Skip to content

Business Associate Agreement

Last updated: July 2026

Version v2026.07.1 — effective 21 July 2026

Acceptance

This Business Associate Agreement ("Agreement") is incorporated by reference into the Zerapy Terms of Service. By executing this Agreement on behalf of a healthcare organization, that organization ("Covered Entity" or "Provider") and the individual accepting on its behalf agree to be bound by it. This Agreement is effective as of the date Covered Entity first accepts it (the "Effective Date").

This Agreement is entered into by and between ZeraCorp, Inc., a Delaware corporation with its principal place of business at 11160-C1 South Lakes Dr #601, Reston, VA 20191 ("Business Associate" or "Zerapy"), and the Covered Entity. Business Associate and Covered Entity are collectively the "Parties" and individually a "Party."

This Agreement governs Business Associate's Creation, receipt, maintenance, and transmission of Protected Health Information in connection with the Zerapy platform, including remote therapeutic monitoring, home exercise program delivery, care-journey management, scheduling, patient messaging, clinical documentation support, and billing services (collectively, the "Services").

This Agreement supersedes any prior business associate agreement between the Parties.

Recitals

WHEREAS, Covered Entity is a "covered entity" as defined by HIPAA and the regulations promulgated thereunder, including the Privacy Rule (45 C.F.R. Part 160 and Part 164, Subparts A and E) and the Security Rule (45 C.F.R. Part 160 and Part 164, Subparts A and C), as amended by the HITECH Act;

WHEREAS, Business Associate provides an AI-assisted physical therapy platform and related services that involve the Creation, receipt, maintenance, or transmission of PHI on behalf of Covered Entity;

WHEREAS, Business Associate maintains an information security program with administrative, physical, and technical safeguards consistent with the HIPAA Security Rule;

NOW, THEREFORE, in consideration of the mutual promises and covenants contained herein, the Parties agree as follows.

Article I — Definitions

Capitalized terms used but not defined in this Agreement have the meanings assigned to them in HIPAA, the HITECH Act, and their implementing regulations, including "Breach" (45 C.F.R. § 164.402), "Designated Record Set" (45 C.F.R. § 164.501), "Individual" (45 C.F.R. § 160.103), "Protected Health Information" or "PHI" (45 C.F.R. § 160.103), "Required By Law" (45 C.F.R. § 164.103), "Security Incident" (45 C.F.R. § 164.304), "Subcontractor" (45 C.F.R. § 160.103), and "Unsecured Protected Health Information" (45 C.F.R. § 164.402).

"HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended, together with the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164.

"Subprocessor" means a Subcontractor engaged by Business Associate that Creates, receives, maintains, or transmits PHI in the course of supporting the Services. The Subprocessors engaged as of the Effective Date are listed in Schedule A.

Article II — Permitted Uses and Disclosures by Business Associate

Business Associate may use and disclose PHI only as follows:

  1. To perform the Services described in the Terms of Service and any applicable order form, and as otherwise directed in writing by Covered Entity.
  2. For the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any disclosure to a third party is either Required By Law or made subject to written assurances that the information will be held confidentially, used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
  3. To provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
  4. To de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(b). De-identified information is not PHI and may be used by Business Associate for product improvement, benchmarking, research, and analytics. Business Associate will not attempt to re-identify de-identified information, and will not disclose the de-identification methodology in a manner that would facilitate re-identification.
  5. As Required By Law.

Article III — Prohibited Uses and Disclosures

Business Associate will not:

  1. Use or disclose PHI other than as permitted by this Agreement, as permitted by HIPAA had the use or disclosure been made by Covered Entity, or as Required By Law.
  2. Sell PHI, or use or disclose PHI for marketing or fundraising purposes, except as expressly permitted by 45 C.F.R. §§ 164.501, 164.508(a)(3)–(4), and then only with a valid authorization.
  3. Use or disclose PHI for the training, fine-tuning, or improvement of any generative artificial intelligence or machine-learning model operated by Business Associate or by any third party, whether or not that model is used to provide the Services.
  4. Transmit PHI to any generative artificial intelligence service except as expressly described in Schedule A, and then only under a business associate agreement or equivalent written commitment with the relevant Subprocessor.
  5. Disclose PHI to any Subprocessor not listed in Schedule A without first publishing an amended version of this Agreement in accordance with Article X.

