Business Associate Agreement
Version 2026-10-09. This agreement is accepted electronically by the account owner at sign-up, on behalf of the customer organization.
1. Parties and purpose
This Business Associate Agreement ("BAA") is between the customer organization that creates an account ("Covered Entity") and the operator of xStackHost Fax ("Business Associate"). It applies whenever the Covered Entity uses the service to transmit, receive or store Protected Health Information ("PHI") as defined in 45 CFR 160.103. Terms not defined here have the meanings given in the HIPAA Privacy, Security and Breach Notification Rules.
2. Permitted uses and disclosures
Business Associate may use and disclose PHI only to provide the fax service to the Covered Entity, as required by law, and for its own proper management and administration as permitted by 45 CFR 164.504(e)(4). Business Associate will not use or disclose PHI in any way that would violate the Privacy Rule if done by the Covered Entity, and will not sell PHI or use it for marketing.
3. Safeguards
Business Associate will use appropriate administrative, physical and technical safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, to prevent use or disclosure of PHI other than as this BAA allows. These include encryption of stored documents, access controls, unique user identification, automatic logoff and audit logging.
4. Reporting
Business Associate will report to the Covered Entity any use or disclosure of PHI not permitted by this BAA, any Security Incident, and any Breach of Unsecured PHI, without unreasonable delay and no later than 30 days after discovery, with the information required by 45 CFR 164.410.
5. Subcontractors
Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions and conditions that apply to Business Associate under this BAA.
6. Individual rights and records
Within 15 days of a written request, Business Associate will make PHI in its possession available to the Covered Entity so that the Covered Entity can meet its obligations under 45 CFR 164.524, 164.526 and 164.528. The in-product audit trail documents disclosures made through the service. Business Associate will make its internal practices and records relating to PHI available to the Secretary of Health and Human Services to determine compliance.
7. Covered Entity responsibilities
The Covered Entity is responsible for the accuracy of destination fax numbers, for managing its users and their access, for safeguarding its sign-in credentials and API keys, and for having any consents or authorizations required for the PHI it sends.
8. Term and termination
This BAA is in effect for as long as the Covered Entity has an account. Either party may terminate the account if the other materially breaches this BAA and does not cure the breach within 30 days. On termination Business Associate will return or destroy all PHI it maintains for the Covered Entity; where that is not feasible, the protections of this BAA continue to apply to the retained PHI.
9. General
If this BAA conflicts with any other agreement between the parties, this BAA controls with respect to PHI. Ambiguities are resolved in favor of compliance with HIPAA.