HomeMy WebLinkAbout2009-052 DSS - UNC Hospitals Madicaid Program- . ~_>
STATE OF NORTH CAROLINA
COUNTY OF ORANGE
AGREEMENT BETWEEN
THE UNIVERSITY OF NORTH CAROLINA HOSPITALS
AND
ORANGE COUNTY, NORTH CAROLINA
Contract# 68-1001
LTNC Hospital
THIS AGREEMENT, made and entered into this the 1st day of July, 2009 by and
between ORANGE COUNTY (hereinafter referred to as the COUNTY) and THE
UNIVERSITY OF NORTH CAROLINA HOSPITALS, (hereinafter referred to as
UNCH) Orange County, North Carolina.
WITNESSETH:
WHEREAS, the parties have agreed with each other that the County will provide
certain services for The University of North Carolina Hospitals in connection with the
Orange County Department of Social Services (hereinafter referred to as OCDSS),
Medicaid Program; and
WHEREAS, the UNCH has agreed to pay certain compensation for said service
and the parties desire to execute this contract to delineate their understanding of this
agreement;
NOW, THEREFORE, the parties hereby agree as follows:
1. Orange County agrees to make available to UNCH the services of one full time
Income Maintenance Caseworker and one part-time supervisor providing up to 15 hours
of supervision a week.
2. UNCH agrees to reimburse the County within 15 days of receipt of monthly
billings for the county share of the salary, benefits, and the indirect costs to which the
parties have agreed are involved in maintaining one Social Services Income Maintenance
Caseworker at UNCH. UNCH also agrees to reimburse the county for the costs of a part-
time supervisor. The county share of these positions is approximately 50 percent. Salary
and benefits for the Income Maintenance Caseworker and the supervisor include: base
salary according to the Orange County pay plan; FICA taxes; local government
retirement; vacation, sick, petty, or other leave under approved county plan; paid holidays
as observed by county; county paid insurance (health, dental, and life). UNCH will also
pay half of the administrative overhead and indirect costs associated with these positions.
This includes all other supportive services provided by OCDSS or Orange County. The
total cost of this contract is $55,562. -
3. Other supportive services provided by OCDSS without additional charge to
UNCH include continuing program training of the Income Maintenance Caseworker and
consultation with other counties in the catchment area about applications for pre-and
post-discharge patients.
4. Other supportive services provided by LTNCH without charge to OCDSS
include: office space; parking space; office equipment; clerical support; and telephone
service.
5. The Income Maintenance Caseworker shall receive all potential medical
assistance applications originating at UNCH. Specifically, the Income Maintenance
Caseworker shall perform intake and processing functions on MPW and MIC
applications for Orange County and intake functions only for all other applications,
consisting of the following: conducting interviews that initiate an application; obtaining
signatures; obtaining documentation available at the time of interview; forwarding
applications to the appropriate county for processing; meeting verification requirements,
processing and data entry timeframes, and sending appropriate notices timely in all
processing functions.
6. The Income Maintenance Caseworker shall be assisted by iJNCH staff in
obtaining information and documentation required to complete the application process.
7. The Social Services Income Maintenance Caseworker shall work cooperatively
with LTNCH staff and the staff of any Department of Social Services to make appropriate
referrals of patients and family members., with problems not related to eligibility
determination.
8. As an employee of the County, the Income Maintenance Caseworker shall be
directly supervised by and accountable to OCDSS. Due to the nature of this agreement
and the working relationship with LTNCH, it is necessary that close contact be kept with
LTNCH administration and certain members of the hospital medical staff. In recognition
of this factor, LJNCH will name a staff member to act as liaison between the OCDSS, the
Income Maintenance Caseworker, the departments of L1NCH and other staff personnel.
Assignment of work to the Income Maintenance Caseworker and coordination of sick,
vacation, and other leave will be the joint responsibility of this LJNCH staff member and
the OCDSS supervisor.
9. UNCH shall participate in the interviewing and selection process utilized by
OCDSS for the hiring of the Income Maintenance Caseworker covered by this agreement,
in accordance with County policy and procedures.
