Business Associate Agreement
Last updated: August 25, 2026
This is the Business Associate Agreement (BAA) between Ablespace Inc., which owns and operates the Dashtrial service, and the organizations that use Dashtrial to create, receive, maintain, or transmit Protected Health Information (PHI).
Parties and effective date
This Business Associate Agreement (this “Agreement” or “BAA”) is entered into by and between Ablespace Inc., a corporation that owns and operates the Dashtrial service available at Dashtrial.com and hosted at app.dashtrial.com (“Business Associate” or “Dashtrial”), and the individual or entity that registers for, accesses, or uses the Dashtrial service and accepts this Agreement (“Covered Entity” or “Customer”). Business Associate and Covered Entity may each be referred to as a “Party” and together as the “Parties.”
This Agreement is effective as of the date Covered Entity electronically accepts it during account registration or otherwise indicates assent as described in Section 12 (the “Effective Date”). This Agreement supplements and is incorporated into the Dashtrial Terms of Service or other underlying services agreement between the Parties (the “Services Agreement”).
Recitals
WHEREAS, Covered Entity is a “covered entity” or a “business associate” acting on behalf of a covered entity, as those terms are defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH”) and their implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, the “HIPAA Rules”);
WHEREAS, in connection with Covered Entity's use of the Dashtrial service, Business Associate may create, receive, maintain, or transmit Protected Health Information (“PHI”) on behalf of Covered Entity; and
WHEREAS, the HIPAA Rules require Covered Entity to obtain satisfactory assurances, in the form of a written agreement, that Business Associate will appropriately safeguard PHI;
NOW, THEREFORE, in consideration of the mutual promises below and the exchange of information pursuant to this Agreement, the Parties agree as follows:
1. Definitions
1.1 Catch-all. Capitalized terms used but not otherwise defined in this Agreement have the meanings given to them in the HIPAA Rules, including without limitation: Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information (“ePHI”), Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
1.2 Protected Health Information / PHI. “PHI” means Protected Health Information as defined in 45 C.F.R. § 160.103, limited to the information created, received, maintained, or transmitted by Business Associate from or on behalf of Covered Entity in connection with the Dashtrial service. PHI includes ePHI.
1.3 Secretary. “Secretary” means the Secretary of the U.S. Department of Health and Human Services (“HHS”) or the Secretary's designee.
2. Permitted Uses and Disclosures by Business Associate
2.1 Services. Business Associate may Use and Disclose PHI only as necessary to perform the services described in the Services Agreement, as permitted by this Agreement, or as Required by Law. Business Associate shall not Use or Disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted under Sections 2.2 and 2.3 below.
2.2 Management and Administration. Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities. Business Associate may Disclose PHI for such purposes only if the Disclosure is Required by Law, or Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially and Used or further Disclosed only as Required by Law or for the purposes for which it was disclosed, and the recipient agrees to notify Business Associate of any instances of which it becomes aware in which the confidentiality of the PHI has been breached.
2.3 Data Aggregation and De-Identification. Business Associate may Use PHI to provide Data Aggregation services relating to the Health Care Operations of Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c); information de-identified in accordance with the HIPAA Rules is no longer PHI and is not subject to this Agreement.
2.4 Minimum Necessary. Business Associate shall make reasonable efforts to Use, Disclose, and request only the Minimum Necessary PHI to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b) and any applicable guidance issued by the Secretary.
2.5 Prohibited Uses. Business Associate shall not Use or Disclose PHI for marketing purposes, and shall not directly or indirectly receive remuneration in exchange for PHI, except in each case as expressly permitted by the HIPAA Rules and authorized in writing by Covered Entity.
3. Obligations of Business Associate
3.1 Limitations on Use and Disclosure. Business Associate shall not Use or Disclose PHI other than as permitted or required by this Agreement or as Required by Law.
