Laserfiche WebLink
P <br />THIS BUSINESS ASSOCIATE AGREEMENT ("Agreement") is entered into by and CITY OF SOUTH BEND, <br />(referred to as "Covered Entity") and SEMMA HEALTH, INC. ("Business Associate"). This Agreement is effective <br />as of October 23, 2018 ("Effective Date"). <br />WHEREAS, Business Associate provides services under a Data Services Agreement dated October 23, <br />2018 to City of South Bend, which is a Covered Entity as that term is defined under the Health Insurance <br />Portability and Accountability Act of 1996, Public Low 104-191, and its implementing regulations (collectively, <br />"HIPAA"), as amended by the final regulations promulgated pursuant to the Health Information Technology for <br />Economic and Clinical Health (such regulations, "HITECH") Act (Division A, Title XIII and Division B, Title IV of Pub. <br />L. No. 1 1 1-5) (which was part of the American Recovery and Reinvestment Act of 2009); and <br />WHEREAS, Covered Entity is required to protect the privacy and security of Protected Health Information, <br />including Electronic Protected Health Information (sometimes collectively referred to as "PHI" or individually as <br />"PHI" <br />!F <br />PHI and "EPHI ), and to obtain written assurances that Business Associate will protect the privacy and security <br />of PHI disclosed to or created by Business Associate on its behalf in compliance with HIPAA and HITECH; and <br />WHEREAS, the HIPAA Privacy Rule and Security Rules and HITECH require Covered Entity and Business <br />Associate to enter into this Agreement containing specific requirements prior to the disclosure of PHI, as set forth <br />in, but not limited to, Title 45, Sections I64.502(e) and 164.504(e) of the Code of Federal Regulations ("CER"); <br />and <br />NOW, THEREFORE, in consideration of the mutual promises below and other consideration contained <br />herein, the sufficiency of which is hereby acknowledged, the parties agree as follows. <br />A. "Breach" shall have the meaning set forth in 45 C.F.R. Section 164,402. <br />B3 "Breach Notification Rule" shall mean the rule related to breach notification for Unsecured Protected <br />Health Information codified at 45 C.F.R. Parts 160 and 164, Subpart D. <br />C. "Electronic Protected Health Information" or "EPHI" shall have the meaning given to such term at 45 C.F.R. <br />§ 160.103, limited to the information created or received by Business Associate from or on behalf of <br />Covered Entity. <br />D. "HIPAA Rules" shall mean the Privacy, Security and Breach Notification Rules. <br />E. "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information, <br />codified at 45 C.F.R. Parts 160 and 164, Subparts A and E. <br />