Business Associate Agreement

Version 1.0 · Effective 2026-09-22 · WellSpring Digital LLC

Every practice accepts this agreement on its first sign-in, before any patient information is entered. The administrator who accepts it types the practice’s legal name, their own name and title, and the platform files the executed copy under the practice’s Settings, Compliance documents. Nothing to print, mail or scan.

Business Associate Agreement

Version 1.0 · effective 2026-09-22

This Business Associate Agreement (the "Agreement") is between the healthcare practice identified in the signature block ("Covered Entity" or "Practice") and WellSpring Digital LLC, a New Jersey limited liability company that operates the RowanFlow platform ("Business Associate" or "RowanFlow").

Version 1.0, effective 2026-09-22.

Recitals

A. Covered Entity is a health care provider that is a "covered entity" under the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and the regulations at 45 CFR Parts 160 and 164 (together, "HIPAA").

B. Business Associate provides Covered Entity with practice-management, scheduling, clinical documentation, patient-portal, billing, claims, messaging and related software services under the RowanFlow Terms of Service and the Practice's subscription (together, the "Services Agreement"). Performing those services requires Business Associate to create, receive, maintain and transmit Protected Health Information on Covered Entity's behalf.

C. HIPAA requires Covered Entity to obtain satisfactory written assurances that Business Associate will appropriately safeguard that information (45 CFR 164.502(e) and 164.504(e)). This Agreement is those assurances.

The parties therefore agree as follows.

1. Definitions

1.1 Capitalized terms used but not defined in this Agreement have the meanings given in HIPAA. In particular: Breach, Data Aggregation, Designated Record Set, Individual, Protected Health Information ("PHI"), Required by Law, Secretary, Security Incident, Subcontractor and Unsecured PHI have the meanings in 45 CFR 160.103, 164.304, 164.402 and 164.501.

1.2 "PHI" in this Agreement means only the Protected Health Information that Business Associate creates, receives, maintains or transmits on behalf of Covered Entity. It includes electronic PHI.

1.3 "Discovery" of a Breach has the meaning in 45 CFR 164.410(a)(2): the first day the Breach is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate.

1.4 "Unsuccessful Security Incident" means a Security Incident that does not result in unauthorized access, use, disclosure, modification or destruction of PHI or interference with an information system, such as a blocked network probe, a rejected sign-in attempt, a blocked malware download or a denial-of-service attempt that did not succeed.

2. Permitted and required uses and disclosures

2.1 Services. Business Associate may use and disclose PHI as necessary to perform the services described in the Services Agreement and Exhibit A, and as otherwise permitted or required by this Agreement or Required by Law. Business Associate shall not use or further disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as sections 2.2 through 2.4 allow (45 CFR 164.504(e)(2)(i)).

2.2 Management and administration. Business Associate may use PHI for its proper management and administration and to carry out its legal responsibilities (45 CFR 164.504(e)(4)(i)). Business Associate may disclose PHI for those purposes only if the disclosure is Required by Law, or Business Associate obtains reasonable written assurances from the recipient that the information will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any instance in which the confidentiality of the information has been breached (45 CFR 164.504(e)(4)(ii)).

2.3 Data aggregation. Business Associate may use PHI to provide Data Aggregation services relating to Covered Entity's health care operations, such as benchmarking Covered Entity's claims, denials and collections against other practices on the platform in a form that does not identify any Individual (45 CFR 164.504(e)(2)(i)(B)).

2.4 De-identification. Business Associate may de-identify PHI in accordance with 45 CFR 164.514(a) through (c). Information that has been de-identified in accordance with that section is not PHI. De-identified data is owned by WellSpring Digital LLC, which may use it for any lawful purpose, including product improvement, analytics and benchmarking, and Covered Entity assigns to Business Associate any interest it may have in it. Business Associate shall not re-identify de-identified data or attempt to.

2.5 Minimum necessary. Business Associate shall request, use and disclose only the minimum PHI necessary to accomplish the intended purpose, consistent with 45 CFR 164.502(b) and 164.514(d).

