Business Associate Agreement

This Part Two supplements Part One and is intended to satisfy the business associate agreement requirements of the HIPAA Privacy, Security, and Breach Notification Rules. In the event of any conflict between Part One and Part Two regarding the use, disclosure, or protection of PHI, Part Two controls.

1. Definitions

Terms used but not otherwise defined in this Part Two (including “Breach,” “Data Aggregation,” “Designated Record Set,” “Electronic Protected Health Information,” “Individual,” “Minimum Necessary,” “Protected Health Information,” “Required By Law,” “Security Incident,” and “Unsecured PHI”) shall have the meanings given in HIPAA, including 45 C.F.R. §§ 160.103 and 164.501.

2. Permitted Uses and Disclosures of PHI

  • Business Associate may use or disclose PHI only as necessary to perform the Services described in Part One, or as otherwise required by law.

  • Business Associate may use PHI for its own proper management and administration, or to carry out its legal responsibilities, provided any disclosure for such purposes is Required by Law or Business Associate obtains reasonable assurances of confidentiality from the recipient.

  • Business Associate shall not use or disclose PHI in any manner that would violate HIPAA if done by Covered Entity, except as permitted for management, administration, or data aggregation services as expressly permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).

  • Business Associate shall make uses and disclosures of, and requests for, PHI consistent with the Minimum Necessary standard.

3. Obligations of Business Associate

  • Safeguards. Business Associate shall implement appropriate administrative, physical, and technical safeguards, including compliance with the HIPAA Security Rule with respect to electronic PHI, to prevent use or disclosure of PHI other than as provided by this Agreement.

  • Reporting. Business Associate shall report to Covered Entity, without unreasonable delay and in no event later than [5] business days after discovery, any use or disclosure of PHI not permitted by this Agreement, any Security Incident, and any Breach of Unsecured PHI, as required by 45 C.F.R. § 164.410.

  • Subcontractors. Business Associate shall ensure that any subcontractor, including independent contractors, that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees, in writing, to the same restrictions and conditions on PHI that apply to Business Associate under this Agreement.

  • Access. Business Associate shall make PHI in a Designated Record Set available to Covered Entity within [10] business days of a request, to enable Covered Entity to respond to an Individual’s access request under 45 C.F.R. § 164.524.

  • Amendment. Business Associate shall make PHI available for amendment and incorporate any amendments to PHI as directed by Covered Entity under 45 C.F.R. § 164.526.

  • Accounting of Disclosures. Business Associate shall document disclosures of PHI and make information available to Covered Entity as necessary to respond to an Individual’s request for an accounting of disclosures under 45 C.F.R. § 164.528.

  • Availability to Government. Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity’s compliance with HIPAA.

  • Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement.

4. Permitted Uses and Disclosures by Covered Entity

Covered Entity shall notify Business Associate of any limitation(s) on the use or disclosure of PHI that Covered Entity has agreed to (e.g., restrictions requested by an Individual) to the extent such limitation may affect Business Associate’s use or disclosure of PHI. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity itself.

5. Term and Termination of Business Associate Obligations

  • Term. This Part Two is effective as of the Effective Date and terminates when all PHI provided by, or created or received on behalf of, Covered Entity is destroyed or returned, or, if return or destruction is infeasible, protections are extended in accordance with Section 5(c) below.

  • Termination for Cause. Covered Entity may terminate this Agreement immediately if it determines Business Associate has violated a material term of this Part Two and Business Associate does not cure the violation within a reasonable time specified by Covered Entity.

  • Return or Destruction of PHI. Upon termination of this Agreement for any reason, Business Associate shall return or destroy all PHI received from, or created or received on behalf of, Covered Entity that Business Associate still maintains, and retain no copies. If return or destruction is not feasible, Business Associate shall extend the protections of this Part Two to the PHI for as long as it maintains it, and limit further uses and disclosures to those purposes that make return or destruction infeasible.

6. Miscellaneous

  • Regulatory References. A reference in this Agreement to a section in HIPAA means the section as in effect or as amended.

  • Amendment. The Parties agree to amend this Agreement as necessary for Covered Entity to comply with HIPAA and its implementing regulations.

  • Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with HIPAA.

  • No Third-Party Beneficiaries. Nothing in this Agreement confers any rights on any person other than the Parties and their respective successors and permitted assigns.