HomeMy WebLinkAbout2013-426 Attorney - Setoff Clearinghouse - Legal Subscription _ Please return this copy to the Clerk to the Board's
office for permanent agenda file.yG
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement (this "Agreement") is entered into as of the day of
0Cfqb;, , 2013 (the "Effective Date") by and between
Orange County ("Covered Entity") and the North Carolina League of
Municipalities and the North Carolina Association of County Commissioners together acting as the North
Carolina Local Government Debt Setoff Clearinghouse ("Business Associate") (each, a "Party" and
collectively,the"Parties").
t. BACKGROUND AND PURPOSE. The Parties have entered into one or more agreements,
written or oral, pursuant to which Business Associate performs functions or activities for, or provides
services to, Covered Entity that involve the use and disclosure of Protected Health Information (as
defined below) (the "Underlying Contracts"). Business Associate does not itself receive or maintain
Protected Health Information to perform its obligations under the Underlying Contractors but does
coordinate the provision of Protected Health Information from Covered Entity to a subcontractor engaged
by Business Associate. Therefore, in connection with the Underlying Contracts, the Parties wish to
execute this Agreement(1)to ensure Covered Entity's and Business Associate's compliance with health
information privacy and security rules promulgated under the Health Insurance Portability and
Accountability Act of 1996 ("HIPAA") and codified at 45 C.F.R. Part 160 and Part 164, subparts A and
C (the "Security Rule"), subparts A and D (the "Breach Notification Rule"), and subparts A and E (the
"Privacy Rule"), all as applicable and as amended from time to time an&as clarified by guidance issued
pursuant thereto, and(2)to ensure that Business Associate protects the privacy and security of Protected
Health Information as further provided herein. This Agreement is intended to apply to any existing
relationships between Covered Entity and Business Associate involving the exchange of Protected Health
Information.
2. DEFINITIONS. Unless otherwise defined in this Agreement, all capitalized terms used in this
Agreement have the meanings ascribed to them in HIPAA, the Privacy Rule, the Security Rule, and the
Breach Notification Rule; provided, however, that"Protected Health Information" or "PHI" shall mean
Protected Health Information limited to the information Business Associate received from, or created,
maintained,transmitted,or received on behalf of, Covered Entity.
3. OBLIGATIONS OF THE PARTIES WITH RESPECT TO PHI.
3.1 Obligations of Business Associate. With regard to its use and disclosure of PHI, Business
Associate agrees to:
a. not use or further disclose PHI other than as permitted or required by this Agreement or as
Required by Law.
b. use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this
Agreement. Without limiting the generality of the foregoing,Business Associate will:
• implement administrative, physical, and technical safeguards that reasonably and
appropriately protect the confidentiality, integrity, and availability of electronic PHI (or
`EPHI") that it receives from, or creates, receives, maintains, or transmits on behalf of,
Covered Entity;
1
• ensure that any agent of Business Associate, including a subcontractor, to whom
Business Associate provides such EPHI agrees to implement substantially the same
safeguards and other measures to protect such EPHI as set forth in this Agreement; and
• report to Covered Entity any successful Security Incident of which Business Associate
becomes aware. This Agreement shall serve as notice of all attempted but unsuccessful
Security Incidents.
C. report to Covered Entity any use or disclosure of PHI in violation of this Agreement, as well as
any incident which, in Business Associate's view, compromises the security of PHI, of which
Business Associate becomes aware. Business Associate shall use reasonable efforts to mitigate
any deleterious effects from any use or disclosure of PHI that Business Associate reports to
Covered Entity as provided herein.
d. ensure that any agent, including any subcontractor, to whom Business Associate provides PHI
agrees to the same restrictions and conditions on the use and disclosure of PHI that apply to
Business Associate pursuant to this Agreement.
e. make available, in the form, time, and manner reasonably requested by Covered Entity, any and
all PHI maintained in a Designated Record set as required for Covered Entity to respond to an
Individual's request for access to PHI about them in accordance with 45 C.F.R. 164.524.
Business Associate will provide PHI in such electronic format as may be reasonably requested
by Covered Entity to the extent that Business Associate maintains such PHI in electronic format.
f. make available, in the form, time, and manner reasonably requested by Covered Entity, PHI
maintained in a Designated Record Set for amendment and incorporate any such amendment as
directed by Covered Entity to allow Covered Entity to comply with 45 C.F.R. 164.526.
g. document any and all disclosures of PHI by Business Associate or its agents, including
subcontractors, as well as any other information related to such disclosures of PHI that would be
required for Covered Entity to respond to an Individual's request for an accounting of
disclosures in accordance with 45 C.F.R. 164.528.
h. make available, in the form, time, and manner reasonably requested by Covered Entity, any and
all information documented in accordance with subsection 3.1.g.
