Business Associate Agreement | Savvy Agents           [ Savvy Agents ![Savvy Agents](https://savvyagents.ai/images/savvy-agents-logo.png) ](https://savvyagents.ai "Savvy Agents Home")

  - AI Workforce      [

    Ira - AI Receptionist

    24/7 phone answering &amp; scheduling

     ](https://savvyagents.ai/ai-receptionist-for-dental-practices) [

    Sia - AI Scribe

    Clinical documentation assistant

     ](https://savvyagents.ai/ai-scribe-for-dental-practices) [

    Milo - AI Insurance Coordinator

    Insurance verification &amp; billing

     ](https://savvyagents.ai/ai-insurance-coordinator-for-dental-practices) [

    Novi - AI Retention Manager

    Patient reactivation &amp; recalls

     ](https://savvyagents.ai/ai-retention-manager-for-dental-practices)
 - Products      [

    Agent Hub

    Build, run &amp; monitor dental workflows

     ](https://savvyagents.ai/agent-hub-for-dental-practices) [

    Online Scheduling

    24/7 patient self-booking

     ](https://savvyagents.ai/online-scheduling-for-dental-practices) [

    Website Chat Widget

    AI-powered website chat

     ](https://savvyagents.ai/website-chat-widget-for-dental-practices) [

    AI Chat

    Staff assistant for practice work

     ](https://savvyagents.ai/ai-chat-for-dental-practices) [

    Appointment Confirmation

    Confirm visits by text and voice

     ](https://savvyagents.ai/agent-hub-for-dental-practices/appointment-confirmation) [

    Morning Brief

    Daily practice huddle dashboard

     ](https://savvyagents.ai/morning-brief-for-dental-practices) [

    Multilingual AI

    Seamless multi-language phone calls

     ](https://savvyagents.ai/multilingual-ai-phone-agent-for-dental-practices) [

    Unified Inbox

    All patient conversations in one place

     ](https://savvyagents.ai/unified-inbox-for-dental-practices) [

    Desk Phones

    Ring staff first, then Ira as backup

     ](https://savvyagents.ai/desk-phones-for-dental-practices) [

    Patient Forms

    Digital intake, consent &amp; signatures

     ](https://savvyagents.ai/patient-forms-for-dental-practices) [

    Open Dental Integration

    AI workforce for Open Dental practices

     ](https://savvyagents.ai/integrations/open-dental) [

    Dentrix Integration

    AI workforce for Dentrix practices

     ](https://savvyagents.ai/integrations/dentrix)
  - [Customer Stories](/#impact)
- [DSO](https://savvyagents.ai/ai-phone-answering-service-for-dsos)
  - Resources
    - [

        Dental Conferences

        Meet us at dental trade shows

         ](https://savvyagents.ai/dental-conferences)
    - [

        Blog

        Learn how to maximize your business

         ](https://savvyagents.ai/blogs)
    - [

        Partner Program

        Refer dental practices and earn 20%

         ](https://savvyagents.ai/resources/partner-program)
    - [

        Login

        Access your account dashboard

         ](https://savvyagents.ai/login)

     [ See all blog posts → ](https://savvyagents.ai/blog)

   [ Book a demo    ](https://savvyagents.ai/meeting-with-ai-dental-agent)

   Toggle main menu

    AI Workforce

  [ Ira - AI Receptionist ](https://savvyagents.ai/ai-receptionist-for-dental-practices) [ Sia - AI Scribe ](https://savvyagents.ai/ai-scribe-for-dental-practices) [ Milo - AI Insurance Coordinator ](https://savvyagents.ai/ai-insurance-coordinator-for-dental-practices) [ Novi - AI Retention Manager ](https://savvyagents.ai/ai-retention-manager-for-dental-practices)

