Business Associate Agreement

Last updated July 26, 2026 · RxAuto is a product of AccelRx · New York, NY

This is the standard BAA we offer every pharmacy. You can read the whole thing here before you ask for a copy to sign — we would rather you know exactly what you are agreeing to.

How to execute this. Email support@rxauto.ai with your pharmacy's legal name and address, and we will send this agreement for signature. Sign it before RxAuto processes live prescriptions. If your pharmacy requires its own BAA form instead, send it — we will review and sign yours.

Parties

This Business Associate Agreement ("Agreement") is entered into between AccelRx, a New York company doing business as RxAuto ("Business Associate"), and the pharmacy identified on the signature page ("Covered Entity"). It supplements the Terms of Service and controls over them on any conflict about protected health information.

1. Definitions

Terms used but not defined here have the meaning given in the HIPAA Rules at 45 CFR Parts 160 and 164. "PHI" means protected health information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.

2. What PHI is involved

For transparency, the parties record what Business Associate actually receives. RxAuto operates on a workstation inside Covered Entity's pharmacy. Reading and entering prescriptions occurs locally. Business Associate receives, per prescription entered:

  • Covered Entity’s internal patient number and prescriber number (not names)
  • The prescription number, fill date and time
  • Drug identification, quantity, days supply, refills, and pricing basis
  • The prescription directions (sig), which may contain clinical detail such as an indication
  • Which of the above fields the pharmacist corrected on review

Business Associate does not receive patient names, dates of birth, addresses, telephone numbers, email addresses, Social Security numbers, insurance identifiers, or a copy of Covered Entity's database. The parties acknowledge the information above is PHI and is not de-identified under 45 CFR 164.514.

3. Permitted uses and disclosures

Business Associate may use and disclose PHI only:

  • To perform the services described in the Terms of Service — entering prescriptions, supporting the installation, and diagnosing problems;
  • To improve the accuracy of the software, including training the store-specific logic that determines what RxAuto enters for Covered Entity;
  • For the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any disclosure is required by law or is made with reasonable assurances of confidentiality and of notice of any breach;
  • To create de-identified information in accordance with 45 CFR 164.514(b), which Business Associate may thereafter use without restriction; and
  • As required by law.

Business Associate will not use or disclose PHI in any manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity. Business Associate will not sell PHI, and will not use or disclose PHI for marketing or for its own independent commercial purposes.

Minimum necessary. Business Associate will request, use, and disclose only the minimum PHI necessary for the permitted purpose.

4. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and will comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided by this Agreement. Current practice includes encryption of PHI in transit and at rest, exclusion of direct patient identifiers at the source, and restriction of access to named administrators.

5. Subcontractors

Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate, as required by 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2). This includes cloud hosting and database providers and, where Covered Entity enables the optional language-model feature, the model provider. A current list of subcontractors is available on request, and Business Associate will give notice before adding a subcontractor that will handle PHI.

6. Reporting

Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, any security incident, and any breach of unsecured PHI, without unreasonable delay and in no case later than fifteen (15) calendar days after discovery. The report will include, to the extent known: the nature of the incident, the PHI involved, the identifiers involved, who accessed or received it, what has been done to mitigate and investigate, and a contact for further information. Business Associate will cooperate with Covered Entity's breach analysis and notification obligations under 45 CFR 164.400–414. Unsuccessful attempts at unauthorized access that are trivially unsuccessful — pings, port scans, blocked login attempts — are reported in aggregate on request rather than individually.

7. Individual rights

  • Access — Business Associate will make PHI in a designated record set available to Covered Entity as necessary to satisfy 45 CFR 164.524, within ten (10) business days of a written request.
  • Amendment — Business Associate will make PHI available for amendment and incorporate amendments as directed by Covered Entity, per 45 CFR 164.526.
  • Accounting — Business Associate will document and make available the information required for an accounting of disclosures under 45 CFR 164.528.
  • Restrictions — Business Associate will comply with any restriction on use or disclosure that Covered Entity notifies it of, to the extent the restriction affects Business Associate’s services.

If an individual contacts Business Associate directly with a request regarding their PHI, Business Associate will refer that individual to Covered Entity and notify Covered Entity promptly.

8. Availability to the Secretary

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules, and will notify Covered Entity of any such request unless prohibited from doing so.

9. Term and termination

This Agreement begins on the date of signature and continues until all PHI is returned or destroyed, or protections are extended under Section 10. Covered Entity may terminate immediately if Business Associate materially breaches this Agreement and fails to cure within thirty (30) days of written notice. Termination of the underlying service terminates this Agreement, subject to Section 10.

10. Return or destruction of PHI

On termination, Business Associate will, at Covered Entity's election, return or destroy all PHI it maintains and retain no copies, where feasible. Where return or destruction is not feasible — for example PHI held in routine encrypted backups pending expiry — Business Associate will extend the protections of this Agreement to that PHI and limit further use or disclosure to the purposes that make return or destruction infeasible, for as long as it retains the PHI. Absent a contrary election, Business Associate will destroy PHI within sixty (60) days of termination and confirm destruction in writing.

11. Clinical responsibility is unchanged

Nothing in this Agreement shifts clinical responsibility. RxAuto enters prescriptions in a held, unverified state; a licensed pharmacist employed by or contracted to Covered Entity must independently verify every prescription before dispensing. Business Associate is not a provider of pharmacy services, does not exercise professional judgment, and does not supervise Covered Entity's staff.

12. Miscellaneous

  • Regulatory references mean the section as amended from time to time; the parties will amend this Agreement as necessary to comply with changes in the HIPAA Rules.
  • Ambiguity is resolved in favor of a meaning that permits compliance with the HIPAA Rules.
  • This Agreement is governed by the laws of the State of New York, except where preempted by federal law.
  • This Agreement does not create third-party beneficiary rights.
  • Neither party may assign this Agreement without the other’s written consent, except to a successor in interest.

Signature

The executable copy carries signature blocks for both parties: an authorized representative of the pharmacy (name, title, pharmacy legal name, address, date) and an authorized representative of AccelRx. Request it at support@rxauto.ai and we will send it for electronic signature.

Note on this draft. This document tracks the elements required by 45 CFR 164.504(e) and the breach-notification rules at 45 CFR 164.400–414. It has not yet been reviewed by counsel. We are having it reviewed, and we will tell you if anything material changes. If your own counsel wants edits, send them.
Questions about this document, security, or a Business Associate Agreement? Email support@rxauto.ai or call (917) 780-9525. We answer compliance questions in writing.