This Agreement governs the handling of Protected Health Information between your organization and CriteriaIQ, LLC in connection with your use of CriteriaIQ RCM.
This Business Associate Agreement ("Agreement") is entered into between you, the subscribing organization ("Covered Entity"), and CriteriaIQ, LLC ("Business Associate"), effective as of the date on which Covered Entity creates an account on the CriteriaIQ RCM platform ("Effective Date"). Together, the parties are referred to as "the Parties."
WHEREAS, Covered Entity wishes to use the CriteriaIQ RCM platform, and in doing so may create, receive, maintain, or transmit Protected Health Information; and
WHEREAS, the Parties intend to protect the privacy and security of PHI in compliance with HIPAA, HITECH, and all applicable regulations;
NOW THEREFORE, the Parties agree as follows:
The following terms have the same meaning as in the HIPAA Rules (45 CFR Parts 160 and 164):
CriteriaIQ will use or disclose PHI only as necessary to provide the CriteriaIQ RCM services, as otherwise permitted by this Agreement, or as required by law. CriteriaIQ will not use or disclose PHI in any manner that would violate the HIPAA Privacy Rule if done by Covered Entity.
CriteriaIQ will implement and maintain appropriate administrative, physical, and technical safeguards to prevent unauthorized use or disclosure of PHI, and will comply with all applicable requirements of the HIPAA Security Rule (45 CFR Part 164, Subparts A and C).
Important Disclosure: CriteriaIQ's AI-powered analysis functions process PHI strictly in-memory during active analysis sessions. No patient data is persisted to, stored in, or used to train any AI model, including the Anthropic Claude API. PHI is transmitted to the analysis endpoint, processed, and the response is returned — no PHI is retained by any AI subprocessor beyond the duration of the API call.
CriteriaIQ will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay, and in no event more than 30 days following Discovery, per 45 CFR § 164.410. Notification will include, to the extent available:
Note: Unsuccessful attempts at unauthorized access — which occur routinely in any internet-connected system — will not require individual notification unless they result in a confirmed Breach.
CriteriaIQ will ensure that any Subcontractors that create, receive, maintain, or transmit PHI on its behalf agree to the same restrictions and requirements that apply to CriteriaIQ under this Agreement, including HIPAA Security Rule compliance.
Within five (5) business days of a written request from Covered Entity, CriteriaIQ will make PHI available as necessary to fulfill Covered Entity's obligations under 45 CFR §§ 164.524 and 164.526. If an individual requests access or amendment directly from CriteriaIQ, CriteriaIQ will notify Covered Entity within five (5) business days.
CriteriaIQ will maintain a record of PHI disclosures and make it available to Covered Entity within five (5) business days of request, per 45 CFR § 164.528.
CriteriaIQ will make its internal practices, books, and records relating to PHI available to the Secretary of HHS for purposes of determining Covered Entity's compliance with HIPAA, per 45 CFR § 160.310.
CriteriaIQ will make reasonable efforts to use, disclose, and request only the minimum amount of PHI necessary to accomplish the intended purpose of each use, disclosure, or request.
CriteriaIQ acknowledges that Covered Entity is the sole owner of all PHI created, received, maintained, or transmitted by CriteriaIQ on behalf of Covered Entity. CriteriaIQ acquires no rights in such PHI.
CriteriaIQ will mitigate, to the extent practicable, any harmful effect resulting from a use or disclosure of PHI in violation of this Agreement.
This Agreement is effective as of the date Covered Entity creates a CriteriaIQ RCM account and remains in effect for the duration of Covered Entity's active subscription.
Either Party may terminate this Agreement upon written notice if the other Party materially breaches any provision and fails to cure such breach within thirty (30) days. Covered Entity may terminate immediately if CriteriaIQ breaches a material term and cure is not possible.
Upon termination, CriteriaIQ will within thirty (30) days:
Standard policy: CriteriaIQ provides for secure deletion of all tenant PHI within 30 days of subscription termination. Covered Entity may request expedited deletion by contacting compliance@criteriaiq.com.
Each Party agrees to indemnify, defend, and hold harmless the other Party and its officers, directors, employees, and agents from third-party claims, penalties, fines, costs, liabilities, or damages — including reasonable attorneys' fees — arising from that Party's breach of this Agreement or violation of applicable HIPAA rules.
CriteriaIQ's total indemnification liability shall not exceed the total fees paid by Covered Entity during the six (6) month period immediately preceding the date the claim accrued.
In no event shall either Party be liable to the other for lost profits, lost revenue, or any indirect, incidental, consequential, punitive, or special damages, to the maximum extent permitted by applicable law.
By creating a CriteriaIQ RCM account and checking the BAA acceptance box during account creation or login, Covered Entity acknowledges that it has read, understands, and agrees to be bound by this Agreement. The individual accepting represents and warrants that they have legal authority to bind Covered Entity.
This electronic acceptance constitutes a valid and binding signature under the Electronic Signatures in Global and National Commerce Act (E-SIGN Act). Acceptance timestamp and IP address are recorded in CriteriaIQ's audit log for compliance purposes.
Acceptance is recorded electronically at the time of account creation or login, including timestamp and IP address for HIPAA audit purposes.
CriteriaIQ, LLC
Behavioral Health Revenue Cycle Platform
support@criteriaiq.com
compliance@criteriaiq.com
Your Organization
As identified in your CriteriaIQ RCM account
Accepted electronically upon account creation
Timestamp recorded in audit log