Civaren / Recover
Return to app
Electronic agreement. This is the posted version presented for acceptance in Recover by Civaren. Please review it before accepting or starting a paid subscription.
Version 2026-08-10-v2-civaren · Effective 2026-08-10 · SHA-256 b6e4c8101d5e348d18638c1e404ed7130335bd0d33c0e833d9cc614ad5e7c03b

Recover by Civaren Business Associate Agreement

Version: 2026-08-10-v1

Effective date: August 10, 2026

This Business Associate Agreement ("BAA") is incorporated into the Recover by Civaren Customer Agreement between Civaren, meaning the person or legal entity offering the Recover by Civaren service and identified as the merchant or service provider on the applicable checkout page, invoice, receipt, or order record ("Business Associate"), and the person or legal entity identified by the subscribing user during acceptance or in the applicable order record ("Covered Entity" or "Customer").

Every paying Customer affirmatively accepts this BAA as part of the subscription workflow. The HIPAA-specific provisions of this BAA are operative to the extent Customer is a Covered Entity or Business Associate under HIPAA and Civaren creates, receives, maintains, or transmits Protected Health Information on Customer's behalf in a capacity regulated by HIPAA. If Customer is itself a Business Associate, references to "Covered Entity" will be interpreted as references to Customer as appropriate, and Civaren will be treated as a subcontractor Business Associate to the extent required by HIPAA.

1. Definitions

Terms including Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Minimum Necessary, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use have the meanings assigned under the HIPAA Rules.

HIPAA Rules means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, as amended.

PHI means Protected Health Information received from or created, maintained, or received by Civaren on behalf of Customer, including electronic PHI where applicable. PHI excludes information that has been de-identified in accordance with 45 C.F.R. § 164.514(a)-(c).

2. Permitted uses and disclosures by Business Associate

Civaren may Use or Disclose PHI only:

Civaren will not Use or Disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Customer, except for uses and disclosures expressly permitted for a Business Associate under the HIPAA Rules and this BAA.

Civaren will make Uses, Disclosures, and requests for PHI consistent with the Minimum Necessary requirements applicable to the activity, to the extent required by the HIPAA Rules.

Civaren will not sell PHI or use PHI for targeted advertising or unrelated marketing except as expressly authorized in writing by Customer and permitted by applicable law.

3. Safeguards and Security Rule compliance

Civaren will use appropriate safeguards to prevent Use or Disclosure of PHI other than as provided by this BAA.

With respect to electronic PHI, Civaren will comply with the applicable requirements of Subpart C of 45 C.F.R. Part 164, including reasonable and appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic PHI.

Civaren will maintain security measures appropriate to the services it provides, including access controls, encryption where appropriate, logging, vulnerability management, incident-response procedures, and workforce access restrictions.

4. Reporting of impermissible uses, disclosures, breaches, and security incidents

Civaren will report to Customer any Use or Disclosure of PHI not permitted by this BAA of which Civaren becomes aware, including any Breach of Unsecured PHI as required by 45 C.F.R. § 164.410, and any Security Incident of which Civaren becomes aware.

Civaren will provide required Breach notifications without unreasonable delay and in no event later than the maximum period permitted by applicable law. As an interim contractual target, Civaren will endeavor to provide notice of a confirmed reportable Breach to Customer within ten (10) business days after determining that a reportable Breach has occurred, unless law-enforcement delay or other lawfully permitted circumstances apply.

The parties acknowledge that unsuccessful security events such as routine pings, port scans, unsuccessful login attempts, and similar events may occur continuously. To the extent permitted by HIPAA, this Section constitutes notice that such unsuccessful events may occur, and no separate report is required unless they result in unauthorized access, Use, Disclosure, modification, destruction, or material interference with system operations.

5. Breach information and cooperation

To the extent available, Civaren's Breach report will include information reasonably necessary for Customer to meet its obligations under the HIPAA Breach Notification Rule, including the identity of affected Individuals, the nature of PHI involved, known or reasonably suspected circumstances, mitigation steps taken, and corrective actions.

Civaren will reasonably cooperate with Customer's investigation and legally required notification process. Allocation of direct notification costs, forensic costs, or other expenses will be governed by the Customer Agreement, applicable law, and the facts of the incident.

6. Subcontractors

Civaren will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on Civaren's behalf agrees in writing to substantially the same restrictions, conditions, and requirements that apply to Civaren with respect to such PHI, as required by the HIPAA Rules.

Civaren remains responsible for managing its Subcontractors as required by applicable law and the parties' agreements.

7. Access to PHI

To the extent Civaren maintains PHI in a Designated Record Set on Customer's behalf, Civaren will make such PHI available to Customer as reasonably necessary for Customer to satisfy its obligations under 45 C.F.R. § 164.524.