10. Both the County and UNCH agree and understand that if at any time UNCH
determines that the Income Maintenance Caseworker's performance or professional
interactions are inadequate or inappropriate, LJNCH may request that OCDSS initiate
appropriate action to correct that employee's deficiencies, or to dismiss that employee if
indicated. Any disciplinary action shall be pursued in compliance with the Orange
County Personnel ordinance and the State Personnel Act and UNCH shall provide
sufficient documentation to support any such action.
11. Both the County and LTNCH agree and understand the conditions outlined in
the Business Associate Agreement.
12. This Agreement shall be effective from July 1, 2009 to June 30, 2010.
13. This Agreement shall be reviewed at least annually, prior to June 1st and may
be terminated by either party upon 60 days written notice.
14. The Agreement contains the entire understanding of the parties and shall not
be altered, amended or modified, except by an agreement in writing executed by the duly
authorized officials of both parties.
IN WITNESS WHEREOF, the parties hereto have caused this contract to be
signed by its duly authorized officials.
FOR AND ON BEHALF OF:
FOR AND ON BEHALF OF:
ORANGE COUNTY, NORTH CAROLINA THE UNIVERSITY OF NORTH
~~~
W~-~.t--~ ~_
nJ
Chair, Orange County Board of
Commissioners
CAROLINA HOSPITALS
Todd L. Peterson
Executive Vice President and
Chief Operations Officer
DATE: O
Attest:
Clerk o e range County
Board of Commissioners
DATE: ~~a-~~Of
This instrument has been preaudited in the manner required by the Local Government
Budget and Fiscal Control Act.
Ga mp s, range County Fin nc Offi er
BUSINESS ASSOCIATE AGREEMENT
This Agreement is made effective the 1St day of July, 2009, by and between the University of
North Carolina Hospitals, hereinafter referred to as "Covered Entity", and Orange County, hereinafter
referred to as "Business Associate", (individually, a "Party" and collectively, the "Parties"). This
Agreement supersedes any previously executed Business Associate Agreement between the parties.
WITNESSETH:
WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and
Accountability Act of 1996, Public Law 104-191, known as "the Administrative Simplification provisions,"
direct the Department of Health and Human Services to develop standards to protect the security,
confidentiality and integrity of health information; and
WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and
Human Services has issued regulations modifying 45 CFR Parts 160 and 164 (the "HIPAA Security and
Privacy Rule"); and ~-
WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby
Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangement,
Business Associate may be considered a "business associate" of Covered Entity as defined in the
HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is described on Exhibit
A attached hereto and made a part hereof, and is hereby referred to as the "Arrangement Agreement");
and
WHEREAS, Business Associate may have access to Protected Health Information (as defined
below) in fulfilling its responsibilities under such arrangement;
THEREFORE, in consideration of the Parties' continuing obligations under the Arrangement
Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable
consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the
provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy
Rule and to protect the interests of both Parties.
DEFINITIONS
Except as otherwise defined herein, any and all capitalized terms in this Section shall have the
definitions set forth in the HIPAA Security and Privacy Rule. In the event of an inconsistency between
the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as
amended, the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are
different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted
by the HIPAA Security and Privacy Rule, the provisions of this Agreement shall control.
The term "Protected Health Information" means individually identifiable health information including,
without limitation, all information, data, documentation, and materials, including without limitation,
demographic, medical and financial information, that relates to the past, present, or future physical or
mental health or condition of an individual; the provision of health care to an individual; or the past,
present, or future payment for the provision of health care to an individual; and that identifies the
individual or with respect to which there is a reasonable basis to believe the information can be used to
identify the individual. "Protected Health Information" includes without limitation "Electronic Protected
Health Information" as defined below.
The term "Electronic Protected Health Information" means Protected Health Information which is
transmitted by Electronic Media (as defined in the HIPAA Security and Privacy Rule) or maintained in
Electronic Media.
Business Associate acknowledges and agrees,that all Protected Health Information that is created or
received by Covered Entity and disclosed or made available in any form, including paper record, oral
communication, audio recording, and electronic display by Covered Entity or its operating units to
Business Associate or is created or received by Business Associate on Covered Entity's behalf shall be
subject to this Agreement.
