Common use of Responsibilities of Business Associate Clause in Contracts

Responsibilities of Business Associate. Business Associate agrees: a. to use appropriate safeguards, and to comply with Subpart C of 45 CFR Part 164 with respect to electronic protected health information, to prevent use or disclosure of protected health information other than as provided for by the Agreement. b. to report to Covered Entity promptly, but in no case longer than fifteen (15) business days, any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including a Breach of Unsecured PHI as required by 45 C.F.R. § 164.410, and any successful Security Incident of which it becomes aware. The Parties acknowledge and agree that this section 4.b. constitutes notice by Business Associate to Covered Entity of the ongoing existence and occurrence or attempts of Unsuccessful Security Incidents for which no additional notice to Covered Entity shall be required. “Unsuccessful Security Incidents” means, without limitation, pings and other broadcast attacks on Business Associate’s firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and any combination of the above, so long as no such incident results in unauthorized access, use, or disclosure of PHI. The contact information for the Business Associate and Covered Entity employees to whom reports of unauthorized use or disclosure of PHI, Breaches of Unsecured PHI and successful Security Incidents under this Section shall be made as provided below (as such information may be updated from time to time between the parties). Notification shall be made using the methods as provided in the relevant Underlying Agreement. Business Associate: ▇▇▇▇▇ ▇▇▇▇▇▇▇▇, Chief Legal & Compliance Officer DeliverHealth Solutions, LLC ▇▇▇▇ ▇▇▇▇▇▇▇ ▇▇., ▇▇▇▇▇ ▇▇▇ ▇▇▇▇▇▇▇, ▇▇ ▇▇▇▇▇ Email: ▇▇▇▇▇▇▇▇▇▇@▇▇▇▇▇▇▇▇▇▇▇▇▇.▇▇▇ Covered Entity: [Employee Name and Title] [Company Name] [Street Address] [City, State, Zip] [Phone] [Email]

Appears in 3 contracts

Sources: General Terms and Conditions Agreement, General Terms and Conditions Agreement, General Terms and Conditions Agreement

