{"component": "clause", "props": {"groups": [{"size": 118, "snippet_links": [{"key": "business-associate", "type": "definition", "offset": [0, 18]}], "samples": [{"hash": "A8Z2DruOfA", "uri": "/contracts/A8Z2DruOfA#responsibilities-of-business-associate", "label": "Agreement for Special Services", "score": 36.5167694092, "published": true}, {"hash": "g35dmch1iEF", "uri": "/contracts/g35dmch1iEF#responsibilities-of-business-associate", "label": "Agreement for Special Services", "score": 36.4552307129, "published": true}, {"hash": "hOOj5zXQ3av", "uri": "/contracts/hOOj5zXQ3av#responsibilities-of-business-associate", "label": "Contract No. 2020243", "score": 36.4019546509, "published": true}], "snippet": "Business Associate agrees:", "hash": "29642252bca951a75618e36dbfcbf58f", "id": 1}, {"size": 35, "snippet_links": [{"key": "with-regard-to", "type": "clause", "offset": [0, 14]}, {"key": "disclosure-of-phi", "type": "clause", "offset": [30, 47]}, {"key": "business-associate-shall", "type": "definition", "offset": [49, 73]}, {"key": "agreement-or", "type": "definition", "offset": [145, 157]}, {"key": "required-by-law", "type": "clause", "offset": [171, 186]}, {"key": "report-to", "type": "definition", "offset": [192, 201]}, {"key": "privacy-officer", "type": "definition", "offset": [206, 221]}, {"key": "in-writing", "type": "definition", "offset": [241, 251]}, {"key": "not-permitted", "type": "clause", "offset": [298, 311]}, {"key": "business-days-of", "type": "clause", "offset": [405, 421]}, {"key": "determination-of-the", "type": "clause", "offset": [443, 463]}, {"key": "unauthorized-use", "type": "definition", "offset": [483, 499]}, {"key": "use-commercially-reasonable-efforts", "type": "clause", "offset": [523, 558]}, {"key": "to-maintain", "type": "clause", "offset": [559, 570]}, {"key": "security-of-the", "type": "clause", "offset": [575, 590]}, {"key": "subcontractors-and-agents", "type": "clause", "offset": [698, 723]}, {"key": "agree-to", "type": "clause", "offset": [769, 777]}, {"key": "adhere-to", "type": "clause", "offset": [778, 787]}, {"key": "restrictions-and-conditions", "type": "clause", "offset": [797, 824]}, {"key": "pursuant-to-this-agreement", "type": "clause", "offset": [894, 920]}, {"key": "written-request", "type": "clause", "offset": [965, 980]}, {"key": "make-available", "type": "definition", "offset": [982, 996]}, {"key": "internal-practices", "type": "clause", "offset": [1001, 1019]}, {"key": "policies-and-procedures", "type": "definition", "offset": [1049, 1072]}, {"key": "relating-to", "type": "definition", "offset": [1081, 1092]}, {"key": "the-secretary", "type": "clause", "offset": [1129, 1142]}, {"key": "for-purposes-of", "type": "clause", "offset": [1143, 1158]}, {"key": "compliance-with-the-privacy-rule", "type": "clause", "offset": [1188, 1220]}, {"key": "document-disclosures", "type": "clause", "offset": [1226, 1246]}, {"key": "and-information", "type": "clause", "offset": [1254, 1269]}, {"key": "related-to", "type": "definition", "offset": [1270, 1280]}, {"key": "to-covered-entity", "type": "clause", "offset": [1396, 1413]}, {"key": "such-information", "type": "definition", "offset": [1414, 1430]}, {"key": "by-covered-entity", "type": "clause", "offset": [1447, 1464]}, {"key": "respond-to", "type": "definition", "offset": [1493, 1503]}, {"key": "an-individual", "type": "clause", "offset": [1517, 1530]}, {"key": "the-individual", "type": "clause", "offset": [1571, 1585]}, {"key": "in-accordance-with", "type": "definition", "offset": [1592, 1610]}, {"key": "section-44", "type": "clause", "offset": [1647, 1658]}, {"key": "return-to", "type": "definition", "offset": [1666, 1675]}, {"key": "termination-of-this-agreement", "type": "clause", "offset": [1735, 1764]}, {"key": "no-copies", "type": "clause", "offset": [1803, 1812]}, {"key": "backup-copies", "type": "clause", "offset": [1824, 1837]}, {"key": "other-third-parties", "type": "definition", "offset": [1885, 1904]}, {"key": "designated-record-set", "type": "definition", "offset": [2105, 2126]}, {"key": "access-to-the", "type": "clause", "offset": [2216, 2229]}, {"key": "as-directed", "type": "definition", "offset": [2283, 2294]}, {"key": "authorized-representative", "type": "clause", "offset": [2368, 2393]}], "samples": [{"hash": "jWZr3M0d6FX", "uri": "/contracts/jWZr3M0d6FX#responsibilities-of-business-associate", "label": "Business Associate Agreement (Prospect Medical Holdings Inc)", "score": 19.0, "published": true}, {"hash": "imIT0WsYizu", "uri": "/contracts/imIT0WsYizu#responsibilities-of-business-associate", "label": "Business Associate Agreement (Prospect Medical Holdings Inc)", "score": 19.0, "published": true}, {"hash": "hnbyCivTjWt", "uri": "/contracts/hnbyCivTjWt#responsibilities-of-business-associate", "label": "Business Associate Agreement (Prospect Medical Holdings Inc)", "score": 19.0, "published": true}], "snippet": "With regard to its use and/or disclosure of PHI, Business Associate shall:\n(a) use and/or disclose the PHI only as permitted or required by this Agreement or as otherwise required by law;\n(b) report to the privacy officer of Covered Entity, in writing, any use and/or disclosure of the PHI that is not permitted or required by this Agreement of which Business Associate becomes aware, within fifteen (15) business days of Business Associate's determination of the occurrence of such unauthorized use and/or disclosure;\n(c) use commercially reasonable efforts to maintain the security of the PHI and to prevent use and/or disclosure of such PHI other than as provided herein;\n(d) require all of its subcontractors and agents that receive, use, or have access to, PHI to agree to adhere to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate pursuant to this Agreement;\n(e) upon fifteen (15) business days' prior written request, make available all internal practices, records, books, agreements, policies and procedures and PHI relating to the use and/or disclosure of PHI to the Secretary for purposes of determining Covered Entity's compliance with the Privacy Rule;\n(f) document disclosures of PHI and information related to such disclosure and, within fifteen (15) business days of receiving a written request from Covered Entity, provide to Covered Entity such information as is requested by Covered Entity to permit Covered Entity to respond to a request by an individual for an accounting of the disclosures of the individual's PHI in accordance with 45 C.F.R. \u00a7 164.528;\n(g) subject to Section 4.4 below, return to Covered Entity within twenty-one (21) business days of the termination of this Agreement, the PHI in its possession and retain no copies, including backup copies;\n(h) disclose to its subcontractors, agents or other third parties, and request from Covered Entity, only the minimum PHI necessary to perform or fulfill a specific function required or permitted hereunder; and\n(i) if all or any portion of the PHI is maintained in a Designated Record Set:\n(i) upon fifteen (15) business days' prior written request from Covered Entity, provide access to the PHI in a Designated Record Set to Covered Entity or, as directed by Covered Entity, the individual to whom such PHI relates or his or her authorized representative to meet a request by such individual under 45 C.F.R. \u00a7 164.524; and\n(ii) upon fifteen (15) business days' prior written request from Covered Entity, make any amendment(s) to the PHI that Covered Entity directs pursuant to 45 C.F.R. \u00a7 164.526.", "hash": "28519aaef7b0e33ae65aeecfc71f7bd0", "id": 2}, {"size": 27, "snippet_links": [{"key": "business-associate-shall", "type": "definition", "offset": [3, 27]}, {"key": "relevant-training", "type": "clause", "offset": [36, 53]}, {"key": "agreement-to", "type": "definition", "offset": [92, 104]}, {"key": "materials-and-records", "type": "clause", "offset": [153, 174]}, {"key": "upon-request", "type": "definition", "offset": [215, 227]}, {"key": "administrative-safeguards", "type": "definition", "offset": [311, 336]}, {"key": "availability-of-phi", "type": "clause", "offset": [412, 431]}, {"key": "compliance-date", "type": "definition", "offset": [565, 580]}, {"key": "from-the-effective-date", "type": "clause", "offset": [592, 615]}, {"key": "provisions-of-the", "type": "clause", "offset": [644, 661]}, {"key": "risk-assessment", "type": "definition", "offset": [716, 731]}, {"key": "compliance-with-the-security-rule", "type": "clause", "offset": [744, 777]}, {"key": "the-request", "type": "clause", "offset": [792, 803]}, {"key": "the-risk", "type": "definition", "offset": [915, 923]}, {"key": "portable-media", "type": "definition", "offset": [1006, 1020]}, {"key": "storage-devices", "type": "clause", "offset": [1024, 1039]}, {"key": "after-receiving", "type": "clause", "offset": [1141, 1156]}, {"key": "written-request", "type": "clause", "offset": [1159, 1174]}, {"key": "available-information", "type": "clause", "offset": [1201, 1222]}, {"key": "for-covered-entity", "type": "clause", "offset": [1233, 1251]}, {"key": "accounting-of-disclosures-of-phi", "type": "clause", "offset": [1263, 1295]}, {"key": "an-individual", "type": "clause", "offset": [1302, 