Loading...
HomeMy WebLinkAbout2017-640-E HR - Flexible Benefits Administrators, Inc. (FBA) to authorize FBA to work directly with Delta Dental DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ("Agreement") is made effective the 13th day of July, 2017, by and between Orange County Government ("Covered Entity"), and Flexible Benefits Administrators, Inc., ("Business Associate"). Covered Entity and Business Associate may be referred herein individually as a "Party" or collectively as the "Parties". This Agreement supersedes any previously executed Business Associate Agreement between the Parties. WITNESSETH: WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), Public Law 104-191, as modified by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), Public Law 111-5, known as "the Administrative Simplification provisions," direct the Department of Health and Human Services to develop standards to protect the security, confidentiality and integrity of health information; and WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human Services ("Secretary") has issued regulations modifying the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from time to time (the"HIPAA Security and Privacy Rule"); and WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangements, Business Associate may be considered a"Business Associate"of Covered Entity as defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred to as the"Service Agreement(s)"); and WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in fulfilling its responsibilities under such arrangement; THEREFORE, in consideration of the Parties' continuing obligations under the Service Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect the interests of both Parties. I. DEFINITIONS (a) Service Agreement. Agreement(s) for services affected by this HIPAA Business Associate Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby incorporated by reference, and which shall be taken and considered as a part of this document the same as if fully set out herein: Vendor Authorization Agreement (b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule, 45 CFR Parts 160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule,the provisions of this Agreement shall control. 1 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 (c) Electronic Protected Health Information. Protected Health Information that is transmitted by or maintained in Electronic Media(as defined in the HIPAA Security and Privacy Rule). (d) Protected Health Information. "Protected Health Information" shall have the same meaning as the term in 45 CFR § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity and includes without limitation `Electronic Protected Health Information." Business Associate acknowledges and agrees that all Protected Health Information that is created or received by Covered Entity and disclosed or made available in any form,including paper record, oral communication, audio recording, and electronic display by Covered Entity or its operating units to Business Associate or is created or received by Business Associate on Covered Entity's behalf shall be subject to this Agreement. (e) Required by Law. "Required by Law" shall have the same meaning as the term in 45 CFR § 164.103. II. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE (a) Use and Disclosure. Business Associate agrees to fully comply with the requirements under the HIPPA Security and Privacy Rule applicable to Business Associates and not to use or disclose Protected Health Information other than as permitted or required by this Agreement, the Service Agreement or as Required by Law. To the extent Business Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. Business Associate agrees to comply with Covered Entity's policies regarding the minimum necessary use or disclosure of Protected Health Information. (b) Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of Protected Health Information other than as provided for by this Service Agreement(s), this Agreement or as Required by Law. This includes the implementation physical, technical and administrative safeguards to prevent use or disclosure of Protected Health Information other than as permitted in this Agreement or Required by Law and reasonably and appropriately protect the confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with the HIPPA Security and Privacy Rule, including, but not limited to, its policies, procedures, records of training and sanctions of members in its workforce. (c) Assurances. Business Associate agrees to provide Covered Entity with written assurances that any Protected Health Information placed on any type of mobile media, including, but by no means limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with guidance issued by the Secretary. (d) Agents and Subcontractors. Business Associate shall require any agents, including any subcontractors, to whom it provides Protected Health Information from Covered Entity that is created, received, maintained or transmitted on behalf of Business Associate to agree by written contract with Business Associate to the same (or greater) restrictions, conditions and requirements that apply to Business Associate with respect to such information, and to agree to implement reasonable and appropriate safeguards to protect any of such information that is Electronic Protected Health Information. In addition, Business Associate agrees to take reasonable steps to ensure that its employees' actions or omissions do not cause Business Associate to breach the terms of this Agreement. (e) Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health 2 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 Information by Business Associate in violation of the requirements of this Agreement, as well as to provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate such noncompliance or Security Incident. Business Associate shall cooperate in Covered Entity's breach analysis and/or risk assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the event that Covered Entity determines that any third parties must be notified of a Breach,provided that Business Associate shall not provide any such notification except at the direction of Covered Entity. (f) Breach Reporting. Business Associate shall report in writing to Covered Entity's Privacy Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance with the terms of this Agreement, as well as any Security Incident and any actual or suspected Breach, of which it becomes aware, without unreasonable delay, and in no event later than forty-eight (48) hours of such discovery. For purposes of this Agreement, "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Such notification shall contain the elements required by 45 C.F.R. § 164.410. (g) Compliance. To the extent applicable, Business Associate will comply with (i) Covered Entity's Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual's permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to agree. (h) Government Access. Business Associate will make its internal practices, books and records available to the Secretary of the Department of Health and Human Services for purposes of determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations and compliance reviews,permit access to information, and cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event, no more than 48 hours of receipt of the request or notification, Business Associate will notify Covered Entity in writing of any request by any governmental entity, or its designee, to review Business assessment of any kind. (i) Electronic Transactions. If Business Associate conducts any Standard Transactions for or on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic Transaction Rule. (j) Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an audit of Business Associate's compliance with this Agreement, HIPAA, and HITECH. Such audit may consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate shall promptly and completely respond to Covered Entity's requests for information in support of the audit, which shall not be conducted more than once annually except in cases of an actual or reasonably