Get your free denial audit

One page, about three minutes: sign the BAA and upload your files right here. Your scorecard arrives within one business day. No waiting, no back-and-forth. Prefer to watch first? 60 seconds from the founder →

1. Sign the BAA below (type your name)  →  2. Upload your 835/ERA files on this page (how to export them — 3 clicks per billing system)  →  3. Scorecard, within one business day. Free either way.

HIPAA BUSINESS ASSOCIATE AGREEMENT (Claimmender)

This Business Associate Agreement ("BAA") is entered into between the practice identified above ("Covered Entity") and Claimmender ("Business Associate"), effective upon electronic acceptance below, in connection with denial-recovery and billing-audit services.

1. Definitions

Terms used but not defined here have the meanings given in HIPAA and the HITECH Act and their implementing regulations (45 CFR Parts 160, 162, 164). "PHI" means protected health information created, received, maintained, or transmitted by Business Associate for Covered Entity.

2. Permitted uses

Business Associate may use or disclose PHI solely to perform billing-audit and denial-recovery services for Covered Entity — including analysis of claims and remittance data, preparation of resubmissions, appeals, and payment disputes, and communication with Covered Entity's payers — and as required by law, limited to the minimum necessary.

3. Safeguards

Business Associate will implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including encryption of electronic PHI in transit and at rest, access controls, and processing of claim files on access-controlled systems. PHI will not be placed in third-party tools not covered by a BAA or equivalent safeguard.

4. Reporting

Business Associate will report to Covered Entity any impermissible use or disclosure, security incident, or breach of unsecured PHI without unreasonable delay and no later than 10 days after discovery, with information reasonably needed for Covered Entity's notification obligations (45 CFR 164.404–.410).

5. Subcontractors

Any subcontractor creating, receiving, maintaining, or transmitting PHI for Business Associate will be bound in writing to restrictions at least as stringent as this BAA (current: Google LLC — Workspace storage, under Google's BAA).

6. Individual rights & HHS

Business Associate will make PHI available to Covered Entity as needed for individuals' access, amendment, and accounting rights (45 CFR 164.524, .526, .528) and make its practices and records available to the Secretary of HHS for compliance determination.

7. Term; return of PHI

This BAA terminates with the parties' service relationship. On termination, Business Associate will return or destroy all PHI where feasible; where not feasible, this BAA's protections continue to apply to retained PHI.

8. Miscellaneous

No third-party beneficiary rights are created. Ambiguities resolve in favor of HIPAA compliance. A copy of this executed BAA will be emailed to the address provided for Covered Entity's records.

Nothing to worry about here: the BAA is a standard healthcare privacy agreement that legally binds us to protect your practice's data. It does not sign you up for any paid service. Our pledge: for every dollar Claimmender earns, we commit 1% of fees toward helping erase patient medical debt — roughly a dollar of debt relieved per dollar earned, through partner-driven debt forgiveness. Files upload directly into our HIPAA-covered Google Workspace storage (under Google's Business Associate Agreement), access-controlled — never plain email. You'll receive instant confirmation; your scorecard follows within one business day. The audit is free and yours to keep; recovery, if you want it, is a separate agreement at a % of recovered dollars only. Questions first? rahul@claimmender.com · How we protect your data