Responsibilities of Business Associate. Regarding the use or disclosure of PHI and PI, Business Associate agrees to: 4.2.1 Only use or further disclose the PHI and PI as allowable under this Agreement or applicable law. 4.2.2 Only use or further disclosure PHI and PI in a manner that would not violate the HIPAA Privacy and Security Rules if done so by the Covered Entity. 4.2.3 Establish and implement appropriate procedures, physical, and technical safeguards to prevent improper access, uses, transmissions, or disclosures of PHI and PI for mitigating to the greatest extents possible under the circumstances any deleterious effects from any improper access, use, or disclosure of PHI and PI that Business Associate reports to Covered Entity. Safeguards shall include, but are not limited to, the implementation and use of electronic security measures to safeguard electronic data, requiring employees to agree to access, use, or disclose PHI and PI only as permitted or required by this Agreement and taking related disciplinary action for inappropriate access, use or disclosure as necessary. 4.2.4 Report to Covered Entity’s Privacy Officer, in writing, any suspected or confirmed access, use or disclosure of PHI or PI, regardless of form, not permitted or required by this Agreement of which Business Associate becomes aware within two (2) days of Business Associate’s discovery of such unauthorized use or disclosure. 4.2.5 Ensure that Business Associate’s subcontractors or agents to whom Business Associate provides PHI or PI, received from, created, or received by the Business Associate on behalf of the Covered Entity, agree to the same restrictions and conditions that apply to the Business Associate with respect to PHI and PI, and ensure that its subcontractors or agents agree to establish and implement reasonable and appropriate safeguards to protect the confidentiality, integrity, and availability of all PHI and PI that it creates receives, maintains, or transmits on behalf of Covered Entity. 4.2.6 The Business Associate must make its records, books, accounts, agreements, policies, and procedures available to the Secretary of HHS for determining the Covered Entity’s compliance with the HIPAA Privacy and Security Rules. 4.2.7 Use or disclose to its subcontractors, agents, other third parties, and Covered Entity, only the minimum PHI and PI necessary to perform or fulfill a specific function required or permitted hereunder. 4.2.8 Provide information to Covered Entity to permit Covered Entity to respond to a request by an individual for an accounting of disclosures within five (5) days of receiving a written request from Covered Entity, if Business Associate maintains a Designated Records Set on behalf of Covered Entity. 4.2.9 At the request of, and in the time and manner designated by Covered Entity, provide access to the PHI and PI maintained by Business Associate to Covered Entity or individual, if Business Associate maintains a Designated Records Set on behalf of Covered Entity. 4.2.10 At the request of, and in the time and manner designated by Covered Entity, make any amendment(s) to the PHI and PI when directed by Covered Entity, if Business Associate maintains a Designated Record Set on behalf of Covered Entity. 4.2.11 Establish and implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any PHI and PI Business Associate creates, receives, maintains or transmits on behalf of Covered Entity. 4.2.12 Report to Covered Entity any Security Incident involving PHI and PI that Business Associate discovers.
Appears in 7 contracts
Sources: Business Associate Agreement (Baa), Business Associate Agreement (Baa), Business Associate Agreement (Baa)
Responsibilities of Business Associate. Regarding the With regard to its use or and/or disclosure of PHI and PIPHI, the Business Associate hereby agrees toto do the following:
4.2.1 Only use or further 1. Use and/or disclose the PHI and PI as allowable under this Agreement or applicable law.
4.2.2 Only use or further disclosure PHI and PI in a manner that would not violate the HIPAA Privacy and Security Rules if done so by the Covered Entity.
