This Business Associate Agreement (this “BAA”) supplements the terms and conditions of the Mabel Subscription Agreement (together with its Order Forms) or other written services agreement (the “Underlying Agreement”) entered into between you (“Covered Entity”) and Calyx Health, Inc. d/b/a Mabel (“Business Associate”). Covered Entity and Business Associate are sometimes referred to collectively as the “Parties” and individually as a “Party.” The version of this BAA in effect on the effective date of the Underlying Agreement (or, where the Underlying Agreement is the Mabel Subscription Agreement, the applicable Order Form) governs the Parties, and may be amended thereafter only as required by changes in applicable law or by written agreement of the Parties.

1. Definitions

Terms used in this BAA — including “Breach,” “Electronic Protected Health Information,” “HIPAA,” “HITECH Standards,” “Individually Identifiable Health Information,” “Privacy Rule,” “Protected Health Information” (“PHI”), “Security Rule,” “Security Incident,” and “Unsecured Protected Health Information” — carry the meanings given to them under HIPAA, the Privacy Rule, the Security Rule, and the HITECH Standards, as those terms may be updated from time to time. “Security Incident” excludes routine, unsuccessful attempts to penetrate or interfere with Business Associate’s systems, such as pings, port scans, and failed log-in attempts.

2. Status of Parties

The Parties acknowledge and agree that Covered Entity is a “Covered Entity” and that Business Associate is a “Business Associate” of Covered Entity, as those terms are defined in HIPAA and the Privacy and Security Rule. If Covered Entity is itself a business associate of one or more covered entities, then references to “Covered Entity” apply to it in that capacity, Business Associate acts as its subcontractor under 45 C.F.R. § 164.502(e), and this BAA is the written agreement required by 45 C.F.R. § 164.504(e)(5).

3. Permitted Uses and Disclosures

Performance of Services. Business Associate may access, use, and/or disclose Covered Entity’s PHI and/or ePHI in connection with the performance of its obligations under the Underlying Agreement, consistent with HIPAA, the Privacy Rule, and the HITECH Standards.

Minimum Necessary. Business Associate shall limit its use, access, or disclosure of PHI to the minimum necessary to accomplish the intended purpose, in accordance with HIPAA and applicable guidance.

Documentation of Disclosures. Business Associate shall document any permitted disclosures of PHI, including the date, recipient, description of the PHI disclosed, and purpose of the disclosure.

Modification of PHI. Business Associate shall not modify existing data other than to correct errors or derive new data, and shall record and retain any such modifications for seven (7) years.

Other Permitted Uses. Business Associate may use PHI for the proper management and administration of its business, to provide data aggregation or de-identification services relating to Covered Entity’s health care operations, or to carry out its legal responsibilities, subject to the limitations below.

De-identification. Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(b). De-identified data is no longer PHI, and Business Associate may use and disclose it as permitted by the Underlying Agreement.

Nondisclosure. Business Associate is not authorized to use or further disclose PHI other than as permitted or required under this BAA, or as required by law.

Disclosures Required by Law; Legal Process. Business Associate shall notify Covered Entity in advance of any disclosure required by law where possible, and within five (5) business days of receiving any legal process or governmental request that may require disclosure of PHI, so Covered Entity may object or seek relief.

State Law; Subcontractors. Business Associate shall comply with applicable state law requirements that are more stringent than HIPAA, and shall ensure that any subcontractor that creates, receives, transmits, or stores PHI agrees in writing to the same restrictions that apply to Business Associate.

Notification of Investigation or Lawsuit. Business Associate shall notify Covered Entity immediately upon receipt of notice of an investigation or lawsuit related to its use or disclosure of PHI.

4. Safeguards, Reporting, Mitigation, and Enforcement

Safeguards. Business Associate shall use appropriate administrative, physical, and technical safeguards — including policies, procedures, and employee training — to protect the confidentiality, integrity, and availability of PHI and ePHI in accordance with the Security Rule and HITECH Standards.

Notification. Business Associate shall notify Covered Entity in writing without unreasonable delay, and in no event more than thirty (30) calendar days, after becoming aware of any Breach or Security Incident involving Covered Entity’s PHI, and shall cooperate in good faith in any related investigation. Notification of Security Incidents that do not constitute a Breach may be provided in periodic aggregate reports.

