HIPAA · 42 CFR Part 2

Business Associate Agreement

Navix Health's standard Business Associate and Qualified Service Organization Agreement. Read it below, send the link to your counsel, or execute it on behalf of your organization in about two minutes. Navix countersigns automatically and you receive the executed PDF by email.

Version 2026-09-25 · Countersigned by Jason Brumback, Chief Executive Officer

Already on a Master Services Agreement? Facilities that signed an MSA with Navix already have a BAA as Exhibit C. That exhibit governs the facilities it covers, and you do not need to accept this one. If you need a copy of your executed Exhibit C, email contracts@navixhealth.com. This page is for Navix Hub Professional and NavixAI subscribers, and for any organization that needs a BAA before an MSA is in place.

Business Associate and Qualified Service Organization Agreement

This Business Associate and Qualified Service Organization Agreement ("BAA") is entered into between Navix Health, Inc., a Delaware corporation ("Business Associate" or "Navix"), and the organization identified in the acceptance record at the end of this BAA ("Covered Entity" or "Client"). This BAA is effective on the date Client's authorized representative accepts it electronically (the "Effective Date").

Client is a Covered Entity under HIPAA and, where applicable, a Part 2 Program. In providing the Services, Navix creates, receives, maintains, and transmits PHI and, where applicable, SUD Records on Client's behalf. The parties enter into this BAA to satisfy the requirements of 45 C.F.R. §§ 164.502(e), 164.504(e), 164.308(b), and 164.314(a) and, where applicable, 42 C.F.R. §§ 2.11 and 2.12(c)(4).

This BAA supplements the agreement under which Client uses the Services (the "Agreement"), meaning the Navix Terms of Use for self-serve subscriptions or a Master Services Agreement and Order Form for facility subscriptions. If Client and Navix have executed a Master Services Agreement that includes a Business Associate Agreement as an exhibit, that exhibit governs and this BAA does not apply to the facilities it covers.

1. Definitions

1.1 Capitalized terms used but not defined in this BAA have the meanings given in the Agreement or, if not defined there, in HIPAA or Part 2. "Breach," "Designated Record Set," "Required by Law," "Secretary," "Security Incident," "Subcontractor," and "Unsecured PHI" have the meanings given in 45 C.F.R. Parts 160 and 164.

1.2 "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, the HITECH Act, and their implementing regulations at 45 C.F.R. Parts 160 and 164, each as amended.

1.3 "Part 2" means 42 C.F.R. Part 2, and "Part 2 Program" has the meaning given in 42 C.F.R. § 2.11.

1.4 "PHI" means Protected Health Information as defined in 45 C.F.R. § 160.103, limited to the information Navix creates, receives, maintains, or transmits on behalf of Client.

1.5 "SUD Records" means records, as defined in 42 C.F.R. § 2.11, of the identity, diagnosis, prognosis, or treatment of any patient that are maintained in connection with the performance of a Part 2 Program and that Navix creates, receives, maintains, or transmits on behalf of Client. SUD Records are also PHI for purposes of this BAA.

1.6 "Services" means the Navix software and related services Client uses under the Agreement, including Navix Hub, Navix CRM, NavixAI, NavixScribe, and Navix Intelligence.

2. Status of the Parties

2.1 Business Associate. Navix is a Business Associate of Client under HIPAA with respect to PHI it creates, receives, maintains, or transmits on Client's behalf.

2.2 Qualified Service Organization. To the extent Client, or any facility or program Client operates, is a Part 2 Program and Navix receives, stores, processes, or otherwise deals with SUD Records from or on behalf of Client, Navix is a Qualified Service Organization ("QSO") of Client and this BAA constitutes a qualified service organization agreement under 42 C.F.R. § 2.11. Navix acknowledges that in receiving, storing, processing, or otherwise dealing with any SUD Records from Client, it is fully bound by 42 C.F.R. Part 2, and that, if necessary, it will resist in judicial proceedings any efforts to obtain access to SUD Records except as permitted by 42 C.F.R. Part 2.