suspected Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or HITECH. Each Party shall bear its own costs associated with the audit. (k) Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies and Procedures to protect any patient information that may be breached by the Business Associate to the extent applicable under the Federal Trade Commission's Red Flag Rules. (1) HITECH Compliance. Business Associate shall: A. Not receive, directly or indirectly, any impermissible remuneration in exchange for Protected Health Information or Electronic Protected Health Information, except as permitted by HITECH § 13405(d) or the HTPPA Regulations; 3 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 B. Comply with the marketing and other restrictions applicable to Business Associates contained in HITECH § 13406 and the HIPPA Regulations; C. To the extent required under HITECH § 13404, fully comply with the applicable requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected Health Information; D. To the extent required under HITECH § 13401, fully comply with 45 CFR §§ 164.308, 164.310, 164.312, and 164.316; E. To the extent required under HITECH §§13401 and 13404, comply with the additional privacy and security requirements that apply to Covered Entities in the same manner and to the same extent as Covered Entity is required to do so; and F. To the extent required under the HIPPA Regulations, comply with the privacy and security requirements that apply to Business Associates. (m) State Privacy Laws. Business Associate shall understand and comply with state privacy laws to the extent that such privacy laws are not preempted by HIPPA or HITECH. III. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE (a) Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities or services for, or on behalf of, Covered Entity described in the Service Agreement,provided that such use or disclosure would not violate the HIPPA Security and Privacy Rule if it were made by Covered Entity or would not violate the Covered Entities minimum necessary policies. (b) Other Uses of Protected Health Information. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information within its workforce for the proper management and administration of Business Associate not to include Marketing or Commercial Use and to carry out the legal responsibilities of Business Associate; and (c) Third Party Confidentiality. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that if Business Associate discloses any Protected Health Information to a third party for such purpose, the Business Associate shall enter into a written agreement with such third party requiring the following: A. Disclosure only as Required by Law; or B. Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality, integrity, and or availability of the Protected Health Information has been breached immediately upon becoming aware. (d) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity pursuant to any agreements between the Parties evidencing their business relationship as permitted by 45 CFR§ 164.504(e)(2)(i)(B). (e) Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business Associate to share Protected Health Information with Business Associate's affiliates or contractors except 4 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s) identified in Section 1(a) of this Agreement. (f) Covered Entity Authorization for Additional Uses. Any use of Protected Health Information by Business Associate, its affiliate or Contractor, other than those purposes of this Agreement, shall require express written authorization by the Covered Entity, and a Business Associate Agreement or amendment as necessary. Activities which are prohibited include, but are not limited to, Marketing, as defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed by Covered Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal or state laws. (g) Business Associate may de-identify Protected Health Information only at the specific direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health Information except at the direction of Covered Entity and in compliance with the requirements of the HIPAA Security and Privacy Rule. IV. AVAILABILITY OF PHI (a) Access to Protected Health Information. Business Associate agrees, in the event the Business Associate maintains protected health information in a Designated Record Set,to make available, within ten (10) days of a request by Covered Entity in a time and manner designated by Covered Entity, Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security and Privacy Rule. (b) Amendments to Protected Health Information. In the event that the Business Associate maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make any amendment(s) to Protected Health Information in a designated record set that the Covered Entity directs or agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of an individual, within ten(10) days of receipt of a request from Covered Entity and in the time and manner designated by Covered Entity. (c) Accounting of Disclosures. Business Associate agrees to maintain and make available the information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the HIPAA Security and Privacy Rule. Business Associate will comply with Covered Entity's policy regarding accounting of disclosures. (d) Document Disclosures. In the event an Individual makes a request under this Section of the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such request within three (3) business days and shall cooperate with, and act only at the direction of Covered Entity in responding to such request. V. OBLIGATIONS OF COVERED ENTITY (a) Notice of Privacy Practices. Covered Entity shall provide Business Associate with the notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as any changes to that notice. (b) Notice of Changes in Individual's Access or Protected Health Information. Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, is such changes affect Business Associate's permitted or required uses. 5 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 (c) Notice of Restriction in Individual's Access to Protected Health Information. Covered Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such restriction may affect Business Associate's use of Protected Health Information. VI. PERMISSABLE REQUESTS BY COVERED ENTITY Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy or Security Rule. VII. TERMINATION (a) Term. This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the termination by Covered Entity for cause as provided herein. (b) Termination for Cause. Notwithstanding anything in this Agreement to the contrary, Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately if Covered Entity determines that Business Associate has or will violated any material term of this Agreement. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall provide an opportunity for Business Associate to cure the breach or end the violation. Covered Entity may terminate this Agreement if Business Associate does not cure the breach or end the violation within the time period specified by Covered Entity. If termination, cure or end of the violation is not feasible, Covered Entity may report the violation to the Secretary. (c) Obligation of Business Associate Upon Termination. At termination of this Agreement, the Service Agreement(or any similar documentation of the business relationship of the Parties), or upon request of Covered Entity,whichever occurs first, Business Associate, shall: A. if feasible, return(in a manner or process approved by the Covered Entity) or destroy all Protected Health Information, regardless of form, including but not limited to paper or electronic format, received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity. Business Associate shall retain no copies of the Protected Health Information. This provision shall also apply to Protected Health Information and other confidential information in the possession of sub-contractors or agents of Business Associate. B. If such return or destruction is not feasible, Business Associate shall (i) retain only that Protected Health Information necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities; (ii) return or destroy the remaining Protected Health Information that the Business Associate still maintains in any form; (iii) extend the protections of this Agreement to the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or destruction of the Protected Health Information not feasible; and (v) return or destroy the retained Protected Health Information when it is no longer needed by Business Associate. (d) Survival. This paragraph shall survive the termination of this Agreement and shall apply to Protected Health Information created, maintained, or received by Business Associate and any of its subcontractors. VIII. MISCELLANEOUS 6 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 (a) Indemnification. