Skip to main content
Trust Center

Business Associate Agreement Overview

PrismCDM is designed to support HIPAA-regulated clinical development through a combination of contractual commitments and technical controls. The Business Associate Agreement defines the legal framework for processing Protected Health Information; the platform architecture enforces tenant isolation, least-privilege access, provenance, auditability, and Source Fidelity throughout the PHI lifecycle.

1. The BAA and the architecture

The PrismCDM Business Associate Agreement (BAA) is the written contract required by the HIPAA Privacy Rule at 45 CFR 164.504(e) and the HIPAA Security Rule at 45 CFR 164.308(b) when a covered entity (or another business associate) engages PrismCDM to create, receive, maintain, or transmit Protected Health Information on its behalf.

The BAA defines the contractual obligations. The platform architecture provides the technical enforcement of those obligations through tenant isolation, least-privilege access, comprehensive audit, integrity anchors, and Source Fidelity controls.

2. When the BAA applies

  • When the customer is a HIPAA-defined covered entity (such as a health plan, health care provider conducting standard electronic transactions, or health care clearinghouse).
  • When the customer is itself a business associate engaging PrismCDM as a subcontractor that creates, receives, maintains, or transmits PHI on its behalf.
  • By default for any commercial customer engagement where Protected Health Information may be processed on the platform.

3. Responsibility matrix

The BAA distributes responsibility between the covered entity or business associate (the customer) and PrismCDM. The distribution at a glance.

AreaCustomer (CE/BA)PrismCDM
Determine permitted use of PHIYesFollows
Process PHI on documented instructionsIssuesYes
Maintain safeguardsReviewsYes
Individual rights requestsPrimaryAssists
Breach notificationNotifies individuals + HHSNotifies customer + assists
Regulatory complianceSharedShared

4. What the BAA covers

  • Permitted uses and disclosures. PrismCDM uses and discloses PHI only as permitted or required by the BAA, as required by law, and as necessary to perform the services under the Master Services Agreement.
  • Prohibited uses and disclosures. PrismCDM does not use or disclose PHI in ways that would violate HIPAA if done by the covered entity itself, and does not sell PHI.
  • Safeguards. PrismCDM implements administrative, physical, and technical safeguards reasonably designed to protect PHI.
  • Workforce training and access controls. PrismCDM personnel with access to PHI receive HIPAA training and are subject to access controls aligned with the minimum-necessary standard.
  • Subcontractor flow-through. Any subcontractor that processes PHI on PrismCDM's behalf is bound by HIPAA obligations equivalent to PrismCDM's own.
  • Breach notification. PrismCDM notifies the customer of any Breach of unsecured PHI without unreasonable delay, with the information needed to allow the customer to fulfill its Breach Notification Rule obligations.
  • Individual rights assistance. PrismCDM assists the customer in providing access, amendment, accounting of disclosures, and other rights under the Privacy Rule.
  • HHS access. PrismCDM makes its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance.
  • Return or destruction. On termination, PrismCDM returns or destroys PHI in accordance with the BAA, subject to retention obligations imposed by applicable law.

5. HIPAA Security Rule mapping

Each HIPAA Security Rule safeguard maps to a specific PrismCDM capability. The architecture implements the safeguard; the BAA commits to it.

HIPAA RequirementPrismCDM Capability
Access ControlRole-based access control with data-role permissions
AuthenticationMulti-factor authentication
Audit ControlsAppend-only audit chain with identity-bound signatures
IntegritySource Fidelity controls plus integrity anchors
Transmission SecurityTLS 1.2 or higher
Backup and ContingencyMulti-zone backup with tested disaster recovery
Minimum NecessaryLeast-privilege authorization throughout

In addition to HIPAA-required safeguards, PrismCDM applies Source Fidelity controls that classify every value by origin, preserve provenance, and maintain an inspectable integrity chain for AI-generated and human-authored content. These controls complement, not replace, HIPAA Security Rule safeguards.

6. PHI lifecycle

Where does PHI go inside PrismCDM? The lifecycle below gives reviewers an immediate mental model.

  1. PHI Received
  2. Encrypted Transmission
  3. Tenant-Isolated Processing
  4. Controlled Access
  5. Audit Logging
  6. Retention
  7. Return or Destruction

7. Permitted uses and disclosures in detail

  • To perform the services described in the Master Services Agreement on behalf of the customer.
  • For the proper management and administration of PrismCDM, and to carry out its legal responsibilities, subject to the limitations in the BAA.
  • To provide data aggregation services relating to the health care operations of the customer, as permitted under HIPAA.
  • To report violations of law to appropriate Federal and State authorities, consistent with 45 CFR 164.502(j)(1).

All other uses and disclosures of PHI require the customer's prior written authorization or are otherwise required by law.

8. Subcontractors that process PHI

Subcontractors process PHI only as necessary to perform their contracted service. They are contractually bound to HIPAA obligations equivalent to those undertaken by PrismCDM under the executed BAA, including breach notification, permitted-use limitations, and subcontractor flow-through. These subcontractors are listed in the subprocessor documentation shared during the Compliance Review.

9. Breach notification

  • PrismCDM notifies the customer of any Breach of unsecured PHI without unreasonable delay and in no event later than the period specified in the executed BAA.
  • The notification includes the information required for the customer to fulfill its Breach Notification Rule obligations, to the extent known at the time and supplemented as additional information becomes available.
  • PrismCDM cooperates with the customer to investigate and mitigate the impact of the Breach.
  • Investigation, containment, and remediation activities are documented and preserved as part of PrismCDM's incident response process (see /trust/security).

10. Term and termination

  • The BAA is effective on execution and remains in effect for the term of the Master Services Agreement.
  • On termination, PrismCDM returns or destroys PHI in accordance with the BAA, subject to retention obligations imposed by applicable law.
  • Where return or destruction is infeasible, PrismCDM continues to protect the PHI under the BAA terms for so long as PrismCDM maintains the PHI.

11. Architecture as enforcement

The BAA defines PrismCDM's contractual obligations under HIPAA. The platform architecture, including tenant isolation, least-privilege access, auditability, provenance, and Source Fidelity, provides the technical enforcement of those obligations.

12. How to execute a BAA

Customers entering a commercial relationship with PrismCDM that involves PHI receive the BAA alongside the Master Services Agreement. To request the BAA in advance of a commercial conversation, contact us through /contact with reason “Compliance Review”.

13. Document relationships

DocumentPurpose
Master Services AgreementCommercial terms governing the engagement
Business Associate AgreementHIPAA-specific PHI obligations
Data Processing AgreementGDPR and equivalent privacy obligations
SecurityTechnical safeguards
Responsible AI ArchitectureAI governance commitments
SubprocessorsThird-party processing scope and trust boundary

14. Related Trust Center documents

Version
1.0
Effective Date
July 2026
Last Updated
July 2026