  Products

  [ Agent Hub ](https://savvyagents.ai/agent-hub-for-dental-practices) [ Online Scheduling ](https://savvyagents.ai/online-scheduling-for-dental-practices) [ Website Chat Widget ](https://savvyagents.ai/website-chat-widget-for-dental-practices) [ AI Chat ](https://savvyagents.ai/ai-chat-for-dental-practices) [ Appointment Confirmation ](https://savvyagents.ai/agent-hub-for-dental-practices/appointment-confirmation) [ Morning Brief ](https://savvyagents.ai/morning-brief-for-dental-practices) [ Multilingual AI ](https://savvyagents.ai/multilingual-ai-phone-agent-for-dental-practices) [ Unified Inbox ](https://savvyagents.ai/unified-inbox-for-dental-practices) [ Desk Phones ](https://savvyagents.ai/desk-phones-for-dental-practices) [ Patient Forms ](https://savvyagents.ai/patient-forms-for-dental-practices) [ Open Dental Integration ](https://savvyagents.ai/integrations/open-dental) [ Dentrix Integration ](https://savvyagents.ai/integrations/dentrix)

 Navigation

 - [Customer Stories](/#impact)
- [DSO](https://savvyagents.ai/ai-phone-answering-service-for-dsos)

  Resources

 - [ Dental Conferences ](https://savvyagents.ai/dental-conferences)
- [ Blog ](https://savvyagents.ai/blogs)
- [ Partner Program ](https://savvyagents.ai/resources/partner-program)
- [ Login ](https://savvyagents.ai/login)

   [ Book a demo ](https://savvyagents.ai/meeting-with-ai-dental-agent)

    Legal agreement

Business Associate Agreement
============================

 This agreement applies when a dental or healthcare practice engages Savvy Agents to create, receive, maintain, or transmit protected health information on the practice's behalf.

Covered Entity

The accepting dental or healthcare practice

Business Associate

Savvy Agents Inc.

Version

 2026-07-21 · Published July 21, 2026

  In this agreement

 1. [ 1. Definitions ](#definitions)
2. [ 2. Permitted Uses and Disclosures ](#permitted-uses)
3. [ 3. Obligations of Business Associate ](#business-associate-obligations)
4. [ 4. Obligations of Covered Entity ](#covered-entity-obligations)
5. [ 5. Term and Termination ](#term-and-termination)
6. [ 6. Breach Notification Coordination ](#breach-coordination)
7. [ 7. Miscellaneous ](#miscellaneous)

  This Business Associate Agreement ("Agreement") is entered into by and between the dental or healthcare practice, provider, or other HIPAA covered entity that accepts this Agreement ("Covered Entity") and Savvy Agents Inc. ("Business Associate"). Covered Entity and Business Associate are each a "Party" and together the "Parties."

This Agreement supplements the applicable Terms of Service, service agreement, order form, statement of work, or other written agreement governing the services provided by Business Associate to Covered Entity (collectively, the "Underlying Agreement").

This Agreement becomes effective on the date Covered Entity electronically accepts it, signs it, or enters into an Underlying Agreement that incorporates it, whichever occurs first (the "Effective Date").

  1. Definitions
--------------

  **1.1 HIPAA Terms.** The following terms have the meanings assigned to them in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Minimum Necessary, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

 **1.2 HIPAA Rules.** "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, as amended, together with applicable provisions of the Health Information Technology for Economic and Clinical Health Act ("HITECH").

 **1.3 Protected Health Information.** "PHI" means Protected Health Information that Business Associate creates, receives, maintains, or transmits from or on behalf of Covered Entity. "ePHI" means PHI maintained in or transmitted by electronic media.

 **1.4 Services.** "Services" means the AI-assisted phone, messaging, scheduling, clinical documentation, insurance coordination, patient-retention, integration, onboarding, support, and related services described in the Underlying Agreement.

  2. Permitted Uses and Disclosures
---------------------------------

  **2.1 Services and Required Disclosures.** Business Associate may Use or Disclose PHI only as necessary to provide the Services, as permitted or required by this Agreement, as directed in writing by Covered Entity, or as Required by Law. Business Associate will not Use or Disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except for the specific management, administration, Data Aggregation, and de-identification activities permitted below.

 **2.2 Management and Administration.** Business Associate may Use PHI for its proper management and administration or to carry out its legal responsibilities. Business Associate may Disclose PHI for those purposes only if the Disclosure is Required by Law or Business Associate obtains reasonable written assurances that the recipient will keep the PHI confidential, Use or further Disclose it only as Required by Law or for the purpose for which it was disclosed, and notify Business Associate of any breach of confidentiality.

