate Privacy Laws if done by CE, except as permitted or required by this BAA. Caspio agrees that it shall keep confidential all PHI protected under Privacy Laws that Caspio receives, accesses, or otherwise obtains under and/or in connection with this BAA, and will only use or disclose PHI as permitted or required by this BAA and the Agreement, or required by law. To the extent Caspio is to carry out one or more of CE’s obligations under Subpart E of 45 CFR Part 64, Caspio will comply with the requirements of Subpart E that apply to CE. Except as otherwise limited in the Agreement or this BAA, Caspio may access, use, or disclose Protected Information:
    1. to perform its services as specified in the Agreement and as permitted in this BAA;
    2. to de-identify Protected Health Information in accordance with 45 CFR 164.514(a)-(c), and shall be permitted to use such de-identified information as permitted by applicable law and
    3. for the proper administration of Caspio, provided that such access, use, or disclosure would not violate HIPAA, the HITECH Act, the HIPAA Regulations, or applicable state law if done or maintained by CE.
  2. Minimum Necessary. Caspio shall request, use, and disclose only the minimum amount of Protected Information necessary to accomplish the purpose of the request, use, or disclosure. Because the definition of “minimum necessary” is in flux, Caspio, making reasonable efforts, will keep itself informed of guidance issued by the qualified governmental entity with respect to what constitutes “minimum necessary.” Notwithstanding the foregoing, the parties agree that based on the nature of the services provided to CE by Caspio under the Agreement, Caspio may be unable to determine what constitutes “minimum necessary” under HIPAA, and thus Caspio shall be entitled to rely on CE’s direction as to what constitutes “minimum necessary” with respect to the access, use, or disclosure of CE’s Protected Information in the possession or under the control of Caspio.
  3. Disclosures to Subcontractors and/or Third Parties. Caspio shall ensure that all representatives, subcontractors, persons and/or entities to whom Caspio discloses or provides the PHI execute a written agreement, as required under the Privacy Laws, in which such third persons and/or entities expressly agree to the same restrictions and conditions that apply to Caspio with respect to the PHI. If a Caspio agreement is not required by the Privacy Laws, Caspio shall obtain reasonable assurances from all persons and entities who have access to, or are recipients of, the PHI that: (i) the PHI shall be held confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the third party; and (ii) the third party shall promptly notify Caspio of any Compromise of PHI, and Caspio shall, in turn, notify CE.
  4. Availability of Books and Records. Caspio shall make its internal practices, books, and such records as are not protected by applicable legal privilege or work product protection relating to the use, disclosure, and/or compromise of PHI available to the Secretary of the United States, Department of Health and Human Services and/or other authorized lawful authority as required by law or authorized by CE in writing, to determine compliance with applicable Privacy Laws.
  5. Prohibited Uses and Disclosures. Notwithstanding any other provision in this BAA, Caspio shall comply with the following requirements:
    1. Caspio shall not use or disclose Protected Information for fundraising or marketing purposes, except as provided under the Agreement and consistent with Privacy Laws;
    2. Caspio shall not directly or indirectly receive remuneration in exchange for Protected Information, except with the prior written consent of CE and as permitted by Privacy Laws; however, this prohibition shall not affect payment by CE to Caspio for services provided pursuant to the Agreement.
  6. Appropriate Safeguards. Caspio shall use commercially reasonable efforts to prevent the unauthorized or unlawful access of Protected Information and shall implement appropriate safeguards designed to protect the confidentiality of Protected Information. Caspio shall use administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of EPHI. Caspio shall comply with each of its obligations under the applicable requirements of the Security Rule.
  7. Access to Protected Information. To the extent Caspio maintains a Designated Record Set on behalf of the CE outside CE’s Caspio Account, Caspio shall make Protected Information maintained by Caspio or its agents or subcontractors in Designated Record Sets available to CE for inspection and copying within 10 days of a request by CE to enable CE to fulfill its obligations under the Privacy Rule. If Caspio maintains an Electronic Health Record, Caspio shall provide such information in electronic format to enable CE to fulfill its obligations under Privacy Laws. To the extent that a patient makes a request to Caspio for a Designated Record Set or Electronic Health Record that Caspio maintains on behalf of the CE, Caspio shall forward such request to the CE within 10 calendar days of receipt and advise the patient that the CE will respond to the request. CE agrees that it, and not Caspio, is responsible for responding to the patient to fulfill its obligations under the Privacy Laws.
  8. Amendment of PHI. To the extent Caspio maintains a Designated Record Set on behalf of CE outside CE’s Caspio Account, within 10 days of receipt of a request from the CE for an amendment of Protected Information or a record about an individual contained in a Designated Record Set, Caspio or its agents or subcontractors shall make Protected Information available to CE so that CE may make any amendments that CE directs or agrees to in accordance with the Privacy Rule.
  9. Accounting Rights. To the extent Caspio uses and discloses Protected Information, Caspio and its agents or subcontractors shall maintain and make available to CE within 10 days of notice by CE of a request for an accounting of disclosures of Protected Information the information required to provide an accounting of disclosures to enable CE to fulfill its obligations under Privacy Laws. Any requests made to Caspio for an accounting shall be referred to CE within five (5) business days. CE shall be responsible for responding to all requests from Individuals for an accounting, and shall reimburse Caspio for any costs associated with providing such an accounting. CE acknowledges that any uses and disclosures it makes using CE’s Caspio Account must be documented by CE for purposes of providing an accounting under Privacy Laws and is not the responsibility of Caspio.
  10. Restrictions. Caspio shall comply with all reasonable and required restrictions on the use and disclosure of PHI requested by individuals granted by CE upon receipt of notice provided under Section 4(g) (Restrictions and Revocations). Caspio shall refer Individuals requesting restrictions on the use and disclosure of PHI directly from Caspio to CE within five (5) business days from the date Caspio receives any such request. CE shall be responsible for responding to requests from Individuals for restrictions.