4.2.3 Establish and implement appropriate procedures, physical, and technical safeguards to prevent improper access, uses, transmissions, or disclosures of PHI and PI for mitigating to the greatest extents possible under the circumstances any deleterious effects from any improper access, use, or disclosure of PHI and PI that Business Associate reports to Covered Entity. Safeguards shall include, but are not limited to, the implementation and use of electronic security measures to safeguard electronic data, requiring employees to agree to access, use, or disclose PHI and PI only as permitted or required by this Agreement or as otherwise required by law and taking related disciplinary action for inappropriate access, use or disclosure as to the minimum necessary.;
4.2.4 2. Report to Covered Entity’s Privacy Officerthe executive director or designated privacy officer of Homeward, the primary Business Associate, in writing, any suspected or confirmed access, use or and/or disclosure of the PHI or PI, regardless of form, that is not permitted or required by this Agreement of which Business Associate becomes aware aware, including breaches of unsecured protected health information as required at 45 C.F.R. § 164.410 and any security incident of which it becomes aware, within two fifteen (215) days of the Business Associate’s discovery of such unauthorized use or and/or disclosure.;
4.2.5 Ensure that Business Associate’s subcontractors or agents to whom Business Associate provides PHI or PI, received from, created, or received by the Business Associate on behalf of the Covered Entity, agree to the same restrictions 3. Develop and conditions that apply to the Business Associate with respect to PHI and PI, and ensure that its subcontractors or agents agree to establish and implement use reasonable and appropriate administrative, technical and physical safeguards to ensure and protect against reasonably anticipated threats or hazards to the confidentialitysecurity or integrity of PHI, integrityto protect against reasonably anticipated unauthorized use or disclosure of PHI, and availability to reasonably safeguard PHI from any intentional or unintentional use or disclosure in violation of all this Agreement;
4. To document disclosures of PHI and PI that it creates receives, maintains, or transmits on behalf of Covered Entity.
4.2.6 The Business Associate must make its records, books, accounts, agreements, policies, and procedures available to the Secretary of HHS for determining the Covered Entity’s compliance with the HIPAA Privacy and Security Rules.
4.2.7 Use or disclose to its subcontractors, agents, other third parties, and Covered Entity, only the minimum PHI and PI related information as necessary to perform or fulfill a specific function required or permitted hereunder.
4.2.8 Provide information to Covered Entity to permit Covered Entity to respond to a request by an individual for an accounting of PHI disclosures in accordance with 45 C.F.R. § 164.528;
5. Require all of its employees, representatives, subcontractors, or agents that receive or use or have access to PHI under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of PHI that apply herein, including the obligation to return or destroy the PHI as provided herein.
6. Make available all records, books, agreements, policies, and procedures relating to the use and/or disclosure of PHI to the Secretary of HHS for purposes of determining a Covered Entity’s compliance with the HIPAA Rules.
7. Upon request by a Covered Entity, make available during normal business hours at Business Associate’s offices all records, books, agreements, policies, and procedures relating to the use and/or disclosure of PHI to the Covered Entity within five (5) business days for purposes of enabling the Covered Entity to determine the C.F.R. § 164.524.
9. Within ten (10) days of receiving a written request from Covered Entity, if Business Associate maintains a Designated Records Set on behalf of Covered Entity.
4.2.9 At the request of, and in the time and manner designated by Covered Entity, provide access to the Covered Entity such information as is requested to permit the Covered Entity to respond to a request by the subject individual for amendment and accounting purposes of the disclosures of the individual’s protected PHI in accordance with 45 C.F.R. § 164.526 & § 164.528;
10. Return to a Covered Entity or destroy, as requested by the Covered Entity, within fifteen (15) days of the termination of this Agreement, the PHI in Business Associate’s possession and PI maintained retain no copies or back-up tapes;
11. To mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Agreement; and
12. To take all steps necessary to Covered Entity or individual, if Business Associate maintains a Designated Records Set on behalf comply with the Notice of Covered EntityPrivacy Practices required under 45 C.F.R. § 164.520.
4.2.10 At the request of, and in the time and manner designated by Covered Entity, make any amendment(s) to the PHI and PI when directed by Covered Entity, if Business Associate maintains a Designated Record Set on behalf of Covered Entity.
4.2.11 Establish and implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any PHI and PI Business Associate creates, receives, maintains or transmits on behalf of Covered Entity.
4.2.12 Report to Covered Entity any Security Incident involving PHI and PI that Business Associate discovers.
Appears in 1 contract
Sources: Agency Participation and Business Associate Agreement
Responsibilities of Business Associate. Regarding the With regard to its use or and/or disclosure of PHI and PIProtected Health Information created by or received from or on behalf of Customer, Business Associate agrees toas follows:
4.2.1 Only (a) Business Associate will use or further and/or disclose the PHI and PI as allowable under this Agreement or applicable law.
4.2.2 Only use or further disclosure PHI and PI in a manner that would not violate the HIPAA Privacy and Security Rules if done so by the Covered Entity.
