Skip to content
Closeout
Demo
Back to overview

Business Associate Agreement


Last updated August 19, 2026

This Business Associate Agreement (this “BAA”) is entered into between your firm (the “Covered Entity,” or a business associate acting on behalf of one) and Closeout Technologies, Inc. (“Business Associate,” “Closeout”). It is incorporated into and forms part of the General Terms of Use (the “Agreement”). It governs Closeout's handling of Protected Health Information (“PHI”) that your firm places into the Service, and it applies whenever Closeout creates, receives, maintains, or transmits PHI on your behalf. Terms used but not defined here have the meanings given by HIPAA.

1

Definitions

1.1

“HIPAA” means the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including the Privacy Rule, the Security Rule, and the Breach Notification Rule (45 CFR Parts 160 and 164), each as amended, including by the HITECH Act.

1.2

“Protected Health Information” or “PHI” means individually identifiable health information that Closeout creates, receives, maintains, or transmits on your firm's behalf through the Service, and includes electronic PHI (“ePHI”). “Individual,” “Required by Law,” “Security Incident,” “Subcontractor,” and “Breach” have the meanings given in 45 CFR Parts 160 and 164.

2

Permitted uses and disclosures

2.1

Closeout may use and disclose PHI only as necessary to provide and support the Service under the Agreement, as permitted or required by this BAA, or as Required by Law. Closeout will not use or disclose PHI in any manner that would violate HIPAA if done by the Covered Entity, except as expressly permitted below.

2.2

Closeout may use PHI for the proper management and administration of Closeout and to carry out its legal responsibilities, and may disclose PHI for those purposes only if the disclosure is Required by Law, or Closeout obtains reasonable assurances from the recipient that the PHI will be held confidentially and the recipient will notify Closeout of any breach of confidentiality.

2.3

Closeout may de-identify PHI in accordance with 45 CFR 164.514(a)-(c) and use the resulting de-identified data as permitted by law. Closeout will not use PHI or your firm's client data to train shared, public, or third-party artificial intelligence models.

2.4

Closeout will make reasonable efforts to use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose.

3

Safeguards

3.1

Closeout will use appropriate administrative, physical, and technical safeguards, and will comply with the Security Rule with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this BAA. This includes encrypting PHI in transit and at rest, enforcing least-privilege access controls, isolating each firm's data, and maintaining a tamper-evident audit trail.

4

Reporting breaches and security incidents

4.1

Closeout will report to your firm any use or disclosure of PHI not permitted by this BAA of which it becomes aware, any Security Incident, and any Breach of unsecured PHI, without unreasonable delay and in any event within the timeframes required by HIPAA. Closeout's report will include the information reasonably available to it to allow your firm to meet its own notification obligations.

4.2

The parties acknowledge this section as notice of the ongoing existence of routine, unsuccessful security incidents (such as pings, port scans, and failed log-in attempts) for which no additional per-incident notice is required.

5

Subcontractors

5.1

Closeout will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on Closeout's behalf agrees in writing to restrictions and conditions on the PHI at least as protective as those that apply to Closeout under this BAA. Closeout's current sub-processors, and the safeguards that bind them, are described in the Privacy Policy.

6

Individual rights

6.1

To the extent Closeout maintains PHI in a Designated Record Set, Closeout will, at your firm's request and within the timeframes HIPAA requires, make PHI available so your firm can meet its obligations to provide access under 45 CFR 164.524 and to amend PHI under 45 CFR 164.526, and will incorporate any amendments your firm directs.

6.2

Closeout will document and make available the information required for your firm to respond to a request for an accounting of disclosures under 45 CFR 164.528.

6.3

If Closeout receives a request from an Individual directly, it will forward the request to your firm and will not respond to the Individual except as directed by your firm or as Required by Law.

7

Availability to HHS

7.1

Closeout will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining your firm's compliance with HIPAA, subject to applicable legal protections and privileges.

8

Return or destruction of PHI

8.1

On termination of this BAA or the Agreement, Closeout will, if feasible, return or securely destroy all PHI it maintains on your firm's behalf and retain no copies. Your firm may export its data during the retention window described in the Privacy Policy. Where return or destruction is not feasible, Closeout will extend the protections of this BAA to the retained PHI and limit further use or disclosure to the purposes that make return or destruction infeasible, for as long as it retains the PHI.

9

Term and termination

9.1

This BAA takes effect when you accept it or the Agreement, whichever is first, and continues until all PHI is returned or destroyed. If either party materially breaches this BAA, the other party may terminate the Agreement if the breach is not cured within a reasonable period after notice, or immediately if cure is not feasible, consistent with 45 CFR 164.504(e)(2)(iii).

10

Miscellaneous

10.1

This BAA will be interpreted to permit compliance with HIPAA. The parties agree to take such action as is necessary to amend this BAA from time to time as needed for the parties to comply with HIPAA and related law. In the event of a conflict between this BAA and any other part of the Agreement regarding PHI, this BAA controls. There are no third-party beneficiaries. This BAA is governed by the law that governs the Agreement, the State of Texas, except where HIPAA or other applicable law requires otherwise.

10.2

A firm that requires a separately negotiated or countersigned Business Associate Agreement may request one by contacting legal@usecloseout.com.

Questions about this document? Email legal@usecloseout.com.