Loading...
HomeMy WebLinkAbout2013-426 Attorney - Setoff Clearinghouse - Legal Subscription _ Please return this copy to the Clerk to the Board's office for permanent agenda file.yG BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (this "Agreement") is entered into as of the day of 0Cfqb;, , 2013 (the "Effective Date") by and between Orange County ("Covered Entity") and the North Carolina League of Municipalities and the North Carolina Association of County Commissioners together acting as the North Carolina Local Government Debt Setoff Clearinghouse ("Business Associate") (each, a "Party" and collectively,the"Parties"). t. BACKGROUND AND PURPOSE. The Parties have entered into one or more agreements, written or oral, pursuant to which Business Associate performs functions or activities for, or provides services to, Covered Entity that involve the use and disclosure of Protected Health Information (as defined below) (the "Underlying Contracts"). Business Associate does not itself receive or maintain Protected Health Information to perform its obligations under the Underlying Contractors but does coordinate the provision of Protected Health Information from Covered Entity to a subcontractor engaged by Business Associate. Therefore, in connection with the Underlying Contracts, the Parties wish to execute this Agreement(1)to ensure Covered Entity's and Business Associate's compliance with health information privacy and security rules promulgated under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and codified at 45 C.F.R. Part 160 and Part 164, subparts A and C (the "Security Rule"), subparts A and D (the "Breach Notification Rule"), and subparts A and E (the "Privacy Rule"), all as applicable and as amended from time to time an&as clarified by guidance issued pursuant thereto, and(2)to ensure that Business Associate protects the privacy and security of Protected Health Information as further provided herein. This Agreement is intended to apply to any existing relationships between Covered Entity and Business Associate involving the exchange of Protected Health Information. 2. DEFINITIONS. Unless otherwise defined in this Agreement, all capitalized terms used in this Agreement have the meanings ascribed to them in HIPAA, the Privacy Rule, the Security Rule, and the Breach Notification Rule; provided, however, that"Protected Health Information" or "PHI" shall mean Protected Health Information limited to the information Business Associate received from, or created, maintained,transmitted,or received on behalf of, Covered Entity. 3. OBLIGATIONS OF THE PARTIES WITH RESPECT TO PHI. 3.1 Obligations of Business Associate. With regard to its use and disclosure of PHI, Business Associate agrees to: a. not use or further disclose PHI other than as permitted or required by this Agreement or as Required by Law. b. use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement. Without limiting the generality of the foregoing,Business Associate will: • implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of electronic PHI (or `EPHI") that it receives from, or creates, receives, maintains, or transmits on behalf of, Covered Entity; 1 • ensure that any agent of Business Associate, including a subcontractor, to whom Business Associate provides such EPHI agrees to implement substantially the same safeguards and other measures to protect such EPHI as set forth in this Agreement; and • report to Covered Entity any successful Security Incident of which Business Associate becomes aware. This Agreement shall serve as notice of all attempted but unsuccessful Security Incidents. C. report to Covered Entity any use or disclosure of PHI in violation of this Agreement, as well as any incident which, in Business Associate's view, compromises the security of PHI, of which Business Associate becomes aware. Business Associate shall use reasonable efforts to mitigate any deleterious effects from any use or disclosure of PHI that Business Associate reports to Covered Entity as provided herein. d. ensure that any agent, including any subcontractor, to whom Business Associate provides PHI agrees to the same restrictions and conditions on the use and disclosure of PHI that apply to Business Associate pursuant to this Agreement. e. make available, in the form, time, and manner reasonably requested by Covered Entity, any and all PHI maintained in a Designated Record set as required for Covered Entity to respond to an Individual's request for access to PHI about them in accordance with 45 C.F.R. 164.524. Business Associate will provide PHI in such electronic format as may be reasonably requested by Covered Entity to the extent that Business Associate maintains such PHI in electronic format. f. make available, in the form, time, and manner reasonably requested by Covered Entity, PHI maintained in a Designated Record Set for amendment and incorporate any such amendment as directed by Covered Entity to allow Covered Entity to comply with 45 C.F.R. 164.526. g. document any and all disclosures of PHI by Business Associate or its agents, including subcontractors, as well as any other information related to such disclosures of PHI that would be required for Covered Entity to respond to an Individual's request for an accounting of disclosures in accordance with 45 C.F.R. 164.528. h. make available, in the form, time, and manner reasonably requested by Covered Entity, any and all information documented in accordance with subsection 3.1.g. L make available to the Secretary of the U.S. Department of Health and Human Services ("HHS") any and all internal practices, books, and records of Business Associate or its agents, including subcontractors, relating to the use and disclosure of PHI, for purposes of determining Covered Entity's compliance with the Privacy Rule. j. comply with the Security Rule. k. determine the Minimum Necessary PHI to be used, disclosed, or requested in order to accomplished the intended purpose of the use, disclosure, or request, except when the use, disclosure, or request is exempt from the Minimum Necessary requirement under 45 C.F.R. 164.502(b)(2). 