Stack PT legal

Business Associate Agreement

Version 1 · Effective August 1, 2026

Last updated: August 1, 2026 · Version: 1


This Business Associate Agreement (this "BAA") is between Stack Systems Inc. dba Stack PT, a Delaware corporation ("Stack PT" or "Business Associate"), and the Practice that accepts the Stack PT Terms of Service ("You," "Your," or "Covered Entity").

This BAA is incorporated into and forms part of the Stack PT Terms of Service, including Part A — Additional Terms for Practices (together, the "Terms"). Capitalized terms used but not defined here have the meanings given in the Terms or, failing that, in HIPAA.

Formation and effective date

This BAA is made and entered into automatically at the moment You accept the Terms and Your Practice account is created (the "Effective Date"). No separate signature, countersignature, or exchange of paper is required.

You agree that Your click-acceptance of the Terms constitutes Your electronic signature to this BAA and has the same legal effect as a handwritten signature on a paper original under the federal Electronic Signatures in Global and National Commerce Act (E-SIGN) and the Uniform Electronic Transactions Act (UETA) as adopted in Colorado and elsewhere. This BAA is a signed writing.

Only an owner of the Practice, or another individual with authority to bind the Practice, may accept the Terms and thereby execute this BAA. You represent that the individual who did so had that authority.

Our form governs. This BAA is the business associate agreement between the parties. Any business associate agreement, addendum, or other form You submit to us, including one transmitted with a purchase order, vendor-onboarding packet, or security questionnaire, has no effect and creates no obligation unless it is signed by an authorized officer of Stack PT. Our acceptance of Your order, payment, or continued provision of the Services is not assent to any such form.

Recitals

You are a covered entity as defined at 45 C.F.R. § 160.103, or a business associate of one. In providing the Services, Stack PT creates, receives, maintains, or transmits Protected Health Information on Your behalf. The parties enter into this BAA to satisfy 45 C.F.R. §§ 164.308(b), 164.314(a), 164.502(e), and 164.504(e), and to protect the privacy and security of that information in compliance with HIPAA.

Scope of application. This BAA applies to the extent that You are a Covered Entity, or a business associate acting on behalf of one, and that Stack PT meets the definition of "business associate" at 45 C.F.R. § 160.103 with respect to You. If You are not a Covered Entity, Stack PT will nonetheless create, receive, maintain, and transmit Your Patients' health information in accordance with this BAA, and this BAA remains binding on Stack PT and available to You as a record of how that information is handled.


1. Definitions

"Breach" has the meaning at 45 C.F.R. § 164.402, as applied to Unsecured PHI that Stack PT creates, receives, maintains, or transmits for or on behalf of Covered Entity.

"Data Aggregation" has the meaning at 45 C.F.R. § 164.501.

"De-identified Data" means information derived from PHI that has been de-identified in accordance with 45 C.F.R. § 164.514(a)–(c). De-identified Data is not PHI.

"Designated Record Set" has the meaning at 45 C.F.R. § 164.501.

"ePHI" means PHI that is transmitted by or maintained in electronic media.

"Individual" has the meaning at 45 C.F.R. § 160.103 and includes a person who qualifies as a personal representative under 45 C.F.R. § 164.502(g).

"HIPAA" means the Health Insurance Portability and Accountability Act of 1996, Subtitle D of the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), and the regulations and guidance issued under both.

"PHI" means protected health information as defined at 45 C.F.R. § 160.103, limited to information that Stack PT creates, receives, maintains, or transmits for or on behalf of Covered Entity.

"Privacy Rule" means 45 C.F.R. Part 160 and Part 164, Subparts A and E.

"Reportable Event" means any (a) use or disclosure of PHI not permitted by this BAA, (b) Security Incident, or (c) Breach of Unsecured PHI.

"Required by Law" has the meaning at 45 C.F.R. § 164.103.

"Secretary" means the Secretary of the U.S. Department of Health and Human Services or their designee.

"Security Incident" has the meaning at 45 C.F.R. § 164.304, as applied to ePHI that Stack PT creates, receives, maintains, or transmits for or on behalf of Covered Entity.

"Security Rule" means 45 C.F.R. Part 160 and Part 164, Subparts A and C.

"Services" has the meaning given in the Terms.

"Subcontractor" has the meaning at 45 C.F.R. § 160.103.

"Unsecured PHI" has the meaning at 45 C.F.R. § 164.402.