3.2 Safeguards. Business Associate shall use appropriate administrative, physical, and technical safeguards to prevent Use or Disclosure of PHI other than as provided for by this Agreement, and shall comply with Subpart C of 45 C.F.R. Part 164 (the “Security Rule”) with respect to ePHI, including implementing written policies and procedures and maintaining documentation as required by the Security Rule.
3.3 Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effect known to Business Associate of a Use or Disclosure of PHI by Business Associate or its Subcontractors in violation of this Agreement.
3.4 Reporting. Business Associate shall report to Covered Entity: (a) any Use or Disclosure of PHI not provided for by this Agreement of which it becomes aware; (b) any Security Incident of which it becomes aware, provided that this Section constitutes notice, and no further notice shall be required, of the ongoing existence and occurrence of Unsuccessful Security Incidents (defined as pings and other broadcast attacks on firewalls, port scans, unsuccessful log-on attempts, denials of service, and similar incidents that do not result in unauthorized access, acquisition, Use, or Disclosure of ePHI); and (c) any Breach of Unsecured PHI as required by Section 4.
3.5 Subcontractors. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement, including compliance with the Security Rule with respect to ePHI.
3.6 Access by Individuals. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall, within fifteen (15) business days of a written request by Covered Entity, make such PHI available to Covered Entity (or, as directed by Covered Entity, to an Individual) as necessary for Covered Entity to satisfy its obligations under 45 C.F.R. § 164.524, including, where applicable, providing an electronic copy of ePHI. If an Individual requests access directly from Business Associate, Business Associate shall promptly forward the request to Covered Entity.
3.7 Amendment. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall, within fifteen (15) business days of a written request by Covered Entity, make such PHI available for amendment and incorporate any amendments as necessary for Covered Entity to satisfy its obligations under 45 C.F.R. § 164.526.
3.8 Accounting of Disclosures. Business Associate shall document Disclosures of PHI and information related to such Disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of Disclosures under 45 C.F.R. § 164.528, and shall provide such documentation to Covered Entity within fifteen (15) business days of a written request. If an Individual requests an accounting directly from Business Associate, Business Associate shall promptly forward the request to Covered Entity.
3.9 Obligations Performed on Behalf of Covered Entity. To the extent Business Associate is to carry out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligations.
3.10 Availability of Records. Business Associate shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Secretary for purposes of determining Covered Entity's compliance with the HIPAA Rules.
4. Breach Notification
4.1 Notice to Covered Entity. Following the discovery of a Breach of Unsecured PHI, Business Associate shall notify Covered Entity without unreasonable delay and in no event later than ten (10) business days after discovery of the Breach, in accordance with 45 C.F.R. § 164.410. A Breach is treated as discovered as of the first day on which the Breach is known, or by exercising reasonable diligence would have been known, to Business Associate or any employee, officer, or agent of Business Associate (other than the person committing the Breach).
4.2 Content of Notice. To the extent known at the time of the notice, and supplemented promptly thereafter as information becomes available, the notice shall include: (a) the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; (b) a description of the nature of the Breach, including the date of the Breach and the date of its discovery; (c) the types of Unsecured PHI involved; (d) the steps Individuals should take to protect themselves from potential harm; and (e) a description of what Business Associate is doing to investigate, mitigate, and prevent recurrence.
4.3 Responsibility for Notifications. Unless otherwise agreed in writing, Covered Entity shall be responsible for providing any notifications to Individuals, the Secretary, and the media required under 45 C.F.R. §§ 164.404–164.408. Business Associate shall reasonably cooperate with Covered Entity in connection with such notifications.
5. Obligations of Covered Entity
5.1 Notice of Privacy Practices. Covered Entity shall notify Business Associate of any limitation(s) in Covered Entity's Notice of Privacy Practices under 45 C.F.R. § 164.520, to the extent such limitation may affect Business Associate's Use or Disclosure of PHI.
