Common use of Responsibilities of Business Associate Clause in Contracts

Responsibilities of Business Associate. With regard to the use and/or disclosure of Protected Health Information, Business Associate agrees: 4.1 not to use and/or disclose Protected Health Information other than as permitted or required by the Business Relationship or this BA Agreement or as Required by Law; 4.2 to use appropriate safeguards to prevent the use and/or disclosure of Protected Health Information other than as provided for by the Business Relationship or this BA Agreement; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destruction; 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314) and Policies and Documentation (45 CFR § 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY. 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of Protected Health Information that is not provided for by the Business Relationship or this BA Agreement; 4.7 to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information; 4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet the 4.11 to make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR § 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receipt; 4.12 to document such disclosures of Protected Health Information and information related to such disclosures as would be required for COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule that apply to COUNTY in the performance of such obligation; 4.15 to make its internal practices, books, and records relating to the use and/or disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY or Business Associate is in compliance with the Privacy Rule; 4.17 if Business Associate is aware of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the Secretary.

Appears in 5 contracts

Sources: Business Associate Agreement, Business Associate Agreement, Business Associate Agreement

Responsibilities of Business Associate. With regard to the use and/or disclosure of Protected Health Information, Business Associate agrees: 4.1 not to use and/or disclose Protected Health Information other than as permitted or required by the Business Relationship or this BA Agreement or as Required by Law; 4.2 to use appropriate safeguards to prevent the use and/or disclosure of Protected Health Information other than as provided for by the Business Relationship or this BA Agreement; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destruction; 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314) and Policies and Documentation (45 CFR § 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY.Rules 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of Protected Health Information that is not provided for by the Business Relationship or this BA Agreement; 4.7 to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information; 4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet thethe requirements under 45 CFR § 164.524 and to notify COUNTY of any requests for access it receives from an individual within 2 business days of receipt; 4.11 to make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR § 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receipt; 4.12 to document such disclosures of Protected Health Information and information related to such disclosures as would be required for COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule that apply to COUNTY in the performance of such obligation; 4.15 to make its internal practices, books, and records relating to the use and/or disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY or Business Associate is in compliance with the Privacy Rule; 4.17 if Business Associate is aware of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the Secretary.

Appears in 4 contracts

Sources: Business Associate Agreement, Business Associate Agreement, Business Associate Agreement

Responsibilities of Business Associate. With regard to the its use and/or disclosure of Protected Health Information, the Business Associate agreeshereby agrees to the following: 4.1 not 3.1.1 Not to use and/or or disclose Protected Health Information other than except as permitted or required by the Business Relationship or this BA Agreement or as Required by By Law; 4.2 to 3.1.2 To use appropriate safeguards to maintain the security of the Protected Health Information and to prevent the unauthorized use and/or disclosure of the Protected Health Information other than as provided for by the Business Relationship or this BA AgreementInformation; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees 3.1.3 To report to the destruction; 4.4 to comply with the Security Rule provisions set forth designated privacy officer of Covered Entity, in 45 CFR Part 164writing, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314) and Policies and Documentation (45 CFR § 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY. 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of the Protected Health Information that is not provided for permitted, required by the this Agreement, or Required By Law, of which Business Relationship or this BA AgreementAssociate becomes aware, including breaches of unsecured Protected Health Information as required at 45 CFR 164.410, and any security incident of which it becomes aware, within ten (10) days of Business Associate’s discovery of such unauthorized use and/or disclosure; 4.7 to 3.1.4 To mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of the Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation 3.1.5 To require all of any potential Breach and in connection with any notices COUNTY determines are required as a resultits employees, representatives, subcontractors, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain maintain, transmit or transmit otherwise have access to the Protected Health Information on behalf of Business Associate under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of the Protected Health Information that apply herein; 3.1.6 Upon written request, to make available during normal business hours at Business Associate with respect Associate’s offices, within ten (10) calendar days of such request, all books, records, and agreements, including policies and procedures, relating to such the use and disclosure of the Protected Health InformationInformation to Covered Entity for purposes of enabling Covered Entity to determine Business Associate’s compliance with the terms of this Agreement; 4.10 3.1.7 Upon written request, to provide access (at the request ofmake available all books, records, and agreements, including policies and procedures, relating to the use and disclosure of the Protected Health Information to the Secretary in the a time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet the 4.11 to make any amendment(s) (at the request of, Secretary for the purposes of determining compliance with HIPAA and in the time Privacy and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR § 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receiptSecurity Rules; 4.12 to 3.1.8 To document such any disclosures of the Protected Health Information and information related to such disclosures as would be required for COUNTY Covered Entity to respond to a request by an Individual for an accounting of disclosures of the Protected Health Information in accordance with 45 CFR § §164.528;; and 4.13 to 3.1.9 To provide to COUNTYCovered Entity or an Individual, in a the time and manner designated by COUNTYCovered Entity, information collected in accordance with 4.12 of this BA Agreement, Agreement to permit COUNTY Covered Entity to respond to a request by an Individual for an accounting of disclosures of the Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule that apply to COUNTY in the performance of such obligation; 4.15 to make its internal practices, books, and records relating to the use and/or disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY or Business Associate is in compliance with the Privacy Rule; 4.17 if Business Associate is aware of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the Secretary164.528.