4. Obligations of CE

  1. Identification of Accounts. Only the accounts on Exhibit A are designated as Accounts. None of CE’s other accounts with Caspio, if any, may contain PHI.
  2. Acceptable Collection Methods. Accounts must be “HIPAA-enabled” accounts. CE acknowledges that once the Account becomes a HIPAA-enabled account, that classification is irreversible. CE may only create, transmit, receive, maintain, and otherwise access PHI through HIPAA-enabled accounts.
  3. Subscription Plan. Only certain Caspio subscription plans support HIPAA-enabled accounts (“HIPAA Subscription Plans”), and this BAA may only be entered into if the Account is under a HIPAA Subscription Plan. For example, if CE is not a HIPAA Subscriber, this BAA may only be entered into if the applicable account is migrated under a Caspio HIPAA Subscription Plan. CE must maintain the Account under a HIPAA Subscription Plan and may not downgrade or otherwise change the Account to a subscription plan that is not a HIPAA Subscription Plan. Caspio will not remove support for HIPAA-enabled accounts from a HIPAA Subscription Plan during the Term. In order for this BAA to be applicable, the Account must be in good standing and CE must be current in paying the fees that commensurate with being a HIPAA Subscriber.
  4. Appropriate Use of Accounts. CE is responsible for implementing appropriate access, privacy and security safeguards in order to protect PHI in compliance with HIPAA and this BAA.
  5. Appropriate Configuration. CE is solely responsible for configuring, and will configure, all Accounts as follows:
    1. Establish each and every user of your account with strong passwords and require them to replace their password at least every 3 months with another strong password. CE is responsible for verifying the identity of Caspio Platform Users and maintaining users’ profiles, access rights and the management of their activities inside the Caspio Platform. Further, CE is responsible for the same as it relates to any of CE application users, for applications that are built and deployed using the Caspio platform.
    2. Require all Account administrators, application authors and application users to become trained and fully aware of HIPAA requirements, as needed given individual access levels.
    3. Apply Authentication to every DataPage and Application that transmits PHI.
    4. Require and enforce strong passwords for application users and require them to change their passwords frequently.
  6. Necessary Consents. CE shall obtain any necessary authorizations, consents, and other permissions that may be required under applicable law prior to placing PHI in a Caspio Account.
  7. Restrictions and Revocations. CE will promptly notify Caspio in writing of any patient-requested restrictions, changes to, or revocation of, consent and/or authorization to use and/or disclose PHI that may affect Caspio’s ability to perform its obligations under this BAA and the Agreement. CE will not agree to any restriction requests or place any restrictions in any Notice of Privacy Practices (“Notice”) that would cause Caspio to violate this BAA or any applicable law.
  8. Notice of Privacy Practices. CE will promptly provide Caspio a copy of its Notice, and any changes to the Notice that may affect Caspio’s use or disclosure of PHI or performance of this BAA.
  9. Accounting of PHI Disclosures. CE will include in individual accountings requested under the Privacy Laws, including without limitation, 45 C.F.R. § 164.528, any disclosures by Caspio.
  10. Compliance with HIPAA. CE shall not request Caspio to access, use, or disclose Protected Information, nor to otherwise act, in any manner that would not be permissible under HIPAA or the HITECH Act if done by CE. CE shall not request Caspio take any action that is inconsistent with Privacy Laws or this BAA.

