Business Associate Agreement
Version: 2026-07-02
This is the agreement you are being asked to sign when you accept the BAA during onboarding.
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement ("Agreement") is entered into between Molarone Inc., a Delaware corporation ("Business Associate"), and the dental practice accepting this Agreement through the M1 platform ("Covered Entity"), effective as of the date of electronic acceptance below.
1. DEFINITIONS
Terms used but not otherwise defined in this Agreement have the meanings given to them in the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations at 45 CFR Parts 160 and 164 (collectively, "HIPAA"), including the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
"Protected Health Information" or "PHI" means individually identifiable health information, as defined at 45 CFR § 160.103, that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity through the M1 platform, including electronic PHI ("ePHI").
"Services" means the eligibility verification, claims submission, remittance (ERA) processing, denial management, and related dental revenue cycle management functionality provided by Business Associate to Covered Entity through the M1 platform.
"Security Incident" has the meaning set forth in 45 CFR § 164.304.
2. PERMITTED USES AND DISCLOSURES OF PHI
2.1 Business Associate may use or disclose PHI only as necessary to perform the Services, as permitted or required by this Agreement, or as required by law.
2.2 Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that any disclosure for such purposes is required by law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and be used or further disclosed only as required by law or for the purpose for which it was disclosed, and the person notifies Business Associate of any instance of which it becomes aware in which the confidentiality of the information has been breached.
2.3 Business Associate may use PHI to provide data aggregation services relating to the health care operations of Covered Entity, and to report violations of law to appropriate federal and state authorities, consistent with 45 CFR § 164.502(j)(1).
2.4 Business Associate may de-identify PHI in accordance with 45 CFR § 164.514(a)-(c) and use such de-identified information for product improvement, analytics, and benchmarking purposes. De-identified information no longer constitutes PHI and is not subject to the restrictions of this Agreement. Covered Entity may opt out of this use at any time by contacting support@molarone.com; opt-out will take effect within thirty (30) days of receipt of the request and will apply to future de-identification only, not to de-identified data already processed.
2.5 Business Associate will not use or disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Covered Entity, except as permitted under Sections 2.2 and 2.3 above.
3. OBLIGATIONS OF BUSINESS ASSOCIATE
3.1 Safeguards. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, consistent with the HIPAA Security Rule (45 CFR Part 164, Subpart C), including but not limited to: encryption of PHI at rest (AES-256-GCM) and in transit (TLS 1.2 or higher); row-level access controls scoping each Covered Entity's data to that Covered Entity alone; and audit logging of access to and modification of PHI.
3.2 Breach Reporting. Business Associate will report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including breaches of unsecured PHI as required by 45 CFR § 164.410, without unreasonable delay and in no case later than sixty (60) days after discovery of the breach.
3.2(b) Security Incident Reporting. Business Associate shall report to Covered Entity any Security Incident of which it becomes aware within a reasonable time. The parties acknowledge that attempted but unsuccessful Security Incidents (including without limitation pings, port scans, denial-of-service attempts, and unsuccessful log-on attempts) occur routinely on internet-facing systems, and that no individual notice of such routine unsuccessful attempts is required; Business Associate will instead include a summary of material unsuccessful Security Incidents in any annual or periodic security report made available to Covered Entity upon request.
3.3 Subcontractors. Business Associate will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees, in writing, to the same restrictions and conditions that apply to Business Associate under this Agreement with respect to such PHI.
3.4 Access. Business Associate will make PHI available to Covered Entity as necessary to satisfy Covered Entity's obligations to provide individuals with access to their PHI in accordance with 45 CFR § 164.524.
3.5 Amendment. Business Associate will make PHI available for amendment, and will incorporate any amendments to PHI, as directed by Covered Entity in accordance with 45 CFR § 164.526.
3.6 Accounting. Business Associate will document disclosures of PHI and information related to such disclosures as necessary for Covered Entity to respond to a request for an accounting of disclosures in accordance with 45 CFR § 164.528.
3.7 Availability to HHS. Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's and Business Associate's compliance with HIPAA.
3.8 Minimum Necessary. Business Associate will limit its use, disclosure, and request of PHI to the minimum necessary to accomplish the intended purpose, to the extent required by 45 CFR § 164.502(b).
4. OBLIGATIONS OF COVERED ENTITY
4.1 Covered Entity will not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity directly, except for data aggregation or management and administrative activities as permitted under Section 2.
4.2 Covered Entity will notify Business Associate of any limitation in its Notice of Privacy Practices, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.
4.3 Covered Entity will notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent that such changes may affect Business Associate's permitted or required uses or disclosures.
