Laserfiche WebLink
F. "Protected Health Information" or "PHI" shall have the meaning given to such term <br />under the Privacy and Security Rules at 45 C.F.R. § 160.103, limited to the <br />information created or received by Business Associate from or on behalf of <br />Covered Entity. <br />G. "Security Rule" shall mean the Security Standards for the Protection of Electronic <br />Protected Health Information, codified at 45 C.F.R. Parts 160 and 164, Subparts A <br />and C means the HIPAA regulation that is codified at 45 C.F.R. Part 164. <br />H. All capitalized and other terms used in this Agreement and not otherwise defined <br />herein will have the meaning ascribed in the Privacy, Security and Breach <br />Notification Rules.. <br />II. OBLIGATIONS OF BUSINESS ASSOCIATE <br />A. Permitted Uses and Disclosures Use of PHI: Except as provided in Sections <br />II(A)(I)-(6) below, Business Associate may only use or disclose PHI to perform <br />functions, activities or services for, or on behalf of Covered Entity. <br />Use for Management and Administration. Except as otherwise limited in <br />this Agreement, Business Associate may, consistent with 45 C.F.R. § <br />164.504(e)(4), use PHI if necessary (i) for the proper management and <br />administration of Business Associate, or (ii) to carry out the Iegal <br />responsibilities of Business Associate. <br />2. Disclosure for Management and Administration. Except as otherwise <br />limited in this Agreement, Business Associate may, consistent with 45 <br />C.F.R. § 164.504(e)(4), disclose PHI for the proper management and <br />administration of Business Associate or to carry out the legal <br />responsibilities of Business Associate, provided (i) the disclosure is <br />Required by Law, or (ii) Business Associate obtains reasonable assurances <br />from the person to whom the PHI is disclosed ("Person") that it will be held <br />confidentially and will be used or further disclosed only as Required by Law <br />or for the purpose for which it was disclosed to the Person, and that the <br />Person agrees to immediately notify Business Associate in writing of any <br />instances of which it becomes aware in which the confidentiality of the <br />information has been breached or is suspected to have been breached. <br />3. Data Aggregation. Except as otherwise limited in this Agreement, Business <br />Associate may use PHI to provide Data Aggregation services to Covered <br />Entity as permitted by 42 C.F.R. § 164.504(e)(2)(i)(B). <br />4. De -Identification. Business Associate may de -identify PHI in accordance <br />with 45 C.F.R. § I64.514(b). <br />5. Reporting Violations. Business Associate may use PHI to report violations <br />of law to appropriate Federal and State authorities, consistent with 45 <br />C.F.R. § 164.5020)(1). <br />