5. Reporting of Improper Access, Use or Disclosure

  1. Generally. Caspio shall promptly notify CE of any Security Incident of which Caspio becomes aware and/or any access, use, or disclosure of Protected Information in violation of the Agreement, this BAA, and/or Privacy Laws of which it becomes aware. Caspio shall take: (i) prompt corrective action to cure any deficiencies in its policies and procedures that may have led to the incident; and (ii) any action pertaining to such unauthorized access, use, or disclosure required of Caspio by applicable federal and state laws and regulations. The parties agree that this section satisfies any notices necessary by Caspio to CE of the ongoing existence and occurrence of attempted but Unsuccessful Security Incidents (as defined below) for which no additional notice to CE shall be required. For purposes of this BAA, “Unsuccessful Security Incidents” include activity such as pings and other broadcast attacks on Caspio’s firewall, port scans, unsuccessful log-on attempts, denials of service and any combination of the above, so long as no such incident results in unauthorized access, use or disclosure of electronic PHI.
  2. Breaches of Unsecured PHI. Without limiting the generality of the reporting requirements set forth in Section 5(a), Caspio also shall notify CE of a Breach of Unsecured PHI in writing without unreasonable delay and in no case later than 5 business days after discovery. The notice shall include the following information if known (or can be reasonably obtained) by Caspio: (i) contact information for the individuals who were or who may have been impacted by the Breach (e.g., first and last name, mailing address, email address); (ii) a brief description of the circumstances of the Breach, including the date of the Breach and date of discovery (as defined in 42 U.S.C. § 17932(c)); (iii) a description of the types of Unsecured PHI involved in the Breach (e.g., names, social security numbers, date of birth, addresses, account numbers of any type, disability codes, diagnostic and/or billing codes and similar information); and (iv) a brief description of what Caspio has done or is doing to investigate the Breach and to mitigate harm to the individuals impacted by the Breach.
  3. Mitigation. Caspio shall mitigate, to the extent practicable, any deleterious effects known to Caspio of any unauthorized or unlawful access or use or disclosure of Protected Information not authorized by the Agreement, this BAA, or Privacy Laws; provided, however, that unless otherwise agreed in writing by the parties or required by Privacy Laws, such mitigation efforts shall not require Caspio to bear the costs of notifying individuals impacted by such unauthorized or unlawful access, use, or disclosure of Protected Information. Caspio shall remain fully responsible for all aspects of its reporting duties to CE under this Section 5.
  4. Meet and Confer. Upon any suspected or actual Breach, unauthorized disclosure of the PHI or breach of this BAA, CE will meet and confer in good faith with Caspio before notifying affected individuals, government agencies, and/or commencing any legal action.