4.2.3 Establish and implement appropriate procedures, physical, and technical safeguards to prevent improper access, uses, transmissions, or disclosures of PHI and PI for mitigating to the greatest extents possible under the circumstances any deleterious effects from any improper access, use, or disclosure of PHI and PI that Business Associate reports to Covered Entity. Safeguards shall include, but are not limited to, the implementation and use of electronic security measures to safeguard electronic data, requiring employees to agree to access, use, or disclose PHI and PI Protected Health Information only (1) as permitted or required by this Agreement or as otherwise required by applicable law, rule or regulation, or by accrediting or credentialing organization to whom Customer is required to disclose such information; or (2) as otherwise permitted under this Agreement, the Services Agreement(s) (if consistent with this Agreement and taking related disciplinary action for inappropriate accessthe HIPAA Security and Privacy Rule), or the HIPAA Security and Privacy Rule, and (3) as would be permitted by the HIPAA Security and Privacy Rule if such use or disclosure as necessary.were made by Customer. All such uses and disclosures shall be subject to the limits set forth in 45 CFR § 164.514 regarding limited data sets and 45 CFR § 164.502(b) regarding the minimum necessary requirements;
4.2.4 Report to Covered Entity’s Privacy Officer, in writing, any suspected or confirmed access, use or disclosure of PHI or PI, regardless of form, not permitted or required by this Agreement of which (b) Business Associate becomes aware within two (2) days of Business Associate’s discovery of such unauthorized use or disclosure.
4.2.5 Ensure will ensure that Business Associate’s subcontractors or agents its agents, including subcontractors, to whom Business Associate it provides PHI Protected Health Information received from or PI, received from, created, or received created by the Business Associate on behalf of the Covered EntityCustomer, agree to the same restrictions and conditions that apply to the Business Associate with respect to PHI and PIsuch information, and ensure that its subcontractors or agents agree to establish and implement reasonable and appropriate safeguards to protect the confidentialityany of such information which is Electronic Protected Health Information. In addition, integrity, and availability of all PHI and PI that it creates receives, maintains, or transmits on behalf of Covered Entity.
4.2.6 The Business Associate must make agrees to take reasonable steps to ensure that its recordsemployees’ actions or omissions do not cause Business Associate to breach the terms of this Agreement;
(c) Business Associate, booksfollowing the discovery of a breach of unsecured PHI, accountsas defined in the HITECH Act or accompanying regulations, agreements, policies, and procedures available will notify the Customer of such breach pursuant to the Secretary terms of HHS for determining 45 CFR § 164.410 and cooperate in the Covered EntityCustomer’s compliance with the HIPAA Privacy and Security Rules.
4.2.7 Use or disclose to its subcontractorsbreach analysis procedures, agents, other third parties, and Covered Entity, only the minimum PHI and PI necessary to perform or fulfill a specific function required or permitted hereunder.
4.2.8 Provide information to Covered Entity to permit Covered Entity to respond to a request by an individual for an accounting of disclosures within five (5) days of receiving a written request from Covered Entityincluding risk assessment, if Business Associate maintains a Designated Records Set on behalf of Covered Entity.
4.2.9 At the request of, and in the time and manner designated by Covered Entity, provide access to the PHI and PI maintained requested. A breach shall be treated as discovered by Business Associate as of the first day on which such breach is known to Covered Entity or individual, if Business Associate maintains or, by exercising reasonable diligence, would have been known to Business Associate. Business Associate will provide such notification to Customer without unreasonable delay and in no event later than thirty (30) calendar days after discovery of the breach. Such notification will contain the elements required in 45 CFR § 164.410;
(d) Business Associate, pursuant to the HITECH Act and its implementing regulations, will comply with all additional applicable requirements of the Privacy Rule, including those contained in 45 CFR §§ 164.502(e) and 164.504(e)(1)(ii), at such time as the requirements are applicable to Business Associate. Business Associate will not directly or indirectly receive remuneration in exchange for any PHI, subject to the exceptions contained in the HITECH Act, without a Designated Records Set on behalf valid authorization from the applicable individual. Business Associate will not engage in any communication which might be deemed to be “marketing” under the HITECH Act. In addition, Business Associate will, pursuant to the HITECH Act and its implementing regulations, comply with all applicable requirements of Covered Entitythe Security Rule, contained in 45 CFR §§ 164.308, 164.310, 164.312 and 164.316, at such time as the requirements are applicable to Business Associate.