Any other capitalized term used but not defined here or in the Terms has the meaning given in HIPAA. Any inconsistency in the definition of a term is resolved in favor of a meaning that permits compliance with HIPAA.


2. Permitted uses and disclosures of PHI

Except as otherwise limited by this BAA or the Terms, Stack PT may:

2.1 Perform the Services. Use or disclose PHI to perform the functions, activities, and services described in the Terms for or on behalf of Covered Entity, provided that the use or disclosure would not violate the Privacy Rule or applicable state law if done by Covered Entity.

2.2 Manage and administer Stack PT. Use PHI for the proper management and administration of Stack PT and to carry out Stack PT's legal responsibilities.

2.3 Disclose for management and administration. Disclose PHI for the proper management and administration of Stack PT or to carry out Stack PT's legal responsibilities, provided that the disclosure is Required by Law, or Stack PT obtains reasonable assurances from the recipient that the information will remain confidential and be used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Stack PT of any breach of confidentiality of which it becomes aware.

2.4 Report violations of law. Use PHI to report violations of law to appropriate federal, state, and local authorities, consistent with 45 C.F.R. § 164.502(j).

2.5 Provide Data Aggregation services. Use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). Stack PT will disclose the results of Data Aggregation only to the covered entities whose PHI was aggregated, and only as to their own health care operations. Data Aggregation does not permit Stack PT to disclose one covered entity's PHI to another.

2.6 Create and use De-identified Data. Use PHI to create De-identified Data in accordance with 45 C.F.R. §§ 164.502(d) and 164.514(a)–(c). De-identified Data is not PHI, is not subject to this BAA, and Stack PT may use and disclose it for any purpose permitted by applicable law, including after this BAA terminates. See § 5.3(d).

This Section 2.6 stands independently of Section 2.7. The invalidity or unenforceability of any other permitted use in this Section 2 does not affect this Section 2.6.

2.7 Operate, improve, and develop the Services. Use PHI to operate, evaluate, maintain, secure, improve, and develop the Services, including to develop, train, test, validate, and improve the algorithms, models, features, and clinical content that comprise or support the Services.

This Section 2.7 does not permit Stack PT to:

(a) disclose PHI to any person other than a Subcontractor bound under § 3.6;

(b) use PHI to develop products or services other than the Services, including products offered under a different brand or to a different profession; or

(c) use or disclose PHI for marketing, or engage in any sale of PHI, as those terms are used at 45 C.F.R. §§ 164.501 and 164.502(a)(5).

Stack PT will apply the minimum necessary standard to uses under this Section 2.7.


3. Obligations of Stack PT

3.1 Limits on use and disclosure. Stack PT will not use or disclose PHI other than as permitted or required by this BAA and the Terms, or as Required by Law.

3.2 Compliance with HIPAA. To the extent Stack PT carries out an obligation of Covered Entity under the Privacy Rule, Stack PT will comply with the requirements of the Privacy Rule that apply to Covered Entity in performing that obligation.

3.3 Safeguards. Stack PT will use appropriate safeguards and will comply with the Security Rule with respect to ePHI, to prevent use or disclosure of PHI other than as permitted by this BAA.

3.4 Reporting.

(a) Breach of Unsecured PHI — ten (10) business days. Stack PT will report to Covered Entity any Breach of Unsecured PHI of which it becomes aware, without unreasonable delay and in no case later than ten (10) business days after discovery.

(b) Any other Reportable Event — twenty (20) business days. Stack PT will report any other Reportable Event of which it becomes aware, without unreasonable delay and in no case later than twenty (20) business days after discovery.

(c) Contents. Each report will include, to the extent known: the Individuals whose PHI was or is reasonably believed to have been accessed, acquired, used, lost, modified, destroyed, or disclosed; a description of what happened and the dates of the event and of its discovery; the types of PHI involved; steps Individuals should take to protect themselves; what Stack PT is doing to investigate, mitigate, and remediate; and any other information reasonably available to Stack PT that Covered Entity would reasonably need to meet its own notification obligations. Stack PT will supplement its initial report as further information becomes available.

(d) Cooperation and mitigation. Stack PT will cooperate with Covered Entity in investigating a Reportable Event, will assist Covered Entity in determining whether it constitutes a Breach of Unsecured PHI, and will mitigate, to the extent practicable, any harmful effect known to Stack PT.