CONFIDENTIALITY AND SECURITY REQUIREMENTS
(a) Business Associate agrees:
(i) to use or disclose any Protected Health Information solely: (1) for meeting
its obligations as set forth in any agreements between the Parties evidencing their
business relationship, or (2) as required by applicable law, rule or regulation, or by
accrediting or credentialing organization to whom Covered Entity is required to disclose
such information or as otherwise permitted under this Agreement, the Arrangement
Agreement (if consistent with this Agreement and the HIPAA Security and Privacy Rule),
or the HIPAA Security and Privacy Rule, and (3) as would be permitted by the HIPAA
Security and Privacy Rule if such use or disclosure were made by Covered Entity;
(ii) to account for certain disclosures of Protected Health Information as
required by Section 164.528 of the HIPAA Security and Privacy Rule. A copy of
Covered Entity's policy regarding accounting of disclosures is available at
http://www.med.unc.edu/security/hipaa/documents/d13.pdf ;
(iii) to provide appropriate HIPAA training to its personnel within thirty days of
the date of this agreement as follows: (1) general HIPAA training for all of Business
Associate's personnel, and (2) Business Associate will compare the UNC HCS policies
and procedures outlined in the training materials to the general HIPAA training provided
by the Business Associate to its personnel, and, if there are material differences, will
train all of its personnel who service the UNC HCS account on those different
policies/procedures. (Business Associate may obtain a copy of the UNC HCS training
materials at http://www.unchealthcare.orq/site/hipaa Internet);
(iv) at termination of this Agreement, the Arrangement Agreement (or any
similar documentation of the business relationship of the Parties), or upon request of
Covered Entity, whichever occurs first, if feasible, Business Associate will return or
destroy all Protected Health Information received from or created or received by
Business Associate on behalf of Covered Entity that Business Associate still maintains in
any form and retain no copies of such information, or if such return or destruction is not
feasible, Business Associate will extend the protections of this Agreement to the
information and limit further uses and disclosures to those purposes that make the return
or destruction of the information not feasible; and
(v) to ensure that its agents, including a subcontractor, to whom it provides
Protected Health Information received from or created by Business Associate on behalf
of Covered Entity, agrees to the same restrictions and conditions that apply to Business
Associate with respect to such information, and agrees to implement reasonable and
appropriate safeguards to protect any of such information which is Electronic Protected
Health Information. In addition, Business Associate agrees to take reasonable steps to
ensure that its employees' actions or omissions do not cause Business Associate to
breach the terms of this Agreement.
(b) Notwithstanding the prohibitions set forth in this Agreement, Business Associate may
use and disclose Protected Health Information as follows:
(i) if necessary, for the proper management and administration of Business
Associate or to carry out the legal responsibilities of Business Associate, provided that
as to any such disclosure, the following requirements are met:
(A) the disclosure is required by law; or
(B) Business Associate obtains reasonable assurances from the
person to whom the information is disclosed that it will be held confidentially and
used or further disclosed only as required by law or for the purpose for which it
was disclosed to the person, and the person notifies Business Associate of any
instances of which it is aware in which the confidentiality of the information has
been breached;
(ii) for data aggregation services, if to be provided by Business Associate for
the health care operations of Covered Entity pursuant to any agreements between the
Parties evidencing their business relationship. For purposes of this Agreement, data
aggregation services means the combining of Protected Health Information by Business
Associate with the protected health information received by Business Associate in its
capacity as a business associate of another covered entity, to permit data analyses that
relate to the health care operations of the respective covered entities.
(c) Business Associate will implement appropriate safeguards to prevent use or disclosure
of Protected Health Information other than as permitted in this Agreement. Business Associate will
implement administrative, physical, and technical safeguards that reasonably and appropriately protect
the confidentiality, integrity, and availability of any Electronic Protected Health Information that it
creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA
Security and Privacy Rule.
(d) The Secretary of Health and Human Services shall have the right to audit Business
Associate's records and practices related to use and disclosure of Protected Health Information to
ensure Covered Entity's compliance with the terms of the HIPAA Security and Privacy Rule.
(e) Business Associate shall report to Covered Entity (see Exhibit B) any use or disclosure
of Protected Health Information which is not in compliance with the terms of this Agreement, as well as
any Security Incident, of which it becomes aware within forty-eight (48) hours of such discovery. For
purposes of this Agreement, "Security Incident" means the attempted or successful unauthorized
access, use, disclosure, modification, or destruction of information or interference with system
operations in an information system. In addition, Business Associate agrees to mitigate, to the extent
practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected
Health Information by Business Associate in violation of the requirements of this Agreement, as well as
to provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate
such noncompliance or Security Incident. Business Associate shall indemnify and hold harmless
Covered Entity for any injury or damages arising from any noncompliance or Security Incident
attributable to the negligence of Business Associate, including the failure to execute the terms of this
Agreement.
