Business Associate Agreement
Last updated 18 September 2026
When a HIPAA-covered entity uses Patient Care Circle to coordinate care, PCC acts as a Business Associate under HIPAA. We take on — and comply with — the obligations that role carries for protecting protected health information (PHI).
Agreements with our vendors
We maintain Business Associate Agreements with every subprocessor that creates, receives, maintains, or transmits PHI on our behalf — currently our database host (Neon) and our infrastructure and document-storage provider (DigitalOcean) — with terms at least as protective as our own obligations. Vendors that never receive PHI, such as our payments processor, do not require one. See our subprocessors page for the current register.
How we comply
- Use and disclose PHI only as permitted and as needed to provide the service.
- Apply administrative, physical, and technical safeguards — see our security documentation.
- Require every subprocessor that handles PHI to sign an equivalent agreement before that data reaches them.
- Report security incidents and breaches of unsecured PHI as required, and cooperate on notification.
- Support access, amendment, and accounting-of-disclosures requests, and return or destroy PHI at termination where feasible.
For covered-entity customers
We enter into a Business Associate Agreement with each covered-entity customer as part of onboarding. To arrange one, contact legal@patientcarecircle.com. The PCC contracting entity is [Patient Care Circle, Inc.].