1315]}, {"key": "in-accordance-with", "type": "definition", "offset": [1357, 1375]}, {"key": "implementing-regulations", "type": "definition", "offset": [1405, 1429]}, {"key": "the-individual", "type": "clause", "offset": [1490, 1504]}, {"key": "directed-to", "type": "definition", "offset": [1508, 1519]}, {"key": "by-covered-entity", "type": "clause", "offset": [1526, 1543]}, {"key": "not-to-exceed", "type": "clause", "offset": [1645, 1658]}, {"key": "access-to-phi", "type": "clause", "offset": [1676, 1689]}, {"key": "designated-record-set", "type": "definition", "offset": [1695, 1716]}, {"key": "to-covered-entity", "type": "clause", "offset": [1717, 1734]}, {"key": "associated-with", "type": "definition", "offset": [1972, 1987]}, {"key": "the-production", "type": "clause", "offset": [1988, 2002]}, {"key": "receipt-of-a", "type": "clause", "offset": [2175, 2187]}, {"key": "amendment-and", "type": "clause", "offset": [2231, 2244]}, {"key": "amendments-to-the", "type": "clause", "offset": [2261, 2278]}, {"key": "as-directed", "type": "definition", "offset": [2283, 2294]}, {"key": "notify-covered-entity", "type": "clause", "offset": [2386, 2407]}, {"key": "request-for-an-accounting", "type": "definition", "offset": [2515, 2540]}, {"key": "amendment-of-phi", "type": "clause", "offset": [2572, 2588]}, {"key": "sections-ii", "type": "clause", "offset": [2608, 2619]}, {"key": "restrictions-and-conditions", "type": "clause", "offset": [2732, 2759]}, {"key": "subject-to-the", "type": "clause", "offset": [3086, 3100]}, {"key": "laws-of-the-united-states", "type": "definition", "offset": [3117, 3142]}, {"key": "the-obligations", "type": "clause", "offset": [3193, 3208]}, {"key": "jurisdiction-of-the-united-states", "type": "definition", "offset": [3264, 3297]}, {"key": "written-contract", "type": "clause", "offset": [3357, 3373]}, {"key": "the-secretary", "type": "clause", "offset": [3435, 3448]}, {"key": "the-laws", "type": "definition", "offset": [3450, 3458]}, {"key": "the-parties", "type": "definition", "offset": [3561, 3572]}, {"key": "agreement-or", "type": "definition", "offset": [3727, 3739]}, {"key": "required-by", "type": "definition", "offset": [3753, 3764]}, {"key": "provided-that", "type": "definition", "offset": [3775, 3788]}, {"key": "applicable-requirement", "type": "definition", "offset": [3866, 3888]}, {"key": "in-compliance-with", "type": "definition", "offset": [3919, 3937]}, {"key": "following-the-effective-date", "type": "clause", "offset": [4015, 4043]}, {"key": "minimum-amount", "type": "clause", "offset": [4128, 4142]}, {"key": "purpose-of-the", "type": "clause", "offset": [4178, 4192]}, {"key": "without-unreasonable-delay", "type": "definition", "offset": [4344, 4370]}, {"key": "not-permitted", "type": "clause", "offset": [4516, 4529]}, {"key": "security-incident", "type": "clause", "offset": [4553, 4570]}, {"key": "notification-of", "type": "definition", "offset": [4617, 4632]}, {"key": "description-of-the", "type": "definition", "offset": [4699, 4717]}, {"key": "to-mitigate", "type": "definition", "offset": [4786, 4797]}, {"key": "types-of", "type": "clause", "offset": [5106, 5114]}, {"key": "written-updates", "type": "clause", "offset": [5133, 5148]}, {"key": "the-event", "type": "definition", "offset": [5177, 5186]}, {"key": "other-information", "type": "clause", "offset": [5211, 5228]}, {"key": "requested-by", "type": "clause", "offset": [5240, 5252]}, {"key": "all-information", "type": "clause", "offset": [5279, 5294]}, {"key": "part-164", "type": "clause", "offset": [5401, 5409]}, {"key": "notice-to-individuals", "type": "clause", "offset": [5487, 5508]}, {"key": "the-us", "type": "clause", "offset": [5510, 5517]}, {"key": "department-of-health", "type": "definition", "offset": [5519, 5539]}, {"key": "human-services", "type": "clause", "offset": [5542, 5556]}, {"key": "the-media", "type": "clause", "offset": [5569, 5578]}, {"key": "if-required", "type": "definition", "offset": [5580, 5591]}, {"key": "sole-and-absolute-discretion", "type": "definition", "offset": [5675, 5703]}, {"key": "costs-of", "type": "clause", "offset": [5788, 5796]}, {"key": "notices-required", "type": "clause", "offset": [5892, 5908]}, {"key": "breach-notice-rule", "type": "definition", "offset": [5916, 5934]}, {"key": "other-applicable-law", "type": "clause", "offset": [5938, 5958]}, {"key": "to-the-extent-practicable", "type": "definition", "offset": [5998, 6023]}, {"key": "use-or-disclosure-of-phi-by-business-associate", "type": "clause", "offset": [6085, 6131]}, {"key": "to-hhs", "type": "clause", "offset": [6210, 6216]}, {"key": "internal-practices", "type": "clause", "offset": [6221, 6239]}, {"key": "relating-to", "type": "definition", "offset": [6261, 6272]}, {"key": "use-and-disclosure-of-phi", "type": "clause", "offset": [6277, 6302]}, {"key": "for-purposes-of", "type": "clause", "offset": [6329, 6344]}, {"key": "and-covered", "type": "clause", "offset": [6378, 6389]}, {"key": "compliance-with-the-privacy-rule", "type": "clause", "offset": [6399, 6431]}, {"key": "directly-or-indirectly", "type": "clause", "offset": [6465, 6487]}, {"key": "in-exchange", "type": "clause", "offset": [6509, 6520]}, {"key": "comply-with-the", "type": "clause", "offset": [6683, 6698]}, {"key": "requirements-of-the", "type": "clause", "offset": [6699, 6718]}, {"key": "in-the-performance", "type": "clause", "offset": [6761, 6779]}, {"key": "contact-information", "type": "clause", "offset": [6837, 6856]}, {"key": "primary-person", "type": "definition", "offset": [6865, 6879]}, {"key": "secondary-person", "type": "definition", "offset": [6888, 6904]}, {"key": "changes-in", "type": "clause", "offset": [6924, 6934]}, {"key": "respond-in-writing", "type": "definition", "offset": [7033, 7051]}, {"key": "business-days", "type": "definition", "offset": [7062, 7075]}, {"key": "responsibilities-of-the-business-associate", "type": "clause", "offset": [7210, 7252]}, {"key": "as-specified", "type": "clause", "offset": [7253, 7265]}, {"key": "attestation-of-compliance", "type": "clause", "offset": [7464, 7489]}], "samples": [{"hash": "1m27qzMNTR3", "uri": "/contracts/1m27qzMNTR3#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 26.1690616608, "published": true}, {"hash": "llwUWQh8gOZ", "uri": "/contracts/llwUWQh8gOZ#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 26.1430530548, "published": true}, {"hash": "jpOayZQronT", "uri": "/contracts/jpOayZQronT#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 26.1430530548, "published": true}], "snippet": "A. Business Associate shall provide relevant training on HIPAA and the requirements of this agreement to all persons accessing PHI or ePHI. The training materials and records shall be provided to the covered entity upon request.\nB. Business Associate shall implement and use appropriate Technical, Physical and Administrative Safeguards to reasonably and appropriately protect the Confidentiality, Integrity and Availability of PHI and to prevent Use or Disclosure of PHI, other than as permitted by this BAA.\nC. Business Associate shall, within the earlier of the Compliance Date or 90-days from the Effective Date, comply with all applicable provisions of the Security Rule. The Business Associate shall conduct a risk assessment to evaluate compliance with the Security Rule and shall, at the request of the Covered Entity, provide a written attestation acknowledging completion and communicating the results of the risk assessment.\nD. Business Associate shall Encrypt all transmissions of ePHI and all portable media or storage devices on which ePHI may be stored, including laptops, back-up media, CDs, or USB drives.\nE. Within 30-days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual, as provided in 45 C.F.R. \u00a7 164.528; and in accordance with 42 U.S.C. \u00a7 17935(c) and its implementing regulations as of the Compliance Date, make that accounting directly to the Individual if directed to do so by Covered Entity.\nF. At the request of Covered Entity and in the time, manner, and form designated by Covered Entity, not to exceed 15-days, provide access to PHI in a Designated Record Set to Covered Entity or, if directed by Covered Entity, to an Individual or to a recipient designated by the Individual, in accordance with the requirements of 45 C.F.R. \u00a7 164.524. Business Associate shall not charge Covered Entity or any Individual any fee associated with the production of PHI in accordance with this section that exceeds fees described at 45 C.F.R. \u00a7 164.524.\nG. Make available PHI in a Designated Record Set, no more than 30-days following receipt of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. \u00a7 164.526.\nH. Business Associate shall notify Covered Entity, in writing, no more than 3-days following Business Associate\u2019s receipt directly from an Individual of any request for an accounting of disclosures or access to or amendment of PHI as contemplated in Sections II (D) (E) or (F), above.