Business Associate Agreement
Version 1.0 — Effective September 2026
This is the current version of Cord's HIPAA Business Associate Agreement. It is incorporated by reference into your Order Form or platform agreement with Cord — accepting that agreement is acceptance of the version published here as of your acceptance date. You do not sign this page separately. See Updates and Version Control below for how changes are made and notified.
Parties and Recitals
This Business Associate Agreement ("Agreement") is between Cord Labs LLC, a Delaware limited liability company with its principal place of business at 301 Chestnut Street, San Carlos, California 94070 ("Business Associate" or "Cord"), and the healthcare provider, wellness practice, or other business entity that has accepted Cord's Order Form, platform agreement, or Terms of Service ("Covered Entity"). Covered Entity and Business Associate are each a "Party" and together the "Parties."
The Parties enter into this Agreement to establish contractual protections for Protected Health Information consistent with the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (collectively, "HIPAA").
The Parties enter into this Agreement without determining or conceding whether Covered Entity is a "covered entity" or "business associate" as those terms are defined under HIPAA, and without either Party representing that it holds any such status; this Agreement applies to the extent HIPAA applies and otherwise operates as the Parties' agreed contractual standard for the handling of Protected Health Information.
Cord operates Cord Health, a payment processing and FSA/HSA documentation platform for wellness and allied health providers. In connection with the services Cord provides under Covered Entity's Order Form or platform agreement (the "Service Agreement"), Cord may create, receive, maintain, or transmit Protected Health Information on Covered Entity's behalf. HIPAA requires Covered Entity to enter into a business associate agreement with Cord before permitting that.
1. Definitions
Capitalized terms used but not otherwise defined in this Agreement have the meanings given under HIPAA, including 45 C.F.R. Parts 160 and 164. Key terms:
- Breach — the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises its security or privacy, as defined at 45 C.F.R. § 164.402.
- Protected Health Information (PHI) — has the meaning at 45 C.F.R. § 160.103, limited to PHI Cord creates, receives, maintains, or transmits on Covered Entity's behalf.
- Security Incident — has the meaning at 45 C.F.R. § 164.304.
- Subcontractor — a person or entity that creates, receives, maintains, or transmits PHI on Cord's behalf in connection with the Permitted Purpose (defined in Section 3 below).
- Unsecured PHI — has the meaning at 45 C.F.R. § 164.402.
2. Scope and Relationship to the Service Agreement
This Agreement governs the creation, receipt, maintenance, and transmission of PHI by Cord in connection with: payment processing for health care services; generation of payment receipts and explanation-of-benefits documentation; FSA/HSA eligibility documentation including Practitioner Recommendation Letters; and related health care operations support (the "Services").
This Agreement is incorporated into and made a part of the Service Agreement. If this Agreement and the Service Agreement conflict with respect to PHI, this Agreement controls.
3. Permitted Uses and Disclosures
Cord may use PHI only to:
- Perform the Services — process patient payments; generate itemized receipts, payment confirmations, and explanation-of-benefits statements; create FSA/HSA documentation including Letters of Medical Necessity; and provide checkout interfaces that capture or display PHI necessary to complete a transaction (the "Permitted Purpose")
- Manage and administer Cord's own operations, where necessary to carry out a legal responsibility of Cord
- Provide data aggregation services relating to Covered Entity's health care operations, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B)
- Comply with a legal requirement
Cord may disclose PHI only to:
- Covered Entity and its authorized workforce, in connection with the Services
- Subcontractors that have executed a business associate agreement with Cord providing protections at least as protective as this Agreement (Section 6)
- The individual who is the subject of the PHI, if directed by Covered Entity or required to fulfill the Permitted Purpose
- The Secretary of HHS for compliance investigations or enforcement, or as otherwise required by law
Cord makes reasonable efforts to use, disclose, and request only the minimum PHI necessary for the Permitted Purpose, consistent with 45 C.F.R. § 164.514(d).
De-identified data. Cord may create, maintain, use, and disclose data de-identified in accordance with 45 C.F.R. § 164.514(a)–(b) (Safe Harbor or Expert Determination). Properly de-identified data is not PHI and is not subject to this Agreement's use/disclosure restrictions. Cord may use such data for platform analytics and product development, publishing aggregate non-identifiable industry insights, and training machine learning models — provided no individual can be re-identified from any model input or output. Cord will not use de-identified data in any manner designed or likely to re-identify individuals, and bears the burden of demonstrating compliance with 45 C.F.R. § 164.514(b) if challenged.
4. Prohibited Uses and Disclosures
Cord will not use or disclose PHI in a way that would violate the HIPAA Rules if done by Covered Entity, and specifically will not:
- Marketing — use or disclose PHI for marketing, targeted advertising, behavioral advertising, or cross-platform tracking based on PHI.
- Sale of PHI — sell PHI or exchange it for remuneration.
