Rx
MyRxWallet
Business Associate Agreement
HIPAA-Compliant Business Associate Agreement · 45 CFR § 164.314
Between MyRxWallet North America Corporation (Business Associate) and each Covered Entity utilizing our services.
This Agreement governs the use, disclosure, and protection of Protected Health Information.
HIPAA / HITECH Compliant 45 CFR § 164.314 OMNIBUS RULE 2013 HITECH ACT § 13401
⚖️
LEGALLY BINDING AGREEMENT: This Business Associate Agreement ("BAA") is incorporated by reference into the MyRxWallet platform Terms of Service and becomes effective upon first access to or use of the MyRxWallet platform by any Covered Entity. This Agreement is designed to satisfy the requirements of 45 CFR §§ 164.308(b), 164.314(a), and 164.504(e). Questions should be directed to privacy@myrxwallet.io.
Section 1 — Definitions

Capitalized terms not otherwise defined herein shall have the meanings set forth in the HIPAA Rules.

TermDefinition
"Business Associate" or "BA"MyRxWallet North America Corporation, a Wyoming corporation operating as a HIPAA conduit and digital health infrastructure provider.
"Covered Entity" or "CE"Any healthcare provider, health plan, or healthcare clearinghouse that uses or discloses PHI to Business Associate in connection with the MyRxWallet platform.
"PHI"Protected Health Information as defined at 45 CFR § 160.103, including individually identifiable health information created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
"ePHI"Electronic Protected Health Information — PHI that is created, received, maintained, or transmitted in electronic form.
"HIPAA Rules"The Health Insurance Portability and Accountability Act of 1996 as amended by HITECH, and all implementing regulations, including the Privacy Rule (45 CFR Part 164, Subpart E), Security Rule (45 CFR Part 164, Subparts A and C), and Breach Notification Rule (45 CFR Part 164, Subpart D).
"Services"Electronic health information exchange facilitation, patient-sovereign data vault services, FHIR API access, and related health IT infrastructure services provided by Business Associate to Covered Entity or to patients at Covered Entity direction.
"Breach"The acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI, as defined at 45 CFR § 164.402.
"Subcontractor"Any person or entity to whom Business Associate delegates a function, activity, or service involving the creation, receipt, maintenance, or transmission of PHI.
Section 2 — Permitted Uses and Disclosures by Business Associate

Business Associate may Use or Disclose PHI only as follows, and in no other manner:

  • (a) Services Provision: To provide the Services described in the applicable service agreement, as necessary to perform functions, activities, or services for or on behalf of Covered Entity involving the use or disclosure of PHI. 45 CFR § 164.504(e)(2)(i)
  • (b) Management and Administration: For Business Associate's proper management and administration or to carry out legal responsibilities, provided that disclosures are required by law or Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially and used only for the purpose for which it was disclosed. 45 CFR § 164.504(e)(4)
  • (c) Reporting Violations: To report violations of law to appropriate federal and state authorities, consistent with 45 CFR § 164.502(j)(1).
  • (d) Data Aggregation: To provide data aggregation services relating to the healthcare operations of Covered Entity, where such services are part of the agreed Services. 45 CFR § 164.504(e)(2)(i)(B)
  • (e) As Required by Law: As required by law (as defined in 45 CFR § 164.103), including to Secretary of HHS upon request.
Absolute Prohibitions

Business Associate shall NEVER:

  • Use or disclose PHI in any manner that would violate the Privacy Rule if done by Covered Entity, except as otherwise permitted by this Agreement
  • Sell PHI without a valid written authorization from the individual. 45 CFR § 164.508(a)(4)
  • Use PHI for marketing communications without a valid authorization. 45 CFR § 164.508(a)(3)
  • Use PHI to create, maintain, or sell a database of PHI for competing services
Section 3 — Required Uses and Disclosures

Business Associate shall make PHI available:

  • (a) To HHS Secretary: When required for determining compliance with the HIPAA Rules. 45 CFR § 164.504(e)(2)(ii)(G)
  • (b) To Individuals: To provide access to individuals (or their personal representatives) to the extent required under 45 CFR § 164.524, including providing copies of electronic PHI in electronic format when requested. 45 CFR § 164.524
  • (c) To Covered Entity: To make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations under the HIPAA Rules.
Section 4 — Safeguards Obligations

