Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHI, Business Associate agrees to: (a) use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) or as otherwise Required by Law; (b) implement and use appropriate technical, physical and administrative safeguards to (i) prevent use or disclosure of PHI other than as permitted or required by this B.A. Agreement; (ii) reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316; (c) promptly report to Covered Entity: (i) any use or disclosure of PHI of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) any Security Incident of which Business Associate becomes aware; (d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date; (e) require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI; (f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule; (g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual; (h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement; (i) provide access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with the requirements of 45 C.F.R. § 164.524; (j) in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date; (k) to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. § 164.526; (l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date; (m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date; (n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date; (o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and (p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a).
Appears in 3 contracts
Sources: Business Associate Agreement, Business Associate Agreement, Business Associate Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHI, Business Associate agrees to:
(a) : use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) or as otherwise Required by Law;
(b) ; implement and use appropriate technical, physical and administrative safeguards to (i) prevent use or disclosure of PHI other than as permitted or required by this B.A. Agreement; (ii) reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) ; promptly report to Covered Entity: (i) any use or disclosure of PHI of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) any Security Incident of which Business Associate becomes aware;
(d) ; without unreasonable delay and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date;
(e) ; require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;
(f) ePHI; make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule;
(g) ; within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;
(h) ; mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
(i) ; provide access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with the requirements of 45 C.F.R. § 164.524;
(j) ; in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date;
(k) ; to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. § 164.526;
(l) ; request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) ; not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) ; and not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) . not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a).
Appears in 2 contracts
Sources: Business Associate Agreement, Business Associate Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of Protected Health Information (PHI), Business Associate agrees to:
(a) 2.1 not use and/or disclose PHI only except as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement BAA and/or the Agreement, and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) ), or as otherwise Required by Law;; except that, to the extent Business Associate is to carry out Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of those obligations.
(b) 2.2 implement and use appropriate technicaladministrative, physical and administrative technical safeguards and comply with applicable Security Rule requirements with respect to (i) Electronic Protected Health Information, to prevent use or disclosure of PHI other than as permitted or required provided for by this B.A. BAA and/or the Agreement; (ii) reasonably and appropriately protect the confidentiality.
2.3 without unreasonable delay, integrity, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) promptly report to Covered Entity: Entity (i) any use or disclosure of PHI not provided for by this BAA and/or the Agreement, of which it becomes aware that is not permitted by this B.A. Agreementin accordance with 45 C.F.R. 164.504(e)(2)(ii)(C); and/or (ii) any Security Incident of which Business Associate becomes aware;aware in accordance with 45 C.F.R. 164.314(a)(2)(i)(C).
(d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery2.4 with respect to any use or disclosure of Unsecured PHI not permitted by the Privacy Rule that is caused solely by Business Associate’s failure to comply with one or more of its obligations under this BAA, Covered Entity hereby delegates to Business Associate the responsibility for determining when any such incident is a Breach. In the event of a Breach, Business Associate shall notify (i) provide Covered Entity with written notification, and (ii) provide all legally required notifications to Individuals, HHS and/or the media, on behalf of a Breach of any Unsecured PHI all Covered Entity, in accordance with 42 U.S.C. § 17932(b45 C.F.R. 164 (Subpart D). Business Associate shall pay for the reasonable and actual costs associated with those notifications.
2.5 in accordance with 45 C.F.R. 164.502(e)(1)(ii) as and 45 C.F.R. 164.308(b)(2), ensure that any subcontractors of its Compliance Date;
(e) require all of its subcontractors and agents Business Associate that create, receive, maintain, maintain or transmit PHI to on behalf of Business Associate agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; Associate with respect to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;PHI.
(f) 2.6 make available its internal practices, books, books and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule;.
(g) within thirty (30) days 2.7 after receiving a written request from Covered EntityEntity or an Individual, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Datethe Individual, in accordance with 42 U.S.C. 17935(c)45 C.F.R. 164.528.
2.8 after receiving a written request from Covered Entity or an Individual, and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
(i) provide access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to Set about an Individual, in accordance with the requirements of 45 C.F.R. § 164.524;.
(j) in the event that Business Associate in connection with the Services uses 2.9 after receiving a written request from Covered Entity or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date;
(k) to the extent that the make PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI Set about an Individual available for amendment and incorporate any amendments to the PHI as directed by Covered EntityPHI, all in accordance with 45 C.F.R. § 164.526;
(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a).
Appears in 2 contracts
Sources: Administrative Services Agreement, Administrative Services Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHI, Business Associate hereby agrees toto do the following:
(a) 2.1.1 Not use and/or or disclose PHI only as necessary to provide the Services, specifically other than as permitted or required by this B.A. Agreement or as Required by Law.
2.1.2 Use appropriate safeguards, and in compliance comply with each applicable requirement Subpart C of 45 C.F.R. § 164.504(e) or as otherwise Required by Law;
(b) implement and use appropriate technicalPart 164 with respect to electronic PHI, physical and administrative safeguards to (i) prevent use or disclosure of PHI other than as permitted or required provided for by this B.A. Agreement; (ii) reasonably and appropriately protect the confidentiality.