Appears in 2 contracts

Sources: Agent/Agency Agreement, Business Associate Agreement

Responsibilities of Business Associate. With regard to the its use and/or disclosure of Protected Health InformationPHI, Business Associate agreesagrees to: 4.1 2.1 not to use and/or further disclose Protected Health Information other than PHI except as necessary to provide the Services, as permitted or required by this BAA and in compliance with the Business Relationship or this BA Agreement applicable requirements of 45 C.F.R. § 164.504(e), or as Required by Law; 4.2 to use appropriate safeguards to prevent the use and/or disclosure of Protected Health Information other than as ; provided for by the Business Relationship or this BA Agreement; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to othersthat, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destruction; 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314) and Policies and Documentation (45 CFR § 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY. 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of Protected Health Information that is not provided for by the Business Relationship or this BA Agreement; 4.7 to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information; 4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet the 4.11 to make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR § 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receipt; 4.12 to document such disclosures of Protected Health Information and information related to such disclosures as would be required for COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY Covered Entity’s obligations under the Privacy Rule provisions set forth at 45 CFR Part 164Rule, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to Associate will comply with the requirements of the Privacy Rule that apply to COUNTY Covered Entity in the performance of those obligations. 2.2 implement and use appropriate administrative, physical and technical safeguards and comply with applicable Security Rule requirements with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this BAA. 2.3 without unreasonable delay, and in any event on or before ten days after its Discovery, report to Covered Entity (i) any use or disclosure of PHI not provided for in this BAA and/or (ii) any Security Incident of which Business Associate becomes aware in accordance with 45 C.F.R. § 164.314(a)(2)(i)(C). For the purposes of reporting under this BAA, a reportable “Security Incident” shall not include unsuccessful or inconsequential incidents that do not represent a material threat to confidentiality, integrity or availability of PHI (such obligation;as scans, pings, or unsuccessful attempts to penetrate computer networks). 4.15 2.4 report to Covered Entity within ten business days: (i) any Breach of Unsecured PHI of which it becomes aware in accordance with 45 C.F.R. § 164.504(e)(2)(ii)(C). Business Associate shall provide to Covered Entity a description of the Breach and a list of Individuals affected (unless Covered Entity is a plan sponsor ineligible to receive PHI). Business Associate shall provide required notifications to Individuals and the Media and Secretary, where appropriate, in accordance with the Privacy Rule and with Covered Entity’s approval of the notification text. Business Associate shall pay for the reasonable and actual costs associated with those notifications and with credit monitoring, if appropriate. 2.5 in accordance with 45 C.F.R. § 164.502(e)(1)(ii) and 45 C.F.R. § 164.308(b)(2), ensure that any subcontractors of Business Associate that create, receive, maintain or transmit PHI on behalf of Business Associate agree, in writing, to the same restrictions on the use and/or disclosure of PHI that apply to Business Associate with respect to that PHI, including complying with the applicable Security Rule requirements with respect to ePHI. 2.6 make available its internal practices, books, books and records relating to the use and/or and disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available PHI to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY or Business Associate is in Covered Entity’s compliance with the Privacy Rule;, in accordance with 45 C.F.R. § 164.504(e)(2)(ii)(l). 4.17 if 2.7 within thirty days after receiving a written request from Covered Entity or an Individual, make available to Covered Entity or an Individual information necessary for an accounting of disclosures of PHI about an Individual, in accordance with 45 C.F.R. § 164.528. 2.8 provide access to Covered Entity or an Individual, within ten business days after receiving a written request from Covered Entity or an Individual, to PHI in a Designated Record Set about an Individual, sufficient for compliance with 45 C.F.R. § 164.524. 2.9 to the extent that the PHI in Business Associate is aware of a pattern of activity or practice by COUNTY that Associate’s possession constitutes a material breach Designated Record Set, make available, within thirty days after a written request by Covered Entity or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery an Individual, PHI for amendment and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem incorporate any amendments to the Secretary and provide COUNTY PHI as requested in accordance with a copy of any such report at least 2 business days in advance of its submission to the Secretary45 C.F.R. § 164.526.

