Legal

Business Associate Agreement

HIPAA obligations for clinics storing patient information

VGT MEDIA, LLC d/b/a PI Chiro Nexus · Effective August 11, 2026

This Business Associate Agreement (“BAA”) is entered into between the health care provider accepting it (“Covered Entity”) and VGT MEDIA, LLC, a Florida limited liability company, doing business as PI Chiro Nexus (“Business Associate”). It supplements and is incorporated into the Master Service Agreement between the parties (the “Underlying Agreement”).

Covered Entity uses the PI Chiro Nexus platform to create, receive, maintain, or transmit Protected Health Information. This BAA sets out how Business Associate safeguards that information, as required by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 C.F.R. Parts 160 and 164, as amended by the HITECH Act (together, “HIPAA”).

1. Definitions

Terms used but not defined in this BAA have the meanings given to them in HIPAA. Without limiting that, “Breach,” “Covered Entity,” “Designated Record Set,” “Disclosure,” “Electronic Protected Health Information,” “Individual,” “Required By Law,” “Secretary,” “Security Incident,” “Subcontractor,” “Unsecured Protected Health Information,” and “Use” have the meanings assigned in 45 C.F.R. Parts 160 and 164.

“Protected Health Information” or “PHI” means Protected Health Information as defined in 45 C.F.R. § 160.103, limited to information Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity.

2. Permitted Uses and Disclosures

Business Associate may Use or Disclose PHI only:

  • To perform the services described in the Underlying Agreement, including operating, supporting, maintaining, and securing the platform;
  • For the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any Disclosure for those purposes is either Required By Law or made subject to written assurances that the recipient will keep the information confidential, use or further disclose it only as Required By Law or for the purpose for which it was disclosed, and notify Business Associate of any breach of confidentiality;
  • To provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B); and
  • To de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c).

Business Associate will not Use or Disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted above.

Business Associate will not sell PHI, and will not Use or Disclose PHI for marketing, advertising, or its own product development, except as expressly permitted by HIPAA and authorized in writing by Covered Entity. Business Associate will not Use or Disclose PHI to train or improve any machine learning or artificial intelligence model except where the information has first been de-identified in accordance with 45 C.F.R. § 164.514.

Business Associate will limit its Use, Disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b).

3. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to Electronic Protected Health Information, to prevent Use or Disclosure of PHI other than as provided by this BAA. These safeguards include encryption of PHI in transit and at rest, role-based access controls limiting access to personnel with a need to know, authentication controls, and logging of access to systems containing PHI.

4. Subcontractors

Business Associate operates the platform using third-party service providers, including cloud hosting, database, communications, and processing providers. Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA, as required by 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2).

Business Associate remains responsible to Covered Entity for the performance of its Subcontractors with respect to PHI. Business Associate will make available to Covered Entity, on written request, a current list of Subcontractors that process PHI.

5. Reporting

5.1 Breach and Improper Use or Disclosure.

Business Associate will report to Covered Entity any Use or Disclosure of PHI not permitted by this BAA of which it becomes aware, and any Breach of Unsecured Protected Health Information, without unreasonable delay and in no case later than ten (10) business days after Discovery. Discovery occurs as defined in 45 C.F.R. § 164.410(a)(2).

The report will include, to the extent then known and thereafter as it becomes available: the nature of the incident, the Individuals whose PHI was involved, the types of information involved, the date of the incident and of Discovery, and the steps Business Associate is taking to investigate, mitigate, and prevent recurrence. Business Associate will cooperate with Covered Entity in Covered Entity’s assessment of its notification obligations under 45 C.F.R. §§ 164.404–164.408.

5.2 Security Incidents.

Business Associate will report Security Incidents affecting Electronic PHI as set out in Section 5.1. The parties acknowledge that Business Associate’s systems, like all internet-connected systems, routinely experience unsuccessful attempts at unauthorized access such as scans, pings, and blocked login attempts that do not result in unauthorized access to, or Use or Disclosure of, PHI. This paragraph serves as notice of those unsuccessful attempts, and no additional report of them is required.

