Legal
Business Associate Agreement
Version 2026-07-31.v1 — executes upon acceptance of the Terms of Service
Su Information Technologies LLC, doing business as Suithera
This Business Associate Agreement (“Agreement”) is entered into between Su Information Technologies LLC, a Colorado limited liability company (d/b/a “SuiThera”) (“Business Associate” or “Suithera”) and the covered-entity customer accepting these terms (“Covered Entity”), effective on the date Covered Entity accepts Suithera’s Terms of Service (“Effective Date”). It governs Business Associate’s Use and Disclosure of Protected Health Information on Covered Entity’s behalf.
1. Definitions
Terms used but not defined here have the meaning in the HIPAA Rules (45 CFR Parts 160 and 164). “PHI” means Protected Health Information created, received, maintained, or transmitted by Business Associate for Covered Entity. “HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules.
2. Permitted uses and disclosures of PHI
Business Associate may Use or Disclose PHI only:
- to perform the services in the Terms of Service (clinical documentation, scheduling, billing, telehealth, and related practice operations);
- as Required By Law;
- for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided any Disclosure is Required By Law or the recipient provides written assurances of confidentiality and breach notification;
- to provide Data Aggregation services relating to Covered Entity’s health care operations, if applicable.
Business Associate will not Use or Disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except as permitted above for management, administration, and data aggregation. Business Associate will request, Use, and Disclose only the minimum necessary PHI to accomplish the intended purpose, consistent with 45 CFR 164.502(b).
2.1 AI and de-identified data.Business Associate will not Use PHI to train, fine-tune, or improve any machine-learning model. Clinical AI processing occurs only through subcontractors covered by a business associate agreement, and Business Associate will not transmit PHI to any subcontractor lacking one. Business Associate may create de-identified data from PHI in accordance with 45 CFR 164.514(a)–(b) and use it for its lawful business purposes (including service improvement and aggregate benchmarking); Business Associate will not attempt to re-identify de-identified data and will prohibit its recipients from doing so.
3. Safeguards
Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with the Security Rule (Subpart C of 45 CFR Part 164), to prevent Use or Disclosure of PHI other than as provided by this Agreement. This includes encryption of PHI at rest and in transit, access controls, and an append-only audit log of PHI access.
4. Reporting
Business Associate will report to Covered Entity:
- any Use or Disclosure of PHI not provided for by this Agreement of which it becomes aware;
- any Security Incident of which it becomes aware; and
- any Breach of Unsecured PHI as required by 45 CFR 164.410, without unreasonable delay and no later than five (5) business days after Discovery, including (to the extent known) the identification of affected Individuals and the information described in 45 CFR 164.410(c).
4.1 Unsuccessful security incidents.The parties acknowledge that Business Associate’s systems are subject to routine unsuccessful attempts at unauthorized access — such as pings, port scans, denial-of-service attempts without PHI access, failed log-in attempts, and malware blocked at the perimeter — that do not result in unauthorized access to, or acquisition, Use, or Disclosure of, PHI. Such Unsuccessful Security Incidents are hereby deemed reported by this Section, without further individual notice.
4.2 Breach notification roles and costs.As between the parties, Covered Entity is responsible for determining whether notification of Individuals, HHS, or the media is required under 45 CFR 164.404–164.408 and for making such notifications. Business Associate will provide the information reasonably required for Covered Entity to meet those obligations and will reasonably cooperate. Where the Breach arises from Business Associate’s (or its subcontractors’) acts or omissions, Business Associate will reimburse Covered Entity’s reasonable, documented costs of legally required notifications and industry-standard credit monitoring, subject to and as part of Section 10.3(a).
5. Subcontractors (flow-down)
In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate. A current list of subprocessors is maintained in the Privacy Policy’s subprocessors section.
6. Individual rights
Business Associate will:
- make PHI in a Designated Record Set available to Covered Entity (or the Individual) to satisfy access rights under 45 CFR 164.524;
- make PHI available for amendment and incorporate amendments per 45 CFR 164.526;
- maintain and make available the information required for an accounting of disclosures per 45 CFR 164.528.
Timeframe: within 15 business days of a written request.
