Business Associate Agreement
Version 1.0 · Last updated August 29, 2026
This Business Associate Agreement ("BAA" or "Agreement") is entered into by and between SM Flow Pro Limited Liability Company ("Business Associate" or "SM Flow Pro") and the organization identified below ("Covered Entity" or "Customer"). The parties may individually be referred to as a "Party" and collectively as the "Parties."
1. Purpose
This Agreement establishes the obligations of SM Flow Pro concerning Protected Health Information ("PHI") and Electronic Protected Health Information ("ePHI") that SM Flow Pro may create, receive, maintain, transmit, access, store, process, or otherwise handle on behalf of Covered Entity through the Sports Med Flow Pro platform and related services. This Agreement is intended to satisfy applicable requirements of HIPAA, the HITECH Act, and applicable regulations in 45 C.F.R. Parts 160 and 164.
This Agreement applies only to information constituting PHI under HIPAA. Information excluded from the HIPAA definition of PHI, including education records or treatment records governed by FERPA, does not become PHI solely because it is processed through Sports Med Flow Pro.
2. Definitions
Terms including Breach, Business Associate, Covered Entity, Designated Record Set, Disclosure, Electronic Protected Health Information, Individual, Minimum Necessary, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use have the meanings assigned under HIPAA and its implementing regulations.
PHI means individually identifiable health information protected under HIPAA that is created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity. ePHI means PHI created, received, maintained, processed, stored, or transmitted electronically. Platform means Sports Med Flow Pro software, web applications, portals, modules, integrations, APIs, databases, AI features, and associated services operated or provided by SM Flow Pro.
3. Services provided by Business Associate
Depending on the Customer's subscription and configuration, Sports Med Flow Pro may support student-athlete or patient profiles; injury evaluations and injury reports; AI-assisted and voice-assisted SOAP documentation; treatment and rehabilitation records; rehabilitation protocols; return-to-play documentation; concussion-related documentation when enabled; emergency action plans; athletic training room encounters; Live Training Room functionality; AT Sidekick/Kiosk check-in and check-out; treatment and rehabilitation logs; body-part and injury tracking; Contract Athletic Trainer documentation; routing of injury reports to authorized campus Athletic Trainers; referral and physician coordination; appointment and care coordination; insurance information when specifically enabled and appropriately configured; uploaded documents and forms; electronic signatures; timestamps; documentation history; administrative reporting; and other sports medicine workflow functionality offered by the Platform.
4. Permitted uses and disclosures
Business Associate may Use or Disclose PHI only as necessary to provide the Platform and services to Covered Entity; as permitted by this Agreement or the underlying services agreement; as Required by Law; or as otherwise permitted by HIPAA. Business Associate shall not Use or Disclose PHI in a manner that would violate the HIPAA Privacy Rule if performed by Covered Entity, except where expressly permitted for Business Associate's proper management and administration or as Required by Law.
5. Minimum necessary
Business Associate shall make reasonable efforts to limit Uses, Disclosures, and requests for PHI to the Minimum Necessary information required to accomplish the intended purpose when that HIPAA standard applies. Access shall be limited based on reasonable authorization, role, function, and business need.
6. Safeguards
Business Associate shall implement reasonable and appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of ePHI as required by applicable provisions of the HIPAA Security Rule. Safeguards may include unique authentication, role-based and least-privilege access, password controls, encryption in transit, encryption at rest where appropriate, secure communications, access and audit logging, security monitoring, session controls, backup and recovery measures, incident procedures, workforce controls, administrative restrictions, secure software-development practices, vulnerability management, data-integrity protections, and availability/disaster-recovery measures. Nothing in this Agreement represents that a particular safeguard is implemented unless it is actually deployed in the applicable production environment.
7. Access control and customer responsibilities
Business Associate shall maintain mechanisms reasonably designed to restrict PHI access to authorized users. Covered Entity is responsible for determining authorized workforce members, assigning appropriate roles, maintaining accurate user information, promptly disabling unauthorized users, protecting credentials, ensuring lawful access, and informing Business Associate when permissions must change. Business Associate is not responsible for unauthorized access caused solely by Covered Entity's failure to manage its users or credentials, except to the extent Business Associate independently contributed to the event.
8. Athletic Trainer and campus information routing
Where Covered Entity uses Sports Med Flow Pro to route injury documentation, SOAP notes, treatment records, referrals, or other information among Contract Athletic Trainers, campus Athletic Trainers, administrators, physicians, or other authorized personnel, Business Associate shall process the information according to authorization rules and configuration established for the applicable organization. Business Associate shall not intentionally disclose PHI to another school, campus, organization, trainer, healthcare provider, or third party unless authorized through Covered Entity instructions or configuration, permitted under this Agreement, authorized by the Individual where required, or required or permitted by applicable law.