4.2.10 At the request of, and in the time and manner designated by Covered Entity, make any amendment(s(e) to the PHI and PI when directed by Covered Entity, if Business Associate maintains a Designated Record Set on behalf will implement appropriate safeguards to prevent use or disclosure of Covered Entity.
4.2.11 Establish and Protected Health Information other than as permitted in this Agreement. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any PHI and PI Business Associate Electronic Protected Health Information that it creates, receives, maintains maintains, or transmits on behalf of Covered EntityCustomer as required by the HIPAA Security and Privacy Rule.
4.2.12 Report (f) The Secretary of Health and Human Services shall have the right to audit Business Associate’s records and practices related to use and disclosure of Protected Health Information to ensure Customer’s compliance with the terms of the HIPAA Security and Privacy Rule.
(g) Business Associate will report to Customer any use or disclosure of Protected Health Information which is not in compliance with the terms of this Agreement of which it becomes aware. Business Associate shall report to Covered Entity any Security Incident involving PHI and PI that of which it becomes aware. For purposes of this Agreement, “Security Incident” means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. In addition, Business Associate discoversagrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement.
Appears in 1 contract
Sources: Business Associate Agreement
Responsibilities of Business Associate. Regarding the With regard to its use or and/or disclosure of PHI and PIPHI, the Business Associate hereby agrees toto do the following:
4.2.1 Only use or further 1. Use and/or disclose the PHI and PI as allowable under this Agreement or applicable law.
4.2.2 Only use or further disclosure PHI and PI in a manner that would not violate the HIPAA Privacy and Security Rules if done so by the Covered Entity.
4.2.3 Establish and implement appropriate procedures, physical, and technical safeguards to prevent improper access, uses, transmissions, or disclosures of PHI and PI for mitigating to the greatest extents possible under the circumstances any deleterious effects from any improper access, use, or disclosure of PHI and PI that Business Associate reports to Covered Entity. Safeguards shall include, but are not limited to, the implementation and use of electronic security measures to safeguard electronic data, requiring employees to agree to access, use, or disclose PHI and PI only as permitted or required by this Agreement or as otherwise required by law and taking related disciplinary action for inappropriate access, use or disclosure as to the minimum necessary.;
4.2.4 2. Report to Covered Entity’s Privacy Officerthe executive director or designated privacy officer of Homeward, the primary Business Associate, in writing, any suspected or confirmed access, use or and/or disclosure of the PHI or PI, regardless of form, that is not permitted or required by this Agreement of which Business Associate becomes aware aware, including breaches of unsecured protected health information as required at 45 C.F.R. § 164.410 and any security incident of which it becomes aware, within two fifteen (215) days of the Business Associate’s discovery of such unauthorized use or and/or disclosure.;
4.2.5 Ensure that Business Associate’s subcontractors or agents to whom Business Associate provides PHI or PI, received from, created, or received by the Business Associate on behalf of the Covered Entity, agree to the same restrictions 3. Develop and conditions that apply to the Business Associate with respect to PHI and PI, and ensure that its subcontractors or agents agree to establish and implement use reasonable and appropriate administrative, technical and physical safeguards to ensure and protect against reasonably anticipated threats or hazards to the confidentialitysecurity or integrity of PHI, integrityto protect against reasonably anticipated unauthorized use or disclosure of PHI, and availability to reasonably safeguard PHI from any intentional or unintentional use or disclosure in violation of all this Agreement;
4. To document disclosures of PHI and PI that it creates receives, maintains, or transmits on behalf of Covered Entity.
4.2.6 The Business Associate must make its records, books, accounts, agreements, policies, and procedures available to the Secretary of HHS for determining the Covered Entity’s compliance with the HIPAA Privacy and Security Rules.
4.2.7 Use or disclose to its subcontractors, agents, other third parties, and Covered Entity, only the minimum PHI and PI related information as necessary to perform or fulfill a specific function required or permitted hereunder.
4.2.8 Provide information to Covered Entity to permit Covered Entity to respond to a request by an individual for an accounting of PHI disclosures in accordance with 45 C.F.R. § 164.528;
5. Require all of its employees, representatives, subcontractors, or agents that receive or use or have access to PHI under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of PHI that apply herein, including the obligation to return or destroy the PHI as provided herein.