Article IV — Obligations of Business Associate

Business Associate agrees to:

  1. Safeguards. Implement and maintain appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided for by this Agreement. Such safeguards include encryption of PHI in transit using industry-standard transport security and encryption at rest, role-based access controls enforcing least privilege, unique user identification, audit logging of access to PHI, and support for multi-factor authentication on administrative access.
  2. Mitigation. Mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this Agreement.
  3. Reporting. Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, any Security Incident of which it becomes aware, and any Breach of Unsecured PHI, in accordance with Article VII.
  4. Subcontractor flow-down. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that each Subcontractor that Creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement.
  5. Access. Make PHI in a Designated Record Set available to Covered Entity, or to the Individual where directed by Covered Entity, as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524, within fifteen (15) business days of a written request.
  6. Amendment. Make PHI in a Designated Record Set available for amendment and incorporate any amendment directed by Covered Entity, as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.526, within fifteen (15) business days of a written request.
  7. Accounting of disclosures. Document disclosures of PHI and information relating to such disclosures, and make that information available to Covered Entity, as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.528, within fifteen (15) business days of a written request.
  8. Covered Entity obligations. To the extent Business Associate is to carry out an obligation of Covered Entity under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of that obligation.
  9. Availability to the Secretary. Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.
  10. Minimum necessary. Request, use, and disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use, or disclosure, consistent with 45 C.F.R. § 164.502(b).
  11. HITECH. Comply with the applicable requirements of the HITECH Act and its implementing regulations.
  12. Workforce. Train members of its workforce with access to PHI on their obligations under this Agreement and applicable law, and apply appropriate sanctions for violations.

Article V — Subcontractors and Subprocessors

Business Associate engages the Subprocessors listed in Schedule A to support the Services. Covered Entity authorizes that engagement as a condition of using the Services.

Business Associate remains fully responsible to Covered Entity for the acts and omissions of its Subprocessors with respect to PHI, to the same extent as for its own acts and omissions.

Business Associate will maintain a current, written business associate agreement, or an equivalent written commitment providing at least equivalent protection, with each Subprocessor that Creates, receives, maintains, or transmits PHI.

Business Associate will not engage a new PHI Subprocessor, or materially expand the categories of PHI disclosed to an existing Subprocessor, without publishing an amended version of this Agreement in accordance with Article X. Publication of an amended version re-gates acceptance, and continued use of the Services following notice constitutes acceptance of the amended Schedule A.

Article VI — Individual Rights and Restrictions

Business Associate will comply with any restriction on the use or disclosure of PHI to which Covered Entity has agreed under 45 C.F.R. § 164.522, and with any limitation in Covered Entity's Notice of Privacy Practices, in each case to the extent Covered Entity has notified Business Associate in writing of that restriction or limitation and it affects Business Associate's permitted uses or disclosures.

Business Associate will promptly forward to Covered Entity any request it receives directly from an Individual for access to, amendment of, or an accounting of disclosures of PHI, and will not respond to such a request directly except as directed in writing by Covered Entity or as Required By Law.

Article VII — Breach and Security Incident Notification

Breach of Unsecured PHI. Business Associate will notify Covered Entity in writing without unreasonable delay, and in no event later than seventy-two (72) hours after Discovery, of any Breach of Unsecured PHI. The notification will include, to the extent then known and in subsequent supplements as further information becomes available: the identification of each Individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; a description of what occurred, including the date of the Breach and the date of Discovery; the types of PHI involved; any steps Individuals should take to protect themselves; and the steps Business Associate is taking to investigate, mitigate, and prevent recurrence.

