HomeMy WebLinkAboutAgreements - Business Associate and Confidentiality for HIPAA Compliance and Confidential Data Transfer, Maintenance & Disclosure for SBFD - enFocus1316 COUNTY -CITY BUILDING
�� f PHONE 574/ 235-9251
227 W. JEFFERSON BOULEVARD
r FAX 574/ 235-9171
SOI ITH BEND_ INDIANA 46601-1 830
a.°
CITY OF SOUTH BEND PETE BUTTIGIEG, MAYOR
BOARD OF PUBLIC WORKS
December 10, 2019
Mr. Andrew Wiand
enFocus
Studebaker Building 113
635 S. Lafayette Blvd.
South Bend, IN 46601
RE: Business Associate Agreement, and Confidentiality Agreement
Dear Mr. Wiand:
The Board of Public Works, at its meeting held on December 10, 2019, approved the above
referenced agreements for HIPAA Compliance and Confidential Data Transfer,
Maintenance, and Disclosure Responsibilities for Fire Department's NIOSH Grant.
Enclosed please find a copy of the agreement for your records.
If you have any further questions regarding this matter, please call this office at (574) 235-
9251.
Sincerely,
Linda M. Martin, Clerk
Enclosure
GARY A. GILOT GENEVIEVE E. MILLER ELIZABETH A. MARADIK LAURA L. O'SULLIVAN THERESE J. DORAU
CONFIDENTIALITY AGREEMENT
This Confidentiality Agreement (this "Agreement"), effective as of f J0j 0101 q
(the "Effective Date"), is entered into by and between the City of South Bend (the "Disclosing
Party"), an Indiana municipal corporation, acting by and through its Board of Public Works, and
enFocus, an Indiana nonprofit corporation (the "Recipient," and together with the Disclosing Party,
the "Parties," and each, a "Party").
WHEREAS, in connection with enFocus' consultation on and provision of project
management services for the City of South Bend's application to and, if approved, participation in
the National Institute for Occupational Safety and Health research grant program regarding
firefighter health and safety (the "Purpose"), the Recipient desires to receive certain information
from the Disclosing Party that is non-public, confidential, or proprietary in nature; and
WHEREAS, the Disclosing Party desires to disclose such information to the Recipient,
subject to the terms and conditions of this Agreement.
NOW, THEREFORE, in consideration of the mutual covenants, terms, and conditions set
forth herein, the Parties agree as follows:
1. Confidential Information.. Except as set forth in Section 2 below, "Confidential
Information" means all non-public, confidential, or proprietary information disclosed before, on,
or after the Effective Date, by the Disclosing Party to the Recipient, for the furtherance of or in
any way associated with the Purpose described above, whether disclosed orally or disclosed or
accessed in written, electronic or other form or media, and whether or not marked, designated, or
otherwise identified as "confidential," including, but not limited to, any and all information that
would reasonably be considered non-public, confidential, or proprietary given the nature of the
information and the Recipient's services performed on behalf of the Disclosing Party.
2. Exclusions from Confidential Information. Except as required by applicable
federal, state, or local law or regulation, the term "Confidential Information" as used in this
Agreement shall not include information that:
(a) at the time of disclosure is, or thereafter becomes, generally available to and
known by the public other than as a result of, directly or indirectly, any act or omission by
the Recipient;
(b) at the time of disclosure is, or thereafter becomes, available to the Recipient
on a non -confidential basis from a third -party source, provided that such third party is not
and was not prohibited from disclosing such Confidential Information to the Recipient by
any legal, fiduciary, or contractual obligation;
(c) was known by or in the possession of the Recipient, as established by
documentary evidence, prior to being disclosed by or on behalf of the Disclosing Party
pursuant to this Agreement; or
(d) was or is independently developed by the Recipient, as established by
documentary evidence, without reference to or use of, in whole or in part, any of the
Disclosing Party's Confidential Information.
