Business Associate Agreement
Business Associate Agreement
Last Updated: August 25, 2026
This Business Associate Agreement ("BAA") is entered into between Dynamanic LLC ("Business Associate") and the entity agreeing to these terms ("Covered Entity") pursuant to the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH").
1. Definitions
All capitalized terms used herein shall have the meanings set forth in 45 CFR Parts 160 and 164, unless otherwise defined:
- "Breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI.
- "Business Associate" means Dynamanic LLC.
- "Covered Entity" means the Customer entering into this BAA.
- "PHI" or "Protected Health Information" has the meaning set forth in 45 CFR § 160.103.
- "Security Incident" has the meaning set forth in 45 CFR § 164.304.
2. Scope and Purpose
Business Associate provides the CaseLens service (the "Service") which may involve the processing of Protected Health Information on behalf of Covered Entity. This BAA establishes the permitted and required uses and disclosures of PHI.
3. Permitted Uses and Disclosures
3.1 Permitted Uses
Business Associate may use or disclose PHI only:
- As necessary to perform the Service for Covered Entity
- As required by law
- For the proper management and administration of Business Associate
- To provide data aggregation services (if applicable)
3.2 Minimum Necessary
Business Associate shall limit uses and disclosures to the minimum necessary to accomplish the intended purpose.
4. Obligations of Business Associate
4.1 Safeguards
Business Associate shall:
- Implement administrative, physical, and technical safeguards
- Comply with the Security Rule (45 CFR Part 164, Subpart C)
- Ensure the confidentiality, integrity, and availability of PHI
- Protect against reasonably anticipated threats or hazards
- Protect against impermissible uses or disclosures
4.2 Security Measures
Business Associate implements the following safeguards:
Administrative Safeguards:
- Security officer designation
- Workforce training programs
- Access management procedures
- Contingency plans
- Periodic security evaluations
Physical Safeguards:
- Facility access controls
- Workstation security
- Device and media controls
- Secure data center facilities
Technical Safeguards:
- Access controls (unique user IDs, automatic logoff)
- Audit controls and logging
- Integrity controls (authentication, transmission security)
- Encryption (AES-256-GCM at rest, TLS 1.3 in transit)
4.3 Subcontractors
Business Associate shall:
- Enter into written agreements with subcontractors
- Ensure subcontractors agree to equivalent restrictions
- Maintain a list of subcontractors
4.4 Reporting Obligations
Business Associate shall report to Covered Entity:
- Any use or disclosure not permitted by this BAA
- Any Security Incident (within 24 hours of discovery)
- Any Breach of Unsecured PHI (within 24 hours of discovery)
4.5 Breach Notification
In the event of a Breach, Business Associate shall:
- Notify Covered Entity without unreasonable delay (within 24 hours)
- Provide information required for notification to individuals
- Cooperate with Covered Entity's investigation
- Mitigate harmful effects to the extent practicable
4.6 Access and Amendment
Business Associate shall:
- Provide access to PHI upon request within 30 days
- Make amendments to PHI as directed by Covered Entity
- Maintain an accounting of disclosures
4.7 Audit Rights
Business Associate shall:
- Make internal practices and records available for audit
- Provide documentation upon request
- Cooperate with HHS investigations
5. Obligations of Covered Entity
Covered Entity shall:
- Provide notice of any restrictions on use or disclosure
- Notify of any changes to authorizations or consents
- Ensure PHI provided is the minimum necessary
- Obtain necessary consents before disclosing to Business Associate
6. Term and Termination
6.1 Term
This BAA is effective for the duration of the Agreement between the parties.
6.2 Termination for Cause
Either party may terminate upon:
- Material breach that is not cured within 30 days
- Pattern of non-compliance
- Breach that cannot be cured
6.3 Effect of Termination
Upon termination:
- Business Associate shall return or destroy all PHI
- If return/destruction is not feasible, protections shall continue
- Business Associate shall certify destruction upon request
7. Amendment
This BAA shall be amended as necessary to comply with HIPAA and HITECH requirements. Amendments require written agreement or 30 days notice from Business Associate.
8. General Provisions
8.1 Interpretation
This BAA shall be interpreted consistently with HIPAA and HITECH.
8.2 Regulatory References
References to HIPAA and related regulations include any amendments.
8.3 Survival
Obligations regarding PHI shall survive termination.
8.4 No Third-Party Beneficiaries
This BAA does not create rights in third parties.
9. Contact Information
HIPAA Privacy Officer:
Dynamanic LLC
Dynamanic LLC — registered mailing address available on request via legal@dynamanic.io
Email: privacy@dynamanic.io
Phone: Contact via website
Breach Notification Contact:
Email: security@caselens.dynamanic.io
EXHIBIT A: Description of Services
| Element | Description |
|---|---|
| Services | CaseLens document processing and review platform |
| PHI Types | Health records, patient identifiers, protected documents |
| Purpose | Legal discovery, compliance, litigation support |
| Access | Authorized users designated by Covered Entity |
EXHIBIT B: Security Controls
See Section 4.2 above for detailed security measures. Additional documentation available upon request:
- Security Policies and Procedures
- Security architecture and controls documentation
By using the Service with PHI, Covered Entity agrees to this Business Associate Agreement.