6. Make available all records, books, agreements, policies, and procedures relating to the use and/or disclosure of PHI to the Secretary of HHS for purposes of determining a Covered Entity’s compliance with the HIPAA Rules.
7. Upon request by a Covered Entity, make available during normal business hours at Business Associate’s offices all records, books, agreements, policies, and procedures relating to the use and/or disclosure of PHI to the Covered Entity within five (5) business days for purposes of enabling the Covered Entity to determine the Business Associate’s compliance with the terms of this Agreement;
8. Make PHI in a designated recordset available in accordance with 45 C.F.R. § 164.524.
9. Within ten (10) days of receiving a written request from Covered Entity, if Business Associate maintains a Designated Records Set on behalf of Covered Entity.
4.2.9 At the request of, and in the time and manner designated by Covered Entity, provide access to the Covered Entity such information as is requested to permit the Covered Entity to respond to a request by the subject individual for amendment and accounting purposes of the disclosures of the individual’s protected PHI in accordance with 45 C.F.R. § 164.526 & § 164.528;
10. Return to a Covered Entity or destroy, as requested by the Covered Entity, within fifteen (15) days of the termination of this Agreement, the PHI in Business Associate’s possession and PI maintained retain no copies or back-up tapes;
11. To mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Agreement; and
12. To take all steps necessary to Covered Entity or individual, if Business Associate maintains a Designated Records Set on behalf comply with the Notice of Covered EntityPrivacy Practices required under 45 C.F.R. § 164.520.
4.2.10 At the request of, and in the time and manner designated by Covered Entity, make any amendment(s) to the PHI and PI when directed by Covered Entity, if Business Associate maintains a Designated Record Set on behalf of Covered Entity.
4.2.11 Establish and implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any PHI and PI Business Associate creates, receives, maintains or transmits on behalf of Covered Entity.
4.2.12 Report to Covered Entity any Security Incident involving PHI and PI that Business Associate discovers.
Appears in 1 contract
Sources: Agency Participation and Business Associate Agreement
Responsibilities of Business Associate. Regarding If, during the use or disclosure term of PHI and PIthis Agreement, Business Associate is in receipt of PHI, Business Associate hereby agrees toto do the following:
4.2.1 Only use or further a. Use and/or disclose the PHI and PI as allowable under this Agreement or applicable law.
4.2.2 Only use or further disclosure PHI and PI in a manner that would not violate the HIPAA Privacy and Security Rules if done so by the Covered Entity.
4.2.3 Establish and implement appropriate procedures, physical, and technical safeguards to prevent improper access, uses, transmissions, or disclosures of PHI and PI for mitigating to the greatest extents possible under the circumstances any deleterious effects from any improper access, use, or disclosure of PHI and PI that Business Associate reports to Covered Entity. Safeguards shall include, but are not limited to, the implementation and use of electronic security measures to safeguard electronic data, requiring employees to agree to access, use, or disclose PHI and PI only as permitted or required by this the Agreement and taking related disciplinary action for inappropriate access, use or disclosure as necessaryotherwise Required by Law.
4.2.4 b. Report to Covered Entity’s the designated Privacy Officerand Security Officer of FMCNA, in writing, any suspected or confirmed access, use or and/or disclosure of the PHI or PI, regardless of form, that is not permitted or required by this the Agreement of which Business Associate becomes aware within two (2) days of Business Associate’s discovery of such unauthorized use or and/or disclosure.
4.2.5 Ensure c. Establish procedures for mitigating, to the greatest extent possible, any deleterious effects from any improper use and/or disclosure of PHI that Business Associate’s subcontractors or agents Associate reports to whom Business Associate provides PHI or PI, received from, created, or received by the Business Associate on behalf of the Covered Entity, agree to the same restrictions and conditions that apply to the Business Associate with respect to PHI and PI, and ensure that its subcontractors or agents agree to establish and implement reasonable and FMCNA.
d. Use appropriate safeguards to prevent unauthorized use and/or disclosure of PHI.
e. Implement Administrative, Physical, and Technical safeguards that reasonably and appropriately protect the confidentialityConfidentiality, integrityIntegrity and Availability of the Electronic PHI that Business Associate creates, and availability of all PHI and PI that it creates receives, maintains, or transmits on behalf of Covered EntityFMCNA.
