HomeMy WebLinkAbout2013-356 DSS - UNC Hospitals To provide Income Maintenance Worker and Su[ervisor to UNC Hospital $49,587 ,®s s
STATE OF NORTH CAROLINA UNCH#92
COUNTY OF ORANGE
AGREEMENT BETWEEN THE UNIVERSITY OF NORTH CAROLINA HOSPITALS
AND ORANGE COUNTY,NORTH CAROLINA
THIS AGREEMENT, made and entered into this the 1 st day of July, 2013 by and
between Orange County ("County") by and through the Orange County Department of Social
Services ("OCDSS") and The University of North Carolina Hospitals, ("UNCH") in Orange
County,North Carolina.
WITNESSETH:
WHEREAS, the parties have agreed with each other that the County will provide certain
services for The University of North Carolina Hospitals in connection with the Orange County
Department of Social Services(hereinafter referred to as OCDSS),Medicaid Program; and
WHEREAS, the UNCH has agreed to pay certain compensation for said service and the
parties desire to execute this contract to delineate their understanding of this agreement;
NOW, THEREFORE,the parties hereby agree as follows:
1. Term. The term of this Agreement shall be from July 1,2013 to June 30, 2014.
2. The County agrees to the following:
a. Scope of Services: The County agrees to provide UNCH the services of one full
time Income Maintenance Caseworker and one part-time supervisor providing up
to 10 hours of supervision a week.
i. The Income Maintenance Caseworker shall receive all potential medical
assistance applications originating at UNCH. Specifically, the Income
Maintenance Caseworker shall perform intake and processing functions
on MPW and MIC applications for Orange County and intake functions
only for all other applications, consisting of the following: conducting
interviews that initiate an application; obtaining signatures; obtaining
documentation available at the time of interview; forwarding applications
to the appropriate county for processing; meeting verification
requirements, processing and data entry timeframes, and sending
appropriate notices timely in all processing functions.
ii. The Income Maintenance Caseworker shall be assisted by UNCH staff in
obtaining information and documentation required to complete the
application process.
iii. The Income Maintenance Caseworker shall work cooperatively with
UNCH staff and the staff of any Department of Social Services to make
appropriate referrals of patients and family members with problems not
related to eligibility determination.
iv. The Income Maintenance Worker is an employee of the County and will
be directly supervised by and accountable to OCDSS. Due to the nature
of this agreement and the working relationship with UNCH, it is
necessary that close contact be kept with UNCH administration and
certain members of the hospital medical staff. In recognition of this
factor, UNCH will name a staff member to act as liaison between the
OCDSS, the Income Maintenance Caseworker, the departments of
UNCH and other staff personnel. Assignment of work to the Income
Maintenance Caseworker and coordination of sick, vacation, and other
leave will be the joint responsibility of this UNCH staff member and the
OCDSS supervisor.
V. The part-time Supervisor is an employee of Orange County and will
provide supervision and oversight of the Income Maintenance Worker.
b. The County will provide other agreed upon supportive services to UNCH without
additional charge, include continuing program training of the Income
Maintenance Caseworker and consultation with other counties in the catchment
area about applications for pre-and post-discharge patients.
C. The County will provide a monthly invoice to UNCH for the County's share of
the costs for the services of the income maintenance worker and for the part-time
supervisor. The county share of these positions is approximately 50 percent of
the cost of salary and benefits. Salary and benefits for the income maintenance
caseworker and the supervisor include: base salary according to the Orange
County pay plan; FICA taxes; local government retirement;vacation, sick, petty,
or other leave under approved county plan; paid holidays as observed by county;
county paid insurance(health, dental, and life).
3. UNCH agrees to the following:
a. Payment. UNCH will reimburse the County within fifteen(15)days of receipt of
monthly billings for the following:
i. The county share of the salary, benefits, and the indirect costs for both
the income maintenance caseworker and the part-time supervisor. The
reimbursement of the county's share of these positions is approximately
50 percent of the total cost of salary and benefits for these two positions.
Salary and benefits for the income maintenance caseworker and the
supervisor include: base salary according to the Orange County pay
plan; FICA taxes; local government retirement; vacation, sick, petty, or
other leave under approved county plan; paid holidays as observed by
county; county paid insurance(health, dental,and life).
ii. Administrative overhead and indirect costs associated with the income
maintenance worker and supervisor positions. This includes all other
supportive services provided by OCDSS or Orange County.
iii. The total cost of this contract is $49,587.
b. To participate in the interviewing and selection process utilized by OCDSS for
the hiring of the income maintenance caseworker and supervisor covered by this
agreement, in accordance with County policy and procedures.