2 1. not, directly or indirectly, receive remuneration in exchange for PHI unless Business Associate or Covered Entity has obtained an authorization from the subject individual(s)that complies with all applicable requirements or unless an exception specified in Section 45 C.F.R. 164.502(a)(5)(ii)(B)(2)applies. m. to the extent Business Associate is to carry out any of Covered Entity's obligations under the Privacy Rule, comply with the requirements of the Privacy Rule applicable to Covered Entity in the performance of such obligations. 3.2 Permitted Uses and Disclosures of PHI by Business Associate. Except as otherwise specified in this Agreement, Business Associate may make any and all uses and disclosures of PHI necessary to perform its obligations under the Underlying Contracts. Unless otherwise limited by this Agreement, Business Associate may also: (a) use the PHI in its possession for its proper management and administration or to carry out the legal responsibilities of Business Associate; (b) disclose the PHI in its possession to a third party for the purpose of Business Associate's proper management and administration or to carry out the legal responsibilities of Business Associate, provided that the disclosures are Required by Law or that Business Associate has obtained reasonable assurances from the third party to whom PHI is to be disclosed that the PHI will be held confidentially and used and further disclosed only as Required by Law or for the purposes it was disclosed to the third party, and the third party has agreed to notify Business Associate of any instances of which it becomes aware in which the confidentiality of the information has been breached; (c)provide Data Aggregation services relating to the Health Care Operations of the Covered Entity as permitted by the Privacy Rule; and(d)de-identify the PHI in accordance with the de-identification standards set forth in 45 C.F.R. § 165.514 and use and disclose such de-identified information on Business Associate's own behalf. Business Associate may only use and disclose PHI as described above if such use and disclosure is in compliance with 45 C.F.R. 164.504(e). 3.3 Obligations of Covered Entity. Covered Entity agrees to notify Business Associate of any restrictions on uses and disclosures of PHI to which Covered Entity agrees that will impact in any manner the use and/or disclosure of that PHI by Business Associate under this Agreement. Covered Entity agrees to notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI that will impact in any manner the use and/or disclosure of that PHI by Business Associate under this Agreement. Covered Entity agrees to notify Business Associate of any changes in its Notice of Privacy Practices that will impact in any manner the use and/or disclosure of PHI by Business Associate under this Agreement. 3.4 Breach of Unsecured Protected Health Information. Business Associate shall report to Covered Entity in writing a Breach of Unsecured PHI within ten (10) days of the first day the Breach is known, or reasonably should have been known, to Business Associate. The written notice shall include, to the extent possible, the identification of each individual whose Unsecured PHI was, or is reasonably believed to have been, subject to the Breach and the circumstances of the Breach, as both are known to Business Associate at that time. To the extent possible, the description of the circumstances of the Breach shall include: (1) a brief description of what happened, including the date of the Breach and the date of the discovery of the Breach; (2) a description of the types of Unsecured PHI that were involved in the Breach; and (3) a brief description of what Business Associate is doing to investigate the Breach, to mitigate harm to individuals,and to protect against any further Breaches. Following the written notice to Covered Entity, Business Associate shall conduct such further investigation and analysis as is reasonably required, and shall promptly advise Covered Entity of additional information pertinent to the 3 Breach which Business Associate obtains. Business Associate shall cooperate with Covered Entity to determine whether the Breach requires notice to Individuals and others under the Breach Notification Rule. , 3.5 Marketing and Fundraising. Business Associate shall not use or disclose PHI to engage in any marketing or fundraising communications on behalf of Covered Entity. If the Parties wish for Business Associate to use or disclose any PHI to engage in any marketing or fundraising communications on behalf of Covered Entity, the Parties agree to amend the Underlying Contracts and this Agreement accordingly. 3.6 Effect of Chances to HIPAA the Privacy Rule Security Rule or Breach Notification Rule. To the extent that any relevant provision of HIPAA, the Privacy Rule, the Security Rule, or the Breach Notification Rule is amended in a manner that materially changes the obligations of Business Associate or Covered Entity that are embodied in the terms of this Agreement, the Parties agree to negotiate in good faith appropriate amendment(s) to this Agreement in order to give effect to such revised obligations. If the Parties cannot agree on an amendment to this Agreement, either Party may terminate this Agreement and the Underlying Contracts upon thirty (30) days written notice to the other Party or upon such lesser notice as may be required by applicable law. 4. TERMINATION. 