7. Availability to HHS
Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of HHS for determining Covered Entity’s compliance with the HIPAA Rules.
8. Return or destruction at termination
On termination, Business Associate will, if feasible, return or destroy all PHI and retain no copies. Where return or destruction is infeasible, Business Associate will extend the protections of this Agreement to such PHI and limit further Uses and Disclosures to the purposes that make return or destruction infeasible, for as long as it retains the PHI. Business Associate will provide a copy or export of Covered Entity’s records in a usable, machine-readable format before destruction; for at least thirty (30) days after termination, Covered Entity retains read-only access to export its records (per-client and practice-wide export), after which destruction proceeds subject to legal holds and the retention periods required by law.
9. Term and termination
(a) Term— effective on the Effective Date and continuing until the later of (i) termination of the Terms of Service and (ii) the date all PHI is returned or destroyed (or, where return/destruction is infeasible, for as long as Business Associate retains PHI under Section 8).
(b) Termination for cause— if Business Associate materially breaches this Agreement, Covered Entity may provide an opportunity to cure and, if not cured within 30 days, terminate the Terms of Service.
10. Liability, indemnification, insurance, and injunctive relief
10.1 Limitation of liability.Except as provided in Section 10.2, and notwithstanding anything to the contrary in this Agreement or the underlying services agreement, each party’s total cumulative liability to the other arising out of or relating to this Agreement (in contract, tort including negligence, strict liability, or otherwise) shall not exceed the greater of (a) the total fees paid or payable by Covered Entity during the twelve (12) months immediately preceding the event giving rise to the claim, or (b) USD $10,000. Except as provided in Section 10.2, neither party shall be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or lost profits or revenue, even if advised of the possibility.
10.2 Exclusions from the limitation (carve-outs).Section 10.1 shall not apply to, and shall not limit, liability arising from: (a) Business Associate’s unauthorized use or disclosure of PHI, or any Breach of Unsecured PHI or Security Incident, caused by Business Associate or its subcontractors; (b) a party’s breach of confidentiality obligations; (c) indemnification obligations under Section 10.3; (d) gross negligence, willful misconduct, or fraud; (e) violation of applicable law (HIPAA, HITECH, or state law); and (f) Business Associate’s breach of Section 10.4 (insurance). Notwithstanding the foregoing, liability arising under Sections 10.2(a)–(c) shall not exceed the greater of (i) three (3) times the total fees paid or payable by Covered Entity during the twelve (12) months preceding the event and (ii) the limits of the insurance coverage required by Section 10.4 (including available proceeds). Liability under Sections 10.2(d)–(f) remains uncapped.
10.3 Mutual indemnification.(a) Business Associate shall defend, indemnify, and hold harmless Covered Entity and its owners, employees, and agents from any third-party claims, actions, liabilities, losses, damages, fines, civil monetary penalties, regulatory assessments, settlements, and reasonable costs and expenses (including reasonable attorneys’ fees and the reasonable costs of Breach notification, credit monitoring, and regulatory response) (“Losses”) to the extent arising out of (i) its breach of this Agreement, (ii) its negligence, gross negligence, or willful misconduct, or (iii) any Breach of Unsecured PHI or Security Incident caused by Business Associate or its subcontractors. (b) Covered Entity shall defend, indemnify, and hold harmless Business Associate and its officers, employees, and agents from any Losses to the extent arising out of (i) its breach of this Agreement, (ii) its negligence, gross negligence, or willful misconduct, or (iii) its instructions, uses, or disclosures of PHI not permitted by HIPAA or that Business Associate implemented in good-faith reliance on Covered Entity’s written direction. (c) The indemnified party shall promptly notify the indemnifying party (failure to give prompt notice relieves the indemnifying party only to the extent actually prejudiced); the indemnifying party controls defense and settlement but may not settle in a manner imposing non-indemnified liability or an admission of fault on the indemnified party without prior written consent (not unreasonably withheld). This Section 10.3 survives termination.