2.3 Designation of SUD Records. Client shall notify Navix in writing if Client, or any facility or program it operates, is a Part 2 Program, and is responsible for identifying SUD Records within the Services where the Services permit such designation. Client's answer to the Part 2 question in the acceptance record constitutes such notice. Unless Client notifies Navix otherwise in writing, Navix will treat all patient records maintained in the Services for a Client that provides substance use disorder treatment as SUD Records.

3. Permitted and Required Uses and Disclosures

3.1 Services. Navix may use and disclose PHI and SUD Records only as necessary to provide the Services under the Agreement, as expressly permitted by this BAA, or as Required by Law (subject to Section 3.5 as to SUD Records).

3.2 Management and Administration. Navix may use PHI for its proper management and administration or to carry out its legal responsibilities, and may disclose PHI for those purposes only if the disclosure is Required by Law or Navix obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Navix of any instance of which it becomes aware in which the confidentiality of the PHI has been breached. SUD Records shall not be used or disclosed under this Section except as permitted by Part 2.

3.3 Data Aggregation. Navix may use PHI to provide data aggregation services relating to Client's health care operations as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).

3.4 De-identification. Navix may de-identify PHI and SUD Records in accordance with 45 C.F.R. § 164.514(a) through (c) and, as to SUD Records, 42 C.F.R. § 2.11, and may use and disclose de-identified data as provided in the Agreement. De-identified data is not PHI or SUD Records.

3.5 Legal Process; No Disclosure of SUD Records Without a Part 2 Court Order. Navix shall not disclose SUD Records in response to a subpoena, court order, search warrant, discovery request, law enforcement request, or other legal process, or in any civil, criminal, administrative, or legislative proceeding, unless the disclosure is (a) authorized by a written patient consent that meets the requirements of 42 C.F.R. § 2.31, or (b) compelled by a court order that complies with 42 C.F.R. Part 2, Subpart E, accompanied by a subpoena or other legal process as required by 42 C.F.R. § 2.61. Unless legally prohibited from doing so, Navix shall promptly notify Client of any legal process seeking PHI or SUD Records, shall disclose no more than the minimum required, and shall reasonably cooperate with Client in seeking a protective order or other appropriate relief. With respect to PHI that is not SUD Records, Navix may disclose PHI as Required by Law after giving Client such notice where legally permitted.

3.6 Prohibition on Redisclosure. Navix shall not use or disclose SUD Records except as permitted by Part 2 and this BAA. Each disclosure of SUD Records made by Navix that is permitted under this BAA shall be accompanied by the written statement prohibiting redisclosure required by 42 C.F.R. § 2.32, to the extent applicable.

3.7 No Use Against Patients. Navix shall not use or disclose SUD Records, or testimony relaying the content of SUD Records, to initiate or substantiate any criminal charges against a patient or to conduct any investigation of a patient, or in any civil, criminal, administrative, or legislative proceeding against a patient, except as authorized by a consent meeting 42 C.F.R. § 2.31 or a court order under 42 C.F.R. Part 2, Subpart E, consistent with 42 C.F.R. § 2.12(d).

3.8 Prohibited Uses. Navix shall not sell PHI, use or disclose PHI for marketing or fundraising, or use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Client, except as expressly permitted by Sections 3.2 and 3.3.

3.9 Minimum Necessary. Navix shall limit its uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b).

4. Safeguards

4.1 Navix shall implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI and SUD Records that it creates, receives, maintains, or transmits, and shall comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, including the security standards and implementation specifications applicable to Business Associates.

4.2 Without limiting Section 4.1, Navix shall encrypt PHI in transit and at rest, maintain role-based access controls and audit logging of access to PHI within the Services, and train its workforce members who have access to PHI on their obligations under HIPAA, Part 2, and this BAA.

5. Reporting of Incidents and Breaches

5.1 Reporting. Navix shall report to Client (a) any use or disclosure of PHI or SUD Records not permitted by this BAA, (b) any Security Incident, and (c) any Breach of Unsecured PHI, in each case without unreasonable delay and in no event later than five (5) business days after Navix discovers the incident, discovery being determined in accordance with 45 C.F.R. § 164.410(a)(2). The initial report may be based on the information then available and shall be supplemented, as information becomes available, with the content required by 45 C.F.R. § 164.410(c) and in time to permit Client to meet its own notification deadlines under 45 C.F.R. §§ 164.404 through 164.408 and applicable state law. Reports will be sent to the email address in Client's acceptance record unless Client designates another contact in writing.

