Attorney review required. Agreements drafted from this template enter
attorney_review automatically and cannot be sent to a counterparty until an authorised attorney approves them.Persona prompts
The system prompts used by the Legal / CISO / CEO personas when drafting and reviewing this template. Inherited from the Intelligent Automation MSP-attorney baseline.
Legal persona
You are an expert MSP (Managed Service Provider) contract attorney specialising in IT services agreements. You help Intelligent Automation, LLC — a Managed Cybersecurity Service Provider (MCSP) based in Fairfield, NJ — draft professional, legally sound contract language. Write in formal, B2B contract English. Be specific to the service type (cybersecurity, cloud, vCISO, etc). Include concrete metrics, timeframes, and obligations where appropriate. Reference NIST CSF 2.0, CIS Controls v8, MITRE ATT&CK, SOC 2 Type 2 where applicable. Output ONLY the revised clause text, no preamble or explanation. Return a JSON object with keys "body_md" (string, full revised section text), "redline_summary_md" (short bullet list of what you changed and why) and "confidence" (float 0.0–1.0 reflecting your certainty the language is legally sound for IA's NJ jurisdiction).
CISO persona
You are the CISO of Intelligent Automation, LLC, reviewing a draft MSP/MSSP contract for security, compliance, and data-handling adequacy. Verify breach-notification windows, sub-processor obligations, encryption requirements, audit-rights, BAA/HIPAA alignment, SOC 2 evidence requirements, incident-response timing. Flag sections that weaken IA's security posture or compliance position with customers in healthcare, finance, or CMMC-regulated industries. Output ONLY a JSON object with keys "body_md" (your security-revised version of the section), "redline_summary_md" (bullet list of security/compliance changes with rationale), "confidence" (float 0.0–1.0).
CEO persona
You are the CEO of Intelligent Automation, LLC reviewing a draft MSP contract for commercial reasonableness from the MSP's perspective. Verify pricing/payment terms, term length, auto-renewal clauses, termination-for-convenience, liability caps, indemnification scope, limitation-of-liability, IP ownership. Flag terms that give away too much margin, accept unreasonable risk, or create operational drag. Output ONLY a JSON object with keys "body_md" (your commercial-revised version), "redline_summary_md" (bullet list of commercial changes with rationale), "confidence" (float 0.0–1.0).
Merge fields
Filled in by the "New agreement" form before the AI personas draft.
effective_datecustomer_nametenant_nameterm_monthsGoverningClause
Body preview
> ⚠️ **Drafted with AI assistance via Argos Counsel.** This document reflects standard commercial terms but may not address jurisdiction-specific requirements or the unique facts of your transaction. Both parties should obtain independent legal review before signing.
# Business Associate Agreement
This **Business Associate Agreement** (this "BAA") is entered into as of **{{.effective_date}}** by and between **{{.customer_name}}** ("Covered Entity") and **{{.tenant_name}}** ("Business Associate") and supplements the Master Services Agreement between the Parties (the "Underlying Agreement"). This BAA is required because Business Associate may create, receive, maintain, or transmit Protected Health Information ("PHI") on behalf of Covered Entity in connection with the Underlying Agreement.
## 1. Definitions
Capitalised terms not otherwise defined have the meanings set forth in 45 CFR Parts 160 and 164. "**PHI**" means Protected Health Information as defined at 45 CFR § 160.103, limited to PHI that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity. "**Electronic PHI**" or "**ePHI**" means PHI in electronic form. "**HIPAA Rules**" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164.
## 2. Permitted Uses and Disclosures of PHI
**(a)** Business Associate may use or disclose PHI only as necessary to perform the Services described in the Underlying Agreement and any SOW, or as Required by Law.
**(b)** Business Associate may use PHI for the proper management and administration of Business Associate or to carry out Business Associate's legal responsibilities.
**(c)** Business Associate may disclose PHI for the proper management and administration of Business Associate, provided that disclosures are Required by Law, or Business Associate obtains reasonable assurances from the recipient that the information will remain confidential and used or further disclosed only as Required by Law or for the purposes for which it was disclosed, and the recipient notifies Business Associate of any breach of confidentiality.
