Laserfiche WebLink
"Security Rule') without limitation any amendments or successor statutes, rules or regulations <br />to the Privacy Rule and Security Rule. <br />(d) Individual. "Individual" shall mean the person who is the subject of the PHI, and has the <br />same meaning as the term "individual" as defined by 45 C M 164.501 and shall include a <br />person who qualifies as a personal representative in accordance -with 45 C,RR, 164.502(g). <br />(e) Minimum Necessary. '`Minimum Necessary" shall mean the principle that PHI should only <br />be used and disclosed to the extent needed for the purpose of the Use or Disclosure in <br />accordance with 45 C.F.R. 164,502(b). <br />( Protected Health Information (PHI) "Protected Health Information" shall have the same <br />meaning as the term "protected health information" in 45 CFR § 160.103, limited to, but only <br />to the extent such regulatory definition includes, the information created, received, and/or <br />retained by Business Associate from or on behalf of Covered Entity. <br />(g,) Physical Safeguards. "Physical Safeguards" shall have the same meaning as the term <br />"Physical safeguards" in 45 C.F.R. § 164.304. <br />(h) Security Incident. "Security Incident" shall have the same meaning as the term "security <br />incident" in 45 C.F.R. § 164.304. <br />(i) Technical Safeguards. "Technical Safeguards" shall have the same meaning as the term <br />"technical safeguards" in 45 CY.R. § 164.304, <br />Treatment, Payment, and Health Cate Operations. "Treatment," "Payrnent" and "Health <br />Care Operations" shall have the same meanings given under 45 CER Section 164.501 <br />3.Obligations of Covered Entity <br />(a) Covered Etitity sliall provide the Business Associate with any changes in, or revocation of, <br />permission by the individual to use or disclose PHI, if such changes affect Business Associate's <br />permitted or required uses and disclosures. <br />(b) Covered Entity shall notify Business Associate of any restriction to the use or disclosure of <br />PHI that the Covered Entity has agreed to in accordance with 45 CFR §164.522, <br />(c) Covered Entity shall not request Business Associate to Use or Disclose PHI in any manner <br />that would not be permissible under 45 CFR §164.520 if done by Covered Entity, except for <br />those Uses or Disclosures for Data Aggregation or management and administrative activities of <br />Business Associate. <br />(d) Covered Entity shall use reasonable and appropriate safeguards to maintain, and ensure the <br />confidentiality, privacy and security of the PHI transmitted to or received from the Business <br />Associate, <br />