Business Associate Agreement

SmileMaxer LLC signs a HIPAA business associate agreement with every practice that uses the SmileMaxer and PerioMaxer office-link services. This page summarizes what that agreement says. It is a summary, not the agreement itself: the full text is shown in your account before you sign, and only that text binds either party.

The current text is with our healthcare privacy counsel, so we do not publish it here as final. If your compliance team wants to read it before you subscribe, or needs a wet signature, email support@periomaxer.com and we will send the current text as a PDF.

What it covers

The agreement applies to the SmileMaxer and PerioMaxer office-link services described in your SmileMaxer subscription agreement, and to the patient information those services handle for your practice. You sign once for those services; there is no separate signature per app.

It does not extend to other SmileMaxer LLC products that are designed to hold no patient information, and signing it does not permit patient information to be entered into such a product. If you use one of those, its own terms say what it may hold.

What it commits us to

  • Patient information stays on your network. Chart values move between your own devices and go into your own practice-management software. Voice audio is processed on the clinician’s device and does not leave it.
  • Our cloud is built to receive no patient information. It holds account, licensing, billing, device-configuration, and service-health records. We cannot change that design without written notice to you and a new or amended agreement.
  • We do not sell patient information and do not use it for marketing.
  • We report any breach of unsecured patient information without unreasonable delay and no later than thirty days after we discover it, with the detail you need for your own notices.
  • Any subcontractor that would handle patient information for us must agree in writing to the same terms. Today none does, because patient information does not leave your network.
  • On termination we return or destroy any patient information we still hold.
  • The agreement does not make your practice “HIPAA compliant” and does not certify anyone. Compliance stays a shared job.

How the agreement is organized

  • 1. Definitions
  • 2. Architectural Limit on PHI Handling
  • 3. Permitted Uses and Disclosures by Business Associate
  • 4. Obligations and Activities of Business Associate
  • 5. Obligations of Covered Entity
  • 6. Term and Termination
  • 7. Miscellaneous
  • 8. Execution
  • 9. What this Agreement does not do

Where this summary and the agreement you signed differ, the signed agreement governs.