(e) Unsuccessful Security Incidents. The parties agree that this § 3.4 constitutes notice by Stack PT of the ongoing occurrence of attempted but unsuccessful Security Incidents that do not result in unauthorized access to, or use, loss, modification, destruction, or disclosure of, PHI — such as pings, broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, and unsuccessful denial-of-service attacks. No separate report of these is required.

3.5 No breach-cost assumption. Nothing in this BAA obligates Stack PT to perform, or to bear the cost of, notification to Individuals, the media, or the Secretary, or to provide credit monitoring or identity-protection services. Those obligations are Covered Entity's under 45 C.F.R. §§ 164.404–164.408.

3.6 Subcontractors. If Stack PT discloses PHI to a Subcontractor, or permits a Subcontractor to create, receive, maintain, or transmit PHI on its behalf, Stack PT will require that Subcontractor to agree in writing to restrictions, conditions, and requirements substantially similar to those that apply to Stack PT under this BAA, in an arrangement that complies with 45 C.F.R. §§ 164.314(a) and 164.504(e).

Stack PT will provide Covered Entity with a copy of any such written arrangement, or a summary of its material terms, within ten (10) business days of Covered Entity's written request.

3.7 Access to PHI. To the extent Stack PT maintains PHI in a Designated Record Set, Stack PT will make that PHI available to Covered Entity, or as Covered Entity directs to an Individual, in a reasonable electronic format and within a time and manner that allows Covered Entity to meet its obligations under 45 C.F.R. § 164.524. This § 3.7 does not apply where Stack PT and its Subcontractors maintain no PHI in a Designated Record Set of Covered Entity.

3.8 Amendment of PHI. To the extent Stack PT maintains PHI in a Designated Record Set, Stack PT will make amendments to that PHI as Covered Entity directs or agrees to, in a time and manner that meets 45 C.F.R. § 164.526. This § 3.8 does not apply where Stack PT and its Subcontractors maintain no PHI in a Designated Record Set of Covered Entity.

3.9 Accounting of disclosures. Stack PT will document disclosures of PHI and information related to those disclosures as would be required for Covered Entity to respond to a request for an accounting under 45 C.F.R. § 164.528, and will provide that documentation to Covered Entity on request. Stack PT will have a reasonable period in which to respond, and in no case will be required to respond in fewer than ten (10) business days after receiving the request.

3.10 Requests received directly from Individuals. If Stack PT receives a request from an Individual for access to, amendment of, or an accounting of disclosures of PHI, or a similar request, Stack PT will redirect the Individual to Covered Entity.

3.11 Availability of records to the Secretary. Stack PT will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining Covered Entity's compliance with the Privacy Rule. No attorney-client, work-product, or other privilege is waived by Stack PT's compliance with this § 3.11.

Stack PT may, in its discretion, provide Covered Entity with a summary of its information security and privacy practices on request. Nothing in this BAA requires Stack PT to provide Covered Entity with copies of its internal policies and procedures.

3.12 Minimum necessary. Stack PT will limit its requests for, uses of, and disclosures of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b).

3.13 Other business associates of Covered Entity. In performing the Services, Stack PT may disclose PHI to, and receive PHI from, other business associates of Covered Entity, and may use and disclose PHI received from them as though it had been received from Covered Entity. Covered Entity is responsible for entering into and maintaining business associate agreements with its other business associates.


4. Obligations of Covered Entity

4.1 Notice of privacy practices. Covered Entity will notify Stack PT in writing of any limitation in its notice of privacy practices, to the extent the limitation may affect Stack PT's use or disclosure of PHI.

4.2 Revocations. Covered Entity will notify Stack PT in writing of any change in, or revocation of, an Individual's authorization to use or disclose PHI, to the extent it may affect Stack PT's use or disclosure of PHI.

4.3 Restrictions. Covered Entity will notify Stack PT in writing of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or must abide by under 45 C.F.R. § 164.522, to the extent it may affect Stack PT's use or disclosure of PHI.

4.4 Permissible requests. Covered Entity will not request that Stack PT use or disclose PHI in any manner that would not be permissible under HIPAA or other applicable law if done by Covered Entity.

4.5 Minimum necessary. Covered Entity will comply with the minimum necessary standard and will provide Stack PT only the minimum PHI necessary for Stack PT to provide the Services.