5.2 Changes in Permissions. Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an Individual to Use or Disclose PHI, to the extent such change may affect Business Associate's Use or Disclosure of PHI.
5.3 Restrictions. Covered Entity shall notify Business Associate of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent such restriction may affect Business Associate's Use or Disclosure of PHI.
5.4 Permissible Requests. Covered Entity shall not request that Business Associate Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except as permitted under Sections 2.2 and 2.3.
5.5 Appropriate Use of the Service. Covered Entity is responsible for using the Dashtrial service in a manner consistent with the HIPAA Rules, including configuring available security features (such as access controls and user permissions), managing its users' credentials, and transmitting PHI only through the features of the service designated by Business Associate as appropriate for PHI. Covered Entity shall not include PHI in fields, support tickets, or communications channels not intended for PHI, unless expressly permitted in Business Associate's documentation.
6. Term and Termination
6.1 Term. This Agreement is effective as of the Effective Date and shall remain in effect until the later of (a) termination or expiration of the Services Agreement, or (b) the date Business Associate ceases to create, receive, maintain, or transmit PHI on behalf of Covered Entity, unless earlier terminated in accordance with this Section 6.
6.2 Termination for Cause. Upon a Party's knowledge of a material breach of this Agreement by the other Party, the non-breaching Party shall provide written notice of the breach and an opportunity to cure within thirty (30) days. If the breaching Party does not cure the breach within such period, the non-breaching Party may terminate this Agreement and the Services Agreement. If cure is not possible, the non-breaching Party may terminate this Agreement and the Services Agreement immediately upon written notice.
6.3 Return or Destruction of PHI. Upon termination of this Agreement for any reason, Business Associate shall, at Covered Entity's election communicated within thirty (30) days of termination, return or destroy all PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, that Business Associate or its Subcontractors still maintain, and shall retain no copies. If Covered Entity makes no election within such period, Business Associate may destroy the PHI in accordance with this Section.
6.4 Retention Where Return or Destruction Is Infeasible. If return or destruction of PHI is infeasible (including PHI stored in routine backup media, or PHI that Business Associate is required by law to retain), Business Associate shall notify Covered Entity of the conditions that make return or destruction infeasible, shall extend the protections of this Agreement to such PHI, shall limit further Uses and Disclosures to those purposes that make return or destruction infeasible, and shall destroy such PHI when it becomes feasible to do so.
6.5 Survival. The obligations of Business Associate under Sections 6.3 and 6.4 shall survive termination of this Agreement.
7. HITECH Applicability
The Parties acknowledge that, pursuant to HITECH and its implementing regulations, certain provisions of the HIPAA Rules apply directly to business associates, including 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316, and that Business Associate is directly subject to civil and criminal penalties for violations of such provisions. Business Associate shall comply with all requirements of HITECH and the HIPAA Rules applicable to business associates, as of their respective compliance dates.
8. Liability
8.1 Relationship to Services Agreement. Except as expressly stated in this Agreement, any limitations of liability, disclaimers, and remedies set forth in the Services Agreement apply to claims arising under this Agreement.
8.2 No Third-Party Beneficiaries. Nothing in this Agreement shall confer upon any person other than the Parties and their respective successors and permitted assigns any rights, remedies, obligations, or liabilities whatsoever.
9. Regulatory References and Amendment
9.1 Regulatory References. A reference in this Agreement to a section of the HIPAA Rules means the section as in effect or as amended, and for which compliance is required.
9.2 Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as required for compliance with the HIPAA Rules and other applicable law. Business Associate may amend this Agreement upon at least thirty (30) days' notice to Covered Entity (which may be provided by email or by posting within the Dashtrial service) where such amendment is reasonably necessary to comply with changes in applicable law; Covered Entity's continued use of the service after the effective date of such amendment constitutes acceptance. Any other amendment must be in a writing (including electronic form) agreed to by both Parties.