2.1.3 Report, integrityin writing, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) promptly report to Covered Entity: Entity within five (i5) business days any use or disclosure of PHI not provided for by this Agreement of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) and any Security Incident security incident of which Business Associate it becomes aware;
(d) without unreasonable delay , including breaches of unsecured PHI as required at 45 C.F.R. § 164.410, and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify cooperate with Covered Entity of a Breach of in any Unsecured PHI all in mitigation or breach reporting efforts.
2.1.4 In accordance with 42 U.S.C. 45 C.F.R. §§ 17932(b164.502(e)(1)(ii) as of its Compliance Date;
(e) require all of its and 164.308(b)(2), if applicable, ensure that any subcontractors and agents that create, receive, maintain, maintain or transmit PHI to on behalf of Business Associate agree, in writing, to the same restrictions restrictions, conditions and conditions on the use and/or disclosure of PHI requirements that apply to Business Associate; Associate with respect to the extent such information.
2.1.5 Ensure that any agent or subcontractor to whom Business Associate provides ePHI PHI, as well as Business Associate, not provide, transmit or export PHI beyond the borders of the United States of America for any purpose or permit anyone located outside the borders of the United States of America access to PHI.
2.1.6 Within five (5) business days of a subcontractor or agentrequest by Covered Entity, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;
(f) make available PHI in a designated record set, if applicable, to Covered Entity as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.524.
2.1.7 Within five (5) business days, make any amendment(s) to PHI in a designated record set, if applicable, as directed or agreed to by Covered Entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.526.
2.1.8 As applicable, maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.528.
2.1.9 To the extent Business Associate is to carry out one or more of Covered Entity’s obligation(s) under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s).
2.1.10 Upon request, make its internal practices, books, books and records relating to the use and disclosure of PHI available to the Secretary and to Covered Entity for purposes of determining Covered Entity’s compliance with the Privacy Rule;HIPAA Rules.
(g) within thirty (30) days after receiving a written request from Covered Entity, make available information 2.1.11 Comply with the minimum necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as requirements under the HIPAA Rules.
2.1.12 Provide all of its Compliance Date, in accordance with 42 U.S.C. 17935(c), employees and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate members of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
(i) provide its workforce who will have access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, with general HIPAA-related training and education prior to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with allowing the requirements of 45 C.F.R. § 164.524;
(j) in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, employees and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as members of its Compliance Date;
(k) workforce access to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. § 164.526;
(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a)PHI.
Appears in 2 contracts
Sources: Business Associate Agreement, Business Associate Agreement
Responsibilities of Business Associate. 2.1 Business Associate acknowledges that it will create, receive, use and/or disclose PHI and CDI on University’s behalf solely to provide the Services in accordance with the Agreement. Without limiting the foregoing sentence, Business Associate may use or disclose PHI and CDI for the purposes of performing its obligations under any existing agreements between University and Business Associate involving the use or disclosure of PHI and CDI to the extent that such purposes are consistent with FERPA, HIPAA and ARRA. Further, Business Associate agrees that it shall only use and/or disclose University’s PHI and CDI in accordance with: (a) applicable requirements of applicable Federal and state laws, rules and regulations; and (b) the terms of this Agreement and any subsequent written amendments thereto executed by the parties. In addition, Business Associate may use or disclose PHI for the proper management and administration of the Business Associate, as permitted by, and subject to, the requirements of HIPAA (including, without limitation, the minimum necessary rule). With regard to its use and/or disclosure of PHIPHI and CDI, Business Associate agrees to:
(a) use and/or disclose PHI and CDI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) or as otherwise Required required by Law;
(b) implement and use appropriate technical, physical and administrative safeguards to (i) prevent use or disclosure of PHI and CDI other than as permitted or required by this B.A. AgreementAgreement or the Law; (ii) reasonably and appropriately protect the confidentiality, integrity, and an availability of the ePHI that it creates, maintains, or transmits transits on behalf of the Covered EntityUniversity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) promptly report to Covered EntityUniversity in writing: (i) any use or disclosure of PHI or CDI of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) any Security Incident of which Business Associate becomes aware;
(d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery, Business Associate . Such report shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date;
(e) require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;
(f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule;
(g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
identify: (i) provide access (at the request nature of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with the requirements of 45 C.F.R. § 164.524;
(j) in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date;
(k) to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. § 164.526;
(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, unauthorized use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b(ii) as of its Compliance Date;
the PHI or CDI used or disclosed, (miii) not directly who made the unauthorized use or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at received the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a).unauthorized disclosure,
Appears in 2 contracts
Sources: Business Associate Agreement, Business Associate Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHI, Business Associate agrees to:
(a) 2.1 use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement Addendum, and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) or as otherwise Required by Law;.
(b) 2.2 implement and use appropriate technicaladministrative, physical and administrative technical safeguards to (i) prevent use or disclosure of PHI other than as permitted or required by this B.A. AgreementAddendum; (ii) reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it Business Associate creates, receives, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the Security Rule requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;.
(c) promptly 2.3 without unreasonable delay, and in any event on or before the next business day after the date of its discovery by Business Associate, report to Covered Entity: (i) any use or disclosure of PHI not provided for by this Addendum of which it becomes aware that is not permitted by this B.A. Agreementin accordance with 45 C.F.R. § 164.504(e)(2)(ii)(C); and/or (ii) any Security Incident of which Business Associate becomes aware;
(d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date;
(e) require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;
(f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule;
(g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
(i) provide access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with the requirements of 45 C.F.R. § 164.524;
(j) in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date;
(k) to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all aware in accordance with 45 C.F.R. § 164.526;164.314(a)(2)(C).