Appears in 2 contracts

Sources: Prescription Drug Benefit Administration Agreement, Prescription Drug Benefit Administration Agreement

Responsibilities of Business Associate. With regard to the use and/or disclosure of Protected Health Information, Business Associate agrees:agrees to: DRAFT 4.1 not to 3.1 Not use and/or or disclose Protected Health Information PHI or other confidential information other than as permitted or required by the Business Relationship or this BA Agreement BAA or as Required required by Lawlaw; 4.2 3.2 Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to use appropriate safeguards electronic PHI, to prevent the use and/or or disclosure of Protected Health Information PHI other than as provided for by the Business Relationship or this BA AgreementBAA; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destruction; 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314) and Policies and Documentation (45 CFR § 164.316), and to implement 3.3 Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate PHI that it creates, receives, maintains, or transmits on behalf of COUNTY.the Plan. Business Associate shall comply with the applicable standards at Subpart C of 45 CFR Part 164. Such safeguards shall be based on applicable Federal Information Processing Standards (FIPS) Publication 199 protection levels; 4.5 3.4 Identify the security official who is responsible for the development and implementation of the policies and procedures required by 45 CFR Part 164, Subpart C; 3.5 Shall, at a minimum, utilize an industry-recognized security framework when selecting and implementing its security controls, and shall maintain continuous compliance with its selected framework; 3.6 Apply security patches and upgrades, and keep virus software up-to-date, on all systems on which PHI and other confidential information may be used; 3.7 Employ FIPS 140-2 compliant encryption of PHI at rest and in motion unless Business Associate determines it is not reasonable and appropriate to do so based upon a risk assessment, and equivalent alternative measures are in place and documented as such. In addition, Business Associate shall maintain, at a minimum, the most current industry standards for transmission and storage of PHI and other confidential information; 3.8 Immediately report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of Plan any use and/or or disclosure of Protected Health Information that is PHI not provided for by the BAA of which it becomes aware, including, but not limited to, Breaches or suspected Breaches of unsecured PHI under 45 CFR 164.410, and any Security Incident or suspected Security Incidents of PHI or confidential information which it becomes aware. Business Relationship Associate shall report the improper or this BA Agreement; 4.7 unauthorized use or disclosure of PHI or potential loss of confidential information within 24 hours to the Plan. Business Associate shall immediately investigate any suspected Security Incident or Breach. Business Associate shall provide Covered Entity with all requested information so Covered Entity may comply with its reporting obligations to DHCS per the Medi-Cal Contract and all required Breach notifications. Business Associate shall mitigate, to the extent practicable, any harmful effect effects that is known to Business Associate of such Breach or Security Incident of PHI or other confidential information in violation of this BAA. Business Associate shall indemnify Covered Entity against any losses, damages, expenses or other liabilities including reasonable attorney’s fees incurred as a result of Business Associate’s or its agent’s or Subcontractor’s unauthorized use or disclosure of Protected Health Information PHI including, but not limited to, the costs of notifying individuals affected by Business Associate in violation of the requirements of this BA Agreementa Breach; DRAFT 3.9 In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any subcontractors, agents, vendors, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors others that create, receive, maintain maintain, or transmit Protected Health Information PHI and/or confidential information on behalf of the Business Associate agree in writing to the same restrictions restrictions, conditions, and conditions requirements that apply to the Business Associate with respect to such Protected Health Informationinformation; 4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information 3.10 Make available PHI in a Designated Record Set designated record set to COUNTY or, the Plan as directed by COUNTY, necessary to an Individual in order to meet thesatisfy the Plan’s obligations under 45 CFR 164.524; 4.11 to make 3.11 Make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information PHI in a Designated Record Set that COUNTY directs designated record set as directed or agreed to by the Plan pursuant to 45 CFR § 164.526 and 164.526, or take other measures as necessary to notify COUNTY of satisfy the Plan’s