Last updated July 26, 2026 · Version 2026-07-26
Who this agreement is for. This Business Associate Agreement is between Rehabity and the physical therapy clinics and other health care providers that subscribe to Rehabity. It is required by HIPAA and governs how Rehabity may handle protected health information on your clinic's behalf.
If you are a patient using Rehabity through your clinic, this agreement does not apply to you. Your information is governed by your clinic's Notice of Privacy Practices and by our Privacy Policy.
This Business Associate Agreement (this "Agreement") is entered into by and between Rehabity Health LLC, a Pennsylvania limited liability company doing business as Rehabity ("Business Associate" or "Rehabity"), and the health care provider organization that accepts this Agreement and is identified in its Rehabity account registration ("Covered Entity" or "Clinic"). Business Associate and Covered Entity are each a "Party" and together the "Parties."
This Agreement is effective as of the date Covered Entity accepts it (the "Effective Date") and supplements, and is incorporated into, the Rehabity Terms of Service and any other agreement under which Rehabity provides services to Covered Entity (together, the "Service Agreement").
Recitals
- Covered Entity is a "covered entity" as that term is defined at 45 CFR 160.103.
- Rehabity provides a digital health platform through which patients follow therapist-assigned exercise programs, log their exercises and how they feel, and communicate with their care team, and through which clinicians monitor adherence, adjust treatment plans, and support Remote Therapeutic Monitoring.
- In performing these services, Rehabity creates, receives, maintains, or transmits Protected Health Information on behalf of Covered Entity, and is therefore a "business associate" as defined at 45 CFR 160.103.
- The Parties enter into this Agreement to comply with 45 CFR 164.502(e) and 164.504(e), and to set out the terms on which Rehabity may use and disclose Protected Health Information.
Contents
- Definitions
- Obligations and Activities of Business Associate
- Security Safeguards
- Breach and Security Incident Reporting
- Permitted Uses and Disclosures
- Prohibited Uses and Disclosures
- Subcontractors
- Obligations of Covered Entity
- Term and Termination
- Return or Destruction of Protected Health Information
- Liability and Indemnification
- Miscellaneous
- Acceptance
1. Definitions
Catch-all definition. The following terms used in this Agreement have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
Specific definitions.
- "Business Associate" generally has the same meaning as the term "business associate" at 45 CFR 160.103, and in reference to the party to this Agreement means Rehabity Health LLC.
- "Covered Entity" generally has the same meaning as the term "covered entity" at 45 CFR 160.103, and in reference to the party to this Agreement means the clinic or other health care provider organization identified in the Rehabity account registration through which this Agreement was accepted.
- "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
- "PHI" means Protected Health Information created, received, maintained, or transmitted by Rehabity from or on behalf of Covered Entity.
2. Obligations and Activities of Business Associate
Rehabity agrees to:
- Not use or disclose PHI other than as permitted or required by this Agreement or as Required By Law;
- Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement;
- Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including Breaches of Unsecured PHI as required at 45 CFR 164.410, and any Security Incident of which it becomes aware, in accordance with Section 4;
- In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of Rehabity agree in writing to the same restrictions, conditions, and requirements that apply to Rehabity with respect to such information;
- Make PHI in a Designated Record Set available to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 CFR 164.524. Rehabity will provide such PHI within ten (10) business days of a written request from Covered Entity. If Rehabity receives a request for access directly from an Individual, Rehabity will forward that request to Covered Entity within five (5) business days rather than responding to it directly, and Covered Entity remains responsible for determining how to respond;
- Make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under 45 CFR 164.526, within ten (10) business days of a written request. If Rehabity receives a request for amendment directly from an Individual, Rehabity will forward that request to Covered Entity within five (5) business days;
- Maintain and make available to Covered Entity the information required to provide an accounting of disclosures as necessary to satisfy Covered Entity's obligations under 45 CFR 164.528, within ten (10) business days of a written request. Rehabity maintains an audit log of access to PHI within the Services for this purpose;
- To the extent Rehabity is to carry out one or more of Covered Entity's obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s); and
- Make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Rehabity on behalf of, Covered Entity available to the Secretary for purposes of determining Covered Entity's compliance with the HIPAA Rules. Rehabity will notify Covered Entity of any such request, unless prohibited from doing so by law.
