Obligations of the Parties With Respect to Phi Sample Clauses
The "Obligations of the Parties with Respect to PHI" clause defines the responsibilities each party has regarding the handling, protection, and use of Protected Health Information (PHI). Typically, this clause outlines requirements such as maintaining confidentiality, implementing security measures, and restricting access to PHI only to authorized personnel or for permitted purposes. It may also specify procedures for reporting breaches or improper disclosures. The core function of this clause is to ensure compliance with privacy laws like HIPAA and to protect sensitive health information from unauthorized use or disclosure.
Obligations of the Parties With Respect to Phi. 3.1 Uses and Disclosures of PHI by Hythiam. Except as otherwise specified in this B.A. Agreement, Hythiam may make any and all uses and disclosures of PHI necessary to perform its obligations under the Agreement. In addition, unless otherwise limited in this B.A. Agreement, Hythiam may (a) use the PHI in its possession for its proper management and administration and to carry out the legal responsibilities of Hythiam; (b) disclose the Minimum Necessary information in its possession to a third party for the purpose of Hythiam’s proper management and administration or to carry out the legal responsibilities of Hythiam, provided, that such disclosure is required by law or Hythiam obtains reasonable assurances in writing from the third party regarding the confidential handling of such PHI as required under the Privacy and Security Rule; (c) provide Data Aggregation services relating to the health care operations of the Covered Entity; (d) use the PHI to create a Limited Data Set (“LDS”), the use and disclosure of which shall be governed by the Data Use Agreement set forth in 5 of this B.A. Agreement and by the Privacy and Security Rule; and (e) de-identify any and all PHI obtained by Hythiam under this B.A. Agreement, and use such de-identified data, all in accordance with the de-identification requirements of the Privacy and Security Rule.
Obligations of the Parties With Respect to Phi. With regard to use and/or disclosure of PHI, Business Associate agrees to:
a. Not use or disclose PHI other than as permitted or required by the Agreement or as Required
b. Use appropriate safeguards to prevent use or disclosure of the PHI other than as provided for by this Agreement.
c. Mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate or by Business Associate’s Subcontractors in violation of the requirements of this Agreement. Business Associate shall provide all information and take all action reasonably requested by Customer and consistent with HIPAA standards to assist Customer in providing any required Notice and in otherwise investigating and responding to any improper use or disclosure or Security Incident (as defined in HIPAA).
d. Report to Covered Entity within 72 hours any use or disclosure of the PHI not provided for by this Agreement of which it becomes aware or any Security Incident involving the PHI of which it becomes aware. Such notice shall identify each individual whose PHI has been, or is reasonably believed to have been, improperly accessed, acquired or disclosed.
e. Ensure that any agent, including a subcontractor, to whom it provides PHI received from, or created or received by Business Associate on behalf of Covered Entity agrees to the same restrictions and conditions that apply through this Agreement to Business Associate with respect to suchinformation.
f. Provide access, at the request of Covered Entity, and in a prompt and reasonable manner consistent with the HIPAA regulations, to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 CFR § 164.524.
g. Make any amendment(s) to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 CFR § 164.526 at the request of Covered Entity or an Individual, and in a prompt and reasonable manner consistent with the HIPAA regulations.
h. Make internal practices, books, and records, including policies and procedures and PHI, relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity available to the Covered Entity, or to the Secretary, in a prompt and reasonable manner consistent with the HIPAA regulations or designated by the Secretary, for purposes of the Secretary determining Covered Entity's compliance...
Obligations of the Parties With Respect to Phi a. Obligations of Empire Health Care Solutions. With regard to its use and/or disclosure of PHI, Empire Health Care Solutions agrees to:
b. not to use or disclose PHI other than as permitted or required by this Addendum or as required by law. [§164.504 (e)(2)(ii)(A)] c. use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this Addendum. [§164.504 (e)(2)(ii)(B)] d. report to Customer any use or disclosure of PHI not provided for by this Addendum of which Empire Health Care Solutions becomes aware. [§164.504 (e)(2)(ii)(C)]
e. ensure that any agents and subcontractors to whom it provides PHI received from, or created or received by Empire Health Care Solutions [Vendor] on behalf of Customer agree to the same restrictions and conditions set forth in the business associate provisions of the HIPAA Regulations that apply through this Addendum to Empire Health Care Solutions with respect to such information. [§164.504 (e)(2)(ii)(D)] f. within twenty (20) days of receiving a written request from Customer, make available to the Customer PHI necessary for Customer to respond to individuals’ requests for access to PHI about them in the event that the PHI in Empire Health Care Solutions’ possession constitutes a Designated Record Set. [§164.504 (e)(2)(ii)(E)] g. within forty (40) days of receiving a written request from Customer, make available to the Customer PHI for amendment and incorporate any amendments to the PHI in accordance with 45 C.F.R. Part 164 Subpart E (“Privacy Rule”) in the event that the PHI in Empire Health Care Solutions’ possession constitutes a Designated Record Set. [§164.504 (e)(2)(ii)(F)] h. within forty (40) days of receiving a written request from Customer, make available to the Customer the information required for the Customer to provide an accounting of disclosures of PHI as required by the Privacy Rule. [§164.504 (e)(2)(ii)(G)]
i. make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining Customer's compliance with the Privacy Rule. [§164.504 (e)(2)(ii)(H)] j. upon the expiration or termination of an Underlying Contract, return to Customer or destroy all PHI, including such information in possession of Empire Health Care Solutions’ subcontractors, as a result of the Underlying Contract at issue and retain no copies, if it is feasible to do so. If return or destruction is infeasible, Empire Health Care Solution...
Obligations of the Parties With Respect to Phi