obligations under 45 CFR 164.526; 3.12 Forward any requests from a Plan member for access to records maintained in accordance with the BAA as soon as they are received. The Plan will maintain responsibility for making determinations regarding access to records; 3.13 Direct any requests for an amendment requests it receives from an individual within 2 business days of receiptas soon as they are received to the Plan. The Business Associate will incorporate any amendments from the Plan immediately upon direction from the covered entity; 4.12 3.14 Maintain and make available the information required to document such provide an accounting of disclosures of Protected Health Information and information related to such disclosures the Plan as would be required for COUNTY necessary to respond to satisfy the Plan’s obligations under 45 CFR 164.528; 3.15 Forward any requests from a request by an Individual Plan member for an accounting of disclosures of Protected Health Information maintained in accordance with 45 CFR § 164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 the BAA as soon as they are received. The Plan will maintain responsibility for making determinations regarding the provision of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR §disclosures; 4.14 to 3.16 To the extent the Business Associate is to carry out an obligation one or more of COUNTY the Plan's obligations under the Privacy Rule provisions set forth at Subpart E of 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule Subpart E that apply to COUNTY the covered entity in the performance of such obligationobligation(s); 4.15 to make 3.17 Make its internal practices, books, and records relating to the use and/or disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human ServicesCovered Entity, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, and DHCS upon reasonable request for purposes of determining if COUNTY or Business Associate is in compliance with the Privacy RuleHIPAA Rules. Make its facilities and systems available to DHCS to monitor compliance with the Medi-Cal Contract; 4.17 3.18 Ensure that all members of its Workforce with access to PHI and/or other confidential information sign a confidentiality statement prior to access to such data. The confidentiality statement must be renewed annually; 3.19 Agree to comply with DHCS’s monitoring provisions contained in the Medi-Cal Contract; 3.20 Agree to comply with the more protective of the privacy and security standards defined herein as Privacy Rules. Therefore, to the extent other applicable state laws or federal laws provide a greater degree of protection and security than HIPAA or are more favorable to the individuals whose information is concerned, Business Associate shall comply with the more protective applicable privacy and security standards. Business Associate shall treat any violation of the more protective standards as a Breach or Security Incident pursuant to Section 3.8 herein; DRAFT 3.21 If applicable, in the event Business Associate received data from Covered Entity that was verified by or provided by Social Security Administration (“SSA”) and is subject to an agreement between DHCS and SSA, upon request, Business Associate shall provide Covered Entity with a list of all employees and agents who have access to such data, including employees and agents of its agents, so that Covered Entity can submit this list to DHCS. Business Associate shall notify Covered Entity immediately upon the discovery of a suspected breach or security incident that involves SSA data; 3.22 Shall promptly report to Covered Entity if Business Associate is aware the subject of a pattern of activity any audit, compliance review, investigation, or practice by COUNTY any proceeding that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) is related to give written notice of such pattern or practice to COUNTY within 2 business days the performance of its discovery and obligations pursuant to take reasonable steps the Agreement, so Covered Entity can to cure report this information to DHCS per the breach or end the violation,Medi-Cal Contract; (b) 3.23 Shall promptly report to Covered Entity if Business Associate determines that such steps appear is the subject of any judicial or administrative proceeding alleging a violation of HIPAA, Business Associate shall report this to have been unsuccessfulCovered Entity unless it is legally prohibited from doing so. Covered Entity is then required to report this information to DHCS per the Medi-Cal Contract; and 3.24 Shall make itself, and any subcontractors, employees or agents assisting Business Associate in the performance of its obligations under the Agreement, available to Covered Entity, to give COUNTY written notice testify as witnesses, or otherwise, in the event of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the Secretarylitigation or administrative proceedings commenced against DHCS or Covered Entity, or their directors, officers or employees.

