Business Associate Agreement (BAA)
Yes — Thyra will sign a BAA. Thyra is operated by Endo Mind, Inc. When Thyra creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity, Endo Mind acts as a Business Associate and executes a HIPAA Business Associate Agreement under 45 CFR Parts 160 and 164.
Note: This page summarizes Thyra's standard BAA for informational purposes and does not constitute legal advice. The executed agreement controls. To request the current signable BAA, contact support@thyrahealth.com.
What Thyra commits to as a Business Associate
- Use and disclosure limits. PHI is used or disclosed only as permitted by the BAA or as required by law, and never for advertising.
- No sale of PHI. Thyra will not sell PHI.
- Safeguards. Administrative, physical, and technical safeguards under the HIPAA Security Rule (45 CFR Part 164 Subpart C), including role-based access, least privilege, encryption in transit, and audit controls.
- Minimum necessary. Only the minimum necessary PHI is requested, used, or disclosed for the intended purpose.
Breach notification
Thyra notifies the covered entity without unreasonable delay and no later than sixty (60) days after discovery of a breach of unsecured PHI, consistent with 45 CFR 164.410. A shorter period may be agreed in the underlying agreement. Notification includes, to the extent available, the individuals affected, what happened, the types of information involved, and the steps being taken to investigate and mitigate.
Subcontractors
Any subcontractor that handles PHI on Thyra's behalf must agree in writing to the same restrictions and conditions, and Thyra remains responsible for their compliance as required by HIPAA.
Access, amendment, and accounting
Where Thyra maintains PHI in a designated record set, Thyra makes it available so the covered entity can meet its obligations for access (45 CFR 164.524), amendment (45 CFR 164.526), and accounting of disclosures (45 CFR 164.528).
Return or destruction of PHI
On termination, Thyra returns or destroys PHI it still maintains, at the covered entity's option and where feasible. Where return or destruction is infeasible, the protections of the BAA continue to apply and further use is limited.
See also Thyra's HIPAA compliance statement and security overview.