- OBLIGATIONS OF BUSINESS ASSOCIATE
2.1 Permitted Uses and Disclosures of PHI. BA, its directors, officers, Subcontractors, employees, affiliates, agents, and representatives shall use or disclose PHI only (a) in connection with fulfilling its duties and obligations under this Agreement and the Service Agreement; (b) for the proper management and administration of BA; or (c) to carry out the legal responsibilities of BA.
2.2 Prohibited Uses and Disclosures of PHI. BA shall not use or disclose PHI other than as permitted or Required by Law. BA shall not use or disclose PHI in any manner that violates state or federal laws or would violate such laws if used or disclosed in such manner by CE.
2.3 Third Party Disclosures. BA shall obtain and maintain an agreement with each Subcontractor that has or will have access to PHI which is received from, created, or received by BA on behalf of CE, pursuant to which agreement such Subcontractor agrees to be bound by the same restrictions, terms, and conditions that apply to BA pursuant to this Agreement with respect to such PHI. BA shall also (a) obtain reasonable assurances from the Subcontractor that the PHI will be held in confidence and used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and (b) obligate such person to notify BA of any instance in which PHI is used or disclosed that is not provided for in the Service Agreement, including incidents that constitute breaches of unsecured PHI or any security incident of which it becomes aware in which the confidentiality of the PHI has been breached.
2.4 Minimum Necessary. To the extent BA uses or discloses PHI received from, created, or received by BA on behalf of CE, BA will make reasonable efforts to limit PHI to the Minimum Necessary to accomplish the intended purpose of the use, disclosure or request.
2.5 Access of Individuals to PHI.
- In the event an Individual or entity requests access to PHI from BA, BA shall forward such request to CE within two (2) business days. CE is responsible for determining what PHI shall be unavailable to the Individual pursuant to 45 C.F.R. § 164.524.
- Any denial of access to PHI determined by CE pursuant to 45 C.F.R. § 164.524, and conveyed to BA by CE, shall be the responsibility of CE, including resolution or reporting of all appeals, and/or complaints arising from denials.
- BA shall cooperate with CE in a manner that enables CE to meet its obligations under 45 C.F.R § 164.524.
2.6 Amendment of PHI.
-
- In the event that any Individual requests that the BA amend his/her PHI, BA shall forward such request to CE within two (2) business days. The CE is responsible for determining what PHI is unavailable to the Individual pursuant to 45 C.F.R. § 164.526.
- Any denial of an amendment to PHI determined by CE pursuant to 45 C.F.R. § 164.526, and conveyed to BA by CE, shall be the responsibility of CE, including resolution or reporting of all appeals and/or complaints arising from denials.
- BA shall cooperate with CE in a manner that enables CE to meet its obligations under 45 C.F.R. § 164.526.
- Within a mutually agreed upon time from receipt of a request from CE to amend an Individual’s PHI in a Designated Record Set, BA shall incorporate any amendments, statements of disagreement, and/or rebuttals approved by CE into its Designated Record Set, as required by 45 C.F.R. § 164.526.
2.7 Accounting of Disclosures.
- In order to allow CE to respond to a request by an Individual for an accounting of disclosures of a Designated Record Set pursuant to 45 C.F.R. § 164.528, BA shall, within a mutually agreed upon timeframe from CE’s written request for an accounting of disclosures of PHI about an Individual, make such information available to CE.
- In the event an Individual requests an accounting of disclosures of PHI directly from BA, BA shall forward such request to CE within a mutually agreed upon timeframe.
- BA shall cooperate with CE in a manner that enables CE to meet its obligations under 45 C.F.R. § 164.528.
2.8 Subpoena or Legal Request for PHI. BA shall notify CE within a reasonable timeframe upon receipt of any request, subpoena, or other legal process to obtain PHI received from, or created or received by BA on behalf of CE. CE, in conjunction with BA, shall determine whether BA may disclose PHI pursuant to such request, subpoena, or other legal process. BA agrees to comply with CE’s determination in such instances. BA agrees to cooperate fully with CE in any legal challenge initiated by CE in response to such request, subpoena, or other legal process. The provisions of this Section shall survive the termination of this Agreement.
2.9 Reporting Breaches, Improper Disclosures, and Security Incidents.
- Breaches. In the event of notification of a Breach of any Unsecured PHI that BA accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds or uses on behalf of CE, BA shall report such Breach to CE immediately, but in no event more than five (5) days after discovering the breach. BA shall, in consultation with CE, mitigate, to the extent practicable any harmful effect of such Breach that is known to the BA.
- Improper Disclosures. BA shall report any unauthorized or improper use or disclosure of PHI regarding the terms and conditions of this Agreement or applicable federal and state laws to CE as soon as practicable, but in no event later than five (5) business days of the date on which BA becomes aware of such unauthorized or improper use or disclosure. BA shall, in consultation with CE, mitigate to the extent practicable any harmful effect of such improper disclosures.
- Security Incidents. BA shall report to CE any Security Incident of which it becomes aware within a reasonable timeframe.
2.10 Safeguards.
- BA shall employ appropriate administrative, technical, and physical safeguards, consistent with the size and complexity of BA’s operations, to protect the confidentiality and security of PHI that it creates, receives, maintains, or transmits on behalf of CE and to prevent the use or disclosure of PHI in any manner inconsistent with the terms of this Agreement.
- BA shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, receives, maintains, or transmits on behalf of CE. Such safeguards shall include implementing written policies and procedures in compliance with HIPAA and the HITECH Act, conducting a security risk assessment, and training BA employees who will have access to PHI on BA’s policies and procedures as required by HIPAA and the HITECH Act.
2.11 Availability of Books and Records to CE. Within a mutually agreed upon timeframe of a written request by CE (tied to its own external audit), BA and its agents or Subcontractors shall provide to CE, BA’s internal practices, books, and records at reasonable times as they pertain to the use and disclosure of PHI received from, or created or received by BA on behalf of CE in order to ensure that CE and BA are in compliance with the requirements of this Agreement, and to the extent that CE determines such examination is necessary to comply with CE’s obligations pursuant to HIPAA. The availability of books and records from BA to CE is subject to the following conditions:
- BA and CE shall mutually agree in advance upon the reasonability, scope, timing, and location of such a review.
- CE shall protect the confidentiality of all confidential and proprietary information of BA to which CE has access during the course of inspection.
- CE shall execute a nondisclosure agreement, under terms mutually agreed upon by the parties, if requested by BA.
2.12 Governmental Access to Records. If requested, BA shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary for purposes of determining BA’s compliance with the Privacy Rule and the Security Rule. BA shall notify CE within ten (10) calendar days of learning that BA has become the subject of an audit, compliance review, or complaint investigation by the Secretary. BA shall provide to CE a copy of such request for information and a copy of any PHI that BA provides to the Secretary concurrently with providing such PHI to the Secretary.
2.13 Data Ownership of PHI. BA acknowledges that, as between BA and CE, BA has no ownership rights with respect to PHI received from, created for, or used on behalf of CE.