Appears in 1 contract

Sources: Master Services Agreement

Responsibilities of Business Associate. With regard to the its use and/or or disclosure of Protected Health Information, the Business Associate agreeshereby agrees that it shall: 4.1 (a) Use or disclose the Protected Health Information only as needed to perform its obligations to the Covered Entity under the Service Agreement, provided that such use or disclosure would not to violate the HIPAA Rules or the HITECH Act if done by the Covered Entity; (b) Not use and/or or further disclose Protected Health Information other than as permitted or required by this Addendum, the Business Relationship or this BA Service Agreement or as Required otherwise required by Lawlaw; 4.2 to use (c) Use appropriate safeguards to prevent the unauthorized use and/or or disclosure of Protected Health Information other than as provided for by the Business Relationship or this BA Agreement; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destructionInformation; 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314d) and Policies and Documentation (45 CFR § 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY. 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of Protected Health Information that is not provided for by the Business Relationship or this BA Agreement; 4.7 to mitigateMitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA AgreementAddendum; (e) Report to the designated Compliance Officer of the Covered Entity, in writing, (i) any Use or as the result Disclosure of Protected Health Information that is not permitted or required by this Addendum and (ii) any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at of which Business Associate becomes aware within ten (10) days of the sole cost and expense of Business Associate’s discovery of such unauthorized Use or Disclosure or Security Incident; 4.8 (f) Require all of its employees, representatives, subcontractors or agents that receive or use or have access to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate to agree in writing to adhere to the same restrictions and conditions that apply to Business Associate with respect to such on the Use and/or Disclosure of Protected Health InformationInformation as are contained herein; 4.10 to provide access (g) Provide access, at the request ofof Covered Entity, and in the time and manner designated by COUNTY) Covered Entity, to Protected Health Information in a Designated Record Set Set, to COUNTY Covered Entity or, as directed by COUNTYCovered Entity, to an Individual in order to meet thethe requirements under 45 CFR 164.524; 4.11 to make (h) Make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY the Covered Entity directs or agrees to pursuant to 45 CFR § 164.526 at the request of Covered Entity or an Individual, and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receiptin the time and manner designated by Covered Entity; 4.12 to document (i) Document such disclosures of Protected Health Information and information related to such disclosures as would be required for COUNTY the Covered Entity to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § C.F.R. §164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule that apply to COUNTY in the performance of such obligation; 4.15 to make its internal practicesj) Make available all records, books, agreements, policies and records procedures relating to the use and/or disclosure of Protected Health Information received fromto the Covered Entity, or created or received by Business Associate on behalf at the request of COUNTY available the Covered Entity to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, HHS for purposes of determining if COUNTY or Business Associate is in the Covered Entity’s compliance with the Privacy RuleHIPAA Rules; 4.17 if (k) Upon written request, make available during normal business hours at Business Associate’s offices all records, books, agreements, policies and procedures relating to the Use and/or Disclosure of Protected Health Information to the Covered Entity within thirty (30) days for purposes of enabling the Covered Entity to determine the Business Associate’s compliance with the terms of this Addendum; (l) Return to the Covered Entity or destroy, as requested by the Covered Entity, within thirty (30) days of the expiration or termination of this Addendum, the Protected Health Information in Business Associate’s possession and retain no copies or back-ups of any kind; and (m) Implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information that the Business Associate is aware Uses and/or Discloses on behalf of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the SecretaryCovered Entity.