\nI. Business Associate shall require each Subcontractor to agree, in writing, to the same restrictions and conditions that apply to Business Associate. Furthermore, to the extent that Business Associate provides ePHI to Subcontractor, Business Associate shall require Subcontractor to comply with all applicable provisions of the Security Rule upon the earlier of the Compliance Date or 90-days from the Effective Date. If Subcontractor is not subject to the jurisdiction or laws of the United States, or if any use or disclosure of PHI in performing the obligations under this BAA or the Agreement will be outside of the jurisdiction of the United States, Business Associate must require Subcontractor to agree by written contract with Business Associate to be subject to the jurisdiction of the Secretary, the laws, and the courts of the United States, and waive any available jurisdictional defenses that pertain to the parties\u2019 obligations under this BAA, HIPAA, or ARRA.\nJ. Business Associate shall not Use or Disclose PHI except as necessary to perform its obligations under the Agreement or as otherwise required by this BAA, provided that such Use or Disclosure is permitted by applicable law and complies with each applicable requirement of 45 C.F.R. \u00a7 164.504(e).\n1. In compliance with 45 C.F.R. \u00a7 164.502(b)(1), as of its Compliance Date or no more than 90-days following the Effective Date, whichever is earlier, Business Associate shall request, Use, and Disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, Use, or Disclosure.\n2. Business Associate shall not use PHI to make or cause to be made any communication that would constitute Marketing.\nK. Without unreasonable delay, and in any event, no more than 24-hours after Discovery, Business Associate shall notify Covered Entity of any Breach, Use or Disclosure of PHI not permitted under this BAA, or any Security Incident. Business Associate shall deliver the initial notification of such Breach, in writing, which must include a reasonably detailed description of the Breach and the steps Business Associate is taking and would propose to mitigate or terminate the Breach. Furthermore, Business Associate shall supplement the initial notification, no more than 5 calendar-days following Discovery, with information including the identification of each individual whose PHI was or is believed to have been involved; a reasonably detailed description of the types of PHI involved, and written updates every 5 calendar-days until the event has been concluded; all other information reasonably requested by Covered Entity, including all information necessary to enable Covered Entity to perform and document a risk assessment in accordance with 45 C.F.R. Part 164 subpart D; and all other information necessary for Covered Entity to provide notice to individuals, the U.S. Department of Health & Human Services (\u201cHHS\u201d), or the media, if required. Despite anything to the contrary in the preceding provisions, in Covered Entity\u2019s sole and absolute discretion and in accordance with its directions, Business Associate shall conduct, or pay the costs of conducting, an investigation of any Breach and shall provide or pay the costs of providing any notices required by the Breach Notice Rule or other applicable law.\nL. Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a Use or Disclosure of PHI by Business Associate that is not permitted by this BAA.\nM. Business Associate shall make available to HHS its internal practices, books, and records, relating to the Use and Disclosure of PHI pursuant to the Agreement for purposes of determining Business Associate\u2019s and Covered Entity\u2019s compliance with the Privacy Rule.\nN. Business Associate shall not directly or indirectly receive remuneration in exchange for any PHI.\nO. To the extent Business Associate is to carry out one or more of Covered Entity\u2019s obligations under the Privacy Rule, the Business Associate shall comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of such obligations.\nP. Business Associate shall provide contact information for one primary person and one secondary person in Appendix A. Any changes in the contact information shall be forwarded to the Covered Entity.\nQ. The Business Associate shall respond in writing within 10 business days to the Covered Entity\u2019s request(s) to attest to the Business Associate\u2019s compliance with the Privacy Rule, the Security Rule, and the Responsibilities of the Business Associate as specified in this BAA. The Business Associate shall make available to the Covered Entity its internal practices, books, and records, relating to the Use and Disclosure of PHI as necessary to substantiate the attestation of compliance.", "hash": "c32fd4f7bb21d781ca52e8b428d84613", "id": 3}, {"size": 19, "snippet_links": [{"key": "with-regard-to", "type": "clause", "offset": [4, 18]}, {"key": "business-associate-agrees-to", "type": "clause", "offset": [53, 81]}, {"key": "the-services", "type": "clause", "offset": [140, 152]}, {"key": "in-compliance-with", "type": "definition", "offset": [219, 237]}, {"key": "applicable-requirement", "type": "definition", "offset": [243, 265]}, {"key": "required-by-law", "type": "clause", "offset": [308, 323]}, {"key": "administrative-safeguards", "type": "definition", "offset": [383, 408]}, {"key": "availability-of", "type": "clause", "offset": [587, 602]}, {"key": "on-behalf-of", "type": "clause", "offset": [653, 665]}, {"key": "date-of", "type": "clause", "offset": [717, 724]}, {"key": "the-requirements", "type": "clause", "offset": [756, 772]}, {"key": "to-covered-entity", "type": "clause", "offset": [859, 876]}, {"key": "not-permitted", "type": "clause", "offset": [945, 958]}, {"key": "security-incident", "type": "clause", "offset": [999, 1016]}, {"key": "without-unreasonable-delay", "type": "definition", "offset": [1064, 1090]}, {"key": "in-no-case", "type": "clause", "offset": [1095, 1105]}, {"key": "days-after", "type": "definition", "offset": [1137, 1147]}, {"key": "business-associate-shall", "type": "definition", "offset": [1159, 1183]}, {"key": "notify-covered-entity", "type": "clause", "offset": [1184, 1205]}, {"key": "unsecured-phi", "type": "definition", "offset": [1225, 1238]}, {"key": "in-accordance-with", "type": "definition", "offset": [1243, 1261]}, {"key": "subcontractors-and-agents", "type": "clause", "offset": [1333, 1358]}, {"key": "in-writing", "type": "definition", "offset": [1417, 1427]}, {"key": "restrictions-and-conditions", "type": "clause", "offset": [1441, 1468]}, {"key": "a-subcontractor", "type": "definition", "offset": [1594, 1609]}, {"key": "the-subcontractor", "type": "clause", "offset": [1637, 1654]}, {"key": "reasonable-and-appropriate-safeguards", "type": "clause", "offset": [1677, 1714]}, {"key": "make-available", "type": "definition", "offset": [1741, 1755]}, {"key": "internal-practices", "type": "clause", "offset": [1760, 1778]}, {"key": "relating-to", "type": "definition", "offset": [1799, 1810]}, {"key": "use-and-disclosure-of-phi", "type": "clause", "offset": [1815, 1840]}, {"key": "the-secretary", "type": "clause", "offset": [1844, 1857]}, {"key": "for-purposes-of", "type": "clause", "offset": [1858, 1873]}, {"key": "compliance-with-the-privacy-rule", "type": "clause", "offset": [1903, 1935]}, {"key": "within-thirty", "type": "clause", "offset": [1941, 1954]}, {"key": "after-receiving", "type": "clause", "offset": [1965, 1980]}, {"key": "written-request", "type": "clause", "offset": [1983, 1998]}, {"key": "available-information", "type": "clause", "offset": [2025, 2046]}, {"key": "for-covered-entity", "type": "clause", "offset": [2057, 2075]}, {"key": "accounting-of-disclosures-of-phi", "type": "clause", "offset": [2087, 2119]}, {"key": "an-individual", "type": "clause", "offset": [2126, 2139]}, {"key": "by-covered-entity", "type": "clause", "offset": [2264, 2281]}, {"key": "the-individual", "type": "clause", "offset": [2316, 2330]}, {"key": "to-the-extent-practicable", "type": "definition", "offset": [2346, 2371]}, {"key": "use-or-disclosure-of-phi-by-business-associate", "type": "clause", "offset": [2433, 2479]}, {"key": "provide-access", "type": "clause", "offset": [2550, 2564]}, {"key": "the-request", "type": "clause", "offset": [2569, 2580]}, {"key": "time-and-manner", "type": "clause", "offset": [2615, 2630]}, {"key": "designated-record-set", "type": "definition", "offset": [2673, 2694]}, {"key": "as-directed", "type": "definition", "offset": [2718, 2729]}, {"key": "in-the-event", "type": "clause", "offset": [2831, 2843]}, {"key": "in-connection-with", "type": "clause", "offset": [2868, 2886]}, {"key": "information-of", "type": "clause", "offset": [2949, 2963]}, {"key": "the-business", "type": "clause", "offset": [2993, 3005]}, {"key": "electronic-copy", "type": "definition", "offset": [3033, 3048]}, {"key": "a-third-party", "type": "clause", "offset": [3235, 3248]}, {"key": "in-business", "type": "definition", "offset": [3381, 3392]}, {"key": "amendment-and", "type": "clause", "offset": [3541, 3554]}, {"key": "amendments-to-the", "type": "clause", "offset": [3571, 3588]}, {"key": "minimum-amount", "type": "clause", "offset": [3710, 3724]}, {"key": "purpose-of-the", "type": "clause", "offset": [3760, 