9. AI-assisted documentation
The Platform may provide AI-assisted functionality for generating or organizing SOAP notes, injury reports, summaries, or related sports medicine documentation. Where PHI is processed through an AI-assisted feature, Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf is appropriately bound to applicable HIPAA obligations when required by law. AI-generated content assists authorized professionals and does not replace professional clinical judgment. The authorized healthcare professional or Athletic Trainer remains responsible for reviewing, correcting, approving, and signing clinical documentation before relying upon or submitting it.
10. Subcontractors and third-party services
Business Associate may use Subcontractors or third-party providers to operate, maintain, host, secure, support, or provide Platform functionality. Where a Subcontractor creates, receives, maintains, or transmits PHI on behalf of Business Associate and qualifies as a Business Associate Subcontractor under HIPAA, Business Associate shall obtain satisfactory assurances and enter into a written Business Associate Agreement or equivalent HIPAA-required agreement. No third-party integration is authorized to receive PHI merely because it is technically integrated with the Platform.
11. Cloud hosting and data storage
If Business Associate uses cloud infrastructure or hosting providers to create, receive, maintain, process, or transmit ePHI, it shall use providers appropriate for the intended HIPAA-regulated environment and obtain a Business Associate Agreement when required. Business Associate shall maintain reasonable procedures concerning data storage, access management, backup, recovery, security monitoring, retention, and secure deletion.
12. Tracking technologies and analytics
Business Associate shall not knowingly permit advertising, analytics, tracking, session-replay, or similar technology vendors to receive PHI from authenticated or PHI-containing portions of the Platform unless the Disclosure is permitted by HIPAA and all required contractual protections are in place. PHI shall not be sold or disclosed for targeted advertising except pursuant to a valid authorization or other lawful HIPAA basis.
13. Impermissible uses, disclosures, and security incidents
Business Associate shall report to Covered Entity any Use or Disclosure of PHI not permitted by this Agreement of which it becomes aware and shall report Security Incidents as required by applicable law. Routine unsuccessful security events such as blocked probes, failed logins, or automated scans that do not result in unauthorized access, Use, Disclosure, modification, destruction, or interference with ePHI may be considered collectively reported through this provision unless otherwise required by law.
14. Breach notification
Following discovery of a Breach of Unsecured PHI involving Covered Entity information, Business Associate shall notify Covered Entity without unreasonable delay and no later than the timeframe required by 45 C.F.R. § 164.410. To the extent reasonably available, notice shall identify affected Individuals; describe what occurred; state the known dates of Breach and discovery; identify categories or types of PHI involved; identify known or suspected recipients; describe mitigation actions; and provide other information reasonably necessary for Covered Entity's Breach Notification obligations. Business Associate shall reasonably cooperate in investigation and response.
15. Security incident response and mitigation
Business Associate shall maintain reasonable procedures for identifying, investigating, mitigating, documenting, and responding to Security Incidents involving systems containing ePHI. It may suspend accounts, revoke credentials or sessions, restrict access, preserve logs, investigate activity, correct vulnerabilities, restore services, and take other reasonable protective actions. Business Associate shall take reasonable steps to mitigate, to the extent practicable, known harmful effects resulting from an impermissible Use or Disclosure by Business Associate.
16. Access, amendment, and accounting
To the extent Business Associate maintains PHI in a Designated Record Set, it shall make such PHI available to Covered Entity as reasonably necessary for Covered Entity to satisfy 45 C.F.R. § 164.524; make PHI available for amendment and incorporate amendments as reasonably directed under 45 C.F.R. § 164.526; and document Disclosures and provide information reasonably necessary for an accounting under 45 C.F.R. § 164.528. Covered Entity remains primarily responsible for responding directly to Individual requests unless otherwise required by law or agreed in writing.
17. Requests from individuals
If Business Associate directly receives an Individual's request concerning access, amendment, restriction, accounting, or another HIPAA privacy right relating to PHI maintained on behalf of Covered Entity, Business Associate may refer the Individual to Covered Entity unless applicable law requires Business Associate to respond directly.
18. Access by the Secretary of HHS
Business Associate shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, created for, or maintained on behalf of Covered Entity available to the Secretary of the U.S. Department of Health and Human Services as required to determine HIPAA compliance.
19. Legal requests
Business Associate may Disclose PHI where Required by Law. To the extent legally permitted, Business Associate shall reasonably notify Covered Entity of governmental, judicial, administrative, or law-enforcement requests seeking Covered Entity PHI when notice is appropriate and lawful, and shall disclose only information legally required or otherwise authorized under HIPAA.