4.6 Authority and consents. Covered Entity represents and warrants that:

(a) it has the authority to disclose PHI to Stack PT and to authorize the uses and disclosures permitted by § 2;

(b) its notice of privacy practices, and its relationships with its Individuals, permit those uses and disclosures, including the creation and use of De-identified Data under § 2.6, Data Aggregation under § 2.5, and the uses described in § 2.7; and

(c) the PHI it provides to Stack PT, and the PHI its Individuals provide through the Services, may lawfully be provided to Stack PT for those purposes.


5. Term and termination

5.1 Term. This BAA begins on the Effective Date and is coterminous with the Terms. It terminates on the earliest of: expiration or termination of the Terms, with or without cause; termination for cause under § 5.2; the parties' mutual written agreement; or termination required by applicable law.

5.2 Termination for cause. If either party determines that the other has breached a material term of this BAA, it will give written notice describing the breach in sufficient detail for the other party to understand it, and will allow thirty (30) days to cure. If the breach is not cured within that period, the notifying party may terminate this BAA and the Terms.

5.3 Effect of termination.

(a) Retention during the export window. For the sixty-five (65) day period described in Terms § A15.3, Stack PT will retain PHI and make it available to Covered Entity for export. Retention and disclosure to Covered Entity during that period is a permitted use under this BAA. This applies regardless of the reason for termination, including termination for cause.

(b) Return or destruction. Within a reasonable period after the window in § 5.3(a) ends, Stack PT will return or destroy all PHI that it still maintains in any form, and will retain no copies.

(c) If return or destruction is not feasible. If returning or destroying any PHI is not feasible, Stack PT will: retain only that PHI; return or destroy the remainder; extend the protections of this BAA to the retained PHI and continue to apply appropriate safeguards and comply with the Security Rule for as long as it is retained; limit further use and disclosure of the retained PHI to the purposes that made return or destruction infeasible, subject to the same conditions that applied before termination; and return or destroy it when doing so becomes feasible.

(d) De-identified Data survives. De-identified Data created under § 2.6 before termination is not PHI and is not subject to § 5.3(b) or § 5.3(c). Stack PT may continue to use and disclose it after termination as permitted by applicable law.

(e) Survival. This § 5.3 survives termination of this BAA and of the Terms.


6. General

6.1 Regulatory references. A reference to a section of HIPAA means that section as in effect or as amended at the relevant time.

6.2 Amendment. On the effective date of any statute, regulation, or guidance amending or expanding HIPAA that applies to this BAA, this BAA is automatically amended so that the obligations it imposes remain in compliance, unless the parties agree otherwise. The parties will take the actions necessary to reflect those automatic amendments. Any other amendment to this BAA requires a writing signed by both parties; consistent with the Formation section above, Your click-acceptance of an updated version presented through the Services is such a signed writing.

6.3 Interpretation. Any ambiguity in this BAA is resolved in favor of a meaning that permits compliance with HIPAA. Headings are for convenience only. In the event of an inconsistency between this BAA and the mandatory terms of HIPAA, the interpretation of the Secretary or of a court or regulatory agency with authority over the parties prevails.

6.4 Relationship to the Terms; limitation of liability. This BAA controls over the Terms with respect to the use and disclosure of PHI, and in no other respect.

This BAA creates no limitation of liability of its own and no indemnification obligation of its own. Section 16 of the Terms (Limitation of liability), including the cap in Section 16.2, applies to all claims arising out of or relating to this BAA, including claims relating to PHI and to any Breach of Unsecured PHI. Section 17 of the Terms and § A18 of Part A govern indemnification.

6.5 No third-party beneficiaries. This BAA is between Stack PT and Covered Entity. Nothing in it confers any right, remedy, obligation, or liability on any other person, including any Individual or Patient, or their successors and assigns.

6.6 Independent contractors. The parties are independent contractors. This BAA creates no agency, partnership, joint venture, or employment relationship.

6.7 Notices. Notices to Stack PT under this BAA must be in writing and sent to 3327 Broadway St., Boulder, CO 80304, attention Privacy Officer, or to legal@stackpt.app. Notices to Covered Entity may be sent to the email address associated with the Practice account. Either party may change its address for notice on written notice to the other.

6.8 Other terms. Assignment, governing law and venue, dispute resolution and arbitration, severability, and waiver are governed by the corresponding provisions of the Terms, except to the extent preempted by federal law.