that:
3. Recipient Obligations. The Recipient shall:
(a) use its best efforts to protect and safeguard the confidentiality of all such
Confidential Information;
(b) not use the Disclosing Party's Confidential Information, or permit it to be
accessed or used, for any purpose other than the Purpose or any related transactions
between the Parties, or otherwise in any manner to the Disclosing Party's detriment;
(c) not use or disclose Derivative Information, or permit it to be accessed, used,
or disclosed, for any purpose other than the Purpose or any related transactions between
the Parties, or otherwise in any manner to the Disclosing Party's detriment, without
obtaining the Disclosing Party's prior written consent;
(d) to limit access to Confidential Information to only those employees of
Recipient who need to know the Confidential Information to act on Recipient's behalf in
relation to the Purpose;
(e) comply with all applicable on -site access, remote access, and related
security rules and procedures of the Disclosing Party;
(f) immediately notify the Disclosing Party of any unauthorized disclosure of
Confidential Information or other breaches of this Agreement by the Recipient or its
Representatives of which the Recipient has knowledge;
(g) fully cooperate with the Disclosing Party in any effort undertaken by the
Disclosing Party to enforce its rights related to any such unauthorized disclosure; and
"Derivative Information" means information derived by the Recipient from the
Disclosing Party's Confidential Information, which has been aggregated, anonymized, and
otherwise de -identified to the Parties' complete satisfaction so as to ensure that its use and
disclosure for the Purpose does not violate any of the Disclosing Party's legal obligations
as to its Confidential Information.
4. Recipient Representations and Warranties. The Recipient represents and warrants
(a) it will comply with all applicable federal, state, and local data protection
laws and regulations in the maintenance, disclosure, and use of all Personal Information
contained in any Confidential Information that is disclosed to the Recipient hereunder. For
purposes of this Agreement, "Personal Information" means information that:
(i) relates to an individual person; and
(ii) identifies or can be used to identify, locate, or contact that individual
alone or when combined with other personal or identifying information that is or
can be associated with that specific individual;
(b) the performance of its obligations herein does not and will not violate any
other contract or obligation to which the Recipient is a party, including covenants not to
compete and confidentiality agreements;
(c) it has implemented and will continue to maintain sufficient information
security protocols to secure and protect the confidentiality of all Confidential Information
in the Recipient's possession or control.
5. Required Disclosure. Any disclosure by the Recipient of any of the Disclosing
Party's Confidential Information pursuant to applicable federal, state, or local law, regulation or a
valid order issued by a court or governmental agency of competent jurisdiction (a "Legal Order")
shall be subject to the terms of this Section. Prior to making any such disclosure, the Recipient
shall provide the Disclosing Party with:
(a) prompt written notice of such requirement so that the Disclosing Party may
seek a protective order or other remedy; and
(b) reasonable assistance in opposing such disclosure or seeking a protective
order or other limitations on disclosure.
If, after providing such notice and assistance as required herein, the Recipient
remains subject to a Legal Order to disclose any Confidential Information, the Recipient shall
disclose no more than that portion of the Confidential Information which, on the advice of the
Recipient's legal counsel, such Legal Order specifically requires and shall use commercially
reasonable efforts to obtain assurances from the applicable court or agency that such Confidential
Information will be afforded confidential treatment.
6. Term and Termination. Unless earlier terminated in accordance with its terms, this
Agreement will commence on the Effective Date and end upon the Parties' mutual agreement that
the Purpose has been fulfilled. Notwithstanding the foregoing, effectively immediately upon
delivery of a written termination notice to the Recipient, the Disclosing Party may also terminate
this Agreement at any time for any reason. Upon termination, each Party's rights and obligations
under this Agreement shall survive for a period of five (5) years from the date that the Recipient
satisfies its obligation to the Disclosing Party under Section 7 of this Agreement.
7. Return or Destwdiolr of Confidential Information. Upon the expiration or
termination of this Agreement, or at the Disclosing Party's request at any time during the term of
this Agreement, the Recipient shall promptly return to the Disclosing Party all copies, whether in
written, electronic or other form or media, of the Disclosing Party's Confidential Information, or
destroy all such copies and certify in writing to the Disclosing Party that such Confidential
Information has been destroyed. In addition, the Recipient shall also destroy all copies of any notes
created by the Recipient and certify in writing to the Disclosing Party that such copies have been
destroyed.