(l) request2.4 without unreasonable delay, use and/or disclose only and in any event on or before the minimum amount next business day after the date of PHI necessary to accomplish the purpose its discovery by Business Associate, notify Covered Entity of the requestany incident that involves an unauthorized acquisition, use access, use, or disclosure; provideddisclosure of PHI, that even if Business Associate believes the incident will not rise to the level of a Breach. The notification shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entityinclude, to comply with requests by Individuals not the extent possible, and shall be supplemented on an ongoing basis with: (i) the identification of all individuals whose Unsecured PHI was or is believed to send PHI to a Health Plan in accordance with 42 USC 17935(a).have been involved,
Appears in 2 contracts
Sources: Agent Contract, Agent Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHI, the Business Associate hereby agrees toto do the following:
(a) use 2.3.1 Use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement Addendum, HIPAA and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) HIPAA Rules, or as otherwise Required by Law;
(b) implement and use appropriate technical, physical and administrative safeguards to (i) prevent use or disclosure of PHI other than as permitted or required by this B.A. Agreement; (ii) reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI law. Business Associate agrees that it createswill not use or disclose PHI in any manner that violates federal law, maintainsincluding but not limited to HIPAA and any regulations enacted pursuant to its provisions, or transmits on behalf applicable provisions of Washington State law. The Business Associate agrees that it is subject to and directly responsible for full compliance with the Privacy Rule that applies to the Business Associate to the same extent as the Covered Entity; and (iii) as .
2.3.2 Use commercially reasonable efforts to maintain the security of the Compliance Date PHI and to prevent unauthorized use and/or disclosure of 42 U.S.C. § 17931such PHI, comply with including, but not limited to the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;following:
(c) promptly report 2.3.3 Business Associate shall apply the HIPAA Minimum Necessary standard to Covered Entity: (i) any use or disclosure of PHI necessary to achieve the purposes of which it becomes aware that is not permitted by this B.A. the Underlying Agreement; and/or . See 45 C.F.R. 164.514(d)(2) through (ii) any Security Incident of which Business Associate becomes aware;d)(5).
(d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date;
(e) require 2.3.4 Require all of its employees, representatives, subcontractors and agents that create, receive, maintain, or transmit PHI or use or have access to agree, PHI under the Underlying Agreement to agree in writing, writing to adhere to the same restrictions and conditions on the use and/or disclosure of PHI that apply herein, including the obligation to Business Associate; return or destroy the PHI if feasible, as provided under Sections 5.4 and 5.5 of this
2.3.5 Promptly report to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;
(f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule;
(g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
(i) provide access (at the request designated privacy officer of the Covered Entity, and in any use and/or disclosure of the time and manner designated PHI that is not permitted or required by Covered Entitythis Addendum by telephoning the privacy officer within twenty-four (24) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with the requirements hours of 45 C.F.R. § 164.524;
(j) in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record becoming aware of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entityit, and in the time and manner designated by Covered Entity) providing a written report of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(eunauthorized disclosure within five (5) as of its Compliance Date;
(k) to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. § 164.526;
(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a)business days.
Appears in 1 contract
Sources: Professional Services Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHIProtected Health Information, Business Associate hereby agrees to:
(a) use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) or as otherwise Required by Law;
(b) implement and use appropriate technical, physical and administrative safeguards to (i) prevent Not use or disclosure of PHI disclose Protected Health Information other than as permitted or required by this B.A. Agreement or as otherwise required by law;
(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to Electronic Protected Health Information, to prevent the use or disclosure of the Protected Health Information other than as provided for by this Agreement; ;
(iic) Implement and comply with (and ensure that its subcontractors implement and comply with) the standards set forth at Subpart C of 45 CFR Part 164, to reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) promptly report to Covered Entity: (i) any use or disclosure of PHI of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) any HIPAA Security Incident of which Business Associate becomes awareRule;
(d) without unreasonable delay Establish and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date;
(e) require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;
(f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary procedures for purposes of determining Covered Entity’s compliance with the Privacy Rule;
(g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigatemitigating, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate Protected Health Information that violates the requirements of this Agreement;
(e) Report to the designated privacy officer of Plan, in writing, any use and/or disclosure of the Protected Health Information that is not permitted or required by the requirements this Agreement of this B.A. Agreementwhich Business Associate becomes aware within three (3) calendar days of Business Associate’s discovery of such unauthorized use and/or disclosure, including breaches of unsecured Protected Health Information as required at 45 CFR § 164.410, and any security incident of which it becomes aware;
(if) provide access (at the request In accordance with 45 CFR Parts 164.502(e)(1)(ii) and 164.308(b)(2), require and ensure that all of the Covered Entityits employees, representatives, and agents, including subcontractors, that create, receive, maintain, transmit, use, or have access to Protected Health Information under this Agreement to agree in writing to adhere to the time same restrictions, conditions, and manner designated requirements that apply to the business associate with respect to such information on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as provided under Section 5.3 hereof;
(1) Implement and maintain sanctions against any agent or subcontractor that violates such restrictions and conditions and mitigate the effects of any such violation;
(g) Provide access, within ten (10) calendar days of receipt by Covered Entity) Business Associate of a request by Plan, to PHI Protected Health Information in a Designated Record Set, to Covered Entity Plan or, as directed by Covered EntityPlan, to an Individual, or Individual’s designee in accordance with order to meet the requirements of under 45 C.F.R. § 164.524.