- Secondary use — use PHI for any purpose beyond the Permitted Purpose, including training machine learning models on identifiable PHI, or product development unrelated to the Services. (This does not restrict properly de-identified data, per Section 3 above.)
- Payment processors — transmit diagnosis codes, condition identifiers, clinical notes, reason-for-visit information, or any other PHI to Stripe, Inc. or any other payment processor, in any field including payment metadata, charge descriptions, customer records, invoice line items, or webhook payloads. Stripe does not execute HIPAA business associate agreements. Payment processors receive only non-PHI transaction data — amount, currency, anonymized transaction identifiers.
- Research — disclose PHI for research without Covered Entity's prior written authorization and, where required, patient authorization or an applicable HIPAA waiver.
5. Cord's Safeguards
Cord complies with the applicable HIPAA Rules to the same extent as Covered Entity, including HITECH provisions that apply directly to business associates, and maintains administrative, physical, and technical safeguards required by the Security Rule (45 C.F.R. § 164.306), including at minimum:
- Encryption at rest. All electronic PHI is encrypted at rest using AES-256 or a NIST-approved equivalent, via Cord's managed database provider's HIPAA-plan infrastructure. Encryption keys are managed by that provider and are not accessible to Cord's application code.
- Encryption in transit. All electronic PHI transmitted by Cord, including to any Subcontractor, uses TLS 1.2 or higher. TLS 1.0 and 1.1 are prohibited.
- Access controls. Role-based access limits PHI access to authorized personnel whose job responsibilities require it, reviewed no less than quarterly.
- Audit logging. Access to electronic PHI is logged for a minimum of six years.
- Vulnerability management. Penetration testing at least annually, with critical/high findings remediated within 30 days.
- Workforce training. Annual HIPAA training for all workforce members who handle PHI.
Cord reports to Covered Entity any use or disclosure of PHI not permitted by this Agreement, including any Breach of Unsecured PHI or Security Incident, per Section 7 below.
6. Subcontractors
Before disclosing PHI to any Subcontractor, Cord obtains a written business associate agreement from that Subcontractor providing protections no less protective than this Agreement. Cord maintains a current list of its approved Subcontractors — identifying each one, the function it performs, and its BAA status — and provides that list to Covered Entity on written request, including before this Agreement is accepted if requested. Cord notifies Covered Entity of a new Subcontractor with PHI access in advance, per the notice period stated in your Order Form, and Covered Entity may object and the Parties will negotiate in good faith. Cord remains fully liable for its Subcontractors' acts and omissions to the same extent as if Cord had acted directly.
Stripe is explicitly excluded. Stripe, Inc. and its affiliates are not Cord's Subcontractors for PHI purposes — no PHI is ever transmitted to Stripe. Stripe processes only non-PHI payment card data under PCI-DSS. This exclusion is enforced in Cord's application code, not by policy alone. Cord also uses other third-party payment-processing and product-catalog services that do not execute business associate agreements; the same rule applies — no diagnosis, clinical detail, or treatment information appears in any field sent to them, including metadata, description fields, order notes, or webhook payloads.
7. Breach Notification
Cord notifies Covered Entity of a Breach of Unsecured PHI without unreasonable delay and in no event later than seventy-two (72) hours after discovering it — deliberately stricter than the 60-day period HIPAA itself sets at 45 C.F.R. § 164.410(b). To the extent known at the time, notification includes what happened and when discovered, the types of PHI involved, the number of individuals affected (or an estimate), steps individuals should take to protect themselves, what Cord is doing to investigate and mitigate, and a contact for Cord's privacy/security team — supplemented as more information becomes available. If law enforcement states that notification would impede an investigation, Cord may delay to the extent and duration requested, notifying Covered Entity as soon as that delay ends. Cord cooperates with Covered Entity's own notification obligations to affected individuals, HHS, and, where applicable, the media.
8. Individual Rights
Cord supports Covered Entity in fulfilling patients' HIPAA rights — access, amendment, and an accounting of disclosures — within the timeframe stated in your Order Form, and makes its internal PHI practices, books, and records available to HHS on request (notifying Covered Entity of any such request). If a patient submits a rights request directly to Cord, Cord forwards it to Covered Entity promptly and does not respond directly without Covered Entity's prior written authorization, unless required by law.
9. Covered Entity's Obligations
Covered Entity notifies Cord of any limitation in its own Notice of Privacy Practices, or any restriction it has agreed to honor under 45 C.F.R. § 164.522, that affects Cord's use or disclosure of PHI. Covered Entity obtains all necessary authorizations and consents from patients, and does not instruct Cord to use or disclose PHI in a way that would violate the HIPAA Rules.
10. Term and Termination
This Agreement is effective as of the date Covered Entity accepts the Service Agreement and remains in effect until the Service Agreement expires or terminates. Either Party may terminate this Agreement and the Service Agreement immediately on written notice if the other Party materially breaches this Agreement and fails to cure within the period stated in your Order Form (or, if not reasonably curable in that period, fails to diligently pursue cure). If HHS determines Cord has violated the HIPAA Rules, HHS may require Covered Entity to terminate this Agreement. Sections 11 (Return or Destruction of PHI) and 12 (Indemnification) survive termination for any reason.