6. Term and Termination

  1. Term. This BAA shall be effective as of the Effective Date and shall continue until the Agreement is terminated (the “Term”).
  2. Suspension Events.
    1. Lapsed Account. The Account is provided to CE by Caspio on a paid subscription basis, which means that the Account must be periodically renewed in accordance with the Agreement if CE wishes to continue receiving services from Caspio in connection with the Account. If the Account is not renewed, or if CE fails to pay any fees due in relation to the Account (such as renewal, overages and consulting fees), Caspio may suspend CE’s access to the Account. In such case, CE may reinstate the Account by renewing it, or paying any overdue fees due in relation to it (as the case may be), before the end of the Suspension Period.
    2. Breach by CE. If CE materially breaches this BAA and the breach is not cured by CE within 15 days of receiving written notice of such breach, Caspio may suspend and ultimately terminate the Account upon notice to the CE. In such case, the Account may only be reinstated at the discretion of Caspio and only if the breach is cured.
    3. Suspended Account. If Caspio suspends the Account, Caspio will preserve all data contained in the Suspended Account for the Suspension Period, but functionality for the Account will be disabled (except for certain billing and account administration functions) and the Protected Information will no longer be directly accessible to CE through the Account’s online interface. All Protected Information contained in the Suspended Account will continue to be subject to this BAA. During the Suspension Period, CE may:
      1. Access the Suspended Account to retrieve billing details and make account payments to bring the account current, and in such case Caspio shall remove the Account from Suspended status;
      2. Submit a written request to Caspio for an export of CE’s data contained in the Suspended HIPAA Account. The fulfillment of this request will be subject to the CE bringing the account current and paying all past due amounts and paying for applicable fees relating to the export service. Caspio will use commercially reasonable efforts to fulfill such request promptly; and
      3. Close its Suspended Account by submitting a written notice to Caspio. Caspio will fulfill such closure request promptly upon receiving the notice and final payment for its services rendered to the effective date of termination. Further, Caspio may respond to an individual customer or patient’s request for access to their individual PHI record or records by exporting the subject data to the CE for provision to the individual whose PHI is contained in the Caspio system. In this circumstance, CE shall provide a copy of the customer/patient’s written request. Caspio shall invoice the CE for the applicable access fees for exporting the records.
  3. Effect of Account Closure. This BAA will terminate upon the termination of the underlying Terms of Service and closure of the applicable Account (including termination by Caspio at the end of the Suspension Period). If CE requests Caspio to close the Account, CE is solely responsible for ensuring that such closure will not cause CE or Caspio to violate any applicable laws.
  4. Termination. This BAA may be terminated:
    1. by CE upon written notice if Caspio materially breaches this BAA and the breach is not cured by Caspio within 30 business days of receiving written notice of such breach; or
    2. by Caspio for any reason upon 90 days’ prior written notice, provided that Caspio shall provide reasonable assistance to CE to destroy or return any of CE’s Protected Information before the effective date of termination. In such case, CE will be entitled to receive a pro rata refund of any fees prepaid by the Customer applicable to the Account for the period following the closure of the Account;
    3. by Caspio at the end of the Suspension Period should the CE not act to remedy the issue which led to the Account’s suspension; or
    4. by CE or Caspio should CE or Caspio choose not to renew Caspio’s services in accordance with its rights under the Agreement.
  5. Effect of Termination. Upon termination of this BAA:
    1. the Account will be closed by Caspio; and
    2. Caspio shall, if feasible, return or destroy within thirty (30) days of the Account’s termination all Protected Information that Caspio or its agents or subcontractors still maintain in any form, and shall retain no copies of such Protected Information. If return or destruction is not feasible, Caspio shall continue to extend the protections of this BAA to such information, and limit further use of such Protected Information to those purposes that make the return or destruction of such Protected Information infeasible. CE acknowledges that it is CE’s responsibility to export or backup any PHI that it wishes to retain before any termination is effected and Caspio shall have no responsibility for any liability that may arise from any data loss caused as a result of that termination.

7. Compliance with State Law

Nothing in this BAA shall be construed to require Caspio to use or disclose Protected Information without a written authorization from an individual who is a subject of the Protected Information, or without written authorization from any other person, where such authorization would be required under state law for such use or disclosure, or otherwise violate applicable state law.

8. Amendments to Comply with Law

Because state and federal laws relating to data security and privacy are rapidly evolving, amendment of the Agreement or this BAA may be required to provide for procedures to ensure compliance with such developments. Caspio and CE shall take such action as is necessary to implement the standards and requirements of HIPAA, the HITECH Act, and other applicable laws relating to the security or confidentiality of PHI. Upon the request of either party, the other party shall promptly enter into negotiations concerning the terms of an amendment to this BAA embodying written assurances consistent with the standards and requirements of HIPAA, the HITECH Act, or other applicable laws. If such negotiations are unsuccessful, either party may terminate this BAA and close the Account upon 30 days’ written notice to the other party.

9. No Third-Party Beneficiaries

Nothing express or implied in the Agreement or this BAA is intended to confer, nor shall anything herein confer upon any person other than CE, Caspio and their respective successors or permitted assigns, any rights, remedies, obligations or liabilities whatsoever.

10. Indemnification

Subject to the limitations defined in Section 11 (Limitation of Liability) below, each party (an “Indemnifier”) shall indemnify and hold harmless the other party (the “Indemnified”) from and against any and all fines, losses, liabilities, expenses, damages or injuries that the Indemnified sustains as a result of, or arises out of, a third party claim that: (a) the Indemnifier has violated an applicable law or regulation (including the HIPAA Regulations) in connection with this BAA, or (b) arises out of a breach of this BAA by the Indemnifier or its agents or subcontractors (including the unauthorized use or disclosure of any Protected Information).

