In plain terms
This applies whenever our work touches data a law protects — patient records, financial records, personal information under a state privacy statute. Part A is the HIPAA business associate agreement. Part B covers state privacy law. Part C covers everything else. It applies automatically; there is no box to tick.
This Data Processing Agreement (the “DPA”) is between We Solve Problems, LLC (“Provider,” “we,” “us”) and the client identified on the applicable Order (“Client,” “you”). It applies where the Order identifies Regulated Data.
Only the Parts identified on the Order apply.
Part A — HIPAA Business Associate Agreement
Applies where the Order identifies HIPAA and Client is a Covered Entity or a Business Associate engaging us as a Subcontractor.
A.1 Definitions
Capitalized terms not defined here have the meaning given in 45 C.F.R. Parts 160 and 164. “PHI” means Protected Health Information we create, receive, maintain, or transmit for or on behalf of Client. “Breach,” “Covered Entity,” “Business Associate,” “Subcontractor,” “Required by Law,” “Security Incident,” and “Unsecured PHI” have their regulatory meanings.
In this Part, we are the Business Associate and Client is the Covered Entity, or, where Client is itself a Business Associate, we are the Subcontractor and Client’s obligations to its Covered Entity flow down to us.
A.2 Permitted uses and disclosures
We will not use or disclose PHI other than as this DPA permits, as the Agreement requires to deliver the Services, or as Required by Law.
We may use PHI for our own proper management and administration and to carry out our legal responsibilities. We may disclose PHI for those purposes only where the disclosure is Required by Law, or where we obtain reasonable assurances from the recipient that the PHI will be held confidentially, used only as we disclosed it, and that the recipient will notify us of any breach of its confidentiality.
We may de-identify PHI in accordance with 45 C.F.R. § 164.514(b) and use the de-identified data for our own purposes.
We will not sell PHI and will not use or disclose it for marketing or fundraising.
A.3 Minimum necessary
We will limit our use, disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose.
A.4 Safeguards
We will use appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as this DPA provides, and will comply with the HIPAA Security Rule at 45 C.F.R. Part 164 Subpart C with respect to electronic PHI.
A.5 Subcontractors
We will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on our behalf agrees in writing to restrictions and conditions at least as protective as those in this Part. A current list of subcontractors with access to PHI is available to Client on request.
A.6 Reporting
We will report to Client:
- any use or disclosure of PHI not permitted by this DPA, without unreasonable delay and in no case later than ten (10) business days after we become aware of it;
- any Security Incident involving electronic PHI, on the same timeline. Unsuccessful attempts that do not result in unauthorized access — such as routine scans, pings, and blocked login attempts — are reported in aggregate on request rather than individually; and
- any Breach of Unsecured PHI, without unreasonable delay and in no case later than ten (10) business days after discovery.
A Breach report will include, to the extent known: the identification of each individual whose PHI was involved, a description of what happened, the date of the incident and of discovery, the types of information involved, what we are doing to investigate and mitigate, and a contact for further information. We will supplement the report as further information becomes available.
Client is responsible for determining whether an incident is a reportable Breach and for making any required notification to individuals, the Secretary, or the media.
A.7 Individual rights
We will, within ten (10) business days of Client’s written request and to the extent we hold PHI in a Designated Record Set:
- make PHI available to Client so Client can meet an individual’s right of access under 45 C.F.R. § 164.524;
- make PHI available for amendment and incorporate an amendment under 45 C.F.R. § 164.526; and
- provide the information required for Client to respond to an accounting of disclosures request under 45 C.F.R. § 164.528.
Where an individual makes such a request directly to us, we will forward it to Client within five (5) business days and will not respond to it ourselves.
A.8 Access by the Secretary
We will make our internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for determining Client’s compliance. We will notify Client of such a request where legally permitted.
A.9 Term and termination
This Part is effective on the Order Effective Date and terminates when all PHI is returned or destroyed, or when the protections here are extended to PHI we cannot feasibly return or destroy.
Client may terminate the Agreement if we materially breach this Part and fail to cure within thirty (30) days of written notice.