8. Inderrinitication° Exceptions and Limitations. Each Party (the "Indemnifying
Party") shall indemnify, defend, and hold harmless the other Party and its officers, directors,
employees, agents, and affiliates (collectively, the "Indemnified Party") against any and all losses,
damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest, awards,
penalties, fines, costs, or expenses of whatever kind, including reasonable attorneys' fees, that are
incurred by or awarded against the Indemnified Party (collectively, "Losses"), arising out of any
third -party claim alleging:
(a) breach or non -fulfillment of this Agreement by the Indemnifying Party;
(b) any negligent or more culpable act or omission of the Indemnifying Party in
connection with the performance of its obligations under this Agreement; or
(c) any failure by the Indemnifying Party to comply with any applicable federal,
state, or local laws or regulations in the performance of its obligations under this
Agreement.
Notwithstanding anything to the contrary in this Agreement, the Indemnifying Party is not
obligated to indemnify, defend, or hold harmless the Indemnified Party against any claim (whether
direct or indirect) if such claim or corresponding Losses arise out of or result from the Indemnified
Party's: (i) negligence or more culpable act or omission (including recklessness or willful
misconduct); or (ii) bad faith failure to comply with any of the material obligations set forth in this
Agreement.
9. No Transfer of Riglits, Title or Interest. The Disclosing Party hereby retains its
entire right, title, and interest in and to all Confidential Information. Any disclosure of such
Confidential Information hereunder shall not be construed as an assignment, grant, option, license,
or other transfer of any such right, title, or interest whatsoever to the Recipient.
10. No Other Obli =atioil. The Parties agree that this Agreement does not require or
compel the Disclosing Party to disclose any Confidential Information to the Recipient.
11. Govergili _ [..aw, Jurisdiction; Compliance. This Agreement shall be governed by
and construed in accordance with the internal laws of the state of Indiana without giving effect to
any choice or conflict of law provision or rule that would cause the application of laws of any
jurisdiction other than those of the state of Indiana. Any legal suit, action, or proceeding arising
out of or related to this Agreement or the matters contemplated hereunder shall be instituted in the
federal courts of the United States or the courts of the state of Indiana in each case located in the
city of South Bend and in St. Joseph County. The Recipient shall comply with all federal, state,
and municipal laws, regulations, and standards applicable to its activities pursuant to this
Agreement.
12. Notices. All notices or communications required or permitted pursuant to the terms
of this Agreement shall be in writing and shall be delivered to such Party as follows:
To Disclosing Party: Attn: Corporation Counsel
City of South Bend
1200 County -City Building
227 W. Jefferson Blvd.
South Bend, IN 46601
To Recipient: Attn:..... m
enFocus
Studebaker Building 113
635 S. Lafayette Blvd.
South Bend, IN 46601
13. Severabilily. If any term or provision of this Agreement is invalid, illegal, or
unenforceable in any jurisdiction, such invalidity, illegality, or unenforceability shall not affect
any other term or provision of this Agreement or invalidate or render unenforceable such term or
provision in any other jurisdiction.
14. No Assi ment. Neither Party may assign its rights under this Agreement. This
Agreement is for the sole benefit of the Parties and nothing in this Agreement, express or implied,
is intended to or shall confer upon any other person or entity any legal or equitable right, benefit,
or remedy of any nature whatsoever under or by reason of this Agreement.
15. Waivers. No waiver by any Party of any of the provisions of this Agreement shall
be effective unless explicitly set forth in writing and signed by the Party so waiving. No waiver by
any Party shall operate or be construed as a waiver in respect of any failure, breach, or default not
expressly identified by such written waiver, whether of a similar or different character, and whether
occurring before or after that waiver. No failure to exercise, or delay in exercising, any right,
remedy, power, or privilege arising from this Agreement shall operate or be construed as a waiver
thereof; nor shall any single or partial exercise of any right, remedy, power, or privilege hereunder
preclude any other or further exercise thereof or the exercise of any other right, remedy, power, or
privilege.
16. entire A greetiiettt- Atiiej dtitent. This Agreement constitutes the sole and entire
agreement between the Parties with respect to the subject matter contained herein and supersedes
all prior and contemporaneous understandings, agreements, representations, and warranties, both
written and oral, with respect to such subject matter. This Agreement may only be amended,
modified, or supplemented by an agreement in writing signed by each Party hereto.
[Signature page follows.]
IN WITNESS WHEREOF, the parties have executed this Agreement to be effective as of
the Effective Date.
