Business Associate Agreement
Version: 2026-08-02 · HIPAA BAA for US RehabPilot clinics
This Business Associate Agreement (“BAA”) is offered to Clinics established in the United States that use RehabPilot cloud features involving Protected Health Information (“PHI”) as defined under HIPAA. It supplements the RehabPilot Data Processing Agreement (including Annexes A–D). By accepting this BAA (including via clickwrap at trial signup or checkout), the Clinic and Rosenheinrich Software Solutions agree as follows.
1. Parties and roles
Covered Entity: the physiotherapy clinic / practice that creates a RehabPilot clinic account and is a Covered Entity (or acts as a Business Associate of a Covered Entity) under HIPAA (“Clinic”).
Business Associate: Rosenheinrich Software Solutions (Phillip Rosenheinrich), Destouchesstr. 3, 80803 München, Germany (“RehabPilot”, “we”).
RehabPilot provides cloud software and related services that may create, receive, maintain, or transmit PHI on behalf of the Clinic.
2. Definitions
Capitalized terms not defined here have the meanings in HIPAA (45 C.F.R. Parts 160 and 164), including “Protected Health Information”, “Security Incident”, and “Breach”. “Services” means the RehabPilot clinic/patient cloud features described in the DPA Annex A.
3. Permitted uses and disclosures
RehabPilot may use and disclose PHI only as necessary to provide the Services, as required by law, or as expressly permitted in writing by the Clinic. RehabPilot will not use or disclose PHI in a manner that would violate HIPAA if done by the Clinic, except for data aggregation for the Clinic’s healthcare operations and for RehabPilot’s proper management and administration where permitted by 45 C.F.R. § 164.504(e).
4. Safeguards
RehabPilot will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI, consistent with the HIPAA Security Rule and the technical and organizational measures described in the DPA Annexes (TOMs / Subprocessors).
5. Reporting
RehabPilot will report to the Clinic any use or disclosure of PHI not permitted by this BAA of which it becomes aware, and any Security Incident or Breach of unsecured PHI without unreasonable delay and in no case later than sixty (60) days after discovery (or sooner if required by applicable law), including information reasonably available to RehabPilot that the Clinic needs to meet its breach-notification obligations.
6. Agents and subcontractors
RehabPilot will ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of RehabPilot agrees in writing to restrictions and conditions that are at least as protective as those in this BAA. Current subprocessors are listed in the DPA Annex C and may be updated as described there.
7. Access, amendment, and accounting
To the extent RehabPilot maintains PHI in a Designated Record Set, RehabPilot will make PHI available to the Clinic (and amend it or provide an accounting of disclosures) as reasonably necessary for the Clinic to meet its obligations under 45 C.F.R. §§ 164.524, 164.526, and 164.528, within timeframes that allow the Clinic to comply with HIPAA.
8. HHS access
RehabPilot will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of Health and Human Services for purposes of determining the Clinic’s or RehabPilot’s compliance with HIPAA, subject to applicable privileges and legal process.
9. Term and termination
This BAA is effective when accepted and continues until the Services end or either party terminates for material breach uncured within thirty (30) days after written notice. Upon termination, RehabPilot will return or destroy PHI remaining in its possession if feasible, or continue to protect it under this BAA if return or destruction is infeasible, as described in the DPA exit / deletion terms.
10. Precedence and contact
If this BAA conflicts with the DPA for US Clinics regarding PHI under HIPAA, this BAA prevails for those HIPAA matters. For questions: [email protected].