C. To provide the following supportive services to OCDSS: office space; parking
space; office equipment; clerical support; and telephone service.
4. The Parties agree to the following:
a. If at any time UNCH determines that the Income Maintenance Caseworker's or
Supervisor's performance or professional interactions are inadequate or
inappropriate, UNCH may request that OCDSS initiate appropriate action to
correct that employee's deficiencies. Any disciplinary action taken shall be in
compliance with the Orange County Personnel Ordinance and the State Personnel
Act. Upon request UNCH shall provide sufficient documentation to support any
such action.
b. To abide by the conditions set forth in attached Business Associate Agreement,
which is attached hereto and incorporated by reference.
5. Termination. This Agreement or its renewals may be terminated at any time without
penalty by either party provided that written notice of such termination is furnished to the
other party at least 60 days prior to termination. In the event of such termination any
payment shall be prorated to the date of termination.
6. Amendments or Modification. This Agreement shall not be altered, amended or
modified, except by an agreement in writing executed by the duly authorized officials of
both parties.
6. Subcontract or Assignment. The County shall not sub-contract out any of the services
provided for in this Agreement or make any assignment of this Agreement (including
rights to payments)without the prior written consent of the UNCH.
7. Relationship of the Parties. The County is an independent contractor. Neither the
County nor any employee of the County shall be deemed to be an officer, employee or
agent of UNCH. OCDSS personnel shall not be employees of, or have any contractual
relationship with the UNCH.
8. Intent to be Bound. The parties have read this Agreement, including the Business
Associates Agreement attached, and agree to be bound by all of its terms, and further
agree that the documents constitute the complete and exclusive statement of the
Agreement between the parties.
16. Entire Understanding. The Agreement contains the entire understanding of the parties
and shall not be altered, amended or modified, except by an agreement in writing
executed by the duly authorized officials of both parties.
17. Governing Law. The laws of North Carolina shall govern the validity and interpretation
of the provisions,terms and conditions of this Agreement.
18. Notices. Any notice required by this Agreement shall be in writing and delivered by
certified or registered mail,return receipt requested to the following:
Orange County Department of Social Services UNCH
Nancy Coston Nicole Driver
Director HCS Program Manager
113 Mayo Street UNC Health Care
P.O. Box 8181 101 Manning Drive
Hillsborough,NC 27278 Chapel Hill,NC 27514
Phone: (919)245-2800 Phone: (919)966-5581
IN WITNESS WHEREOF, the parties hereto have caused this contract to be signed by its duly
authorized officials.
FOR AND ON BEHALF OF: FOR AND ON BEHALF OF:
ORANGE COUNTY,NORTH CAROLINA THE UNIVERSITY OF NORTH
CAROL A HOSPITALS
7*d I
Frank . Cli on,Jr., ounty Manager Chris El Rngton, Exe live Vice President
and Chief Financial Officer.
DATE: DATE:
This insu ujilpVt has been approved as to technical content.
$- f`I-�
Nancy Coston, ocial Services Director Date
This instrument has been pre-audited in the manner required by the Local Government Budget
and Fiscal Control Aft. A, Z743
Clarence 6; Grier,Director Date
Orange County Financial Services Director
This ' tru ent has been approved as to form and legal sufficiency.
C?LS
Annette M. Moore, Staff Attorney Date
Office of the County Attorney
BUSINESS ASSOCIATE AGREEMENT
This Agreement is made effective the 1St day of July 2013, by and between the University of
North Carolina Hospitals, hereinafter referred to as "Covered Entity", and Orange County by and
through the Orange County Department of Social Services, hereinafter referred to as "Business
Associate", (individually, a "Party" and collectively, the "Parties"). This Agreement supersedes any
previously executed Business Associate Agreement between the parties.
WITNESSETH:
WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and
Accountability Act of 1996, Public Law 104-191, as modified by the Health Information Technology for
Economic and Clinical Health Act, known collectively as "the Administrative Simplification provisions,"
direct the Department of Health and Human Services to develop standards to protect the security,
confidentiality and integrity of health information; and
WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and
Human Services has issued regulations at 45 CFR Parts 160 and 164, as the same may be amended
from time to time (the "HIPAA Security and Privacy Rule"); and
WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby
Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangement,
Business Associate may be considered a "business associate" of Covered Entity as defined in the
HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is described on Exhibit
A attached hereto and made a part hereof, and is hereby referred to as the "Arrangement Agreement");
and
WHEREAS, Business Associate may have access to Protected Health Information (as defined
below) in fulfilling its responsibilities under such arrangement;
THEREFORE, in consideration of the Parties' continuing obligations under the Arrangement
Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable
consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the
provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy
Rule and to protect the interests of both Parties.