On termination, we will return or destroy all PHI we hold, including PHI held by subcontractors, where feasible. Where return or destruction is not feasible, we will extend the protections of this Part to that PHI and limit further use and disclosure to the purposes that make return or destruction infeasible, for as long as we retain it.
A.10 Client’s obligations
Client will notify us of any limitation in its notice of privacy practices, any change in or revocation of an individual’s permission, and any restriction on use or disclosure Client has agreed to, to the extent any of them affects our use or disclosure of PHI.
Client will not ask us to use or disclose PHI in a way that would violate HIPAA if done by Client, except as 45 C.F.R. § 164.504(e)(2)(i)(B) permits.
Part B — State privacy law
Applies where the Order identifies a state privacy statute, including the California Consumer Privacy Act as amended.
B.1 Roles
Client is the Business or Controller. We are the Service Provider or Processor. We process Personal Information only on Client’s documented instructions and only for the Business Purpose of delivering the Services described in the Order.
B.2 Restrictions
We will not:
- sell or share Personal Information as those terms are defined by the applicable statute;
- retain, use, or disclose Personal Information for any purpose other than performing the Services, or outside the direct business relationship with Client;
- combine Personal Information received from Client with Personal Information from another source, except as the applicable statute permits to perform a Business Purpose; or
- retain, use, or disclose Personal Information for a commercial purpose other than the Services.
We certify that we understand these restrictions and will comply with them.
B.3 Assistance
We will assist Client, taking into account the nature of the processing, in responding to verifiable consumer requests to know, delete, correct, opt out, or limit use of sensitive Personal Information, to the extent the request concerns Personal Information we hold on Client’s behalf. Where a consumer makes such a request directly to us, we will forward it to Client and will not respond to it ourselves.
We will assist Client with data protection impact assessments and with regulator inquiries relating to our processing, at our then-prevailing rates where the assistance is substantial.
B.4 Subprocessors
We may engage subprocessors to deliver the Services. Each is bound in writing to obligations no less protective than this Part. A current list is available to Client on request, and we will give Client notice of a new subprocessor with access to Personal Information before it begins processing.
B.5 Security and incidents
We will implement and maintain reasonable security procedures and practices appropriate to the nature of the Personal Information. We will notify Client without unreasonable delay, and in no case later than ten (10) business days, after becoming aware of a breach of the security of Personal Information we hold on Client’s behalf, with the information reasonably available to us.
B.6 Deletion and return
On termination, or on Client’s written request, we will delete or return Personal Information we hold on Client’s behalf, except where retention is required by law. Section 4.4 of the Services Agreement governs the timing.
B.7 Audit
Client may, no more than once in any twelve-month period and on thirty (30) days’ written notice, take reasonable and appropriate steps to verify our compliance with this Part, which we may satisfy by providing a current third-party assessment, a completed security questionnaire, or a written description of our controls.
Part C — General data protection terms
Applies to all Regulated Data identified on the Order.
C.1 Scope of processing
The subject matter, duration, nature, and purpose of the processing, the types of data, and the categories of data subjects are those described in the Order and the applicable Service Attachments.
C.2 Instructions
We process Regulated Data only on Client’s documented instructions, which the Agreement and the Order constitute. If we believe an instruction violates applicable law, we will notify Client and may suspend the affected processing.
C.3 Confidentiality of personnel
We ensure that personnel authorized to process Regulated Data are bound by confidentiality obligations.
C.4 Security measures
We maintain administrative, technical, and physical safeguards appropriate to the risk, including access control, encryption of data in transit and at rest where the systems involved support it, logging, backup, and a documented incident response process. A current description is available to Client on request.
C.5 Location of processing
We process Regulated Data in the United States. We will not transfer Regulated Data outside the United States without Client’s prior written consent and an appropriate transfer mechanism.
C.6 Artificial intelligence
We will not submit Regulated Data to an AI Tool unless the Order identifies the tool, Client has licensed it on a plan that supports the required contractual protections, and the vendor has executed any business associate agreement or data processing agreement the law requires.
C.7 Records
We maintain records of the categories of processing we carry out on Client’s behalf and make them available to Client on request.
C.8 Conflict
Where this DPA conflicts with the Services Agreement or a Service Attachment, this DPA controls with respect to the processing of Regulated Data.