4.2.6 The f. Require all of its subcontractors and agents that create, receive, maintain, transmit, use, or have access to, PHI governed by this Agreement to agree, in writing, to adhere to the same restrictions and conditions on the use, disclosure, and/or protection of PHI that apply to Business Associate must make its pursuant hereto.
g. Make available all records, books, accounts, agreements, policies, procedures, and procedures internal practices relating to the use and/or disclosure of PHI to the United States Secretary of Health and Human Services for purposes of determining FMCNA’s compliance with HIPAA, subject to attorney-client and other applicable legal privileges.
h. Upon prior written request, make available to FMCNA during normal business hours at Business Associate’s offices all records, books, agreements, policies and procedures, and internal practices relating to the Secretary use and/or disclosure of HHS PHI within three (3) days for determining the Covered Entitypurposes of enabling FMCNA to determine Business Associate’s compliance with the HIPAA Privacy and Security Rulesterms of this Agreement.
4.2.7 Use i. Upon termination of the Agreement, where feasible, destroy or disclose return to FMCNA within thirty (30) days all PHI received from, or created, received, maintained or transmitted by Business Associate on behalf of FMCNA. Where return or destruction is not feasible, the duties of Business Associate under this Agreement shall be extended to protect the PHI retained by Business Associate. Business Associate agrees to limit further uses and disclosures of the PHI retained to those purposes that made the return or destruction infeasible.
j. Disclose to its subcontractors, agents, agents or other third parties, and Covered Entityrequest from FMCNA, only the minimum PHI and PI necessary to perform or fulfill a specific function required or permitted hereunder.
4.2.8 Provide information k. Notify FMCNA within two (2) business days if an Individual (FMCNA patient or the patient’s legal representative) wishes to Covered Entity assert his or her right of access to permit Covered Entity obtain a copy of PHI as set forth in 45 C.F.R. § 164.524.
l. At the request of FMCNA, and in the time and manner specified by FMCNA, provide access to PHI contained in a Designated Record Set to an Individual in accordance with the terms and provisions of 45 C.F.R. § 164.524. FMCNA’s determination of what constitutes PHI or a Designated Record Set shall be final and conclusive.
m. Notify FMCNA within two (2) business days if an Individual (FMCNA patient or the patient’s legal representative) wishes to assert his or her right to amend PHI or amend a record in a Designated Record Set as set forth in 45 C.F.R. § 164.526.
n. Make any amendment(s) to an Individual’s PHI contained in a Designated Record Set that FMCNA directs or agrees to pursuant to 45 C.F.R. § 164.526 and in the time and manner directed by FMCNA. FMCNA’s determination of what PHI is subject to amendment pursuant to 45 C.F.R. § 164.526 shall be final and conclusive.
o. Notify FMCNA within two (2) business days if an Individual (FMCNA patient or the patient’s legal representative) wishes to assert his or her right to receive an accounting of disclosures of PHI as set forth in 45 C.F.R. § 164.528.
p. Document any disclosures of PHI that would be required for FMCNA to respond to a request by an individual Individual for an accounting of disclosures within five (5) days of receiving a written request from Covered Entity, if PHI in accordance with 45 C.F.R. § 164.528. Business Associate maintains agrees to provide to FMCNA, in a Designated Records Set on behalf of Covered Entity.
4.2.9 At the request of, and in the time and manner designated by Covered EntityFMCNA, provide access the information collected in accordance with this paragraph to the PHI and PI maintained permit FMCNA respond to a request by Business Associate an Individual for an accounting of disclosures pursuant to Covered Entity or individual, if Business Associate maintains a Designated Records Set on behalf of Covered Entity45 C.F.R. § 164.528.
4.2.10 At the request ofq. Report in writing, and in the time and manner designated by Covered Entitywithin two (2) days, make any amendment(s) to the PHI and PI when directed by Covered Entity, if Business Associate maintains a Designated Record Set on behalf of Covered Entity.
4.2.11 Establish and implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any PHI and PI Business Associate creates, receives, maintains or transmits on behalf of Covered Entity.
4.2.12 Report to Covered Entity FMCNA any Security Incident involving PHI and PI that (as defined in 45 C.F.R. § 164.304) of which Business Associate discoversbecomes aware. However, the obligation to report a Security Incident shall not include immaterial incidents, such as unsuccessful attempts to penetrate Business Associate’s information system.
Appears in 1 contract
Sources: Transfer and Administration Agreement (Fresenius Medical Care AG & Co. KGaA)