Business Associate Agreement

If you use PsychAssist.ai, this agreement is already in force. Under Section 4(d), acceptance occurs on use of the service or through digital onboarding - you do not need to sign anything to be covered. The copy below is provided in full so you can read it, and as a countersigned download for your compliance records.

What a BAA is, and why it matters

Under HIPAA, if a third party creates, receives, maintains or transmits protected health information on your behalf, they are a Business Associate - and you are required to have a written agreement with them before that happens. It is not optional and it is not a formality. The obligation sits with you, the covered entity, not with the vendor.

A Business Associate Agreement sets out what the vendor may do with patient information, what safeguards they must maintain, how quickly they must tell you if something goes wrong, what happens to the data if you leave, and whether their own subcontractors are bound by the same terms.

In an assessment practice this covers more ground than people expect. Intake responses, scored protocols, session notes, uploaded score reports, generated report text, scheduling and contact details - all of it is protected health information.

Every vendor that touches patient data needs one - including AI tools

This is worth stating plainly, because it is the most common gap we see in assessment practices.

Any tool that receives patient information needs a BAA in place before it does. Your practice management system, your scheduling tool, your transcription service, your storage provider, your email host if patient information passes through it - and any AI system you use to help write, summarise or edit clinical documentation.

Pasting patient material into a general-purpose AI assistant without an agreement in place is a disclosure of protected health information to a third party. That remains true whether the material is a full report, a paragraph of a clinical interview, or a set of scores with a name attached, and it remains true if you intend to delete the conversation afterwards.

Some major AI providers do offer Business Associate Agreements, typically on enterprise or API plans rather than consumer tiers. The point is not that AI cannot be used safely - it is that the agreement has to exist, in writing, before any patient information is entered, and it is your responsibility to confirm that it does.

Ask every vendor for their BAA. If they cannot produce one, they should not be receiving patient information.

Key terms at a glance

A plain summary for reference. The agreement below is the operative document.

Business AssociatePsychAssist.ai, a DBA of LAR Holdings
Covered EntityThe clinician or practice using the platform
What PHI is used forProviding the PsychAssist.ai service only, or as required by law
SafeguardsAdministrative, technical and physical, per 45 CFR §§ 164.308, 164.310, 164.312
Breach notificationWithout unreasonable delay, no later than 60 calendar days, per 45 CFR § 164.410
SubcontractorsBound by the same restrictions and conditions
On terminationPHI returned or destroyed; protections continue if that is infeasible
Governing lawState of Michigan
How it takes effectOn use of the service or digital acceptance during onboarding (§ 4(d))

Get a countersigned copy

Download the countersigned BAA (PDF)

This copy is executed by PsychAssist.ai as Business Associate, with the Covered Entity block left blank for your practice to complete and file. It is provided for your compliance records - the agreement is already in force under Section 4(d) whether or not you return a signed copy.

The agreement in full

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement ("Agreement") is entered into by and between the Clinician User ("Covered Entity") and PsychAssist.ai, a DBA of LAR Holdings ("Business Associate").

Effective Date: June 1, 2025

1. DEFINITIONS

All terms used herein shall have the same meanings as those in the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), and its implementing regulations, including 45 CFR Parts 160 and 164.

Protected Health Information (PHI): Individually identifiable health information maintained or transmitted in any form, created or received by Business Associate from or on behalf of Covered Entity.

2. OBLIGATIONS OF BUSINESS ASSOCIATE

Business Associate agrees to:

a. Permitted Uses and Disclosures

Use or disclose PHI solely to provide services under the PsychAssist.ai platform, or as required by law. Services include, but are not limited to:

  • Intake form collection and processing
  • AI-assisted report generation
  • Patient and clinician communication portals
  • Practice management tools
  • Secure PHI storage and data handling

All use or disclosure of PHI shall be in compliance with HIPAA.

b. Safeguards

Implement appropriate administrative, technical, and physical safeguards (in compliance with 45 CFR §§ 164.308, 164.310, and 164.312) to ensure the confidentiality, integrity, and availability of PHI.

c. Breach Notification

Report any unauthorized use or disclosure of PHI or any security incident involving PHI to the Covered Entity without unreasonable delay, and no later than 60 calendar days after discovery, in accordance with 45 CFR § 164.410.

d. Subcontractors

Ensure all subcontractors and agents (including AWS and EZOPS) who receive PHI agree to the same restrictions and conditions that apply to Business Associate with respect to such information.

e. Access and Amendment

Provide access to PHI to the Covered Entity or individual, and make any amendments as required under 45 CFR §§ 164.524 and 164.526.

f. Accounting of Disclosures

Maintain and provide records of disclosures as necessary to comply with 45 CFR § 164.528.

g. Internal Practices

Make available to the Secretary of the U.S. Department of Health and Human Services all records and practices related to the use and disclosure of PHI for determining HIPAA compliance.

3. TERM AND TERMINATION

a. Term

This Agreement shall be effective on the Effective Date and shall remain in effect until terminated by either party in accordance with this section.

b. Termination for Cause

If Covered Entity becomes aware of a pattern of activity or practice of Business Associate that constitutes a material breach, and the breach is not cured within 30 days of written notice, Covered Entity may terminate this Agreement.

c. Effect of Termination

Upon termination, Business Associate shall return or destroy all PHI. If return or destruction is infeasible, Business Associate will continue to extend the protections of this Agreement to such PHI and limit further uses and disclosures.

4. MISCELLANEOUS

a. Governing Law

This Agreement shall be governed by and construed in accordance with the laws of the State of Michigan.

b. No Agency Relationship

Nothing in this Agreement creates an agency relationship, joint venture, or partnership between the parties.

c. Amendment

This Agreement may only be modified in writing signed by both parties, except where required to maintain HIPAA compliance.

d. Digital Acceptance

Covered Entity's use of PsychAssist.ai services after the Effective Date, including agreement to the Terms of Service and/or explicit acceptance via digital onboarding, constitutes acceptance of this Agreement.

e. Record of Agreement

This Agreement will be stored in the Covered Entity's user account and made publicly available at https://psychassist.ai/baa.

PARTIES TO AGREEMENT

BUSINESS ASSOCIATE

PsychAssist.ai, a DBA of LAR Holdings

1900 Whites Road

Kalamazoo, MI 49008

Contact: Chris Barnes, Founder & CEO

Email: legal@psychassist.ai

COVERED ENTITY

Entity Name: [To be completed by user]

Entity Address: [To be completed by user]

Contact: [To be completed by user]

Email: [To be completed by user]

Digital Acceptance: By accepting this Agreement electronically during account creation or use of services, Covered Entity agrees to the terms herein.

Version 1.0 · Effective June 1, 2025

Questions, or a different form of BAA

If your practice, health system or institution requires its own BAA form, or you need changes to these terms, write to legal@psychassist.ai and we will work through it.

Questions about how patient information is handled on the platform are answered on our Trust and Security page and in The Defensible Assessment Documentation Standard.

This page reproduces the agreement in full as required by Section 4(e). Nothing on this page is legal advice.