← Privacy Policy
HeartLane

Business Associate Agreement

Version 1.0 · Effective August 19, 2026

This agreement is for organizations — clinics, provider groups, and employers — that use HeartLane on behalf of the people they serve. If you use HeartLane as an individual, you don't need to sign it; the Privacy Policy covers you.

1. Parties and purpose

This Business Associate Agreement (the "Agreement") is entered into between HeartLane ("Business Associate") and the organization identified in the signature block below ("Covered Entity"). It takes effect on the date Covered Entity signs it electronically within the HeartLane application.

Covered Entity uses HeartLane to help the individuals it serves record blood pressure readings, food entries, and related wellness information. In performing those services, Business Associate may create, receive, maintain, or transmit Protected Health Information ("PHI") on Covered Entity's behalf. This Agreement sets out the terms required by the HIPAA Privacy, Security, and Breach Notification Rules, 45 C.F.R. Parts 160 and 164, as amended by the HITECH Act.

2. Definitions

Capitalized terms not defined here have the meanings given to them in 45 C.F.R. Parts 160 and 164, including Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information ("ePHI"), Health Care Operations, Individual, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

3. Permitted uses and disclosures

Business Associate may use or disclose PHI only as follows:

  • To perform the services described in the underlying service arrangement with Covered Entity.
  • For the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any disclosure is Required By Law or is made with reasonable assurances of confidentiality and notice of any breach.
  • To provide Data Aggregation services relating to Covered Entity's Health Care Operations, where requested.
  • As Required By Law.

4. Prohibited uses and disclosures

Business Associate will not use or disclose PHI other than as permitted by this Agreement or as Required By Law, and will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity. Business Associate will not sell PHI, use PHI for marketing or advertising, or use PHI to train third-party models outside the scope of the services.

Where HeartLane uses artificial intelligence to generate wellness insights, only the minimum information necessary is transmitted to the model provider under contract, and outputs are returned to the individual's own record.

5. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. Current safeguards include:

  • Encryption of PHI in transit (TLS) and at rest in the managed database and backups.
  • Row-level security so each individual's records are readable only by that individual's authenticated session.
  • Multi-factor authentication (TOTP authenticator apps) gating access to health screens, with second-factor assurance enforced before health data is loaded.
  • A 15-minute inactivity sign-out with warning, plus an absolute session lifetime cap.
  • An immutable security audit log recording sign-ins, second-factor changes, data downloads, and deletion requests.
  • Least-privilege access for personnel, with privileged database credentials never exposed to client applications.

6. Subcontractors

Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement. Current categories of Subcontractors include managed cloud hosting and database services, transactional email delivery, payment processing (which receives billing data only, never health data), and contracted AI inference providers.

7. Reporting and breach notification

Business Associate will report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including any Security Incident and any Breach of Unsecured PHI, without unreasonable delay and in no case later than thirty (30) calendar days after discovery. Reports will include, to the extent known, the individuals affected, a description of what occurred, the types of information involved, and the mitigation steps taken. Unsuccessful Security Incidents that result in no unauthorized access (such as routine blocked scans or failed sign-in attempts) are reported on request in aggregate.

8. Individual rights

Business Associate will, within fifteen (15) business days of a written request:

  • Make PHI in a Designated Record Set available to Covered Entity or the Individual, as required by 45 C.F.R. § 164.524. HeartLane also provides individuals a self-service machine-readable download of their own records.
  • Make PHI available for amendment and incorporate amendments as required by 45 C.F.R. § 164.526.
  • Maintain and make available the information required to provide an accounting of disclosures under 45 C.F.R. § 164.528.
  • Comply with any request for restriction that Covered Entity has agreed to and communicated to Business Associate.

9. Access by the Secretary

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.

10. Obligations of Covered Entity

Covered Entity will notify Business Associate of any limitation in its notice of privacy practices, of any changes in or revocation of an Individual's permission to use or disclose PHI, and of any restriction to which it has agreed, to the extent any of these affect Business Associate's use or disclosure of PHI. Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.

11. Term and termination

This Agreement begins on the date of electronic signature and continues until all PHI is returned or destroyed, or protections are extended in accordance with the termination provisions below.

Covered Entity may terminate this Agreement if Business Associate materially breaches it and fails to cure within thirty (30) days of written notice, or immediately if cure is not possible.

On termination, Business Associate will return or destroy all PHI it maintains on Covered Entity's behalf, including PHI held by Subcontractors, where feasible. Where return or destruction is infeasible, Business Associate will extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for so long as it retains the PHI.

12. Miscellaneous

The parties agree to amend this Agreement as necessary to comply with changes in HIPAA or other applicable law. Any ambiguity is resolved in favor of a meaning that permits compliance with HIPAA. Nothing in this Agreement creates third-party beneficiary rights. This Agreement supplements, and does not replace, the underlying service arrangement between the parties.

Questions and notices under this Agreement may be sent to privacy@heartlane.app.

Questions about this agreement? Email privacy@heartlane.app.

Checking your agreement status…

HeartLane offers general wellness information, not medical advice.