Version 1.0 · Effective August 19, 2026
This agreement is for organizations — clinics, provider groups, and employers — that use HeartLane on behalf of the people they serve. If you use HeartLane as an individual, you don't need to sign it; the Privacy Policy covers you.
This Business Associate Agreement (the "Agreement") is entered into between HeartLane ("Business Associate") and the organization identified in the signature block below ("Covered Entity"). It takes effect on the date Covered Entity signs it electronically within the HeartLane application.
Covered Entity uses HeartLane to help the individuals it serves record blood pressure readings, food entries, and related wellness information. In performing those services, Business Associate may create, receive, maintain, or transmit Protected Health Information ("PHI") on Covered Entity's behalf. This Agreement sets out the terms required by the HIPAA Privacy, Security, and Breach Notification Rules, 45 C.F.R. Parts 160 and 164, as amended by the HITECH Act.
Capitalized terms not defined here have the meanings given to them in 45 C.F.R. Parts 160 and 164, including Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information ("ePHI"), Health Care Operations, Individual, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Business Associate may use or disclose PHI only as follows:
Business Associate will not use or disclose PHI other than as permitted by this Agreement or as Required By Law, and will not use or disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity. Business Associate will not sell PHI, use PHI for marketing or advertising, or use PHI to train third-party models outside the scope of the services.
Where HeartLane uses artificial intelligence to generate wellness insights, only the minimum information necessary is transmitted to the model provider under contract, and outputs are returned to the individual's own record.
Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. Current safeguards include:
Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement. Current categories of Subcontractors include managed cloud hosting and database services, transactional email delivery, payment processing (which receives billing data only, never health data), and contracted AI inference providers.
Business Associate will report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including any Security Incident and any Breach of Unsecured PHI, without unreasonable delay and in no case later than thirty (30) calendar days after discovery. Reports will include, to the extent known, the individuals affected, a description of what occurred, the types of information involved, and the mitigation steps taken. Unsuccessful Security Incidents that result in no unauthorized access (such as routine blocked scans or failed sign-in attempts) are reported on request in aggregate.
Business Associate will, within fifteen (15) business days of a written request:
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.
Covered Entity will notify Business Associate of any limitation in its notice of privacy practices, of any changes in or revocation of an Individual's permission to use or disclose PHI, and of any restriction to which it has agreed, to the extent any of these affect Business Associate's use or disclosure of PHI. Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
This Agreement begins on the date of electronic signature and continues until all PHI is returned or destroyed, or protections are extended in accordance with the termination provisions below.
Covered Entity may terminate this Agreement if Business Associate materially breaches it and fails to cure within thirty (30) days of written notice, or immediately if cure is not possible.
On termination, Business Associate will return or destroy all PHI it maintains on Covered Entity's behalf, including PHI held by Subcontractors, where feasible. Where return or destruction is infeasible, Business Associate will extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for so long as it retains the PHI.
The parties agree to amend this Agreement as necessary to comply with changes in HIPAA or other applicable law. Any ambiguity is resolved in favor of a meaning that permits compliance with HIPAA. Nothing in this Agreement creates third-party beneficiary rights. This Agreement supplements, and does not replace, the underlying service arrangement between the parties.
Questions and notices under this Agreement may be sent to privacy@heartlane.app.
Questions about this agreement? Email privacy@heartlane.app.
HeartLane offers general wellness information, not medical advice.