Legal

Business Associate Agreement

Last updated: June 19, 2026

This Business Associate Agreement ("BAA") forms part of the agreement between you (the "Covered Entity") and TMS Insurance Brokerage, Inc., operating OmniReach CRM (the "Business Associate"), and governs the handling of Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the HITECH Act, and their implementing regulations.

This is a legal contract. By using OmniReach CRM to create, receive, maintain, or transmit PHI on behalf of your insurance business, you agree to the terms of this BAA. If you do not agree, do not use OmniReach to handle PHI. Where required, this BAA may also be executed as a separate signed document — contact us to request one.

1.The Parties

This BAA is entered into between:

Role Under HIPAA
Party
Business Associate
TMS Insurance Brokerage, Inc., a Texas corporation, operating OmniReach CRM. 1901 NW Military Hwy, Ste 200, San Antonio, TX 78213.
Covered Entity
The OmniReach customer (insurance agent, agency, FMO, GA, MGA, or downline organization) who uses the Service to create, receive, maintain, or transmit PHI in the course of their insurance business.

The Covered Entity may itself also act as a Business Associate to another Covered Entity (for example, an FMO acting on behalf of a carrier). In that case, this BAA applies in the same way, with "Covered Entity" referring to the customer using OmniReach.

2.Definitions

Capitalized terms used but not defined in this BAA have the meanings given to them in HIPAA. The following definitions apply:

"BAA"
means this Business Associate Agreement.
"Breach"
has the meaning given in 45 C.F.R. § 164.402.
"Business Associate"
has the meaning given in 45 C.F.R. § 160.103 and, for purposes of this BAA, refers to TMS Insurance Brokerage, Inc.
"Covered Entity"
has the meaning given in 45 C.F.R. § 160.103 and, for purposes of this BAA, refers to the OmniReach customer.
"Electronic PHI"
or "ePHI" means PHI transmitted by or maintained in electronic media.
"HIPAA Rules"
means the Privacy, Security, Breach Notification, and Enforcement Rules issued under HIPAA and the HITECH Act, as amended.
"PHI"
or Protected Health Information has the meaning given in 45 C.F.R. § 160.103, limited to PHI created, received, maintained, or transmitted by Business Associate from or on behalf of Covered Entity.
"Secretary"
means the Secretary of the U.S. Department of Health and Human Services or their designee.
"Security Incident"
has the meaning given in 45 C.F.R. § 164.304.
"Subcontractor"
has the meaning given in 45 C.F.R. § 160.103.

3.Permitted Uses and Disclosures of PHI

3.1 Service-Related Uses

Business Associate may use and disclose PHI only as necessary to perform the services described in the underlying Terms and Conditions and Subscription agreement between the parties, and as permitted or required by this BAA.

3.2 Required by Law

Business Associate may use and disclose PHI as required by law, including in response to subpoenas, court orders, or government investigations, subject to the conditions of 45 C.F.R. § 164.512.

3.3 Operations and Management

Business Associate may use PHI for its own proper management and administration and to carry out its legal responsibilities, provided that:

3.5 De-Identification

Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c) and use such de-identified information for any lawful purpose. De-identified information is not subject to this BAA.

3.6 Prohibited Uses

Business Associate will not:

4.Obligations of Business Associate

Business Associate agrees to:

4.1 Use Limitation

Not use or further disclose PHI other than as permitted or required by this BAA or as required by law.

4.2 Safeguards

Use appropriate administrative, physical, and technical safeguards, and comply with the HIPAA Security Rule (45 C.F.R. §§ 164.302–164.318) with respect to ePHI, to prevent unauthorized use or disclosure of PHI. This includes:

4.3 Mitigation

Mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this BAA.

4.4 Reporting

Report to Covered Entity any use or disclosure of PHI not permitted by this BAA, any Security Incident of which it becomes aware, and any Breach of Unsecured PHI in accordance with 45 C.F.R. § 164.410 and Section 7 of this BAA.

4.5 Subcontractors

Ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate under this BAA. See Section 6.

4.6 Access

Provide access to PHI in a Designated Record Set to Covered Entity or, as directed by Covered Entity, to an individual, in order to meet Covered Entity's obligations under 45 C.F.R. § 164.524, within thirty (30) days of a request.

4.7 Amendment

Make any amendments to PHI in a Designated Record Set as directed or agreed to by Covered Entity under 45 C.F.R. § 164.526, or take other reasonable measures to incorporate amendments, within thirty (30) days of a request.

4.8 Accounting

Document and make available to Covered Entity, within sixty (60) days of a request, the information required to provide an accounting of disclosures in accordance with 45 C.F.R. § 164.528.

4.9 Internal Practices

Make Business Associate's internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining Covered Entity's compliance with the HIPAA Rules.

4.10 Compliance with Privacy Rule

To the extent Business Associate carries out a Covered Entity's obligation under the HIPAA Privacy Rule, comply with the requirements of the Privacy Rule that apply to Covered Entity in performance of that obligation.

5.Obligations of Covered Entity

Covered Entity agrees to:

5.1 Notice of Privacy Practices

Provide Business Associate with notice of any limitations in Covered Entity's Notice of Privacy Practices (under 45 C.F.R. § 164.520) that may affect Business Associate's use or disclosure of PHI.

5.2 Changes in Authorization

Notify Business Associate of any changes in, or revocation of, an individual's authorization to use or disclose PHI, if such changes affect Business Associate's permitted uses or disclosures.

5.3 Restrictions

Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent such restriction may affect Business Associate's use or disclosure of PHI.

5.4 Permissible Requests

Not request Business Associate to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity, except where Business Associate may use or disclose PHI for data aggregation, de-identification, or its own management and administration as described in Section 3.