10.4 Insurance.Throughout the term and for two (2) years thereafter, Business Associate shall, at its expense, maintain with insurers rated A- VII or better (A.M. Best): (a) combined Cyber Liability / Privacy & Network Security / Technology E&O insurance with limits of at least USD $1,000,000 per claim and $2,000,000 aggregate, expressly covering (i) unauthorized access to or disclosure of PHI, (ii) regulatory defense and penalties to the extent insurable, and (iii) breach-response, notification, and credit-monitoring costs; and (b) Commercial General Liability of at least $1,000,000 per occurrence and $2,000,000 aggregate. Claims-made coverage shall be maintained (or tail coverage purchased) for at least two (2) years after termination. On request, Business Associate shall provide a certificate of insurance. This Section 10.4 does not limit liability under Section 10.2 or 10.3.
10.5 Injunctive relief. Each party acknowledges that any actual or threatened unauthorized use or disclosure of PHI, or breach of the confidentiality or data-security obligations, may cause irreparable harm for which monetary damages are inadequate. The non-breaching party may seek injunctive or other equitable relief to prevent or restrain such breach, without posting a bond or proving actual damages, in any court of competent jurisdiction, in addition to (not in lieu of) any other cumulative remedies at law or equity.
11. State law and 42 CFR Part 2 (substance-use-disorder records)
11.1 Colorado mental-health confidentiality.Business Associate acknowledges that Covered Entity’s records may be protected not only by HIPAA but by Colorado law, including the confidentiality provisions governing mental-health services and records (C.R.S. § 12-245-220), the record-confidentiality provisions of the Colorado behavioral-health care-and-treatment statutes (C.R.S. § 27-65-123), and the general medical-records confidentiality statutes (C.R.S. § 25-1-1201 et seq.). To the extent any such provision affords the Individual greater protection, or imposes stricter conditions on Use or Disclosure, than the HIPAA Rules, Business Associate will comply with the more protective provision when acting on Covered Entity’s behalf. Business Associate will not Use or Disclose such records except as directed by Covered Entity consistent with these laws or as Required By Law.
11.2 Colorado Privacy Act.To the extent the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) and its rules apply to any data that is not otherwise exempt as PHI or as records governed by Section 11.1, Business Associate will process such data only as a processor acting on Covered Entity’s documented instructions and will provide reasonable assistance with data-subject requests and security obligations.
11.3 42 CFR Part 2 (conditional).(a) The federal confidentiality rules at 42 CFR Part 2 apply only to records of a “program” as defined in 42 CFR 2.11. Covered Entity represents at account creation whether it is such a program. (b) If Covered Entity is not a Part 2 program, this Section imposes no additional Part 2 obligations, and the parties rely on that representation. (c) If Covered Entity is a Part 2 program (or transmits Part 2 records), it must not use the service until Suithera has confirmed Part 2 support in writing; Part 2 support is not yet available at self-serve signup.
12. Miscellaneous
- Regulatory references are to the section as in effect or amended.
- Amendment— the parties will amend this Agreement as needed to comply with the HIPAA Rules; Business Associate may update this Agreement by posting a new version and requiring re-acceptance for material changes.
- Interpretation— ambiguity is resolved to permit compliance with the HIPAA Rules.
- No third-party beneficiaries.
- Governing law— Colorado, except where preempted by federal law.
- Order of precedence— for any conflict concerning PHI, this Agreement controls over the Terms of Service and any other agreement between the parties.
- Notices— notices under this Agreement are given in writing: to Covered Entity, at the account owner’s email address on file (deemed given when sent); to Business Associate, at info@suitech.co and Su Information Technologies LLC, 6571 N Danube Way Unit 6, Denver, CO 80249.
- Assignment— Covered Entity may not assign this Agreement without Business Associate’s consent (not unreasonably withheld). Business Associate may assign this Agreement in connection with a merger, acquisition, or sale of substantially all assets, provided the assignee assumes its obligations and Covered Entity is notified.
- Survival— Sections 4, 8, 10, 11, and 12 survive termination to the extent of retained PHI or accrued claims.
Acceptance
By accepting Suithera’s Terms of Service at account creation, Covered Entity executes this Agreement. Suithera records the acceptance (version, timestamp, user, IP) in its immutable audit log. This page is the permanent, viewable copy of the agreement; the version accepted by your account is shown in Settings.