 **2.3 Data Aggregation and De-identification.** Business Associate may provide Data Aggregation services relating to Covered Entity's Health Care Operations. Business Associate may de-identify PHI in accordance with 45 C.F.R. section 164.514(a)-(c) and may Use or Disclose the resulting de-identified information only as permitted by the Underlying Agreement and applicable law.

 **2.4 Restricted Uses.** Business Associate will not sell PHI, Use PHI for advertising or marketing except as expressly authorized by Covered Entity and permitted by the HIPAA Rules, or Use PHI to train or improve generalized artificial intelligence models for Business Associate's or a third party's independent benefit. This restriction does not prohibit a Subcontractor from processing PHI solely to provide the Services on Business Associate's behalf under a written agreement that satisfies Section 3.5.

 **2.5 Minimum Necessary.** Business Associate will limit its Uses, Disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose and will follow Covered Entity's reasonable Minimum Necessary policies communicated to Business Associate.

  3. Obligations of Business Associate
------------------------------------

  **3.1 Safeguards.** Business Associate will use appropriate administrative, physical, and technical safeguards to prevent Uses or Disclosures of PHI other than as provided by this Agreement and will comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI.

 **3.2 Incident and Breach Reporting.** Business Associate will report to Covered Entity, without unreasonable delay and no later than forty-eight (48) hours after discovery, any Use or Disclosure of PHI not permitted by this Agreement, any Breach of Unsecured PHI as required by 45 C.F.R. section 164.410, and any Security Incident of which Business Associate becomes aware.

 **3.3 Routine Unsuccessful Security Incidents.** The Parties acknowledge that routine unsuccessful Security Incidents, such as unsuccessful log-in attempts, port scans, pings, denial-of-service attempts that do not result in unauthorized access, and attacks blocked by security controls, occur regularly. These events are deemed reported by this Section unless they result in unauthorized access, Use, Disclosure, modification, destruction, or material interference with system operations.

 **3.4 Breach Information and Mitigation.** To the extent known at the time of notice, Business Associate will identify each affected Individual and provide the information reasonably required for Covered Entity to investigate and make notifications under 45 C.F.R. sections 164.404, 164.406, and 164.408. Business Associate will supplement its notice as additional information becomes available and mitigate, to the extent practicable, harmful effects of an impermissible Use or Disclosure known to Business Associate.

 **3.5 Subcontractors.** In accordance with 45 C.F.R. sections 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on Business Associate's behalf agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to that PHI.

 **3.6 Access.** Within five (5) business days after Covered Entity's request, Business Associate will make PHI in a Designated Record Set available to Covered Entity or, if directed by Covered Entity, to the Individual or the Individual's designee, as necessary to satisfy Covered Entity's obligations under 45 C.F.R. section 164.524. Business Associate will promptly forward to Covered Entity any access request received directly from an Individual unless the Parties agree otherwise in writing.

 **3.7 Amendment.** Within five (5) business days after Covered Entity's request, Business Associate will make PHI available for amendment and will make or incorporate amendments to PHI in a Designated Record Set as directed or agreed to by Covered Entity under 45 C.F.R. section 164.526. Business Associate will promptly forward to Covered Entity any amendment request received directly from an Individual.

 **3.8 Accounting of Disclosures.** Business Associate will document Disclosures and maintain information necessary to satisfy Covered Entity's obligations under 45 C.F.R. section 164.528. Within five (5) business days after Covered Entity's request, Business Associate will provide the required accounting information and will promptly forward any accounting request received directly from an Individual.

 **3.9 Government Access.** Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining compliance with the HIPAA Rules. To the extent legally permitted, Business Associate will notify Covered Entity of a request received directly from the Secretary.

 **3.10 Delegated Privacy Obligations.** To the extent Business Associate carries out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in performing those obligations.