CITY OF SOUTH BEND
BOARD OF PUBLIC WORKS
Gary A. Gilot, President
Genevieve E. Miller, Member
Laura Sullivan, Member
;0�i WL---
Elizabeth A. Maradik, Member
°"h"k�erese .l � ora�, Member
ATTEST:
5
enFocus,
an Indiana iionprofit corporation.
Printed:
Its:
Date: "W `"
BOARD OF PUBLIC WORKS
AGENDA ITEM REVIEW REQUEST FORM
Date 12/3/19
Name Todd Skwarcan Department Fire
BPW Date 12/10/19 Phone Extension 9255
�;_ �_ le'�z�retl Prior to Submittal to Board _
BPW Attorney Attorney Name Clara McDaniels
Dept. Attorney Attorney Name Elliot Anderson
_ ........—
Purchasing
�necx the r item,,! elf �i��c��l , All Submissions
_uu _ .......
Professional Services Agreement Z Contract [:1 Proposal
El Open Market Contract ❑ Amendment/Addendum ❑ Special Purchase, QPA
❑ Bid Opening ❑ Bid Award ❑ Req. to Advertise
❑ Quote Opening
[❑ Proposal Opening
Chg. Order, No. _
F-1 Other:
] Quote Award ❑ Reject Bids/Quotes
R C/O & PCA No. ❑ PCA
E] Traffic Control ❑ Resolution
F Ease./Encroach
❑ Title
Sheet
Company or Vendor Name
enFocus
New Vendor
Yes[] If Yes, Approved by Purchasing
® No
MBE/WBE Contractor
❑ MBE Completed E-Verify Form Attached ❑ Yes
❑ WBE ❑ No
Project Name
Business Associate Agreement for NIOSH Grant Project
_. ...... ............... .
Terms of Contract
Final date of PHI return/destruction
Purpose/Description
Further to the underlying Consulting Agreement between the City and
enFoous dated December 20, 2018, the South Bend Fire Department is
requesting that the BPW approve a Business Associate Agreement
between the City and enFocus to ensure the parties' HIPAA compliance
and govern the parties' confidential data transfer, maintenance, and
disclosure responsibilities in furtherance of enFocus' support on and
project management of the SBFD's NIOSH Grant application.
For Cln ° Orders Only
Amount of ❑
Increase
Decrease �$ )
Previous Amount
$
..... _....._..�....._......
.._... .
Increase %
Current Percent of Change:
Decrease
New Amount
$
Increase %
Total Percent of Change:
..............
Decrease %
Time Extension Amount:
.............._. _..�
New Completion Date:
BUSINESS ASSOCIATE AGREEMENT
1. Preamble and Definitions.
1.1 Pursuant to the Health Insurance Portability and Accountability Act of 1996, as
amended ("HIPAA"), the City of South Bend ("Covered Entity"), an Indiana municipal
corporation, acting by and through its Board of Public Works, and enFocus ('Business
Associate"), an Indiana nonprofit corporation (each a "Party" and together, the "Parties), enter
into this Business Associate Agreeniejit ("BAA") as of J�W� 19(tl�te "Effective
Date") that addresses the HIPAA requirements with respect. to "business associates," as
defined under the privacy, security, breach notification, and enforcement rules at 45 C.F.R.
Part 160 and Part 164 ("HIPAA Rules"). A reference in this BAA to a section in the HIPAA
Rules means the section as in effect or as amended.
1.2 This BAA is intended to ensure that Business Associate will establish and
implement appropriate safeguards for the protected health information (the "PHI") (as defined
under the HIPAA Rules) that Business Associate may receive, create, maintain, use, or
disclose in connection with the functions, activities, and services that Business Associate
performs for Covered Entity. The functions, activities, and services that Business Associate
performs for Covered Entity are described, in part, in that certain Consulting Agreement dated
December 20, 2018, as amended or renewed from time to time, and any and all other
agreements between Covered Entity and Business Associate now in effect or which may be
entered into following the Effective Date of this BAA (collectively, the "Underlying
Agreements").
1.3 Pursuant to changes required under the Health Information Technology for
Economic and Clinical Health Act of 2009 (the "HITECH Act") and under the American
Recovery and Reinvestment Act of 2009 ("ARRA"), this BAA also reflects federal breach
notification requirements imposed on Business Associate when unsecured protected health
information ("Unsecured PHI") (as defined under the HIPAA Rules) is acquired by an
unauthorized party, and the expanded privacy and security provisions imposed on business
associates.
