Business Associate Agreement (BAA)
Standard HIPAA BAA topics for US covered entities and business associates that use Ritaja Practice to create, receive, maintain, or transmit protected health information (PHI).
Not a substitute for counsel. This page is the readable form of the standard BAA we generate when you e-sign during onboarding. Your executed PDF is the signed copy for your records.
Last updated: August 2026
Parties and purpose
When your practice is a HIPAA covered entity (or another business associate acting for a covered entity), Ritaja Practice (operated by Ritaja Systems) acts as your business associate for protected health information (PHI) created, received, maintained, or transmitted in the service.
This BAA supplements the Terms of Service. If this BAA and the Terms conflict on how PHI may be used or disclosed, this BAA controls. Fees, price changes, and feature packaging are governed by the Terms; a plain-language summary is included so you see it before you sign.
This agreement is intended to satisfy 45 CFR §164.504(e), §164.308(b), and §164.314(a). It is not a substitute for advice from your own counsel.
Permitted uses and disclosures
Ritaja Practice may use or disclose PHI only to provide the subscribed service, to support your practice as you instruct, for proper management and administration of Ritaja Systems, or as required by law.
- We will not use or disclose PHI for our own marketing unrelated to your instructions.
- We will not sell PHI.
- We apply the minimum necessary standard to our workforce when using PHI to run the service.
- You remain responsible for sending only the PHI needed for the task (minimum necessary from the covered entity).
- We may de-identify PHI under HIPAA de-identification rules and use de-identified information to improve the service, unless you instruct us in writing not to.
Safeguards
We implement administrative, physical, and technical safeguards appropriate to the service, including access controls, encryption in transit and at rest, audit logging, and workforce confidentiality. Operational detail is on the Trust & security page. We limit PHI access to workforce members who need it to perform their jobs.
Subcontractors (subprocessors)
If we engage a subcontractor that creates, receives, maintains, or transmits PHI for us, that subcontractor must agree in writing to restrictions and safeguards at least as protective as this BAA. Categories of subprocessors we may use (hosting, email, video, and similar) are listed on the Trust center. We remain responsible to you for their PHI handling under this BAA.
Access, amendment, and accounting
We will make PHI available so you can meet individual rights of access (45 CFR §164.524), amendment (§164.526), and accounting of disclosures (§164.528), using product tools where they exist or through support if they do not. You remain responsible for responding to the individual; we assist within a reasonable time after a documented request from you.
Availability to the Secretary of HHS
We will make our internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for determining your or our compliance with HIPAA, as required by 45 CFR §164.504(e)(2)(ii)(H).
Security incidents and breach notification
We will report to you any use or disclosure of PHI not permitted by this BAA, and any security incident we discover that affects your PHI, without unreasonable delay.
For a breach of unsecured PHI in systems we control, we will notify you without unreasonable delay and no later than 60 calendar days after discovery, and provide information reasonably required for your notification duties under HIPAA and HITECH.
Report suspected incidents to [email protected] (or the security contact on the Trust page). An outage or software defect is not a breach unless unsecured PHI is actually acquired, accessed, used, or disclosed in a manner not permitted by HIPAA.
If you stop paying, cancel, or are suspended
Stopping payment does not immediately wipe your charts. We treat PHI as a clinical record, not as collateral we destroy the day an invoice fails.
Past due: if an invoice is overdue, charts, calendar, and clinical notes stay available so care can continue. Billing tools, the client portal, and payroll may pause until we receive payment.
Suspended or cancelled: after notice, staff sign-in is blocked (including for non-payment). PHI remains stored. It is not deleted on that day.
Export hold: for 90 calendar days after we notify you that the account is suspended or cancelled, we keep PHI so you can save a copy or ask us for one. After that window we return or destroy PHI where feasible, as described below.
How you save data and how to ask us
While you can still sign in, a practice administrator should export records you must keep (charts, notes, appointments, billing) from Settings when export is enabled for your practice. Do this before you cancel if you can.
If sign-in is already blocked, or export is not enabled in the product, email [email protected] with your practice legal name, the owner email on the account, and “data export” in the subject. We will provide a reasonably complete copy of patient charts, notes, appointments, and billing records we hold, in commonly used formats (such as PDF and CSV) as available, during the 90-day hold.
We do not email unencrypted PHI. We will agree a secure transfer method (for example a time-limited download link). You remain responsible for storing the copy under your own retention and board rules.
We are not a records-storage vendor after the hold ends. Keep the copies your malpractice carrier, licensing board, or state law requires.
Return or destruction of PHI
When the service ends and the 90-day hold expires, or sooner if you instruct us in writing after you have received your copy, we will return or destroy PHI in our production systems where feasible.
Exceptions: (1) copies in encrypted backups that expire on a rolling schedule; (2) records we must keep by law or for the defense of legal claims, used only for that purpose; (3) copies you already exported. If return or destruction is not feasible, we will extend the protections of this BAA to remaining PHI and limit further uses and disclosures to those that make return or destruction infeasible, until the PHI is destroyed.
Term, termination for cause, and survival
This BAA lasts until the underlying service ends, unless terminated earlier as allowed here.
Either party may terminate the service relationship on 30 days written notice. You may terminate this BAA if we have violated a material term and we do not cure within 30 days after written notice (or immediately if cure is not possible). We may terminate if you violate a material term.
Obligations that by their nature should survive (including return or destruction of PHI, remaining protections if destruction is infeasible, and limitations on use of retained PHI) survive termination.
If the system has a problem while you are working
We use reasonable efforts to keep Ritaja Practice available. This standard BAA does not promise a numeric uptime percentage. Scheduled maintenance will be announced when practicable. For an unplanned outage we restore the service and, if needed, restore data from backups. Your PHI remains yours.
If you cannot work in the product, keep paper or offline notes as your professional rules require, then enter them when service returns. Contact [email protected] with your practice name and what failed. We will give you status and any workaround we have.
A service interruption is not by itself a reportable breach. Fees, credits, and liability for downtime are in the Terms of Service, not in this BAA.
Plans, price changes, and new features (summary)
Fees are governed by the Terms of Service. For the record at signing: we may review list prices at most once every 12 months (not twice a year as a default). A like-for-like base subscription increase requires at least 30 days email notice, applies at the next billing period, honors prepaid time, and will not exceed 10% in any 12-month period. Plan changes, extra seats, and usage add-ons (video, AI) are billed at then-current published rates and are outside that cap.
We may add features to your plan at no extra charge. Optional paid modules require your opt-in. We will not remove a core capability of the plan you pay for without 30 days written notice or an equivalent replacement.
If the Terms and this summary conflict on money, the Terms control. If they conflict on PHI, this BAA controls.
Your practice’s duties
- Provide only the minimum necessary PHI to the service.
- Maintain your own HIPAA policies, workforce training, Notice of Privacy Practices, and patient rights processes.
- Keep BAAs with other vendors that handle your PHI.
- Use unique staff logins; do not share passwords.
- Report suspected misuse or security incidents to us promptly.
- Export or request copies of records you must retain before the post-termination hold ends.
How to obtain the BAA
Complete practice registration. After approval you e-sign during onboarding; Ritaja Practice countersigns, stores the PDF, and emails the executed copy to the practice owner. Contact us if you need a copy resent. Related: Terms of Service (fees and availability) and Trust & security.
Contact
Privacy, export requests, and compliance inquiries:
EU/UK practices: see the Data Processing Agreement.
← Plans & pricing · Trust center · BAA · DPA