Business Associate Agreement

ChiroMike — Chiropractic Practice Management System

Effective Date: April 17, 2026 · Version 1.0

Whereas the "Client" referred herein as "Covered Entity" (the chiropractic practice using ChiroMike) and Michael Jo Tech, the technology provider operating the ChiroMike platform, together with their designees, employees, associates, affiliates, successors, and assigns referred here as "Business Associate", intend to protect the privacy and provide for the security of certain Protected Health Information (PHI) to which Business Associate may have access in order to provide goods or services to or on behalf of Covered Entity. This agreement is effective upon first use of the ChiroMike software and/or services.

WHEREAS, both parties are subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HIPAA Privacy Rule (45 CFR Parts 160 and 164), the HIPAA Security Rule (45 CFR Parts 160, 162 and 164), as amended by Subtitle D of the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act"), and the Office of Civil Rights Omnibus Rule released in January 2013, relating to obligations of each in connection with the privacy and security of individually identifiable health information subject to protection under HIPAA.

WHEREAS, Business Associate may receive PHI from Covered Entity, or may create or obtain PHI from other parties for use on behalf of Covered Entity, which must be handled in accordance with this Agreement and the standards established by the Privacy Rule and the Security Rule.

NOW, THEREFORE, Covered Entity and Business Associate agree as follows:

1. Definitions

A. "Business Associate" shall have the meaning given under the Privacy and Security Rules, including but not limited to 45 CFR §160.103.

B. "Covered Entity" shall have the meaning given under the Privacy and Security Rules, including but not limited to 45 CFR §160.103.

C. "HIPAA" shall mean the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191.

D. "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 CFR Parts 160 and 164, Subparts A and E, as amended by the HITECH Act.

E. "Protected Health Information" or "PHI" means any information transmitted or recorded in any form or medium that relates to the past, present, or future physical or mental condition of an individual; the provision of health care to an individual; or payment for the provision of health care to an individual; and that identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual, as defined under 45 CFR §164.501.

F. "Security Rule" shall mean the Security Standards at 45 CFR Parts 160, 162 and 164.

G. "Breach" shall have the same meaning as the term "breach" in §13400 of the HITECH Act, including the unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of such information.

H. "Unsecured PHI" shall mean PHI that is not secured through a technology or methodology that renders it unusable, unreadable, or indecipherable to unauthorized individuals.

2. Permitted Uses and Disclosures of PHI

A. Business Associate shall be permitted to use and/or disclose PHI provided by or obtained on behalf of Covered Entity for the purpose of operating, supporting, and maintaining the ChiroMike practice management platform, including patient intake, appointment scheduling, claim building, billing support, SOAP note generation, and related clinical and administrative functions.

B. Business Associate shall be permitted to use or disclose PHI to perform functions, activities, or services on behalf of Covered Entity as described herein, provided that such use or disclosure would not violate the Privacy and Security Rule if performed by Covered Entity.

C. Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided disclosures are required by law or Business Associate obtains reasonable written assurances of confidentiality from any third-party recipient.

3. Business Associate Obligations

A. Limits on Use and Disclosure. Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as required by law, in compliance with Subpart C of 45 CFR Part 164.

B. Appropriate Safeguards. Business Associate shall establish and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI created, received, maintained, or transmitted on behalf of Covered Entity.

C. Breach Reporting. Business Associate shall report to Covered Entity within ten (10) days of discovery any use or disclosure of PHI not provided for by this Agreement, and any security incident of which it becomes aware, in compliance with 45 CFR §164.410.

D. Subcontractors and Agents. Business Associate shall ensure that any subcontractors or agents that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions and conditions that apply to Business Associate under this Agreement, in compliance with 45 CFR §164.502(e)(1)(ii) and 164.308(b)(2).

E. Access to PHI. Business Associate shall make PHI available to Covered Entity or to individuals as required by 45 CFR §164.524 within ten (10) business days of receiving a written request.

F. Amendment of PHI. Business Associate shall incorporate amendments to PHI in a designated record set within ten (10) business days of a written request from Covered Entity, in compliance with 45 CFR §164.526.

G. Accounting of Disclosures. Business Associate shall maintain records of PHI disclosures and make such records available to Covered Entity or an individual within thirty (30) days of a request, in compliance with 45 CFR §164.528.

H. Access to Books and Records. Business Associate shall make its internal practices, books, and records relating to the use or disclosure of PHI available to the Secretary of Health and Human Services for compliance determination purposes.

I. Return or Destruction of PHI. Upon termination of this Agreement, Business Associate shall return or destroy all PHI, retaining no copies. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further use or disclosure.

J. Mitigation. Business Associate agrees to mitigate, to the maximum extent practicable, any harmful effect from the use or disclosure of PHI in violation of this Agreement, per 45 CFR §164.530(f).

4. Obligations of Covered Entity

A. Covered Entity shall provide Business Associate with any limitations in its Notice of Privacy Practices per 45 CFR §164.520 that may impact Business Associate's use or disclosure of PHI.

B. Covered Entity shall notify Business Associate of any changes in or revocation of permission by individuals to use or disclose PHI that may affect Business Associate's permitted uses and disclosures.

C. Covered Entity shall implement and maintain appropriate administrative, physical, and technical safeguards to protect PHI it creates, receives, maintains, or transmits, in compliance with HIPAA and the HITECH Act.

5. Term and Termination

A. This Agreement shall become effective upon first use of ChiroMike and remain in effect until terminated as set forth herein.

B. Termination for Cause. Upon material breach by either party, the non-breaching party shall provide an opportunity to cure. If cure is not possible, the non-breaching party may immediately terminate this Agreement, or if neither termination nor cure is feasible, report the violation to the Secretary.

C. Effect of Termination. All rights, duties, and obligations established in this Agreement shall survive termination.

6. Indemnification

Each party shall indemnify, hold harmless, and defend the other party from and against any and all claims, losses, liabilities, costs, and other expenses arising directly or indirectly from: (i) any misrepresentation, breach of warranty, or non-fulfillment of any undertaking under this Agreement; and (ii) any claims, demands, awards, judgments, actions, and proceedings arising out of or in connection with the breaching party's performance or non-performance of its obligations under this Agreement.

7. Other Provisions

A. Construction. This Agreement shall be construed as broadly as necessary to implement and comply with HIPAA and the HITECH regulations. Any ambiguity shall be resolved in favor of a meaning that complies with HIPAA and the HITECH regulations.

B. Amendment. This Agreement may only be amended through a writing signed by both parties. The parties agree to amend this Agreement as necessary to ensure consistency with changes in applicable federal and state laws and regulations, including HIPAA.

C. Governing Law. This Agreement shall be interpreted, construed, and enforced in accordance with applicable federal law and the laws of the state in which Covered Entity's primary practice is located.

D. Binding Effect. This Agreement shall be binding upon and inure to the benefit of the parties and their respective permitted successors and assigns.

E. Priority of Agreement. If any portion of this Agreement is inconsistent with any other agreement between the parties, the terms of this Agreement shall prevail with respect to PHI obligations.

F. Authority to Contract. Each party represents and warrants that it is authorized to enter into this Agreement and to be bound by its terms.

IN WITNESS WHEREOF, the parties have agreed to the terms of this Business Associate Agreement effective upon first use of the ChiroMike platform.

Business Associate

Michael Jo Tech (ChiroMike Platform)

Covered Entity

The subscribing practice (ChiroMike account holder)

For questions about this agreement, contact your administrator or email support regarding your ChiroMike account.