Skip to Addendum
← Legal Library
A R C H A N G E L  ·  H E A L T H C A R E   A D D E N D U M

Healthcare Addendum & Business Associate Agreement

Sector-specific terms for hospitals, clinics, and healthcare systems. Attaches to and modifies the MSA where the deploying Authority is a HIPAA Covered Entity or where Personal Data may include Protected Health Information.

Document AX-ADD-HC-1.0.0 Effective 2026-10-01 Publisher White Crown Enterprises Version 1.0.0

1. Applicability

Where the Authority is a "Covered Entity" under the Health Insurance Portability and Accountability Act ("HIPAA," 45 C.F.R. Parts 160, 162, 164) or a "Business Associate" that engages WCE to perform functions on its behalf, this Addendum constitutes the required Business Associate Agreement ("BAA"). Terms not defined here have the meaning given in HIPAA.

2. Permitted uses and disclosures of PHI

WCE, as Business Associate, shall use or disclose Protected Health Information ("PHI") only as necessary to perform the Purpose under the MSA, as required by law, or for the proper management and administration of WCE consistent with 45 C.F.R. § 164.504(e)(4). WCE shall not use or disclose PHI in a manner that would violate HIPAA if done by the Covered Entity.

3. Minimum necessary

WCE shall request, use, and disclose only the minimum PHI necessary to accomplish the Purpose. Notifications generated by the Platform are categorical and are designed not to be PHI; where PHI may nonetheless be present (for example, in metadata associated with a hospital operator's session), the minimum-necessary rule applies.

4. Safeguards

WCE shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, consistent with 45 C.F.R. Part 164, Subpart C.

5. Reporting of breaches and security incidents

WCE shall report to the Covered Entity, without unreasonable delay and in no case later than seventy-two (72) hours after discovery, any Breach of Unsecured PHI, and shall report any Security Incident of which WCE becomes aware. Reports shall include the information required by 45 C.F.R. §§ 164.404(c) and 164.410(c).

6. Subcontractors

WCE shall enter into a written agreement with each subcontractor that creates, receives, maintains, or transmits PHI on behalf of WCE, imposing on the subcontractor the same restrictions and conditions that apply to WCE under this Addendum.

7. Access, amendment, and accounting

WCE shall, at the Covered Entity's request and in the time and manner reasonably designated by the Covered Entity, provide access to PHI, incorporate amendments to PHI, and make available information required to provide an accounting of disclosures.

8. Interaction with hospital security

Where the Platform is integrated with hospital security operations (e.g., emergency-department entry vestibules), operator response to a Notification shall be coordinated with clinical operations to avoid interference with patient care. WCE will not access clinical systems and shall not receive clinical data unless expressly required for the Purpose, which is not anticipated.

9. Return or destruction of PHI

Upon termination or expiration of the MSA, WCE shall, if feasible, return or destroy all PHI, retaining no copies. Where return or destruction is not feasible, WCE shall extend the protections of this Addendum to the PHI and limit further uses and disclosures for so long as the PHI is maintained.

10. Access by the Secretary

WCE shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining the Covered Entity's compliance with HIPAA, on reasonable notice.

11. State law

Where state law imposes additional requirements more protective than HIPAA (California CMIA, New York SHIELD Act, Texas HB 300, or analogous), those requirements apply concurrently.

12. Order of precedence

In the event of a conflict with the body of the MSA, this Addendum governs to the extent required by HIPAA or applicable state medical-privacy law.

This Addendum attaches to the MSA and is effective concurrently with it.

XRYSTAL: AX-ADD-HC-1.0.0 · Published 2026-10-01 · Publisher: White Crown Enterprises

← Legal Library · Archangel