I. DEFINITIONS
Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the
definitions set forth in the HIPAA Security and Privacy Rule. In the event of an inconsistency between
the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as
amended, the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are
different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted
by the HIPAA Security and Privacy Rule, the provisions of this Agreement shall control.
The term "Protected Health Information" means individually identifiable health information including,
without limitation, all information, data, documentation, and materials, including without limitation,
demographic, medical and financial information, that relates to the past, present, or future physical or
mental health or condition of an individual; the provision of health care to an individual; or the past,
present, or future payment for the provision of health care to an individual; and that identifies the
individual or with respect to which there is a reasonable basis to believe the information can be used to
identify the individual. "Protected Health Information" includes without limitation "Electronic Protected
Health Information" as defined below.
The term "Electronic Protected Health Information means Protected Health Information that is
transmitted by Electronic Media (as defined in the HIPAA Security and Privacy Rule) or maintained in
Electronic Media.
Business Associate acknowledges and agrees that all Protected Health Information that is created or
received by Covered Entity and disclosed or made available in any form, including paper record, oral
communication, audio recording, and electronic display by Covered Entity or its operating units to
Business Associate or is created or received by Business Associate on Covered Entity's behalf shall be
subject to this Agreement.
II. PERMITTED USES AND DISCLOSURES
(a) Business Associate may use or disclose Protected Health Information only as permitted
or required by this Agreement or as required by law. Except as specifically set forth herein, Business
Associate may not use or disclose Protected Health Information in a manner that would violate the
HIPAA Security and Privacy Rule if such use or disclosure were done by Covered Entity. Specifically,
Business Associate may use or disclose Protected Health Information (1) for meeting its obligations as
set forth in any agreements between the Parties evidencing their business relationship, including the
Arrangement Agreement, or (2) as required by applicable law, rule or regulation, or by an accrediting or
credentialing organization to whom Covered Entity is required to disclose such information, or (3) as
otherwise permitted under this Agreement, the Arrangement Agreement (if consistent with this
Agreement and the HIPAA Security and Privacy Rule), or the HIPAA Security and Privacy Rule, or (4)
as would be permitted by the HIPAA Security and Privacy Rule as if such use or disclosure were made
by Covered Entity.
(b) Business Associate may de-identify Protected Health Information only at the specific
direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health
Information except at the direction of Covered Entity and in compliance with the requirements of the
HIPAA Security and Privacy Rule.
(c) Notwithstanding the prohibitions set forth in this Agreement,
(i) Business Associate may use Protected Health Information for the proper
management and administration of Business Associate or to carry out the legal
responsibilities of Business Associate;
(ii) Business Associate may disclose Protected Health Information for the proper
management and administration of Business Associate or to carry out the legal
responsibilities of Business Associate, provided that as to any such disclosure, the
following requirements are met:
(A) The disclosure is required by law; or
(B) Business Associate obtains reasonable assurances from the person
to whom the information is disclosed that the information will remain confidential
and will be used or further disclosed only as required by law or for the purpose
for which it was disclosed to the person, and the person notifies Business
Associate of any instances of which it is aware in which the confidentiality of the
information has been breached;
(iii) Business Associate may provide data aggregation services relating to the health
care operations of Covered Entity pursuant to any agreements between the Parties
evidencing their business relationship. For purposes of this Agreement, data
aggregation means the combining of Protected Health Information by Business
Associate with the protected health information received by Business Associate in its
capacity as a business associate of another covered entity, to permit data analyses that
relate to the health care operations of the respective covered entities.
III. CONFIDENTIALITY AND SECURITY REQUIREMENTS
(a) Business Associate agrees not to use or disclose Protected Health Information other
than as permitted or required by this Agreement or as required by law. To the extent Business
Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule,
Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule
as if such use or disclosure were made by Covered Entity. Covered Entity will not request Business
Associate to use or disclose Protected Health Information in any manner that would not be permissible
under the HIPAA Security and Privacy Rule if done by Covered Entity, except as otherwise provided
herein. Business Associate agrees to comply with.Covered Entity's policies regarding the minimum
necessary use or disclosure of Protected Health Information.
