Business Associate Agreement
Last updated: July 2026
Overview
Measure-Based Care (“MBC”) is operated by Neo HealthTech LLC dba measurebasedcare.com (Neo HealthTech LLC). MBC is designed for use by HIPAA-covered clinicians and practices that collect, store, or transmit protected health information (PHI) through the platform—for example, patient names, measure responses, and scores.
When a covered entity uses MBC to process PHI, MBC acts as a business associate under the Health Insurance Portability and Accountability Act (HIPAA). This page summarizes our Business Associate Agreement (“BAA”). The full executed agreement governs in case of any conflict with this summary.
By signing up for MBC or using the Service to process PHI, your organization agrees to the BAA terms incorporated into our Terms of Service (version 2026-07), unless you have executed a separate signed BAA with us. We record the version accepted and the time of acceptance for your organization at signup.
Who is covered
The BAA applies when:
- You are a covered entity or an organization acting on behalf of a covered entity (for example, a group practice or clinic)
- You use MBC to create, receive, maintain, or transmit PHI on behalf of your patients
- Your staff access MBC under your organization with appropriate authorization
Patients who complete measures through one-time links are not MBC customers under the BAA; they interact with PHI you control as the covered entity.
Our obligations as business associate
MBC agrees to:
- Use and disclose PHI only as permitted by the BAA, our agreement with you, or as required by law
- Implement appropriate administrative, physical, and technical safeguards to protect PHI, consistent with the HIPAA Security Rule
- Report to you without unreasonable delay upon discovery of a breach of unsecured PHI affecting your patients, as required by the HIPAA Breach Notification Rule
- Ensure that any subcontractors that create, receive, maintain, or transmit PHI on our behalf agree to substantially similar restrictions and safeguards
- Make PHI available for access, amendment, and accounting as required for us to fulfill our obligations to you under HIPAA, to the extent we maintain such PHI
- Return or destroy PHI upon termination of the agreement where feasible, subject to legal retention requirements
Your obligations as covered entity
You agree to:
- Obtain any patient authorizations or provide any notices required before sending measures or collecting PHI through MBC
- Use MBC in compliance with HIPAA and applicable state privacy laws
- Limit staff access to PHI through role-appropriate use of the platform
- Promptly notify us of any changes in contact information for security or breach notifications
- Not request us to use or disclose PHI in a manner that would violate HIPAA
Permitted uses and disclosures
MBC may use and disclose PHI to:
- Provide, maintain, and improve the Service you have engaged us to perform
- Carry out our legal responsibilities and enforce our agreements
- Perform data aggregation services relating to health care operations, in de-identified or limited form where applicable
We do not use PHI for unrelated marketing. Our Privacy Policy describes additional transparency for clinicians and patients.
Infrastructure and subprocessors
MBC is hosted on Google Cloud Platform under Google's HIPAA Business Associate Agreement for in-scope services (including Cloud Run, Cloud SQL, Firebase Hosting, Secret Manager, and related services we use in production). Email delivery and other subprocessors are selected with HIPAA-aligned contractual requirements where PHI may be processed.
A current subprocessor list is available on request at info@measurebasedcare.com. We plan to publish a public subprocessor page for enterprise prospects. Material changes to subprocessors that handle PHI will be communicated as required by our BAA.
Security practices (summary)
Our technical program includes, among other measures:
- TLS encryption for data in transit
- Encrypted database connections and access-controlled production environments
- Hashed invite tokens and least-privilege service accounts
- Production host allowlisting and security headers
- Backup and point-in-time recovery for production databases
- Exclusion of patient measure routes from third-party analytics
Detailed security documentation may be provided to enterprise customers on request.
Term and termination
The BAA remains in effect while you use MBC to process PHI. Upon termination of your account or cessation of PHI processing, we will return or destroy PHI where feasible, retaining only what is required by law or documented backup retention schedules.
Requesting a signed BAA
For solo and group practices, acceptance of our Terms incorporates the standard MBC BAA. Any practice may request a countersigned BAA at any time—there is no minimum size or plan requirement. Email us at:
- Legal: info@measurebasedcare.com
- Support: support@measurebasedcare.com
Please include your practice or organization name, primary contact, and whether you need a PDF countersignature.
Disclaimer
This page is a summary for convenience and does not replace a fully executed Business Associate Agreement. Consult your compliance advisor and legal counsel regarding your HIPAA obligations.