DocLienDocLien
LegalTermsPrivacy

Business Associate Agreement

Effective October 11, 2026 · Version 2026-10-11.1

This Business Associate Agreement ("Agreement") is between DocLien ("Business Associate" or "DocLien") and the medical provider that accepts it ("Covered Entity" or "Provider"). It is part of DocLien’s Terms of Service.

It takes effect when an authorized person accepts it for the Provider in DocLien. That person confirms they are allowed to bind the Provider.

Contents
  1. Definitions
  2. What DocLien may do with PHI
  3. Limits
  4. Safeguards
  5. Reporting
  6. Subcontractors
  7. Patients’ rights
  8. Other obligations
  9. The Provider’s obligations
  10. Term and ending
  11. General

1. Definitions

Terms used but not defined here (including Breach, Data Aggregation, Designated Record Set, Health Care Operations, Individual, Minimum Necessary, Protected Health Information ("PHI"), Required by Law, Secretary, Security Incident, Subcontractor and Unsecured PHI) have the meanings given in the HIPAA Privacy, Security, Breach Notification and Enforcement Rules at 45 C.F.R. Parts 160 and 164 (the "HIPAA Rules"). PHI here means PHI that DocLien creates, receives, keeps or sends for the Provider.

2. What DocLien may do with PHI

  • Use and disclose PHI to provide the Service to the Provider under the Terms of Service: receiving referrals, scheduling, collecting forms and electronic signatures, storing records and bills, sharing them with the patient and with the patient’s attorney as the patient has authorized, and tracking liens and case status.
  • Use PHI for its proper management and administration and to carry out its legal responsibilities, and disclose PHI for those purposes if the disclosure is Required by Law, or if DocLien gets reasonable written assurance that the recipient will keep it confidential, use it only for the purpose given or as Required by Law, and report any breach of confidentiality to DocLien.
  • Provide Data Aggregation services relating to the Provider’s Health Care Operations.
  • De-identify PHI as allowed by 45 C.F.R. 164.514(a)–(c). De-identified information is no longer PHI.
  • Report violations of law to authorities as allowed by 45 C.F.R. 164.502(j)(1).

3. Limits

  • DocLien will not use or disclose PHI except as this Agreement allows or as Required by Law, and will not use or disclose it in a way that would break the HIPAA Rules if the Provider did it (except as section 2 allows for management and administration and Data Aggregation).
  • DocLien will follow the Minimum Necessary standard.
  • DocLien will not sell PHI and will not use or disclose it for marketing or fundraising.

4. Safeguards

DocLien will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) for electronic PHI, to prevent uses and disclosures this Agreement does not allow. These include encryption, two-step sign-in, role-based access controls, audit logging, workforce training and confidentiality agreements.

5. Reporting

DocLien will report to the Provider any use or disclosure of PHI that this Agreement does not allow, any Security Incident it becomes aware of, and any Breach of Unsecured PHI as 45 C.F.R. 164.410 requires. It will report without unreasonable delay and no later than 10 business days after discovery. Breach reports will include, to the extent known, the people affected and the other information the Provider needs to notify them. DocLien will cooperate with the Provider’s investigation and its notices to patients, regulators and others.

The parties agree that this section is notice of unsuccessful Security Incidents that happen routinely and do not result in unauthorized access to PHI, such as pings, port scans, blocked sign-in attempts and denial-of-service attempts. No further report of those is required.

DocLien will take reasonable steps to reduce any harmful effect it knows of from a use or disclosure that this Agreement does not allow.

6. Subcontractors

DocLien will make sure that any Subcontractor that creates, receives, keeps or sends PHI for DocLien agrees in writing to the same restrictions, conditions and requirements that apply to DocLien under this Agreement, as 45 C.F.R. 164.502(e)(1)(ii) and 164.308(b)(2) require.

7. Patients’ rights

  • Access: when the Provider asks, DocLien will make PHI in a Designated Record Set available to the Provider, or to the patient as the Provider directs, within 5 business days, in electronic form when asked, so the Provider can meet 45 C.F.R. 164.524 and California Health and Safety Code section 123110.
  • Amendment: DocLien will make amendments to PHI in a Designated Record Set that the Provider directs, within 10 business days, as 45 C.F.R. 164.526 requires.
  • Accounting: DocLien will document disclosures and give the Provider, within 10 business days of a request, the information it needs to account for disclosures under 45 C.F.R. 164.528.
  • If a patient asks DocLien directly for any of these, DocLien will tell the Provider within 5 business days.

8. Other obligations

  • Where DocLien carries out one of the Provider’s obligations under the Privacy Rule, it will comply with the requirements that apply to the Provider for that obligation.
  • DocLien will make its internal practices, books and records about PHI available to the Secretary to decide whether the Provider is complying with the HIPAA Rules.
  • DocLien will comply with the California Confidentiality of Medical Information Act (Civil Code section 56 and following) as it applies to DocLien, and with California data-breach laws.

9. The Provider’s obligations

  • Tell DocLien about any limitation in the Provider’s Notice of Privacy Practices, any change in or withdrawal of a patient’s permission (including a revoked authorization), and any restriction the Provider has agreed to, that affects DocLien’s use or disclosure of PHI.
  • Get any authorization or consent the law requires before PHI is shared through DocLien, including the patient’s authorization to release information to the patient’s attorney. DocLien provides an authorization form for this, which the Provider is responsible for approving.
  • Not ask DocLien to use or disclose PHI in a way the HIPAA Rules would not allow the Provider to.
  • Give patients its own Notice of Privacy Practices, and keep its own medical records as the law requires.

10. Term and ending

This Agreement lasts as long as DocLien handles PHI for the Provider. Either party may end it, along with the Provider’s use of the Service, if the other materially breaches it and does not fix the breach within 30 days of written notice. If a fix is not possible, either party may end it immediately.

When it ends, DocLien will return or destroy all PHI it holds for the Provider, if that is feasible. Where returning or destroying it is not feasible (for example, records needed for a patient’s ongoing case or lien, audit and signature records, or records under a legal hold), DocLien will keep protecting it under this Agreement and use or disclose it only for the purposes that make returning or destroying it infeasible, for as long as it keeps it.

11. General

  • References to the HIPAA Rules mean the rules as amended. The parties will amend this Agreement as needed to comply with changes in the law.
  • This Agreement is read to allow compliance with the HIPAA Rules. If it conflicts with the Terms of Service, this Agreement controls for PHI.
  • Sections 5, 6, 8 and 10 continue after this Agreement ends for as long as DocLien holds PHI.
  • Nothing in this Agreement gives anyone other than DocLien and the Provider any rights.
  • Notices to DocLien under this Agreement go to privacy@doclien.com. Notices to the Provider go to the email on its DocLien account.

All legal documents