11. Limitation of Liability

  1. DIRECT DAMAGES. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL A PARTY BE LIABLE TO THE OTHER FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, SPECIAL OR EXEMPLARY DAMAGES (EVEN IF THAT PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES), ARISING IN CONNECTION WITH THIS BAA (INCLUDING SUCH DAMAGES INCURRED BY THIRD PARTIES), SUCH AS, BUT NOT LIMITED TO DATA LOSS, LOSS OF REVENUE OR ANTICIPATED PROFITS OR LOST BUSINESS , EXCEPT IN THE CASE OF , A BREACH OF SECTION 12 (CONFIDENTIALITY) OR CLAIMS BASED ON GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.
  2. LIABILITY CAP. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY’S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS BAA, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED THE LESSER OF THE TOTAL AMOUNTS ACTUALLY PAID BY CE TO US UNDER THE AGREEMENT FOR THE SERVICE THAT GAVE RISE TO THE CLAIM DURING THE 12 MONTHS PRECEDING THE INCIDENT CAUSING THE LIABILITY, OR ONE HUNDRED THOUSAND DOLLARS (US$100,000).

12. Confidential Information

  1. Confidentiality. Caspio shall use the Protected Information only to exercise its rights and fulfill its obligations under this BAA or the Agreement. Caspio will not disclose the Protected Information, except to its affiliates, officers, employees, directors, agents, contractors, legal counsel, financial advisors, and other similar professionals who need to know it (“Representatives”) and who have agreed to treat the Protected Information in accordance with the confidentiality provisions in this BAA. Caspio will be responsible for any actions of its Representatives in violation of this Section 12. Caspio may disclose the Protected Information when required by law, regulation, legal process, or court order.
  2. Exceptions. For the purposes of Section 12 (Confidentiality) only, the confidentiality obligations therein do not cover Protected Information that: (a) Caspio already lawfully knew at the time of receipt from CE; (b) becomes public through no fault of Caspio; (c) was independently developed by Caspio without reference to the Protected Information; or (d) was rightfully and lawfully given to Caspio by a third party who did not acquire that information through a breach of confidence.

13. Notices

All notices hereunder shall be in writing and shall be deemed to have been duly given if delivered personally, by overnight courier or, in the case of notices to CE, by email, addressed as follows:

To CE: ________________________________________________________________________

By email to the Account’s registered email address (as may be updated by CE from time to time), and by copy, to the Account’s main contact and address as entered in the Caspio Platform.

To Caspio:

Caspio, Inc. 1286 Kifer Road, Suite 107, Sunnyvale, CA 94086 USA Attn: Legal Department

With a copy by email to legal@caspio.com or to such other persons or places as Caspio may from time to time designate by written notice to CE.

14. General

  1. Interpretation; Precedence. The provisions of this BAA shall prevail over any provisions in the Agreement that conflict or appear inconsistent with any provision in this BAA. This BAA and the Agreement shall be interpreted as broadly as necessary to implement and comply with HIPAA and the HITECH Act. Any ambiguity in this BAA shall be resolved in favor of a meaning that complies and is consistent with HIPAA and the HITECH Act. Except as specifically required to implement the purposes of this BAA, or to the extent inconsistent with this BAA, all other terms of the Agreement shall remain in force and effect.
  2. Entire Agreement. This BAA supersedes any and all prior and contemporaneous business associate agreements or addenda between the parties with respect to the Account and any Additional Accounts (defined below) and constitutes the final and entire agreement between the parties hereto with respect to the subject matter hereof. Each party to this BAA acknowledges that no representations, inducements, promises, or agreements, oral or otherwise, with respect to the subject matter hereof, have been made by either party, or by anyone acting on behalf of either party, which are not embodied herein. No other agreement, statement or promise, with respect to the subject matter hereof, not contained in this BAA shall be valid or binding.
  3. Regulatory References. A reference in this BAA to a section of regulations means the section as in effect or as amended, and for which compliance is required.
  4. Amendments. Caspio may propose amendments to this BAA by written notice to CE (including by email to the email address associated with the Account). If CE does not object to such amendments in writing within 30 days of such notice, the amendments will become effective on the day following the end of the notice period, or such later date as may be stated in the amendments. If CE objects to such amendments in writing within the aforementioned notice period, and either a) the CE and Caspio have not agreed to a revised amendment agreed to in writing by both parties, or b) Caspio has not revoked the proposed amendments before the end of such period, then CE may terminate this BAA immediately, or at the end of the notice period, by written notice to Caspio.
  5. Governing Law and Jurisdiction. This BAA is governed by the laws of the State of California, without regard to its conflict of law rules. Each party submits to the exclusive jurisdiction of the state courts located in Santa Clara County and the federal courts located in the Northern District of California with respect to the subject matter of this BAA.
  6. Assignment. Neither party may assign this BAA or the Agreement without the consent of the other party (such consent not to be unreasonably withheld). Notwithstanding the foregoing, Caspio may assign this BAA to an affiliate or to a successor or acquirer, as the case may be, in connection with a merger, acquisition, corporate reorganization, or the sale of all or substantially all of Caspio’s assets, provided that the assignee agrees to be bound by the terms of this BAA. In such case, Caspio may also assign the Agreement to the third party to which the BAA was assigned.

