Effective September 29, 2026 · Version 2026-09-29
Business Associate Agreement
This Business Associate Agreement (“BAA”) is between the practice that accepts it (the “Practice,” a covered entity under HIPAA) and Anansi Technology LLC (“Anansi”), which operates CogniCare and acts as the Practice’s business associate. It applies whenever CogniCare creates, receives, maintains or transmits protected health information on the Practice’s behalf. It forms part of the CogniCare Terms of Service, and the practice owner accepts it on the Practice’s behalf.
Capitalized terms not defined here — including Protected Health Information (“PHI”), Breach, Security Incident and Unsecured PHI — have the meanings given in the HIPAA Privacy, Security and Breach Notification Rules (45 C.F.R. Parts 160 and 164).
1. How Anansi may use and disclose PHI
Anansi may use and disclose PHI only:
- to provide the Service to the Practice — for example, storing client records, generating the AI drafts the Practice requests, sending messages the Practice initiates (such as consent forms and appointment reminders), and preparing client invoices;
- for Anansi’s proper management and administration, or to carry out its legal responsibilities, as permitted by 45 C.F.R. § 164.504(e)(4);
- as required by law.
Anansi will limit its uses and disclosures to the minimum necessary. Anansi will not sell PHI, use it for marketing, or use it to train artificial-intelligence models.
2. Safeguards
Anansi will use appropriate administrative, physical and technical safeguards, and will comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) for electronic PHI, to prevent use or disclosure of PHI other than as this BAA allows. These safeguards include encrypted connections, encryption of sensitive clinical content at rest, access controls that limit each clinician to their assigned clients, email-verified accounts, and audit logs of access to client records.
3. Reporting incidents and breaches
Anansi will report to the Practice any use or disclosure of PHI not allowed by this BAA, any Security Incident, and any Breach of Unsecured PHI, without unreasonable delay and no later than 30 calendar days after discovery. A Breach report will include the information required by 45 C.F.R. § 164.410, as it becomes available.
This section is notice of unsuccessful Security Incidents — such as pings, port scans and blocked login attempts — that do not result in unauthorized access to PHI. No further report of them is required.
4. Subcontractors
Anansi uses subcontractors to run the Service, including cloud hosting, database, file storage, AI model and email delivery providers. Anansi will ensure that every subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to the same restrictions and conditions that apply to Anansi under this BAA, as required by 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2).
5. Individuals’ rights
The Service lets the Practice view, export and amend client records directly, which is how the Practice responds to requests for access (45 C.F.R. § 164.524) and amendment (§ 164.526). Where the Practice needs Anansi’s help with access, amendment or an accounting of disclosures (§ 164.528), Anansi will provide it within 15 days of the Practice’s request. If an individual contacts Anansi directly, Anansi will forward the request to the Practice within 10 business days.
6. The Practice’s obligations
The Practice will:
- obtain any consents and authorizations the law requires before entering PHI, including consent to AI-assisted documentation where required;
- tell Anansi about any restriction or change in an individual’s permission that affects how Anansi may use or disclose PHI;
- enter only the PHI reasonably necessary for the Practice’s use of the Service;
- not ask Anansi to use or disclose PHI in any way the Practice itself could not under HIPAA.
7. Compliance and records
To the extent Anansi carries out any of the Practice’s obligations under the Privacy Rule, it will comply with the requirements that apply to the Practice in performing them. Anansi will make its internal practices, books and records relating to PHI available to the Secretary of Health and Human Services for the purpose of determining compliance with HIPAA.
8. Term and termination
This BAA takes effect when the practice owner accepts it and continues while Anansi holds PHI for the Practice. Either party may terminate it, together with the Practice’s use of the Service, if the other materially breaches it and does not cure the breach within 30 days of written notice.
When the agreement ends, Anansi will, at the Practice’s choice, return the PHI through an export or destroy it, within 30 days. Copies in backups are destroyed on the normal backup cycle. Where return or destruction is not feasible, the protections of this BAA continue to apply for as long as Anansi holds the PHI, and further use and disclosure is limited to the purposes that make return or destruction infeasible.
9. General
- This BAA is interpreted to comply with HIPAA. If HIPAA changes, Anansi will publish an updated version, which the practice owner will be asked to accept at next sign-in.
- Where this BAA and the Terms of Service conflict about PHI, this BAA controls.
- Nothing in this BAA gives rights to anyone other than the Practice and Anansi.
- This BAA is governed by federal law and the laws of the State of Florida.
- Acceptance is recorded electronically with the date, the version accepted and the network address it was accepted from.
10. Contact
Privacy and security questions, or to report a concern: cognicare@anansi.xyz.