Security Incidents. Business Associate will report Security Incidents resulting in unauthorized access to, or use or disclosure of, PHI in accordance with the preceding paragraph. The Parties acknowledge that attempted but unsuccessful Security Incidents that do not result in unauthorized access to PHI — including pings, port scans, unsuccessful authentication attempts, and denial-of-service attempts that do not compromise PHI — occur routinely against internet-connected systems, and agree that this paragraph constitutes notice of such attempts; no additional individual notice is required.

Cooperation. Business Associate will cooperate with Covered Entity in investigating any Breach or Security Incident and in meeting Covered Entity's obligations under 45 C.F.R. §§ 164.400–414 and any applicable state law.

Article VIII — Obligations of Covered Entity

Covered Entity will:

  1. Notify Business Associate of any limitation in its Notice of Privacy Practices, of any change to or revocation of an Individual's authorization, and of any restriction agreed to under 45 C.F.R. § 164.522, in each case to the extent it affects Business Associate's permitted uses or disclosures.
  2. Not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity, except as permitted under Article II for Business Associate's management and administration or data aggregation.
  3. Be solely responsible for the accuracy, quality, and legality of the PHI it or its users submit to the Services, for obtaining any consent or authorization required for that submission, and for the professional and clinical judgments made by its workforce using the Services.
  4. Maintain the confidentiality of authentication credentials issued to its workforce, promptly deactivate accounts for departing workforce members, and configure available access controls appropriately for its organization.

Article IX — Term and Termination

Term. This Agreement takes effect on the Effective Date and continues until all PHI Created or received by Business Associate on behalf of Covered Entity is returned or destroyed, or protections are extended to it in accordance with this Article.

Termination for cause. Covered Entity may terminate this Agreement and the Services if Business Associate materially breaches this Agreement and fails to cure that breach within thirty (30) days of written notice, or immediately if cure is not possible.

Effect of termination. Upon termination, Business Associate will return or destroy all PHI Created or received on behalf of Covered Entity that Business Associate still maintains, including PHI held by Subprocessors, and will retain no copies. Covered Entity may export its data through the Services prior to termination. Where return or destruction is infeasible — including PHI retained in immutable audit logs, backup media pending expiry of the retention cycle, or where retention is Required By Law — Business Associate will extend the protections of this Agreement to that PHI, limit further use and disclosure to the purposes that make return or destruction infeasible, and destroy it when those purposes no longer apply.

Article X — Miscellaneous

Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with HIPAA. Business Associate may amend this Agreement by publishing a new version and providing notice through the Services; the amended version becomes binding on acceptance, and continued use of the Services following notice constitutes acceptance.

Interpretation. Any ambiguity in this Agreement will be resolved to permit compliance with HIPAA. In the event of a conflict between this Agreement and the Terms of Service with respect to PHI, this Agreement controls.

Entire agreement. This Agreement constitutes the entire agreement between the Parties with respect to the handling of PHI and supersedes all prior agreements and understandings, written and oral, on that subject matter.

Indemnification. Business Associate will indemnify and hold harmless Covered Entity from and against any claims, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to any breach of this Agreement by Business Associate, or any unauthorized use or disclosure of PHI by Business Associate or its Subprocessors.

No third-party beneficiaries. Nothing in this Agreement confers any rights on any person other than the Parties and their respective successors and permitted assigns.

Notices. Notices under this Agreement must be in writing and are deemed given: when delivered personally; when sent by confirmed electronic mail to the address associated with the Covered Entity's account; five (5) business days after being sent by registered or certified mail, return receipt requested; or one (1) business day after deposit with a nationally recognized overnight courier specifying next-day delivery.

Governing law. This Agreement is governed by federal law and, to the extent not preempted, by the laws of the State of Delaware, without regard to its conflict-of-laws principles.

Survival. Articles IV, VI, VII, IX, and X survive termination of this Agreement to the extent PHI is retained.