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims, losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur by reason of Business Associate's breach of or failure to perform any the obligations pursuant to this Agreement, including but not limited to any injury or damages arising from any noncompliance with this Agreement or any Security Incident attributable to the negligence of Business Associate, including failure to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, employees, contractors and agents, against all costs and expenses, including but not limited to, reasonable legal expenses, which are incurred by or on behalf of the Breaching Party in connection with the defense of such claims. (b) Disclaimer. Covered Entity makes no warranty or representation that compliance by Business Associate with this Agreement, HIPAA, HITECH, or the HIPAA Regulations will be adequate or satisfactory for Business Associate's own purposes. Business Associate is solely responsible for all decisions made by Business Associate regarding the safeguarding of Protected Health Information. (c) Assistance in Litigation or Administrative Proceedings. Business Associate shall make itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the performance of its obligations under this Agreement, available to Covered Entity, at no cost to Covered Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being commenced against Covered Entity, its directors, officers or employees based upon a claimed violation of HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy, except where Business Associate or its subcontractor, employee or agent is named adverse party. (d) Survival. The obligations of Business Associate under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business relationship of the parties, and shall continue to bind Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein. (e) Ownership of Information. Covered Entity holds all right, title, and interest in and to the Protected Health Information and Business Associate does not hold and will not acquire by virtue of this Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or to the PHI or any portion thereof. (f) Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that the breach, or threatened breach,by it of any provision of this Agreement may cause Covered Entity to be irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore, Business Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek injunctive relief to prevent Business Associate from commencing or continuing any action constituting such breach without having to post a bond or other security and without having to prove the inadequacy of any other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other remedy available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties. (g) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPAA Regulations. In addition, this Agreement may be amended or modified by the Parties only in writing. (h) Assignment. No Party may assign its respective rights and obligations under this Agreement without the prior written consent of the other Party. 7 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 (i) Independent Contractor. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any relationship between the Parties other than that of independent parties contracting with each other solely for the purposes of effecting the provisions of this Agreement and any other agreements between the Parties evidencing their business relationship. This Agreement will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion. (j) Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH or the HIPAA Regulations means the section as it currently is in effect or as amended. (k) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event that any documentation of the arrangement pursuant to which Business Associate provides services to Covered Entity contains provisions relating to the use or disclosure of Protected Health Information that are more restrictive than the provisions of this Agreement, the more restrictive provisions will control. The provisions of this Agreement are intended to establish the minimum requirements regarding Business Associate's use and disclosure of Protected Health Information. (1) Severability. In the event any part or parts of this Agreement are held to be unenforceable, the remainder of this Agreement will continue in effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to (30) thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty-day period, a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to terminate upon written notice to the other party. (m) Notices and Communications. All instructions, notices, consents, demands, or other communications required or contemplated by this Agreement shall be in writing and shall be delivered to the Party at the address below: For Covered Entity: For Business Associate Brenda Bartholomew Orange County Human Resources Department 200 South Cameron Street Hillsborough,NC 27278 (n) Strict compliance. No failure by any Party to insist upon strict compliance with any terms or provisions of this Agreement, to exercise any option, to enforce any right, or to seek any remedy upon any default of any other Party shall affect, or constitute a waiver of, any Party's right to insist upon such strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that default or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at variance with any provisions of this Agreement shall affect, or constitute a waiver of, any Party's right to demand strict compliance with all provisions of this Agreement. (o) Governing Law. This Agreement shall be governed and construed in accordance with the laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County, North Carolina for the purposes of litigation resulting from disagreements of the Parties for purposes of this Agreement and the Service Agreement(s). (p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract 8 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 with governmental units. E-Verify is a Federal program operated by the United States Department of Homeland Security and other federal agencies, or any successor or equivalent program used to verify the work authorization of newly hired employees pursuant to federal law. Where applicable, failure to maintain compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General Statutes shall constitute breach of this Agreement. If applicable, by executing this Agreement, Business Associate affirms that they are in compliance with Article 3 of Chapter 64 if the North Carolina General Statutes. (q) Iran Divestment Certification. By executing this Agreement, Business Associate certifies that Business Associate has not been identified, and has not utilized the services of any agent or subcontractor, on the list created by the State Treasurer pursuant to G.S. 147-86.58. IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above. CO - . ITY: BU I ,.SS,OCIATE: G. (AA,1.61A, fVaWIA,gA.#), IN l botA,ut, NutAwtt,V'St.t,ti By' -53E1 D4c8... By.'--003799413755E477.. Title: vice President Title: County Manager 9 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 EXHIBIT A COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with the terms of this Agreement that might be considered a privacy breach, Business Associate should contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident(as defined in the Agreement), Business Associate should contact Brenda Bartholomew, or the Security Officer at The Orange County Health Department. 