HIPAA Security Sample Clauses
The HIPAA Security clause establishes requirements for protecting electronic protected health information (ePHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA). It typically obligates parties handling ePHI to implement administrative, physical, and technical safeguards such as encryption, access controls, and regular security assessments. By setting these standards, the clause ensures that sensitive health data is kept confidential and secure, thereby reducing the risk of unauthorized access or data breaches.
HIPAA Security. Doctor agrees that:
a. Doctor shall implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of Enrollee electronic Protected Health Information (“e-PHI”) that Doctor creates, receives, maintains or transmits on behalf of CCMI or any health plan company, as required by 45 C.F.R. Part 164 (the “Security Rules”).
b. Doctor shall ensure that any agent, including a subcontractor, to whom Doctor provides e-PHI agrees to implement reasonable and appropriate safeguards to protect e-PHI, and
c. Doctor shall report to CCMI any security incident involving e-PHI of which Doctor becomes aware. The Security Rules define a “Security Incident” as an attempted or successful unauthorized access, use, disclosure, modification or destruction of information or interference with system operations in an information system, involving e-PHI that is created, received, maintained or transmitted by or on behalf of Party. Since the Security Rules include attempted unauthorized access, use, disclosure, modification or destruction of information, CCMI needs to have notification of attempts to bypass electronic security mechanisms. Therefore, the Parties agree to the following reporting procedures: Security Incidents that result in unauthorized access, use, disclosure, modifications or destruction of information or interference with system operations (“Successful Security Incidents”) and for Security Incidents that do not so result (“Unsuccessful Security Incidents”).
i. For Unsuccessful Security Incidents, the Parties agree that this paragraph constitutes notice of such Unsuccessful Security Incidents.
ii. For Successful Security Incidents, Doctor shall give notice to CCMI not more than five (5) days after Doctor learns of the Successful Security Incident.
HIPAA Security. The “HIPAA Security Rule” means the Security Standards published on February 20, 2003 at 68 Fed. Reg. 8334 et seq. (45 C.F.R. Parts 160, 162, and 164) as hereafter amended, and “ePHI” means electronic Protected Health Information, as defined in the HIPAA Security Rule that is created, received, maintained, or transmitted by or on behalf of OLIC with regard to the use and/or disclosure of ePHI. Beginning no later than the compliance date applicable to OLIC under the HIPAA Security Rule (April 20, 2005), You agree as follows:
