Loading...
HomeMy WebLinkAboutProfessional Services Agreement - SEMMA Health Inc - 2020 City Benefit Plan1316 (.ouN'ry-0'ry BUILDING 227 W JEFFE 'RSON BOULEVARD Sol ri'l I N'ND. 1NDIANA46601-1930 CITY OF Sourii BEAD PETE BUTTIGIEG, MAYOR BOARD OF PUBLIC WORKS October 23, 2018 Susan Ford SEMMA Health, Inc. 1.00 E. Wayne Street South Bend, IN 46601 RE: Professional Services Agreement Dear Ms. Ford: 1'110W574/235-9251 FAX 574/ 235-9171 The Board of Public Works, at its meeting held on October 23, 2018, approved the above referenced agreement to help the City develop a 2020 Benefit Plan by ensuring the City is paying reasonable rates for medical services in the amount of $1,000 per month + 30% Success Fee. Enclosed please find a copy of the agreement for your records. If you have .any further questions regarding this matter, please call this office at (574) 235- 9251. Sincerely, Linda M. Martin, Clerk Enclosure a4— T. DORAU GM�y A. Gimi, SUZANNA M. FwT7,131--,R(x ELIZABE i'n A. MARAINK JAW"s A, MUELLF',R THURESE E:=ems , H E A L T H 00 E WEI yAt�'S)1�0, SWIU, -s 10, .54meN &-qd, IN 46 60 1 P THIS BUSINESS ASSOCIATE AGREEMENT ("Agreement") is entered into by and CITY OF SOUTH BEND, (referred to as "Covered Entity") and SEMMA HEALTH, INC. ("Business Associate"). This Agreement is effective as of October 23, 2018 ("Effective Date"). WHEREAS, Business Associate provides services under a Data Services Agreement dated October 23, 2018 to City of South Bend, which is a Covered Entity as that term is defined under the Health Insurance Portability and Accountability Act of 1996, Public Low 104-191, and its implementing regulations (collectively, "HIPAA"), as amended by the final regulations promulgated pursuant to the Health Information Technology for Economic and Clinical Health (such regulations, "HITECH") Act (Division A, Title XIII and Division B, Title IV of Pub. L. No. 1 1 1-5) (which was part of the American Recovery and Reinvestment Act of 2009); and WHEREAS, Covered Entity is required to protect the privacy and security of Protected Health Information, including Electronic Protected Health Information (sometimes collectively referred to as "PHI" or individually as "PHI" !F PHI and "EPHI ), and to obtain written assurances that Business Associate will protect the privacy and security of PHI disclosed to or created by Business Associate on its behalf in compliance with HIPAA and HITECH; and WHEREAS, the HIPAA Privacy Rule and Security Rules and HITECH require Covered Entity and Business Associate to enter into this Agreement containing specific requirements prior to the disclosure of PHI, as set forth in, but not limited to, Title 45, Sections I64.502(e) and 164.504(e) of the Code of Federal Regulations ("CER"); and NOW, THEREFORE, in consideration of the mutual promises below and other consideration contained herein, the sufficiency of which is hereby acknowledged, the parties agree as follows. A. "Breach" shall have the meaning set forth in 45 C.F.R. Section 164,402. B3 "Breach Notification Rule" shall mean the rule related to breach notification for Unsecured Protected Health Information codified at 45 C.F.R. Parts 160 and 164, Subpart D. C. "Electronic Protected Health Information" or "EPHI" shall have the meaning given to such term at 45 C.F.R. § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity. D. "HIPAA Rules" shall mean the Privacy, Security and Breach Notification Rules. E. "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information, codified at 45 C.F.R. Parts 160 and 164, Subparts A and E. =APOJ�6= S E M M A P. "Protected Health Information" or "PHI" shall have the meaning given to such term under the Privacy and Security Rules at 45 C.F.R. § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity. G. "Security Rule" shall mean the Security Standards for the Protection of Electronic Protected Health Information, codified at 45 C.F.R. Parts 160 and 164, Subparts A and C means the HIPAA regulation that is codified at 45 C.F.R. Part 164. H. All capitalized and other terms used in this Agreement and not otherwise defined herein will have the meaning ascribed in the Privacy, Security and Breach Notification Rules. yl R � *.-. A. �errrtittsd Uses and.l isclosures Use of PHI. Except as provided in Sections II(A)(1)-(6) below, Business Associate may only use or disclose PHI to perform functions, activities or services for, or on behalf of Covered Entity. 1. Use for Management and Administration. Except as otherwise limited in this Agreement, Business Associate may, consistent with 45 C.F.R. § i 64.504(e)(4), use PHI if necessary (i) for the proper management and administration of Business Associate, or (ii) to carry out the legal responsibilities of Business Associate. 