L make available to the Secretary of the U.S. Department of Health and Human Services ("HHS")
any and all internal practices, books, and records of Business Associate or its agents, including
subcontractors, relating to the use and disclosure of PHI, for purposes of determining Covered
Entity's compliance with the Privacy Rule.
j. comply with the Security Rule.
k. determine the Minimum Necessary PHI to be used, disclosed, or requested in order to
accomplished the intended purpose of the use, disclosure, or request, except when the use,
disclosure, or request is exempt from the Minimum Necessary requirement under 45 C.F.R.
164.502(b)(2).
2
1. not, directly or indirectly, receive remuneration in exchange for PHI unless Business Associate
or Covered Entity has obtained an authorization from the subject individual(s)that complies with
all applicable requirements or unless an exception specified in Section 45 C.F.R.
164.502(a)(5)(ii)(B)(2)applies.
m. to the extent Business Associate is to carry out any of Covered Entity's obligations under the
Privacy Rule, comply with the requirements of the Privacy Rule applicable to Covered Entity in
the performance of such obligations.
3.2 Permitted Uses and Disclosures of PHI by Business Associate. Except as otherwise specified in
this Agreement, Business Associate may make any and all uses and disclosures of PHI necessary
to perform its obligations under the Underlying Contracts. Unless otherwise limited by this
Agreement, Business Associate may also: (a) use the PHI in its possession for its proper
management and administration or to carry out the legal responsibilities of Business Associate;
(b) disclose the PHI in its possession to a third party for the purpose of Business Associate's
proper management and administration or to carry out the legal responsibilities of Business
Associate, provided that the disclosures are Required by Law or that Business Associate has
obtained reasonable assurances from the third party to whom PHI is to be disclosed that the PHI
will be held confidentially and used and further disclosed only as Required by Law or for the
purposes it was disclosed to the third party, and the third party has agreed to notify Business
Associate of any instances of which it becomes aware in which the confidentiality of the
information has been breached; (c)provide Data Aggregation services relating to the Health Care
Operations of the Covered Entity as permitted by the Privacy Rule; and(d)de-identify the PHI in
accordance with the de-identification standards set forth in 45 C.F.R. § 165.514 and use and
disclose such de-identified information on Business Associate's own behalf. Business Associate
may only use and disclose PHI as described above if such use and disclosure is in compliance
with 45 C.F.R. 164.504(e).
3.3 Obligations of Covered Entity. Covered Entity agrees to notify Business Associate of any
restrictions on uses and disclosures of PHI to which Covered Entity agrees that will impact in
any manner the use and/or disclosure of that PHI by Business Associate under this Agreement.
Covered Entity agrees to notify Business Associate of any changes in, or revocation of,
permission by an Individual to use or disclose PHI that will impact in any manner the use and/or
disclosure of that PHI by Business Associate under this Agreement. Covered Entity agrees to
notify Business Associate of any changes in its Notice of Privacy Practices that will impact in
any manner the use and/or disclosure of PHI by Business Associate under this Agreement.
3.4 Breach of Unsecured Protected Health Information. Business Associate shall report to Covered
Entity in writing a Breach of Unsecured PHI within ten (10) days of the first day the Breach is
known, or reasonably should have been known, to Business Associate. The written notice shall
include, to the extent possible, the identification of each individual whose Unsecured PHI was,
or is reasonably believed to have been, subject to the Breach and the circumstances of the
Breach, as both are known to Business Associate at that time. To the extent possible, the
description of the circumstances of the Breach shall include: (1) a brief description of what
happened, including the date of the Breach and the date of the discovery of the Breach; (2) a
description of the types of Unsecured PHI that were involved in the Breach; and (3) a brief
description of what Business Associate is doing to investigate the Breach, to mitigate harm to
individuals,and to protect against any further Breaches. Following the written notice to Covered
Entity, Business Associate shall conduct such further investigation and analysis as is reasonably
required, and shall promptly advise Covered Entity of additional information pertinent to the
3
Breach which Business Associate obtains. Business Associate shall cooperate with Covered
Entity to determine whether the Breach requires notice to Individuals and others under the
Breach Notification Rule. ,
3.5 Marketing and Fundraising. Business Associate shall not use or disclose PHI to engage in any
marketing or fundraising communications on behalf of Covered Entity. If the Parties wish for
Business Associate to use or disclose any PHI to engage in any marketing or fundraising
communications on behalf of Covered Entity, the Parties agree to amend the Underlying
Contracts and this Agreement accordingly.
3.6 Effect of Chances to HIPAA the Privacy Rule Security Rule or Breach Notification Rule. To
the extent that any relevant provision of HIPAA, the Privacy Rule, the Security Rule, or the
Breach Notification Rule is amended in a manner that materially changes the obligations of
Business Associate or Covered Entity that are embodied in the terms of this Agreement, the
Parties agree to negotiate in good faith appropriate amendment(s) to this Agreement in order to
give effect to such revised obligations. If the Parties cannot agree on an amendment to this
Agreement, either Party may terminate this Agreement and the Underlying Contracts upon thirty
(30) days written notice to the other Party or upon such lesser notice as may be required by
applicable law.
