ClientForms Business Associate Agreement
Version: v1 Effective date: 1 August 2026
This Business Associate Agreement (this "BAA") is entered into between:
Covered Entity: the practice or individual practitioner that holds the ClientForms organisation account through which this BAA is accepted ("Covered Entity", "you"); and
Business Associate: Move to Digital (sole trader, Queensland, Australia), trading as ClientForms ("Business Associate", "ClientForms", "we").
Covered Entity and Business Associate are each a "Party" and together the "Parties".
This BAA applies to every United States ClientForms organisation account, on every plan, including accounts on the free tier. It supplements, and is a part of, the agreement under which ClientForms provides its services to Covered Entity (the ClientForms Terms of Service, the "Agreement").
Background
A. Covered Entity is a "covered entity" (or a business associate of a covered entity) as defined under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, as amended by the HITECH Act, and the regulations promulgated under them by the U.S. Department of Health and Human Services ("HHS") (collectively, "HIPAA").
B. ClientForms provides a clinical assessment platform through which Covered Entity sends, collects, scores, and reviews patient assessments and practice forms. In providing those services, ClientForms creates, receives, maintains, and transmits Protected Health Information on behalf of Covered Entity, and is therefore a "business associate" of Covered Entity as that term is defined in 45 CFR 160.103.
C. This BAA provides the satisfactory assurances required by 45 CFR 164.502(e)(1)(i) and 164.504(e).
1. Definitions
Capitalized terms used but not defined in this BAA have the meanings given to them in HIPAA, including 45 CFR Parts 160 and 164. In particular:
- "Breach" has the meaning given in 45 CFR 164.402.
- "Designated Record Set" has the meaning given in 45 CFR 164.501.
- "Electronic PHI" means PHI maintained in or transmitted by electronic media, as described in 45 CFR 160.103.
- "Individual" has the meaning given in 45 CFR 160.103 and includes a person who qualifies as a personal representative under 45 CFR 164.502(g).
- "Protected Health Information" or "PHI" has the meaning given in 45 CFR 160.103, limited to the information created, received, maintained, or transmitted by Business Associate from or on behalf of Covered Entity. In the ClientForms platform this includes patient names, contact details, dates of birth, assessment responses, scores, intake and practice-form submissions, and documents generated from them.
- "Security Incident" has the meaning given in 45 CFR 164.304.
- "Subcontractor" has the meaning given in 45 CFR 160.103.
- "Unsecured PHI" has the meaning given in 45 CFR 164.402.
2. Permitted Uses and Disclosures of PHI
2.1 To provide the services. Business Associate may use and disclose PHI only as necessary to provide, maintain, secure, and support the ClientForms platform for Covered Entity under the Agreement, as expressly permitted by Section 2.2, or as required by law.
2.2 Management and administration. Business Associate may use PHI as necessary for its proper management and administration and to carry out its legal responsibilities, and may disclose PHI for those purposes only if the disclosure is required by law, or Business Associate obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as required by law or for the purposes for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality of which it becomes aware.
2.3 Minimum necessary. Business Associate will limit its uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 CFR 164.502(b) and section 13405(b) of the HITECH Act.
2.4 Prohibited uses. Notwithstanding Sections 2.1 and 2.2, Business Associate will not:
- use PHI to train, fine-tune, or evaluate any machine-learning or artificial-intelligence model;
- sell PHI, or use or disclose PHI for marketing purposes;
- use or disclose PHI for analytics products, benchmarking, or any other purpose not permitted by Sections 2.1 through 2.3;
- de-identify PHI for any purpose other than at Covered Entity's documented request.
2.5 No data ownership. Business Associate's stewardship of PHI confers no ownership interest in it. As between the Parties, Covered Entity owns all PHI.
3. Safeguards
3.1 Security Rule compliance. Business Associate will implement administrative, physical, and technical safeguards that comply with the HIPAA Security Rule (45 CFR 164.308, 164.310, 164.312, and 164.316) with respect to Electronic PHI. Business Associate maintains a written security policy set, a documented risk analysis, and a written incident response and breach procedure, reviewed at least annually, and has designated a Security Official responsible for them (45 CFR 164.308(a)(1)–(2), 164.316). The Security Official is contactable at privacy@clientforms.app.
3.2 Specific safeguards. Without limiting Section 3.1, Business Associate maintains for US customer PHI:
- US data residency — PHI for US organisation accounts is stored in United States data-center regions (US-East) by the storage subcontractor identified in Exhibit A (Convex, Inc.), under a business associate agreement.
- Encryption at rest — AES-256 encryption of stored data.