**(d)** Business Associate may provide Data Aggregation services relating to the health-care operations of Covered Entity as permitted by 45 CFR § 164.504(e)(2)(i)(B).
**(e)** Business Associate shall not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted in (b)–(d) above.
## 3. Safeguards
Business Associate shall implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, in compliance with the Security Rule at 45 CFR Part 164, Subpart C. Such safeguards include, at minimum, encryption of ePHI at rest and in transit, role-based access control, multi-factor authentication for administrative access, audit logging, formal risk analysis updated at least annually, and a documented incident response plan.
## 4. Reporting
**(a) Security Incidents.** Business Associate shall report to Covered Entity any successful Security Incident affecting ePHI without unreasonable delay and in no event later than **twenty-four (24) hours** after discovery. Reports of unsuccessful Security Incidents (e.g., port scans, blocked login attempts) are deemed made by this BAA and need not be individually reported.
**(b) Breaches.** Business Associate shall notify Covered Entity of any Breach of Unsecured PHI in accordance with 45 CFR § 164.410 without unreasonable delay and in no event later than **sixty (60) days** after discovery. The notification shall include, to the extent known, identification of each individual whose Unsecured PHI was involved, a description of the Breach, the dates of occurrence and discovery, the nature of the PHI involved, and steps Business Associate has taken to mitigate and prevent recurrence.
## 5. Subcontractors
Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA, in compliance with 45 CFR § 164.502(e)(1)(ii) and § 164.308(b)(2).
## 6. Access; Amendment; Accounting
**(a) Access.** Within fifteen (15) business days of Covered Entity's written request, Business Associate shall make available PHI in a Designated Record Set to Covered Entity (or, as directed by Covered Entity, to the individual) as necessary to satisfy Covered Entity's obligations under 45 CFR § 164.524.
**(b) Amendment.** Within fifteen (15) business days of Covered Entity's written request, Business Associate shall incorporate amendments to PHI in a Designated Record Set as directed by Covered Entity per 45 CFR § 164.526.
**(c) Accounting of Disclosures.** Business Associate shall maintain and, upon Covered Entity's written request, make available to Covered Entity information sufficient to permit Covered Entity to respond to a request for an Accounting of Disclosures under 45 CFR § 164.528.
## 7. Internal Practices and Records
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining compliance with the HIPAA Rules.
## 8. Mitigation
Business Associate shall mitigate, to the extent practicable, any harmful effect of a use or disclosure of PHI by Business Associate in violation of this BAA that is known to Business Associate.
## 9. Term and Termination
**(a) Term.** This BAA shall be effective as of the Effective Date and shall continue in effect for **{{.term_months}} months**, or until terminated under (b) or in conjunction with termination of the Underlying Agreement, whichever is earlier.
**(b) Termination for Cause.** Covered Entity may terminate this BAA and the Underlying Agreement immediately on written notice if Business Associate has materially breached this BAA and either (i) fails to cure within thirty (30) days, or (ii) cure is not feasible.
## 10. Return or Destruction of PHI on Termination
Upon termination of this BAA, Business Associate shall, if feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity. Where return or destruction is not feasible, Business Associate shall extend the protections of this BAA to the retained PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, for so long as the PHI is retained.
## 11. Indemnification
Business Associate shall indemnify and hold Covered Entity harmless from third-party claims, damages, and reasonable expenses (including reasonable attorneys' fees) arising out of Business Associate's material breach of this BAA, subject to any limitations of liability in the Underlying Agreement except that the limitations of liability shall not apply to amounts paid to government authorities as civil monetary penalties or to affected individuals as required by HIPAA.
## 12. Survival
Sections 4(b), 7, 8, 10, and 11 survive termination of this BAA.
## 13. Governing Law
{{.GoverningClause}} The HIPAA Rules preempt any contrary or less-protective state-law provision.
**{{.customer_name}}** (Covered Entity): By ____________________ Name ____________________ Title ____________________
**{{.tenant_name}}** (Business Associate): By ____________________ Name ____________________ Title ____________________