2. Disclosure for Management and Administration. Except as otherwise limited in this Agreement, Business Associate may, consistent with 45 C.F.R. § 164.504(e)(4), disclose PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided (i) the disclosure Is Required by Low, or (ii) Business Associate obtains. reasonable assurances from the person to whom the PHI is disclosed ("Pe ") that it will be held confidentially and will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the Person, and that the Person agrees to immediately notify Business Associate in writing of any instances of which it becomes aware in which the confidentiality of the information has been breached or is suspected to have been breached. 3. Data Actareciation. Except as otherwise limited in this Agreement, Business Associate may use PHI to provide Dbta Aggregation services to Covered Entity as permitted by 45 C.F.R. § i 64.504(e)(2)(1)(B)_ 4. fie-ldentification. Business Associate may de -identify PHI in accordance with 45 C.F.R. § 164.514(b). 5. Reaorting Violations. Business Associate may use PHI to report violations of law to appropriate Federal and State authorities, consistent with 45 C.F.R. § 164.502(j)(1). B. Limitations on Disclosure of PHI. Business Associate shall not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law. Business Associate shall not use or disclose PHI in a manner that would violate the Privacy Rule if done by Covered Entity, unless expressly permitted to do so pursuant to the Privacy Rule and this Agreement. Page 2 1 14 C. Ci61i atiasrSs on a:half of hovered Emit . To the extent Business Associate carries out on obligation for which Covered Entity is responsible under the Privacy Rule, Business Associate must comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of such obligation. D. HiP kA Safeguards 1. Business Associate shall use appropriate safeguards to prevent use or disclosure of PHI other than as permitted by this Agreement. 2. Business Associate shall comply with the Security Rule and implement reasonable and appropriate Administrative, Physical, and Technical Safeguards to protect the Confidentiality, Integrity, and Availability of EPHI and to prevent the use or disclosure of EPHI other than as permitted by the Agreement. 3. Business Associate shall not disclose or maintain PHI outside of the United States and shall not allow anyone outside the United States to have access to PHI without the express, prior written consent of Covered Entity. E. ffp-gd nca of Disclosures of Protected Health Information in Violation of HIP A. Business Associate shall report to Covered Entity in writing any use or disclosure of PHI not permitted by this Agreement promptly after becoming aware of such use or disclosure. F. Reoortina of Securitv Incidents. Business Associate shall report to Covered Entity any successful Security Incident promptly, but no later than ten (10) days, upon becoming aware of such incident. For purposes of this Agreement, an "unsuccessful" Security Incident is an unsuccessful attempt to breach the security of Business Associate's systems that Business Associate determines was targeted at Business Associate's systems storing Covered Entity's EPHI, and includes general "pinging" or "denial of service" attacks that are not determined to have been directed at such EPHI, and such unsuccessful Security Incidents shall be deemed as having been reported. G. Reporting of Breaches of Unsecured PHI. i. Notification Requirement. Business Associate shall report any Breach of Unsecured PHI known or suspected by Business Associate to Covered Entity without unreasonable delay and in no case later than ten (10) days after discovery of the Breach. 2. Discovery of Breach. For purposes of reporting a Breach to Covered Entity, the discovery of a Breach shall occur on the first day on which such Breach is known to Business Associate or, by exercising reasonable diligence, would have been known to or suspected by the Business Associate. Business Associate will be considered to have had knowledge of a Breach if the Breach is known, or by exercising reasonable diligence would have been known to any person (other than the person committing the Breach) who is an employee, officer or agent of the Business Associate. 3. Contents of Notification. Any notice referenced above in Section II(C)(1) of this Agreement will include, to the extent known to the Business Associate, the identification of each individual whose Unsecured PHI has been, or is reasonably believed by Business Associate to have been accessed, acquired, used, or disclosed during such Breach. Business Associate will also provide to Covered Entity other available information that the Covered Entity is required to include in its notification to the individual pursuant to the Breach Notification Rule. Page 3 1 14 H. Acareerrtenta by Third Parties. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.808(b)(2), Business Associate shall enter into a written agreement with any Subcontractor that creates, receives, maintains or transmits PHI for or on behalf of Business Associate pursuant to which such Subcontractor agrees to be bound by substantially the same restrictions, terms, and conditions that apply to Business Associate with respect to such PHI. I. Disclosu. Business Associate shall make its internal practices, books, and records relating to the use and disclosures of PHI available to the Secretary for purposes of determining Covered Entity's or Business Associate's compliance with HIPAA. J. Access bv individuals. Business Associate shall provide access, at the request of Covered Entity, and in the time and manner reasonably designated by Covered Entity, to PHI in a Designated Record Set, to Covered Entity in order for Covered Entity to meet the requirements under the Privacy Rule at 45 C.F.R. 164.524. K. Amendment of PHI. Business Associate shall make any PHI contained in a Designated Record Set available to Covered Entity for purposes of amendment pursuant to 45 C.F.R. § 164,526. L. Accounting of Disclosures. To the extent applicable, Business Associate agrees to document disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with the Privacy Rule at 45 C.F.R. § 164,528. Business Associate shall provide Covered Entity with such documentation upon the request of Covered Entity. M. MiniMum Necessary. Business Associate shall only request, Use, and Disclose the minimum amount of PHI necessary to accomplish the purpose of the request, Use, or Disclosure. N. Mittiga on. Business Associate shall, to the extent practicable, mitigate any harm caused by a use or disclosure that is not permitted by this Agreement. +r W; • :M 0 A. Notice of Privacy Practices. Covered Entity shall notify Business Associate of any limitation(s) in the Notice of Privacy Practices of Covered Entity under 45 CFR 164.520, to the extent that such limitations pray affect Business Associate's Use or Disclosure of PHI. a. Revocation of Permission. Covered Entity shall notify Business Associate of any changes in, or revocation of, the permission by an Individual to use or disclose his or her PHI, to the extent that such changes may affect Business Associate's Use or Disclosure of PHI. C. Ri ht to Request Privacy.Protection for PHI. Covered Entity shall notify Business Associate of any restriction on the Use or Disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR 164.522 ("Right to Request Privacy Protection for PHI"), to the extent that such restriction may affect Business Associate's Use or Disclosure of PHI. D. Permissible Requests by Covered Entity. Covered Entity shall not request Business Associate to Use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity. Exceptions to this Section include Use or Disclosure PHI for Data Aggregation or management and administration and legal responsibilities of Business Associate. Page 4 1 ]A �11 A. Terms. The Term of this Agreement shall be effective as of the date specified above, and shall terminate when all of the PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed, or returned to Covered Entity. If it is infeasible to return or destroy Protected Health Information, Business Associate shall extend protections to such information, in accordance with the termination provisions in this Section. B. ermination for Cause. If Covered Entity becomes aware of a pattern of activity or practice that constitutes a material breach or violation of the obligations under the provisions of this Agreement, Covered Entity has the option to terminate the Agreement upon demanding a cure within thirty (30) days of obtaining such knowledge. If Business Associate fails to cure such breach within the thirty (30) day period, Covered Entity has the right to terminate the Agreement immediately. C. iJbli finr�s o business Asspciesie U an Cermina9inr�. t. Except as provided in paragraph two (2) of this Section IV(C), upon termination of this Agreement for any reason, Business Associate shall return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, and shall retain no copies of the PHI except as required by the Agreement. 