Corrective Action. Business Associate shall take prompt corrective action to remedy any Breach or Security Incident, mitigate any harmful effects, and provide Covered Entity with a written report — including the nature, scope, and timeline of the incident and the corrective action taken — no later than thirty (30) calendar days following the initial report.

Cooperation. Business Associate shall cooperate with Covered Entity to investigate, remediate, mitigate, and report any Breach, and shall provide such assistance as Covered Entity may reasonably request to meet its own investigation, reporting, and notification obligations.

Inspection. Upon at least thirty (30) days’ prior written notice, no more than once per calendar year (except following a confirmed Breach), and during normal business hours in a manner that does not unreasonably interfere with Business Associate’s operations, Covered Entity may inspect those of Business Associate’s facilities, systems, books, and records that relate solely to Business Associate’s use, disclosure, or safeguarding of Covered Entity’s PHI under this BAA. Persons conducting the inspection shall be subject to reasonable confidentiality obligations, and Business Associate may redact or withhold information that is proprietary, relates to other customers, or is subject to legal privilege. In lieu of an on-site inspection, Business Associate may provide a recent SOC 2 Type II report, HITRUST certification, or comparable independent third-party audit report.

HHS Access. Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining compliance with HIPAA, the Privacy Rule, the Security Rule, and the HITECH Standards, and shall promptly notify Covered Entity of any such request.

Costs. To the extent a Breach is caused by Business Associate’s breach of this BAA or its negligent or willful acts or omissions, Business Associate shall reimburse Covered Entity for reasonable, documented out-of-pocket costs directly incurred in providing breach notifications required by 45 C.F.R. §§ 164.404–164.408. Each Party is responsible for fines or penalties imposed on it by a regulatory authority for its own acts or omissions. The Parties’ obligations under this Section are subject to the limitations of liability set forth in the Underlying Agreement.

Sanctions. Business Associate shall apply appropriate sanctions against any employee, subcontractor, or agent who uses or discloses PHI in violation of this BAA or applicable law.

5. Access, Amendment, and Accounting of PHI

Business Associate shall make available to Covered Entity such information as is necessary for Covered Entity to fulfill its obligations to provide individuals with access to, amendment of, and an accounting of disclosures of PHI in accordance with HIPAA, the Privacy Rule, and the HITECH Standards. If an individual requests access, amendment, or an accounting directly from Business Associate, Business Associate shall forward the request to Covered Entity within five (5) days.

6. Material Breach, Enforcement, and Termination

Term; Termination. This BAA remains effective until termination of the Underlying Agreement or as otherwise provided herein. If Covered Entity determines that Business Associate has materially breached this BAA, Covered Entity may require Business Associate to cure the breach within thirty (30) days, and may terminate this BAA and the Underlying Agreement if Business Associate does not do so. If neither cure nor termination is feasible, Covered Entity may report the breach to the Secretary of HHS. Covered Entity may also terminate this BAA immediately if Business Associate is convicted of, or enters into a settlement resolving, a criminal violation of HIPAA, or if a finding of a HIPAA violation is made against Business Associate in any administrative or civil proceeding.

Effects of Termination. Upon termination, Business Associate shall return or destroy all PHI in its possession, provided that return or destruction shall not apply to PHI that Business Associate is required to retain under applicable law, regulation, or its auditable-record obligations under the Underlying Agreement (including CMS recordkeeping requirements). Business Associate shall continue to extend the protections of this BAA to any retained PHI and limit further use and disclosure to the purposes that make return or destruction infeasible.

7. Miscellaneous Terms

This BAA may be amended as required to ensure compliance with changes in applicable privacy and security laws, and shall be construed in accordance with the laws of the State of California. Notices under this BAA shall be given in the manner provided in the Underlying Agreement. In the event of a conflict between this BAA and any other agreement between the Parties, this BAA controls with respect to the subject matter herein. Nothing in this BAA confers any rights, obligations, or remedies on any party other than the Parties and their respective successors and assigns.