HIPAA Business Associate Agreement for Shape Software Inc. “Covered Entity” Clients

Updated April 29, 2022

Table of Contents

These Standard HIPAA Business Associate Agreement Terms and Conditions (“HIPAA Addendum”) shall be incorporated into the Terms of Service (which may be found at https://setshape.com/terms-of-service/) and any other agreement that a person or entity signs with Shape Software Inc. (“Shape” “Covered Entity” or “Company”)  for Customers that are Covered Entities (as defined below) and that provide Protected Health Information (“PHI”)(as defined below) to Shape in connection with services they have purchased. These terms supplement and are made part of any agreement between Shape and Customers (“Underlying Agreement”) in order to comply with the federal Standards for Privacy of Individually Identifiable Health Information, located at 45 C.F.R. Part 160 and Part 164, Subparts A through E (“Privacy Rule”) and the Health Information Technology for Economic and Clinical Health Act, Public Law 111-005 (the “HITECH Act”).

Definitions

Terms used, but not otherwise defined, in this HIPAA Addendum shall have the same meaning as those terms in the Privacy Rule or the HITECH Act.

Obligations And Activities Of Business Associate

Permitted Uses And Disclosures By Shape

Obligations Of Covered Entity

Term And Termination

Miscellaneous In Addition To Terms And Conditions