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to the use and/or disclosure of Protected Health Information, Business Associate agrees: 4.1 not to use and/or disclose Protected Health Information other than as permitted or required by the Business Relationship or this BA Agreement or as Required by Law; 4.2 to use appropriate safeguards to prevent the use and/or disclosure of Protected Health Information other than as provided for by the Business Relationship or this BA Agreement; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destruction; 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314) and Policies and Documentation (45 CFR § 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY. 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of Protected Health Information that is not provided for by the Business Relationship or this BA Agreement; 4.7 to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information; 4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet thethe requirements under 45 CFR § 164.524 and to notify COUNTY of any requests for access it receives from an individual within 2 business days of receipt; 4.11 to make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR § 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receipt; 4.12 to document such disclosures of Protected Health Information and information related to such disclosures as would be required for COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule that apply to COUNTY in the performance of such obligation; 4.15 to make its internal practices, books, and records relating to the use and/or disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY or Business Associate is in compliance with the Privacy Rule; 4.17 if Business Associate is aware of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the Secretary.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to the use and/or disclosure of Protected Health Information, Business Associate agrees: 4.1 not to use and/or disclose Protected Health Information other than as permitted or required by the Business Relationship or this BA Agreement or as Required by By Law; 4.2 to use appropriate safeguards to prevent the use and/or disclosure of Protected Health Information other than as provided for by the Business Relationship or this BA Agreement; 4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destruction; 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314) and Policies and Documentation (45 CFR § 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY.Rules 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of Protected Health Information that is not provided for by the Business Relationship or this BA Agreement; 4.7 to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information; 4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet thethe requirements under 45 CFR § 164.524 and to notify COUNTY of any requests for access it receives from an individual within 2 business days of receipt; 4.11 to make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR § 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receipt; 4.12 to document such disclosures of Protected Health Information and information related to such disclosures as would be required for COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule that apply to COUNTY in the performance of such obligation; 4.15 to make its internal practices, books, and records relating to the use and/or disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY; 4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY or Business Associate is in compliance with the Privacy Rule; 4.17 if Business Associate is aware of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the Secretary.

