APALYRX BUSINESS ASSOCIATE AGREEMENT
Apaly Health Inc.
Last Updated: September 6, 2026
WHO THIS APPLIES TO
ABOUT THIS DOCUMENT
This is the standard form Business Associate Agreement of Apaly Health Inc. It is published so that participating organizations and their advisors can review it.
Where Apaly Health Inc. and an organization have executed a Business Associate Agreement separately, the executed agreement controls and this posted form does not apply to that relationship.
This Agreement does not apply to individual members or patients. It applies to organizations that are covered entities under HIPAA, or that are business associates delegating a function to Apaly Health Inc.
1. PARTIES AND APPLICATION
1.1 Parties
This Business Associate Agreement (this "BAA") is entered into between Apaly Health Inc., a Delaware corporation ("Apaly Health"), and the organization accepting it (the "Counterparty").
1.2 How This BAA Applies
This BAA is written to apply in either of two relationships. The relationship that exists determines how the defined terms operate.
1.2.1 Counterparty as Covered Entity. Where the Counterparty is a covered entity, including a group health plan or a plan sponsor acting for a group health plan, the Counterparty is the "Covered Entity" and Apaly Health is the "Business Associate."
1.2.2 Counterparty as Business Associate. Where the Counterparty is itself a business associate of a covered entity and delegates a function, activity, or service to Apaly Health, the Counterparty is treated as the "Covered Entity" for purposes of this BAA and Apaly Health is a subcontractor and is treated as the "Business Associate." In that case, this BAA operates as the flow-down agreement required by 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), the Counterparty's own obligations to its covered entity are not altered, and Apaly Health's obligations under this BAA are no less protective than those the Counterparty owes its covered entity.
1.2.3 Effective Date. This BAA is effective on the earliest of the date the Counterparty accepts it, the date Apaly Health first receives Protected Health Information from or on behalf of the Counterparty, or the effective date of any executed version.
1.3 Relationship to Other Agreements
This BAA governs Protected Health Information. As to Protected Health Information, this BAA controls over the ApalyRx Terms of Use, any Addendum to those Terms, and any other agreement between the parties, except an executed Business Associate Agreement as described above.
Nothing in this BAA modifies the commercial terms of any signed agreement between the parties.
2. DEFINITIONS
2.1 Catch-All Definition
Capitalized terms used but not otherwise defined in this BAA have the meanings given to them in the HIPAA Rules. This includes Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
2.2 Specific Definitions
2.2.1 Business Associate. "Business Associate" has the meaning given at 45 CFR 160.103 and, in reference to the parties to this BAA, means Apaly Health.
2.2.2 Covered Entity. "Covered Entity" has the meaning given at 45 CFR 160.103 and, in reference to the parties to this BAA, means the Counterparty as described in Section 1.2.
2.2.3 De-Identified Information. "De-Identified Information" means health information that has been de-identified in accordance with 45 CFR 164.514(a) through (c) and that is therefore not Protected Health Information.
2.2.4 HIPAA Rules. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
2.2.5 Services. "Services" means the functions, activities, or services Apaly Health performs for or on behalf of the Covered Entity, as described in the parties' signed agreement or, absent one, as described in the ApalyRx Terms of Use and the applicable Addendum.
2.2.6 Unsuccessful Security Incidents. "Unsuccessful Security Incidents" means, without limitation, pings and other broadcast attacks on Apaly Health's firewalls, port scans, unsuccessful log-on attempts, denials of service, and any combination of the foregoing, so long as no such incident results in unauthorized access, Use, or Disclosure of Protected Health Information.
3. OBLIGATIONS OF BUSINESS ASSOCIATE
Apaly Health shall:
- Not Use or Disclose Protected Health Information other than as permitted or required by this BAA or as Required By Law
- Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic Protected Health Information, to prevent Use or Disclosure of Protected Health Information other than as provided for by this BAA
- Report to the Covered Entity any Use or Disclosure of Protected Health Information not provided for by this BAA of which it becomes aware, including Breaches of Unsecured Protected Health Information as required at 45 CFR 164.410, and any Security Incident of which it becomes aware
- In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits Protected Health Information on behalf of Apaly Health agrees in writing to restrictions, conditions, and requirements that are at least as protective as those that apply to Apaly Health under this BAA
- Make Protected Health Information in a Designated Record Set available to the Covered Entity as necessary to satisfy the Covered Entity's obligations under 45 CFR 164.524
- Make any amendment to Protected Health Information in a Designated Record Set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy the Covered Entity's obligations under 45 CFR 164.526
- Maintain and make available the information required to provide an accounting of Disclosures as necessary to satisfy the Covered Entity's obligations under 45 CFR 164.528
- To the extent Apaly Health carries out an obligation of the Covered Entity under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to the Covered Entity in the performance of that obligation
- Make its internal practices, books, and records relating to the Use and Disclosure of Protected Health Information available to the Secretary for purposes of determining compliance with the HIPAA Rules
- Limit its Use, Disclosure, and requests for Protected Health Information to the Minimum Necessary to accomplish the intended purpose, consistent with 45 CFR 164.502(b)
4. BREACH AND SECURITY INCIDENT REPORTING
4.1 Timing
Apaly Health shall report a Breach of Unsecured Protected Health Information to the Covered Entity without unreasonable delay and in no case later than thirty calendar days after discovery, as determined under 45 CFR 164.410(a)(2).