(h) Make any amendment(s) to Protected Health Information in a Designated Record Set that Plan directs or agrees to pursuant to 45 C.F.R. § 164.526 at the request of Plan or an Individual, within ten (10) calendar days of receipt by Business Associate of such request, or to take other measures as necessary to satisfy covered entity’s obligations under 45 CFR Part 164.526;
(1) If any Individual requests an amendment to Protected Health Information directly from Business Associate or its agent or subcontractor, Business Associate must notify Plan in writing within five (5) calendar days of receipt of the request.
(2) Any denial of amendment of Protected Health Information maintained by Business Associate or its agent or subcontractor shall be the responsibility of Plan;
(i) Make available all records, books, agreements, and policies and procedures relating to the use and/or disclosure of Protected Health Information received from, created, or received by Business Associate on behalf of Plan, available to Plan, or at the request of Plan to the Secretary of the U.S. Department of Health and Human Services (“HHS”), in a time and manner designated by Plan or the Secretary, for purposes of the Secretary determining Plan's compliance with the HIPAA Regulations, subject to attorney-client and other applicable legal privileges;
(j) in Within ten (10) calendar days of receiving a written request from Plan, make available to Plan during normal business hours at Business Associate’s offices all records, books, agreements, and policies and procedures relating to the event that use and/or disclosure of Protected Health Information for purposes of enabling Plan to determine Business Associate in connection Associate’s compliance with the Services uses or maintains an Electronic Health Record terms of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Datethis Agreement;
(k) Maintain and make available within ten (10) calendar days of receiving a written request from Plan, the information required to provide an accounting of disclosures of Protected Health Information and information related to such disclosures as would be required for Plan to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR Part 164.528, or an accounting of disclosures of Protected Health Information from an Electronic Health Record in accordance with the HITECH Amendment; Business Associate shall retain such documentation during the term of this Agreement and for a period of ten (10) years following termination of the Agreement. Business Associate shall not disclose Protected Health Information unless directed in writing by Plan or as expressly permitted under this Agreement of the Services Agreement.
(l) Ensure that any agent, group provider or subcontractor to whom Business Associate provides Electronic Protected Health Information agrees to implement reasonable and appropriate safeguards to protect such Electronic Protected Health Information; provided however, that Business Associate shall not assign, delegate, or subcontract any obligation of Business Associate owed by Plan in violation of this Agreement.
(m) To the extent the Business Associate is to carry out one or more of Plan’s obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that would apply to the extent Plan in the performance of such obligation(s);
(n) Immediately report to Plan any Security Incident, of which Business Associate becomes aware.
(o) Authorize termination of the Service Agreement by Plan if Plan determines that Business Associate has violated a material term of this Agreement.
(p) Business Associate understands that pursuant to the HITECH Amendment, it is subject to the HIPAA Privacy and Security Rules in a similar manner as the rules apply to Plan. As a result, Business Associate agrees to take all actions necessary to comply with the HIPAA Privacy and Security Rules for business associates as revised by the HITECH Amendment. Business Associate agrees to the following in connection with the breach notification requirements of the HITECH Amendment:
1.1 If Business Associate discovers a breach of unsecured PHI, as those terms are defined by 45 CFR 164.202, Business Associate shall notify Plan without unreasonable delay and within 5 calendar days after discovery. For breaches with potential for a significant beneficiary harm (i.e., a high likelihood that the information was used inappropriately) or situations that may have heightened public or media scrutiny (i.e. a higher number of beneficiaries affected or particularly egregious breaches), Business Associate will report to Plan within 24 hours of learning of breaches that fall in these categories or at the time of reporting may appear to fall into these categories. For this purpose, discovery means the first day on which the breach is known to Business Associate or by exercising reasonable diligence would have been known to Business Associate. Business Associate shall be deemed to have knowledge of a breach if the breach is known or by exercising reasonable diligence would have been known to any person, other than the person committing the breach, who is an employee, officer, subcontractor or other agent of Business Associate. The notification must include identification of each individual whose unsecured PHI has been, or is reasonably believed to have been breached, and any other available information in Business Associate’s possession constitutes which the Plan is required to include in the individual notice contemplated by 45 CFR 164.404.
1.2 Notwithstanding the immediately preceding paragraph, Business Associate shall assume the individual notice obligation specified in 45 CFR 164.404 on behalf of Plan where a Designated Record Setbreach of unsecured PHI was committed by Business Associate or its employee, make availableofficer, subcontractor or other agent of Business Associate or is within thirty (30) the unique knowledge of Business Associate as opposed to Plan. In such case, Business Associate will prepare the notice and shall provide it to Plan for review and approval at least 5 calendar days of a written request by Covered Entity, PHI for amendment and incorporate any amendments before it is required to be sent to the affected individual(s). Plan shall promptly review the notice and shall not unreasonably withhold its approval.
1.3 Further, where a breach involves more than 500 individuals and was committed by the Business Associate or its employee, officer, subcontractor or other agent or is within the unique knowledge of Business Associate as opposed to Plan, Business Associate shall provide notice to the media pursuant to 45 CFR 164.406. Again, Business Associate will prepare the notice and shall provide it to Plan for review and approval at least 5 calendar days before it is required to be sent to the media. Plan shall promptly review the notice and shall not unreasonably withhold its approval.