  4. Obligations of Covered Entity
--------------------------------

  **4.1 Privacy Practices and Restrictions.** Covered Entity will notify Business Associate of any limitation in its Notice of Privacy Practices, any change in or revocation of an Individual's permission, and any restriction on the Use or Disclosure of PHI to which Covered Entity has agreed or is required to abide, to the extent the limitation, change, revocation, or restriction may affect Business Associate's Use or Disclosure of PHI.

 **4.2 Permissible Requests.** Covered Entity will not request Business Associate to Use or Disclose PHI in a manner that would violate the HIPAA Rules if done by Covered Entity, except for the management, administration, Data Aggregation, and de-identification activities expressly permitted by this Agreement.

 **4.3 Authority and Contact Information.** Covered Entity represents that it has authority to provide PHI to Business Associate for the Services and will maintain accurate privacy, security, and breach-notification contact information with Business Associate.

  5. Term and Termination
-----------------------

  **5.1 Term.** This Agreement begins on the Effective Date and remains in effect for as long as Business Associate creates, receives, maintains, or transmits PHI on behalf of Covered Entity, unless terminated in accordance with this Agreement.

 **5.2 Termination for Cause.** Covered Entity may terminate this Agreement and the applicable Underlying Agreement if Business Associate violates a material term of this Agreement and does not cure the violation or end the violation within the time reasonably specified by Covered Entity. Covered Entity may terminate immediately if cure is not possible. If termination is not feasible, Covered Entity may report the violation to the Secretary.

 **5.3 Return or Destruction.** Upon termination, Business Associate will return to Covered Entity or, if agreed to by Covered Entity, destroy all PHI that Business Associate still maintains in any form. Business Associate may retain only PHI necessary for its proper management and administration or to carry out its legal responsibilities. For retained PHI, Business Associate will continue the safeguards required by this Agreement, limit further Uses and Disclosures to the purpose requiring retention, and return or destroy the PHI when no longer needed. Business Associate will apply these requirements to PHI maintained in backups and by Subcontractors, subject to documented backup-rotation and legal-retention schedules.

 **5.4 Survival.** Business Associate's obligations concerning retained PHI survive termination of this Agreement.

  6. Breach Notification Coordination
-----------------------------------

  **6.1 Covered Entity Notifications.** Unless the Parties expressly agree otherwise in writing, Covered Entity is responsible for notifications to Individuals, the Secretary, and the media required by the HIPAA Rules. Business Associate will reasonably cooperate with Covered Entity and provide available information needed for those notifications.

 **6.2 Costs and Other Remedies.** Responsibility for investigation, notification, remediation costs, indemnification, liability limitations, and other remedies is governed by the Underlying Agreement and applicable law.

  7. Miscellaneous
----------------

  **7.1 Regulatory References.** A reference to the HIPAA Rules means the provision as in effect or as amended. The Parties will amend this Agreement as necessary to comply with changes in applicable law.

 **7.2 Interpretation and Priority.** Any ambiguity will be interpreted to permit compliance with the HIPAA Rules. If this Agreement conflicts with the Underlying Agreement regarding PHI, this Agreement controls. A more protective obligation in the Underlying Agreement remains effective.

 **7.3 Governing Law.** Except to the extent preempted by federal law, this Agreement is governed by the laws of Texas, without regard to conflict-of-law rules.

 **7.4 Notices.** Notices to Covered Entity will be sent to the privacy, security, or administrative contact maintained for Covered Entity's account. Notices to Business Associate concerning this Agreement may be sent to support@savvyagents.ai and must identify the Covered Entity and the nature of the notice.

 **7.5 Electronic Acceptance and Counterparts.** This Agreement may be accepted electronically and executed in counterparts. Electronic acceptance, electronic signatures, and copies have the same effect as originals to the extent permitted by applicable law.

 **7.6 No Third-Party Beneficiaries.** This Agreement is for the benefit of the Parties and does not create rights in any other person, except as required by the HIPAA Rules.

Electronic acceptance

By electronically accepting this Agreement through Savvy Agents onboarding, signing it, or entering into an Underlying Agreement that incorporates it, the person accepting on behalf of Covered Entity represents that they are authorized to bind Covered Entity to this Agreement.

