M MBN Care App
HomePricingAbout Log InGet Started
⚠ Draft for attorney review. This Business Associate Agreement is a thorough starting point that tracks the mandatory elements of 45 CFR § 164.504(e). It must be reviewed and finalized by a licensed Washington healthcare attorney before use. It is not legal advice.

Business Associate Agreement

Version 1.0 · Effective July 14, 2026 · Between MBN Care Solutions, LLC (Business Associate) and Customer (Covered Entity)

This Business Associate Agreement ("BAA") supplements the Terms of Service between MBN Care Solutions, LLC ("Business Associate" or "MBN") and the customer adult family home ("Covered Entity"). It governs Protected Health Information ("PHI"), including electronic PHI ("ePHI"), that MBN creates, receives, maintains, or transmits on the Covered Entity's behalf. Capitalized terms not defined here have the meanings in the HIPAA Rules (45 CFR Parts 160 and 164). Where this BAA conflicts with the Terms of Service as to PHI, this BAA controls.

1.Permitted Uses & Disclosures § 164.504(e)(2)(i)

MBN may use and disclose PHI only as necessary to perform the services described in the Terms of Service and as this BAA permits, and may not use or disclose PHI in a manner that would violate the Privacy Rule if done by the Covered Entity. MBN may use PHI for its own proper management and administration and to carry out its legal responsibilities, and may de-identify PHI in accordance with 45 CFR § 164.514(b), only with the protections stated in this BAA.

2.Obligations of Business Associate

MBN agrees that it will:

(A)Not use or disclose PHI other than as permitted or required by this BAA or as required by law. § 164.504(e)(2)(ii)(A)

(B)Use appropriate safeguards, and comply with the Security Rule (Subpart C of Part 164) with respect to ePHI, to prevent use or disclosure of PHI other than as provided by this BAA. § 164.504(e)(2)(ii)(B); § 164.314(a)

(C)Report to the Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including breaches of unsecured PHI and any Security Incident. See Section 3 (breach notification). § 164.504(e)(2)(ii)(C); § 164.314(a)(2)(i)(C); § 164.410

(D)Ensure subcontractors that create, receive, maintain, or transmit PHI on MBN's behalf agree, in writing, to the same restrictions, conditions, and requirements that apply to MBN (flow-down). § 164.504(e)(2)(ii)(D); § 164.314(a)(2)(i)(B)

(E)Make PHI available for access by individuals as required by 45 CFR § 164.524. § 164.504(e)(2)(ii)(E)

(F)Make PHI available for amendment, and incorporate amendments, as required by 45 CFR § 164.526. § 164.504(e)(2)(ii)(F)

(G)Maintain and make available the information required to provide an accounting of disclosures as required by 45 CFR § 164.528. § 164.504(e)(2)(ii)(G)

(H)Comply with the Covered Entity's Privacy Rule obligations to the extent MBN is to carry out any such obligation. § 164.504(e)(2)(ii)(H)

(I)Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance. § 164.504(e)(2)(ii)(I)

(J)Return or destroy all PHI at termination as provided in Section 6; if return or destruction is infeasible, extend the protections of this BAA and limit further use to those purposes that make return or destruction infeasible. § 164.504(e)(2)(ii)(J)

3.Breach & Security-Incident Notification § 164.410

MBN will notify the Covered Entity of a breach of unsecured PHI without unreasonable delay and no later than ten (10) business days after discovery (a contractual commitment shorter than the 60-day outer limit permitted by § 164.410(b)). The notice will identify, to the extent known, each individual whose unsecured PHI was or is reasonably believed to have been involved, and provide the information the Covered Entity needs for its notifications under § 164.404. MBN will cooperate with the Covered Entity's investigation and mitigation.

4.Enhanced Safeguards

Beyond the minimum, MBN commits to the following controls for ePHI (aligned to what the Service actually enforces): encryption of ePHI in transit and at rest; multi-factor authentication available for user accounts; role-based access control and per-home data isolation; audit logging of access to and changes of records; and encrypted backups. MBN maintains administrative, physical, and technical safeguards appropriate to its role as a business associate.

5.Subcontractors & Subprocessors

MBN uses the following categories of subprocessors, each under a HIPAA-compliant written agreement: Amazon Web Services (cloud hosting and storage). MBN will maintain a current list of subprocessors that handle PHI and will not permit a subprocessor to handle PHI without a compliant downstream agreement in place.

6.Term, Termination & Return of PHI

  • Term. This BAA is effective while the Covered Entity's subscription is active and PHI is maintained by MBN.
  • Termination for cause. The Covered Entity may terminate if it determines MBN has violated a material term of this BAA and MBN fails to cure within a reasonable period. If termination is not feasible, the Covered Entity may report the violation to HHS. § 164.504(e)(2)(iii); § 164.504(e)(1)(ii)
  • Return or destruction. Within 30 days of termination, MBN will return PHI in a machine-readable format and/or destroy all PHI it maintains, and will provide written certification of destruction using industry-standard sanitization methods. Where return or destruction is infeasible, MBN will continue to protect the PHI and limit further use accordingly.
  • Survival. The obligations regarding breach notification and return/destruction of PHI survive termination.

7.Audit Rights

On at least ten (10) days' written notice, and no more than once per year absent cause, the Covered Entity may review MBN's relevant compliance documentation. MBN may satisfy an audit request by providing a current third-party security attestation where available.

8.Indemnification

MBN will indemnify the Covered Entity for the portion of losses, including regulatory penalties, directly caused by MBN's or its subcontractors' breach of this BAA. This allocation is contractual; HIPAA itself provides no private right of action.

9.Covered Entity Responsibilities

The Covered Entity will: obtain any consents or authorizations required for MBN to use PHI as contemplated; maintain its own HIPAA policies and safeguards; not request MBN to use or disclose PHI in a manner that would violate the Privacy Rule; and enter PHI only for residents for whom it is authorized to keep such records.

Questions about this BAA: [email protected].

© 2026 MBN Care Solutions, LLC. All rights reserved.

© 2026 MBN Care Solutions, LLC Terms Privacy Supports WAC 388-76 recordkeeping