5.5 Appropriate Use of the Service

Use the Service in a manner consistent with HIPAA, including:

6.Subcontractors

Business Associate may engage Subcontractors to perform services that involve PHI. Business Associate will:

Subcontractors used to deliver the Service may include (but are not limited to) the underlying platform provider (HighLevel Inc.), cloud infrastructure providers, encrypted communication carriers, and security and audit-logging vendors. A list of current Subcontractors is available upon written request to info@omnireachcrm.com.

7.Breach Notification

7.1 Notification to Covered Entity

Business Associate will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay and in no event later than sixty (60) days after discovery of the Breach, in accordance with 45 C.F.R. § 164.410. To the extent practicable, Business Associate will provide notification sooner to enable Covered Entity to meet its own notification obligations under the HIPAA Breach Notification Rule.

7.2 Contents of Notification

The notification will include, to the extent then known and as it becomes available:

7.3 Security Incident Reporting

Business Associate will report to Covered Entity any Security Incident of which it becomes aware. The parties acknowledge and agree that this section satisfies any notice requirement for unsuccessful Security Incidents (such as routine pings, port scans, and unsuccessful login attempts) that do not result in unauthorized access, use, disclosure, modification, or destruction of ePHI.

8.Term and Termination

8.1 Term

This BAA becomes effective when Covered Entity first uses the Service to handle PHI and continues in effect until terminated as provided below or until the underlying Subscription terminates, whichever occurs first.

8.2 Termination for Cause

If either party becomes aware of a material breach of this BAA by the other party, the non-breaching party may:

8.3 Termination Without Cause

Either party may terminate this BAA upon termination of the underlying Subscription, with or without cause, by following the termination procedures in the Terms and Conditions.

9.Return or Destruction of PHI

9.1 Upon Termination

Upon termination of this BAA, Business Associate will, if feasible, return or destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity. This obligation extends to PHI in the possession of Subcontractors.

9.2 When Return or Destruction Is Not Feasible

If return or destruction is not feasible (for example, because PHI is retained in backups or for legal retention requirements), Business Associate will:

9.3 Data Export

Covered Entity is responsible for exporting any PHI it wishes to retain from the Service prior to termination. Business Associate provides export functionality within the platform and will offer reasonable assistance with export upon written request.

10.Audits and Compliance Reviews

Business Associate will, upon reasonable written notice, provide Covered Entity with documentation of its administrative, physical, and technical safeguards relevant to the protection of PHI. This may include summaries of policies, procedures, security certifications, and third-party audit reports (such as SOC 2 or HITRUST attestations, where available through the platform provider).

Business Associate is not obligated to provide access to internal systems, source code, or proprietary security details that are not reasonably necessary for Covered Entity to assess HIPAA compliance.

11.Indemnification

Each party will indemnify, defend, and hold harmless the other from and against any third-party claims, losses, damages, fines, penalties, and reasonable attorneys' fees arising from the indemnifying party's breach of this BAA or violation of HIPAA. The indemnifying party's total cumulative liability under this BAA is subject to the limitation of liability set forth in the underlying Terms and Conditions, except that the limitation does not apply to fines or penalties imposed directly on the non-indemnifying party by the U.S. Department of Health and Human Services or a state attorney general resulting from the indemnifying party's breach.

12.Amendments and Regulatory Changes

The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary to comply with the requirements of HIPAA, the HITECH Act, and any other applicable law or regulation.

Business Associate may update this BAA to reflect changes in law or regulation by providing thirty (30) days' written notice (which may be by email or in-account notification) to Covered Entity. Covered Entity's continued use of the Service after the effective date of the updated BAA constitutes acceptance of the changes. If Covered Entity does not agree to the updated BAA, Covered Entity must stop using the Service to handle PHI.

13.Miscellaneous

13.1 Regulatory References

A reference in this BAA to a section in HIPAA, the HITECH Act, or the HIPAA Rules means the section as in effect or as amended.

13.2 Interpretation

Any ambiguity in this BAA shall be resolved in favor of a meaning that permits the parties to comply with HIPAA, the HITECH Act, and the HIPAA Rules.

13.3 Survival

The respective rights and obligations of Business Associate under Section 9 (Return or Destruction of PHI) survive the termination of this BAA.

13.4 No Third-Party Beneficiaries

Nothing in this BAA creates any rights in favor of any third party.

13.5 Relationship to Underlying Agreement

This BAA forms part of, and is incorporated by reference into, the Terms and Conditions between the parties. In the event of any conflict between this BAA and the Terms and Conditions with respect to the handling of PHI, this BAA controls.

13.6 Governing Law

This BAA is governed by the laws of the State of Texas and the federal laws of the United States, without regard to conflict of laws principles, consistent with the Governing Law section of the Terms and Conditions.

13.7 Assignment

Business Associate may assign this BAA in connection with a merger, acquisition, sale of assets, or restructuring of the OmniReach CRM business (including a future transition of ownership to a separate legal entity), provided that the assignee assumes all obligations under this BAA. Covered Entity may not assign this BAA without Business Associate's prior written consent.

13.8 Counterparts and Electronic Acceptance

This BAA may be accepted electronically through the OmniReach platform or by signing a counterpart copy provided upon request. Electronic acceptance has the same legal effect as a handwritten signature.

Need a signed BAA on file? Some compliance frameworks (carrier audits, FMO upline requirements, state insurance department reviews) require a signed paper or PDF copy. Contact info@omnireachcrm.com and we'll send you a counterpart for signature.

Questions about this BAA?

Email: info@omnireachcrm.com

Mail: TMS Insurance Brokerage, Inc. — 1901 NW Military Hwy, Ste 200, San Antonio, TX 78213

Inside the Service: click the blue support button in OmniReach CRM