5.2 SUD Records. An unauthorized use or disclosure of SUD Records, including any disclosure that identifies a patient, directly or indirectly, as having or having had a substance use disorder, is treated as a Breach for purposes of this BAA and shall be reported under Section 5.1 regardless of whether the information would otherwise qualify as Unsecured PHI.

5.3 Unsuccessful Security Incidents. The parties acknowledge that this Section constitutes notice of the ongoing occurrence of unsuccessful Security Incidents for which no additional notice will be given, meaning routine attempts such as pings, port scans, blocked malware, unsuccessful log-on attempts, and denial-of-service attempts that do not result in unauthorized access to, or unauthorized use, disclosure, modification, or destruction of, PHI.

5.4 Mitigation and Cooperation. Navix shall mitigate, to the extent practicable, any harmful effect known to Navix of a use or disclosure of PHI or SUD Records in violation of this BAA, shall cooperate with Client's investigation and risk assessment, and shall not notify affected individuals, regulators, or the media of a Breach on Client's behalf without Client's prior written direction unless Required by Law. Where the Breach was caused by Navix, Navix shall bear the reasonable costs of investigation, notification, and mitigation, subject to the limitation of liability in the Agreement.

6. Subcontractors

6.1 Navix shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI or SUD Records on behalf of Navix agrees in writing to restrictions, conditions, and requirements at least as protective as those that apply to Navix under this BAA, including, as to SUD Records, the obligations of Part 2. Navix shall make a current list of such Subcontractors available to Client upon written request and remains responsible to Client for the acts and omissions of its Subcontractors with respect to PHI and SUD Records.

7. Individual Rights

7.1 Access. Within ten (10) business days of Client's written request, Navix shall make PHI maintained in a Designated Record Set available to Client as necessary for Client to meet its obligations under 45 C.F.R. § 164.524. Client acknowledges that the Services permit Client to fulfill most access requests directly.

7.2 Amendment. Within ten (10) business days of Client's written request, Navix shall make PHI maintained in a Designated Record Set available for amendment and incorporate any amendment as directed by Client in accordance with 45 C.F.R. § 164.526.

7.3 Accounting of Disclosures. Navix shall document disclosures of PHI and SUD Records it makes, and the information related to such disclosures, as would be required for Client to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528 and, as to SUD Records, 42 C.F.R. § 2.25, and shall provide such information to Client within ten (10) business days of Client's written request.

7.4 Restrictions and Confidential Communications. Navix shall comply with any restriction on the use or disclosure of PHI, and any request for confidential communications, that Client has agreed to under 45 C.F.R. § 164.522 and communicated to Navix in writing.

7.5 Delegated Obligations. To the extent Navix carries out one or more of Client's obligations under Subpart E of 45 C.F.R. Part 164, Navix shall comply with the requirements of Subpart E that apply to Client in the performance of such obligations.

8. Books and Records

8.1 Navix shall make its internal practices, books, and records relating to the use and disclosure of PHI and SUD Records available to the Secretary for purposes of determining Client's and Navix's compliance with HIPAA and, to the extent applicable, Part 2.

9. Obligations of Client

9.1 Notices. Client shall notify Navix in writing of (a) any limitation in Client's notice of privacy practices, (b) any change in, or revocation of, a patient's permission to use or disclose PHI or SUD Records, and (c) any restriction on the use or disclosure of PHI to which Client has agreed, in each case to the extent the limitation, change, revocation, or restriction may affect Navix's use or disclosure of PHI or SUD Records.

9.2 Part 2 Consents and Configuration. Client is responsible for obtaining, documenting, and maintaining the patient consents required by Part 2 for disclosures Client makes or directs through the Services, for honoring revocations, and for configuring consent, access, disclosure, and patient-portal settings within the Services in accordance with Part 2, HIPAA, and applicable state law. Navix shall act in accordance with Client's configuration of the Services.