10 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ("Agreement") is made effective the 13th day of July, 2017, by and between Orange County Government ("Covered Entity"), and Delta Dental of North Carolina, including its affiliates and/or subsidiaries, ("Business Associate"). Covered Entity and Business Associate may be referred herein individually as a "Party" or collectively as the "Parties". This Agreement supersedes any previously executed Business Associate Agreement between the Parties. WITNESSETH: WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), Public Law 104-191, as modified by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), Public Law 111-5, known as "the Administrative Simplification provisions," direct the Department of Health and Human Services to develop standards to protect the security, confidentiality and integrity of health information; and WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human Services ("Secretary") has issued regulations modifying the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from time to time (the"HIPAA Security and Privacy Rule"); and WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangements, Business Associate may be considered a"Business Associate" of Covered Entity as defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred to as the"Service Agreement(s)"); and WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in fulfilling its responsibilities under such arrangement; THEREFORE, in consideration of the Parties' continuing obligations under the Service Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect the interests of both Parties. I. DEFINITIONS (a) Service Agreement. Agreement(s) for services affected by this HIPAA Business Associate Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby incorporated by reference, and which shall be taken and considered as a part of this document the same as if fully set out herein: Vendor Authorization Agreement (b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule, 45 CFR Parts 160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule,the provisions of this Agreement shall control. 1 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 (c) Electronic Protected Health Information. Protected Health Information that is transmitted by or maintained in Electronic Media(as defined in the HIPAA Security and Privacy Rule). (d) Protected Health Information. "Protected Health Information" shall have the same meaning as the term in 45 CFR § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity and includes without limitation `Electronic Protected Health Information." Business Associate acknowledges and agrees that all Protected Health Information that is created or received by Covered Entity and disclosed or made available in any form,including paper record, oral communication, audio recording, and electronic display by Covered Entity or its operating units to Business Associate or is created or received by Business Associate on Covered Entity's behalf shall be subject to this Agreement. (e) Required by Law. "Required by Law" shall have the same meaning as the term in 45 CFR § 164.103. II. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE (a) Use and Disclosure. Business Associate agrees to fully comply with the requirements under the HIPPA Security and Privacy Rule applicable to Business Associates and not to use or disclose Protected Health Information other than as permitted or required by this Agreement, the Service Agreement or as Required by Law. To the extent Business Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. Business Associate agrees to comply with Covered Entity's policies regarding the minimum necessary use or disclosure of Protected Health Information. (b) Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of Protected Health Information other than as provided for by this Service Agreement(s), this Agreement or as Required by Law. This includes the implementation physical, technical and administrative safeguards to prevent use or disclosure of Protected Health Information other than as permitted in this Agreement or Required by Law and reasonably and appropriately protect the confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with the HIPPA Security and Privacy Rule, including, but not limited to, its policies, procedures, records of training and sanctions of members in its workforce. (c) Assurances. Business Associate agrees to provide Covered Entity with written assurances that any Protected Health Information placed on any type of mobile media, including, but by no means limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with guidance issued by the Secretary. (d) Agents and Subcontractors. Business Associate shall require any agents, including any subcontractors, to whom it provides Protected Health Information from Covered Entity that is created, received, maintained or transmitted on behalf of Business Associate to agree by written contract with Business Associate to the same (or greater) restrictions, conditions and requirements that apply to Business Associate with respect to such information, and to agree to implement reasonable and appropriate safeguards to protect any of such information that is Electronic Protected Health Information. In addition, Business Associate agrees to take reasonable steps to ensure that its employees' actions or omissions do not cause Business Associate to breach the terms of this Agreement. (e) Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health 2 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 Information by Business Associate in violation of the requirements of this Agreement, as well as to provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate such noncompliance or Security Incident. Business Associate shall cooperate in Covered Entity's breach analysis and/or risk assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the event that Covered Entity determines that any third parties must be notified of a Breach,provided that Business Associate shall not provide any such notification except at the direction of Covered Entity. (f) Breach Reporting. Business Associate shall report in writing to Covered Entity's Privacy Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance with the terms of this Agreement, as well as any Security Incident and any actual Breach, of which it becomes aware, without unreasonable delay, and in no event later than forty-eight (48) hours of such discovery. For purposes of this Agreement, "Security Incident" means the unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Such notification shall contain the elements required by 45 C.F.R. § 164.410. (g) Compliance. To the extent applicable, Business Associate will comply with (i) Covered Entity's Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual's permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to agree. (h) Government Access. Business Associate will make its internal practices, books and records available to the Secretary of the Department of Health and Human Services for purposes of determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations and compliance reviews,permit access to information, and cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event, no more than 48 hours of receipt of the request or notification, Business Associate will notify Covered Entity in writing of any request by any governmental entity, or its designee, to review Business assessment of any kind. (i) Electronic Transactions. If Business Associate conducts any Standard Transactions for or on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic Transaction Rule. (j) Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an audit of Business Associate's compliance with this Agreement, HIPAA, and HITECH. Such audit may consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate shall promptly and completely respond to Covered Entity's requests for information in support of the audit, which shall not be conducted more than once annually except in cases of an actual or reasonably