4.4 Covered Entity will promptly notify Business Associate if Covered Entity becomes aware of any breach or potential breach of the security or confidentiality of PHI in Business Associate's possession.
5. CLAIMS INTEGRITY CERTIFICATION
5.1 Covered Entity certifies that all claims submitted through M1 represent services actually rendered to patients, coded accurately in accordance with ADA CDT standards, and supported by contemporaneous clinical documentation.
5.2 For purposes of this Agreement, "false claims" include without limitation: claims for services not actually rendered to the identified patient; claims that misrepresent the nature, extent, or medical necessity of services provided; upcoded claims (billing a more complex or expensive service than was performed); unbundled claims (billing separately for services that are required to be billed together under applicable payer rules); and claims submitted with inaccurate patient, provider, or payer identification information.
5.3 Business Associate reserves the right to terminate Covered Entity's access to M1 immediately and without prior notice upon a reasonable determination that Covered Entity has submitted or attempted to submit false claims through the platform. Such termination is without prejudice to any other remedies available to Business Associate at law or in equity.
5.4 Business Associate may, in its sole discretion, monitor aggregate billing patterns across its platform to identify statistical anomalies consistent with improper billing practices. Business Associate is not obligated to report identified anomalies to payers or regulators except as required by applicable law.
6. TERM AND TERMINATION
6.1 Term. This Agreement is effective as of the date of electronic acceptance and remains in effect until the earlier of: (a) termination of all Services agreements between the parties; or (b) thirty (30) days' written notice of termination by either party. Notwithstanding the foregoing, Business Associate may terminate this Agreement immediately upon written notice if Covered Entity has materially violated Section 5 (Claims Integrity Certification). The obligations of Business Associate under Section 6.3 survive any termination of this Agreement.
6.2 Termination for Cause. Either party may terminate this Agreement upon written notice if the other party has violated a material term of this Agreement and has not cured such violation within thirty (30) days of written notice thereof, if the violation is capable of cure.
6.3 Effect of Termination. Upon termination of this Agreement, Business Associate will, at Covered Entity's written election made within thirty (30) days of termination, return or destroy all PHI in its possession that was received from, or created or received on behalf of, Covered Entity. If return or destruction is not feasible, Business Associate will extend the protections of this Agreement to such PHI and limit further use and disclosure to those purposes that make return or destruction infeasible, for as long as Business Associate retains the PHI. Business Associate will certify in writing to Covered Entity that PHI has been returned, destroyed, or is subject to extended protections, as applicable.
7. MISCELLANEOUS
7.1 Regulatory References. A reference in this Agreement to a section in HIPAA means the section as in effect or as amended from time to time.
7.2 Amendment. The parties agree to take such action as is necessary to amend this Agreement from time to time as necessary for compliance with changes in HIPAA and its implementing regulations. Business Associate will provide at least thirty (30) days' advance notice of any material amendment to this Agreement; Covered Entity's continued use of the Services after the notice period constitutes acceptance of the amended Agreement.
7.3 Survival. The respective rights and obligations of Business Associate under Section 6.3 (Effect of Termination) and Section 7.6 (Governing Law) survive the termination of this Agreement.
7.4 Interpretation. Any ambiguity in this Agreement will be resolved in favor of a meaning that permits compliance with HIPAA.
7.5 No Third-Party Beneficiaries. Nothing in this Agreement confers any rights, remedies, obligations, or liabilities upon any person or entity other than the parties and their respective successors and permitted assigns.
7.6 Governing Law. This Agreement is governed by the laws of the State of Delaware, without regard to its conflict of law provisions, to the extent not preempted by federal law. Any dispute arising out of or relating to this Agreement that cannot be resolved by the parties shall be submitted to binding arbitration in accordance with the rules of the American Arbitration Association, except that either party may seek injunctive or other equitable relief in any court of competent jurisdiction.
7.7 Entire Agreement. This Agreement, together with any Service Agreement or Terms of Service between the parties, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, representations, and understandings of the parties with respect to such subject matter.
ELECTRONIC SIGNATURE AND ACCEPTANCE
By checking the acceptance box during onboarding, the signer: (a) represents that they are duly authorized to bind the Covered Entity (the dental practice identified during account registration) to this Agreement; (b) acknowledges that they have read and understood this Agreement in full; and (c) agrees that this electronic acceptance constitutes a valid and binding signature pursuant to the Electronic Signatures in Global and National Commerce Act (E-SIGN Act, 15 U.S.C. § 7001 et seq.) and applicable state electronic signature laws. The parties agree that electronic records of acceptance — including the signer's name, title, email address, IP address, device information, and timestamp as captured by the M1 platform — constitute sufficient evidence of execution and may be presented as such in any legal proceeding.