Responsibilities of Business Associate. Business Associate agreesshall: a. to use 2.1.1 Use or Disclose PHI only as expressly authorized by this BAA or as Required by Law. 2.1.2 Use appropriate safeguards, and to comply with Subpart C of 45 CFR C.F.R. Part 164 with respect to electronic protected health informationPHI, to prevent use Use or disclosure Disclosure of protected health information PHI other than as provided for by the Agreementthis BAA. b. to report 2.1.3 Report, in writing, to Covered Entity promptly, but in no case longer than fifteen within five (155) business days, days of (i) any use or disclosure of PHI not provided for by this Agreement Security Incident of which Business Associate it becomes aware, including a (ii) any Breach of Unsecured PHI as required by 45 C.F.R. § 164.410164.410(c), and any successful Security Incident (iii) all other Uses or Disclosures of PHI not permitted by this BAA of which it becomes aware. Business Associate shall mitigate, to the extent reasonably possible, any harmful effects that are known to Business Associate of any Security Incident, Breach, or other unauthorized Use or Disclosure of PHI, and cooperate with Covered Entity in any mitigation or Breach reporting efforts. The Parties acknowledge and agree that this section 4.b. Section 2.1.3 constitutes notice by Business Associate to Covered Entity of the ongoing existence and occurrence or attempts of Unsuccessful Security Incidents (as defined below) for which no other additional notice to Covered Entity shall be required. “Unsuccessful Security Incidents” means, without limitation, shall include pings and other broadcast attacks on Business Associate’s firewall, port scans, unsuccessful log-on attempts, denial denials of service attacksattacks that do not result in a server being taken offline, and any combination of the above, so long as no such incident results in any of the following: (i) unauthorized access, useUse, Disclosure, modification, or disclosure destruction of PHI. The contact ; (ii) modifications to Business Associate’s security policies or procedures; (iii) modifications to Business Associate’s safeguarding measures; (iv) interference with Business Associate’s operations; or (v) interference with Business Associate’s information for the systems. 2.1.4 Ensure that any Subcontractors that create, receive, maintain or transmit PHI on behalf of Business Associate agree, in writing, to substantially the same restrictions, conditions, and requirements that apply to Business Associate with respect to PHI, in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2). 2.1.5 Not maintain, transmit, or export PHI beyond the borders of the United States of America for any purpose or permit anyone located outside the borders of the United States of America access to PHI. 2.1.6 Make available PHI in a designated record set to Covered Entity employees as necessary to whom reports satisfy Covered Entity’s obligations under 45 C.F.R. § 164.524, within ten (10) business days of unauthorized use a request by Covered Entity. 2.1.7 Make any amendment(s) to PHI in a designated record set as directed or disclosure agreed to by Covered Entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.526, within ten (10) business days of PHI, Breaches a request by Covered Entity. 2.1.8 Document Disclosures of Unsecured PHI and successful Security Incidents under this Section shall be made maintain information related to such Disclosures as provided below required for Covered Entity to respond to a request by an Individual for an accounting of Disclosures of PHI in accordance with 45 CFR § 164.528. 2.1.9 Make available to Covered Entity the information required for Covered Entity to provide an accounting of disclosures in accordance with 45 C.F.R. § 164.528, within ten (as such information may be updated from time to time between the parties). Notification shall be made using the methods as provided in the relevant Underlying Agreement. Business Associate: ▇▇▇▇▇ ▇▇▇▇▇▇▇▇, Chief Legal & Compliance Officer DeliverHealth Solutions, LLC ▇▇▇▇ ▇▇▇▇▇▇▇ ▇▇., ▇▇▇▇▇ ▇▇▇ ▇▇▇▇▇▇▇, ▇▇ ▇▇▇▇▇ Email: ▇▇▇▇▇▇▇▇▇▇@▇▇▇▇▇▇▇▇▇▇▇▇▇.▇▇▇ 10) business days of a request by Covered Entity: [Employee Name . 2.1.10 Notify Covered Entity in writing within five (5) business days of its receipt of a request directly from an Individual for access to or amendment of PHI or an accounting of disclosures. 2.1.11 Comply with the requirements of Subpart E of 45 C.F.R. Part 164 that apply to Covered Entity to the extent Business Associate is to carry out one or more of Covered Entity’s obligation(s) under Subpart E. 2.1.12 Make its internal practices, books, and Title] [Company Name] [Street Address] [City, State, Zip] [Phone] [Email]records relating to the Use and Disclosure of PHI available to the Secretary and to Covered Entity upon request for purposes of determining Covered Entity’s compliance with the HIPAA Rules. 2.1.13 Comply with the minimum necessary requirements under the HIPAA Rules.

Appears in 2 contracts

Sources: Business Associate Agreement, Business Associate Agreement

Responsibilities of Business Associate. Business Associate agrees: a. to use appropriate safeguards, and to comply with Subpart C of 45 CFR Part 164 with respect to electronic protected health information, to prevent use or disclosure of protected health information other than as provided for by the Agreement. b. to report to Covered Entity promptly, but in no case longer than fifteen (15) business days, any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including a Breach of Unsecured PHI as required by 45 C.F.R. § 164.410, and any successful Security Incident of which it becomes aware. The Parties acknowledge and agree that this section 4.b. constitutes notice by Business Associate to Covered Entity of the ongoing existence and occurrence or attempts of Unsuccessful Security Incidents for which no additional notice to Covered Entity shall be required. “Unsuccessful Security Incidents” means, without limitation, pings and other broadcast attacks on Business Associate’s firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and any combination of the above, so long as no such incident results in unauthorized access, use, or disclosure of PHI. The contact information for the Business Associate and Covered Entity employees to whom reports of unauthorized use or disclosure of PHI, Breaches of Unsecured PHI and successful Security Incidents under this Section shall be made as provided below (as such information may be updated from time to time between the parties). Notification shall be made using the methods as provided in the relevant Underlying Agreement. Business Associate: ▇▇▇▇▇ ▇▇▇▇▇▇▇▇, Chief Legal & Compliance Officer Department DeliverHealth Solutions, LLC ▇▇▇▇ ▇▇▇▇▇▇▇ ▇▇., ▇▇▇▇▇ ▇▇▇ ▇▇▇▇▇▇▇, ▇▇ ▇▇▇▇▇ Email: ▇▇▇▇▇▇▇▇.▇▇▇▇▇▇▇▇▇▇@▇▇▇▇▇▇▇▇▇▇▇▇▇.▇▇▇ Covered Entity: [Employee Name and Title] [Company Name] [Street Address] [City, State, Zip] [Phone] [Email]

Appears in 1 contract

Sources: General Terms and Conditions Agreement