2. In the event that Business Associate determines that returning or destroying the PHI is infeasible, Business Associate shall provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the parties that return or destruction of PHI is infeasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI. A. Insurance. Business Associate shall provide, pay for, and maintain first party and third -party liability insurance coverage to cover its obligations under this Agreement, commonly known as "cyber liability insurance" or "data breach liability insurance" with limits of not less than One Million Dollars ($1,000,000). Covered Entity shall be named as an additional insured on such insurance policy or policies. Such insurance shall expressly provide coverage for (among other things) HIPAA/HITECH violations and/or issues. Such insurance shall be maintained throughout the term of this Agreement and if such insurance is written on a "claims made" basis, for an extended period of not less than two (2) years rafter all PHI is destroyed or returned to the Covered Entity. Upon request at the commencement of this Agreement, and upon request at any reasonable time during the term thereof, Business Associate shall furnish to Covered Entity certified copies of the insurance policy or policies and endorsements to all policies, certificates of insurance, declarations pages and schedules of forms to all policies, & AmendmeVIT. The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for the parties to comply with the HIPAA Rules. C. Survival. The respective rights and obligations of Business Associate under Section IV(A), (B), and (C) of this Agreement shall survive the termination of this Agreement. D. Governipq Lawn. This Agreement shall be construed, and the rights and liabilities of the parties hereto determined, in accordance with the internal laws of the State of Indiana. Pane 5 1 14 E. Titles and Heaciin s. Titles and headings to sections herein are for purposes of reference only, and shall in no way limit, define, or otherwise affect the provisions herein. F. En irg Agreement. This Agreement, including any exhibits presently or subsequently attached hereto, constitutes the entire agreement between the parties concerning the subject matter hereof, and supersedes all prior agreements, whether written or oral, between the parties and the subject matter hereto. G. No ThirdnPart Ri,ghis. The parties agree that it is their specific intention to create no third -party rights by virtue of this Agreement. H. No Third -Party Beneficiaries. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than Covered Entity, Business Associate, and their respective successors or assigns, any rights, remedies, obligations, or liabilities whatsoever. 1. Ind"gnde ent Contractors. The parties are and shall be independent contractors to one another, and nothing in this Agreement shall be deemed to cause this Agreement to create an agency, partnership, or joint venture between the parties. Except as expressly provided herein, neither party shall be liable for any debts, accounts, obligations, or other liabilities of the other party. J. Assignment. This Agreement shall be binding on the parties and their successors and assigns, provided that neither party shall assign any of its rights under this Agreement to any other party without the prior written consent of the other party. K. Severability. In the event that any court or any governmental authority or agency declares all or part of any section of this Agreement to be unlawful or invalid, such unlawfulness or invalidity shall not serve to invalidate any other section of this Agreement, and in the event that only a portion of any section is so declared to be unlawful or invalid, such unlawfulness or invalidity shall not serve to invalidate the balance of such section. Countg1parts. This Agreement may be executed in two or more counterparts, each of which shall be deemed to be an original, but all of which shall constitute one and the some agreement. M. Reaulatory References. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended. N. Interpretation. The provisions of this Agreement shall prevail over any provisions in any other agreement between the parties that may conflict or appear Inconsistent with any provision in this Agreement. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules. 0. Indemnification. Business Associate shall indemnify and hold harmless Covered Entity and its officers, trustees, employees, and agents from any and all claims, penalties, fines, costs, liabilities or damages, including but not limited to reasonable attorney fees, incurred by Covered Entity arising from a violation by Business Associate of its obligations under this Agreement. Page 6 1 14 I P. Remedies. Business Associate acknowledges and stipulates that its unauthorized use or disclosure of PHI while performing services pursuant to the Agreement would cause irreparable harm to Covered Entity, and in such event, Covered Entity shall be entitled, if it so elects, to institute and prosecute proceedings in any court of competent jurisdiction, either in law or in equity, to obtain damages and injunctive relief without the necessity of posting a bond, together with the right to recover from Business Associate costs, including reasonable attorneys' fees, for any such breach of the ternis and conditions of the Agreement. [Signature page follows] Page 7 1 14 =JXP�aw S E Ill 11. /\ L 1I'd SIGNATURE PAGE TO BUSINESS ASSOCIATE AGREEMENT IN WITNESS WHEREOF, the partles hereto have duly executed this Agree merfl cis of the date firsi set forlh above, SEMMA Health, Inc, City of South Bend Signature: Printed t,,4ariie- Printed Narim: Mle: Title. Date: Uate,. Printed None Title. Dnte: Signature; Prhiled I\Jarne' Title: Date: Signature-, Printed Name. Title: D a re. Pa g e 8 1 14 Ax S E M M A THI THIS DATA SERVICES AGREEMENT ("Agreement") meement") is entered into as of the 231c, day of October 2018 (the "Effective pate"), by and between SEMMA HEALTH, INC. ("SEMMA') and CITY OF SOUTH BEND ("Client"). WHEREAS, SEMMA Health Inc. provides a variety of data and consulting services for employers sponsoring self -funded group health Insurance plans, including but not limited to certain data aggregation, data analysis, and forecasting services; WHEREAS, Client is the sponsor of a self -funded group health insurance plan providing, among other services, health care benefits to certain eligible employees and their qualified dependents; WHEREAS, Client desires to retain SEMMA as an independent contractor to provide certain data and consulting services in connection with Client's self -funded group health plan(s), as more particularly described ill this Agreement; and WHEREAS, SEMMA desires to provide data and consulting services to the Client in connection with the Client's self -funded group health plan, pursuant to the terms of this Agreement. NOW, THEREFORE, in consideration of the promises and mutual covenants contained herein and other valuable consideration, the parties hereto agree as follows- 1.1 Services. Client hereby retains SEMMA to provide, and SEMMA hereby agrees to provide, on the terms and conditions set forth in this Agreement, the data and consulting services set forth in this Section 1.1 (the "Se ry ices")- 1.1.1 SEMMA shall employ its proprietary big data and analytic platform to proactively identify ways to reduce waste and variation in the cost and quality of care that is purchased through the Client's health benefit plan. 1.1.2 SEMMA shall provide regular analyses of Client's health benefit claims as processed by Client's health benefit administrator. 1 .1.3 SEMMA shall generate and provide to Client regular reports (collectively, the "Reports") on analyses of health benefit utilization and costs. 1.1.4 SEMMA will work to digitally transform the annual health benefit design process the City of South fiend HR department utilizes. This will be done by leveraging the City of South Bend data sources provided to SEMMA, including but not limited to: medical claims, prescription claims, HRIS data, workers' compensation data, near site clinic data; SEMMA's data platform; and industry knowledge. 1.1.5 SEMMA will provide targeted analyses related to the post, current, & projected health benefit usage of the City of South Bend plan members. Page 9 1 14 1.1.6 SEMMA will deploy its predictive analytic models on the City of South Bend, specifically chronic disease, high dollar claims, new diagnoses 1.1.7 SEMMA will partner with the City of South Bend's health care broker & other vendors to act on the insights 1.2 Independent Contractors. The parties intend to, and shall, act and perform as independent contractors, Each party shall be solely responsible for, and shall comply with, ail state and federal laws, rules and regulations pertaining to employment taxes, income tax withholding, unemployment compensation contributions, and all other employment related laws, rules and regulations applicable to that party. SEMMA retains all the rights and privileges as the employer of its employees including, without limitation, the right to control, supervise, hire, discipline, compensate, and terminate such employees. Nothing in this Agreement shall constitute or be construed to be or to create an employer -employee, partnership or joint " venture relationship between SEMMA and Client. 2.1 Services Fees. In consideration of the Services rendered by SEMMA under this Agreement, Client shall pay SEMMA the services fees set forth in this Section: 2.1.1 Services Fees. Client will pay SEMMA a Monthly Data Management and Analysis Fee of $1.000 (the "Services. Fees"). 