suspected Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or HITECH. Each Party shall bear its own costs associated with the audit. (k) Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies and Procedures to protect any patient information that may be breached by the Business Associate to the extent applicable under the Federal Trade Commission's Red Flag Rules. (1) HITECH Compliance. Business Associate shall: A. Not receive, directly or indirectly, any impermissible remuneration in exchange for Protected Health Information or Electronic Protected Health Information, except as permitted by HITECH § 13405(d) or the HIPPA Regulations; B. Comply with the marketing and other restrictions applicable to Business Associates contained in HITECH § 13406 and the HIPPA Regulations; 3 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 C. To the extent required under HITECH § 13404, fully comply with the applicable requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected Health Information; D. To the extent required under HITECH § 13401, fully comply with 45 CFR §§ 164.308, 164.310, 164.312, and 164.316; E. To the extent required under HITECH §§13401 and 13404, comply with the additional privacy and security requirements that apply to Covered Entities in the same manner and to the same extent as Covered Entity is required to do so; and F. To the extent required under the HIPPA Regulations, comply with the privacy and security requirements that apply to Business Associates. (m) State Privacy Laws. Business Associate shall understand and comply with state privacy laws to the extent that such privacy laws are not preempted by HIPAA or HITECH. III. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE (a) Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities or services for, or on behalf of, Covered Entity described in the Service Agreement, provided that such use or disclosure would not violate the HIPAA Security and Privacy Rule if it were made by Covered Entity or would not violate the Covered Entities minimum necessary policies. (b) Other Uses of Protected Health Information. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information within its workforce for the proper management and administration of Business Associate not to include Marketing or Commercial Use and to carry out the legal responsibilities of Business Associate; and (c) Third Party Confidentiality. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that if Business Associate discloses any Protected Health Information to a third party for such purpose, the Business Associate shall enter into a written agreement with such third party requiring the following: A. Disclosure only as Required by Law; or B. Business Associate obtains reasonable assurances from the person to whom the infoiivation is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality, integrity, and or availability of the Protected Health Information has been breached immediately upon becoming aware. (d) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity pursuant to any agreements between the Parties evidencing their business relationship as permitted by 45 CFR § 164.504(e)(2)(i)(B). (e) Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business Associate to share Protected Health Information with Business Associate's affiliates or contractors except for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s) identified in Section I(a) of this Agreement. 4 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 (f) Covered Entity Authorization for Additional Uses. Any use of Protected Health Information by Business Associate, its affiliate or Contractor, other than those purposes of this Agreement, shall require express written authorization by the Covered Entity, and a Business Associate Agreement or amendment as necessary. Activities which are prohibited include, but are not limited to, Marketing, as defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed by Covered Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal or state laws. (g) Business Associate may de-identify Protected Health as necessary for data aggregation purposes of Business Associate, but only if the PHI is de-identified pursuant to 45 CFR 164.514. Business Associate may not sell Protected Health Information except at the direction of Covered Entity and in compliance with the requirements of the HIPAA Security and Privacy Rule. IV. AVAILABILITY OF PHI (a) Access to Protected Health Information. Business Associate agrees, in the event the Business Associate maintains protected health information in a Designated Record Set,to make available, within ten (10) days of a request by Covered Entity in a time and manner designated by Covered Entity, Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security and Privacy Rule. (b) Amendments to Protected Health Information. In the event that the Business Associate maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make any amendment(s) to Protected Health Information in a designated record set that the Covered Entity directs or agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of an individual,within ten(10) days of receipt of a request from Covered Entity and in the time and manner designated by Covered Entity. (c) Accounting of Disclosures. Business Associate agrees to maintain and make available the information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the HIPAA Security and Privacy Rule. (d) Document Disclosures. In the event an Individual makes a request under this Section of the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such request within three (3) business days and shall cooperate with, and act only at the direction of Covered Entity in responding to such request. V. OBLIGATIONS OF COVERED ENTITY (a) Notice of Privacy Practices. Covered Entity shall provide Business Associate with the notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as any changes to that notice. (b) Notice of Changes in Individual's Access or Protected Health Information. Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, if such changes affect Business Associate's permitted or required uses. (c) Notice of Restriction in Individual's Access to Protected Health Information. Covered Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such restriction may affect Business Associate's use of Protected Health Information. 5 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 VI. PERMISSIBLE REQUESTS BY COVERED ENTITY Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy or Security Rule. VII. TERMINATION (a) Term. This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the termination by Covered Entity for cause as provided herein. (b) Termination for Cause. Notwithstanding anything in this Agreement to the contrary, Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately if Covered Entity determines that Business Associate has or will violated any material term of this Agreement. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall provide an opportunity for Business Associate to cure the breach or end the violation. Covered Entity may terminate this Agreement if Business Associate does not cure the breach or end the violation within the time period specified by Covered Entity. If termination, cure or end of the violation is not feasible, Covered Entity may report the violation to the Secretary. (c) Obligation of Business Associate Upon Termination. At termination of this Agreement, the Service Agreement(or any similar documentation of the business relationship of the Parties), or upon request of Covered Entity,whichever occurs first, Business Associate, shall: A. if feasible, return(in a manner or process approved by the Covered Entity) or destroy all Protected Health Information, regardless of form, including but not limited to paper or electronic format, received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity. Business Associate shall retain no copies of the Protected Health Information. This provision shall also apply to Protected Health Information and other confidential information in the possession of sub-contractors or agents of Business Associate. B. If such return or destruction is not feasible, Business Associate shall (i) retain only that Protected Health Information necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities; (ii) return or destroy the remaining Protected Health Information that the Business Associate still maintains in any form; (iii) extend the protections of this Agreement to the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or destruction of the Protected Health Infoitnation not feasible; and (v) return or destroy the retained Protected Health Information when it is no longer needed by Business Associate. (d) Survival. This paragraph shall survive the termination of this Agreement and shall apply to Protected Health Information created, maintained, or received by Business Associate and any of its subcontractors. VIII. MISCELLANEOUS (a) Indemnification. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims, losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur by reason of Business Associate's breach of or failure to perform any the obligations pursuant to this 6 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 Agreement,including but not limited to any injury or damages arising from any noncompliance with this Agreement or any Security Incident attributable to the negligence of Business Associate, including failure to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, employees, contractors and agents, against all costs and expenses, including but not limited to, reasonable legal expenses, which are incurred by or on behalf of the Breaching Party in connection with the defense of such (b) Disclaimer. Covered Entity makes no warranty or representation that compliance by Business Associate with this Agreement, HIPAA, HITECH, or the HIPAA Regulations will be adequate or satisfactory for Business Associate's own purposes. Business Associate is solely responsible for all decisions made by Business Associate regarding the safeguarding of Protected Health Information. (c) Assistance in Litigation or Administrative Proceedings. Business Associate shall make itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the performance of its obligations under this Agreement, reasonably available to Covered Entity, at no cost to Covered Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being commenced against Covered Entity, its directors, officers or employees based upon a claimed violation of HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy,to the extent the litigation or administrative proceedings directly relate to the services performed by Business Associate pursuant to this Agreement or the Service Agreement, except where Business Associate or its subcontractor, employee or agent is named adverse party. (d) Survival. The obligations of Business Associate under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business relationship of the parties, and shall continue to bind Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein. (e) Ownership of Information. Covered Entity holds all right, title, and interest in and to the Protected Health Information and Business Associate does not hold and will not acquire by virtue of this Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or to the PHI or any portion thereof. (f) Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that the breach, or threatened breach,by it of any provision of this Agreement may cause Covered Entity to be irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore, Business Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek injunctive relief to prevent Business Associate from commencing or continuing any action constituting such breach without having to post a bond or other security and without having to prove the inadequacy of any other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other remedy available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties. (g) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPAA Regulations. In addition, this Agreement may be amended or modified by the Parties only in writing. (h) Assignment. No Party may assign its respective rights and obligations under this Agreement without the prior written consent of the other Party. (i) Independent Contractor. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any relationship between the Parties other than that of independent parties contracting with each other solely for the purposes of effecting the provisions of this Agreement 7 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 and any other agreements between the Parties evidencing their business relationship. This Agreement will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion. (j) Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH or the HIPAA Regulations means the section as it currently is in effect or as amended. (k) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event that any documentation of the arrangement pursuant to which Business Associate provides services to Covered Entity contains provisions relating to the use or disclosure of Protected Health Information that are more restrictive than the provisions of this Agreement, the more restrictive provisions will control. The provisions of this Agreement are intended to establish the minimum requirements regarding Business Associate's use and disclosure of Protected Health Information. (1) Severability. In the event any part or parts of this Agreement are held to be unenforceable, the remainder of this Agreement will continue in effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to (30) thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty-day period, a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to terminate upon written notice to the other party. (m) Notices and Communications. All instructions, notices, consents, demands, or other communications required or contemplated by this Agreement shall be in writing and shall be delivered to the Party at the address below: For Business Associate: For Covered Entity: Delta Dental Plan of North Carolina Brenda Bartholomew ATTN: Legal Department Orange County Human Resources Department 4100 Okemos Road 200 South Cameron Street Okemos,MI 48864 Hillsborough,NC 27278 (n) Strict compliance. No failure by any Party to insist upon strict compliance with any terms or provisions of this Agreement, to exercise any option, to enforce any right, or to seek any remedy upon any default of any other Party shall affect, or constitute a waiver of, any Party's right to insist upon such strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that default or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at variance with any provisions of this Agreement shall affect, or constitute a waiver of, any Party's right to demand strict compliance with all provisions of this Agreement. (o) Governing Law. This Agreement shall be governed and construed in accordance with the laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County, North Carolina for the purposes of litigation resulting from disagreements of the Parties for purposes of this Agreement and the Service Agreement(s). (p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract with governmental units. E-Verify is a Federal program operated by the United States Department of Homeland Security and other federal agencies, or any successor or equivalent program used to verify the work authorization of newly hired employees pursuant to federal law. Where applicable, failure to 8 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 maintain compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General Statutes shall constitute breach of this Agreement. If applicable, by executing this Agreement, Business Associate affirms that they are in compliance with Article 3 of Chapter 64 if the North Carolina General Statutes. (q) Iran Divestment Certification. By executing this Agreement, Business Associate certifies that Business Associate has not been identified, and has not utilized the services of any agent or subcontractor, on the list created by the State Treasurer pursuant to G.S. 147-86.58. IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above. CO _ o,r . .. :ITY: BU AS OCIATE: bbtaA,it, tkeuMMwte-rSt 1 ui C Art iS By 0037994B7'.,C477... By. 95BF9D1B39C4475 Title: County Manager Title: President & CEO Reviewed by Legal Department MRS 11-1-17 9 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 EXHIBIT A COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with the terms of this Agreement that might be considered a privacy breach, Business Associate should contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident(as defined in the Agreement), Business Associate should contact Brenda Bartholomew at(919)245-2552 or bbartholomew @orangecountync.gov,or the Security Officer at The Orange County Health Department. 