Appears in 1 contract

Sources: Business Associate Agreement

Responsibilities of Business Associate. With regard to the use its Use and/or disclosure Disclosure of Protected Health Information, the Business Associate agreesagrees to do the following: 4.1 not to use a) Use and/or disclose Disclose the Protected Health Information other than only as permitted or required by the Business Relationship or this BA Agreement BAA or as otherwise Required by By Law;. 4.2 b) Report to use appropriate safeguards to prevent the use designated Privacy Officer of the Covered Entity, in writing, any Use and/or disclosure Disclosure of the Protected Health Information other than as provided for that is not permitted or required by the Business Relationship or this BA Agreement; 4.3 to protect BAA, any Breach of Unsecured Protected Health Information taken off-site from COUNTY from disclosure to othersof which Business Associate becomes aware, and any Security Incident of which Business Associate becomes aware, within 10 business days of the Business Associate's discovery of the unauthorized Use and/or Disclosure, Breach, or Security Incident. Business Associate shall reasonably cooperate with Covered Entity to return all comply with applicable mitigation and/or notification obligations under the Privacy and Security Regulation. c) Use commercially reasonable efforts to maintain the security of the Protected Health Information in any form and to COUNTY or destroy prevent unauthorized Use and/or Disclosure of such Protected Health Information in Information. Such security measures shall, at a manner that renders it unreadable and unusable by anyone elseminimum, if COUNTY agrees to include the destruction;following: 4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR § 164.306), Administrative Safeguards (45 CFR § 164.308), Physical Safeguards (45 CFR § 164.310), Technical Safeguards (45 CFR § 164.312), Organizational Requirements (45 CFR § 164.314i) and Policies and Documentation (45 CFR § 164.316), and to implement Implement HIPAA-compliant administrative, physical, physical and technical safeguards safeguards, as defined by 45 C.F.R. § 164.304, that reasonably and appropriately protect the confidentiality, integrity, integrity and availability of the Covered Entity’s Electronic Protected Health Information that the Business Associate creates, receives, maintains, or transmits on behalf of COUNTY.the Covered Entity; 4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured ii) Implement disclosure accounting procedures for Protected Health Information within 2 business days of discovery. Any such report shall include and/or, if applicable, any Electronic Health Record; and iii) Ensure that any agent, including a subcontractor, to whom the identification of each individual whose Unsecured Business Associate provides Protected Health Information has beenagrees in writing, as required by this BAA, to implement reasonable and appropriate safeguards to protect it. d) Require its agents, including subcontractors, that receive, create, Use or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Disclose Protected Health Information involved under this BAA to agree in the event, the nature writing to adhere to each of the information, etc.) or promptly thereafter as such other information becomes available; 4.6 to notify COUNTY in writing within 2 business days of any use same restrictions and conditions on the Use and/or disclosure Disclosure of Protected Health Information that is not are set forth herein, including the obligation to return or destroy the Protected Health Information as provided under (g) of this section. e) Make available all books and records relating to the Use and/or Disclosure of Protected Health Information to the Secretary for purposes of determining the Covered Entity's compliance with the Privacy and Security Regulation, subject to attorney-client and other applicable legal privileges. f) Within 10 business days of receiving a written request from the Covered Entity: i) Make available to the Covered Entity Protected Health Information in a Designated Record Set as required for the Covered Entity to respond to a request by the Business Relationship subject Individual for access to his or this BA Agreementher Protected Health Information in compliance with 45 C.F.R. §164.524; 4.7 ii) Make amendments to mitigateProtected Health Information in a Designated Record Set as agreed to by the Covered Entity in compliance with 45 C.F.R. §164.526; and iii) Provide information to the Covered Entity as required for Covered Entity to provide the Individual with an accounting of Disclosures of Protected Health Information in compliance with 45 C.F.R. §164.528. g) Return to the Covered Entity or destroy, as requested by the Covered Entity, within 10 business days of the termination of this BAA, the Protected Health Information in Business Associate's possession and retain no copies or back-up tapes, except that if Business Associate determines that returning or destroying the Protected Health Information is infeasible, Business Associate shall provide to Covered Entity notification of the conditions that make return or destruction infeasible. Business Associate shall extend the protections of this BAA to such Protected Health Information and limit further Use and Disclosure of such Protected Health Information to those purposes that make return or destruction infeasible, for so long as Business Associate maintains such Protected Health Information. h) Mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use Use or disclosure Disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of BAA and assist Covered Entity in any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate; 4.8 to work cooperatively with COUNTY in connection with COUNTY’s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate; 4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information; 4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet the 4.11 to make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR § 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receipt; 4.12 to document such disclosures of Protected Health Information and information notifications related to such disclosures violations as would be required for COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 164.528; 4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR § 4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), necessary to comply with the requirements Privacy and Security Regulation. i) Comply with applicable provisions of the Privacy Rule that apply to COUNTY and Security Regulation, which are expressly incorporated in the performance of such obligation; 4.15 to make its internal practices, books, and records relating this BAA to the use and/or disclosure of extent Required By Law. j) Request, Use and Disclose only the Minimum Necessary Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY; 4.16 to cooperate with any investigation by accomplish the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY the request, Use or Business Associate is in compliance with the Privacy Rule; 4.17 if Business Associate is aware of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY’s obligations under this BA Agreement, (a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation, (b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the SecretaryDisclosure.

Appears in 1 contract

Sources: Master Agreement