3. Security Safeguards
Without limiting Section 2(b), Rehabity implements and maintains administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI, including:
- Encryption. PHI is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
- Access controls. Access to PHI requires individual authentication, is scoped so that clinical users may access only the records of patients within their own clinic, and follows least-privilege principles for administrative access.
- Multi-factor authentication. Accounts belonging to clinical and administrative staff are required to use a second authentication factor.
- Audit logging. Access to PHI through the Services is recorded in an audit log retained for no less than six (6) years.
- Network isolation. The database storing PHI is not publicly addressable and is reachable only from Rehabity's application infrastructure.
- Data location. PHI is stored and processed in the United States.
- Workforce. Rehabity trains its workforce members on their obligations under the HIPAA Rules and this Agreement, and terminates access promptly upon separation.
Rehabity may update the specific measures above as technology and threats evolve, provided that it does not materially reduce the overall level of protection afforded to PHI.
4. Breach and Security Incident Reporting
(a) Breaches of Unsecured PHI. Rehabity will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay and in no case later than ten (10) business days after Discovery of the Breach. This timeframe is deliberately shorter than the sixty (60) day outer limit permitted by 45 CFR 164.410 so that Covered Entity retains adequate time to meet its own notification obligations to Individuals, the Secretary, and (where applicable) the media.
(b) Contents of notice. To the extent known at the time, and supplemented promptly as further information becomes available, Rehabity's notice will include: the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; a description of what happened, including the date of the Breach and the date of Discovery; the types of PHI involved; the steps Rehabity has taken to investigate, mitigate harm, and protect against further Breaches; and any other information Covered Entity is required to include in its notification to Individuals under 45 CFR 164.404(c).
(c) Other impermissible uses or disclosures. Rehabity will report any use or disclosure of PHI not permitted by this Agreement, whether or not it constitutes a Breach, without unreasonable delay and in no case later than ten (10) business days after becoming aware of it.
(d) Successful Security Incidents. Rehabity will report Security Incidents that result in unauthorized access to, or the unauthorized use, disclosure, modification, or destruction of, PHI on the same timeline as subsection (c).
(e) Unsuccessful Security Incidents. The Parties acknowledge that Rehabity's systems are routinely subject to unsuccessful attempts that do not result in unauthorized access to PHI, such as port scans, failed log-in attempts, denial-of-service attempts, and blocked network traffic. This Section constitutes notice of such unsuccessful Security Incidents, and Rehabity is not required to report them individually. Rehabity will provide a summary of such activity upon Covered Entity's reasonable written request.
(f) Responsibility for notification. Unless the Parties agree otherwise in writing for a particular incident, Covered Entity is responsible for providing any required notifications to Individuals, the Secretary, and the media. Rehabity will cooperate with and provide reasonable assistance to Covered Entity in preparing those notifications.
(g) Mitigation. Rehabity will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement.
5. Permitted Uses and Disclosures
(a) Rehabity may use and disclose PHI only as necessary to perform the services set forth in the Service Agreement, or as otherwise permitted by this Section.
(b) Rehabity may use or disclose PHI as Required By Law.
(c) Minimum necessary. Rehabity will make uses and disclosures of, and requests for, PHI consistent with Covered Entity's minimum necessary policies and procedures, and in any event limited to the minimum necessary to accomplish the intended purpose.
(d) Rehabity may not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except for the specific uses and disclosures set forth in subsections (e), (f), and (g) below.
(e) Management and administration. Rehabity may use PHI for the proper management and administration of Rehabity or to carry out its legal responsibilities.
(f) Disclosure for management and administration. Rehabity may disclose PHI for the proper management and administration of Rehabity or to carry out its legal responsibilities, provided that the disclosure is Required By Law, or Rehabity obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and be used or further disclosed only as Required By Law or for the purposes for which it was disclosed to the person, and that the person will notify Rehabity of any instance of which it is aware in which the confidentiality of the information has been breached.