2.6 Marketing and sale. Business Associate shall not use or disclose PHI for marketing, and shall not sell PHI, except as HIPAA permits with any authorization that HIPAA requires. Business Associate's own communications to the Practice about the services are not marketing to Individuals.

3. Obligations of Business Associate

3.1 No other use. Business Associate shall not use or further disclose PHI other than as permitted or required by this Agreement or as Required by Law (45 CFR 164.504(e)(2)(ii)(A)).

3.2 Safeguards. Business Associate shall use appropriate administrative, physical and technical safeguards, and shall comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to electronic PHI, to prevent use or disclosure of PHI other than as this Agreement provides (45 CFR 164.504(e)(2)(ii)(B) and 164.314(a)(2)(i)(A)). Exhibit B summarizes the safeguards in place on the effective date. Business Associate may change specific safeguards over time provided the overall level of protection is not reduced.

3.3 Reporting.

(a) Breach of Unsecured PHI. Business Associate shall notify Covered Entity in writing of any Breach of Unsecured PHI without unreasonable delay and in no case later than ten (10) business days after Discovery. The notice shall include, to the extent possible, the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used or disclosed, and any other available information that Covered Entity is required to include in its notification to Individuals under 45 CFR 164.404(c), provided at the time of the notice or promptly thereafter as it becomes available (45 CFR 164.410(c)). Business Associate shall cooperate with Covered Entity's risk assessment under 45 CFR 164.402 and shall not notify Individuals, the media or the Secretary on Covered Entity's behalf unless Covered Entity asks it to in writing.

(b) Other impermissible uses and disclosures. Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, within the same period as paragraph (a) (45 CFR 164.504(e)(2)(ii)(C)).

(c) Security Incidents. Business Associate shall report to Covered Entity any Security Incident of which it becomes aware (45 CFR 164.314(a)(2)(i)(C)). A Security Incident that results, or is reasonably believed to have resulted, in unauthorized access to PHI is reported under paragraph (a) or (b). This paragraph is Covered Entity's notice, and Business Associate's ongoing report, of Unsuccessful Security Incidents; Business Associate shall provide a summary of Unsuccessful Security Incidents on Covered Entity's reasonable written request, no more than once per calendar quarter.

(d) Delay at law enforcement request. Business Associate may delay a notice under this section to the extent 45 CFR 164.412 permits, and shall tell Covered Entity that it has done so as soon as the delay is no longer required.

(e) Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI by Business Associate or its Subcontractors in violation of this Agreement.

3.4 Subcontractors. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate shall ensure that any Subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions and conditions that apply to Business Associate under this Agreement with respect to that PHI, including compliance with the Security Rule for electronic PHI (45 CFR 164.504(e)(2)(ii)(D), 164.504(e)(5) and 164.314(a)(2)(i)(B)). Exhibit A lists the Subcontractors that receive PHI on the effective date. Business Associate may add or replace a Subcontractor provided a written agreement meeting this section is in place before the Subcontractor receives PHI and the list in Exhibit A, as published on the platform's compliance page, is updated within thirty (30) days.

3.5 Right of access. Business Associate shall make PHI in a Designated Record Set available to Covered Entity, or at Covered Entity's direction to the Individual, as necessary for Covered Entity to meet its obligations under 45 CFR 164.524, within ten (10) business days of a written request (45 CFR 164.504(e)(2)(ii)(E)). The platform's patient-facing export and records-request features satisfy this obligation for requests handled through them.

3.6 Amendment. Business Associate shall make PHI in a Designated Record Set available for amendment, and shall incorporate any amendment that Covered Entity directs, as necessary for Covered Entity to meet its obligations under 45 CFR 164.526, within ten (10) business days of a written request (45 CFR 164.504(e)(2)(ii)(F)).

