Responsibilities of the Parties With Respect to Phi Sample Clauses
The "Responsibilities of the Parties with Respect to PHI" clause defines the obligations of each party regarding the handling, protection, and use of Protected Health Information (PHI). It typically outlines specific duties such as maintaining confidentiality, implementing security measures, and reporting unauthorized disclosures or breaches. For example, one party may be required to ensure that only authorized personnel access PHI, while the other must notify of any security incidents. This clause is essential for ensuring compliance with privacy laws like HIPAA and for clearly allocating responsibility to prevent misuse or unauthorized access to sensitive health information.
POPULAR SAMPLE Copied 1 times
Responsibilities of the Parties With Respect to Phi. Responsibilities of the Business Associate. With regard to its use and/or disclosure of PHI, the Business Associate hereby agrees to do the following: Use and/or disclose the PHI only as permitted or required by this BA Agreement or as otherwise required by law. To the extent the business associate is to carry out one or more of covered entity’s obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to the covered entity in the performance of such obligation(s). Use appropriate safeguards to protect the privacy and security of PHI, and comply with Subpart C of 45 CFR Part 164 with respect to electronic Protected Health Information (EPHI), to prevent use or disclosure of PHI other than as provided for by this BA Agreement. Business Associate acknowledges its obligations under HIPAA and agrees to comply with any and all privacy and security provisions not otherwise specifically addressed in the Agreement made applicable to Business Associate by HIPAA on the applicable effective date and any subsequent regulations promulgated under HIPAA and/or guidance thereto. Business Associate acknowledges that: (i) the foregoing requirements shall apply to Business Associate in the same manner that such requirements apply to Covered Entity; and (ii) Business Associate shall be subject to the civil and criminal enforcement provisions set forth at 42 USC 1320d-5 and 1320d-6, as amended from time to time, for failure to comply with the requirements and any applicable guidance subsequently issued by the Secretary of the Department of Health and Human Services (“Secretary”) with respect to such requirements. Disclose to its subcontractors, agents, or other third parties, and request from the Covered Entity, only the minimum PHI necessary to perform or fulfill a specific function required or permitted hereunder. Business Associate agrees that any EPHI it creates, receives, maintains, or transmits will be maintained or transmitted in a manner that is rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of technology or methodology specified by the Secretary in the guidance issued under section 13402(h)(2) of Public Law 111-5. Establish procedures for mitigating, to the greatest extent possible, any deleterious effects from any improper use and/or disclosure of Covered Entity’s PHI. Require all of its subcontractors and agents that receive, use, or have access to PHI under this BA Agreement to ag...
Responsibilities of the Parties With Respect to Phi. 2.1 Responsibilities of the CATRAC. With regard to its use and/or disclosure of PHI, the CATRAC hereby agrees to do the following:
2.1.1. Not use or disclose PHI other than as permitted or required by this Agreement or the Underlying Agreement or as required by law;
2.1.2. Use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement or the Underlying Agreement;
2.1.3. Report, in writing, to Covered Entity within five ( 5) business days any use or disclosure of PHI not provided for by this Agreement or the Underlying Agreement of which it becomes aware, including breaches of unsecured PHI as required at 45 CFR 164.410, and any security incident of which it becomes aware, and cooperate with the Covered Entity in any mitigation or breach reporting efforts;
2.1.4. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the CATRAC agree pursuant to a written agreement to the same restrictions, conditions, and requirements that apply to the CATRAC with respect to such information;
2.1.5. Ensure that any agent or subcontractor to whom the CATRAC provides PHI, as well as CATRAC, not export PHI beyond the borders of the United States of America;
2.1.6. Within five (5) business days of a request by Covered Entity, make available PHI in a designated record set, i f applicable, to Covered Entity, as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.524;
2.1.7. Within five (5) business days, make any amendment(s) to PHI, i f applicabl e , in a designated record set as directed or agreed to by the Covered Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.526.
2.1.8. As applicable, maintain and make available the information required to provide an accounting of disclosures as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.528.
2.1.9. To the extent the CATRAC is to carry out one or more of Covered Entity's obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to the Covered Entity in the performance of such obligation(s).
2.1.10. Make its internal practices, books, and records available to the Secretary and to the Covered Entity for purposes of determining compliance with the HIPAA Rules.
2.1.11. Comply with minimum necessary requirements under the HIPA...
Responsibilities of the Parties With Respect to Phi. 3.1. With regard to its use and/or disclosure of PHI and the privacy and security of PHI, the Business Associate hereby agrees to the following:
Responsibilities of the Parties With Respect to Phi