1.4 Business Associate shall maintain a log of breaches of unsecured PHI as directed by Covered Entity, all with respect to Plan and shall submit the log to Plan within 30 calendar days following the end of each calendar year so that the Plan may report breaches to the Secretary in accordance with 45 C.F.R. § 164.526;CFR 164.408. This requirement shall take effect with respect to breaches occurring on or after September 23, 2009.
(lq) requestBusiness Associate acknowledges that, use and/or disclose only effective the minimum amount of PHI necessary to accomplish the purpose later of the requestEffective Date of this Agreement or February 17, use or disclosure; provided2010, that Business Associate it shall comply with be liable under the civil and criminal enforcement penalty provisions as set forth at 42 U.S.C. § 17935(b) 1320d-5 and 1320d-6, as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange amended from time to time, for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, failure to comply with requests the use and disclosure requirements of this Agreement, or failure to comply with the with safeguard, policies and procedures requirements and any guidance issued by Individuals not the Secretary from time to send PHI to a Health Plan in accordance time with 42 USC 17935(a)such requirements.
Appears in 1 contract
Sources: Business Associate Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of Protected Health Information (PHI), Business Associate agrees to:
(a) 2.1 not use and/or disclose PHI only except as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement BAA and/or the Agreement, and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) ), or as otherwise Required by Law;, except that to the extent Business Associate is to carry out Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of those obligations.
(b) 2.2 implement and use appropriate technicaladministrative, physical and administrative technical safeguards and comply with applicable Security Rule requirements with respect to (i) Electronic Protected Health Information, to prevent use or disclosure of PHI other than as permitted or required provided for by this B.A. BAA and/or the Agreement; (ii) reasonably and appropriately protect the confidentiality.
2.3 without unreasonable delay, integrity, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) promptly report to Covered Entity: Entity (i) any use or disclosure of PHI not provided for by this BAA and/or the Agreement, of which it becomes aware that is not permitted by this B.A. Agreementin accordance with 45 C.F.R. 164.504(e)(2)(ii)(C); and/or (ii) any Security Incident of which Business Associate becomes aware;aware in accordance with 45 C.F.R. 164.314(a)(2)(i)(C).
(d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery2.4 with respect to any use or disclosure of Unsecured PHI not permitted by the Privacy Rule that is caused solely by Business Associate’s failure to comply with one or more of its obligations under this BAA, Covered Entity hereby delegates to Business Associate the responsibility for determining when any such incident is a Breach. In the event of a Breach, Business Associate shall notify (i) provide Covered Entity with written notification, and (ii) provide all legally required notifications to Individuals, HHS and/or the media, on behalf of a Breach of any Unsecured PHI all Covered Entity, in accordance with 42 U.S.C. § 17932(b45 C.F.R. 164 (Subpart D) as Business Associate shall pay for the reasonable and actual costs associated with those notifications.
2.5 in accordance with 45 C.F.R. 164.502(e)(1)(ii) and 45 C.F.R. 164.308(b)(2), ensure that any subcontractors of its Compliance Date;
(e) require all of its subcontractors and agents Business Associate that create, receive, maintain, or transmit PHI to on behalf of Business Associate agree, in writing, to the same restrictions and conditions on the use and/or disclosure disclosure, of PHI that apply to Business Associate; Associate with respect to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;PHI.
(f) 2.6 make available its internal practices, books, books and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule;.
(g) within thirty (30) days 2.7 after receiving a written request from Covered EntityEntity or an Individual, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Datethe Individual, in accordance with 42 U.S.C. 17935(c)45 C.F.R. 164.528.
2.8 after receiving a written request from Covered Entity or an Individual, and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
(i) provide access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to Set about an Individual, in accordance with the requirements of 45 C.F.R. § 164.524;.
(j) in the event that Business Associate in connection with the Services uses 2.9 after receiving a written request from Covered Entity or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date;
(k) to the extent that the make PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI Set about an Individual available for amendment and incorporate any amendments to the PHI as directed by Covered EntityPHI, all in accordance with 45 C.F.R. § 164.526;.
(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall 2.10 comply with the applicable requirements of 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause CFR Part 2 to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of extent Covered Entity, a Part 2 program or another lawful holder provides Part 2 Records to comply with requests by Individuals not to send PHI to a Health Plan Business Associate in accordance with 42 USC 17935(a).CFR § 2.32 or Subpart D.