9.3 Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules. In the event of a conflict between this Agreement and the Services Agreement with respect to PHI, this Agreement controls.
10. Miscellaneous
10.1 Independent Contractors. The Parties are independent contractors. Nothing in this Agreement creates an agency, partnership, or joint venture between the Parties, and neither Party is an agent of the other for any purpose.
10.2 Assignment. Neither Party may assign this Agreement without the prior written consent of the other Party, except that Business Associate may assign this Agreement in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided the assignee assumes all obligations under this Agreement.
10.3 Notices. Notices to Business Associate shall be sent to Ablespace Inc. at the notice address specified in the Services Agreement or at legal@dashtrial.com. Notices to Covered Entity may be sent to the email address associated with Covered Entity's Dashtrial account and shall be deemed given when sent.
10.4 Severability. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid provision shall be reformed to the minimum extent necessary to make it enforceable.
10.5 Waiver. No waiver of any provision of this Agreement shall be effective unless in writing, and no waiver shall constitute a waiver of any other provision or of the same provision on another occasion.
10.6 Governing Law. This Agreement shall be governed by the governing law specified in the Services Agreement, without regard to conflict-of-laws principles, except to the extent preempted by federal law.
10.7 Entire Agreement. This Agreement, together with the Services Agreement, constitutes the entire agreement between the Parties with respect to its subject matter and supersedes all prior or contemporaneous understandings regarding such subject matter.
10.8 Counterparts; Electronic Execution. This Agreement may be executed electronically, including by clickwrap acceptance as described in Section 12, and in counterparts, each of which is deemed an original and all of which together constitute one instrument.
11. Customer Eligibility and Scope
11.1 Applicability. This Agreement applies only if and to the extent Covered Entity is a covered entity or business associate under the HIPAA Rules and PHI is created, received, maintained, or transmitted through the Dashtrial service on Covered Entity's behalf. If Covered Entity is not subject to the HIPAA Rules, or does not process PHI through the service, this Agreement imposes no obligations on either Party.
11.2 Authority. The person accepting this Agreement represents and warrants that they are authorized to bind Covered Entity to this Agreement.
11.3 Downstream Arrangements. If Customer is itself a business associate of another covered entity, Customer represents that its use of the Dashtrial service and this Agreement are consistent with Customer's obligations to such covered entity, and this Agreement constitutes the subcontractor agreement required under 45 C.F.R. § 164.502(e)(1)(ii).
12. Electronic Acceptance
By clicking “I Agree” (or a similar button or checkbox) during registration at app.dashtrial.com, by executing an order form or signup flow that references this Agreement, or by using the Dashtrial service to create, receive, maintain, or transmit PHI, Covered Entity agrees to be bound by this Agreement. The Parties agree that such electronic acceptance constitutes a valid and binding signature under the U.S. Electronic Signatures in Global and National Commerce Act (E-SIGN), the Uniform Electronic Transactions Act (UETA), and other applicable law, and satisfies the written-agreement requirements of 45 C.F.R. §§ 164.504(e) and 164.314(a). Business Associate shall maintain a record of the date and time of acceptance and the account through which acceptance occurred.
Execution
This Agreement is executed electronically and does not require handwritten signatures.
Covered Entity executes this Agreement by clicking “I Agree” (or a similar button or checkbox) presented during registration at app.dashtrial.com, or by otherwise indicating assent as described in Section 12. Business Associate maintains an electronic record of each acceptance, including the customer organization, the accepting user and associated email address, the date and time of acceptance, and the version of this Agreement accepted. Such record constitutes the executed Agreement between the Parties.
Business Associate (Ablespace Inc.) executes this Agreement by publishing it within the registration flow and making the Dashtrial service available to Covered Entity following Covered Entity's acceptance, which together constitute Business Associate's assent to and execution of this Agreement as of the Effective Date.
A countersigned copy of this Agreement is available upon written request to Business Associate for Covered Entities that require one for their compliance records.