Obligations and Activities of Business Associates Clause Samples

POPULAR SAMPLE Copied 1 times
Obligations and Activities of Business Associates. (1) Business Associate agrees not to use or disclose PHI other than as permitted or required by this Section of the Contract or as Required by Law. (2) Business Associate agrees to use and maintain appropriate safeguards and comply with applicable HIPAA Standards with respect to all PHI and to prevent use or disclosure of PHI other than as provided for in this Section of the Contract and in accordance with HIPAA Standards. (3) Business Associate agrees to use administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of the Covered Entity. (4) Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by Business Associate in violation of this Section of the Contract. (5) Business Associate agrees to report to Covered Entity any use or disclosure of PHI not provided for by this Section of the Contract or any Security Incident of which it becomes aware. (6) Business Associate agrees, in accordance with 45 C.F.R. 502(e)(1)(ii) and 164.308(d)(2), if applicable, to ensure that any subcontractors that create, receive, maintain or transmit PHI on behalf of the Business Associate, agree to the same restrictions, conditions, and requirements that apply to the business associate with respect to such information. (7) Business Associate agrees to provide access (including inspection, obtaining a copy or both), at the request of the Covered Entity, and in the time and manner designated by the Covered Entity, to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 C.F.R. § 164.524. Business Associate shall not charge any fees greater than the lesser of the amount charged by the Covered Entity to an Individual for such records; the amount permitted by state law; or the Business Associate’s actual cost of postage, labor and supplies for complying with the request. (8) Business Associate agrees to make any amendments to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 C.F.R. § 164.526 at the request of the Covered Entity, and in the time and manner designated by the Covered Entity. (9) Business Associate agrees to make internal practices, books, and records, inclu...
Obligations and Activities of Business Associates a. Business Associate agrees not to use or disclose PHI other than as permitted or required by this Section of the Contract or as Required by Law. DocuSign Envelope ID: ECA2080F-F2BD-440A-B380-0243D9E67ACE b. Business Associate agrees to use and maintain appropriate safeguards and comply with applicable HIPAA Standards with respect to all PHI and to prevent use or disclosure of PHI other than as provided for in this Section of the Contract and in accordance with HIPAA Standards. c. Business Associate agrees to use administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic protected health information that it creates, receives, maintains, or transmits on behalf of the Covered Entity. d. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by Business Associate in violation of this Section of the Contract. e. Business Associate agrees to report to Covered Entity any use or disclosure of PHI not provided for by this Section of the Contract or any security incident of which it becomes aware. f. Business Associate agrees in accordance with 45 C.F.R. § 502(e)(1)(ii) and § 164.308(d)(2), if applicable, to ensure that any subcontractor that creates, receives, maintains or transmits PHI on behalf of the Business Associate agrees to the same restrictions, conditions and requirements that apply to the Business Associate with respect to such information. g. Business Associate agrees to provide access (including inspection, obtaining a copy or both), at the request of the Covered Entity, and in the time and manner designated by the Covered Entity, to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 C.F.R. § 164.524. Business Associate shall not charge any fees greater than the lesser of the amount charged by the Covered Entity to an Individual for such records; the amount permitted by state law; or the Business Associate’s actual cost of postage, labor and supplies for complying with the request. h. Business Associate agrees to make any amendments to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 C.F.R. § 164.526 at the request of the Covered Entity, and in the time and manner designated by the Covered Entity. i. Business Associate agree...
Obligations and Activities of Business Associates. Business Associate agrees to comply with the provisions applicable tobusiness associates” imposed by HIPAA Rules, including the following:
Obligations and Activities of Business Associates. Business Associate agrees not to use or disclose PHI other than as permitted or required by this Section of the Contract or as Required by Law. Business Associate agrees to use and maintain appropriate safeguards and comply with applicable HIPAA Standards with respect to all PHI and to prevent use or disclosure of PHI other than as provided for in this Section of the Contract and in accordance with HIPAA Standards. Business Associate agrees to use administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic protected health information that it creates, receives, maintains, or transmits on behalf of the Covered Entity. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by Business Associate in violation of this Section of the Contract. Business Associate agrees to report to Covered Entity any use or disclosure of PHI not provided for by this Section of the Contract or any security incident of which it becomes aware. Business Associate agrees in accordance with 45 C.F.R. § 502(e)(1)(ii) and § 164.308(d)(2), if applicable, to ensure that any subcontractor that creates, receives, maintains or transmits PHI on behalf of the Business Associate agrees to the same restrictions, conditions and requirements that apply to the Business Associate with respect to such information.