Appears in 1 contract
Sources: Administrative Services Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHIProtected Health Information, Business Associate hereby agrees to:
(a) use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) or as otherwise Required by Law;
(b) implement and use appropriate technical, physical and administrative safeguards to (i) prevent Not use or disclosure of PHI disclose Protected Health Information other than as permitted or required by this B.A. Agreement or as otherwise required by law;
(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to Electronic Protected Health Information, to prevent the use or disclosure of the Protected Health Information other than as provided for by this Agreement; ;
(iic) Implement and comply with (and ensure that its subcontractors implement and comply with) the standards set forth at Subpart C of 45 CFR Part 164, to reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) promptly report to Covered Entity: (i) any use or disclosure of PHI of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) any HIPAA Security Incident of which Business Associate becomes awareRule;
(d) without unreasonable delay Establish and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date;
(e) require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;
(f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary procedures for purposes of determining Covered Entity’s compliance with the Privacy Rule;
(g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigatemitigating, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate Protected Health Information that violates the requirements of this Agreement;
(e) Report to the designated privacy officer of Plan, in writing, any use and/or disclosure of the Protected Health Information that is not permitted or required by the requirements this Agreement of this B.A. Agreementwhich Business Associate becomes aware within three (3) calendar days of Business Associate’s discovery of such unauthorized use and/or disclosure, including breaches of unsecured Protected Health Information as required at 45 CFR § 164.410, and any security incident of which it becomes aware;
(if) provide access (at the request In accordance with 45 CFR Parts 164.502(e)(1)(ii) and 164.308(b)(2), require and ensure that all of the Covered Entityits employees, representatives, and agents, including subcontractors, that create, receive, maintain, transmit, use, or have access to Protected Health Information under this Agreement to agree in writing to adhere to the time same restrictions, conditions, and manner designated requirements that apply to the business associate with respect to such information on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as provided under Section 5.3 hereof;
(1) Implement and maintain sanctions against any agent or subcontractor that violates such restrictions and conditions and mitigate the effects of any such violation;
(g) Provide access, within ten (10) calendar days of receipt by Covered Entity) Business Associate of a request by Plan, to PHI Protected Health Information in a Designated Record Set, to Covered Entity Plan or, as directed by Covered EntityPlan, to an Individual, or Individual’s designee in accordance with order to meet the requirements of under 45 C.F.R. § 164.524.
(h) Make any amendment(s) to Protected Health Information in a Designated Record Set that Plan directs or agrees to pursuant to 45 C.F.R. § 164.526 at the request of Plan or an Individual, within ten (10) calendar days of receipt by Business Associate of such request, or to take other measures as necessary to satisfy covered entity’s obligations under 45 CFR Part 164.526;
(1) If any Individual requests an amendment to Protected Health Information directly from Business Associate or its agent or subcontractor, Business Associate must notify Plan in writing within five (5) calendar days of receipt of the request.
(2) Any denial of amendment of Protected Health Information maintained by Business Associate or its agent or subcontractor shall be the responsibility of Plan;
(i) Make available all records, books, agreements, and policies and procedures relating to the use and/or disclosure of Protected Health Information received from, created, or received by Business Associate on behalf of Plan, available to Plan, or at the request of Plan to the Secretary of the U.S. Department of Health and Human Services (“HHS”), in a time and manner designated by Plan or the Secretary, for purposes of the Secretary determining Plan's compliance with the HIPAA Regulations, subject to attorney-client and other applicable legal privileges;
(j) in Within ten (10) calendar days of receiving a written request from Plan, make available to Plan during normal business hours at Business Associate’s offices all records, books, agreements, and policies and procedures relating to the event that use and/or disclosure of Protected Health Information for purposes of enabling Plan to determine Business Associate in connection Associate’s compliance with the Services uses or maintains an Electronic Health Record terms of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Datethis Agreement;
(k) Maintain and make available within ten (10) calendar days of receiving a written request from Plan, the information required to provide an accounting of disclosures of Protected Health Information and information related to such disclosures as would be required for Plan to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR Part 164.528, or an accounting of disclosures of Protected Health Information from an Electronic Health Record in accordance with the HITECH Amendment; Business Associate shall retain such documentation during the term of this Agreement and for a period of ten (10) years following termination of the Agreement. Business Associate shall not disclose Protected Health Information unless directed in writing by Plan or as expressly permitted under this Agreement of the Services Agreement.
(l) Ensure that any agent, group provider or subcontractor to whom Business Associate provides Electronic Protected Health Information agrees to implement reasonable and appropriate safeguards to protect such Electronic Protected Health Information; provided however, that Business Associate shall not assign, delegate, or subcontract any obligation of Business Associate owed by Plan in violation of this Agreement.
(m) To the extent the Business Associate is to carry out one or more of Plan’s obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that would apply to the extent Plan in the performance of such obligation(s);
(n) Immediately report to Plan any Security Incident, of which Business Associate becomes aware.
(o) Authorize termination of the Service Agreement by Plan if Plan determines that Business Associate has violated a material term of this Agreement.
(p) Business Associate understands that pursuant to the HITECH Amendment, it is subject to the HIPAA Privacy and Security Rules in a similar manner as the rules apply to Plan. As a result, Business Associate agrees to take all actions necessary to comply with the HIPAA Privacy and Security Rules for business associates as revised by the HITECH Amendment. Business Associate agrees to the following in connection with the breach notification requirements of the HITECH Amendment:
1.1 If Business Associate discovers a breach of unsecured PHI, as those terms are defined by 45 CFR 164.402, Business Associate shall notify Plan without unreasonable delay and within 5 calendar days after discovery. For breaches with potential for a significant beneficiary harm (i.e., a high likelihood that the information was used inappropriately) or situations that may have heightened public or media scrutiny (i.e. a higher number of beneficiaries affected or particularly egregious breaches), Business Associate will report to Plan within 24 hours of learning of breaches that fall in these categories or at the time of reporting may appear to fall into these categories. For this purpose, discovery means the first day on which the breach is known to Business Associate or by exercising reasonable diligence would have been known to Business Associate. Business Associate shall be deemed to have knowledge of a breach if the breach is known or by exercising reasonable diligence would have been known to any person, other than the person committing the breach, who is an employee, officer, subcontractor or other agent of Business Associate. The notification must include identification of each individual whose unsecured PHI has been, or is reasonably believed to have been breached, and any other available information in Business Associate’s possession constitutes which the Plan is required to include in the individual notice contemplated by 45 CFR 164.404.