3774]}, {"key": "directly-or-indirectly", "type": "clause", "offset": [3911, 3933]}, {"key": "in-exchange", "type": "clause", "offset": [3955, 3966]}, {"key": "product-or-service", "type": "definition", "offset": [4105, 4123]}, {"key": "necessary-steps", "type": "clause", "offset": [4352, 4367]}, {"key": "health-plan", "type": "definition", "offset": [4465, 4476]}], "samples": [{"hash": "liXkI6w44wI", "uri": "/contracts/liXkI6w44wI#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 22.2429847717, "published": true}, {"hash": "gsJ6Fi5nrYi", "uri": "/contracts/gsJ6Fi5nrYi#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 22.2429847717, "published": true}, {"hash": "21YG8ITr630", "uri": "/contracts/21YG8ITr630#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 22.2429847717, "published": true}], "snippet": "2.1 With regard to its use and/or disclosure of PHI, Business Associate agrees to:\n(a) use and/or disclose PHI only as necessary to provide the Services, specifically as permitted or required by this B.A. Agreement and in compliance with each applicable requirement of 45 C.F.R. \u00a7 164.504(e) or as otherwise Required by Law;\n(b) implement and use appropriate technical, physical and administrative safeguards to (i) prevent use or disclosure of PHI other than as permitted or required by this B.A. Agreement; (ii) reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, maintains, or transmits on behalf of the Covered Entity; and (iii) as of the Compliance Date of 42 U.S.C. \u00a7 17931, comply with the requirements set forth in 45 C.F.R. \u00a7\u00a7 164.308, 164.310, 164.312, and 164.316;\n(c) promptly report to Covered Entity: (i) any use or disclosure of PHI of which it becomes aware that is not permitted by this B.A. Agreement; and/or (ii) any Security Incident of which Business Associate becomes aware;\n(d) without unreasonable delay and in no case later than sixty (60) calendar days after discovery, Business Associate shall notify Covered Entity of a Breach of any Unsecured PHI all in accordance with 42 U.S.C. \u00a7 17932(b) as of its Compliance Date;\n(e) require all of its subcontractors and agents that create, receive, maintain, or transmit PHI to agree, in writing, to the same restrictions and conditions on the use and/or disclosure of PHI that apply to Business Associate; to the extent that Business Associate provides ePHI to a subcontractor or agent, it shall require the subcontractor or agent to implement reasonable and appropriate safeguards to protect the ePHI;\u200c\n(f) make available its internal practices, books, and records relating to the use and disclosure of PHI to the Secretary for purposes of determining Covered Entity\u2019s compliance with the Privacy Rule;\n(g) within thirty (30) days after receiving a written request from Covered Entity, make available information necessary for Covered Entity to make an accounting of disclosures of PHI about an Individual as provided in 45 C.F.R. \u00a7 164.528 and, as of its Compliance Date, in accordance with 42 U.S.C. 17935(c), and when directed by Covered Entity, make that accounting directly to the Individual;\n(h) mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate that is not permitted by the requirements of this B.A. Agreement;\n(i) provide access (at the request of the Covered Entity, and in the time and manner designated by Covered Entity) to PHI in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual, in accordance with the requirements of 45 C.F.R. \u00a7 164.524;\n(j) in the event that Business Associate in connection with the Services uses or maintains an Electronic Health Record of information of or about an Individual, then the Business Associate shall provide an electronic copy (at the request of Covered Entity, and in the time and manner designated by Covered Entity) of the PHI, to Covered Entity or, when and as directed by Covered Entity, to an Individual or a third party designated by the Individual, all in accordance with 42 U.S.C. \u00a7 17935(e) as of its Compliance Date;\n(k) to the extent that the PHI in Business Associate\u2019s possession constitutes a Designated Record Set, make available, within thirty (30) days of a written request by Covered Entity, PHI for amendment and incorporate any amendments to the PHI as directed by Covered Entity, all in accordance with 45 C.F.R. \u00a7 164.526;\n(l) request, use and/or disclose only the minimum amount of PHI necessary to accomplish the purpose of the request, use or disclosure; provided, that Business Associate shall comply with 42 U.S.C. \u00a7 17935(b) as of its Compliance Date;\n(m) not directly or indirectly receive remuneration in exchange for any PHI in compliance with 42 U.S.C. \u00a7 17935(d) as of its Compliance Date;\n(n) not make or cause to be made any communication about a product or service that is prohibited by 42 U.S.C. \u00a7 17936(a) as of its Compliance Date;\n(o) not make or cause to be made any written fundraising communication that is prohibited by 42 U.S.C. \u00a7 17936(b) as of its Compliance Date; and\n(p) take all necessary steps, at the direction of Covered Entity, to comply with requests by Individuals not to send PHI to a Health Plan in accordance with 42 USC 17935(a).", "hash": "6b7e9bff1fe3d772e51985c1441e3d38", "id": 4}, {"size": 18, "snippet_links": [{"key": "with-regard-to", "type": "clause", "offset": [0, 14]}, {"key": "business-relationship", "type": "definition", "offset": [204, 225]}, {"key": "agreement-or", "type": "definition", "offset": [237, 249]}, {"key": "as-required-by-law", "type": "clause", "offset": [250, 268]}, {"key": "appropriate-safeguards", "type": "clause", "offset": [281, 303]}, {"key": "disclosure-to-others", "type": "clause", "offset": [531, 551]}, {"key": "in-any-form", "type": "definition", "offset": [600, 611]}, {"key": "agrees-to", "type": "clause", "offset": [745, 754]}, {"key": "security-rule-provisions", "type": "clause", "offset": [795, 819]}, {"key": "part-164", "type": "clause", "offset": [840, 848]}, {"key": "provisions-relating-to", "type": "clause", "offset": [871, 893]}, {"key": "security-standards", "type": "definition", "offset": [894, 912]}, {"key": "general-rules", "type": "definition", "offset": [913, 926]}, {"key": "administrative-safeguards", "type": "definition", "offset": [947, 972]}, {"key": "physical-safeguards", "type": "definition", "offset": [993, 1012]}, {"key": "technical-safeguards", "type": "definition", "offset": [1033, 1053]}, {"key": "organizational-requirements", "type": "clause", "offset": [1074, 1101]}, {"key": "and-documentation", "type": "clause", "offset": [1134, 1151]}, {"key": "availability-of", "type": "clause", "offset": [1318, 1333]}, {"key": "electronic-protected-health-information", "type": "definition", "offset": [1338, 1377]}, {"key": "on-behalf-of", "type": "clause", "offset": [1440, 1452]}, {"key": "report-to-county", "type": "clause", "offset": [1468, 1484]}, {"key": "security-incident", "type": "clause", "offset": [1489, 1506]}, {"key": "breach-of-unsecured-protected-health-information", "type": "clause", "offset": [1585, 1633]}, {"key": "by-business-associate", "type": "clause", "offset": [1820, 1841]}, {"key": "such-security", "type": "definition", "offset": [1904, 1917]}, {"key": "other-information", "type": "clause", "offset": [1987, 2004]}, {"key": "the-report", "type": "clause", "offset": [2048, 2058]}, {"key": "type-of", "type": "definition", "offset": [2072, 2079]}, {"key": "in-the-event", "type": "clause", "offset": [2118, 2130]}, {"key": "the-information", "type": "clause", "offset": [2146, 2161]}, {"key": "in-writing", "type": "definition", "offset": [2258, 2268]}, {"key": "to-mitigate", "type": "definition", "offset": [2433, 2444]}, {"key": "to-the-extent-practicable", "type": "definition", "offset": [2446, 2471]}, {"key": "use-or-disclosure-of-protected-health-information", "type": "clause", "offset": [2533, 2582]}, {"key": "the-requirements", "type": "clause", "offset": [2621, 2637]}, {"key": "mitigation-actions", "type": "definition", "offset": [2729, 2747]}, {"key": "in-advance", "type": "clause", "offset": [2777, 2787]}, {"key": "by-county", "type": "clause", "offset": [2803, 2812]}, {"key": "cost-and-expense", "type": "clause", "offset": [2830, 2846]}, {"key": "with-county", "type": "clause", "offset": [2896, 2907]}, {"key": "in-connection-with", "type": "clause", "offset": [2908, 2926]}, {"key": "any-notice", "type": "clause", "offset": [3080, 3090]}, {"key": "giving-notice", "type": "definition", "offset": [3177, 3190]}, {"key": "delivery-of", "type": "clause", "offset": [3230, 3241]}, {"key": "to-ensure", "type": "clause", "offset": [3315, 3324]}, {"key": "information-on", "type": "clause", "offset": [3423, 3437]}, {"key": "restrictions-and-conditions", "type": "clause", "offset": [3496, 3523]}, {"key": "with-respect-to", "type": "clause", "offset": [3557, 3572]}, {"key": "provide-access", "type": "clause", "offset": [3616, 3630]}, {"key": "the-request", "type": "clause", "offset": [3635, 3646]}, {"key": "time-and-manner", "type": "clause", "offset": [3662, 3677]}, {"key": "designated-record-set", "type": "definition", "offset": [3737, 