보호되는 건강 정보가 처리, 보호 및 보고되는 방식을 규정하는 Relvema와 대상 기관 간의 HIPAA 필수 계약입니다.
BAA 읽기
Effective June 10, 2026
This Business Associate Agreement (“BAA” or “Agreement”) is entered into between Relvema (“Business Associate”) and the licensed therapist, counselor, psychologist, or covered entity (“Covered Entity”) who accepts this Agreement by creating a Relvema account. This BAA satisfies the requirements of 45 C.F.R. § 164.504(e) of the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended (“HIPAA”).
By creating an account and using the Relvema platform, the Covered Entity agrees to the terms of this Agreement. This Agreement supersedes any prior oral or written representations regarding HIPAA compliance between the parties.
Capitalized terms used in this Agreement have the meanings set forth in HIPAA (45 C.F.R. Parts 160 and 164), including:
Relvema may use or disclose PHI only as follows:
Relvema will not use or disclose PHI in any manner that would violate the Privacy Rule if done by the Covered Entity, except as permitted under this Agreement. Relvema will not sell PHI, use PHI for advertising or marketing, or use PHI to train any artificial intelligence or machine-learning model — including Relvema’s own AI systems.
Relvema will implement and maintain appropriate administrative, technical, and physical safeguards to protect the confidentiality, integrity, and availability of PHI, in accordance with 45 C.F.R. §§ 164.308, 164.310, and 164.312.
Technical safeguards include:
Administrative safeguards include:
Physical safeguards include:
Relvema will report to the Covered Entity any use or disclosure of PHI not provided for by this Agreement that Relvema becomes aware of, including Breaches of Unsecured PHI as required by 45 C.F.R. § 164.410.
Relvema will provide notice of any confirmed Breach of Unsecured PHI without unreasonable delay and in no case later than 60 days after discovery. The notice will include, to the extent possible: the identity of affected individuals, a description of the Breach, the types of PHI involved, steps individuals should take to protect themselves, a description of Relvema’s investigation and mitigation steps, and contact information for follow-up questions.
To report a potential security incident, contact security@relvema.com immediately. For general compliance inquiries, contact compliance@relvema.com.
Relvema will ensure that any Sub-Business Associate that creates, receives, maintains, or transmits PHI on Relvema’s behalf agrees to the same restrictions and conditions regarding PHI that apply to Relvema under this Agreement, in accordance with 45 C.F.R. § 164.504(e)(2)(ii)(D).
Relvema’s current Sub-Business Associates are:
Stripe, Inc. processes subscription payments on behalf of Relvema but does not access, store, or process any PHI. Stripe is not a Sub-Business Associate under HIPAA.
Relvema will update this section as Sub-Business Associates are added or removed. Material changes that reduce the protection of PHI will be communicated to Covered Entities with reasonable advance notice.
To the extent Relvema holds PHI in a Designated Record Set, Relvema will make such PHI available to the Covered Entity within 30 days of a written request, to enable the Covered Entity to fulfill its obligations under 45 C.F.R. §§ 164.524 (individual access) and 164.526 (amendment).
Therapists may access all session data, transcripts, notes, and patient records through the Relvema portal at any time during their subscription. Data export or deletion requests should be submitted to support@relvema.com.
Relvema will make its internal practices, books, and records related to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services (HHS) for purposes of determining compliance with HIPAA, as required by 45 C.F.R. § 164.504(e)(2)(ii)(H).
This Agreement is effective upon the Covered Entity’s acceptance (by creating a Relvema account) and remains in effect for as long as the Covered Entity maintains an active Relvema subscription or Relvema holds PHI on the Covered Entity’s behalf.
Either party may terminate this Agreement immediately upon written notice if the other party has materially breached a provision of this Agreement and has not cured the breach within 30 days of written notice of the breach.
Upon termination for any reason, Relvema will, at the Covered Entity’s election, return or destroy all PHI received from, or created or received on behalf of, the Covered Entity. If return or destruction is not feasible, Relvema will extend the protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible. PHI deletion will be completed within 60 days of account termination unless an applicable law requires a longer retention period.
Relvema may amend this Agreement at any time to comply with changes in HIPAA regulations or guidance issued by HHS. Relvema will provide at least 30 days’ advance notice of material changes by posting the updated Agreement at relvema.com/legal/baa and, where practicable, by email to the address associated with the Covered Entity’s account. Continued use of the Services after the effective date of any amendment constitutes acceptance of the amended Agreement.
This Agreement is governed by the laws of the State of Florida, without regard to its conflict-of-law provisions. Any disputes arising under this Agreement will be resolved in the state or federal courts located in Miami-Dade County, Florida.
For questions about this Agreement, contact compliance@relvema.com.