Laserfiche WebLink
BUSINESS ASSOCIATE AGREEMENT <br />This Business Associate Agreement ("Agreement") is entered into by and between CITY <br />OF SOUTH BEND {referred to as "Covered Entity") and SEMMA HEALTH, INC. ("Business <br />Associate"). This Agreement is effective as of May 15", 2017 ("Effective Date"). <br />RECITALS <br />WHEREAS, Business Associate provides services to CITY OF SOUTH BEND, a <br />Covered Entity as that term is defined under the Health Insurance Portability and Accountability <br />Act of 1996, Public Law 104-191, and its implementing regulations (collectively, "HIPAA"), as <br />amended by the final regulations promulgated pursuant to the Health Information Technology for <br />Economic and Clinical Health (such regulations, "HITECH") Act (Division A, Title XIII and <br />Division B, Title IV of Pub. L. No. 111-5) (which was part of the American Recovery and <br />Reinvestment Act of 2009); and <br />WHEREAS, Covered Entity is required to protect the privacy and security of Protected <br />Health Information, including Electronic Protected Health Information (sometimes collectively <br />referred to as "PHI" or individually as "PHI" and "EPHI"), and to obtain written assurances <br />that Business Associate will protect the privacy and security of PHI disclosed to or created by <br />Business Associate on its behalf in compliance with HIPAA and HITECH; and <br />WHEREAS, the HIPAA Privacy Rule and Security Rules and HITECH require Covered <br />Entity and Business Associate to enter into this Agreement containing specific requirements prior <br />to the disclosure of PHI, as set forth in, but not limited to, Title 45, Sections 164.502(e) and <br />164.504(e) of the Code of Federal Regulations ("CFR"); and <br />NOW, THEREFORE, in consideration of the mutual promises below and other <br />consideration contained herein, the sufficiency of which is hereby acknowledged, the parties agree <br />as follows: <br />I. DEFINITIONS <br />A. "Breach" shall have the meaning set forth in 45 C.F.R. Section 164.402. <br />B. "Breach Notification Rule" shall mean the rule related to breach notification for <br />Unsecured Protected Health Information codified at 45 C.F.R. Parts 160 and 164, <br />Subpart D. <br />C. "Electronic Protected Health Information" or "EPHI" shall have the meaning given <br />to such term under the Security Rule, including, but not limited to, 45 C.F.R. § <br />160.103, limited to the information created or received by Business Associate from <br />or on behalf of Covered Entity. <br />D. "HIPAA Rules" shall mean the Privacy, Security and Breach Notification Rules. <br />E. "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable <br />Health Information, codified at 45 C.F.R. Parts 160 and 164, Subparts A and E. <br />