(g) De-identification. Rehabity may de-identify PHI in accordance with 45 CFR 164.514(a)-(c). Information that has been de-identified in accordance with that standard is no longer PHI, and Rehabity may use and disclose it for any lawful purpose, including improving and operating the Services. Rehabity will not attempt to re-identify such information, and will not disclose de-identified information in a manner that identifies Covered Entity as its source without Covered Entity's prior written consent.
(h) Data aggregation. Rehabity may use PHI to provide Data Aggregation services relating to the Health Care Operations of Covered Entity.
6. Prohibited Uses and Disclosures
Notwithstanding any other provision of this Agreement, Rehabity will not:
- Sell PHI, or receive any direct or indirect remuneration in exchange for PHI, except as expressly permitted by 45 CFR 164.502(a)(5)(ii);
- Use or disclose PHI for marketing or advertising purposes, or share PHI with any advertising network, data broker, or analytics provider that would use it for its own purposes;
- Use PHI to train machine learning or artificial intelligence models for the benefit of any party other than Covered Entity, except with respect to information that has been de-identified under Section 5(g); or
- Transfer, store, or process PHI outside the United States without Covered Entity's prior written consent.
7. Subcontractors
(a) Rehabity may engage Subcontractors that create, receive, maintain, or transmit PHI on its behalf, provided that Rehabity has entered into a written agreement with each such Subcontractor imposing restrictions, conditions, and requirements at least as protective as those that apply to Rehabity under this Agreement.
(b) Current Subcontractors. As of the Effective Date, Rehabity's Subcontractors with access to PHI are:
| Subcontractor | Function | Agreement |
| Google Cloud Platform (Google LLC) | Application hosting, database, secrets management, and authentication infrastructure | HIPAA Business Associate Addendum accepted |
| Google Workspace (Google LLC) | Transmission of notification and invitation email | HIPAA Business Associate Amendment accepted |
(c) Not a Subcontractor. Rehabity's payment processor, Stripe, Inc., processes clinic subscription and billing information only. It does not create, receive, maintain, or transmit PHI, and is therefore not a Subcontractor for purposes of this Agreement.
(d) Changes. Rehabity will maintain a current list of Subcontractors with access to PHI and will make it available to Covered Entity on request. Rehabity will provide Covered Entity with at least thirty (30) days' advance notice before engaging a new Subcontractor with access to PHI. If Covered Entity reasonably objects on data-protection grounds within that period and the Parties cannot resolve the objection, Covered Entity may terminate this Agreement and the Service Agreement without penalty and receive a pro-rata refund of prepaid fees for the unused portion of its subscription term.
8. Obligations of Covered Entity
(a) Covered Entity will notify Rehabity of any limitation(s) in its Notice of Privacy Practices under 45 CFR 164.520, to the extent that such limitation may affect Rehabity's use or disclosure of PHI.
(b) Covered Entity will notify Rehabity of any changes in, or revocation of, an Individual's permission to use or disclose his or her PHI, to the extent that such change may affect Rehabity's use or disclosure of PHI.
(c) Covered Entity will notify Rehabity of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522, to the extent that such restriction may affect Rehabity's use or disclosure of PHI.
(d) Covered Entity will not request Rehabity to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted under Sections 5(e), 5(f), and 5(h).
(e) Accuracy and authority. Covered Entity is responsible for obtaining any consents, authorizations, or notices required under applicable law for its patients' use of the Services, for the accuracy of the clinical content it enters, and for ensuring that individuals to whom it grants access to the Services are authorized to access the PHI they are able to view.
(f) Account security. Covered Entity is responsible for promptly deactivating, through the Services, the accounts of workforce members who no longer require access to PHI.
9. Term and Termination
(a) Term. This Agreement is effective as of the Effective Date and continues until the later of (i) termination of the Service Agreement, or (ii) the date Rehabity no longer maintains any PHI of Covered Entity, unless terminated earlier as provided below.
(b) Termination for cause by Covered Entity. Covered Entity may terminate this Agreement and the Service Agreement if it determines that Rehabity has violated a material term of this Agreement and Rehabity has not cured the breach or ended the violation within thirty (30) days of written notice. If cure is not possible, Covered Entity may terminate immediately.