(b) Business Associate agrees to provide HIPAA training to all of its personnel who service
Covered Entity's account or who otherwise will have access to Covered Entity's Protected Health
Information.
(c) At termination of this Agreement, the Arrangement Agreement (or any similar
documentation of the business relationship of the Parties), or upon request of Covered Entity,
whichever occurs first, if feasible, Business Associate will return (in a manner or process approved by
the Covered Entity) or destroy all Protected Health Information received from Covered Entity, or
created, maintained or received by Business Associate on behalf of Covered Entity, that Business
Associate still maintains in any form and retain no copies of such information. If such return or
destruction is not feasible, Business Associate will (i) retain only that Protected Health Information
necessary under the circumstances; (ii) return or destroy the remaining Protected Health Information
that the Business Associate still maintains in any form; (iii) extend the protections of this Agreement to
the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that
make the return or destruction of the Protected Health Information not feasible; and (v) return or destroy
the retained Protected Health Information when it is no longer needed by Business Associate. This
paragraph shall survive the termination of this Agreement and shall apply to Protected Health
Information created, maintained, or received by Business Associate and any of its subcontractors.
(d) Business Associate agrees to ensure that its agents, including any subcontractors, that
create, receive, maintain or transmit Protected Health Information on behalf of Business Associate
agree to the same (or greater) restrictions and conditions that apply to Business Associate with respect
to such information, and agree to implement reasonable and appropriate safeguards to protect any of
such information that is Electronic Protected Health Information. Business Associate agrees to enter
into written agreements with any subcontractors in accordance with the requirements of the HIPAA
Security and Privacy Rule. In addition, Business Associate agrees to take reasonable steps to ensure
that its employees' actions or omissions do not cause Business Associate to breach the terms of this
Agreement.
(e) Business Associate will implement appropriate safeguards to prevent use or disclosure
of Protected Health Information other than as permitted in this Agreement. Business Associate will
implement administrative, physical, and technical safeguards that reasonably and appropriately protect
the confidentiality, integrity, and availability of any Electronic Protected Health Information that it
creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA
Security and Privacy Rule.
(f) To the extent applicable, Business Associate will comply with (i) Covered Entity's Notice
of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual's
permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the
use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to
agree.
(g) Business Associate will make its internal practices, books and records available to the
Secretary of the Department of Health and Human Services for purposes of determining compliance
with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply
with any investigations and compliance reviews, permit access to information, and cooperate with any
complaints, as required by law. Without unreasonable delay and, in any event, no more than 48 hours
of receipt of the request or notification, Business Associate will notify Covered Entity in writing of any
request by any governmental entity, or its designee, to review Business Associate's compliance with
law or this BAA, to pursue a complaint, or to conduct an audit or assessment of any kind.
(h) Business Associate shall report to Covered Entity (see Exhibit B) any use or disclosure
of Protected Health Information that is not in compliance with the terms of this Agreement, as well as
any Security Incident and any actual or suspected Breach, of which it becomes aware, without
unreasonable delay, and in no event later than forty-eight (48) hours of such discovery. For purposes
of this Agreement, "Security Incident" means the attempted or successful unauthorized access, use,
disclosure, modification, or destruction of information or interference with system operations in an
information system. Such notification shall contain the elements required by 45 C.F.R. 164.410. In
addition, Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is
known to Business Associate of a use or disclosure of Protected Health Information by Business
Associate in violation of the requirements of this Agreement, as well as to provide complete cooperation
to Covered Entity should Covered Entity elect to review or investigate such noncompliance or Security
Incident. Business Associate shall cooperate in Covered Entity's breach analysis and/or risk
assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the
event that Covered Entity determines that any third parties must be notified of a Breach, provided that
Business Associate shall not provide any such notification except at the direction of Covered Entity.
Business Associate shall indemnify and hold harmless Covered Entity for any injury or damages arising
from any noncompliance with this Agreement or any Security Incident attributable to the negligence of
Business Associate, including the failure to execute the terms of this Agreement.
0) Business Associate shall permit Covered Entity, in its discretion, to conduct an audit of
Business Associate's compliance with this BAA, HIPAA, and HITECH. Such audit may consist of an
onsite visit, a series of inquiries that require written responses, or both. Business Associate shall
promptly and completely respond to Covered Entity's requests for information in support of the audit,
which shall not be conducted more than once annually except in cases of an actual or reasonably
suspected Security Incident or reasonably suspected noncompliance with this BAA, HIPAA or
HITECH. Each Party shall bear its own costs associated with the audit.