3758]}, {"key": "as-directed", "type": "definition", "offset": [3773, 3784]}, {"key": "an-individual", "type": "clause", "offset": [3799, 3812]}, {"key": "in-order-to", "type": "clause", "offset": [3813, 3824]}, {"key": "any-amendment", "type": "definition", "offset": [3847, 3860]}, {"key": "county-of", "type": "clause", "offset": [4055, 4064]}, {"key": "amendment-requests", "type": "clause", "offset": [4069, 4087]}, {"key": "business-days-of-receipt", "type": "clause", "offset": [4128, 4152]}, {"key": "and-information", "type": "clause", "offset": [4220, 4235]}, {"key": "related-to", "type": "definition", "offset": [4236, 4246]}, {"key": "for-county", "type": "definition", "offset": [4285, 4295]}, {"key": "respond-to", "type": "definition", "offset": [4299, 4309]}, {"key": "accounting-of-disclosures-of-protected-health-information", "type": "clause", "offset": [4344, 4401]}, {"key": "in-accordance-with", "type": "definition", "offset": [4402, 4420]}, {"key": "information-collected", "type": "clause", "offset": [4509, 4530]}, {"key": "obligation-of-county", "type": "clause", "offset": [4785, 4805]}, {"key": "subpart-e", "type": "definition", "offset": [4870, 4879]}, {"key": "obligation-to", "type": "clause", "offset": [4890, 4903]}, {"key": "pursuant-to-the", "type": "definition", "offset": [4951, 4966]}, {"key": "requirements-of-the", "type": "clause", "offset": [5031, 5050]}, {"key": "in-the-performance", "type": "clause", "offset": [5085, 5103]}, {"key": "internal-practices", "type": "clause", "offset": [5141, 5159]}, {"key": "information-received", "type": "clause", "offset": [5238, 5258]}, {"key": "received-by", "type": "definition", "offset": [5279, 5290]}, {"key": "available-to", "type": "definition", "offset": [5330, 5342]}, {"key": "cooperate-with", "type": "clause", "offset": [5359, 5373]}, {"key": "secretary-of-health-and-human-services", "type": "definition", "offset": [5399, 5437]}, {"key": "oversight-agency", "type": "definition", "offset": [5459, 5475]}, {"key": "for-purposes-of", "type": "clause", "offset": [5537, 5552]}, {"key": "compliance-with-the-privacy-rule", "type": "clause", "offset": [5603, 5635]}, {"key": "pattern-of-activity", "type": "clause", "offset": [5678, 5697]}, {"key": "breach-or-violation", "type": "clause", "offset": [5748, 5767]}, {"key": "notice-of", "type": "definition", "offset": [5837, 5846]}, {"key": "pattern-or-practice", "type": "definition", "offset": [5852, 5871]}, {"key": "reasonable-steps-to-cure", "type": "clause", "offset": [5934, 5958]}, {"key": "such-determination", "type": "definition", "offset": [6112, 6130]}, {"key": "the-problem", "type": "clause", "offset": [6145, 6156]}, {"key": "a-copy-of", "type": "clause", "offset": [6198, 6207]}, {"key": "days-in", "type": "definition", "offset": [6244, 6251]}], "samples": [{"hash": "dIjDkNUoJm9", "uri": "/contracts/dIjDkNUoJm9#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 25.2411975861, "published": true}, {"hash": "aufIlJcdKe5", "uri": "/contracts/aufIlJcdKe5#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 25.2411975861, "published": true}, {"hash": "UlFzh0zVYI", "uri": "/contracts/UlFzh0zVYI#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 25.2411975861, "published": true}], "snippet": "With regard to the use and/or disclosure of Protected Health Information, Business Associate agrees:\n4.1 not to use and/or disclose Protected Health Information other than as permitted or required by the Business Relationship or this BA Agreement or as Required by Law;\n4.2 to use appropriate safeguards to prevent the use and/or disclosure of Protected Health Information other than as provided for by the Business Relationship or this BA Agreement;\n4.3 to protect any Protected Health Information taken off-site from COUNTY from disclosure to others, and to return all Protected Health Information in any form to COUNTY or destroy such Protected Health Information in a manner that renders it unreadable and unusable by anyone else, if COUNTY agrees to the destruction;\n4.4 to comply with the Security Rule provisions set forth in 45 CFR Part 164, Subpart C, including provisions relating to Security Standards General Rules (45 CFR \u00a7 164.306), Administrative Safeguards (45 CFR \u00a7 164.308), Physical Safeguards (45 CFR \u00a7 164.310), Technical Safeguards (45 CFR \u00a7 164.312), Organizational Requirements (45 CFR \u00a7 164.314) and Policies and Documentation (45 CFR \u00a7 164.316), and to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information Business Associate creates, receives, maintains, or transmits on behalf of COUNTY.\n4.5 to report to COUNTY any Security Incident of which it becomes aware within 2 business days, and to report any potential Breach of Unsecured Protected Health Information within 2 business days of discovery. Any such report shall include the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been accessed, acquired, used or disclosed during any such Security Incident or potential Breach. Any such report shall also include all other information known to Business Associate at the time of the report (such as the type of Protected Health Information involved in the event, the nature of the information, etc.) or promptly thereafter as such other information becomes available;\n4.6 to notify COUNTY in writing within 2 business days of any use and/or disclosure of Protected Health Information that is not provided for by the Business Relationship or this BA Agreement;\n4.7 to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this BA Agreement, or as the result of any Security Incident or potential Breach, using mitigation actions that are disclosed to COUNTY in advance and authorized by COUNTY, all at the sole cost and expense of Business Associate;\n4.8 to work cooperatively with COUNTY in connection with COUNTY\u2019s investigation of any potential Breach and in connection with any notices COUNTY determines are required as a result, and to refrain from giving any notice itself unless COUNTY expressly agrees in advance and in writing to Business Associate giving notice and to the form, content and method of delivery of such notice, all at the sole cost and expense of Business Associate;\n4.9 to ensure that all agents and/or subcontractors that create, receive, maintain or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information;\n4.10 to provide access (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set to COUNTY or, as directed by COUNTY, to an Individual in order to meet the\n4.11 to make any amendment(s) (at the request of, and in the time and manner designated by COUNTY) to Protected Health Information in a Designated Record Set that COUNTY directs pursuant to 45 CFR \u00a7 164.526 and to notify COUNTY of any amendment requests it receives from an individual within 2 business days of receipt;\n4.12 to document such disclosures of Protected Health Information and information related to such disclosures as would be required for COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR \u00a7 164.528;\n4.13 to provide to COUNTY, in a time and manner designated by COUNTY, information collected in accordance with 4.12 of this BA Agreement, to permit COUNTY to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 CFR \u00a7\n4.14 to the extent Business Associate is to carry out an obligation of COUNTY under the Privacy Rule provisions set forth at 45 CFR Part 164, Subpart E (any such obligation to be carried out only when so directed by COUNTY pursuant to the Business Relationship or this BA Agreement), to comply with the requirements of the Privacy Rule that apply to COUNTY in the performance of such obligation;\n4.15 to make its internal practices, books, and records relating to the use and/or disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of COUNTY available to COUNTY;\n4.16 to cooperate with any investigation by the Secretary of Health and Human Services, or his agent, or an oversight agency, in a time and manner designated by COUNTY or the Secretary, for purposes of determining if COUNTY or Business Associate is in compliance with the Privacy Rule;\n4.17 if Business Associate is aware of a pattern of activity or practice by COUNTY that constitutes a material breach or violation of COUNTY\u2019s obligations under this BA Agreement,\n(a) to give written notice of such pattern or practice to COUNTY within 2 business days of its discovery and to take reasonable steps to cure the breach or end the violation,\n(b) if Business Associate determines that such steps appear to have been unsuccessful, to give COUNTY written notice of such determination and to report the problem to the Secretary and provide COUNTY with a copy of any such report at least 2 business days in advance of its submission to the Secretary.", "hash": "b3944b35059af31e71fc729196fc9559", "id": 5}, {"size": 11, "snippet_links": [{"key": "use-or-disclosure-of-phi", "type": "clause", "offset": [14, 38]}, {"key": "business-associate-agrees-to", "type": "clause", "offset": [47, 75]}, {"key": "agreement-or", "type": "definition", "offset": [151, 163]}, {"key": "applicable-law", "type": "clause", "offset": [164, 