1.2 Notwithstanding the immediately preceding paragraph, Business Associate shall assume the individual notice obligation specified in 45 CFR 164.404 on behalf of Plan where a Designated Record Setbreach of unsecured PHI was committed by Business Associate or its employee, make availableofficer, subcontractor or other agent of Business Associate or is within thirty (30) the unique knowledge of Business Associate as opposed to Plan. In such case, Business Associate will prepare the notice and shall provide it to Plan for review and approval at least 5 calendar days of a written request by Covered Entity, PHI for amendment and incorporate any amendments before it is required to be sent to the affected individual(s). Plan shall promptly review the notice and shall not unreasonably withhold its approval.
1.3 Further, where a breach involves more than 500 individuals and was committed by the Business Associate or its employee, officer, subcontractor or other agent or is within the unique knowledge of Business Associate as opposed to Plan, Business Associate shall provide notice to the media pursuant to 45 CFR 164.406. Again, Business Associate will prepare the notice and shall provide it to Plan for review and approval at least 5 calendar days before it is required to be sent to the media. Plan shall promptly review the notice and shall not unreasonably withhold its approval.
1.4 Business Associate shall maintain a log of breaches of unsecured PHI as directed by Covered Entity, all with respect to Plan and shall submit the log to Plan within 30 calendar days following the end of each calendar year so that the Plan may report breaches to the Secretary in accordance with 45 C.F.R. § 164.526;CFR 164.408. This requirement shall take effect with respect to breaches occurring on or after September 23, 2009.
(lq) requestBusiness Associate acknowledges that, use and/or disclose only effective the minimum amount of PHI necessary to accomplish the purpose later of the requestEffective Date of this Agreement or February 17, use or disclosure; provided2010, that Business Associate it shall comply with be liable under the civil and criminal enforcement penalty provisions as set forth at 42 U.S.C. § 17935(b) 1320d-5 and 1320d-6, as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange amended from time to time, for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, failure to comply with requests the use and disclosure requirements of this Agreement, or failure to comply with the with safeguard, policies and procedures requirements and any guidance issued by Individuals not the Secretary from time to send PHI to a Health Plan in accordance time with 42 USC 17935(a)such requirements.
Appears in 1 contract
Sources: Business Associate Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHI, Business Associate agrees to:
(a) 2.1 not use and/or further disclose PHI only except as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement Agreement, the Medical Professionals Agreement, and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) ), or as otherwise Required by Law;; provided that, to the extent Business Associate is to carry out a Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to that Covered Entity in the performance of those obligations.
(b) 2.2 implement and use appropriate technicaladministrative, physical and administrative technical safeguards and, as of the Compliance Date, comply with applicable Security Rule requirements with respect to (i) ePHI, to prevent use or disclosure of PHI other than as permitted or required provided for by this B.A. Agreement; (ii) reasonably and appropriately protect , including at a minimum, but in any event not limited to, any safeguards set forth in the confidentialityAgreement or other applicable contracts or agreements between the parties. For the avoidance of doubt, integrity, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312the Agreement or other applicable contracts or agreements between the parties do not limit in any way whatsoever Business Associate’s obligations under this Section 2.2 to comply with applicable Security Rule requirements.
2.3 without unreasonable delay, and 164.316;
in any event on or before forty-eight (c48) promptly hours after its discovery by Business Associate, report to Covered EntityEntity in writing: (i) any use or disclosure of PHI not provided for by this Agreement of which it becomes aware that is not permitted by this B.A. Agreementin accordance with 45 C.F.R. § 164.504(e)(2)(ii)(C); and/or (ii) any Security Incident of which Business Associate becomes aware;aware in accordance with 45 C.F.R. § 164.314(a)(2)(i)(C).
(d) 2.4 without unreasonable delay delay, and in no case later than sixty any event on or before forty-eight (6048) calendar days hours after discoveryits Discovery by Business Associate, Business Associate shall notify Covered Entity of any incident that involves an unauthorized acquisition, access, use or disclosure of PHI, even if Business Associate believes the incident will not rise to the level of a Breach. The notification shall include, to the extent possible, and shall be supplemented on an ongoing basis with: (i) the identification of all individuals whose Unsecured PHI was or is believed to have been involved; (ii) all other information required for or requested by Covered Entity (or the applicable Covered Entity) to perform a risk assessment in accordance with 45 C.F.R. § 164.402 with respect to the incident to determine whether a Breach of any Unsecured PHI occurred; and (iii) all other information reasonably necessary to provide notice to the applicable Covered Entities individuals, HHS and/or the media, all in accordance with 42 U.S.C. the Breach Rule. Notwithstanding the foregoing, in Covered Entity’s sole discretion and in accordance with its directions, and without limiting in any way any other remedy available to Covered Entity at law, equity or contract, including but not limited to any rights or remedies the Covered Entity may have under the Agreement, Business Associate (i) shall conduct, or pay the costs of conducting, an investigation of any incident required to be reported under this Section 2.4, (ii) shall reimburse and pay Covered Entity for all expenses and costs incurred by Covered Entity that arise from an investigation of any incident required to be reported under this Section 2.4 and (iii) shall provide, and/or pay the costs of providing, the required notices as set forth in this Section 2.4.