3.7 Accounting of disclosures. Business Associate shall document disclosures of PHI, and information related to them, as would be required for Covered Entity to respond to a request for an accounting under 45 CFR 164.528, and shall make that information available to Covered Entity within ten (10) business days of a written request (45 CFR 164.504(e)(2)(ii)(G)). The platform's audit log, retained for at least six (6) years, is the record of disclosures made through the platform.

3.8 Requests received directly. If an Individual submits a request for access, amendment or an accounting directly to Business Associate, Business Associate shall forward it to Covered Entity within five (5) business days. Covered Entity remains responsible for responding to the Individual.

3.9 Carrying out Covered Entity's obligations. To the extent Business Associate is to carry out any of Covered Entity's obligations under Subpart E of 45 CFR Part 164, Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation (45 CFR 164.504(e)(2)(ii)(H)).

3.10 Books and records. Business Associate shall make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining Covered Entity's compliance with HIPAA (45 CFR 164.504(e)(2)(ii)(I)). Business Associate shall promptly tell Covered Entity of any such request by the Secretary unless the law prohibits it.

3.11 Workforce. Business Associate shall train the members of its workforce who handle PHI on their obligations under HIPAA and this Agreement, and shall apply appropriate sanctions to workforce members who violate them.

3.12 Location of PHI. Business Associate stores and processes PHI within the United States, in cloud infrastructure regions located in the United States. Business Associate shall not store PHI outside the United States without Covered Entity's prior written consent. Subcontractors' locations are governed by their agreements under section 3.4.

4. Obligations of Covered Entity

4.1 Notice of privacy practices. Covered Entity shall notify Business Associate of any limitation in its notice of privacy practices under 45 CFR 164.520 to the extent the limitation may affect Business Associate's use or disclosure of PHI.

4.2 Changes in permission. Covered Entity shall notify Business Associate of any change in, or revocation of, an Individual's permission to use or disclose PHI, to the extent the change may affect Business Associate's use or disclosure of PHI.

4.3 Restrictions. Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent the restriction may affect Business Associate's use or disclosure of PHI. Restrictions recorded in the platform's patient-preference features are notice under this section.

4.4 Permissible requests. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as sections 2.2 through 2.4 allow.

4.5 Access management. Covered Entity is responsible for the accounts it creates for its workforce on the platform, for granting each user only the access that user needs, for removing access when a workforce member leaves, and for the confidentiality of its users' credentials. Covered Entity is responsible for what its users do with PHI they download, print, fax, mail or send from the platform.

4.6 Communications and consents. Covered Entity is responsible for obtaining any consent or authorization that the law requires before it uses the platform to send appointment reminders, text messages, marketing or other communications to Individuals, and for the content of the communications it sends.

4.7 Minimum necessary. Covered Entity shall provide Business Associate only the PHI that is minimally necessary for Business Associate to perform the services.

5. Term and termination

5.1 Term. This Agreement takes effect on the date Covered Entity accepts it, or if earlier on the date Business Associate first receives PHI from or on behalf of Covered Entity, and continues until all PHI is returned, destroyed or made subject to section 5.4, whichever is later.

5.2 Termination for cause. Covered Entity may terminate this Agreement and the Services Agreement if Covered Entity determines that Business Associate has violated a material term of this Agreement and Business Associate has not cured the violation within thirty (30) days of written notice, or immediately if cure is not possible (45 CFR 164.504(e)(2)(iii)). Business Associate may terminate this Agreement and the Services Agreement on the same basis if Covered Entity has violated a material term of this Agreement.

5.3 Effect of termination of the Services Agreement. This Agreement terminates when the Services Agreement terminates, subject to sections 5.4 and 5.5.

5.4 Return or destruction of PHI. On termination for any reason, Business Associate shall, if feasible, return or destroy all PHI that it still maintains in any form and retain no copies, as follows (45 CFR 164.504(e)(2)(ii)(J)):

(a) For ninety (90) days after termination Business Associate shall keep Covered Entity's complete data export available for download through the platform in machine-readable form, and Covered Entity may direct Business Associate in writing to transmit the export to a successor system Covered Entity names. Where Business Associate itself discontinues the service, the longer export period the Services Agreement promises applies instead.