178]}, {"key": "further-disclosure", "type": "clause", "offset": [198, 216]}, {"key": "hipaa-privacy-and-security-rules", "type": "definition", "offset": [267, 299]}, {"key": "technical-safeguards", "type": "definition", "offset": [402, 422]}, {"key": "to-covered-entity", "type": "clause", "offset": [688, 705]}, {"key": "not-limited", "type": "clause", "offset": [741, 752]}, {"key": "measures-to-safeguard", "type": "clause", "offset": [807, 828]}, {"key": "electronic-data", "type": "clause", "offset": [829, 844]}, {"key": "agree-to", "type": "clause", "offset": [869, 877]}, {"key": "by-this-agreement", "type": "clause", "offset": [944, 961]}, {"key": "disciplinary-action", "type": "clause", "offset": [981, 1000]}, {"key": "inappropriate-access", "type": "clause", "offset": [1005, 1025]}, {"key": "report-to", "type": "definition", "offset": [1065, 1074]}, {"key": "privacy-officer", "type": "definition", "offset": [1092, 1107]}, {"key": "in-writing", "type": "definition", "offset": [1109, 1119]}, {"key": "not-permitted", "type": "clause", "offset": [1208, 1221]}, {"key": "discovery-of", "type": "clause", "offset": [1338, 1350]}, {"key": "unauthorized-use-or-disclosure", "type": "clause", "offset": [1356, 1386]}, {"key": "received-by", "type": "definition", "offset": [1526, 1537]}, {"key": "the-business", "type": "clause", "offset": [1538, 1550]}, {"key": "on-behalf-of", "type": "clause", "offset": [1561, 1573]}, {"key": "restrictions-and-conditions", "type": "clause", "offset": [1612, 1639]}, {"key": "with-respect-to", "type": "clause", "offset": [1677, 1692]}, {"key": "to-establish", "type": "clause", "offset": [1756, 1768]}, {"key": "reasonable-and-appropriate-safeguards", "type": "clause", "offset": [1783, 1820]}, {"key": "availability-of", "type": "clause", "offset": [1868, 1883]}, {"key": "and-procedures", "type": "clause", "offset": [2069, 2083]}, {"key": "available-to", "type": "definition", "offset": [2084, 2096]}, {"key": "secretary-of-hhs", "type": "clause", "offset": [2101, 2117]}, {"key": "compliance-with-the", "type": "clause", "offset": [2155, 2174]}, {"key": "other-third-parties", "type": "definition", "offset": [2262, 2281]}, {"key": "and-covered", "type": "clause", "offset": [2283, 2294]}, {"key": "provide-information", "type": "clause", "offset": [2422, 2441]}, {"key": "respond-to", "type": "definition", "offset": [2488, 2498]}, {"key": "an-individual", "type": "clause", "offset": [2512, 2525]}, {"key": "accounting-of-disclosures", "type": "clause", "offset": [2533, 2558]}, {"key": "written-request", "type": "clause", "offset": [2595, 2610]}, {"key": "a-designated", "type": "clause", "offset": [2664, 2676]}, {"key": "the-request", "type": "clause", "offset": [2727, 2738]}, {"key": "time-and-manner", "type": "clause", "offset": [2754, 2769]}, {"key": "by-covered-entity", "type": "clause", "offset": [2781, 2798]}, {"key": "access-to-the", "type": "clause", "offset": [2808, 2821]}, {"key": "by-business-associate", "type": "clause", "offset": [2844, 2865]}, {"key": "designated-record-set", "type": "definition", "offset": [3175, 3196]}, {"key": "pi-business", "type": "definition", "offset": [3414, 3425]}, {"key": "security-incident", "type": "clause", "offset": [3543, 3560]}], "samples": [{"hash": "dAmlrHBYPow", "uri": "/contracts/dAmlrHBYPow#responsibilities-of-business-associate", "label": "Business Associate Agreement (Baa)", "score": 32.697845459, "published": true}, {"hash": "9PE6Id2VOLO", "uri": "/contracts/9PE6Id2VOLO#responsibilities-of-business-associate", "label": "Business Associate Agreement (Baa)", "score": 26.0691299438, "published": true}, {"hash": "gloIBpsmi2Q", "uri": "/contracts/gloIBpsmi2Q#responsibilities-of-business-associate", "label": "Business Associate Agreement (Baa)", "score": 25.4175224304, "published": true}], "snippet": "Regarding the use or disclosure of PHI and PI, Business Associate agrees to:\n4.2.1 Only use or further disclose the PHI and PI as allowable under this Agreement or applicable law.\n4.2.2 Only use or further disclosure PHI and PI in a manner that would not violate the HIPAA Privacy and Security Rules if done so by the Covered Entity.\n4.2.3 Establish and implement appropriate procedures, physical, and technical safeguards to prevent improper access, uses, transmissions, or disclosures of PHI and PI for mitigating to the greatest extents possible under the circumstances any deleterious effects from any improper access, use, or disclosure of PHI and PI that Business Associate reports to Covered Entity. Safeguards shall include, but are not limited to, the implementation and use of electronic security measures to safeguard electronic data, requiring employees to agree to access, use, or disclose PHI and PI only as permitted or required by this Agreement and taking related disciplinary action for inappropriate access, use or disclosure as necessary.\n4.2.4 Report to Covered Entity\u2019s Privacy Officer, in writing, any suspected or confirmed access, use or disclosure of PHI or PI, regardless of form, not permitted or required by this Agreement of which Business Associate becomes aware within two (2) days of Business Associate\u2019s discovery of such unauthorized use or disclosure.\n4.2.5 Ensure that Business Associate\u2019s subcontractors or agents to whom Business Associate provides PHI or PI, received from, created, or received by the Business Associate on behalf of the Covered Entity, agree to the same restrictions and conditions that apply to the Business Associate with respect to PHI and PI, and ensure that its subcontractors or agents agree to establish and implement reasonable and appropriate safeguards to protect the confidentiality, integrity, and availability of all PHI and PI that it creates receives, maintains, or transmits on behalf of Covered Entity.\n4.2.6 The Business Associate must make its records, books, accounts, agreements, policies, and procedures available to the Secretary of HHS for determining the Covered Entity\u2019s compliance with the HIPAA Privacy and Security Rules.\n4.2.7 Use or disclose to its subcontractors, agents, other third parties, and Covered Entity, only the minimum PHI and PI necessary to perform or fulfill a specific function required or permitted hereunder.\n4.2.8 Provide information to Covered Entity to permit Covered Entity to respond to a request by an individual for an accounting of disclosures within five (5) days of receiving a written request from Covered Entity, if Business Associate maintains a Designated Records Set on behalf of Covered Entity.\n4.2.9 At the request of, and in the time and manner designated by Covered Entity, provide access to the PHI and PI maintained by Business Associate to Covered Entity or individual, if Business Associate maintains a Designated Records Set on behalf of Covered Entity.\n4.2.10 At the request of, and in the time and manner designated by Covered Entity, make any amendment(s) to the PHI and PI when directed by Covered Entity, if Business Associate maintains a Designated Record Set on behalf of Covered Entity.\n4.2.11 Establish and implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any PHI and PI Business Associate creates, receives, maintains or transmits on behalf of Covered Entity.\n4.2.12 Report to Covered Entity any Security Incident involving PHI and PI that Business Associate discovers.", "hash": "4d1b3c4864c3e42ce08d0fe3a0bb9ade", "id": 6}, {"size": 11, "snippet_links": [{"key": "with-regard-to", "type": "clause", "offset": [0, 14]}, {"key": "the-business", "type": "clause", "offset": [61, 73]}, {"key": "sole-purpose", "type": "clause", "offset": [140, 152]}, {"key": "information-only", "type": "clause", "offset": [202, 218]}, {"key": "as-required-by", "type": "clause", "offset": [219, 233]}, {"key": "service-agreement", "type": "clause", "offset": [238, 255]}, {"key": "agreement-or", "type": "definition", "offset": [262, 274]}, {"key": "required-by-law", "type": "clause", "offset": [288, 303]}, {"key": "report-to", "type": "definition", "offset": [321, 330]}, {"key": "privacy-officer", "type": "definition", "offset": [343, 358]}, {"key": "in-writing", "type": "definition", "offset": [360, 370]}, {"key": "not-permitted", "type": "clause", "offset": [448, 461]}, {"key": "by-this-agreement", "type": "clause", "offset": [474, 491]}, {"key": "discovery-of", "type": "clause", "offset": [564, 576]}, {"key": "appropriate-safeguards", "type": "clause", "offset": [626, 648]}, {"key": "to-maintain", "type": "clause", "offset": [649, 660]}, {"key": "security-of-the", "type": "clause", "offset": [665, 680]}, {"key": "access-to-protected-health-information", "type": "clause", "offset": [895, 933]}, {"key": "agreement-to", "type": "definition", "offset": [945, 957]}, {"key": "adhere-to", "type": "clause", "offset": [978, 987]}, {"key": "restrictions-and-conditions", "type": "clause", "offset": [997, 1024]}, {"key": "obligation-to-return-or-destroy", "type": "clause", "offset": [1119, 1150]}, {"key": "make-available", "type": "definition", "offset": [1213, 1227]}, {"key": "secretary-of-hhs", "type": "clause", "offset": [1236, 1252]}, {"key": "all-records", "type": "clause", "offset": [1254, 