2.5 in accordance with 45 C.F.R. § 17932(b164.502(e)(1)(ii) as and 45 C.F.R. § 164.308(b)(2), ensure that any subcontractors of its Compliance Date;
(e) require all of its subcontractors and agents Business Associate that create, receive, maintain, maintain or transmit PHI to on behalf of Business Associate agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business AssociateAssociate with respect to that PHI, including complying with the applicable Security Rule requirements with respect to ePHI; to the extent that provided that, in any event Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor its subcontractors (and shall require those subcontractors to require their subcontractors) to report to Business Associate any use or agent disclosure of PHI or Security Incident required to implement reasonable be reported under Sections 2.3 and appropriate safeguards to protect the ePHI;2.4 on or before forty-eight (48) hours after its discovery by any of those subcontractors.
(f) 2.6 make available its internal practices, books, books and records relating to the use and disclosure of PHI to the Secretary for purposes of determining the applicable Covered Entity’s compliance with the Privacy Rule;.
(g) 2.7 document, and within thirty (30) days after receiving a written request from Covered Entity, make available to Covered Entity information necessary for Covered Entity or its applicable Covered Entity customer to make an accounting of disclosures of PHI about an Individual or, when and as provided requested by Covered Entity, make that information available directly to an Individual, all in accordance with 45 C.F.R. § 164.528 and, as of its Compliance Datethe later of the date compliance is required by final regulations or the effective date of the Agreement, in accordance with 42 U.S.C. § 17935(c).
2.8 provide access to Covered Entity, within fifteen (15) days after receiving a written request from Covered Entity, to PHI in a Designated Record Set about an Individual, or when and when directed as requested by Covered Entity, make provide that accounting access directly to an Individual, all in accordance with the Individual;requirements of 45 C.F.R. § 164.524, including as of the Compliance Date, providing or sending a copy to a designated third party and providing or sending a copy in electronic format in accordance with 45 C.F.R. § 164.524.
2.9 to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (h30) days after a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as requested by Covered Entity, all in accordance with 45 C.F.R. § 164.526.
2.10 accommodate reasonable requests for confidential communications in accordance with 45 C.F.R. § 164.522(b), as requested by Covered Entity or as directed by the Individual to whom the PHI relates.
2.11 notify Covered Entity in writing within three (3) days after Business Associate’s receipt directly from an Individual of any request for an accounting of disclosures, access to or amendment of PHI or for confidential communications as contemplated in Sections 2.7-2.10.
2.12 request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 45 C.F.R. §§ 164.502(b) and 164.514(d) as of the Compliance Date.
2.13 not directly or indirectly receive remuneration in exchange for any PHI as prohibited by 45 C.F.R. § 164.502(a)(5)(ii) as of the Compliance Date.
2.14 not make or cause to be made any communication about a product or service that is prohibited by 45 C.F.R. §§ 164.501 and 164.508(a)(3) as of the Compliance Date.
2.15 not make or cause to be made any written fundraising communication that is prohibited by 45 C.F.R. § 164.514(f) as of the Compliance Date.
2.16 mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;.
(i) provide access (at the request of the Covered Entity2.17 comply with all applicable federal, state and in the time local laws and manner designated by Covered Entity) to PHI in a Designated Record Setregulations.
2.18 not use, to Covered Entity ortransfer, as directed by Covered Entity, to an Individual, in accordance with the requirements of 45 C.F.R. § 164.524;
(j) in the event that Business Associate in connection with the Services uses transmit or maintains an Electronic Health Record of information of otherwise send or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date;
(k) to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days any PHI outside of a written request by the geographic confines of the United States of America without Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. § 164.526;
(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any ’s advance written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a)consent.
Appears in 1 contract
Sources: Business Associate Agreement
Responsibilities of Business Associate. 2.1 With regard to its use and/or disclosure of PHI, Business Associate agrees to:
(a) use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e) or as otherwise Required by Law;
(b) implement and use appropriate technical, physical and administrative safeguards to (i) prevent use or disclosure of PHI other than as permitted or required by this B.A. Agreement; (ii) reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. § 17931, comply with the requirements set forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316;
(c) promptly report to Covered Entity: (i) any use or disclosure of PHI of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) any Security Incident of which Business Associate becomes aware;; \\NY - 056461/000001 - 2371665 v1
(d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. § 17932(b) as of its Compliance Date;
(e) require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;ePHI;
(f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity’s compliance with the Privacy Rule;
(g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. § 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;
(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;
(i) provide access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with the requirements of 45 C.F.R. § 164.524;
(j) in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. § 17935(e) as of its Compliance Date;
(k) to the extent that the PHI in Business Associate’s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. § 164.526;
(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. § 17935(b) as of its Compliance Date;
(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. § 17935(d) as of its Compliance Date;
(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. § 17936(a) as of its Compliance Date;
(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. § 17936(b) as of its Compliance Date; and
(p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a).
Appears in 1 contract
Sources: Business Associate Agreement