10 October 2013 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 ADDITIONAL TERMS AND CONDITIONS These additional Terms and Conditions are an Addendum to the Vendor Authorization Agreement entered into on July 13, 2017 ("Effective Date")by and between Delta Dental of North Carolina,including its affiliates and/or subsidiaries, hereinafter referred to as Delta Dental, and Orange County hereinafter referred to as the Employer, and Flexible Benefits Administrators, hereinafter referred to as the Vendor(collectively referred to as the "Parties"). 1. Delta Dental and Vendor shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal anti-discrimination laws,policies,rules, and regulations and the Orange County Non-Discrimination Policy and Orange County Living Wage Policy(each policy is incorporated by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php). Any violation of this requirement is a breach of this Agreement and Employer may immediately terminate this Agreement without further obligation on part of the Employer. This paragraph is not intended to limit and does not limit the definition of breach to discrimination. By executing this Agreement, Delta Dental affirms that Delta Dental is and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement,Vendor affirms that Vendor is and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement, Delta Dental certifies that Delta Dental has not been identified, and has not utilized the services of any agent or subcontractor on the list created by the State Treasurer pursuant to G.S. 147-86.58. By executing this Agreement,Vendor certifies that Vendor has not been identified, and has not utilized the services of any agent or subcontractor on the list created by the State Treasurer pursuant to G.S. 147-86.58. 2. This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the intent of the Parties to comply with Article 11A and Article 40 of the North Carolina General Statutes Chapter 66. Oran eeCoun Delta Dental ocu igne yy: r—DocuSigned by: ' 1 By' OC3799407'..E477 By' a—95131-9Ln B39c44/5... Name: Bonnie Hamme rsl ey Name: Curtis Ladig Title: county Manager Title: President & CEO Vendor DocuSigned by: G (AA,161A, bwwiU, ((l By: 5 aEr04JCA2AD4C8... Name:G. Landon Browning, III Title: vice President Reviewed by Legal Department MRS 9-18-17 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 1 n1(14111 IQ7�I I�Daly�`I I�+��1 VENDOR AUTHORIZATION AGREEMENT This AGREEMENT is effective on JULY 13, 2017 among DELTA DENTAL OF NORTH CAROLINA, including its affiliates and/or subsidiaries, hereinafter referred to as Delta Dental, and ORANGE COUNTY, hereinafter referred to as the Employer, and FLEXIBLE BENEFIT ADMINISTRATORS, hereinafter referred to as the Vendor(collectively referred to as "Parties"). RECITALS WHEREAS, Delta Dental has entered in to an agreement with Employer pursuant to which Delta Dental provides claim administration services to an employee welfare benefit program sponsored by the Employer(the "Plan"); and WHEREAS,the Employer has, pursuant to an agreement between the Vendor and the Employer (the "Vendor Agreement"), requested the Vendor to perform certain services on its behalf ("Services"); and WHEREAS, the Employer has instructed Delta Dental to make certain specified claim and/or eligibility information available to the Vendor to assist Vendor in the Services, and/or has instructed the Vendor to provide certain claim and/or eligibility information to Delta Dental (the "Data"); and WHEREAS, the Plan is an employee welfare benefit plan and the Employer has made the requests and provided the instructions referred to above in its capacity as Plan Administrator; and WHEREAS, each party recognizes the legitimate interests of the other parties in maintaining the confidentiality of their Data, protecting the proprietary nature of their systems and processes, preserving their business reputation, avoiding unnecessary disruption of their claim administration, and protecting themselves from legal liability; and WHEREAS, the Parties are willing to make the Data available in accordance with the request of the Employer upon the condition that the other Parties provide proper assurances, including assurances of protection against claims or liability arising out of the performance of the Services or release of the Data to other Parties; and WHEREAS,the Parties are willing to make such assurances as are expressly provided herein; NOW, THEREFORE, in consideration of the foregoing premises, and the mutual covenants set forth in this Agreement,the Parties agree as follows: 1. Employer represents that it has the authority to authorize the release of the Data as directed herein. 2. The Data contains protected health information of the individuals covered by the healthcare benefit plan sponsored by Employer, as defined by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as well as proprietary business information of Delta Dental. The Parties agree that they will use the Data in accordance with this Agreement, and Vendor agrees that it will use the P:ALegal\CTS\DDNCAORANGE COUNTY-FLEXIBLE BENEFIT ADMINISTRATORS Vendor Authorization Agreement(govenimental entity)(7-13-2017).doc DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 Data in accordance with any other applicable agreement between Employer and Vendor ("Services Agreement"). In case of conflict between this Agreement and the Services Agreement, this Agreement shall control. Nothing herein shall prohibit Vendor from integrating or merging the Data into another Vendor database provided (1) any use or disclosure of any data or information from the merged or integrated database shall be on an aggregated basis such that no individual patients, providers, health plans, insurers, administrative services providers, or other individuals or entities can be identified, explicitly or implicitly, directly or indirectly, by users of such databases, and (2) Vendor does not and will not use, disclose or sell to or on behalf of any third party any pricing data or information contained in the Data without Delta Dental's and Employer's express prior written consent. The Parties' use or disclosure of the Data will be in compliance with all applicable laws, rules and regulations, including but not limited to the patient confidentiality requirements of the HIPAA Privacy Rule (45 CFR Parts 160 and 164). 3. If applicable, as determined by the Employer, the Employer has obtained or will obtain, pursuant to 45 CFR 164.508 of the HIPAA Privacy Rule, proper, written authorization from all individuals whose protected health information is used for any purpose except to carry out payment activities, for health care operations, or as otherwise permitted or required by law without consent or authorization of the individual. 4. The Data will be provided only to those employees, officers and principals of the Parties who are directly involved in the Services or in providing other service to the Employer or the Plan, but only after each individual has been informed of the confidential nature of the Data and instructed to treat the Data in accordance with this Agreement. The Data will be held confidential at all times and will not be divulged to any other party except as required by law. If any court order, regulatory order, other legal process or legal obligation requires Vendor to disclose information covered by its confidentiality obligation, Vendor will provide Delta Dental prompt telephonic and written notice of any such order or process (including providing a copy of the order or process), and cooperate with Delta Dental in responding to it unless such notice is prohibited by law. Such cooperation will be at Vendor's expense, unless the court order, regulatory order, legal process or legal obligation arises from an action against Delta Dental. 