My WebLink
|
Help
|
About
|
Sign Out
Home
Browse
Search
Agreements - Business Associate and Confidentiality for HIPAA Compliance and Confidential Data Transfer, Maintenance & Disclosure for SBFD - enFocus
sbend
>
Public
>
Public Works
>
Board of Works Documents
>
2019
>
Agreements/Contracts/Proposals
>
Agreements - Business Associate and Confidentiality for HIPAA Compliance and Confidential Data Transfer, Maintenance & Disclosure for SBFD - enFocus
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
4/4/2025 1:16:50 PM
Creation date
12/12/2019 9:31:21 AM
Metadata
Fields
Template:
Board of Public Works
Document Type
Contracts
Document Date
12/10/2019
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
17
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
Show annotations
View images
View plain text
2. Cu feral Obligations of Business Associate. <br />2.1 Business Associate agrees not to use or disclose PHI, other than as permitted or <br />required by this BAA or as Required By Law, or if such use or disclosure does not otherwise <br />cause a Breach of Unsecured PHI. <br />2.2 Business Associate agrees to use appropriate safeguards, and to comply with <br />Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI <br />other than as provided for by the BAA. <br />2.3 Business Associate agrees to mitigate, to the extent practicable, any harmful <br />effect that is known to Business Associate as a result of a use or disclosure of PHI by Business <br />Associate in violation of this BAA's requirements or that would otherwise cause a Breach of <br />Unsecured PHI. <br />2.4 Business Associate agrees to the following breach notification requirements: <br />(a) Business Associate agrees to report to Covered Entity any Breach of <br />Unsecured PHI not provided for by the BAA of which it becomes aware within ten (10) <br />calendar days of "discovery" within the meaning of the HITECH Act. Such notice shall <br />include the identification of each individual whose Unsecured PHI has been, or is <br />reasonably believed by Business Associate to have been, accessed, acquired, or <br />disclosed in connection with such Breach. In addition, Business Associate shall provide <br />any additional information reasonably requested by Covered Entity for purposes of <br />investigating the Breach and any other available information that Covered Entity is <br />required to include to the individual under 45 C.F.R. § 164.404(c) at the time of <br />notification or promptly thereafter as information becomes available. Business <br />Associate's notification of a Breach of Unsecured PHI under this Section shall comply <br />in all respects with each applicable provision of Section 13400 of Subtitle D (Privacy) <br />of ARRA, the HIPAA Rules, and related guidance issued by the Secretary or the <br />delegate of the Secretary from time to time. <br />(b) In the event of Business Associate's use or disclosure of Unsecured PHI <br />in violation of HIPAA, the HITECH Act, or ARRA, Business Associate bears the <br />burden of demonstrating that notice as required under this Section 2.4 was made, <br />including evidence demonstrating the necessity of any delay, or that the use or <br />disclosure did not constitute a Breach of Unsecured PHI. <br />2.5 Business Associate agrees, in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) <br />and 164.308(b)(2), if applicable, to require that any Subcontractors that create, receive, <br />maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions, <br />conditions, and requirements that apply to the Business Associate with respect to such <br />information. <br />2.6 Business Associate agrees to make available PHI in a Designated Record Set to <br />Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524. <br />2 <br />
The URL can be used to link to this page
Your browser does not support the video tag.