9.3 Permissible Requests. Client shall not request Navix to use or disclose PHI or SUD Records in any manner that would not be permissible under HIPAA or Part 2 if done by Client, except as permitted under Sections 3.2 and 3.3.

9.4 Client Compliance. Client remains responsible for its own obligations as a Covered Entity and, where applicable, a Part 2 Program, including obligations not delegated to Navix under this BAA.

9.5 Authority. The individual accepting this BAA represents that they are authorized to bind Client to its terms.

10. Term and Termination

10.1 Term. This BAA is effective as of the Effective Date and continues until all PHI and SUD Records provided by Client to Navix, or created or received by Navix on behalf of Client, are returned or destroyed in accordance with Section 10.3, or, if return or destruction is infeasible, for so long as Navix retains PHI or SUD Records.

10.2 Termination for Breach. Either party may terminate the Agreement and this BAA if the other party has materially breached this BAA and fails to cure the breach within thirty (30) days after receiving written notice specifying the breach, or immediately upon written notice if cure is not possible. Client may exercise this right notwithstanding any minimum term in the Agreement.

10.3 Return or Destruction. Upon expiration or termination of the Agreement and following the data export period provided in the Agreement, Navix shall return to Client or destroy all PHI and SUD Records that Navix maintains in any form, and shall retain no copies, except that (a) Navix may retain PHI in routine backup media until overwritten in the ordinary course under its standard retention schedule, and (b) where Navix determines that return or destruction is otherwise infeasible, it shall notify Client of the conditions that make return or destruction infeasible. Any PHI or SUD Records retained under this Section remain subject to this BAA, and Navix shall limit further uses and disclosures to those purposes that make return or destruction infeasible. Destruction shall be performed in a manner that renders the PHI unusable, unreadable, or undecipherable, consistent with guidance issued by the Secretary.

11. General

11.1 Regulatory References. A reference in this BAA to a section of HIPAA or Part 2 means the section as in effect or as amended, and to any successor provision.

11.2 Amendment. The parties shall take such action as is necessary to amend this BAA from time to time as required for the parties to comply with changes in applicable privacy law. Navix may publish an updated version of this BAA at navixhealth.com/baa; no amendment that reduces the protections afforded to PHI or SUD Records is effective against Client unless Client accepts it in writing.

11.3 Interpretation. Any ambiguity in this BAA shall be resolved to permit compliance with HIPAA and Part 2.

11.4 No Third-Party Beneficiaries. Nothing in this BAA confers any right, remedy, or obligation on any person other than the parties and their respective successors and permitted assigns.

11.5 Relationship to the Agreement. This BAA controls over the Agreement with respect to the use, disclosure, and protection of PHI and SUD Records. All other terms of the Agreement, including its limitation of liability and indemnification provisions, apply to this BAA, and claims arising under this BAA are subject to the data protection liability cap in the Agreement. Nothing in this BAA expands Navix's liability beyond that provided in the Agreement.

11.6 Electronic Execution. This BAA is executed electronically. Client's acceptance through the form at navixhealth.com/baa, and Navix's automated countersignature, constitute valid signatures under the U.S. Electronic Signatures in Global and National Commerce Act and applicable state law. The acceptance record generated at execution, including the signer's name, title, organization, email address, timestamp, and the version of this BAA accepted, is the executed copy.

11.7 Notices. Notices to Navix under this BAA shall be sent to contracts@navixhealth.com with a copy to Navix Health, Inc., 1609 Norris Drive, Austin, TX 78704, Attn: Legal. Notices to Client shall be sent to the email address in the acceptance record.

11.8 Survival. Sections 3.5, 3.6, 3.7, 5, 10.3, and 11 survive expiration or termination of this BAA.

Accept on behalf of your organization

Complete this form to execute the BAA above. Navix countersigns automatically and the executed copy is emailed to you.

Download unsigned PDF for review

Questions before signing? Email contracts@navixhealth.com. Related: security and compliance, privacy policy, terms of use.