15. Additional Covered Accounts

CE may, from time to time, enter into additional agreements with Caspio under which Caspio supplies CE with services via additional accounts. For any new account to be enabled and designated as a HIPAA Account, CE must receive a written confirmation from Caspio stating that the new account has been designated as a HIPAA compliant account.

AMENDMENT NO. 1

to the Caspio Business Associate Agreement
Artificial Intelligence Provisions — Last updated July 31, 2026

This Amendment No. 1 (“Amendment”) amends the Business Associate Agreement between Caspio, Inc. (“Caspio”) and the covered entity counterparty identified therein (“CE”) (the “BAA”). This Amendment is effective in accordance with Section 14(d) (Amendments) of the BAA. Capitalized terms used but not defined in this Amendment have the meanings given in the BAA. Except as expressly modified by this Amendment, the BAA remains in full force and effect. In the event of a conflict between this Amendment and the BAA, this Amendment controls with respect to its subject matter.

RECITALS

Caspio has introduced artificial intelligence features and services, certain of which are operated with the assistance of third-party artificial intelligence subcontractors engaged by Caspio under written agreements imposing HIPAA-required restrictions and conditions consistent with Section 3(c) of the BAA. Those subcontractor agreements permit PHI to be processed only through designated eligible services and subject to specific healthcare-related restrictions. Caspio provisions its artificial intelligence subcontractor accounts in the configurations required for HIPAA eligibility under Caspio’s agreements with such subcontractors, as standard for all Caspio accounts; such configurations are not a customer election and apply without further action by CE. The parties enter into this Amendment to (i) identify which Caspio artificial intelligence features may be used with PHI, and (ii) set out the restrictions and conditions applicable to such use.

1. DEFINITIONS

“AI Features” means, collectively, the artificial intelligence and machine learning features and services made available by Caspio, including in-platform AI tools (such as “Caspi” (formerly branded AI Assistant) and the embedded AI agent feature of the Caspio platform (however branded), and the AI Connector Extensions), the Caspio MCP Server, and the managed AI Solutions offered in the Caspio Marketplace (including Live AI Agent, Respond AI Agent, and Listener AI Agent).

“AI Connector Extensions” means the Caspio extensions, however branded or renamed from time to time, that connect an Account to a third-party artificial intelligence model provider, including the extension currently branded AI-Powered GPT Connect and any successor or additional extensions made available for other model providers.

“HIPAA-Eligible AI Features” means only those AI Features expressly designated by Caspio in writing (including in Exhibit A-1 to this Amendment or in Caspio’s published HIPAA documentation) as eligible for use with PHI in a HIPAA-enabled Account, subject to any configuration requirements stated in such designation.

“AI Outputs” means content generated by an AI Feature in response to inputs provided by or on behalf of CE.

“Healthcare Activities” means use of AI Features in connection with healthcare activities, including without limitation the practice of medicine, billing, coding, claims processing, or clinical research.

2. AI FEATURES AND PHI

2.1 General Rule. CE shall not create, transmit, receive, maintain, disclose, or otherwise process PHI through any AI Feature other than a HIPAA-Eligible AI Feature used in accordance with its designated configuration requirements, except as provided in Section 2.4 (Customer-Controlled AI Connections). CE shall ensure that its workforce, application users, and End Users comply with this Section.

2.2 AI Solutions Excluded. The managed AI Solutions (including Live AI Agent, Respond AI Agent, and Listener AI Agent) are not HIPAA-Eligible AI Features, are not covered by the BAA, and shall not be used to collect, receive, process, or transmit PHI. Any PHI provided to an AI Solution is provided outside the scope of the BAA.

