MYOFUNCTIONALTHERAPIST.COM
BUSINESS ASSOCIATE AGREEMENT
Effective Date: The date Provider electronically accepts this Agreement.
This Business Associate Agreement (“Agreement”) establishes the terms under which Myo Web Design, Inc., a California corporation, doing business as MyofunctionalTherapist.com (“Business Associate”), provides certain services to participating healthcare providers that involve the creation, receipt, maintenance, or transmission of Protected Health Information.
The healthcare provider or healthcare practice accepting this Agreement is referred to as “Provider.”
Business Associate and Provider may each be referred to as a “Party” and collectively as the “Parties.”
1. PURPOSE AND RELATIONSHIP
MyofunctionalTherapist.com provides an online professional directory and related technology services for healthcare providers, including provider profiles, appointment scheduling, appointment communications, calendar synchronization, and related functionality.
The name “MyoBooking” refers to the scheduling system and service functionality provided through MyofunctionalTherapist.com. MyoBooking is not a separate legal entity and is not a separate party to this Agreement.
To the extent Business Associate creates, receives, maintains, or transmits Protected Health Information on behalf of Provider in connection with the services described in this Agreement, the Parties intend for Business Associate to act as a “Business Associate” and Provider to act as a “Covered Entity” or, where applicable, as a healthcare provider subject to the HIPAA Rules.
2. SCOPE OF THIS AGREEMENT
This Agreement applies exclusively to Provider’s participation in and use of MyofunctionalTherapist.com and to Protected Health Information created, received, maintained, or transmitted in connection with the services provided through MyofunctionalTherapist.com.
Covered services may include:
- Provider profiles and provider accounts;
- appointment scheduling and booking;
- appointment confirmations and reminders;
- appointment cancellations and rescheduling;
- appointment-related communications;
- booking and intake forms;
- storage and provider access to information submitted through booking or intake forms;
- email communications relating to appointments;
- calendar synchronization;
- video or virtual appointment integrations;
- related hosting, storage, processing, security, and transmission of information; and
- other services specifically made available through MyofunctionalTherapist.com that involve PHI.
For the avoidance of doubt, this Agreement does not cover, encompass, or apply to unrelated websites, customers, projects, services, general web-design work, general marketing services, or other business activities of Business Associate that are outside the services provided through MyofunctionalTherapist.com.
The obligations of Business Associate under this Agreement arise only with respect to PHI handled in connection with the covered MyofunctionalTherapist.com services.
3. DEFINITIONS
The terms “Business Associate,” “Covered Entity,” “Breach,” “Designated Record Set,” “Disclosure,” “Individual,” “Minimum Necessary,” “Protected Health Information,” “Required By Law,” “Security Incident,” “Subcontractor,” “Unsecured Protected Health Information,” and “Use” shall have the meanings assigned to them under the HIPAA Rules, unless otherwise specified in this Agreement.
3.1 Business Associate
“Business Associate” means Myo Web Design, Inc., a California corporation, doing business as MyofunctionalTherapist.com, in its capacity as the provider of the covered services described in this Agreement.
3.2 Provider
“Provider” means the healthcare provider or healthcare practice accepting this Agreement and using MyofunctionalTherapist.com services.
3.3 HIPAA Rules
“HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules under 45 C.F.R. Parts 160 and 164, as amended from time to time.
3.4 MyoBooking
“MyoBooking” means the appointment scheduling and calendar functionality provided through MyofunctionalTherapist.com. MyoBooking is a product or service name and is not a separate legal entity or separate contracting party.
3.5 PHI and ePHI
“PHI” means Protected Health Information as defined under the HIPAA Rules. “ePHI” means electronic Protected Health Information.
4. PERMITTED USES AND DISCLOSURES OF PHI
Business Associate may use and disclose Protected Health Information (“PHI”) as necessary to provide, operate, maintain, secure, and support the services made available to Provider through MyofunctionalTherapist.com, including the following:
4.1 Appointment Scheduling and Management
Business Associate may use and disclose PHI as reasonably necessary to facilitate appointment scheduling, booking, confirmations, reminders, cancellations, rescheduling, appointment management, and related administrative communications requested or authorized by Provider.