11. Return or Destruction of PHI
On termination or expiration, Cord will, within thirty (30) calendar days, either return all PHI in its possession or control (including copies held by Subcontractors) in a mutually agreed electronic format, or destroy it in a manner consistent with NIST Special Publication 800-88 so it cannot be reconstructed, and certify that destruction in writing. If return or destruction is infeasible — for example, PHI embedded in backup systems that cannot be selectively purged without disproportionate burden — Cord will notify Covered Entity of the reason, extend this Agreement's protections to that PHI for as long as it's retained, and destroy it at the earliest feasible opportunity. Cord requires the same of its Subcontractors and certifies their compliance to Covered Entity.
12. Indemnification
Cord indemnifies, defends, and holds harmless Covered Entity and its members, managers, officers, employees, agents, successors, and assigns from losses, liabilities, damages, fines, penalties, claims, and reasonable attorneys' fees arising from: Cord's or a Subcontractor's unauthorized use or disclosure of PHI in violation of this Agreement or the HIPAA Rules; a Breach attributable to Cord or a Subcontractor; Cord's or a Subcontractor's failure to implement the safeguards required by Section 5; a violation of the prohibited uses in Section 4; or Cord's or a Subcontractor's material breach of this Agreement — except to the extent such losses stem from Covered Entity's own negligence, willful misconduct, or breach. Covered Entity indemnifies Cord on the mirror-image basis for its own breach, negligence, or willful misconduct in connection with PHI.
Neither Party is liable to the other for indirect, incidental, consequential, special, exemplary, or punitive damages — except this limitation does not apply to damages from gross negligence or willful misconduct; indemnification for third-party claims under this Section; fines or penalties assessed by a government authority; or breach-response costs (forensic investigation, credit monitoring, notification) from a Breach attributable to Cord.
Cap on ordinary PHI-related claims. For claims not falling within any of the four carve-outs just listed ("Ordinary Claims"), Cord's total aggregate liability under this Agreement is capped at the greater of: two times (2×) the total fees paid to Cord by Covered Entity's organization in the twelve months immediately preceding the claim, or fifty thousand dollars ($50,000). Claims within any of those four carve-outs are excluded from this cap and remain uncapped.
13. Updates and Version Control
Cord maintains the current version of this Agreement at this page (cord.health/legal/baa), incorporated by reference into your Order Form. Accepting your Order Form is acceptance of the version published here as of that date. Cord maintains a version history below documenting each version, its effective date, and a summary of material changes; prior versions are retained for a minimum of six years.
Cord may update this Agreement at any time to correct typos, update Subcontractor information, or make clarifying edits that don't reduce Covered Entity's protections or increase its obligations — those take effect on posting. For any update that materially reduces Covered Entity's protections, removes a HIPAA-required provision, or materially increases its obligations — including changes to permitted uses/disclosures of PHI, breach notification timelines, Subcontractors with PHI access, or indemnification — Cord gives Covered Entity's designated privacy contact at least thirty (30) days' written notice before the change takes effect. Covered Entity may terminate its Service Agreement within thirty (30) days of that notice if it objects, with termination effective no later than the change's effective date; otherwise, continued use of the Services after that date is acceptance of the update. Cord will not unilaterally remove or weaken a HIPAA-required provision — any such removal requires a written amendment signed by both parties. If the HIPAA Rules themselves change in a way that affects this Agreement, Cord updates it within sixty (60) days of the regulatory change's effective date, with the same material-change notice if applicable.
| Version | Effective | Changes |
|---|---|---|
| 1.0 | September 2026 | Initial published version. |
14. General Provisions
This Agreement is governed by Delaware law, except to the extent the HIPAA Rules or other federal law preempts it; disputes are resolved per your Order Form's governing-law and dispute-resolution terms. Any ambiguity is resolved to permit compliance with the HIPAA Rules, construed broadly to protect PHI's privacy and security. This Agreement is not intended to create rights for anyone other than the Parties, except that patients whose PHI is subject to it are intended third-party beneficiaries of the indemnification protections in Section 12, to the extent required by law. Together with your Order Form and its exhibits, this Agreement is the entire agreement between the parties on PHI handling, superseding prior understandings on that subject. If any provision is invalid or unenforceable, it is modified to the minimum extent necessary to make it enforceable, with the rest remaining in force.
Approved Subcontractors. Cord provides its current Subcontractor list — each one's function and BAA status — on written request to privacy@cord.health. The list is Cord's confidential information, provided subject to the confidentiality terms in your Order Form.
Breach Notification Contact
Privacy / Security Officer, Cord Labs LLC — email privacy@cord.health.
This Agreement is governed by the laws of the State of Delaware.