(c) Termination for cause by Rehabity. Rehabity may terminate this Agreement and the Service Agreement if it determines that Covered Entity has violated a material term of this Agreement and Covered Entity has not cured the breach within thirty (30) days of written notice.
(d) Effect on the Service Agreement. Because Rehabity cannot lawfully provide the Services without this Agreement in force, termination of this Agreement automatically terminates Covered Entity's right to use the Services with respect to PHI.
10. Return or Destruction of Protected Health Information
(a) Upon termination of this Agreement for any reason, Rehabity will, with respect to PHI:
- Make the PHI available for export by Covered Entity in a commercially reasonable electronic format for a period of thirty (30) days following termination;
- Retain only that PHI which is necessary for Rehabity to continue its proper management and administration or to carry out its legal responsibilities, including PHI that Rehabity is required to retain by applicable federal or state law;
- Return to Covered Entity or, if agreed to by Covered Entity, destroy the remaining PHI that Rehabity still maintains in any form;
- Continue to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI to prevent use or disclosure of the PHI, other than as provided for in this Section, for as long as Rehabity retains the PHI;
- Not use or disclose the PHI retained by Rehabity other than for the purposes for which such PHI was retained, and subject to the same conditions set out in Sections 5(e) and 5(f), which applied prior to termination; and
- Return to Covered Entity or, if agreed to by Covered Entity, destroy the PHI retained by Rehabity when it is no longer needed for its proper management and administration or to carry out its legal responsibilities.
(b) Retention required by law. The Parties acknowledge that state medical-record retention laws may require patient records to be retained for a period of years after a course of treatment ends, and that returning or destroying such records on termination may therefore be infeasible. Where return or destruction is infeasible, Rehabity will extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for so long as Rehabity maintains it.
(c) Survival. The obligations of Rehabity under this Section survive termination of this Agreement.
11. Liability and Indemnification
(a) Responsibility for own conduct. Each Party is responsible for its own compliance with the HIPAA Rules and for its own acts and omissions, and neither Party is responsible for the acts or omissions of the other Party except as expressly set out in this Section.
(b) Indemnification by Rehabity. Subject to subsections (e) and (f), Rehabity will indemnify, defend, and hold harmless Covered Entity from and against third-party claims to the extent directly arising out of Rehabity's breach of this Agreement or Rehabity's negligent or willful failure to safeguard PHI, including the reasonable and documented out-of-pocket costs of any notification to Individuals, the Secretary, or the media that is required as a direct result of such a failure.
(c) Indemnification by Covered Entity. Subject to subsections (e) and (f), Covered Entity will indemnify, defend, and hold harmless Rehabity from and against third-party claims to the extent arising out of Covered Entity's breach of this Agreement, Covered Entity's failure to obtain any consent or authorization required for its patients' use of the Services, Covered Entity's instruction to Rehabity to use or disclose PHI in a manner that violates the HIPAA Rules, or the acts or omissions of Covered Entity's workforce members in their use of the Services, including their failure to safeguard account credentials.
(d) Indemnification procedure. A Party seeking indemnification must (i) give the indemnifying Party prompt written notice of the claim, provided that a delay in notice relieves the indemnifying Party of its obligations only to the extent it is materially prejudiced by the delay; (ii) give the indemnifying Party sole control of the defense and settlement of the claim, except that the indemnifying Party may not enter into any settlement that admits fault on behalf of, or imposes any non-monetary obligation on, the indemnified Party without that Party's prior written consent, which will not be unreasonably withheld; and (iii) provide reasonable cooperation at the indemnifying Party's expense.
(e) Exclusion of indirect damages. Neither Party will be liable to the other for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any lost profits, lost revenue, lost data, loss of goodwill, or business interruption, arising out of or relating to this Agreement, regardless of the theory of liability and even if the Party has been advised of the possibility of such damages.
(f) Limitation of liability.
- General cap. Except as provided in clauses (ii) and (iii), each Party's total aggregate liability arising out of or relating to this Agreement will not exceed the total fees paid or payable by Covered Entity to Rehabity under the Service Agreement in the twelve (12) months preceding the event giving rise to the claim.