4.2 Content
The report shall include, to the extent known at the time and as it becomes available, the identification of each Individual whose Protected Health Information was or is reasonably believed to have been accessed, acquired, Used, or Disclosed, a description of what occurred, the date of the incident and the date of discovery, the types of information involved, and the steps Apaly Health is taking to investigate, mitigate, and prevent recurrence.
4.3 Unsuccessful Security Incidents
The parties acknowledge and agree that this Section constitutes notice by Apaly Health to the Covered Entity of the ongoing existence and occurrence, or attempted occurrence, of Unsuccessful Security Incidents, for which no additional notice to the Covered Entity is required.
4.4 Mitigation
Apaly Health shall mitigate, to the extent practicable, any harmful effect known to it of a Use or Disclosure of Protected Health Information by Apaly Health in violation of this BAA.
5. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
5.1 Services
Apaly Health may Use and Disclose Protected Health Information as necessary to perform the Services.
5.2 Required By Law
Apaly Health may Use and Disclose Protected Health Information as Required By Law.
5.3 Limitation
Apaly Health shall not Use or Disclose Protected Health Information in a manner that would violate Subpart E of 45 CFR Part 164 if done by the Covered Entity, except for the specific Uses and Disclosures set forth in Sections 5.4 through 5.7.
5.4 Management and Administration
Apaly Health may Use Protected Health Information for the proper management and administration of Apaly Health or to carry out its legal responsibilities.
Apaly Health may Disclose Protected Health Information for the proper management and administration of Apaly Health or to carry out its legal responsibilities, provided the Disclosure is Required By Law, or Apaly Health obtains reasonable assurances from the person to whom the information is Disclosed that the information will remain confidential and be Used or further Disclosed only as Required By Law or for the purpose for which it was Disclosed, and that the person will notify Apaly Health of any instance of which it becomes aware in which the confidentiality of the information has been breached.
5.5 Data Aggregation
Apaly Health may Use and Disclose Protected Health Information to provide Data Aggregation services relating to the Health Care Operations of the Covered Entity, as permitted by 45 CFR 164.504(e)(2)(i)(B).
5.6 De-Identification
Apaly Health may Use Protected Health Information to create De-Identified Information in accordance with 45 CFR 164.514(a) through (c).
5.7 Use of De-Identified Information
De-Identified Information created under Section 5.6 is not Protected Health Information and is not subject to the restrictions of this BAA. As between the parties, De-Identified Information created by Apaly Health is owned by Apaly Health, and Apaly Health may Use and Disclose it for any lawful purpose, including analytics, benchmarking, research, quality measurement, reporting, and product development.
Apaly Health shall not attempt to re-identify De-Identified Information except as permitted by law, and shall not Disclose De-Identified Information in a manner that would permit a recipient to identify an Individual.
Nothing in this Section permits the sale of Protected Health Information as defined at 45 CFR 164.502(a)(5)(ii).
5.8 Affiliates
Apaly Health may Disclose Protected Health Information to its affiliates, including ApalyRx LLC and Apaly Benefits LLC, where those affiliates perform a function on behalf of Apaly Health in connection with the Services. Any affiliate receiving Protected Health Information in that capacity is a Subcontractor for purposes of Section 3, item 4, and is bound by obligations at least as protective as those in this BAA.
This Section does not address Disclosures to an affiliate acting in its own capacity as a covered entity or as a business associate of the Covered Entity, which are governed by the HIPAA Rules and by any separate agreement.