4. TERMINATION.
4.1 The term of this Agreement shall commence on the Effective Date and shall terminate when all
of the PHI provided by Covered Entity to Business Associate or its subcontractors, or created or
received by Business Associate or its subcontractors on behalf of Covered Entity, is destroyed or
returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are
extended to such PHI in accordance with the termination provisions in Section 4.2, unless earlier
terminated as provided herein. Upon either Party's knowledge of a material breach of the terms
of this Agreement by the other Party, the non-breaching Party shall provide the breaching Party
written notice of that breach in sufficient detail to enable the breaching Party to understand the
specific nature of that breach and afford the breaching Party an opportunity to cure the breach. If
the breaching Party fails to cure the breach within a reasonable time as provided by the non-
breaching Party, the non-breaching Party may immediately terminate this Agreement and the
Underlying Contracts.
4.2 Upon termination of the Underlying Contracts, Business Associate shall return to Covered Entity
or destroy any and all PHI in the possession or control of Business Associate and its agents,
including subcontractors, and retain no copies, if it is feasible to do so. If return or destruction of
PHI is infeasible, Business Associate agrees to: (a) provide notification to Covered Entity of the
conditions that make such return or destruction infeasible; and (b) for so long as Business
Associate or its agents, including subcontractors, maintain such PHI, (i) extend all protections
contained in this Agreement to the use and/or disclosure of any retained PHI by Business
Associate or its agents, including subcontractors, and (ii) limit any further uses and/or
disclosures of such PHI by Business Associate or its agents, including subcontractors, to the
purposes that make the PHI's return or destruction infeasible.
4
5. MISCELLANEOUS.
5.1 Interpretation. The terms of this Agreement shall prevail in the case of any conflict with the
terms of any Underlying Contract to the extent necessary to allow Covered Entity and Business
Associate to comply with HIPAA, the Privacy Rule, the Security Rule, or the Breach
Notification Rule.
5.2 Survival. The obligations imposed on Business Associate pursuant to this Agreement with
respect to PHI shall survive termination of this Agreement and continue indefinitely solely with
respect to PHI that Business Associate or its agents, including subcontractors, retain in
accordance with Section 4.2.
5.3 No Third Partv Beneficiaries. Except as may be specifically set forth in this Agreement,nothing
in this Agreement shall confer upon any person other than the Parties and their respective
successors or assigns,any rights,remedies,obligations,or liabilities whatsoever.
5.4 Privileges and Protections Not Waived. Nothing herein shall be construed as waiver of
applicable legal or other privileges or protections held or enjoyed by Covered Entity.
5.5 Amendment. This Agreement shall not be amended except by the mutual written agreement of
the Parties.
5.6 Governing Law. To the extent not preempted by federal law, this Agreement shall be governed
by and construed in accordance with the laws of the State of North Carolina, notwithstanding its
conflicts of law rules.
5.7 Assignment. Neither Party may assign any of its rights or obligations under this Agreement
without the prior written consent of the other Party.
5.8 Notice. Any notices required hereunder shall be given as set forth in the Underlying Contracts.
If the Underlying Contracts do not include a provision for notices, then any and all notices or
other communications required or permitted to be given under any of the provisions of this
Agreement will be in writing and will be deemed to have been duly given (a) when personally
delivered, (b)on the third business day after deposit in the U.S. mail (certified or registered mail,
return receipt requested,postage prepaid), (c)on the next business day after timely delivery to an
overnight courier, or (d) upon confirmation of receipt by facsimile or e-mail; in each case
addressed to the Parties at the addresses set forth below (or at such other address as any Party
may specify by notice to the Party given as aforesaid).
If to Covered Entity: Attention: Privacy Officer
(Insert address,phone,and email)
Annette M. Moore
200 S. Cameron St.
PO Box 8181
Hillsborough, NC 27278
919 .245.2317
amoore @orangecountync.gov
or at such other address as may be furnished to Business Associate in writing; and
5
If to Business Associate: Attention: General Counsel
North Carolina Association of County Commissioners
215 N. Dawson St.
Raleigh,NC 27603
Phone(919)715-1430
Fax(919)719-1165
or at such other address as may be furnished to Covered Entity in writing
5.9 Counterparts. This Agreement may be executed in any number of counterparts, each of which
shall be deemed an original. Facsimile or electronic copies hereof shall be deemed to be
originals.
Signatures on following page
6
IN WITNESS WHEREOF, each of the undersigned has caused this Agreement to be executed
in its name and on its behalf by its duly authorized representative.
COVERED ENTITY
Orange u y
v
By: AA ��LL
Print Name: �11\( ��1� a! �f'I
Print Title: VA ✓
BUSINESS ASSOCIATE
North Carolina Local Government Debt Setoff
Clearinghouse
By:
Print Name: s:FI I i'S Hank}nS
Print Title: le xec u li ye Vi reclar
North Carolina League of Municipalities
By:
Print Name:_ )akj'+d F
Print Title:{ ir'2G1
North Carolina Association of County Commissioners
This instrument has been pre-audited in the
manner required by the Local Government
Budget and scal control Act
Clarence G. Grier,Assistant Co. Manager&
CFO
7