2.3 Designations. The AI Features designated as HIPAA-Eligible AI Features as of the Version date of this Amendment are those identified in Exhibit A-1, subject to the configurations and conditions stated therein. Caspio may add or remove designations by written notice, and removal of a designation shall be treated as a modification to the HIPAA environment and not as a breach of the BAA, provided Caspio gives CE at least thirty (30) days’ notice where reasonably practicable. A designation may cover an AI Feature in whole or as to specified capabilities only (including any file or knowledge-base capability) and subject to specified configurations; capabilities and configurations not specified in a designation are not covered.

2.4 Customer-Controlled AI Connections. Certain AI Features enable CE to connect its Account to artificial intelligence services under CE’s own vendor relationship, including an AI Connector Extension when configured with CE’s own API key and third-party artificial intelligence clients connected through the Caspio MCP Server (collectively, “Customer-Controlled AI Connections”). PHI transmitted through a Customer-Controlled AI Connection is transmitted outside the scope of the BAA and this Amendment and is not covered by any business associate agreement between Caspio and its subcontractors. CE is solely responsible for determining whether to transmit PHI through a Customer-Controlled AI Connection and, if it elects to do so, for first entering into its own business associate agreement with the applicable vendor and configuring the connection (including any required retention or processing settings) in accordance with that agreement and applicable law. Caspio’s responsibility with respect to Customer-Controlled AI Connections is limited to the authentication, permission-scoped access, and audit logging controls that Caspio provides on its side of the connection. Customer-Controlled AI Connections are disabled by default on HIPAA Accounts and may be enabled only by CE’s account administrator; enabling a Customer-Controlled AI Connection constitutes CE’s acknowledgment of this Section 2.4.

3. CONDITIONS ON USE OF HIPAA-ELIGIBLE AI FEATURES

CE’s use of any HIPAA-Eligible AI Feature with PHI is subject to the following conditions, which CE acknowledges implement restrictions imposed on Caspio by its artificial intelligence subcontractors:

3.1 Accuracy Testing. Prior to and during any use of a HIPAA-Eligible AI Feature in connection with Healthcare Activities, CE will test such feature for accuracy in CE’s use cases and, to the extent CE provides AI Outputs to any other person or entity, disclose to such recipients any limitations associated with the AI Outputs.

3.2 Qualified Personnel. CE will ensure that only duly trained and qualified individuals who maintain the licenses, certifications, or other authorizations required to perform the applicable Healthcare Activities use HIPAA-Eligible AI Features, or use or disclose AI Outputs, in connection with such Healthcare Activities.

3.3 Transparency. CE will not represent to any person that services performed by an AI Feature were performed by a human, or that AI Outputs were human-generated.

3.4 No Medical Device Use. CE will not use any AI Feature or AI Output in a manner that constitutes, or would require clearance or approval as, a medical device, and acknowledges that AI Features and AI Outputs are not intended to substitute for the function or services of properly trained and licensed individuals, including physicians and other clinicians, billing, coding, or claims personnel, or clinical researchers.

3.5 Content Responsibility. CE is solely responsible for: (a) the development, content, and integrity of inputs containing PHI; (b) ensuring accurate matching (including patient matching) so that inputs are properly matched to AI Outputs; and (c) ensuring that AI Outputs are provided to the appropriate recipient.

3.6 Third-Party Recipients. To the extent CE provides AI Outputs to another covered entity, business associate, or other third party, CE will require such party, by written agreement or equivalent binding terms, to comply with all laws and regulations applicable to its use of the AI Outputs and with obligations substantially equivalent to Sections 3.2 through 3.4.

3.7 Training. CE will train its workforce and other relevant data custodians on their obligations under this Amendment and ensure compliance therewith.

3.8 State Law; Consents. CE is responsible for confirming that its use of AI Features with identifiable health information complies with applicable state and federal laws, including state health privacy and sensitive-condition laws that are more restrictive than HIPAA, and represents that it has obtained all consents, authorizations, and permissions required by applicable law for such use.

4. DISCLAIMERS

Notwithstanding any warranties or other terms in the Agreement or the BAA, and without limiting any disclaimers therein, Caspio is not responsible or liable for any advice, course of treatment, diagnosis, or other information or services that any patient or other individual may obtain in reliance on AI Outputs; for billing, coding, or claims activities conducted by CE; or for the accuracy, completeness, or suitability of any data or information used in any Healthcare Activities.

