Belcome Business Associate Agreement
Version 2026-10-01
DRAFT, pending legal review
This Business Associate Agreement ("Agreement") is between the business that accepts it in Belcome ("Covered Entity") and Design Master Solutions, LLC, operator of Belcome ("Business Associate"). It follows the structure of the Sample Business Associate Agreement Provisions published by the U.S. Department of Health and Human Services, and it is part of the Belcome Terms of Service.
Who needs it
Med spas, wellness clinics and other businesses that are covered entities under HIPAA, or that handle protected health information for one, accept this Agreement in the Belcome Pro app (Settings) before they import clients or publish a booking page. Other businesses can accept it too.
1. Definitions
Terms used here and not defined, such as Breach, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Protected Health Information ("PHI"), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured PHI and Use, have the meanings given in the HIPAA Rules at 45 CFR Parts 160 and 164.
2. Obligations of Business Associate
Business Associate agrees to:
- Not use or disclose PHI other than as permitted by this Agreement or as Required by Law.
- Use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 CFR Part 164 for electronic PHI, to prevent use or disclosure other than as this Agreement allows.
- Report to Covered Entity any use or disclosure not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required by 45 CFR 164.410, and any Security Incident of which it becomes aware, without unreasonable delay and in no case later than 30 days after discovery. Unsuccessful attempts, such as pings, port scans and blocked sign-in attempts, are reported by this sentence and need no further notice.
- Ensure, under 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees to the same restrictions and conditions. Business Associate stores and transmits PHI using Amazon Web Services under the AWS Business Associate Addendum.
- Make PHI in a Designated Record Set available to Covered Entity as needed to meet 45 CFR 164.524, through the export and client file tools in the Service.
- Make amendments to PHI in a Designated Record Set as directed by Covered Entity under 45 CFR 164.526, which Covered Entity can do directly in the Service.
- Keep and make available the information required for Covered Entity to provide an accounting of disclosures under 45 CFR 164.528.
- To the extent it carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in performing that obligation.
- Make its internal practices, books and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.
3. Permitted uses and disclosures
Business Associate may use or disclose PHI only to provide the Service described in the Terms of Service, as Required by Law, and for its proper management and administration or to carry out its legal responsibilities, under the conditions of 45 CFR 164.504(e)(4). Business Associate follows the minimum necessary standard and does not use PHI for marketing or sell PHI. Business Associate will not use or disclose PHI in a way that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity.
4. Obligations of Covered Entity
Covered Entity will notify Business Associate of any limitation in its notice of privacy practices, any change in or revocation of an Individual's permission, and any restriction it agreed to, to the extent it affects Business Associate's use or disclosure of PHI. Covered Entity will not ask Business Associate to use or disclose PHI in a way not permitted for Covered Entity under the HIPAA Rules, and will not enter PHI in fields that the Service shows publicly or sends by text message, such as service names.
5. Term and termination
This Agreement starts when Covered Entity accepts it in the Service and lasts while Business Associate holds PHI for Covered Entity. Covered Entity may end this Agreement and the Terms of Service if Business Associate has violated a material term and has not cured it within 30 days. When the Agreement ends, Business Associate will return to Covered Entity, through export, or destroy the PHI it holds, and will keep no copies, except that PHI kept in backups is protected under this Agreement until those backups are overwritten on their normal schedule, and any PHI that cannot feasibly be returned or destroyed stays protected for as long as it is kept.
6. Miscellaneous
A reference in this Agreement to a section of the HIPAA Rules means the section as in effect or amended. The parties will amend this Agreement as needed to keep up with the HIPAA Rules. Any ambiguity is resolved to permit compliance with the HIPAA Rules. Acceptance in the Service is recorded with the name and title of the person who signs, the date, and a fingerprint of this exact text.