5.3 Mitigation.

Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a Use or Disclosure of PHI in violation of this BAA.

6. Individual Rights

To the extent Business Associate maintains PHI in a Designated Record Set:

  • Access. Business Associate will make PHI available to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.524, within fifteen (15) business days of a written request.
  • Amendment. Business Associate will make PHI available for amendment and incorporate amendments as directed by Covered Entity, as necessary to satisfy 45 C.F.R. § 164.526, within fifteen (15) business days of a written request.
  • Accounting. Business Associate will maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy 45 C.F.R. § 164.528, within fifteen (15) business days of a written request.

If an Individual makes a request directly to Business Associate under any of the above, Business Associate will forward it to Covered Entity within five (5) business days, and will not respond directly except as directed by Covered Entity or Required By Law.

To the extent Business Associate carries out any obligation of Covered Entity under Subpart E of 45 C.F.R. Part 164, it will comply with the requirements that apply to Covered Entity in performing that obligation.

7. Availability to the Secretary

Business Associate will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity’s compliance with HIPAA. Disclosure to the Secretary under this Section does not waive any applicable privilege.

8. Obligations of Covered Entity

Covered Entity will:

  • Notify Business Associate of any limitation in its notice of privacy practices, of any changes in or revocation of an Individual’s permission to Use or Disclose PHI, and of any restriction on Use or Disclosure agreed to under 45 C.F.R. § 164.522, in each case to the extent it affects Business Associate’s Use or Disclosure of PHI;
  • Obtain any consent, authorization, or permission required for Business Associate to Use and Disclose PHI as contemplated by this BAA and the Underlying Agreement;
  • Be solely responsible for the accuracy, quality, and legality of PHI it or its personnel submit to the platform, and for its own compliance with HIPAA; and
  • Not request Business Associate to Use or Disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as permitted by Section 2.

Covered Entity will submit PHI only to those parts of the platform intended to receive it, and will not enter PHI into free-text fields, support requests, or other features not designated for clinical information.

9. Term and Termination

This BAA takes effect on the Effective Date, or on Covered Entity’s electronic acceptance if later, and continues until all PHI is returned or destroyed as provided below.

Covered Entity may terminate the Underlying Agreement if Business Associate materially breaches this BAA and fails to cure the breach within thirty (30) days of written notice, or immediately if cure is not possible. Business Associate has the same right with respect to a material breach by Covered Entity.

On termination, Business Associate will return or destroy all PHI it maintains, and will require the same of its Subcontractors. Where return or destruction is not feasible, Business Associate will extend the protections of this BAA to the retained PHI and limit further Use and Disclosure to the purposes that make return or destruction infeasible, for so long as it retains the information. Business Associate may retain PHI where retention is Required By Law, subject to the same continuing protections.

The obligations of Business Associate under Sections 2, 3, 4, 5, 7, and this Section survive termination.

10. Miscellaneous

A reference in this BAA to a section of HIPAA means that section as in effect or as amended, and includes any successor provision. The parties will take such action as is necessary to amend this BAA from time to time as is necessary for compliance with HIPAA.

Any ambiguity in this BAA will be resolved in favor of a meaning that permits compliance with HIPAA. In the event of a conflict between this BAA and the Underlying Agreement with respect to PHI, this BAA controls. In all other respects the Underlying Agreement remains in full force.

This BAA creates no rights in any third party. Nothing in this BAA is intended to create, and it does not create, a partnership, joint venture, agency, or employment relationship between the parties.

Covered Entity may accept this BAA electronically through the PI Chiro Nexus platform. Electronic acceptance recorded by the platform, including the identity of the accepting user, the date and time of acceptance, and the originating IP address, constitutes a signed writing and is admissible as evidence of agreement to the same extent as a handwritten signature.

VGT MEDIA, LLC

d/b/a PI Chiro Nexus

500 North Andrews Avenue, Fort Lauderdale, FL 33301

support@vgtmedia.com

HIPAA and privacy inquiries: support@vgtmedia.com

Effective August 11, 2026. Questions: support@vgtmedia.com