1.4 Unless the context clearly indicates otherwise, the following terms in this BAA
shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation,
Designated Record Set, disclosure, Electronic Media, Electronic Protected Health Information
(ePHI), Health Care Operations, individual, Notice of Privacy Practices, Required By Law,
Secretary, Security Incident, Subcontractor, Unsecured PHI, and use.
1.5 A reference in this BAA to the Privacy Rule means the Privacy Rule, in
conformity with the regulations at 45 C.F.R. Parts 160-164 (the "Privacy Rule") as interpreted
under applicable regulations and guidance of general application published by HHS, including
all amendments thereto for which compliance is required, as amended by the HITECH Act,
ARRA, and the HIPAA Rules.
2. Cu feral Obligations of Business Associate.
2.1 Business Associate agrees not to use or disclose PHI, other than as permitted or
required by this BAA or as Required By Law, or if such use or disclosure does not otherwise
cause a Breach of Unsecured PHI.
2.2 Business Associate agrees to use appropriate safeguards, and to comply with
Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI
other than as provided for by the BAA.
2.3 Business Associate agrees to mitigate, to the extent practicable, any harmful
effect that is known to Business Associate as a result of a use or disclosure of PHI by Business
Associate in violation of this BAA's requirements or that would otherwise cause a Breach of
Unsecured PHI.
2.4 Business Associate agrees to the following breach notification requirements:
(a) Business Associate agrees to report to Covered Entity any Breach of
Unsecured PHI not provided for by the BAA of which it becomes aware within ten (10)
calendar days of "discovery" within the meaning of the HITECH Act. Such notice shall
include the identification of each individual whose Unsecured PHI has been, or is
reasonably believed by Business Associate to have been, accessed, acquired, or
disclosed in connection with such Breach. In addition, Business Associate shall provide
any additional information reasonably requested by Covered Entity for purposes of
investigating the Breach and any other available information that Covered Entity is
required to include to the individual under 45 C.F.R. § 164.404(c) at the time of
notification or promptly thereafter as information becomes available. Business
Associate's notification of a Breach of Unsecured PHI under this Section shall comply
in all respects with each applicable provision of Section 13400 of Subtitle D (Privacy)
of ARRA, the HIPAA Rules, and related guidance issued by the Secretary or the
delegate of the Secretary from time to time.
(b) In the event of Business Associate's use or disclosure of Unsecured PHI
in violation of HIPAA, the HITECH Act, or ARRA, Business Associate bears the
burden of demonstrating that notice as required under this Section 2.4 was made,
including evidence demonstrating the necessity of any delay, or that the use or
disclosure did not constitute a Breach of Unsecured PHI.
2.5 Business Associate agrees, in accordance with 45 C.F.R. §§ 164.502(e)(1)(ii)
and 164.308(b)(2), if applicable, to require that any Subcontractors that create, receive,
maintain, or transmit PHI on behalf of the Business Associate agree to the same restrictions,
conditions, and requirements that apply to the Business Associate with respect to such
information.
2.6 Business Associate agrees to make available PHI in a Designated Record Set to
Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524.
2
(a) Business Associate agrees to comply with an individual's request to
restrict the disclosure of their personal PHI in a manner consistent with 45 C.F.R. §
164.522, except where such use, disclosure, or request is required or permitted under
applicable law.
(b) Business Associate agrees that when,requesting, using, or disclosing PHI
in accordance with 45 C.F.R. § 164.502(b)(1) that such request, use, or disclosure shall
be to the minimum extent necessary, including the use of a "limited data set" as defined
in 45 C.F.R. § 164.514(e)(2), to accomplish the intended purpose of such request, use,
or disclosure, as interpreted under related guidance issued by the Secretary from time to
time.
2.7 Business Associate agrees to make any amendments to PHI in a Designated
Record Set as directed or agreed to by the Covered Entity pursuant to 45 C.F.R. § 164.526, or
take other measures as necessary to satisfy Covered Entity's obligations under 45 C.F.R. §
164.526.
2.8 Business Associate agrees to maintain and make available the information
required to provide an accounting of disclosures to Covered Entity as necessary to satisfy
Covered Entity's obligations under 45 C.F.R. § 164.528.