III. AVAILABILITY OF PHI
Business Associate agrees to make available Protected Health Information to the extent and in the
manner required by Section 164.524 of the HIPAA Security and Privacy Rule. Business Associate
agrees to make Protected Health Information available for amendment and incorporate any
amendments to Protected Health Information in accordance with the requirements of Section 164.526
of the HIPAA Security and Privacy Rule. In addition, Business Associate agrees to make Protected
Health Information available for purposes of accounting of disclosures, as required by Section 164.528
of the HIPAA Security and Privacy Rule (see Section II(a)(ii) above).
IV. TERMINATION
Notwithstanding anything in this Agreement to the contrary, Covered Entity shall have the right to
terminate this Agreement and the Arrangement Agreement immediately if Covered Entity determines
that Business Associate has violated any material term of this Agreement. If Covered Entity reasonably
believes that Business Associate will violate a material term of this Agreement and, where practicable,
Covered Entity gives written notice to Business Associate of such belief within a reasonable time after
forming such belief, and Business Associate fails to provide adequate written assurances to Covered
Entity that it will not breach the cited term of this Agreement within a reasonable period of time given
the specific circumstances, but in any event, before the threatened breach is to occur, then Covered
Entity shall have the right to terminate this Agreement and the Arrangement Agreement immediately.
V. MISCELLANEOUS
Except as expressly stated herein or the HIPAA Security and Privacy Rule, the parties to this
Agreement do not intend to create any rights iri~ any third parties. The obligations of Business Associate
under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the
Arrangement Agreement and/or the business relationship of the parties, and shall continue to bind
Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein.
This Agreement may be amended or modified only in a writing signed by the Parties. No Party may
assign its respective rights and obligations under this Agreement without the prior written consent of the
other Party. None of the provisions of this Agreement are intended to create, nor will they be deemed to
create any relationship between the Parties other than that of independent parties contracting with each
other solely for the purposes of effecting the provisions of this Agreement and any other agreements
between the Parties evidencing their business relationship. This Agreement will be governed by the
laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation
hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing
or other obligation, or shall prohibit enforcement of any obligation, on any other occasion.
The parties agree that, in the event that any documentation of the arrangement pursuant to which
Business Associate provides services to Covered Entity contains provisions relating to the use or
disclosure of Protected Health Information which are more restrictive than the provisions of this
Agreement, the provisions of the more restrictive documentation will control. The provisions of this
Agreement are intended to establish the minimum requirements regarding Business Associate's use
and disclosure of Protected Health Information.
In the event that any provision of this Agreement is held by a court of competent jurisdiction to be
invalid or unenforceable, the remainder of the provisions of this Agreement will remain in full force and
effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails
to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall
notify the other party in writing, For a period of up to thirty days, the parties shall address in good faith
such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after
such thirty-day period, the Agreement fails to comply with the HIPAA Security and Privacy Rule, then
either party has the right to terminate upon written notice to the other party.
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year
written above.
COVERED ENTITY:
By:
Title: CUTI E VP & inn
BUSINESS ASSOCIATE:
By:
Title:
EXHIBIT A
ARRANGEMENT AGREEMENT
EXHIBIT B
CONTACT INFORMATION
To report to Covered Entity any use or disclosure of Protected Health Information which is not in
compliance with the terms of this Agreement which might be considered a privacy breach,
Business Associate should contact the Privacy Officer at the applicable entity; to report to
Covered Entity any Security Incident (as defined in the Agreement), Business Associate should
contact the Security Officer at the applicable entity:
The University of North Carolina at Chapel Hill
The University of North Carolina Hospitals
The University of North Carolina Physicians & Associates
Rex Healthcare, Inc. (including Rex Hospital, Inc.)
If Business Associate is uncertain about the proper entity to contact, it should call the University
of North Carolina Health Care System Hotline number: (919) 843-2233.