Business Associate shall implement and maintain appropriate safeguards to prevent unauthorized use or disclosure of PHI and to protect ePHI, as required by the HIPAA Security Rule:

4.1 — Administrative Safeguards 45 CFR § 164.308
  • Designate a Security Official responsible for HIPAA security policies
  • Maintain a risk analysis and risk management program with documented policies
  • Implement workforce training on PHI handling and security procedures
  • Establish and enforce sanctions for workforce members who violate policies
  • Conduct periodic technical and non-technical evaluations of security implementation
  • Execute written subcontractor BAAs before any PHI disclosure to subcontractors § 164.308(b)(2)
4.2 — Physical Safeguards 45 CFR § 164.310
  • Implement physical access controls to facilities containing ePHI systems
  • Maintain workstation use and security policies for devices that access ePHI
  • Implement controls for the proper disposal and reuse of hardware and media containing ePHI
4.3 — Technical Safeguards 45 CFR § 164.312
  • Implement access controls, including unique user identification and automatic logoff
  • Implement encryption and decryption mechanisms for ePHI at rest and in transit
  • Maintain audit controls that record and examine activity in systems containing ePHI
  • Implement integrity controls to ensure ePHI is not improperly altered or destroyed
  • Encrypt ePHI in transit over open networks (TLS 1.2+ minimum)
  • Maintain all ePHI on MyRx-Chain blockchain ledger with immutable audit trail
4.4 — Minimum Necessary Standard 45 CFR § 164.514(d)

Business Associate shall make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of use, disclosure, or request.

Section 5 — Breach Notification

Business Associate shall comply with the Breach Notification requirements of 45 CFR §§ 164.400–164.414, including:

  • (a) Notification Timeline: Business Associate shall notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and in no case later than 60 calendar days from the date of discovery of a Breach. 45 CFR § 164.410
  • (b) Notification Content: Notice to Covered Entity shall include, to the extent possible: (i) the identification of each individual whose Unsecured PHI was or is reasonably believed to have been accessed, acquired, used, or disclosed; (ii) a brief description of what happened; (iii) the date of the Breach and the date of discovery; (iv) a description of the types of Unsecured PHI involved; (v) steps individuals should take to protect themselves; (vi) a brief description of what Business Associate is doing to investigate, mitigate, and protect against further breaches; and (vii) contact information for Business Associate.
  • (c) Mitigation: Business Associate shall take immediate steps to mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this Agreement.
  • (d) Security Incidents: Business Associate shall report to Covered Entity any Security Incident (as defined in 45 CFR § 164.304) of which it becomes aware, including attempted Breaches. 45 CFR § 164.314(a)(2)(i)(C)
Contact for Breach Reports: privacy@myrxwallet.io · Subject line: "HIPAA Breach Notification — [Date]"
Incident response team available 24/7 for confirmed Breaches affecting 500+ individuals.
Section 6 — Subcontractor Obligations

In accordance with 45 CFR §§ 164.308(b)(2) and 164.314(a), Business Associate shall:

  • (a) Subcontractor BAAs: Ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees to the same restrictions, conditions, and requirements that apply to Business Associate under this Agreement by executing a written subcontractor Business Associate Agreement before any PHI disclosure. 45 CFR § 164.308(b)(2)
  • (b) Subcontractor Compliance: Business Associate shall remain responsible for ensuring Subcontractors comply with the applicable requirements of the HIPAA Rules.
  • (c) Subcontractor Breaches: Business Associate shall ensure that any Subcontractor reports any Breach of Unsecured PHI to Business Associate within the time frames required by 45 CFR § 164.410, to enable Business Associate to fulfill its notification obligations.

Current subprocessors handling ePHI include cloud infrastructure providers operating under executed subcontractor BAAs. A current list is available upon written request to privacy@myrxwallet.io.