4.2 Patient-Submitted Booking and Intake Information
Information submitted by a patient or prospective patient through an appointment booking, intake, registration, questionnaire, or related form made available through MyofunctionalTherapist.com may constitute PHI.
Such information may be securely received, stored, maintained, and made available to Provider through Provider’s secure MyofunctionalTherapist.com account or portal for Provider’s access and use.
Provider is responsible for determining what patient information is appropriate or necessary to collect, the purposes for which such information is collected and used, and Provider’s compliance with applicable laws, regulations, professional obligations, patient notices, consents, and healthcare requirements relating to such information.
MyofunctionalTherapist.com does not use information submitted through Provider’s booking or intake forms to make clinical decisions, provide medical advice, diagnose or treat patients, or otherwise provide healthcare services.
4.3 Appointment Communications
Business Associate may use PHI to send appointment-related communications, including confirmations, reminders, cancellation notices, rescheduling notices, and other communications reasonably necessary to manage an appointment.
Routine appointment communications are designed to contain only information reasonably necessary for scheduling and appointment management, such as the patient’s name, appointment date and time, appointment location, and other information reasonably necessary for the particular communication.
Business Associate will not intentionally include unnecessary clinical information, medical history, treatment information, intake information, clinical notes, or other unnecessary PHI in routine appointment communications.
4.4 Calendar Synchronization
Business Associate may transmit limited appointment information to calendar services connected by Provider, including Google Calendar, Microsoft Outlook, and Apple Calendar, for the purpose of synchronizing Provider’s appointments.
Calendar information will be limited to information reasonably necessary for calendar functionality and, where technically feasible, will not include unnecessary clinical information, intake information, medical notes, patient email addresses, or other unnecessary PHI.
4.5 Video and Virtual Appointment Services
Business Associate may use or transmit information reasonably necessary to establish, schedule, manage, and communicate appointments through video or virtual appointment integrations made available through MyofunctionalTherapist.com, including Zoom or similar services.
Provider is responsible for maintaining any third-party accounts, authorizations, configurations, consents, or settings under Provider’s control and for using such third-party services in accordance with applicable law and the terms governing those services.
4.6 Hosting, Storage, Processing, and Transmission
Business Associate may use PHI as reasonably necessary for the secure hosting, storage, processing, transmission, backup, maintenance, technical support, and operation of the MyofunctionalTherapist.com services.
Business Associate may engage subcontractors or service providers to perform these functions, provided that any subcontractor or service provider that creates, receives, maintains, or transmits PHI on behalf of Business Associate is subject to appropriate written obligations requiring compliance with applicable HIPAA requirements.
4.7 Business Administration and Legal Responsibilities
Business Associate may use and disclose PHI as reasonably necessary for its proper management and administration, to carry out its legal responsibilities, to obtain professional services such as legal or accounting services, to comply with applicable law, or as otherwise permitted by the HIPAA Rules.
4.8 Required by Law
Business Associate may use or disclose PHI to the extent required by applicable federal, state, or local law, provided that the use or disclosure is limited to the information required by such law.
4.9 De-Identified Information
Business Associate may create and use information that has been de-identified in accordance with applicable HIPAA requirements for legitimate business, operational, analytical, statistical, security, development, quality-improvement, or other lawful purposes.
4.10 Minimum Necessary
Business Associate will make reasonable efforts to limit its use, disclosure, and request of PHI to the minimum necessary to accomplish the intended purpose, consistent with the HIPAA Rules and the services provided under this Agreement.
5. PROHIBITED USES AND DISCLOSURES
Business Associate shall not use or disclose PHI except as permitted or required by this Agreement or as required by law.
Business Associate shall not:
- use PHI for marketing purposes except as expressly permitted by applicable law and the HIPAA Rules;
- sell PHI except as expressly permitted by applicable law and the HIPAA Rules;
- use PHI for unrelated business purposes;
- use or disclose PHI in a manner that would violate the HIPAA Rules if done by Provider, except as otherwise expressly permitted by the HIPAA Rules; or
- use PHI to make clinical decisions, diagnose or treat patients, or provide healthcare services.
6. SAFEGUARDS
Business Associate shall implement appropriate administrative, physical, and technical safeguards designed to protect PHI from unauthorized access, use, disclosure, alteration, or destruction.