2.9 Business Associate agrees to make its internal practices, books, and records,
including policies and procedures regarding PHI, relating to the use and disclosure of PHI and
Breach of any Unsecured PHI received from Covered Entity, or created or received by
Business Associate on behalf of Covered Entity, available to Covered Entity (or the Secretary)
for the purpose of Covered Entity or the Secretary determining compliance with the Privacy
Rule.
2.10 To the extent that Business Associate is to carry out one or more of Covered
Entity's obligation(s) under Subpart E of 45 C.F.R. Part 164, Business Associate agrees to
comply with the requirements of Subpart E that apply to the Covered Entity in the performance
of such obligation(s).
2.11 Business Associate agrees to account for the following disclosures:
(a) Business Associate agrees to maintain and document disclosures of PHI
and Breaches of Unsecured PHI and any information relating to the disclosure of PHI
and Breach of Unsecured PHI in a manner as would be required for Covered Entity to
respond to a request by an individual or the Secretary for an accounting of PHI
disclosures and Breaches of Unsecured PHI.
(b) Business Associate agrees to provide to Covered Entity, or to an
individual at Covered Entity's request, information collected in accordance with this
Section 2.11, to permit Covered Entity to respond to a request by an individual or the
Secretary for an accounting of PHI disclosures and Breaches of Unsecured PHI.
(c) Business Associate agrees to account for any disclosure of PHI used or
maintained as an Electronic Health Record (as defined in Section 5) ("EHR") in a
3
manner consistent with 45 C.F.R. § 164.528 and related guidance issued by the
Secretary from time to time; provided that an individual shall have the right to receive
an accounting of disclosures of EHR by the Business Associate made on behalf of the
Covered Entity only during the three years prior to the date on which the accounting is
requested from Covered Entity.
2.12 Business Associate agrees to comply with the "Prohibition on Sale of Electronic
Health Records or Protected Health Information," as provided in Section 13405(d) of Subtitle
D (Privacy) of ARRA, and the "Conditions on Certain Contacts as Part of Health Care
Operations," as provided in Section 13406 of Subtitle D (Privacy) of ARRA and related
guidance issued by the Secretary from time to time.
2.13 Business Associate acknowledges that, effective on the Effective Date of this
BAA, it shall be liable under the civil and criminal enforcement provisions set forth at 42
U.S.C. § 1320d-5 and 1320d-6, as amended, for failure to comply with any of the use and
disclosure requirements of this BAA and any guidance issued by the Secretary from time to
time with respect to such use and disclosure requirements.
Permitted Uses and Disclosures b Business Associate.
3.1 General Uses and Disclosures. Business Associate agrees to receive, create, use,
or disclose PHI only in a manner that is consistent with this BAA, the Privacy Rule, or Security
Rule (as defined in Section 5) and only in connection with providing services to Covered
Entity; provided that the use or disclosure would not violate the Privacy Rule, including 45
C.F.R. § 164.504(e), if the use or disclosure would be done by Covered Entity.
3.2 Business Associate may use or disclose PHI as Required By Law.
3.3 When using or disclosing PHI or when requesting PHI from Covered Entity,
Business Associate agrees to make reasonable efforts to limit PHI to the minimum necessary
to accomplish the intended purpose of the use, disclosure, or request.
3.4 Business Associate may not use or disclose PHI in a manner that would violate
Subpart E of 45 C.F.R. Part 164 if done by the Covered Entity.
4. Obli ations of"Covered Egity.
4.1 Covered Entity shall:
(a) Notify Business Associate of any restriction to the use or disclosure of
PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. §
164.522, to the extent that such restriction may affect Business Associate's use or
disclosure of PHI under this BAA.
(b) Notify Business Associate of any changes in or revocation of permission
by an individual to use or disclose PHI, if such change or revocation may affect Business
Associate's permitted or required uses and disclosures of PHI under this BAA.
4
(c) Provide Business Associate with the Notice of Privacy Practices that
Covered Entity produces in accordance with the Privacy Rule, and any changes or
limitations to such notice under 45 C.F.R. § 164.520, to the extent that such changes or
limitations may affect Business Associate's use or disclosure of PHI.