(b) After that period Business Associate shall destroy the PHI within thirty (30) days, using methods consistent with the guidance of the Secretary on rendering PHI unusable, unreadable or indecipherable to unauthorized persons, and shall certify the destruction in writing on request.

(c) Return or destruction is not feasible for: audit records that HIPAA and other law require Business Associate to retain (retained for at least six (6) years from their creation); encrypted backups, which expire in the ordinary course of Business Associate's backup rotation and are not restored except to recover from a disaster; and records Business Associate must keep to establish or defend legal claims or to comply with law. Business Associate shall extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it keeps the PHI.

5.5 Survival. Sections 2.2, 2.4, 3, 5.4, 6 and 7 survive termination for as long as Business Associate retains any PHI.

6. Liability and indemnification

6.1 Indemnification by Business Associate. Business Associate shall indemnify Covered Entity against third-party claims, and against civil monetary penalties assessed on Covered Entity by a government authority, to the extent caused by Business Associate's or its Subcontractors' breach of this Agreement or violation of HIPAA.

6.2 Indemnification by Covered Entity. Covered Entity shall indemnify Business Associate against third-party claims, and against civil monetary penalties assessed on Business Associate by a government authority, to the extent caused by Covered Entity's or its workforce's breach of this Agreement or violation of HIPAA, including impermissible requests under section 4.4 and communications sent under section 4.6.

6.3 Breach costs. Where a Breach of Unsecured PHI was caused by Business Associate or its Subcontractors, Business Associate shall bear the reasonable, documented cost of the notifications to Individuals, the media and the Secretary that HIPAA requires of Covered Entity as a result, and of credit monitoring where the law requires it.

6.4 Limitation of liability for this Agreement. The limitation of liability in the Services Agreement does not apply to claims arising under this Agreement. Instead, each party's total liability for all claims arising under this Agreement, including under sections 6.1 through 6.3, is limited to the greater of (a) $100,000 and (b) the fees Covered Entity paid Business Associate under the Services Agreement in the twelve (12) months preceding the event giving rise to the claim. This limit does not apply to a party's willful misconduct. Neither party is liable to the other under this Agreement for indirect, incidental or consequential damages, except to the extent they are part of a third-party claim or penalty indemnified under sections 6.1 through 6.3.

7. General

7.1 Regulatory references. A reference in this Agreement to a section of HIPAA means the section as in effect or as amended.

7.2 Amendment. The parties shall amend this Agreement as necessary for Covered Entity or Business Associate to comply with HIPAA as it changes. Business Associate may publish an updated version of this Agreement on the platform with at least thirty (30) days' notice to Covered Entity; the update takes effect on the stated date unless Covered Entity objects in writing before then, in which case the prior version continues until the parties agree on a replacement or the Services Agreement ends.

7.3 Interpretation. Any ambiguity in this Agreement shall be resolved to permit compliance with HIPAA. If this Agreement conflicts with the Services Agreement on the handling of PHI, this Agreement controls.

7.4 No third-party beneficiaries. Nothing in this Agreement confers any right or remedy on any person other than the parties and their successors and permitted assigns.

7.5 Independent contractors. The parties are independent contractors. Nothing in this Agreement creates an agency relationship; Business Associate is not Covered Entity's agent for purposes of the federal common law of agency.

7.6 Notices. Notices under sections 3.3 and 5 shall be in writing and sent by email to the notice addresses in the signature block, and for a Breach notice also by overnight courier where a postal address is on file. Business Associate may additionally post notices to the platform's administrator dashboard. A party shall keep its notice address current. Business Associate's notice address is privacy@rowanflow.com.

7.7 Governing law. This Agreement is governed by the laws of the State of New Jersey, without regard to conflict-of-laws principles, and by HIPAA where it applies. Disputes will be resolved in the state or federal courts located in New Jersey.

7.8 Assignment. Neither party may assign this Agreement without the other's written consent, except that Business Associate may assign it to a successor to the RowanFlow service on the notice the Services Agreement requires, provided the successor assumes this Agreement in writing.