Section 7 — Obligations of Covered Entity

Covered Entity shall:

  • (a) Lawful Requests: Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity.
  • (b) Notice of Changes: Notify Business Associate in writing of: (i) any change in, or revocation of, an individual's permission to use or disclose PHI, to the extent that such change may affect Business Associate's use or disclosure of PHI; (ii) any restriction on uses and disclosures agreed to by Covered Entity under 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI; and (iii) the form of notice Covered Entity provides to patients under 45 CFR § 164.520, if such notice affects Business Associate's permitted uses and disclosures.
  • (c) Authorizations: Obtain any consent, authorization, or other permission required by the Privacy Rule before requesting Business Associate to access, use, or disclose PHI on behalf of an individual.
  • (d) Accuracy of PHI: Ensure the accuracy of PHI provided to Business Associate to the extent within Covered Entity's control.
Section 8 — Term and Termination
8.1 — Term

This Agreement is effective upon first use of the MyRxWallet platform by Covered Entity and shall remain in effect until terminated by either party as provided herein, or until the underlying service agreement expires or terminates.

8.2 — Termination for Cause 45 CFR § 164.504(e)(2)(iii)

Either party may terminate this Agreement if the other party has materially breached any term of this Agreement and: (i) the non-breaching party gives written notice specifying the breach; and (ii) the breaching party fails to cure the breach within 30 calendar days of receipt of such notice. Covered Entity may, if cure is not possible, immediately terminate this Agreement and the underlying service agreement upon written notice to Business Associate.

8.3 — Automatic Termination

This Agreement automatically terminates upon termination or expiration of the underlying service agreement between the parties, unless otherwise agreed in writing.

8.4 — Effect of Termination

Upon termination for any reason, Business Associate shall, to the extent feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity that Business Associate still maintains. Business Associate shall retain no copies of PHI. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures to those purposes that make the return or destruction of the PHI infeasible.

Section 9 — Return or Destruction of PHI

Upon termination or expiration of this Agreement, in accordance with 45 CFR § 164.504(e)(2)(ii)(J):

  • (a) Return or Destroy: Business Associate shall, at the election of Covered Entity: (i) return to Covered Entity all PHI in the possession of Business Associate and all Subcontractors; or (ii) destroy all PHI and certify in writing to Covered Entity that such destruction has been completed.
  • (b) Infeasibility: To the extent that it is not feasible to return or destroy PHI, Business Associate shall notify Covered Entity and limit further use or disclosure of such PHI to those purposes that make return or destruction infeasible, for so long as Business Associate maintains such PHI.
  • (c) MyRx-Chain Data: PHI recorded on the MyRx-Chain blockchain ledger constitutes an immutable audit record. Patient-encrypted vault data remains accessible only to the patient via their personal cryptographic key; Business Associate retains no decryption capability. Upon termination, Business Associate shall revoke all service-level access tokens and API credentials tied to the Covered Entity relationship.
  • (d) Certification: Business Associate shall provide written certification of destruction or return within 30 days of termination upon Covered Entity request.
Section 10 — Miscellaneous Provisions
  • Survival: The obligations of Business Associate under Section 9 (Return or Destruction) and those provisions that, by their nature, should survive termination shall survive termination of this Agreement.
  • Amendment: The parties agree to take such action as is necessary to amend this Agreement from time to time as necessary for compliance with the requirements of HIPAA Rules. MyRxWallet reserves the right to amend this Agreement upon 30 days written notice to address regulatory changes.
  • Interpretation: This Agreement shall be interpreted as broadly as necessary to give effect to the requirements of the HIPAA Rules. Any ambiguity shall be resolved in favor of a meaning that permits compliance with HIPAA.
  • No Third-Party Beneficiaries: This Agreement is for the sole benefit of the parties and their respective permitted successors and assigns. Nothing herein shall be construed to create any legal or equitable right or claim for any other person or entity.
  • Relationship of Parties: Business Associate is an independent contractor and is not an agent, employee, or representative of Covered Entity.
  • Governing Law: This Agreement shall be governed by and construed in accordance with the laws of the United States, specifically the HIPAA/HITECH Act (42 U.S.C. § 1320d et seq.) and implementing regulations at 45 CFR Parts 160 and 164.
  • Entire Agreement: This BAA, together with the underlying service agreement and MyRxWallet's Terms of Service, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, and representations relating to the protection of PHI.
Effective as of: May 1, 2026  ·  Jurisdiction: Federal (HIPAA/HITECH)  ·  Questions: privacy@myrxwallet.io
By using the MyRxWallet platform to access, transmit, or receive PHI, Covered Entity acknowledges acceptance of this Business Associate Agreement in its entirety.

Print / Save as PDF   Patient Consent Form