- Encryption in transit — TLS 1.2 or higher for data in transit.
- Organisation-scoped access control — every read and write of PHI through the platform is scoped to the Covered Entity's organisation account; workforce users authenticate through a managed identity provider.
- Event logging — the platform records defined events against patient records: access to a patient record by a practitioner other than the one who holds it, changes to patient record fields, and report exports. This is event logging of those specific actions and is not a log of every read of every record.
3.2.1 Offshore access disclosure. PHI for US accounts is stored and processed in United States regions. Business Associate is located in Australia, and administrative and support access to systems holding PHI occurs from Australia under the safeguards in this Section 3. HIPAA does not restrict the location of a business associate or its personnel; Covered Entities subject to a state or program-specific restriction on offshore access to data (for example, certain state Medicaid rules) should assess this disclosure against those obligations and may contact Business Associate with questions.
3.3 Email. Business Associate ensures that notification email sent by the platform to Covered Entity or its workforce (for example, "an assessment was completed") contains no PHI in its subject line, preheader, or body. Email that Covered Entity directs the platform to send to an Individual — assessment invitations and results or screening summaries a clinician chooses to email — may contain PHI and is transmitted through the email subcontractor identified in Exhibit A. Where Covered Entity directs the platform to send PHI to an Individual by email, Covered Entity is responsible for confirming that the Individual has requested delivery by email and has been advised of the risks of unencrypted email, consistent with 45 CFR 164.524 and OCR's individual-access guidance.
3.4 Workforce. Business Associate will ensure that members of its workforce with access to PHI are bound by obligations of confidentiality and comply with this BAA.
4. Subcontractors
4.1 Except as expressly disclosed in Exhibit A, Business Associate will ensure, in accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA, including implementing reasonable and appropriate safeguards for Electronic PHI. Exhibit A states, per provider, the assurances that are in place and any exception, so that Covered Entity can see the actual position rather than a blanket warranty.
4.2 Named subcontractors. The Subcontractors and service providers engaged by Business Associate as of the version date of this BAA are listed in Exhibit A. Business Associate will give Covered Entity at least thirty (30) days' notice, through the platform, before any new Subcontractor creates, receives, maintains, or transmits PHI, by publishing an updated version of this BAA and its Exhibit A. Where Exhibit A, as of the version effective date, already discloses a planned engagement and its target timeline (including the AWS engagements described in Exhibit A), that disclosure constitutes the notice this Section requires, and the disclosed engagement may proceed on the disclosed timeline even where fewer than thirty (30) days elapse between the version effective date and the date that Subcontractor first handles PHI.
5. Reporting to Covered Entity
5.1 Impermissible uses and disclosures. Business Associate will report to Covered Entity in writing any use or disclosure of PHI not provided for by this BAA of which it becomes aware, without unreasonable delay and in no case later than fifteen (15) calendar days after discovery.
5.2 Security Incidents. Business Associate will report to Covered Entity any successful Security Incident affecting Covered Entity's Electronic PHI of which it becomes aware, on the same timeline as Section 5.1. The Parties acknowledge that this section constitutes notice of the ongoing existence of routine unsuccessful attempts at unauthorized access (such as pings, port scans, and denial-of-service attempts that do not result in unauthorized access to PHI), and no separate report of such unsuccessful attempts is required.
5.3 Breach of Unsecured PHI. Business Associate will notify Covered Entity in writing of any Breach of Unsecured PHI without unreasonable delay and in no case later than fifteen (15) calendar days after discovery of the Breach, so that Covered Entity can meet its own notification obligations under 45 CFR 164.404–164.408, including the 60-day individual-notification limit of 164.404. The notification will include, to the extent known: the identity of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; a description of what happened, the date of the Breach and the date of its discovery; the types of Unsecured PHI involved; and the steps Business Associate is taking to investigate, mitigate, and protect against further Breaches, as contemplated by 45 CFR 164.410. Business Associate will supplement the notification as further information becomes available.
5.4 Mitigation. Business Associate will take reasonable measures to mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI by Business Associate or its Subcontractors in violation of this BAA.
6. Individual Rights Support
6.1 Access (45 CFR 164.524). The platform gives Covered Entity direct, self-service access to the PHI it holds, including patient record and report exports. In addition, on request Business Associate will make available to Covered Entity, within ten (10) business days, any PHI in a Designated Record Set that is not accessible to Covered Entity through the platform, to enable Covered Entity to respond to an Individual's access request.