11.2 Success Fees. Client will pay SEMMA a 30% Success Fee when and only after SEMMA has identified and recovered overpayments exceeding the Client's total Monthly Data Management and Analysis Fee for the "initial term" and any renewal terms collectively, the "term" of the Agreement, generated through its monthly claims overpayment audit. Success savings will be calculated monthly and are to be paid annually at the end of the "initial term", and any renewal terms collectively, the "term". 2.2 invoice5,payment and Reconciliation. 202.1 SEMMA shall submit monthly invoices to Client for the Services Fees and yearly invoices for the Success Fees, beginning upon commencement of this Agreement and every 30 days following. Client shall pay all invoiced amounts within thirty (30) days of receipt of an invoice. 3.1 HIPAA. The parries hereto agree that this relationship meets the requirements established in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended (collectively, "HIPAA"), which governs the use of Protected Health Information (as such terra is defined in 45 C.F.R. § 160.103). For purposes of the parties' compliance with HIPAA, the Business Associate Agreement ("§AA") entered into by the parties shall apply to this Agreement. Page 10 1 14 3.2 Data anti System Access. Client agrees to provide SEMMA with data related to reimbursement claims made by or on behalf of members participating in Client's self -funded group health insurance plan(s) (the "£7ata") as SEMMA requires in connection with performing its Services under this Agreement. Client shall snake the Data available to SEMMA through electronic communications, one or more gateway(s), website(s) and/or secure transfer protocols hosted by or on behalf of SEMMA (the "Systerns"), or another format agreed to by the parties. As permitted by SEMMA, Client may perform all data transmission through such systems utilizing the browsers and technology set forth in documentation provided by SEMMA to Client from time to time. The Client agrees to limit access to and use of such systems to those personnel whose duties require such use. 4. INTELLECTUAL PROPERTY RIGHTS 4.1 Materials. All proprietary materials, including Confidential Information (as defined herein), owned, developed or licensed by or on behalf of either party: (i) prior to the Effective Gate, including, without limitation, the subject matter of patents and all third -party materials licensed by Client or SEMMA; and/or (11) independently developed by the Client and/or the Client's Agents or SEMMA subsequent to the Effective Date (the "Client Materials" and "SEMMA Materials." respectively) are, and all intellectual property rights in and to them shall continue to be, owned by such party. No ownership of the Client Materials or the SEMMA Materials or the intellectual property rights in and to there shall be transferred by virtue of this Agreement. The parties agree that SEMMA retains the right to use the ideas, concepts, techniques, industry data, and know-how it obtains or develops in the Course of performing its Services under this Agreement. 4.2 Client Data. The parties agree that the Data is and will remain the property of Client and/or Client's TPA. SEMMA shall not share, sell, or otherwise give to any third -party person or organization the Data without the prior written consent of Client, except as expressly provided herein. Client agrees that SEMMA may use all of the Data alone or in combination with other data and other third -party data sources, provided any such use is in compliance with HIPAA and the Agreement. 5.1 Confidential Information. 5.1.1 The parties acknowledge that each party may disclose, deliver or give access to the other party (the "Disclosing Party" and the "Receiving Party." respectively) information, data or materials, in either tangible or intangible form, that are trade secrets of, or proprietary and confidential to, the Disclosing Party, including without limitation:(i) Client Data; (11) Client Materials; (if!) SEMMA Materials; (iv) the Reports; (v) all information communicated to it by the other party and identified as confidential; (vi) all information that is not generally known to the public and at the time of disclosure and is identified as, or would reasonably be understood by that party to be, proprietary or confidential, and that the party (or its contractors or agents) observes or learns in connection with this Agreement; and (lv) this Agreement (collectively, the "Confidential Information"). Page 11 1 14 4<p�= S E M M A 6.1.2 Except as expressly