6. OBLIGATIONS OF COVERED ENTITY
6.1 Notice of Privacy Practices
The Covered Entity shall notify Apaly Health of any limitation in its Notice of Privacy Practices under 45 CFR 164.520, to the extent the limitation may affect Apaly Health's Use or Disclosure of Protected Health Information.
6.2 Changes in Permission
The Covered Entity shall notify Apaly Health of any change in, or revocation of, an Individual's permission to Use or Disclose Protected Health Information, to the extent the change may affect Apaly Health's Use or Disclosure of Protected Health Information.
6.3 Restrictions
The Covered Entity shall notify Apaly Health of any restriction on the Use or Disclosure of Protected Health Information that the Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent the restriction may affect Apaly Health's Use or Disclosure of Protected Health Information.
6.4 Authority and Accuracy
The Covered Entity represents that it has the authority to disclose Protected Health Information to Apaly Health for the purposes contemplated by this BAA and the Services, and that any authorization, consent, or other permission on which it relies is valid.
6.5 Permissible Requests
The Covered Entity shall not request Apaly Health to Use or Disclose Protected Health Information in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by the Covered Entity, except as set forth in Sections 5.4 through 5.7.
7. TERM AND TERMINATION
7.1 Term
This BAA is effective as of the Effective Date and terminates when all Protected Health Information provided by, or created or received on behalf of, the Covered Entity is returned or destroyed, or, if return or destruction is infeasible, when the protections of Section 7.4 are extended to that information.
7.2 Termination for Cause
The Covered Entity may terminate this BAA if it determines that Apaly Health has violated a material term of this BAA and Apaly Health has not cured the violation within thirty days after written notice.
Apaly Health may terminate this BAA if it determines that the Covered Entity has violated a material term of this BAA and the Covered Entity has not cured the violation within thirty days after written notice.
7.3 Effect on Other Agreements
Termination of this BAA does not by itself terminate any signed agreement between the parties or the Counterparty's access to the ApalyRx platform. Where Protected Health Information continues to flow, the obligations of this BAA continue as to that information.
7.4 Obligations on Termination
On termination, Apaly Health shall, with respect to Protected Health Information received from the Covered Entity, or created, maintained, or received by Apaly Health on behalf of the Covered Entity:
- Retain only that Protected Health Information which is necessary for Apaly Health to continue its proper management and administration or to carry out its legal responsibilities
- Return to the Covered Entity, or destroy, the remaining Protected Health Information that Apaly Health still maintains in any form
- Continue to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to electronic Protected Health Information, to prevent Use or Disclosure of the Protected Health Information other than as provided for in this Section, for as long as Apaly Health retains it
- Not Use or Disclose the Protected Health Information retained by Apaly Health other than for the purposes for which it was retained, and subject to the same conditions set out in Sections 5.4 and 5.5 that applied prior to termination
- Return to the Covered Entity, or destroy, the Protected Health Information retained by Apaly Health when it is no longer needed for its proper management and administration or to carry out its legal responsibilities
- Require its Subcontractors to comply with this Section
De-Identified Information created under Section 5.6 before termination is not subject to this Section.
7.5 Survival
The obligations of Apaly Health under Sections 3, 4, 5.7, 7.4, and 8 survive termination of this BAA.
8. MISCELLANEOUS
8.1 Regulatory References. A reference in this BAA to a section of the HIPAA Rules means that section as in effect or as amended.
8.2 Amendment. The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for compliance with the HIPAA Rules and any other applicable law. Apaly Health may update this posted form as described in Section 8.7.
8.3 Interpretation. Any ambiguity in this BAA shall be resolved to permit compliance with the HIPAA Rules.
8.4 No Third Party Beneficiaries. Nothing in this BAA confers any right, remedy, or obligation on any person other than the parties and their respective successors and assigns.
8.5 Governing Law. This BAA is governed by the laws of the State of Delaware, without regard to its conflict of laws principles, except to the extent preempted by federal law.
8.6 Severability. If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible, and the remaining provisions will remain in effect.
8.7 Changes to This Form. Apaly Health may modify this posted form. Material changes will be posted with an updated "Last Updated" date and, where the Counterparty has an account, notice by email or within the platform at least thirty days before they take effect. This Section does not permit modification of an executed Business Associate Agreement.
8.8 Notices. Notices to Apaly Health under this BAA must be sent to the address below and to privacy@apalyrx.com. Notices to the Counterparty may be sent to the address or email associated with its account or its signed agreement.
9. CONTACT
Apaly Health Inc.
802 East Whiting
Tampa, Florida 33602
Privacy Officer: privacy@apalyrx.com
Legal: legal@apalyrx.com