Obligations and Activities of Business Associates. Business Associate: Acknowledges and agrees that all PHI that is created or received by Covered Entity and disclosed or made available in any form, including paper record, oral communication, audio recording, and electronic display by Covered Entity or its operating units to Business Associate or is created or received by Business Associate on Covered Entity’s behalf shall be subject to this Agreement. In accordance with 45 CFR 164.308(b) and 164.502(e), will ensure that its agents, including a Subcontractor, to whom it provides PHI received from or created by Business Associate on behalf of Covered Entity, agrees to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information. In addition, Business Associate agrees to take reasonable steps to ensure that its employees’ or agents’ actions or omissions do not cause Business Associate to breach the terms of this Agreement. Will implement appropriate technical, physical, and administrative safeguards to (1) prevent the use or disclosure of PHI other than as permitted in this Agreement; (2) reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, maintains or transmits on behalf of Covered Entity; and (3comply with the requirements set forth in 45 C.F.R. Sections 164.308, 164.310, 164.312, and 164.316, as may be amended from time to time. Agrees to report to covered entity as soon as practicable but no later than five (5) business days after any discovery of (1) any use or disclosure of PHI not permitted under this Agreement of which it becomes aware or reasonably should have been aware; and (2) any Security Incident of which Business Associate becomes aware or reasonably should have been aware. The parties acknowledge and agree that notice to the Covered Entity is not required for Unsuccessful Security Incidents. Unsuccessful Security Incident means, without limitation, pings and other broadcast attacks on Business Associate’s firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and any combination of the above, so long as no such incident results in unauthorized access, use or disclosure of PHI. Agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Agreement. Agrees, within ten (10) business days of written request from Covered Ent...
Obligations and Activities of Business Associates. A) Business Associate agrees not to use or disclose PHI other than as permitted or required by this Section of the Contract or as Required by Law. B) Business Associate agrees to use appropriate safeguards to prevent use or disclosure of PHI other than as provided for in this Section of the Contract. C) Business Associate agrees to use administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic protected health information that it creates, receives, maintains, or transmits on behalf of the Covered Entity. DRAFT D) Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by Business Associate in violation of this Section of the Contract. E) Business Associate agrees to report to Covered Entity any use or disclosure of PHI not provided for by this Section of the Contract or any security incident of which it becomes aware. F) Business Associate agrees to insure that any agent, including a subcontractor, to whom it provides PHI received from, or created or received by Business Associate, on behalf of the Covered Entity, agrees to the same restrictions and conditions that apply through this Section of the Contract to Business Associate with respect to such information. G) Business Associate agrees to provide access, at the request of the Covered Entity, and in the time and manner agreed to by the parties, to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 C.F.R. §164.524. H) Business Associate agrees to make any amendments to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 C.F.R. §164.526 at the request of the Covered Entity, and in the time and manner agreed to by the parties. I) Business Associate agrees to make internal practices, books, and records, including policies and procedures and PHI, relating to the use and disclosure of PHI received from, or created or received by, Business Associate on behalf of Covered Entity, available to Covered Entity or to the Secretary in a time and manner agreed to by the parties or designated by the Secretary, for purposes of the Secretary determining Covered Entity’s compliance with the Privacy Rule. J) Business Associate agrees to document such disclosures of PHI and information related to such...
Obligations and Activities of Business Associates. Each Business Associate agrees to: (a) Not use or disclose PHI other than as permitted or required by this Agreement, or as required by law. (b) Use appropriate safeguards to prevent use or disclosure of the PHI other than as provided for by this Agreement. (c) Report to Covered Entity any use or disclosure of PHI or EPHI not permitted by this Agreement of which it becomes aware or should have known, including any Security Incidents in which there is a successful unauthorized access, use, disclosure, modification, or destruction of unsecured EPHI. Business Associate will make the report to the Covered Entity’s Privacy Official and Security Officer or to an authorized person in the Covered Entity’s legal department as soon as reasonably practicable. This report will include at least the following information: (a) the nature of the non-permitted or violating use or disclosure; and (b) the PHI and EPHI used or disclosed. (d) Notice is hereby deemed provided by Business Associates to Covered Entity for all unsuccessful attempts of an unauthorized access, disclosure, use, modification or destruction of EPHI. No further notice shall be required by Business Associates for any such unsuccessful attempts. (e) Develop, implement, maintain, and use appropriate safeguards to prevent any use or disclosure of the PHI or EPHI other than as provided by this Agreement, and to implement administrative, physical, and technical safeguards as required by sections 164.308, 164.310, 164.312 and 164.316 of title 45, Code of Federal Regulations and HITECH to protect the confidentiality, integrity, and availability of EPHI or PHI that Business Associate creates, receives, maintains, or transmits, in the same manner that such sections apply to the Covered Entity. See HITECH § 13401. (f) Comply with any additional requirements of Title XIII of HITECH that relate to privacy and security and that are made applicable with respect to covered entities. See HITECH § 13401. (g) Adopt the technology and methodology standards required in any guidance issued by the Secretary pursuant to HITECH §§ 13401-13402. (h) Mitigate any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Agreement and notify Covered Entity of any breach of Unsecured PHI, as required under HITECH § 13402. (i) In the case of a breach of Unsecured PHI, following the discovery of a breach of such information, notify Covered Entity of ...
Obligations and Activities of Business Associates