stated in this Agreement, the Receiving Party shall protect Confidential Information received hereunder with the same degree of care as it exercises for its own information of like kind (in no case less than reasonable care in accordance with professional standards) and shall not use the Confidential Information except as necessary to fulfill its obligations under this Agreement. Except as expressly stated in this Agreement, the Receiving Party shall not disclose the Confidential Information to any third party during the Term or thereafter without the Disclosing Party's express written consent in each instance unless disclosure €s required by the Indiana Access to Public Records Act. Access to and use of any Confidential Information shall be restricted to those employees and persons within a party's organization with known discretion and with a need to use the information to perform such party's obligations under this Agreement. The Receiving Party will promptly report to the Disclosing Party any breaches in confidentiality that may materially affect the Disclosing Party and specify the corrective action taken. .1.3 All Confidential Information will remain the exclusive property of the Disclosing Party. Confidential Information does not include information that: (i) is already known by the Receiving Party prior to disclosure by the Disclosing Party; (H) is independently developed by the Receiving Party without the use of the Confidential Information; (iii) is publicly known or becomes publicly known through no breach of this Agreement by the Receiving Party; (iv) is independently obtained from a third party under no duty of confidentiality to the Disclosing Party; or (v) is required to be disclosed in a judicial or administrative proceeding after all reasonable legal remedies for maintaining such Confidential Information in confidence have been exhausted and so long as the receiving Party notifies the disclosing Party a reasonable time prior to disclosure and discloses the minimum amount of Confidential Information required. 5.2 scamof Materials. At the Disclosing Party's written request upon expiration or termination of this Agreement, each party shall return, or if return is not feasible, destroy and certify to such destruction in writing, all Confidential Information and proprietary materials of the other party and all copies and embodiments thereof in its possession. Notwithstanding the foregoing, the Receiving Party may retain copies of the Confidential Information for archival purposes, as otherwise required by law or that is already included in the Reports. 6. TERM 6.1 Terra. This Agreement shall commence as of the Effective Date and shall continue in effect until October 31, 2019 (the "Initial Term". This Agreement shall be automatically renewed for successive one-year terms (the Initial Term and any renewal terms collectively, the "Term"). 6.2 Termination. Either party to this Agreement may terminate this Agreement for any reason or no reason by providing at least thirty (30) days written notice to the other party. If the Agreement is terminated, the parties will only be responsible for obligations incurred through the date of termination. 7. GENERAL TERMS 7.1 Survival. The following Articles and Sections will survive and remain effective following termination or expiration of this Agreement: 3.1 (HIPAA), 4 (intellectual Propert�gRi hts), 5 (Confidentiality), and i (General Terms). Page 12 1 14 7.2 Promotional Materials. Client agrees to permit SEMMA to use the name, trade marl, service marl, or design registered to the Client or its affiliates in any public manner, including in any social media, promotional, or advertising material. Each party agrees to cooperate with the other party regarding any media release, public announcement, or similar disclosure relating to this Agreement or its subject matter and will give the other party a reasonable opportunity to review and comment on the content of such release, announcement, or disclosure prior to its release; provided, however, that no party will issue such release, announcement, or disclosure without the prior written consent of the other party. [Signature page followsi Page 13 1 14 SIGNATURE PAGE TO DATA SERVICES AGREEMENT 114 'WITNESS WHEREOF, the parties have COUsed this Data Services Agreement to be executed by their duly authorized representatives os of the day and yeor first above written. SE MMA Health, Inc, Printed NcArne:---4 Title: Cify of South Bend 111h- Signature. M-1, ------- - Printed Name: Title: Date- Slgnature: Printed Name. Title. Date, Signature; f"rinted Ncurie: Title. Date: Signature: Printed Name- 'fifle. Date 11 ci g e 14 1 14