20. Data ownership, sale, and de-identification
As between the Parties, Covered Entity retains its rights in PHI and records submitted to or created through the Platform on its behalf, subject to applicable law and the services agreement. SM Flow Pro retains its software, algorithms, workflows, templates, databases, architecture, interfaces, documentation, and other intellectual property. Business Associate shall not sell PHI in violation of HIPAA or use PHI for unrelated advertising, marketing, data brokerage, or commercial profiling except as expressly permitted and authorized. Business Associate may create or use properly de-identified information where permitted by the services agreement; properly de-identified information is no longer PHI under HIPAA.
21. Covered Entity obligations
Covered Entity shall use Sports Med Flow Pro in accordance with applicable law; provide only information it is legally permitted to provide; maintain appropriate workforce authorization; notify Business Associate of relevant limitations, restrictions, or changes; not instruct Business Associate to violate HIPAA; maintain appropriate policies for Athletic Trainers, administrators, contractors, coaches, medical personnel, and other users; determine whether parental, student, patient, or other authorization is required before sharing information; and comply with FERPA and other education-record requirements when applicable.
22. FERPA and education records
The Parties acknowledge that student-athlete health and medical information maintained by or on behalf of educational institutions may constitute education records or treatment records governed by FERPA rather than PHI governed by HIPAA. Nothing in this BAA is intended to improperly classify FERPA education records as HIPAA PHI. When SM Flow Pro acts as a service provider or contractor for an educational agency and receives FERPA-regulated education records, the Parties shall comply with applicable FERPA requirements and any separate Data Privacy Agreement or Student Data Privacy Agreement. Where information is governed by FERPA rather than HIPAA, the FERPA-related agreement and applicable law shall govern; where information constitutes PHI, this BAA applies.
23. Texas and other applicable law
To the extent applicable, the Parties shall comply with Texas privacy, health-information, breach-notification, education-record, and data-security requirements. Nothing in this Agreement limits an obligation imposed by applicable federal or state law that provides greater protection.
24. Term and termination
This Agreement becomes effective on the Effective Date and remains in effect while Business Associate creates, receives, maintains, or transmits PHI on behalf of Covered Entity. Covered Entity may terminate this Agreement and applicable services if Business Associate materially violates this Agreement and fails to cure the violation within a reasonable period after written notice where cure is possible. Business Associate may take reasonable action, including suspension or termination of affected services, if Covered Entity's actions create a material HIPAA violation, breach of this Agreement, or substantial threat to PHI confidentiality, integrity, or availability.
25. Return or destruction of PHI
Upon termination, Business Associate shall, where feasible and as required by HIPAA, return or destroy PHI received from Covered Entity or created, received, or maintained on its behalf and retain no copies except where retention is required by law or return/destruction is infeasible. Where retention is required or destruction infeasible, Business Associate shall continue to protect retained PHI and limit further Uses and Disclosures. PHI in backups may remain until overwritten or securely destroyed under normal retention procedures, provided it remains protected and is not restored for an unauthorized purpose.
26. Data export and transition
Subject to the services agreement and Platform capabilities, Business Associate shall provide Covered Entity a reasonable opportunity to retrieve or export Covered Entity information upon termination and shall not intentionally withhold PHI in a manner preventing Covered Entity from satisfying HIPAA obligations.
27. Survival, regulatory changes, and interpretation
Obligations concerning retained PHI survive termination for as long as Business Associate maintains the PHI. The Parties agree to amend this Agreement as reasonably necessary to maintain compliance with changes to HIPAA, HITECH, federal regulations, or other applicable laws. Any ambiguity shall be interpreted in a manner permitting compliance with applicable law. Regulatory references include subsequent amendments and successor provisions.
28. Relationship to other agreements
This BAA supplements any Terms of Service, Master Services Agreement, Subscription Agreement, School District Agreement, Data Privacy Agreement, or other written agreement between the Parties. If another agreement conflicts with this BAA regarding the Use, Disclosure, safeguarding, or handling of PHI, this BAA controls with respect to PHI unless applicable law requires otherwise.
29. No third-party beneficiaries
Except where applicable law expressly provides otherwise, this Agreement is intended solely for the benefit of the Parties and does not create contractual rights for any third party.
30. Notices
Business Associate: SM Flow Pro Limited Liability Company, Attn: Privacy/Security Official, saarlacantera@gmail.com.
Covered Entity: the organization, representative, address, email, and phone recorded on the executed signature page below.
31. Entire BAA
This Agreement constitutes the Parties' agreement concerning Business Associate's HIPAA obligations relating to PHI processed on behalf of Covered Entity and supersedes prior inconsistent BAA provisions concerning the same subject matter. Electronic signatures and counterparts may be accepted to the extent permitted by applicable law.
This document is a business/legal working template and should be reviewed by qualified healthcare or privacy counsel before production use.
