Business Associate Agreement — Kanza CRS Physicians Program
How This Agreement Is Entered Into
This Business Associate Agreement (this “BAA”) is incorporated by reference into the Kanza AI Business Terms Agreement (the “BTA”) and forms part of the Agreement between Kanza AI, Inc. (“Kanza,” as “Business Associate”) and the Kanza CRS Physicians Program participant — the physician or practice identified as Customer under the BTA (“Customer,” as “Covered Entity”).
This BAA takes effect upon Customer’s acceptance at Program onboarding, and in any event before Customer uses any Service to create, receive, maintain, or transmit PHI. Participation in the Kanza CRS Physicians Program is granted only to a clinician with a verified National Provider Identifier (NPI) who has received a formal nomination and invitation from a clinician appointed by Kanza. Electronic acceptance has the same force and effect as a handwritten signature under the federal E-SIGN Act and applicable state UETA. No separate signature page is required.
Applicability
This BAA applies only to the extent that (a) Customer acts as a Covered Entity, or as a Business Associate of another Covered Entity, in creating, receiving, maintaining, or transmitting PHI via the Services, and (b) Kanza, as a result, acts as a Business Associate or Subcontractor under HIPAA. It does not apply to any use of the Services that does not involve PHI.
1. Definitions
Capitalized terms not defined here have the meaning given in 45 C.F.R. Parts 160 and 164 (the “HIPAA Rules”). “PHI” means Protected Health Information that Kanza creates, receives, maintains, or transmits for or on behalf of Customer via the Services, and includes electronic PHI. “Unsuccessful Security Incident” means pings, port scans, unsuccessful log-on attempts, denials of service, and similar attempted but unsuccessful incidents that do not result in unauthorized access, use, or disclosure of PHI.
2. Obligations of Business Associate
2.1 Kanza will not use or disclose PHI other than as permitted by this BAA or the Agreement, or as Required by Law, and will not use or disclose PHI in any manner that would violate the HIPAA Privacy Rule if done by Covered Entity. Kanza will use or disclose only the minimum necessary PHI.
2.2 Kanza will use appropriate safeguards and will comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, consistent with its information security program under Section 5 of the BTA.
2.3 Kanza will report to Customer, without unreasonable delay, any use or disclosure of PHI not permitted by this BAA of which it becomes aware, any Breach of Unsecured PHI under 45 C.F.R. § 164.410, and any Security Incident. This Section constitutes notice of the ongoing occurrence of Unsuccessful Security Incidents, for which no further report is required. A Breach does not include an event that Kanza determines, under 45 C.F.R. § 164.402, carries a low probability that PHI has been compromised. Given the nature of the Services, Kanza may be unable to identify the affected Individuals or the specific PHI involved, and Customer is responsible for that identification.
2.4 Kanza will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on Kanza’s behalf is bound by a written agreement satisfying the applicable subcontractor business-associate requirements of HIPAA, including the restrictions, conditions, and requirements required by 45 C.F.R. §§ 164.308(b), 164.314(a), 164.502(e), and 164.504(e).
2.5 Designated Record Set. To the extent Kanza maintains PHI in a Designated Record Set on Customer’s behalf, Kanza will, upon Customer’s written request, make such PHI available to Customer as necessary for Customer to satisfy its obligations regarding an Individual’s access under 45 C.F.R. § 164.524, amendment under § 164.526, and an accounting of disclosures under § 164.528. Customer makes all determinations regarding an Individual’s request; Kanza makes none.
2.6 Delegated Privacy Rule Obligations. To the extent Kanza is delegated responsibility for an obligation of Customer under Subpart E of 45 C.F.R. Part 164, Kanza will comply with the requirements of Subpart E that apply to Customer in performing that obligation.
2.7 Kanza will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services as required to determine compliance with the HIPAA Rules, subject to applicable legal privileges.
2.8 Kanza will mitigate, to the extent practicable, any harmful effect known to Kanza resulting from a use or disclosure of PHI by Kanza or its subcontractors in violation of this BAA. Kanza will reasonably cooperate with Customer’s mitigation efforts.
3. Permitted Uses and Disclosures by Kanza
3.1 Kanza may use or disclose PHI as necessary to perform the Services and as Required by Law.
3.2 De-identified Data. Kanza may de-identify PHI consistent with 45 C.F.R. § 164.514 and may use and disclose the resulting de-identified data for any purpose, including to provide and improve its products and services.
3.3 Kanza may use PHI for its proper management and administration and to carry out its legal responsibilities, including the development of aggregate usage statistics.
3.4 Kanza may disclose PHI for its proper management and administration or to carry out its legal responsibilities only where Required by Law, or where Kanza obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Kanza of any breach of confidentiality.
3.5 Data Aggregation. Kanza may use PHI to provide Data Aggregation services relating to the health care operations of Customer, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
4. Obligations of Covered Entity
4.1 Customer will obtain any authorization or consent Required by Law before providing PHI to the Services, and is responsible for its inputs as set out in Section 3.3 of the BTA.
4.2 Customer will notify Kanza of any limitation in its notice of privacy practices under 45 C.F.R. § 164.520, any change in or revocation of an Individual’s permission to use or disclose PHI, and any restriction agreed to under § 164.522, in each case to the extent it may affect Kanza’s use or disclosure of PHI.
4.3 Customer will not request Kanza to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Customer, except as permitted under Section 3.
5. Term and Termination
5.1 This BAA takes effect as described above, continues while the Agreement remains in effect, and terminates when all PHI has been returned or destroyed.
5.2 Either party may terminate this BAA for the other party’s material breach that remains uncured following the cure process in Section 8.2 of the BTA.
5.3 Upon termination or expiration, Kanza will return or destroy all PHI it maintains, consistent with the thirty (30) day deletion of Customer Content under Section 8.3 of the BTA, and will retain no copies. Where return or destruction is infeasible, Kanza will extend the protections of this BAA to such PHI and limit further use or disclosure to the purposes that make return or destruction infeasible, for as long as it maintains the PHI. This Section survives termination.
6. General
- 6.1 With respect to PHI, this BAA governs over any conflicting term of the Agreement. In all other respects the BTA controls.
- 6.2 Governing law, venue, and dispute resolution are as set forth in the BTA — the laws of the State of California, arbitration administered by NAM, and the class-action waiver. No separate regime applies to this BAA.
- 6.3 The parties will amend this BAA as necessary for compliance with the HIPAA Rules. Any ambiguity in this BAA will be resolved to permit compliance with the HIPAA Rules.
- 6.4 This BAA confers no rights on any third party. Notices are given as provided in Section 15.10 of the BTA.