Business Associate Agreement (BAA)

Yes — Thyra will sign a BAA. Thyra is operated by Endo Mind, Inc. When Thyra creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity, Endo Mind acts as a Business Associate and executes a HIPAA Business Associate Agreement under 45 CFR Parts 160 and 164.

Note: This page summarizes Thyra's standard BAA for informational purposes and does not constitute legal advice. The executed agreement controls. To request the current signable BAA, contact support@thyrahealth.com.

What Thyra commits to as a Business Associate

Breach notification

Thyra notifies the covered entity without unreasonable delay and no later than sixty (60) days after discovery of a breach of unsecured PHI, consistent with 45 CFR 164.410. A shorter period may be agreed in the underlying agreement. Notification includes, to the extent available, the individuals affected, what happened, the types of information involved, and the steps being taken to investigate and mitigate.

Subcontractors

Any subcontractor that handles PHI on Thyra's behalf must agree in writing to the same restrictions and conditions, and Thyra remains responsible for their compliance as required by HIPAA.

Access, amendment, and accounting

Where Thyra maintains PHI in a designated record set, Thyra makes it available so the covered entity can meet its obligations for access (45 CFR 164.524), amendment (45 CFR 164.526), and accounting of disclosures (45 CFR 164.528).

Return or destruction of PHI

On termination, Thyra returns or destroys PHI it still maintains, at the covered entity's option and where feasible. Where return or destruction is infeasible, the protections of the BAA continue to apply and further use is limited.

See also Thyra's HIPAA compliance statement and security overview.