Last updated: March 24, 2026
This HIPAA Business Associate Agreement ("HIPAA BAA") is entered into between the entity identified in the applicable Order Form or subscription agreement ("you" or "your") and ConsentStack LLC, a California limited liability company ("ConsentStack," "we," "our," or "us") and is incorporated into the terms governing your use of ConsentStack's services (the "Agreement"). Together with the Agreement, this HIPAA BAA addresses the applicability of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH Act"), and their implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Rules") to the Services.
1. Definitions
Capitalized terms not defined in this HIPAA BAA have the meanings set forth in HIPAA or the Agreement.
"Protected Health Information" or "PHI" means "protected health information" as defined in 45 C.F.R. § 160.103.
"Individual" will have the same meaning as the term "individual" in 45 C.F.R. § 160.103, and will include a person who qualifies as a personal representative in accordance with 45 C.F.R. § 164.502(g).
"Services" means ConsentStack's consent management platform, including the consent banner SDK, dashboard, and related APIs.
2. Scope and Data Architecture
(a) ConsentStack's Services are purpose-built for consent management. The platform does not collect, store, or transmit PHI in the ordinary course of providing the Services. The Services store only pseudonymous consent records consisting of: hashed visitor identifiers, consent state, timestamps, geolocation at the country level (derived from IP address by our infrastructure provider, not the IP address itself), device and browser metadata, page URL, and banner interaction data. The platform does not store names, email addresses, dates of birth, medical record numbers, health plan identifiers, or any clinical, diagnostic, or treatment information.
(b) Based on this architecture, the parties acknowledge that ConsentStack does not create, receive, maintain, or transmit PHI on your behalf in the ordinary course of providing the Services. Accordingly, ConsentStack is not a Business Associate solely by reason of the Services as currently architected.
(c) Notwithstanding the foregoing, ConsentStack agrees to the protective commitments in Section 3 of this HIPAA BAA.
3. ConsentStack's Responsibilities
a. Safeguards
We agree to: (i) not use or further disclose data processed on your behalf other than as permitted by this HIPAA BAA, the Agreement, or as required by law; (ii) implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of all data processed through the Services; (iii) report to you any confirmed breach of security leading to the unauthorized access, acquisition, use, or disclosure of data processed on your behalf within seventy-two (72) hours of discovery; and (iv) require subcontractors that process data on your behalf to maintain data protection obligations no less protective than those in this HIPAA BAA.
b. Access to Records
We agree to make our internal practices, books, and records relating to the use and disclosure of data processed on your behalf available to the Secretary of the Department of Health and Human Services ("Secretary") for the purposes of determining compliance with the HIPAA Rules. Nothing in this Section will be construed as a waiver of any legal privilege or of any protections for trade secrets or confidential commercial information.
c. Data Return and Deletion
Upon termination of the Agreement, we will return or destroy all data processed on your behalf to the extent feasible. If we determine that returning or destroying the data is infeasible, we will extend the protections of this HIPAA BAA to such data and limit further uses to those purposes that make return or destruction infeasible, for as long as we maintain such data.
d. Cooperation
Upon your request, we will cooperate in responding to requests from Individuals or the Secretary that relate to data processed through the Services, to the extent we possess relevant information.
4. Your Responsibilities
a. No PHI Submission
You will not submit, upload, or otherwise transmit PHI to ConsentStack through the Services, including through dashboard fields, API calls, or support communications, unless we have agreed in writing to receive such data.
b. Exported Data
This HIPAA BAA does not apply to data after it has been exported, downloaded, or otherwise extracted from the Services by you or your authorized users. Once you export data from the Services, you are solely responsible for safeguarding that data in accordance with all applicable laws, including the HIPAA Rules.
c. Use of Services with PHI
You are solely responsible for determining whether and how you use the Services in connection with PHI. ConsentStack's consent banners collect only the data elements described in Section 2(a) and are not configurable in a manner that would collect clinical, diagnostic, or treatment information.
5. Material Change in Data Architecture
If we materially change our data architecture in a manner that would result in the creation, receipt, maintenance, or transmission of PHI on your behalf, we will: (i) provide you with at least thirty (30) days' prior written notice; (ii) amend this HIPAA BAA to include the full Business Associate obligations required by 45 C.F.R. § 164.504(e); and (iii) not implement the change until the amended HIPAA BAA is in effect. If you object to such a change, you may terminate the Agreement by providing written notice within thirty (30) days of receiving the change notice.
6. Authority to Terminate for Breach
If you determine that we have violated a material term of this HIPAA BAA, you may terminate this HIPAA BAA and the Agreement in accordance with the Agreement.
7. Effect of Termination
This HIPAA BAA is effective as of the date you accept the Agreement and remains in effect for the duration of the Agreement. Upon termination, the obligations in Section 3(a)(iii) (breach notification) and Section 3(c) (data return and deletion) survive.
8. General
Any ambiguity in this HIPAA BAA will be resolved consistently with the intent to comply with the HIPAA Rules. A reference to a section of the HIPAA Rules means the section as in effect or as amended. Nothing in this HIPAA BAA confers any rights on any third party. This HIPAA BAA supersedes any pre-existing agreements between the parties relating to HIPAA. To the extent of any conflict between this HIPAA BAA and the Agreement, the terms of this HIPAA BAA will govern.