1265]}, {"key": "policies-and-procedures", "type": "definition", "offset": [1286, 1309]}, {"key": "relating-to", "type": "definition", "offset": [1310, 1321]}, {"key": "document-destruction", "type": "definition", "offset": [1326, 1346]}, {"key": "associate-in", "type": "clause", "offset": [1377, 1389]}, {"key": "services-provided-to-the-company", "type": "clause", "offset": [1394, 1426]}, {"key": "for-purposes-of", "type": "clause", "offset": [1498, 1513]}, {"key": "privacy-rules", "type": "definition", "offset": [1560, 1573]}, {"key": "subject-to", "type": "clause", "offset": [1575, 1585]}, {"key": "other-applicable", "type": "definition", "offset": [1606, 1622]}, {"key": "legal-privileges", "type": "clause", "offset": [1623, 1639]}, {"key": "normal-business-hours", "type": "clause", "offset": [1668, 1689]}, {"key": "to-this-agreement", "type": "clause", "offset": [1879, 1896]}, {"key": "within-thirty", "type": "clause", "offset": [1913, 1926]}, {"key": "of-the-company", "type": "clause", "offset": [1937, 1951]}, {"key": "written-request", "type": "clause", "offset": [1954, 1969]}, {"key": "for-the-purpose-of", "type": "definition", "offset": [1971, 1989]}, {"key": "to-verify", "type": "definition", "offset": [2011, 2020]}, {"key": "terms-of-this-agreement", "type": "clause", "offset": [2066, 2089]}, {"key": "from-the-company", "type": "clause", "offset": [2150, 2166]}, {"key": "such-information", "type": "definition", "offset": [2191, 2207]}, {"key": "by-the-company", "type": "clause", "offset": [2224, 2238]}, {"key": "respond-to", "type": "definition", "offset": [2264, 2274]}, {"key": "accounting-for", "type": "clause", "offset": [2291, 2305]}, {"key": "an-individual", "type": "clause", "offset": [2325, 2338]}, {"key": "in-accordance-with", "type": "definition", "offset": [2370, 2388]}, {"key": "return-to", "type": "definition", "offset": [2426, 2435]}, {"key": "as-requested", "type": "clause", "offset": [2472, 2484]}, {"key": "information-provided", "type": "clause", "offset": [2522, 2542]}, {"key": "in-business", "type": "definition", "offset": [2574, 2585]}, {"key": "date-of", "type": "clause", "offset": [2616, 2623]}, {"key": "no-copies", "type": "clause", "offset": [2648, 2657]}, {"key": "to-mitigate", "type": "definition", "offset": [2693, 2704]}, {"key": "to-the-extent-practicable", "type": "definition", "offset": [2706, 2731]}, {"key": "use-or-disclosure-of-protected-health-information", "type": "clause", "offset": [2807, 2856]}, {"key": "requirements-of-this-agreement", "type": "clause", "offset": [2899, 2929]}], "samples": [{"hash": "3TOTHsqe0Ck", "uri": "/contracts/3TOTHsqe0Ck#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 30.1876220703, "published": true}], "snippet": "With regard to its handling of Protected Health Information, the Business Associate hereby agrees to do the following:\n3.1 Possess, for the sole purpose of destroying by shredding, the Protected Health Information only as required by the Service Agreement, this Agreement or as otherwise required by law;\n3.2 Immediately report to the Company privacy officer, in writing, any other use and/or disclosure of the Protected Health Information that is not permitted or required by this Agreement of which Business Associate becomes aware upon the Business Associate\u2019s discovery of such unauthorized use and/or disclosure;\n3.3 Use appropriate safeguards to maintain the security of the Protected Health Information and to prevent unauthorized use and/or disclosure of such Protected Health Information;\n3.4 Require all of its employees, representatives, subcontractors or agents that receive or have access to Protected Health Information under this Agreement to agree in writing to adhere to the same restrictions and conditions on the use and/or disclosure of Protected Health Information that apply herein, including the obligation to return or destroy the Protected Health Information as hereinafter provided.\n3.5 Make available, to the Secretary of HHS, all records, books, agreements, policies and procedures relating to the document destruction services provided by Business Associate in the services provided to The Company involving the handling and distraction of Protected Health Information for purposes of determining the Company\u2019s compliance with the Privacy Rules, subject to attorney-client and other applicable legal privileges.\n3.6 Make available, during normal business hours, at Business Associate\u2019s offices all records, books, agreements, policies and procedures relating to the use, destruction, and/or disclosure of Protected Health Information that is subject to this Agreement, to the Company within thirty (30) days of The Company's written request, for the purpose of enabling the Company to verify the Business Associate\u2019s compliance with the terms of this Agreement;\n3.7 Within thirty (30) days of receiving a written request from The Company, provide to the Company such information as is requested by The Company to permit the Company to respond to any request for accounting for any disclosures of an individual\u2019s Protected Health Information in accordance with 45 C.F.R. \u00a7164.526 and \u00a7164.528;\n3.8 Return to the Company or immediately destroy, as requested by the Company, any Protected Health Information provided to Business Associate, that is in Business Associate\u2019s possession on the date of such request and retain no copies; and\n3.9 Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of an unauthorized use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement or the Service Agreement.", "hash": "b67ac99983dd555e77363c41464d0566", "id": 7}, {"size": 6, "snippet_links": [{"key": "appropriate-safeguards", "type": "clause", "offset": [37, 59]}, {"key": "comply-with", "type": "definition", "offset": [68, 79]}, {"key": "part-164", "type": "clause", "offset": [100, 108]}, {"key": "with-respect-to", "type": "clause", "offset": [109, 124]}, {"key": "electronic-protected-health-information", "type": "definition", "offset": [125, 164]}, {"key": "use-or-disclosure-of-protected-health-information", "type": "clause", "offset": [177, 226]}, {"key": "the-agreement", "type": "clause", "offset": [257, 270]}, {"key": "report-to", "type": "definition", "offset": [278, 287]}, {"key": "in-no-case", "type": "clause", "offset": [317, 327]}, {"key": "business-days", "type": "definition", "offset": [353, 366]}, {"key": "by-this-agreement", "type": "clause", "offset": [414, 431]}, {"key": "breach-of-unsecured-phi", "type": "clause", "offset": [487, 510]}, {"key": "as-required-by", "type": "clause", "offset": [511, 525]}, {"key": "the-parties-acknowledge-and-agree-that", "type": "clause", "offset": [611, 649]}, {"key": "by-business-associate", "type": "clause", "offset": [687, 708]}, {"key": "unsuccessful-security-incidents", "type": "clause", "offset": [782, 813]}, {"key": "covered-entity-shall", "type": "clause", "offset": [848, 868]}, {"key": "without-limitation", "type": "clause", "offset": [923, 941]}, {"key": "denial-of-service-attacks", "type": "clause", "offset": [1053, 1078]}, {"key": "unauthorized-access", "type": "definition", "offset": [1153, 1172]}, {"key": "contact-information", "type": "clause", "offset": [1205, 1224]}, {"key": "business-associate-and-covered", "type": "clause", "offset": [1233, 1263]}, {"key": "reports-of", "type": "clause", "offset": [1289, 1299]}, {"key": "unauthorized-use-or-disclosure-of-phi", "type": "clause", "offset": [1300, 1337]}, {"key": "breaches-of-unsecured-phi", "type": "clause", "offset": [1339, 1364]}, {"key": "such-information", "type": "definition", "offset": [1454, 1470]}, {"key": "from-time-to-time", "type": "clause", "offset": [1486, 1503]}, {"key": "between-the-parties", "type": "clause", "offset": [1504, 1523]}, {"key": "underlying-agreement", "type": "definition", "offset": [1599, 1619]}, {"key": "compliance-officer", "type": "definition", "offset": [1671, 1689]}, {"key": "name-and-title", "type": "definition", "offset": [1827, 1841]}, {"key": "company-name", "type": "definition", "offset": [1844, 1856]}, {"key": "street-address", "type": "clause", "offset": [1859, 1873]}], "samples": [{"hash": "9xHWYM1i7bY", "uri": "/contracts/9xHWYM1i7bY#responsibilities-of-business-associate", "label": "General Terms and Conditions Agreement", "score": 32.9184989929, "published": true}, {"hash": "4QZVhIHC4t9", "uri": "/contracts/4QZVhIHC4t9#responsibilities-of-business-associate", "label": "General Terms and Conditions Agreement", "score": 26.7056808472, "published": true}, {"hash": "jeqiafJiYN7", "uri": "/contracts/jeqiafJiYN7#responsibilities-of-business-associate", "label": "General Terms and Conditions Agreement", "score": 26.6522922516, "published": true}], "snippet": "Business Associate agrees:\na. to use appropriate safeguards, and to comply with Subpart C of 45 CFR Part 164 with respect to electronic protected health information, to prevent use or disclosure of protected health information other than as provided for by the Agreement.