- Enhanced cap for PHI claims. For claims arising out of the use or disclosure of PHI, including a Party's indemnification obligations under subsections (b) and (c), each Party's total aggregate liability will not exceed the greater of (A) three (3) times the total fees paid or payable by Covered Entity to Rehabity under the Service Agreement in the twelve (12) months preceding the event giving rise to the claim, or (B) twenty-five thousand United States dollars ($25,000).
- Exclusions from the caps. The limitations in clauses (i) and (ii) do not apply to liability arising from a Party's gross negligence, willful misconduct, or fraud, or to Covered Entity's obligation to pay fees due under the Service Agreement.
(g) Relationship to the Service Agreement. To the extent the Service Agreement contains a limitation of liability or disclaimer that conflicts with this Section, this Section controls with respect to claims arising out of the use or disclosure of PHI.
(h) Allocation of risk. The Parties acknowledge that the limitations in this Section are an essential basis of the bargain between them, that the fees charged under the Service Agreement reflect this allocation of risk, and that these limitations apply notwithstanding the failure of the essential purpose of any limited remedy.
12. Miscellaneous
(a) Regulatory references. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.
(b) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of the HIPAA Rules and any other applicable law. Rehabity may otherwise amend this Agreement by providing Covered Entity at least thirty (30) days' advance written notice; if Covered Entity does not agree to the amendment, it may terminate this Agreement and the Service Agreement within that period without penalty and receive a pro-rata refund of prepaid fees for the unused portion of its subscription term. Continued use of the Services after the effective date of an amendment constitutes acceptance of it.
(c) Interpretation. Any ambiguity in this Agreement will be interpreted to permit compliance with the HIPAA Rules. In the event of a conflict between this Agreement and the Service Agreement with respect to PHI, this Agreement controls.
(d) Governing law. This Agreement is governed by the laws of the Commonwealth of Pennsylvania, without regard to its conflict-of-laws principles, except to the extent preempted by federal law.
(e) Notices. Notices to Rehabity under this Agreement must be sent to privacy@rehabityhealth.com and to Rehabity Health LLC, 6940 Roosevelt Blvd, Philadelphia, PA 19149. Notices to Covered Entity may be sent to the administrative contact email associated with its Rehabity account. Notice is effective upon receipt.
(f) No third-party beneficiaries. Nothing in this Agreement is intended to confer, nor does it confer, any rights on any person other than the Parties and their respective successors and permitted assigns.
(g) Assignment. Neither Party may assign this Agreement without the other Party's prior written consent, except that either Party may assign it in connection with a merger, acquisition, or sale of substantially all of its assets, provided the assignee assumes all obligations under this Agreement.
(h) Severability. If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions remain in full force and effect.
(i) Entire agreement. This Agreement, together with the Service Agreement, constitutes the entire agreement between the Parties with respect to the subject matter of this Agreement and supersedes all prior discussions and agreements regarding the handling of PHI.
(j) Survival. Sections 10, 11, and 12 survive termination of this Agreement.
13. Acceptance
This Agreement is executed electronically. By checking the acceptance box presented during clinic registration, the individual accepting this Agreement represents and warrants that:
- They have read this Agreement in its entirety;
- They are authorized to enter into binding agreements on behalf of Covered Entity; and
- Covered Entity agrees to be bound by the terms of this Agreement.
Rehabity records the name, title, email address, date and time, and document version associated with each acceptance, and retains that record for no less than six (6) years as required by 45 CFR 164.316(b)(2). Covered Entity may request a copy of its executed Agreement at any time by contacting privacy@rehabityhealth.com.
The Parties agree that electronic acceptance under this Section has the same legal force and effect as a handwritten signature, in accordance with the federal Electronic Signatures in Global and National Commerce Act (15 U.S.C. § 7001 et seq.).
Business Associate
Rehabity Health LLC
By: Mohammad Abrar, Sole Member
6940 Roosevelt Blvd, Philadelphia, PA 19149
privacy@rehabityhealth.com
This Agreement is offered pre-executed by Rehabity. It becomes binding on both Parties upon Covered Entity's electronic acceptance as described in Section 13.
Questions about this Agreement, or about signing your clinic's own business associate agreement instead of this one, can be directed to privacy@rehabityhealth.com.