Severability. If any provision of this Agreement is held unenforceable, the remaining provisions remain in full force and effect.

Waiver. A Party's failure to enforce any provision of this Agreement is not a waiver of that provision or of the right to enforce it later.

Counterparts and electronic acceptance. This Agreement may be executed in counterparts, each deemed an original and all together constituting one instrument. Electronic signatures and electronic acceptance are deemed original signatures for all purposes.

Schedule A — Subprocessors

Business Associate engages the following Subprocessors, each of which may Create, receive, maintain, or transmit PHI in support of the Services. All process PHI in the United States unless otherwise noted.

Subprocessor Function Categories of PHI
Google Cloud Platform Application hosting, file storage, encryption key management, and system logging All categories, including patient-uploaded images, audio, and documents
MongoDB Atlas Primary database All categories held in the patient record
Stedi Clearinghouse for eligibility verification, claim submission, and claim status Patient name, date of birth, member and subscriber identifiers, diagnosis and procedure codes, dates of service
Twilio SMS delivery Mobile telephone number and message content, including appointment and adherence reminders
Paubox Encrypted email delivery Email address, name, and message content
Google (Gemini) Clinical text processing and live voice interaction Two distinct paths, described below
ElevenLabs Speech synthesis for exercise guidance Exercise instruction text supplied for narration
Sentry Error monitoring and session replay Diagnostic telemetry and masked session recordings; see below
Inova / NuboHealth Electronic health record interoperability Patient demographics, medical record number, and appointment data retrieved from Covered Entity's EHR
Stripe Billing and payment processing Organization billing contact and payment information; no patient clinical information
Google Maps Platform Address autocomplete Address text entered into address fields

Google (Gemini) — scope of processing. Clinical documentation support and care-journey chat operate on de-identified inputs: direct identifiers are removed before transmission, and the resulting text does not include patient name, date of birth, medical record number, or contact information. Live voice interaction operates differently: where Covered Entity enables voice features, patient speech is streamed directly to Google for real-time processing. Voice recordings are an identifier under 45 C.F.R. § 164.514(b)(2), and this path is therefore a disclosure of PHI rather than de-identified processing.

Analysis of patient-uploaded media. Where enabled, this path transmits the patient's original file — image, audio, or document — rather than a de-identified derivative, and is therefore a disclosure of PHI. It is disabled by default. It operates only where Covered Entity separately and affirmatively authorizes it by acknowledging this capability; that acknowledgement is recorded against this version of the Agreement, and Covered Entity may withdraw it at any time. Text files are read by Business Associate without transmission to Google and are not within this path.

Sentry — scope of processing. Session replay is enabled for a sample of sessions and for sessions in which an error occurs. Text content and media are masked at capture. Diagnostic payloads are filtered to remove known identifier fields before transmission; Business Associate does not warrant that filtering removes every identifier that application code may place into an error message, and treats Sentry as a PHI Subprocessor accordingly.

Processors that do not receive PHI. Business Associate also engages marketing and analytics providers, including Meta Platforms and Google Analytics, in connection with its public website. These providers receive marketing and website-visitor information only. They do not receive PHI, are not engaged in the provision of the Services to Covered Entity, and are not Subprocessors under this Agreement.

Execution

By accepting this Agreement electronically, the Covered Entity and the individual accepting on its behalf represent that the individual is authorized to bind the Covered Entity, and agree to be bound by this Agreement as of the Effective Date with the same force and effect as a handwritten signature. Business Associate (ZeraCorp, Inc.) has authorized this Agreement for electronic acceptance by its customers.

The Agreement ID displayed at acceptance is the SHA-256 digest of this document text and uniquely identifies the version executed.

Contact Us

For questions about this Business Associate Agreement or Zerapy's HIPAA compliance, please contact us:

support@zerapy.ai
Zerapy
11160-C1 South Lakes Dr
Reston, VA 20191
United States