4.1 The term of this Agreement shall commence on the Effective Date and shall terminate when all of the PHI provided by Covered Entity to Business Associate or its subcontractors, or created or received by Business Associate or its subcontractors on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such PHI in accordance with the termination provisions in Section 4.2, unless earlier terminated as provided herein. Upon either Party's knowledge of a material breach of the terms of this Agreement by the other Party, the non-breaching Party shall provide the breaching Party written notice of that breach in sufficient detail to enable the breaching Party to understand the specific nature of that breach and afford the breaching Party an opportunity to cure the breach. If the breaching Party fails to cure the breach within a reasonable time as provided by the non- breaching Party, the non-breaching Party may immediately terminate this Agreement and the Underlying Contracts. 4.2 Upon termination of the Underlying Contracts, Business Associate shall return to Covered Entity or destroy any and all PHI in the possession or control of Business Associate and its agents, including subcontractors, and retain no copies, if it is feasible to do so. If return or destruction of PHI is infeasible, Business Associate agrees to: (a) provide notification to Covered Entity of the conditions that make such return or destruction infeasible; and (b) for so long as Business Associate or its agents, including subcontractors, maintain such PHI, (i) extend all protections contained in this Agreement to the use and/or disclosure of any retained PHI by Business Associate or its agents, including subcontractors, and (ii) limit any further uses and/or disclosures of such PHI by Business Associate or its agents, including subcontractors, to the purposes that make the PHI's return or destruction infeasible. 4 5. MISCELLANEOUS. 5.1 Interpretation. The terms of this Agreement shall prevail in the case of any conflict with the terms of any Underlying Contract to the extent necessary to allow Covered Entity and Business Associate to comply with HIPAA, the Privacy Rule, the Security Rule, or the Breach Notification Rule. 5.2 Survival. The obligations imposed on Business Associate pursuant to this Agreement with respect to PHI shall survive termination of this Agreement and continue indefinitely solely with respect to PHI that Business Associate or its agents, including subcontractors, retain in accordance with Section 4.2. 5.3 No Third Partv Beneficiaries. Except as may be specifically set forth in this Agreement,nothing in this Agreement shall confer upon any person other than the Parties and their respective successors or assigns,any rights,remedies,obligations,or liabilities whatsoever. 5.4 Privileges and Protections Not Waived. Nothing herein shall be construed as waiver of applicable legal or other privileges or protections held or enjoyed by Covered Entity. 5.5 Amendment. This Agreement shall not be amended except by the mutual written agreement of the Parties. 5.6 Governing Law. To the extent not preempted by federal law, this Agreement shall be governed by and construed in accordance with the laws of the State of North Carolina, notwithstanding its conflicts of law rules. 5.7 Assignment. Neither Party may assign any of its rights or obligations under this Agreement without the prior written consent of the other Party. 5.8 Notice. Any notices required hereunder shall be given as set forth in the Underlying Contracts. If the Underlying Contracts do not include a provision for notices, then any and all notices or other communications required or permitted to be given under any of the provisions of this Agreement will be in writing and will be deemed to have been duly given (a) when personally delivered, (b)on the third business day after deposit in the U.S. mail (certified or registered mail, return receipt requested,postage prepaid), (c)on the next business day after timely delivery to an overnight courier, or (d) upon confirmation of receipt by facsimile or e-mail; in each case addressed to the Parties at the addresses set forth below (or at such other address as any Party may specify by notice to the Party given as aforesaid). If to Covered Entity: Attention: Privacy Officer (Insert address,phone,and email) Annette M. Moore 200 S. Cameron St. PO Box 8181 Hillsborough, NC 27278 919 .245.2317 amoore @orangecountync.gov or at such other address as may be furnished to Business Associate in writing; and 5 If to Business Associate: Attention: General Counsel North Carolina Association of County Commissioners 215 N. Dawson St. Raleigh,NC 27603 Phone(919)715-1430 Fax(919)719-1165 or at such other address as may be furnished to Covered Entity in writing 5.9 Counterparts. This Agreement may be executed in any number of counterparts, each of which shall be deemed an original. Facsimile or electronic copies hereof shall be deemed to be originals. Signatures on following page 6 IN WITNESS WHEREOF, each of the undersigned has caused this Agreement to be executed in its name and on its behalf by its duly authorized representative. COVERED ENTITY Orange u y v By: AA ��LL Print Name: �11\( ��1� a! �f'I Print Title: VA ✓ BUSINESS ASSOCIATE North Carolina Local Government Debt Setoff Clearinghouse By: Print Name: s:FI I i'S Hank}nS Print Title: le xec u li ye Vi reclar North Carolina League of Municipalities By: Print Name:_ )akj'+d F Print Title:{ ir'2G1 North Carolina Association of County Commissioners This instrument has been pre-audited in the manner required by the Local Government Budget and scal control Act Clarence G. Grier,Assistant Co. Manager& CFO 7