5. LIABILITY

CE’s indemnification obligations under Section 10 of the BAA extend to any and all fines, losses, liabilities, expenses, damages, or injuries arising out of CE’s breach of this Amendment, including any transmission of PHI through an AI Feature that is not a HIPAA-Eligible AI Feature. Notwithstanding Section 11 of the BAA, CE’s indemnification obligations arising from a breach of Section 2 (AI Features and PHI) of this Amendment are not subject to the liability cap set forth in Section 11(b) of the BAA.

6. MISCELLANEOUS

This Amendment is incorporated into and made part of the BAA. Section 14 (General) of the BAA applies to this Amendment. All other terms and conditions of the BAA remain unchanged.

EXHIBIT A-1 — HIPAA-ELIGIBLE AI FEATURES

HIPAA-Eligible AI Features, including the specific capabilities (such as any file or knowledge-base capability) and required configurations covered for each, are those identified in Caspio’s published HIPAA documentation or within the product, as updated from time to time in accordance with Section 2.3. Any AI Feature or capability not so identified is not HIPAA-eligible, and PHI processed through it is provided outside the scope of the BAA. Customer-Controlled AI Connections are governed by Section 2.4 regardless of any such identification.

Specimen – not effective until executed.

  • PRODUCT

  • Platform Overview
  • What Is Low Code?
  • Case Studies
  • Marketplace
  • Pricing
  • Get a Custom Demo
  • Free Trial
  • SOLUTIONS

  • Healthcare
  • Education
  • Government
  • Financial Services
  • Energy and Utilities
  • Nonprofits
  • Media
  • Consulting
  • RESOURCES

  • Resource Center
  • Caspio Academy
  • Online Help
  • Onboarding
  • Get Certified
  • Professional Services
  • Managed Application Services
  • Support Center
  • Legal Center
  • COMPANY

  • Our Story
  • Careers
  • Leadership
  • News
  • Partner Programs
  • Referral Program
  • Academic Program
  • Discount Programs
  • Contact Us
  • TRENDING

  • HIPAA Compliance
  • SOC 2 Type 2 Compliance
  • FERPA Compliance
  • Build Custom CRM
  • Create Web Dashboards
  • Best Online Database
  • Build a Mini CRM SaaS in 1 Hour
  • Go Paperless With Web Forms
  • Launch Patient Portal
Caspio Logo

Caspio is the world’s leading cloud platform for building online database applications without coding.
Start a free trial today and experience the power of no-code.

Footer Partners

© 2026 Caspio, Inc. Sunnyvale, California. All rights reserved.

  • Privacy Statement
  • Terms of Use
  • Report Abuse
  • Sitemap
  • Feedback
  • Platform
    • Why Caspio
      • Platform Overview
      • What is Low Code
      • Visual App Builder
      • Database
      • Identity Management
      • Automations
      • AI Capabilities
      • Integrations
      • Customer Stories
    • Security & Compliance
      • HIPAA Compliance
      • SOC 2 Compliance
      • FERPA Compliance
      • WCAG Compliance
      • Compliance Overview
      • Trust Center
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Solutions
    • By Industry
      • Healthcare
      • Education
      • Government
      • Financial Services
      • Energy and Utilities
      • Nonprofits
      • Media
      • Consulting
    • By Use Case
      • HIPAA Compliant Apps
      • Custom CRM
      • Excel to Web
      • Finance Management
      • Asset Management
      • Patient Portal
      • Web Dashboard
      • MS Access to Cloud
    • App Templates
      • Custom CRM
      • Patient Portal
      • Knowledge Base
      • Project Management
      • Support Ticketing System
      • Contact Management
      • Task Management
      • View All
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Build
    • Build It Yourself
      • Tutorials
      • Starter Apps
      • Caspio Academy
    • Work With Experts
      • Professional Services
      • Managed Application Services
      • Work With a Partner
      • Onboarding
      • Expert Sessions
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Resources
    • Learn
      • Caspio Academy
      • Get Certified
    • Explore
      • Blogs
      • Podcast
      • Events
      • Customer Stories
      • View All
    • Marketplace
      • Starter Apps
      • App Blocks
      • Extensions
      • Customizations
      • Vertical Solutions
      • View All
    • Get Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • Pricing
    • Pricing Plans
      • Standard Plans
      • Caspio HIPAA Edition
      • Compliance Edition
    • Getting Started
      • Free Trial
      • Request a Consultation
      • Contact Sales
  • search
  • Contact Sales
  • Support
    • Online Help
    • Community Forum
    • Contact Support
  • Log in
Get a Demo Try Free
High Contrast