In short: most of our audits never need patient data, and we ask you not to send it. If an engagement does involve health data, we sign an agreement before we receive any. UK health and care organisations are covered by our data processing addendum with the extra terms in Part A. US covered entities under HIPAA sign the business associate agreement summarised in Part B.
Part A
UK health and care organisations
This part applies to dental practices, care providers, clinics and other UK organisations that handle health or care records.
What applies
Where we process personal data on your behalf, we act as your processor under Article 28 of the UK GDPR, on the terms of our data processing addendum. Health data is special category data under Article 9 of the UK GDPR, so we add the commitments below to any engagement that could involve it.
Keeping patient data out of scope
Our audits look at your systems, settings, policies and evidence, not at patient records. Please redact or leave out patient-identifiable information from anything you send us. If any reaches us by mistake, we will tell you, and we will delete or return it, as you choose.
If health data has to be shared
- Before anything is shared, we agree in writing what data is involved, how it will be sent and where it will be stored.
- We use it only on your documented instructions and only for your engagement.
- Only the people working on your engagement can see it, and they are bound by confidentiality.
- It is stored in the UK and is never sent through our email delivery service.
If something goes wrong
We will tell you without undue delay, and within 48 hours of becoming aware of a personal data breach affecting your data. That gives you time to meet the 72-hour deadline for reporting to the ICO and, where it applies to you, to report through the Data Security and Protection Toolkit.
At the end of the engagement
Within 30 days, and at your choice, we return the personal data we hold for you in a common format or delete it securely and confirm that in writing.
Part B
US covered entities: business associate agreement
Under HIPAA (45 CFR 164.502(e) and 164.504(e)), a covered entity that shares protected health information (PHI) with a business associate must have a written business associate agreement (BAA) in place first. This is a summary of the operative terms of our standard BAA. The signed BAA is a separate document executed alongside your engagement letter.
1. Parties
Covered Entity ("CE"): you, the US healthcare provider engaging Unavoidably Secure.
Business Associate ("BA"): Unavoidable Studio Ltd, a company registered in England and Wales (company number 17367981), trading as Unavoidably Secure, with its registered office in Leeds, United Kingdom.
2. Definitions
Terms in this BAA have the meanings given in the HIPAA Rules (45 CFR Parts 160 and 164) and the HITECH Act. In particular, "Breach", "Designated Record Set", "Individual", "Protected Health Information", "Required by Law", "Secretary", "Security Incident", "Unsecured Protected Health Information" and "Use" have the meanings given in 45 CFR 160.103 and 164.402.
3. Permitted uses and disclosures
BA may use or disclose PHI only:
- to perform the services in the engagement letter (compliance and web risk auditing, documentation review, remediation planning and re-testing);
- as Required by Law;
- for BA's proper management and administration and to carry out its legal responsibilities, provided any disclosure is Required by Law or the recipient gives written assurances of confidential handling and prompt notice of any known Breach;
- to provide data aggregation services relating to CE's health care operations, if CE asks.
4. Prohibited uses and disclosures
- BA will not use or further disclose PHI other than as this BAA permits or as Required by Law.
- BA will not sell PHI or use it for marketing.
- BA will not use or disclose PHI in a way that would breach Subpart E of 45 CFR Part 164 if done by CE, except as permitted above.
5. Safeguards
BA will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 CFR Part 164 for electronic PHI, to prevent use or disclosure of PHI other than as this BAA provides. These include:
- encryption of stored audit evidence and reports at rest with libsodium (XSalsa20-Poly1305), using a key held outside the web root;
- reports delivered as AES-256 encrypted PDFs, with the passphrase sent separately by a different channel;
- HTTPS with HSTS for all data in transit;
- two-factor authentication required on owner and auditor accounts;
- role-based access, limited to the people working on the engagement;
- a tamper-evident, hash-chained audit log of every action in the audit system.
6. Reporting
BA will report to CE without unreasonable delay, and in any event within 48 hours of discovery:
- any use or disclosure of PHI not provided for by this BAA;
- any Security Incident (45 CFR 164.304);
- any Breach of Unsecured PHI, with the information required by 45 CFR 164.410, including the Individuals affected, a description of the Breach, the dates, the types of PHI involved and the steps taken to mitigate it.
Routine unsuccessful attempts, such as port scans, pings and failed log-ins against accounts that do not exist, are not reported individually. BA will provide a summary of these on request.
7. Subcontractors and email
BA will ensure that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions and conditions that apply to BA (45 CFR 164.502(e)(1)(ii) and 164.308(b)(2)). Before any PHI is shared, BA will confirm in writing where it will be stored and which subcontractors, if any, will handle it.
BA does not send PHI by email. Our transactional email provider, Postmark, does not sign business associate agreements, so it is used only for notifications that contain no PHI, such as a message that a report is ready to collect.
8. Access, amendment and accounting
- BA will make PHI in a Designated Record Set available to CE within 15 business days of a written request, so CE can meet 45 CFR 164.524.
- BA will make PHI available for amendment and incorporate amendments CE provides within 30 business days (45 CFR 164.526).
- BA will record and provide the information CE needs for an accounting of disclosures under 45 CFR 164.528 within 30 business days of a written request.
9. Access by the Secretary
BA will make its internal practices, books and records relating to PHI available to the Secretary of the US Department of Health and Human Services for the purpose of determining compliance with HIPAA.
10. Return or destruction of PHI
When the engagement ends, and at CE's choice, BA will either return all PHI in a common machine-readable format within 30 days, or destroy it and certify the destruction in writing. If return or destruction is not feasible, BA will extend the protections of this BAA to that PHI for as long as it holds it, and limit further use to the purposes that make return or destruction infeasible.
11. Term and termination
This BAA runs for the term of the engagement letter. Either party may end it on written notice for a material breach that is not put right within 30 days. On termination, section 10 applies.
12. State law
Where a US state law gives Individuals greater protection than HIPAA, for example on breach notification timelines or notice to a state Attorney General, BA will comply with that law for PHI about residents of that state.
13. Changes in the law
If HIPAA changes in a way that materially affects this BAA, the parties will negotiate in good faith to amend it. If they cannot agree within 60 days, either party may end it on written notice.
14. General
- Any ambiguity in this BAA will be resolved to permit compliance with HIPAA.
- Nothing in this BAA gives rights to any third party.
- The engagement letter and this BAA together are the entire agreement between the parties on this subject.
Signing
The signed agreement is a separate document. We send it with your details completed and signed by us, and it takes effect when you countersign. If you would like it in place before your first engagement, mention it when you request your audit and we will send it for signature within one business day.
Questions about this agreement: support@unavoidablysecure.com or 07749 941111 (+44 7749 941111 from the US).