\nb. to report to Covered Entity promptly, but in no case longer than fifteen (15) business days, any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including a Breach of Unsecured PHI as required by 45 C.F.R. \u00a7 164.410, and any successful Security Incident of which it becomes aware. The Parties acknowledge and agree that this section 4.b. constitutes notice by Business Associate to Covered Entity of the ongoing existence and occurrence or attempts of Unsuccessful Security Incidents for which no additional notice to Covered Entity shall be required. \u201cUnsuccessful Security Incidents\u201d means, without limitation, pings and other broadcast attacks on Business Associate\u2019s firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and any combination of the above, so long as no such incident results in unauthorized access, use, or disclosure of PHI. The contact information for the Business Associate and Covered Entity employees to whom reports of unauthorized use or disclosure of PHI, Breaches of Unsecured PHI and successful Security Incidents under this Section shall be made as provided below (as such information may be updated from time to time between the parties). Notification shall be made using the methods as provided in the relevant Underlying Agreement. Business Associate: \u2587\u2587\u2587\u2587\u2587 \u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587, Chief Legal & Compliance Officer DeliverHealth Solutions, LLC \u2587\u2587\u2587\u2587 \u2587\u2587\u2587\u2587\u2587\u2587\u2587 \u2587\u2587., \u2587\u2587\u2587\u2587\u2587 \u2587\u2587\u2587 \u2587\u2587\u2587\u2587\u2587\u2587\u2587, \u2587\u2587 \u2587\u2587\u2587\u2587\u2587 Email: \u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587@\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587\u2587.\u2587\u2587\u2587 Covered Entity: [Employee Name and Title] [Company Name] [Street Address] [City, State, Zip] [Phone] [Email]", "hash": "ba6f978c60e29d2988dacc9c6c012b68", "id": 8}, {"size": 6, "snippet_links": [{"key": "the-business", "type": "clause", "offset": [0, 12]}, {"key": "agrees-to", "type": "clause", "offset": [30, 39]}, {"key": "use-and-disclosure", "type": "clause", "offset": [58, 76]}, {"key": "by-this-agreement", "type": "clause", "offset": [132, 149]}, {"key": "health-insurance-portability-and-accountability-act", "type": "definition", "offset": [151, 202]}, {"key": "health-information-technology", "type": "definition", "offset": [220, 249]}, {"key": "health-act", "type": "definition", "offset": [276, 286]}, {"key": "the-american-recovery-and-reinvestment-act-of-2009", "type": "clause", "offset": [323, 373]}, {"key": "business-associate-shall", "type": "definition", "offset": [407, 431]}, {"key": "use-or-disclosure", "type": "clause", "offset": [466, 483]}, {"key": "in-compliance-with", "type": "definition", "offset": [502, 520]}, {"key": "applicable-requirement", "type": "definition", "offset": [526, 548]}, {"key": "responsible-for", "type": "clause", "offset": [607, 622]}, {"key": "compliance-with-the", "type": "clause", "offset": [628, 647]}, {"key": "provisions-of", "type": "clause", "offset": [656, 669]}, {"key": "hipaa-and-hitech", "type": "clause", "offset": [670, 686]}, {"key": "to-the-same-extent", "type": "definition", "offset": [724, 742]}, {"key": "covered-entity", "type": "definition", "offset": [750, 764]}], "samples": [{"hash": "cNiQatAHiPL", "uri": "/contracts/cNiQatAHiPL#responsibilities-of-business-associate", "label": "Community Services Contract", "score": 28.6820697784, "published": true}, {"hash": "bvWC8F2v1ze", "uri": "/contracts/bvWC8F2v1ze#responsibilities-of-business-associate", "label": "Community Services Contract", "score": 28.4548683167, "published": true}, {"hash": "bvEgeR2aPL8", "uri": "/contracts/bvEgeR2aPL8#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 26.6769695282, "published": true}], "snippet": "The Business Associate hereby agrees to do the following: Use and Disclosure: Use and/or disclose PHI only as permitted or required by this Agreement, Health Insurance Portability and Accountability Act (HIPAA), and the Health Information Technology for Economic and Clinical Health Act (HITECH) (Division A, Title XIII of the American Recovery and Reinvestment Act of 2009, Pub. Law 111-5, 2009 HR 1). The Business Associate shall use and disclose PHI only if such use or disclosure, respectively, is in compliance with each applicable requirement of 45 CFR \u00a7164.504(e). The Business Associate is directly responsible for full compliance with the privacy provisions of HIPAA and HITECH that apply to the Business Associate to the same extent as the Covered Entity.", "hash": "b8b4562627b8afc9ab2b1719f26e1980", "id": 9}, {"size": 6, "snippet_links": [{"key": "business-associate-shall", "type": "definition", "offset": [3, 27]}, {"key": "protected-health-information", "type": "clause", "offset": [52, 80]}, {"key": "the-agreement", "type": "clause", "offset": [116, 129]}, {"key": "required-by-law", "type": "clause", "offset": [147, 162]}, {"key": "in-writing", "type": "definition", "offset": [191, 201]}, {"key": "covered-entity", "type": "definition", "offset": [209, 223]}, {"key": "management-and-administrative-services", "type": "clause", "offset": [389, 427]}, {"key": "legal-responsibilities", "type": "clause", "offset": [442, 464]}, {"key": "to-provide", "type": "clause", "offset": [492, 502]}, {"key": "data-aggregation-services", "type": "clause", "offset": [503, 528]}, {"key": "relating-to", "type": "definition", "offset": [529, 540]}, {"key": "health-care-operations", "type": "definition", "offset": [541, 563]}, {"key": "if-required", "type": "definition", "offset": [586, 597]}, {"key": "minimum-amount", "type": "clause", "offset": [691, 705]}, {"key": "purpose-of-the", "type": "clause", "offset": [766, 780]}, {"key": "use-or-disclosure", "type": "clause", "offset": [781, 798]}, {"key": "subcontractors-will", "type": "clause", "offset": [867, 886]}, {"key": "the-us", "type": "clause", "offset": [912, 919]}, {"key": "access-to", "type": "definition", "offset": [935, 944]}, {"key": "disclosure-of", "type": "clause", "offset": [953, 966]}], "samples": [{"hash": "jbvuPoeb0Ny", "uri": "/contracts/jbvuPoeb0Ny#responsibilities-of-business-associate", "label": "State and County Contract for Social Services and Community Programs", "score": 31.9456825256, "published": true}, {"hash": "kVtQlNesN1w", "uri": "/contracts/kVtQlNesN1w#responsibilities-of-business-associate", "label": "Business Associate Agreement", "score": 16.1704311371, "published": false}], "snippet": "a. Business Associate shall not use or disclose any Protected Health Information except as permitted or required by the Agreement, as permitted or required by law, or as otherwise authorized in writing by the Covered Entity, if done by the Covered Entity. Unless otherwise limited herein, Business Associate may use or disclose Protected Health Information for Business Associate\u2019s proper management and administrative services, to carry out legal responsibilities of Business Associate, and to provide data aggregation services relating to health care operations of the Covered Entity if required under the Agreement.\nb. Business Associate shall not request, use, or disclose more than the minimum amount of Protected Health Information necessary to accomplish the purpose of the use or disclosure.\nc. Business Associate shall inform the Covered Entity if it or its subcontractors will perform any work outside the U.S. that involves access to, or the disclosure of, Protected Health Information.", "hash": "06470450a3b8dd3a2122aa9c8650c444", "id": 10}], "next_curs": "Cm8SaWoVc35sYXdpbnNpZGVyY29udHJhY3RzcksLEhZDbGF1c2VTbmlwcGV0R3JvdXBfdjU2Ii9yZXNwb25zaWJpbGl0aWVzLW9mLWJ1c2luZXNzLWFzc29jaWF0ZSMwMDAwMDAwYQyiAQJlbhgAIAA=", "clause": {"size": 367, "title": "Responsibilities of Business Associate", "children": [["safeguards", "Safeguards"], ["nondisclosure", "Nondisclosure"], ["security", "Security"], ["documentation-of-disclosures", "Documentation of Disclosures"], ["business-associates-agents", "Business Associate\u2019s Agents"]], "parents": [["staffing-training-and-supervision", "STAFFING, TRAINING AND SUPERVISION"], ["terms-of-agreement", "Terms of Agreement"], ["responsibilities-of-the-parties-with-respect-to-phi", "Responsibilities of the Parties With Respect to Phi"], ["requirements", "REQUIREMENTS"], ["miscellaneous", "Miscellaneous"]], "id": "responsibilities-of-business-associate", "related": [["obligations-and-activities-of-business-associate", "Obligations and Activities of Business Associate", "Obligations and Activities of Business Associate"], ["obligations-and-activities-of-business-associates", "Obligations and Activities of Business Associates", "Obligations and Activities of Business Associates"], ["responsibilities-of-client", "Responsibilities of Client", "Responsibilities of Client"], ["responsibilities-of-covered-entity", "Responsibilities of Covered Entity", "Responsibilities of Covered Entity"], ["obligations-of-business-associate", "Obligations of Business Associate", "Obligations of Business Associate"]], "related_snippets": [], "updated": "2026-03-07T04:27:53+00:00"}, "json": true, "cursor": ""}}