Clinician Business Associate Agreement

Version 2.0 — Effective September 10, 2026


1. Parties and Acceptance

This Clinician Business Associate Agreement (this "BAA") is entered into between Kanza AI, Inc., a Delaware corporation ("Business Associate" or "Kanza"), and the individual clinician accepting this BAA in the NeoMD application, acting on their own behalf or on behalf of the solo practice entity they identify at acceptance ("Covered Entity"). This BAA becomes effective as to a given Covered Entity on the date of that clinician's click-through acceptance. The version identifier shown above corresponds to the version presented at the time of acceptance, and acceptance is recorded with the clinician's identity, a timestamp, and the version number.


Eligibility. By accepting this BAA, the clinician represents and warrants that: (a) the clinician is a covered entity under HIPAA in their own right, or is authorized to bind the solo practice entity identified at acceptance as the Covered Entity; (b) the clinician is not accepting this BAA on behalf of an employer, hospital, health system, or other organization, and will not transmit PHI of any such organization to the Services under this BAA; and (c) the clinician will notify Kanza at legal@kanza.ai promptly if any of these representations ceases to be true. If Covered Entity is not a covered entity under HIPAA, the parties nonetheless agree to comply with this BAA as a contractual matter, and clause (b) continues to apply. PHI of an organization that is not the Covered Entity under this BAA may be transmitted to the Services only under a separate agreement between that organization and Kanza.

2. Recitals

WHEREAS, Covered Entity is a "covered entity" as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as amended by the Health Information Technology for Economic and Clinical Health Act ("HITECH") and their implementing regulations at 45 C.F.R. Parts 160 and 164 (collectively, the "HIPAA Regulations");


WHEREAS, Business Associate provides AI clinical decision-support services (the "Services") to Covered Entity under the Clinician Terms of Service at kanza.ai/terms-clinicians (the "Underlying Terms"), and the performance of those Services may involve the creation, receipt, maintenance, or transmission of Protected Health Information ("PHI") on behalf of Covered Entity; and


WHEREAS, the parties enter into this BAA to satisfy the requirements of the HIPAA Regulations, including 45 C.F.R. §164.504(e);


NOW, THEREFORE, the parties agree as follows.

3. Definitions

Capitalized terms used but not defined in this BAA have the meanings given in the HIPAA Regulations, including 45 C.F.R. §§160.103 and 164.501: Breach, Designated Record Set, Electronic PHI ("ePHI"), Individual, Protected Health Information ("PHI"), Privacy Rule, Required by Law, Secretary, Security Incident, Security Rule, Subcontractor, and Unsecured PHI. For purposes of this BAA, PHI and ePHI refer to information Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity.


Additional defined terms:

  1. "De-identified Data" means information de-identified in accordance with 45 C.F.R. §164.514(a)–(c).
  2. "Services" means the NeoMD services provided under the Underlying Terms.
  3. "Underlying Terms" means the Clinician Terms of Service between the parties, as updated from time to time.

4. Permitted Uses and Disclosures by Business Associate

Business Associate may use or disclose PHI only as follows:

  1. (a) as necessary to perform the Services for Covered Entity;
  2. (b) for Business Associate's proper management and administration, provided that any disclosure for this purpose is Required by Law or is made subject to reasonable assurances of confidentiality and notification of breaches from the recipient;
  3. (c) to carry out Business Associate's legal responsibilities;
  4. (d) to provide Data Aggregation services relating to the health-care operations of Covered Entity, as permitted by 45 C.F.R. §164.504(e)(2)(i)(B);
  5. (e) to de-identify PHI in accordance with 45 C.F.R. §164.514(a)–(c), and to use and disclose the resulting De-identified Data without restriction, including to evaluate, train, tune, and improve the Services — this is the mechanism by which Kanza learns from real-world usage of the Services; and
  6. (f) as Required by Law.