IV. AVAILABILITY OF PHI
(a) Business Associate agrees to make available Protected Health Information in a
Designated Record Set to Covered Entity to the extent and in the manner required by Section 164.524
of the HIPAA Security and Privacy Rule.
(b) Business Associate agrees to make available Protected Health Information in a
Designated Record Set for amendment and to incorporate any amendments to Protected Health
Information in accordance with the requirements of Section 164.526 of the HIPAA Security and Privacy
Rule and at the direction of Covered Entity.
(c) Business Associate agrees to maintain and make available the information required to
provide an accounting of disclosures, as required by Section 164.528 of the HIPAA Security and
Privacy Rule. Business Associate will comply with Covered Entity's policy regarding accounting of
disclosures, a copy of which is available at http://www.med.unc.edu/security/hipaa/documents/dl3.pdf.
(d) In the event an Individual makes a request under this Section IV directly to Business
Associate, Business Associate will notify Covered Entity of such request within three (3) business days
and shall cooperate with, and act only at the direction of, Covered Entity in responding to such request.
V. TERMINATION
This Agreement shall be effective as of the date first set forth above and shall terminate upon the
earlier of (i) the termination of all agreements between the parties, and (ii) the termination by Covered
Entity for cause as provided herein. Notwithstanding anything in this Agreement to the contrary,
Covered Entity shall have the right to terminate this Agreement and the Arrangement Agreement
immediately if Covered Entity determines that Business Associate has violated any material term of this
Agreement. If Covered Entity reasonably believes that Business Associate will violate a material term
of this Agreement and, where practicable, Covered Entity gives written notice to Business Associate of
such belief within a reasonable time after forming such belief, and Business Associate fails to provide
adequate written assurances to Covered Entity that it will not breach the cited term of this Agreement
within a reasonable period of time given the specific circumstances, but in any event, before the
threatened breach is to occur, then Covered Entity shall have the right to terminate this Agreement and
the Arrangement Agreement immediately.
Vl. MISCELLANEOUS
Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this
Agreement do not intend to create any rights in any third parties. The obligations of Business Associate
under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the
Arrangement Agreement and/or the business relationship of the parties, and shall continue to bind
Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein.
This Agreement may be amended or modified only in a writing signed by the Parties. No Party may
assign its respective rights and obligations under this Agreement without the prior written consent of the
other Party. None of the provisions of this Agreement are intended to create, nor will they be deemed to
create any relationship between the Parties other than that of independent parties contracting with each
other solely for the purposes of effecting the provisions of this Agreement and any other agreements
between the Parties evidencing their business relationship. This Agreement will be governed by the
laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation
hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing
or other obligation, or shall prohibit enforcement of any obligation, on any other occasion.
The parties agree that, in the event that any documentation of the arrangement pursuant to which
Business Associate provides services to Covered Entity contains provisions relating to the use or
disclosure of Protected Health Information that are more restrictive than the provisions of this
Agreement, the more restrictive provisions will control. The provisions of this Agreement are intended
to establish the minimum requirements regarding Business Associate's use and disclosure of Protected
Health Information.
In the event that any provision of this Agreement is held by a court of competent jurisdiction to be
invalid or unenforceable, the remainder of the provisions of this Agreement will remain in full force and
effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails
to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall
notify the other party in writing. For a period of up to thirty days, the parties shall address in good faith
such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after
such thirty-day period, a party believes in good faith that the Agreement fails to comply with the HIPAA
Security and Privacy Rule, then either party has the right to terminate upon written notice to the other
party.
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year
written above.
CO }QED ENTITY: BUSINESS ASSOCIATE:
By: Ch r" Ellingto/President By:
Title: Executive V and CFO Title: Z7
EXHIBIT A
ARRANGEMENT AGREEMENT
EXHIBIT B
CONTACT INFORMATION
To report to Covered Entity any use or disclosure of Protected Health Information not in compliance
with the terms of this Agreement that might be considered a privacy breach, Business Associate should
contact the Privacy Officer at the applicable entity.
To report to Covered Entity any Security Incident (as defined in the Agreement), Business Associate
should contact Lacy Farrell, or the Security Officer at The University of North Carolina Health Care
System.