Belcome Business Associate Agreement

Version 2026-10-01

DRAFT, pending legal review

This Business Associate Agreement ("Agreement") is between the business that accepts it in Belcome ("Covered Entity") and Design Master Solutions, LLC, operator of Belcome ("Business Associate"). It follows the structure of the Sample Business Associate Agreement Provisions published by the U.S. Department of Health and Human Services, and it is part of the Belcome Terms of Service.

Who needs it

Med spas, wellness clinics and other businesses that are covered entities under HIPAA, or that handle protected health information for one, accept this Agreement in the Belcome Pro app (Settings) before they import clients or publish a booking page. Other businesses can accept it too.

1. Definitions

Terms used here and not defined, such as Breach, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Protected Health Information ("PHI"), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured PHI and Use, have the meanings given in the HIPAA Rules at 45 CFR Parts 160 and 164.

2. Obligations of Business Associate

Business Associate agrees to:

3. Permitted uses and disclosures

Business Associate may use or disclose PHI only to provide the Service described in the Terms of Service, as Required by Law, and for its proper management and administration or to carry out its legal responsibilities, under the conditions of 45 CFR 164.504(e)(4). Business Associate follows the minimum necessary standard and does not use PHI for marketing or sell PHI. Business Associate will not use or disclose PHI in a way that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity.

4. Obligations of Covered Entity

Covered Entity will notify Business Associate of any limitation in its notice of privacy practices, any change in or revocation of an Individual's permission, and any restriction it agreed to, to the extent it affects Business Associate's use or disclosure of PHI. Covered Entity will not ask Business Associate to use or disclose PHI in a way not permitted for Covered Entity under the HIPAA Rules, and will not enter PHI in fields that the Service shows publicly or sends by text message, such as service names.

5. Term and termination

This Agreement starts when Covered Entity accepts it in the Service and lasts while Business Associate holds PHI for Covered Entity. Covered Entity may end this Agreement and the Terms of Service if Business Associate has violated a material term and has not cured it within 30 days. When the Agreement ends, Business Associate will return to Covered Entity, through export, or destroy the PHI it holds, and will keep no copies, except that PHI kept in backups is protected under this Agreement until those backups are overwritten on their normal schedule, and any PHI that cannot feasibly be returned or destroyed stays protected for as long as it is kept.

6. Miscellaneous

A reference in this Agreement to a section of the HIPAA Rules means the section as in effect or amended. The parties will amend this Agreement as needed to keep up with the HIPAA Rules. Any ambiguity is resolved to permit compliance with the HIPAA Rules. Acceptance in the Service is recorded with the name and title of the person who signs, the date, and a fingerprint of this exact text.