Laserfiche WebLink
(e) Business Associate agrees to make available to the Secretary (i) Business .Associate's internal <br />practices, books and records relating to the Use and Disclosure of PHI for the purposes of <br />determining Covered Entity's compliance with the Privacy Rule; and (u) Business Associate's <br />policies, procedures and documentation relating to the safeguards described herein, for the <br />purposes of determining Covered Entity's compliance with the Security Rule. <br />(0 To the extent the Business As is to carry out one or more of Cornered Entity's <br />obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E <br />that apply to the Covered Entity in the performance of such obligation(s). <br />(g) Business Associate shall have procedures in place for mitigating any injurious or harmful <br />effect from the Use or Disclosure of PHI in a manner contrary to this Appendix. <br />(h)'Business Associate agrees that it will; <br />(1) Implement Administrative Safeguards, Physical Safeguards, and Technical Safeguards <br />that reasonably and appropriately protect the confidentiality, integrity, and availability of <br />EPHI; <br />(2) Ensure that any agent, including a subcontractor, to whom it provides such <br />information agrees to implement reasonable and appropriate safeguards to protect it; <br />and <br />(3) Report to Covered Entity any use or disclosure of protected health information not <br />provided for by the Agreement of which it becomes aware, including breaches of <br />unsecured protected health information as required by 45 CFR §164.410 and any <br />Security Incident of which it becomes aware. <br />S. Permitted Uses and Disclosures by Business Associate <br />(a) Minimum Necessary. Business Associate and its agents and subcontractors shall only <br />request, Use and Disclose the minimum amount of PHI necessary to accomplish the purpose <br />of the request, Use or Disclosure. <br />(b) limits on Use and Disclosure of Information. Business Associate hereby agrees that the <br />PHI shall not be further Used or Disclosed other than as permitted or required by this <br />Appendix, or as Required by Law. <br />(c) Stated Purpose for Use and Disclosure. Except as otherwise limited in this Agreement, <br />Business Associate may Use and Disclose PHI to perform the functions, activities, obligations <br />and services required to be performed as requested by the Covered Entity. Subject to section <br />5(b) above, Business Associate is permitted to disclose PHI received from Covered Entity for <br />purposes of Tieatment, Payment, and Health Care Operations relating to members. <br />3 <br />