Such safeguards may include, as appropriate to the services and systems involved:
- access controls and role-based access;
- authentication and password protections;
- restrictions on administrative access;
- encryption of ePHI in transit and at rest where technically applicable;
- secure transmission methods;
- workforce access controls;
- security monitoring and logging;
- backup and recovery procedures;
- data protection measures;
- vulnerability and security management procedures; and
- other safeguards required by applicable provisions of the HIPAA Security Rule.
Business Associate shall comply with applicable requirements of the HIPAA Security Rule with respect to ePHI.
7. REPORTING OF IMPERMISSIBLE USES, DISCLOSURES, AND SECURITY INCIDENTS
Business Associate shall notify Provider of any use or disclosure of PHI not permitted by this Agreement of which Business Associate becomes aware, as required by the HIPAA Rules.
Business Associate shall also report Security Incidents as required by applicable law and the HIPAA Rules.
Business Associate shall take reasonable steps to mitigate, to the extent practicable, any harmful effect known to Business Associate resulting from an impermissible use or disclosure of PHI.
8. BREACH NOTIFICATION
8.1 Notification of Breach
Business Associate shall notify Provider of a Breach of Unsecured PHI without unreasonable delay and, in any event, no later than forty-eight (48) hours after discovery of the Breach, unless a shorter period is required by applicable law.
This 48-hour contractual requirement is intended to provide Provider with prompt notice and is in addition to any applicable requirements under the HIPAA Rules.
8.2 Content of Notice
To the extent available, Business Associate’s notice shall include:
- the nature of the Breach;
- the date of the Breach, if known;
- the date the Breach was discovered;
- the types of PHI involved;
- identification of affected individuals, to the extent reasonably available;
- actions taken or proposed to mitigate the Breach; and
- actions taken or proposed to prevent recurrence.
Business Associate may supplement the initial notice as additional information becomes available.
8.3 Responsibility for Individual and Government Notifications
Unless otherwise agreed in writing, Provider shall remain responsible for making notifications to affected individuals, the Secretary of the U.S. Department of Health and Human Services, and the media when required by the HIPAA Rules.
Business Associate shall reasonably cooperate with Provider and provide information available to Business Associate that is necessary for Provider to fulfill applicable notification obligations.
9. ACCESS TO PHI
To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make such PHI available to Provider as reasonably necessary for Provider to fulfill its obligations under the HIPAA Rules relating to individual access requests.
Business Associate shall provide reasonable cooperation and assistance in responding to requests for access to PHI maintained through the MyofunctionalTherapist.com services.
Where an individual makes an access request directly to Business Associate, Business Associate may direct the individual to Provider unless otherwise required by applicable law or agreed by the Parties.
10. AMENDMENT OF PHI
Business Associate shall make PHI maintained in a Designated Record Set available for amendment and shall make amendments or other appropriate changes as directed by Provider, to the extent required by the HIPAA Rules and reasonably practicable within the MyofunctionalTherapist.com services.
Business Associate shall provide reasonable cooperation and assistance to Provider in responding to requests for amendment.
11. ACCOUNTING OF DISCLOSURES
Business Associate shall make available information reasonably necessary for Provider to fulfill its obligations under the HIPAA Rules relating to accounting of disclosures of PHI.
Business Associate shall maintain such information as required by applicable law.
12. REGULATORY AND GOVERNMENT ACCESS
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services as required by the HIPAA Rules for purposes of determining Provider’s compliance with the HIPAA Rules.
13. SUBCONTRACTORS AND SERVICE PROVIDERS
Business Associate may engage subcontractors and service providers to perform services on its behalf.
If a subcontractor or service provider creates, receives, maintains, or transmits PHI on behalf of Business Associate, Business Associate shall require such subcontractor or service provider to enter into a written agreement requiring the subcontractor or service provider to comply with applicable HIPAA requirements and to provide appropriate safeguards for PHI.
Business Associate shall remain responsible for the performance of its obligations under this Agreement to the extent required by applicable law.
Business Associate may change or replace subcontractors or service providers from time to time as reasonably necessary to operate and maintain the MyofunctionalTherapist.com services.
14. THIRD-PARTY INTEGRATIONS
MyofunctionalTherapist.com may provide integrations or functionality involving third-party services, including Google Calendar, Microsoft Outlook, Apple Calendar, Zoom, email services, and other technology services.
