Comprehensive HIPAA compliance framework for protected health information
Owner/Operator: Spyface Tech Company, LLC (d/b/a "ClinicBooking")
Registered Office: 30 N Gould St Ste N, Sheridan, WY 82801, USA
Corporate Contact: hello@spyface.com
Support: care@clinicbooking.com
This Business Associate Agreement ("BAA") forms part of, and is incorporated by reference into, any master agreement, platform agreement, or order between a Covered Entity (or its Business Associate) and ClinicBooking. Where this BAA conflicts with any other agreement between the parties regarding Protected Health Information ("PHI"), this BAA controls to the extent of the conflict.
This BAA is between the "Covered Entity" (or a Business Associate acting on behalf of a Covered Entity) and Spyface Tech Company, LLC (d/b/a "ClinicBooking"), a "Business Associate" under 45 C.F.R. §160.103, solely to the extent ClinicBooking creates, receives, maintains, or transmits PHI on behalf of the Covered Entity in providing agreed services (the "Services").
Capitalized terms not defined here have the meanings in HIPAA, HITECH, and their implementing regulations (45 C.F.R. Parts 160 & 164).
ClinicBooking will request, use, disclose, and retain only the minimum necessary PHI to accomplish the intended purpose as required by 45 C.F.R. §164.502(b).
ClinicBooking will implement and maintain safeguards required by 45 C.F.R. §§164.308, 164.310, and 164.312, including:
Administrative
Risk analysis; policies & procedures; role-based access; workforce training; vendor risk management; sanctions policy.
Physical
Data center standards; facility access controls; device/media disposal; screen privacy; visitor logs.
Technical
Access controls (MFA), audit logs, unique IDs, encryption in transit (TLS 1.2+) and at rest (AES-256), integrity controls, endpoint hardening.
| Safeguard Domain | Illustrative Controls |
|---|---|
| Administrative | Risk analysis; policies & procedures; role-based access; workforce training; vendor risk management; sanctions policy. |
| Physical | Data center standards; facility access controls; device/media disposal; screen privacy; visitor logs. |
| Technical | Access controls (MFA), audit logs, unique IDs, encryption in transit (TLS 1.2+) and at rest (AES-256), integrity controls, endpoint hardening. |
ClinicBooking will ensure that any subcontractor or agent that creates, receives, maintains, or transmits PHI on ClinicBooking's behalf agrees in writing to obligations no less stringent than those applicable to ClinicBooking under this BAA (45 C.F.R. §164.502(e)(1)). A current list of subprocessors used for PHI-relevant functions will be made available upon request under appropriate confidentiality.
ClinicBooking will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining Covered Entity's compliance with HIPAA (45 C.F.R. §164.504(e)(2)(ii)(H)).
ClinicBooking is an independent contractor. Nothing creates an agency, partnership, or joint venture. ClinicBooking does not practice medicine or provide medical services.
All notices under this BAA must be in writing and sent to the contacts below (or as otherwise updated by written notice):
ClinicBooking (Business Associate)
Covered Entity
As specified in the applicable order, MSA/SaaS agreement, or by written designation from Covered Entity.
| Party | Notice Details |
|---|---|
| ClinicBooking (Business Associate) | Spyface Tech Company, LLC (d/b/a "ClinicBooking") 30 N Gould St Ste N, Sheridan, WY 82801, USA Corporate: hello@spyface.com Support: care@clinicbooking.com |
| Covered Entity | As specified in the applicable order, MSA/SaaS agreement, or by written designation from Covered Entity. |
Questions about this BAA? Contact Corporate at hello@spyface.com.
Customer support for platform features: care@clinicbooking.com.
If the parties have executed a separate paper or e-signature BAA, that signed document governs and supersedes this online form. Otherwise, this BAA is deemed accepted when the Covered Entity (or its Business Associate) (i) executes an order, MSA, or equivalent instrument referencing HIPAA/PHI services with ClinicBooking, or (ii) otherwise instructs ClinicBooking to process PHI under the Services.