     [ ![Savvy Agents](https://savvyagents.ai/images/savvy-agents-logo.png) ](https://savvyagents.ai) [    ](https://www.linkedin.com/company/savvyagents/) [    ](https://www.instagram.com/savvyagents.ai) [    ](https://facebook.com/savvyagentsinc) [    ](https://twitter.com/savvyagentsinc)

 Platform
----------

- [ Agent Hub ](https://savvyagents.ai/agent-hub-for-dental-practices)
- [ Online Scheduling ](https://savvyagents.ai/online-scheduling-for-dental-practices)
- [ Website Chat Widget ](https://savvyagents.ai/website-chat-widget-for-dental-practices)
- [ AI Chat ](https://savvyagents.ai/ai-chat-for-dental-practices)
- [ Appointment Confirmation ](https://savvyagents.ai/agent-hub-for-dental-practices/appointment-confirmation)
- [ Morning Brief ](https://savvyagents.ai/morning-brief-for-dental-practices)

- [ Multilingual AI ](https://savvyagents.ai/multilingual-ai-phone-agent-for-dental-practices)
- [ Unified Inbox ](https://savvyagents.ai/unified-inbox-for-dental-practices)
- [ Desk Phones ](https://savvyagents.ai/desk-phones-for-dental-practices)
- [ Patient Forms ](https://savvyagents.ai/patient-forms-for-dental-practices)
- [ Open Dental Integration ](https://savvyagents.ai/integrations/open-dental)
- [ Dentrix Integration ](https://savvyagents.ai/integrations/dentrix)

 Resources
-----------

- [ Dental Conferences ](https://savvyagents.ai/dental-conferences)
- [ DSO ](https://savvyagents.ai/ai-phone-answering-service-for-dsos)
- [ Partner Program ](https://savvyagents.ai/resources/partner-program)
- [ Blog ](https://savvyagents.ai/blog)

 Compare
---------

- [ Weave vs. Savvy ](/alternatives/weave)
- [ Dentina AI vs. Savvy ](/alternatives/dentina)
- [ Arini vs. Savvy ](/alternatives/arini)
- [ TrueLark vs. Savvy ](/alternatives/truelark)
- [ Ruby vs. Savvy ](/alternatives/ruby-receptionists)

 Contact
---------

- [    +1 (325) 237-2889 ](tel:+13252372889)
- [    support@savvyagents.ai ](mailto:support@savvyagents.ai)
- [     HQ: Austin, TX ](https://maps.google.com/?q=Austin,TX)
- [    Talk to support → ](javascript:void(0))

© 2026 Savvy Agents, Inc. All rights reserved.

  [ Trust Center ](https://trust.savvyagents.ai/) [ Privacy ](https://savvyagents.ai/privacy-policy) [ HIPAA &amp; Security ](https://savvyagents.ai/hipaa-and-security) [ Status ](https://savvyagents.ai/status)

             Live Demo Available

 ###  See Savvy Agents  in Action

 Book a personalized demo and discover how  our AI agents (Ira, Sia, Milo &amp; Novi) can transform your practice.

   [       Book a Demo     ](https://savvyagents.ai/meeting-with-ai-dental-agent)       White-Glove Setup       No Long-Term Contract

   Maybe later

###  🍪 We value your privacy

 We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. [ Read our Cookie Policy ](https://savvyagents.ai/cookie-policy)

  Reject All   Customize   Accept All

 ###  Privacy Preferences Center

 When you visit our website, we may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences, or your device and is mostly used to make the site work as you expect it to. You can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings.

 ####  Essential Cookies

 These cookies are necessary for the website to function and cannot be switched off. They are usually only set in response to actions made by you such as setting your privacy preferences, logging in, or filling in forms.

 Always Active

 ####  Analytics Cookies

 These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us know which pages are the most and least popular and see how visitors move around the site.

 **Vendors:** Umami Analytics

 ####  Marketing Cookies

 These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant advertisements on other sites.

 **Vendors:** Google Ads

 ####  Functional Cookies

 These cookies enable enhanced functionality and personalization, such as videos and live chats. They may be set by us or by third-party providers whose services we have added to our pages.

 **Vendors:** No functional chat vendors are loaded through this consent category.

  Save Preferences   Accept All   Cancel