The availability and functionality of such third-party integrations may depend upon the third party’s technology, policies, terms, security practices, and configuration requirements.
Provider is responsible for third-party accounts, permissions, authorizations, configurations, and settings that Provider directly controls.
Business Associate shall not intentionally transmit more PHI through an integration than is reasonably necessary for the functionality being provided, subject to the technical capabilities and limitations of the applicable third-party service.
15. PROVIDER RESPONSIBILITIES
Provider shall:
- comply with applicable HIPAA requirements and other applicable privacy and healthcare laws;
- determine what patient information Provider collects through MyofunctionalTherapist.com;
- determine the purposes for which patient information is collected and used;
- provide required notices and obtain required authorizations or consents;
- maintain the accuracy and completeness of information submitted or maintained by Provider;
- appropriately configure available MyofunctionalTherapist.com settings;
- use third-party integrations lawfully and in accordance with their applicable terms;
- notify Business Associate of applicable restrictions or special requirements affecting the use or disclosure of PHI; and
- maintain accurate account and contact information.
16. PROVIDER’S CLINICAL AND HEALTHCARE RESPONSIBILITIES
Provider remains solely responsible for:
- patient care;
- diagnosis and treatment;
- clinical decisions;
- medical and healthcare services;
- clinical documentation;
- accuracy and completeness of clinical information;
- obtaining required patient consents and authorizations;
- maintaining required healthcare records;
- compliance with professional licensing requirements;
- compliance with applicable federal and state healthcare laws; and
- determining the appropriate PHI to collect, maintain, access, and use in connection with Provider’s practice.
MyofunctionalTherapist.com and MyoBooking provide technology and administrative functionality only and do not provide medical advice, diagnosis, treatment, or other healthcare services.
17. SECURITY INFORMATION AND COOPERATION
Upon reasonable request, Business Associate shall provide Provider with reasonably available information concerning the safeguards used to protect PHI within the MyofunctionalTherapist.com services, subject to reasonable confidentiality, security, and operational limitations.
Nothing in this Section requires Business Associate to disclose confidential security information, proprietary security architecture, credentials, security vulnerabilities, penetration-testing details, or other information that could reasonably compromise the security of the services.
18. MITIGATION
Business Associate shall take reasonable measures to mitigate, to the extent practicable, any harmful effect that is known to Business Associate resulting from a use or disclosure of PHI in violation of this Agreement or applicable HIPAA requirements.
19. RETURN OR DESTRUCTION OF PHI
Upon termination of this Agreement, Business Associate shall, where feasible and as required by the HIPAA Rules, return or destroy PHI received from or created or received on behalf of Provider.
If return or destruction of PHI is not reasonably feasible, Business Associate shall continue to protect the PHI and shall limit further use and disclosure of the PHI to those purposes that make return or destruction infeasible or are otherwise required or permitted by law.
Backup copies of PHI may remain in secure backup systems for a reasonable period in accordance with applicable backup, disaster-recovery, retention, and security procedures. Such retained PHI shall remain subject to the protections of this Agreement and shall not be used or disclosed except as permitted by this Agreement or required by law.
Business Associate shall require applicable subcontractors to follow corresponding obligations regarding the return, destruction, retention, and protection of PHI.
20. LEGAL IDENTITY AND BUSINESS NAME
The legal entity responsible for the MyofunctionalTherapist.com services covered by this Agreement is:
Myo Web Design, Inc., a California corporation, doing business as MyofunctionalTherapist.com.
MyofunctionalTherapist.com is the provider-facing business name and does not constitute a separate legal entity.
MyoBooking is a service/product name used for the appointment scheduling functionality provided through MyofunctionalTherapist.com and is not a separate legal entity or party.
Nothing in this Agreement expands the scope of Business Associate’s obligations beyond the services and PHI described in Section 2.
21. TERM
This Agreement becomes effective when Provider electronically accepts it and shall remain in effect for as long as Provider uses MyofunctionalTherapist.com services involving PHI, unless terminated in accordance with this Agreement.
22. TERMINATION FOR CAUSE
Either Party may terminate this Agreement for a material violation by the other Party if the violation is not cured within a reasonable period after written notice.