5. Prohibited Uses and Disclosures

Business Associate will not use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as expressly permitted by Section 4(b), 4(c), or 4(d). Business Associate will not sell PHI. Business Associate will not use or disclose PHI for marketing purposes. To the extent Business Associate carries out one or more of Covered Entity's obligations under Subpart E of 45 C.F.R. Part 164, Business Associate will comply with the requirements of Subpart E that apply to Covered Entity in the performance of those obligations.

6. Safeguards

Business Associate will implement and maintain administrative, physical, and technical safeguards that comply with the Security Rule and that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI, consistent with 45 C.F.R. §§164.308 through 164.312. These safeguards include encryption of ePHI in transit and at rest, role-based access controls, audit logging, and workforce training on the handling of PHI.

7. Reporting

(a) Impermissible uses and disclosures. Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this BAA of which it becomes aware, without unreasonable delay.


(b) Security Incidents. Business Associate will report to Covered Entity any Security Incident of which it becomes aware, other than Unsuccessful Security Incidents. "Unsuccessful Security Incidents" are trivial, routine events that do not result in unauthorized access to, or unauthorized use, disclosure, modification, or destruction of, ePHI — such as port scans, pings, and failed log-in attempts — and this Section 7(b) constitutes notice of such events, consistent with industry practice; no further individual notice of them is required.


(c) Breaches of Unsecured PHI. Business Associate will report to Covered Entity any Breach of Unsecured PHI without unreasonable delay after discovery, and in no case later than 30 calendar days after discovery. To the extent known at the time of the report (and supplemented as information becomes available), the report will include the identity of the Individuals affected, the categories of PHI involved, and the steps Covered Entity should consider taking in response.

8. Mitigation

Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI by Business Associate in violation of this BAA.

9. Subcontractors

Business Associate will enter into a written agreement with each Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate, requiring the Subcontractor to comply with restrictions and conditions substantially the same as those that apply to Business Associate under this BAA, in accordance with 45 C.F.R. §§164.308(b)(2) and 164.502(e)(1)(ii).

10. Individual Rights

(a) Access. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make PHI in a Designated Record Set available to Covered Entity for access and inspection within 15 business days of Covered Entity's written request, to enable Covered Entity to meet its obligations under 45 C.F.R. §164.524.


(b) Amendment. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate will make amendments to PHI in a Designated Record Set as directed by Covered Entity within 15 business days of Covered Entity's written request, to enable Covered Entity to meet its obligations under 45 C.F.R. §164.526.


(c) Accounting of disclosures. Business Associate will document disclosures of PHI, and information related to such disclosures, as would be required for Covered Entity to respond to a request for an accounting of disclosures under 45 C.F.R. §164.528, and will provide that information to Covered Entity within 30 days of Covered Entity's written request.


(d) Requests received directly. If an Individual submits a request under 45 C.F.R. §§164.524, 164.526, or 164.528 directly to Business Associate, Business Associate will forward the request to Covered Entity within 5 business days.

11. Access by the Secretary

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Covered Entity available to the Secretary for purposes of determining Covered Entity's compliance with the HIPAA Regulations, as required by 45 C.F.R. §164.504(e)(2)(ii)(H).

12. Covered Entity's Obligations

Covered Entity will:

  1. (a) not request Business Associate to use or disclose PHI in any manner that would violate the Privacy Rule if done by Covered Entity;
  2. (b) notify Business Associate of any limitation in Covered Entity's notice of privacy practices under 45 C.F.R. §164.520, and of any restriction on the use or disclosure of PHI that Covered Entity has agreed to under 45 C.F.R. §164.522, in each case to the extent it may affect Business Associate's use or disclosure of PHI;
  3. (c) notify Business Associate of any change in, or revocation of, an Individual's authorization to use or disclose PHI, to the extent it may affect Business Associate's use or disclosure of PHI;
  4. (d) obtain any patient consents, authorizations, or notices required by applicable law or Covered Entity's own policies before submitting PHI to Business Associate;
  5. (e) submit only the minimum PHI necessary for the decision-support purpose for which the Services are used; and
  6. (f) not submit to Business Associate any substance use disorder records subject to 42 C.F.R. Part 2, psychotherapy notes, or other information subject to confidentiality protections more stringent than those of the HIPAA Regulations, unless Business Associate has agreed in writing to receive it.