6.2 Amendment (45 CFR 164.526). On Covered Entity's request, Business Associate will make PHI in a Designated Record Set available for amendment, and will incorporate any amendment Covered Entity directs, within fifteen (15) business days. Most patient record fields are directly editable by Covered Entity through the platform.
6.3 Accounting of disclosures (45 CFR 164.528). Business Associate will document disclosures of PHI, and information related to such disclosures, as would be required for Covered Entity to respond to a request for an accounting of disclosures, and will provide that information to Covered Entity within ten (10) business days of a written request.
6.4 Requests received directly. If an Individual (or personal representative) submits a request for access, amendment, or an accounting directly to Business Associate, Business Associate will forward the request to Covered Entity within ten (10) business days. Decisions on such requests are the sole responsibility of Covered Entity.
6.5 Covered Entity obligations carried out by Business Associate. To the extent Business Associate is to carry out one or more of Covered Entity's obligations under Subpart E of 45 CFR Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations (45 CFR 164.504(e)(2)(ii)(H)).
7. Availability of Books and Records
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Covered Entity available to the Secretary of HHS for purposes of determining compliance with HIPAA.
8. Obligations of Covered Entity
Covered Entity will:
8.1 notify Business Associate of any limitation in its notice of privacy practices under 45 CFR 164.520, to the extent the limitation may affect Business Associate's use or disclosure of PHI;
8.2 notify Business Associate of any change in, or revocation of, an Individual's permission to use or disclose PHI, to the extent the change may affect Business Associate's use or disclosure of PHI;
8.3 notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to under 45 CFR 164.522, to the extent the restriction may affect Business Associate's use or disclosure of PHI; and
8.4 not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity (except as permitted for a business associate's management and administration under Section 2.2).
9. Term and Termination
9.1 Term. This BAA takes effect, as between the Parties, on the date Covered Entity accepts it through the platform, and continues until the Agreement ends or this BAA is terminated in accordance with this Section 9. The effective date shown at the top of this document is the version effective date — the date this version was published and became available for acceptance — not the date this BAA binds any particular Covered Entity.
9.2 Termination for cause. Either Party may terminate this BAA and the Agreement if the other Party has materially breached this BAA and has failed to cure the breach within thirty (30) days of written notice. If cure is not possible, the non-breaching Party may terminate immediately on written notice.
9.3 Return or destruction at termination (45 CFR 164.504(e)(2)(ii)(J)). During the term, Business Associate retains PHI and does not purge it on a timer; record-keeping duration is governed by Covered Entity's own state-law retention obligations. On termination of the Agreement for any reason:
- Covered Entity may export its PHI through the platform's export features before its account closes, and may request Business Associate's assistance with export within thirty (30) days after termination;
- on Covered Entity's written request, Business Associate will destroy the PHI it holds for Covered Entity within thirty (30) days of the request and confirm destruction in writing;
- if return or destruction is infeasible (including where retention is required by law), Business Associate will notify Covered Entity of the conditions making it infeasible, and will extend the protections of this BAA to the retained PHI, limit further use and disclosure to the purposes that make return or destruction infeasible, and destroy the PHI when those conditions end.
10. Acceptance and Execution
This BAA is offered to every US organisation account and is accepted electronically: Covered Entity's authorised user reviews the document and accepts it in the ClientForms dashboard (Settings → Practice Profile), typing their full name and, optionally, their title. ClientForms records the accepting organisation, user, typed name, document version, and timestamp as an append-only audit record, and will make that record available to Covered Entity on request. Publication of this BAA in the platform constitutes Business Associate's standing offer and agreement to its terms; the BAA is executed by both Parties on Covered Entity's acceptance. A countersigned PDF copy is available on request to support@clientforms.app.
11. Miscellaneous
11.1 Regulatory references. A reference to a section of HIPAA or the Code of Federal Regulations means the section as in effect or as amended.
11.2 Amendment. The Parties agree to take such action as is necessary to amend this BAA to comply with changes to HIPAA. Business Associate amends this BAA by publishing a new numbered version; each acceptance records the version accepted, and a published amendment does not retroactively alter the version Covered Entity accepted. For a material amendment (one that changes a Party's substantive rights or obligations), Business Associate will request Covered Entity's affirmative re-acceptance through the platform, recorded in the same manner as Section 10. For a non-material amendment (clarifications and corrections that do not change either Party's substantive rights or obligations), Business Associate will give at least thirty (30) days' notice through the platform, and the amended version takes effect for Covered Entity at the end of the notice period; Business Associate's records will show the notice given and the version transition. A change to the Subcontractors handling PHI is governed by Section 4.2 (30 days' advance notice before any new Subcontractor handles PHI), and any such change that reduces protections for PHI is a material amendment.
