This Business Associate Agreement ("BAA") supplements the Terms of Service between MBN Care Solutions, LLC ("Business Associate" or "MBN") and the customer adult family home ("Covered Entity"). It governs Protected Health Information ("PHI"), including electronic PHI ("ePHI"), that MBN creates, receives, maintains, or transmits on the Covered Entity's behalf. Capitalized terms not defined here have the meanings in the HIPAA Rules (45 CFR Parts 160 and 164). Where this BAA conflicts with the Terms of Service as to PHI, this BAA controls.
MBN may use and disclose PHI only as necessary to perform the services described in the Terms of Service and as this BAA permits, and may not use or disclose PHI in a manner that would violate the Privacy Rule if done by the Covered Entity. MBN may use PHI for its own proper management and administration and to carry out its legal responsibilities, and may de-identify PHI in accordance with 45 CFR § 164.514(b), only with the protections stated in this BAA.
MBN agrees that it will:
(A)Not use or disclose PHI other than as permitted or required by this BAA or as required by law. § 164.504(e)(2)(ii)(A)
(B)Use appropriate safeguards, and comply with the Security Rule (Subpart C of Part 164) with respect to ePHI, to prevent use or disclosure of PHI other than as provided by this BAA. § 164.504(e)(2)(ii)(B); § 164.314(a)
(C)Report to the Covered Entity any use or disclosure of PHI not provided for by this BAA of which it becomes aware, including breaches of unsecured PHI and any Security Incident. See Section 3 (breach notification). § 164.504(e)(2)(ii)(C); § 164.314(a)(2)(i)(C); § 164.410
(D)Ensure subcontractors that create, receive, maintain, or transmit PHI on MBN's behalf agree, in writing, to the same restrictions, conditions, and requirements that apply to MBN (flow-down). § 164.504(e)(2)(ii)(D); § 164.314(a)(2)(i)(B)
(E)Make PHI available for access by individuals as required by 45 CFR § 164.524. § 164.504(e)(2)(ii)(E)
(F)Make PHI available for amendment, and incorporate amendments, as required by 45 CFR § 164.526. § 164.504(e)(2)(ii)(F)
(G)Maintain and make available the information required to provide an accounting of disclosures as required by 45 CFR § 164.528. § 164.504(e)(2)(ii)(G)
(H)Comply with the Covered Entity's Privacy Rule obligations to the extent MBN is to carry out any such obligation. § 164.504(e)(2)(ii)(H)
(I)Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance. § 164.504(e)(2)(ii)(I)
(J)Return or destroy all PHI at termination as provided in Section 6; if return or destruction is infeasible, extend the protections of this BAA and limit further use to those purposes that make return or destruction infeasible. § 164.504(e)(2)(ii)(J)
MBN will notify the Covered Entity of a breach of unsecured PHI without unreasonable delay and no later than ten (10) business days after discovery (a contractual commitment shorter than the 60-day outer limit permitted by § 164.410(b)). The notice will identify, to the extent known, each individual whose unsecured PHI was or is reasonably believed to have been involved, and provide the information the Covered Entity needs for its notifications under § 164.404. MBN will cooperate with the Covered Entity's investigation and mitigation.
Beyond the minimum, MBN commits to the following controls for ePHI (aligned to what the Service actually enforces): encryption of ePHI in transit and at rest; multi-factor authentication available for user accounts; role-based access control and per-home data isolation; audit logging of access to and changes of records; and encrypted backups. MBN maintains administrative, physical, and technical safeguards appropriate to its role as a business associate.
MBN uses the following categories of subprocessors, each under a HIPAA-compliant written agreement: Amazon Web Services (cloud hosting and storage). MBN will maintain a current list of subprocessors that handle PHI and will not permit a subprocessor to handle PHI without a compliant downstream agreement in place.
On at least ten (10) days' written notice, and no more than once per year absent cause, the Covered Entity may review MBN's relevant compliance documentation. MBN may satisfy an audit request by providing a current third-party security attestation where available.
MBN will indemnify the Covered Entity for the portion of losses, including regulatory penalties, directly caused by MBN's or its subcontractors' breach of this BAA. This allocation is contractual; HIPAA itself provides no private right of action.
The Covered Entity will: obtain any consents or authorizations required for MBN to use PHI as contemplated; maintain its own HIPAA policies and safeguards; not request MBN to use or disclose PHI in a manner that would violate the Privacy Rule; and enter PHI only for residents for whom it is authorized to keep such records.
Questions about this BAA: [email protected].
© 2026 MBN Care Solutions, LLC. All rights reserved.