7.9 Entire agreement. This Agreement, with its Exhibits, is the parties' entire agreement on the handling of PHI and supersedes any prior business associate agreement between them.

7.10 Electronic acceptance. Covered Entity accepts this Agreement electronically through the platform, by an administrator who represents that they are authorized to bind Covered Entity, and that acceptance is Covered Entity's signature. Business Associate countersigns by issuing the executed copy. Each party may rely on the executed copy the platform produces, which records the version accepted, the signer, and the date and time of acceptance.

Exhibit A. Services and Subcontractors

A.1 Services that involve PHI. Business Associate creates, receives, maintains and transmits PHI on Covered Entity's behalf to provide, as the Practice's subscription includes them:

  • patient records, scheduling, check-in, intake forms and the patient portal;
  • clinical documentation, including optional AI-assisted drafting and dictation that the treating provider reviews and signs;
  • billing, statements, payments, insurance eligibility, claims, remittance posting, denials and appeals;
  • appointment reminders and other communications the Practice sends to its patients by email, text message, fax and mail;
  • documents the Practice sends to other providers, payers, attorneys and patients;
  • reporting, analytics and the Practice's complete data export;
  • hosting, backup, security monitoring and technical support.

A.2 Subcontractors that receive PHI on the effective date. Each has a written agreement with Business Associate meeting section 3.4. The executed agreements are kept in Business Associate's compliance records.

SubcontractorWhat it does with PHI
Amazon Web Services, Inc.Hosts the platform: databases, file storage, application servers, authentication, email and text-message delivery, logging, backups, and the AI and speech services used for clinical drafting and dictation.
Stedi, Inc.Electronic claims clearinghouse: carries claims, eligibility, claim-status and remittance transactions between the Practice and payers.
Stannp.com (US)Prints and mails the letters, statements and postcards the Practice sends through the platform.
Sinch (Phaxio)Transmits the faxes the Practice sends through the platform.
Google LLC (Workspace)Fallback email relay for transactional email if the primary delivery service is unavailable.

A.3 Not a Subcontractor. Stripe, Inc. processes card payments. Business Associate sends Stripe payment amounts, generic charge descriptions and opaque identifiers only, never clinical information, and treats Stripe as a payment processor under the financial-transaction exemption in 45 CFR 164.501 ("payment") rather than as a business associate.

A.4 Where PHI is stored. Business Associate's own storage of PHI is in Amazon Web Services regions in the United States.

Exhibit B. Summary of safeguards

A summary, on the effective date, of the safeguards Business Associate maintains. It is descriptive; section 3.2 states the obligation.

  • Encryption. PHI is encrypted at rest in databases and file storage and in transit over TLS. Patient files are encrypted with a customer-managed key that rotates annually.
  • Access control. Every user has a unique account. Practice administrators grant and remove their own staff's access. Multi-factor authentication is available for staff accounts. Sessions time out after inactivity.
  • Tenant isolation. Every record carries the Practice's identifier and every query is scoped to it, so one Practice's users cannot reach another Practice's PHI.
  • Audit. Every access to and disclosure of PHI through the platform is written to an append-only audit log retained for at least six years. Infrastructure activity is logged with log-file validation and retained for six years.
  • Backups and recovery. Databases and patient files are backed up daily to a locked backup vault that retains recovery points for thirty-five days independently of the source, plus rolling database snapshots. Recovery procedures are documented and drilled.
  • Network. Application traffic passes through a web application firewall with managed rule sets; application servers and the database run inside a private network.
  • Minimum necessary in AI processing. Optional AI drafting features receive structured clinical values or de-identified narrative, never a patient's name, date of birth or contact details; every AI request is audited; audio for dictation is deleted within one day of processing. Every AI feature is off until the Practice turns it on.
  • Data export. The Practice can produce its complete data export at any time.
  • Incident response. A written incident-response and breach-notification playbook governs detection, containment, assessment and notice.