Unless otherwise agreed, Civaren will provide responsive information to Customer rather than directly to an Individual. Customer remains responsible for evaluating and responding to the Individual's request.

8. Amendment of PHI

To the extent Civaren maintains PHI in a Designated Record Set, Civaren will make PHI available for amendment and incorporate amendments as reasonably directed by Customer to enable Customer to satisfy 45 C.F.R. § 164.526.

9. Accounting of disclosures

Civaren will maintain and make available information regarding Disclosures of PHI as reasonably necessary for Customer to satisfy its obligations under 45 C.F.R. § 164.528, to the extent such accounting is required by the HIPAA Rules.

10. Customer obligations carried out by Civaren

To the extent Civaren agrees to carry out an obligation of Customer under Subpart E of 45 C.F.R. Part 164, Civaren will comply with the requirements of Subpart E that apply to Customer in the performance of that obligation.

11. Access by the Secretary

Civaren will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Customer's or Civaren's compliance with the HIPAA Rules, as required by law.

12. Customer responsibilities

Customer will not request Civaren to Use or Disclose PHI in a manner that would be impermissible under the HIPAA Rules if done by Customer, except where the HIPAA Rules permit a Business Associate to make the requested Use or Disclosure.

Customer will notify Civaren of:

Customer is responsible for determining that it has lawful authority to disclose PHI to Civaren and for configuring the Service consistently with its legal obligations and Minimum Necessary policies.

13. Designated PHI channels

Customer will transmit PHI to Civaren only through Service features expressly designated by Civaren as PHI-enabled. Customer will not send PHI through billing fields, general support channels, account-profile fields, or AI features that Civaren has not designated for PHI.

Civaren may block PHI intake until required technical and contractual controls are enabled.

14. De-identification

Customer expressly authorizes Civaren to de-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c) where de-identification is part of the Service. Civaren may retain and use information after it has been de-identified in accordance with those standards as permitted by the Customer Agreement and applicable law, and Civaren will not attempt to re-identify it except as permitted by law and agreed in writing.

Automated sanitization or detection performed by the Service may be used as a technical step in a de-identification workflow but does not by itself constitute a legal determination that information satisfies a particular de-identification method unless Civaren expressly states otherwise in writing.

15. Term and termination

This BAA is accepted when Customer accepts it electronically. Its HIPAA-specific duties become applicable on the first date Civaren creates, receives, maintains, or transmits PHI on Customer's behalf in a relationship subject to HIPAA and continue for so long as Civaren maintains such PHI.

Customer may terminate the Customer Agreement and this BAA for cause if Customer determines that Civaren has violated a material term of this BAA and Civaren does not cure the violation within a reasonable period specified by Customer, where cure is possible. Customer may terminate immediately where cure is not possible or where immediate termination is required by law.

Civaren may terminate or suspend PHI processing if Customer materially violates this BAA, requests an impermissible Use or Disclosure, or if continued processing would violate law.

16. Return or destruction of PHI upon termination

Upon termination of the services involving PHI, Civaren will, if feasible, return or destroy PHI received from Customer or created, maintained, or received on Customer's behalf and will retain no copies except as permitted below.

If return or destruction is infeasible or Civaren must retain PHI for legal responsibilities, Civaren will extend the protections of this BAA to the retained PHI, limit further Uses and Disclosures to the purposes that make return or destruction infeasible or legally necessary, and return or destroy the PHI when no longer needed for those purposes.

This Section survives termination.

17. Mitigation

Civaren will mitigate, to the extent practicable, harmful effects of any Use or Disclosure of PHI by Civaren in violation of this BAA that becomes known to Civaren, as required by the HIPAA Rules.

18. Regulatory references and amendment

A reference in this BAA to a HIPAA provision means that provision as in effect or as amended. The parties will take such action as reasonably necessary to amend this BAA to comply with changes in applicable law.

Any ambiguity in this BAA will be interpreted to permit compliance with the HIPAA Rules.

19. Relationship to Customer Agreement

Except as expressly modified by this BAA, the Customer Agreement remains in effect. If a provision of the Customer Agreement conflicts with this BAA concerning PHI, this BAA controls.

Commercial terms, warranty provisions, indemnification provisions, and limitations of liability in the Customer Agreement apply to this BAA to the extent enforceable and not inconsistent with mandatory law or an express provision of this BAA.

20. No third-party beneficiaries

This BAA is intended solely for the benefit of the parties and does not create rights in any third party except as required by law.

21. Electronic acceptance and identification of parties

Customer agrees that electronic acceptance of this BAA is intended to constitute a written agreement and electronic signature. Customer represents that the accepting user is authorized to bind the legal entity identified during acceptance.

Civaren may retain acceptance evidence including the accepting user's identity, organization legal name, timestamp, source IP address, user agent, BAA version, cryptographic hash, Customer Agreement version, Stripe checkout or subscription identifiers, and related audit metadata.