If termination is not feasible, the Parties shall take reasonable steps to mitigate and protect PHI as required by the HIPAA Rules and this Agreement.
23. EFFECT OF TERMINATION
Termination of this Agreement shall not relieve either Party of obligations that accrued before termination.
The obligations relating to PHI shall survive termination to the extent required by applicable law or as necessary to protect PHI retained by Business Associate.
24. NO OWNERSHIP TRANSFER
Nothing in this Agreement transfers ownership of PHI, patient records, intellectual property, software, trademarks, website content, or other property from one Party to the other.
Provider retains responsibility for the patient and clinical information submitted or maintained by Provider.
Business Associate retains ownership of its software, systems, technology, trademarks, website infrastructure, and other intellectual property, except as otherwise expressly agreed in writing.
25. NO CLINICAL RELATIONSHIP
Business Associate does not provide medical, clinical, diagnostic, therapeutic, or other healthcare services.
The Parties are independent businesses, and nothing in this Agreement creates a physician-patient relationship, therapist-patient relationship, partnership, joint venture, employment relationship, or agency relationship between the Parties.
26. INDEPENDENT BUSINESS RELATIONSHIP
Provider independently operates Provider’s healthcare practice and is responsible for Provider’s professional, legal, regulatory, financial, and clinical obligations.
Business Associate provides technology and administrative services and does not control Provider’s professional judgment or clinical practice.
27. CHANGES IN LAW
If a change in applicable federal or state law materially affects this Agreement or the Parties’ obligations concerning PHI, the Parties shall cooperate in good faith to make reasonable amendments necessary to maintain compliance with applicable law.
28. SEVERABILITY
If any provision of this Agreement is determined to be invalid or unenforceable, the remaining provisions shall remain in effect to the fullest extent permitted by law.
29. GOVERNING LAW
This Agreement shall be governed by applicable federal law, including the HIPAA Rules, and by the laws of the State of California to the extent not preempted by federal law.
30. NOTICES
Formal notices under this Agreement shall be provided in writing using the contact information maintained in Provider’s MyofunctionalTherapist.com account or using the Business Associate contact information below.
Business Associate
Myo Web Design, Inc.
d/b/a MyofunctionalTherapist.com
1019 E Saint Andrews St
Ontario, CA 91761
Email: admin@myofunctionaltherapist.com
Business Associate may update its notice information by providing updated information through MyofunctionalTherapist.com or by written notice to Provider.
Provider shall maintain accurate contact information in Provider’s MyofunctionalTherapist.com account.
31. ENTIRE AGREEMENT
This Agreement constitutes the Parties’ agreement concerning the use and protection of PHI in connection with the MyofunctionalTherapist.com services.
This Agreement may be incorporated into or used together with other agreements governing Provider’s use of MyofunctionalTherapist.com services. If another agreement contains provisions specifically governing PHI that conflict with this Agreement, the Parties shall interpret the agreements to provide the protection required by applicable law.
32. ELECTRONIC ACCEPTANCE
Provider may accept this Agreement electronically by checking the applicable acknowledgment box and submitting the Provider registration or enrollment form.
Provider’s electronic acceptance constitutes Provider’s acknowledgment and acceptance of this Agreement to the extent permitted by applicable law.
The electronic acceptance record should identify, to the extent technically available:
- Provider’s name;
- Provider’s account or registration information;
- the title and version of this Agreement;
- the date and time of acceptance;
- the applicable MyofunctionalTherapist.com account; and
- the legal Business Associate as Myo Web Design, Inc., d/b/a MyofunctionalTherapist.com.
Provider’s electronic acceptance shall have the same force and effect as a written signature to the extent permitted by applicable law.
33. ACKNOWLEDGMENT
By electronically accepting this Agreement, Provider acknowledges that Provider has had an opportunity to review this Agreement and agrees to be bound by its terms with respect to Provider’s use of the MyofunctionalTherapist.com services involving PHI.
BUSINESS ASSOCIATE:
Myo Web Design, Inc.
d/b/a MyofunctionalTherapist.com
1019 E Saint Andrews St
Ontario, CA 91761
admin@myofunctionaltherapist.com
PROVIDER:
Provider Name: ______________________________
Practice Name: ______________________________
Date Accepted: ______________________________
Electronic Acceptance: _______________________