4.2 Covered Entity shall not request Business Associate to use or disclose PHI in
any manner that would not be permissible under the Privacy and Security Rule if done by
Covered Entity, except as provided under Section 3 of this BAA.
5. 'Compliance with Security -Rule.
5.1 Business Associate shall comply with the HIPAA Security Rule, which shall
mean the Standards for Security of Electronic Protected Health Information at 45 C.F.R. Part
160 and Subparts A and C of Part 164, as amended by ARRA and the HITECH Act. The term
"Electronic Health Record" or "EHR" as used in this BAA shall mean an electronic record of
health -related information on an individual that is created, gathered, managed, and consulted
by authorized health care clinicians and staff.
5.2 In accordance with the Security Rule, Business Associate agrees to:
(a) Implement the administrative safeguards set forth at 45 C.F.R. §
164.308, the physical safeguards set forth at 45 C.F.R. § 164.310, the technical
safeguards set forth at 45 C.F.R. § 164.312, and the policies and procedures set forth at
45 C.F.R. § 164.316, to reasonably and appropriately protect the confidentiality,
integrity, and availability of the ePHI that it creates, receives, maintains, or transmits on
behalf of Covered Entity as required by the Security Rule. Business Associate
acknowledges that, effective on the Effective Date of this BAA, (a) the foregoing
safeguards, policies, and procedures requirements shall apply to Business Associate in
the same manner that such requirements apply to Covered Entity, and (b) Business
Associate shall be liable under the civil and criminal enforcement provisions set forth
at 42 U.S.C. § 1320d-5 and 1320d-6, as amended from time to time, for failure to comply
with the safeguards, policies, and procedures requirements and any guidance issued by
the Secretary from time to time with respect to such requirements;
(b) Require that any agent, including a Subcontractor, to whom it provides
such PHI agrees to implement reasonable and appropriate safeguards to protect the PHI;
and
(c) Report to the Covered Entity any Security Incident of which it becomes
aware.
6. Indenmificatiom Exce tions and Limitations. Each Party (the "Indemnifying Party")
shall indemnify, defend, and hold harmless the other Party and its officers, directors,
employees, agents, and affiliates (collectively, the "Indemnified Party") against any and all
losses, damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest,
awards, penalties, fines, costs, or expenses of whatever kind, including reasonable attorneys'
5
fees, that are incurred by or awarded against the Indemnified Party (collectively, "Losses"),
arising out of any third -party claim alleging:
(a) breach or non -fulfillment of this BAA by the Indemnifying Party;
(b) any negligent or more culpable act or omission of the Indemnifying Party in
connection with the performance of its obligations under this BAA; or
(c) any failure by the Indemnifying Party to comply with any applicable federal,
state, or local laws or regulations in the performance of its obligations under this BAA.
Notwithstanding anything to the contrary in this BAA, the Indemnifying Party is not obligated
to indemnify, defend, or hold harmless the Indemnified Party against any claim (whether
direct or indirect) if such claim or corresponding Losses arise out of or result from the
Indemnified Party's: (i) negligence or more culpable act or omission (including recklessness
or willful misconduct); or (ii) bad faith failure to comply with any of the material obligations
set forth in this BAA. The Parties further agree that nothing in this Section 6 shall limit any
rights the Indemnified Party may have to additional remedies under the Underlying
Agreements or under applicable law.
7. Term and Termination.
7.1 This BAA shall be in effect as of the Effective Date, and shall terminate on the
earlier of the date that:
(a) Either Party terminates for cause as authorized under Section 7.2.
(b) All of the PHI received from Covered Entity, or created or received by
Business Associate on behalf of Covered Entity, is destroyed or returned to Covered
Entity. If it is not feasible to return or destroy PHI, protections are extended in
accordance with Section 7.3.
7.2 Upon either Party's knowledge of material breach by the other Party, the non -
breaching Party shall provide an opportunity for the breaching Party to cure the breach or end
the violation; or terminate the BAA. If the breaching Party does not cure the breach or end the
violation within a reasonable timeframe not to exceed thirty (30) days from the notification of
the breach, or if a material term of the BAA has been breached and a cure is not possible, the
non -breaching Party may terminate this BAA and any one or more of the Underlying
Agreements, upon written notice to the other Party.