13. Term

This BAA is effective as of the date of the clinician's click-through acceptance and continues until the earlier of (a) termination of the Underlying Terms, or (b) termination of this BAA by either party under Section 14.

14. Termination

(a) For cause. Either party may terminate this BAA on 30 days' written notice if the other party materially breaches this BAA and fails to cure the breach within the notice period. Notice to Kanza must be sent to legal@kanza.ai; notice to Covered Entity will be sent to the clinician's Account email.


(b) For convenience. Either party may terminate this BAA on 30 days' written notice, delivered as provided in Section 14(a). Termination of this BAA alone does not terminate the Underlying Terms; following termination of this BAA, Covered Entity may continue to use the Services only in the default, non-PHI mode described in the Underlying Terms.

15. Effect of Termination

Upon termination of this BAA, Business Associate will return or destroy all PHI that it maintains in any form, and will retain no copies, if feasible. Business Associate will complete return or destruction of PHI in its active systems within 30 days after termination. PHI in backup or disaster-recovery systems will be deleted in the ordinary course of Business Associate's backup retention cycle, and until then remains subject to the protections of this BAA. Business Associate's backup retention cycle for PHI does not exceed ninety (90) days. Where return or destruction of any PHI is infeasible, Business Associate will extend the protections of this BAA to that PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible, for as long as Business Associate retains the PHI. De-identified Data is not PHI and is not subject to this Section 15.

16. Amendment

The parties will negotiate in good faith to amend this BAA from time to time as necessary for Covered Entity to comply with HIPAA, HITECH, and the HIPAA Regulations. When Business Associate publishes a new version of this BAA, the new version is re-presented to the clinician through the click-through interface in the NeoMD application and takes effect as to that Covered Entity upon the clinician's re-acceptance. If the clinician does not accept a new version within 30 days after it is first presented, Business Associate may terminate this BAA on notice under Section 14, after which Covered Entity may use the Services only in the default, non-PHI mode. A version change to this BAA does not affect the clinician's acceptance of the Underlying Terms.

17. Miscellaneous

Independent contractors. The parties are independent contractors. Nothing in this BAA creates an agency, partnership, joint venture, or employment relationship.


No third-party beneficiaries. Nothing in this BAA confers any rights on any person other than the parties, including any Individual.


Survival. The obligations of Business Associate under Sections 4, 5, and 15, and any other provision that by its nature should survive, survive termination of this BAA for as long as Business Associate retains any PHI.


Interpretation. Any ambiguity in this BAA will be resolved in favor of a meaning that permits the parties to comply with the HIPAA Regulations.


Conflict. In the event of a conflict between this BAA and the Underlying Terms with respect to PHI, this BAA prevails to the extent of the conflict.


Limitation of liability. The disclaimers and limitations of liability in the Underlying Terms apply to claims arising out of or relating to this BAA, except to the extent prohibited by applicable law.


Governing law. This BAA is governed by the same law that governs the Underlying Terms, as set out in the Underlying Terms. Disputes under this BAA are subject to Section 24 of the Underlying Terms.


Notices. Notices under this BAA are given as provided in Section 14(a).

18. Acceptance

This BAA is executed by the clinician's click-through acceptance in the NeoMD application; no handwritten or separate electronic signature is required. Electronic acceptance has the same force and effect as a handwritten signature under the federal Electronic Signatures in Global and National Commerce Act (E-SIGN) and applicable state Uniform Electronic Transactions Act (UETA) provisions. Business Associate's assent is given by its publication of this BAA and its provision of the Services in reliance on the clinician's acceptance. The acceptance record includes the clinician's identity, the timestamp of acceptance, and the BAA version accepted. On request to legal@kanza.ai, Kanza will provide the clinician a countersigned PDF copy of this BAA for their records.