11.3 Interpretation. Any ambiguity in this BAA will be interpreted to permit compliance with HIPAA. If this BAA conflicts with the Agreement, this BAA governs with respect to PHI.
11.4 No third-party beneficiaries. Nothing in this BAA confers any right or remedy on any person other than the Parties.
11.5 Survival. The obligations of Business Associate under Sections 2, 3, 5, 6, 7, and 9.3 survive termination of this BAA for as long as Business Associate retains any PHI.
11.6 Notices. Notices under this BAA will be sent: to Covered Entity, at the practice email address held on its ClientForms account; to Business Associate, at privacy@clientforms.app, which reaches the Security Official. Notices of a suspected or actual Breach or Security Incident should use that address.
11.7 Relationship to the Agreement. This BAA is part of, and is governed by and construed with, the Agreement it supplements; Section 11.3 controls its interpretation with respect to HIPAA.
Exhibit A — Subcontractors and Service Providers
As of the version effective date of v1. Updated by publishing a new version of this BAA with the advance notice Section 4.2 requires — at least thirty (30) days before any new Subcontractor handles PHI.
Subcontractors that create, receive, maintain, or transmit PHI
| Subcontractor | Role | PHI handled | Assurances |
|---|---|---|---|
| Convex, Inc. (Delaware, USA) | Database and backend compute — US-East region | All stored PHI for US accounts: patient records, assessment responses, scores, intake and practice-form submissions. (Convex file storage holds practice logos only — the platform has no patient file-upload feature.) | Business associate agreement in place (executed 2026-03-31) |
| Vercel, Inc. (Delaware, USA) | Application hosting and compute — serves the web application. PHI is present only in transit and in memory while a request is served; no patient records are stored with this provider | Transit and in-memory processing of requests containing PHI | Exception disclosed under Section 4.1, remediation in progress. A business associate agreement is not in place with this provider as at the version date. Business Associate is migrating application hosting for US accounts to Amazon Web Services, Inc. (AWS), whose business associate agreement Business Associate will execute before any PHI reaches that provider, targeted for completion by 28 August 2026, after which this Exhibit will be updated by a new version of this BAA. This disclosure constitutes the Section 4.2 notice of the AWS engagement. Until then Business Associate maintains: no patient records in this provider's storage; application logging designed to exclude patient identifiers and form payloads, verified by automated tests over the submission paths that carry patient data; TLS 1.2 or higher for all traffic; and no analytics or advertising scripts on patient-facing routes |
| Maileroo (transactional email) | Delivery of platform email | Clinician-directed notification email carries no PHI (Section 3.3), and every send necessarily carries the recipient's email address. Email sent to Individuals at Covered Entity's direction (assessment invitations; results a clinician chooses to email) may contain PHI and transits and is retained for a limited period by this provider | Exception disclosed under Section 4.1: this provider does not offer a business associate agreement. Business Associate mitigates by keeping PHI out of clinician-directed email entirely (Section 3.3), minimising the PHI this provider holds, and treating delivery to an Individual as occurring at Covered Entity's direction under the individual-access framework of 45 CFR 164.524 (Section 3.3). Remediation in progress: Business Associate is migrating email delivery for US accounts to Amazon Web Services, Inc. (Amazon SES), whose business associate agreement Business Associate will execute before any PHI reaches that provider, targeted for completion by 28 August 2026, after which this Exhibit will be updated by a new version of this BAA. This disclosure constitutes the Section 4.2 notice of the AWS engagement |
Service providers that do not receive PHI content
| Provider | Role | Why no PHI content |
|---|---|---|
| Clerk, Inc. | Authentication for Covered Entity's workforce users | Holds clinician and practice identifiers (names, emails) only; patients are not Clerk users — patient form links use platform-issued session tokens. Clerk's frontend script loads on patient-facing pages, so Clerk sees visitor IP/user-agent, never patient records |
| Cloudflare, Inc. | Bot protection (Turnstile) on public intake pages | Receives visitor IP, browser signals, and page URL during the bot check; never receives form field values |
| Stripe, Inc. | Subscription billing | Practice billing details only; no patient data |
Analytics and advertising scripts do not run on patient-facing form and session routes; analytics elsewhere on the platform never include patient identifiers or session tokens.
Document history
| Version | Date | Change |
|---|---|---|
| v1 | 1 August 2026 | Initial version. Drafted from the HHS model business associate agreement provisions (45 CFR 164.504(e)) and adapted to the systems ClientForms operates. |