7.3 Upon termination of this BAA for any reason, Business Associate, with respect
to PHI received from Covered Entity, or created, maintained, or received by Business
Associate on behalf of Covered Entity, shall:
(a) Retain only that PHI that is necessary for Business Associate to continue
its proper management and administration or to carry out its legal responsibilities.
2
(b) Return to Covered Entity or, if agreed to by Covered Entity, destroy the
remaining PHI that the Business Associate still maintains in any form.
(c) Continue to use appropriate safeguards and comply with Subpart C of 45
C.F.R. Part 164 with respect to ePHI to prevent use or disclosure of the PHI, other than
as provided for in this Section 7, for as long as Business Associate retains the PHI.
(d) Not use or disclose the PHI retained by Business Associate other than
for the purposes for which such PHI was retained and subject to the same conditions
which applied prior to termination.
(e) Return to Covered Entity or, if agreed to by Covered Entity, destroy the
PHI retained by Business Associate when it is no longer needed by Business Associate
for its proper management and administration or to carry out its legal responsibilities.
8. Miscellaneous Provisions.
8.1 Compliance with Law. The parties agree to take such action as is necessary to
amend this BAA to comply with the requirements of the Privacy Rule, the Security Rule,
HIPAA, ARRA, the HITECH Act, the HIPAA Rules, and any other applicable law.
8.2 Survival. The respective rights and obligations of Business Associate under
Section 6 and Section 7 of this BAA shall survive the termination of this BAA.
8.3 liateroretation. This BAA shall be interpreted in the following manner:
(a) Any ambiguity shall be resolved in favor of a meaning that permits
Covered Entity to comply with the HIPAA Rules.
(b) Any inconsistency between the BAA's provisions and the HIPAA Rules,
including all amendments, as interpreted by the HHS, a court, or another regulatory
agency with authority over the Parties, shall be interpreted according to the
interpretation of the HHS, the court, or the regulatory agency.
(c) Any provision of this BAA that differs from those required by the
HIPAA Rules, but is nonetheless permitted by the HIPAA Rules, shall be adhered to as
stated in this BAA.
8.4 As igninent. This BAA will be binding on the successors and assigns of the
Covered Entity and the Business Associate. However, this BAA may not be assigned, in whole
or in part, without the written consent of the other Party. Any attempted assignment in
violation of this provision shall be null and void.
8.5 Governing Law. Except to the extent preempted by federal law, this BAA shall
be governed by and construed in accordance with the laws of the state of Indiana.
8.6 Notice. All notices or communications required or permitted pursuant to the
terms of this BAA shall be in writing and shall be delivered to such Party as follows:
To Covered Entity: Attn: Corporation Counsel
City of South Bend
1200 County -City Building
227 W. Jefferson Blvd.
South Bend, IN 46601
To Business Associate: Attn:
enFocus
Studebaker Building 113
635 S. Lafayette Blvd.
South Bend, IN 46601
8.7 Severabilit . In the event that any court or governmental authority or agency
declares all or part of any section of this BAA to be unlawful or invalid, such unlawfulness
or invalidity shall not serve to invalidate any other section of this BAA, and in the event that
only a portion of any section is so declared to be unlawful or invalid, such unlawfulness or
invalidity shall not serve to invalidate the balance of such section.
8.8 Entire 1 treenientx Amendrrietit. This BAA constitutes the entire agreement
between the parties related to the subject matter of this BAA, except to the extent that the
Underlying Agreements impose more stringent requirements related to the use and protection
of PHI upon Business Associate. This BAA supersedes all prior negotiations, discussions,
representations, or proposals, whether oral or written. This BAA may not be modified unless
done so in writing and signed by a duly authorized representative of both parties. If any
provision of this BAA, or part thereof, is found to be invalid, the remaining provisions shall
remain in effect.
[Signature page follows.]
8
IN WITNESS WHEREOF, the parties hereto have caused this Business Associate
Agreement to be effective as of the Effective Date stated above.
CITY OF SOUTH BEND
BOARD OF PUBLIC WORDS
Gary A. Gilot, President
Genevieve E. Miller, Member
Laura ' Sullivan, ��eixnber
A
E ]:r both A. Mai .dik�.____
Member
Therese J. raaa, ember
ATTEST:
rda M.mMartin, Clerk
enFocus,
an Indiana noilprofit corporation.
By:
Printed: I _
Its:
Date: J