Last updated: June 18, 2026
This HIPAA Business Associate Agreement ("BAA") supplements the Master Subscription Agreement (the "Agreement") between NorthernPlus Inc., a Delaware corporation ("NorthernPlus"), and the customer that has entered into the Agreement ("Customer"). It applies to the extent NorthernPlus creates, receives, maintains, or transmits Protected Health Information on Customer's behalf, and is offered for eligible engagements where HIPAA applies, as described in an Order Form (for example, on the Advanced tier).
This BAA takes effect when executed as part of an eligible Order Form or when countersigned by NorthernPlus. To request a countersigned BAA, contact hello@northernplus.com. Customer should not submit PHI to the Service unless a BAA is in effect.
Capitalized terms used but not defined in this BAA have the meanings given in the HIPAA Rules or in the Master Subscription Agreement (the "Agreement"). "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, as amended, including by the HITECH Act. "PHI" means Protected Health Information, and "ePHI" means electronic PHI, in each case limited to PHI that NorthernPlus creates, receives, maintains, or transmits for or on behalf of Customer under the Agreement.
In this BAA, NorthernPlus is the "Business Associate" and Customer is the "Covered Entity." If Customer is itself a Business Associate of a third-party covered entity, then NorthernPlus is Customer's Subcontractor and the obligations of a Business Associate in this BAA apply to NorthernPlus as Subcontractor and the obligations of a Covered Entity apply to Customer.
NorthernPlus may use and disclose PHI only as follows:
NorthernPlus will not use or disclose PHI other than as permitted or required by this BAA or as Required by Law, and will not Sell PHI or use or disclose PHI for marketing except as permitted by the HIPAA Rules and the Agreement.
NorthernPlus will:
Customer will:
This BAA is effective on the effective date of the Agreement (or the date Customer becomes eligible for and elects a BAA, as stated in an Order Form) and remains in effect until all PHI is returned or destroyed or, where return or destruction is infeasible, the protections of this BAA are extended to that PHI.
If either party becomes aware of a material breach by the other of its obligations under this BAA, the non-breaching party may require the breaching party to cure the breach within a reasonable period and, if the breach is not cured, may terminate the Agreement and this BAA to the extent permitted by the HIPAA Rules.
On termination of this BAA, NorthernPlus will, if feasible, return or destroy all PHI that it maintains and retain no copies, including by requiring its Subcontractors to do the same. Where return or destruction is infeasible, NorthernPlus will extend the protections of this BAA to that PHI and limit further use or disclosure to the purposes that make return or destruction infeasible, for so long as it maintains the PHI.
7.1 Interpretation. This BAA is to be interpreted so that NorthernPlus and Customer comply with the HIPAA Rules. The parties will negotiate in good faith to amend this BAA as needed to comply with changes to the HIPAA Rules.
7.2 Relationship to the Agreement; precedence. This BAA forms part of the Agreement. With respect to PHI, this BAA controls over any conflicting term of the Agreement (including the DPA). All other terms of the Agreement, including the limitations and exclusions of liability, continue to apply.
7.3 No third-party beneficiaries. Nothing in this BAA creates any rights in any third party.
7.4 Survival. NorthernPlus's obligations with respect to PHI that it continues to maintain after termination survive termination of this BAA.
Analytics stay off until you choose.
We use cookies to improve the site. Read our Privacy Policy to learn more.