5. Each party represents that it has appropriate procedures and safeguards in place with respect to its use of the Data and the confidentiality of protected health information, and/or proprietary information of Delta Dental contained therein, and which will insure the integrity and security of the Data. The Parties will ensure that the transmission, handling, storage, use and any eventual elimination of this Data will preserve patient privacy and the confidentiality of the Data in compliance with all applicable laws, rules and regulations, including but not limited to the HIPAA Privacy Rule. 6. Each party shall assume liability solely for its own actions and shall not be responsible for any claims relating to breaches or alleged breaches of confidentiality concerning Data that is released or disclosed by another party to this Agreement. 7. To the extent that Vendor will be given access to any Delta Dental online toolkit ("Online Toolkit") for purposes of accessing or entering claims or eligibility data, Delta Dental hereby grants Vendor a limited, non-sublicensable, non-transferable, non-exclusive, temporary license to use the Online Toolkit. Vendor shall be solely responsible for the accuracy and completeness of the data entered using the Online Toolkit. Vendor shall indemnify and hold harmless Delta Dental its affiliates, members, officers, employees and agents, including persons or entities acting at the direction of or on behalf of Page 2 of 4 P:\Legal\CTS\DDNC\ORANGE COUNTY-FLEXIBLE BENEFIT ADMINISTRATORS Vendor Authorization Agreement(governmental entity((7-13-2017).doc DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 Delta Dental, from and against any and all losses, claims, damages, liabilities, costs, and expenses (including reasonable attorneys' fees and expenses related to the defense of any claims) resulting from or arising out of any data entered by Vendor's employees/agents or any other third party acting on behalf of Vendor. In addition, Vendor recognizes that Delta Dental retains sole title, right and interest in the intellectual property rights of its Online Toolkit including, but not limited to, any applicable copyrights. As such, neither Vendor nor any of its employees, officers, directors or agents shall attempt to reproduce, modify, reverse assemble, reverse compile or reverse engineer the source code of Delta Dental's Online Toolkit. In addition, Vendor acknowledges that in using the Online Toolkit, Vendor will have access to proprietary business information of Delta Dental. Vendor agrees not to attempt to reverse engineer or otherwise use Delta Dental's proprietary business information except for the purposes permitted under this Agreement. 8. Upon the completion of the Services for Employer, Vendor will immediately return or destroy all Data received from Delta Dental, without retaining any copies thereof (except for disaster recovery copies where that specific data cannot be deleted immediately) and will continue to be bound by this Agreement. Vendor will provide certification of such deletion/destruction to Delta Dental upon request. Notwithstanding the preceding sentence, if Vendor reasonably determines that such return or destruction is not feasible, it shall extend the protections of this Agreement to such information and limit further uses and disclosures to those purposes that make the return or destruction of the Data infeasible. 9. Upon a breach of this Agreement by Vendor, Vendor will immediately return, upon Delta Dental's request, all Data received from Delta Dental without retaining any copies thereof. Without prejudice to any other rights and remedies available to Delta Dental, if Vendor does not comply with the provisions of this paragraph, Delta Dental will be entitled to equitable relief by way of specific performance to enforce the provisions of this paragraph 9. 10. Each party recognizes and agrees that irreparable injury would be caused to the other parties that may not be compensable in money damages in the event of a breach of this Agreement. Without prejudice to any other rights and remedies available to the parties, the non-breaching party will be entitled to seek injunctive and other equitable or legal relief to prevent any actual, intended or likely injuries which may result from a breach. 11. Each party shall assume liability solely for its own actions and shall not be responsible for the actions or omissions of the other party. 12. The parties acknowledge and agree that the confidentiality and indemnification obligations under this Agreement will survive the expiration or termination of this Agreement, and any other contractual relationships between Vendor and Employer. 13. DELTA DENTAL MAKES NO WARRANTY OR REPRESENTATION, EXPRESS OR IMPLIED, AS TO THE COMPATIBILITY OF SUCH INFORMATION OR THE FORMAT IN WHICH IT IS PROVIDED, WITH VENDOR'S HARDWARE AND SYSTEMS. DELTA DENTAL SPECIFICALLY DISCLAIMS THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. ADDITIONALLY, ELECTRONIC TRANSMISSIONS PASSING OVER THE INTERNET ARE NOT GUARANTEED TO BE SECURE, AND DELTA DENTAL DOES NOT WARRANT THE SECURITY OR PRIVACY OF ANY SUCH TRANSMISSIONS, MESSAGES, OR COMMUNICATIONS BY VENDOR AND/OR ITS EMPLOYEES/AGENTS. Page 3 of 4 P:\Legal\CTS\DDNC\ORANGE COUNTY-FLEXIBLE BENEFIT ADMINISTRATORS Vendor Authorization Agreement(governmental entity((7-13-2017).doc DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 14. This Agreement shall be governed by the laws of the State of North Carolina without giving effect to conflict of laws principles thereof. 15. This Agreement may be executed in the original or by facsimile or other electronic means in any number of counterparts, each of which shall be deemed an original, and all of which together shall constitute one and the same instrument. IN WITNESS WHEREOF,the undersigned have hereto affixed their representative signatures. DELTA DENTAL OF NORTH CAROLINA ORANGE COUNTY 40074010 DocuSigned by By: By: bOln,ln,it, AWAAwtt,Vit,t1 ut,7013YStootn 7r... Title: General Counsel Title: County Manager Date: July 13, 2017 Date: 11/28/2017 FLEXIBLE BENEFIT ADMINISTRATORS r-°—DocuSigned by: B �. i, .IAitout, ?r'OW�t41 ((1 y.'* 53EF845CA2AD4C8.. Title: vice President Date:11/21/2017 Revivived by Legal Department MDS 7-13-17 Page 4 of 4 P:\Legal\CTS\DDNC\ORANGE COUNTY-FLEXIBLE BENEFIT ADMINISTRATORS Vendor Authorization Agreement(governmental entity((7-13-2017).doc DocuSign Envelope ID:B 156146B-0400-4433-84BD-A56E1 DCE5DA7 -1 ® DATE(MM/DD/YYYY) �` CERTIFICATE OF LIABILITY INSURANCE 08/31/2017 THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED REPRESENTATIVE OR PRODUCER,AND THE CERTIFICATE HOLDER. IMPORTANT:If the certificate holder is an ADDITIONAL INSURED,the policy(ies)must have ADDITIONAL INSURED provisions or be endorsed.If m SUBROGATION IS WAIVED,subject to the terms and conditions of the policy,certain policies may require an endorsement.A statement on this w. certificate does not confer rights to the certificate holder in lieu of such endorsement(s). c PRODUCER CONTACT — NAME: Aon Risk Services Central, Inc. PHONE (866) 283-7122 FAX (800) 363-0105 v southfi el d MI office (NC.No.Ext): (NC.No.): .a 3000 Town Center E-MAIL Suite 3000 ADDRESS: S Southfield MI 48075 USA INSURER(S)AFFORDING COVERAGE NAIC 8 INSURED INSURER A: Zurich American Ins Co 16535 Delta Dental of North Carolina INSURER B: The Continental Insurance Company 35289 4242 Six 27609 USA x Forks Road, Suite 970 Raleigh INSURER C: Allied World Surplus Lines Insurance Co 24319 INSURER D: , INSURER E: INSURER F: COVERAGES CERTIFICATE NUMBER: 570068227301 REVISION NUMBER: THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED.NOTWITHSTANDING ANY REQUIREMENT,TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES.LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. Limits shown are as requested INSR ADDL SUBR POLICY EFF POLICY EXP LTR TYPE OF INSURANCE INSD WVD POLICY NUMBER (MMIDDIYYYY) IfMMIDDIYYYY LIMITS A X COMMERCIAL GENERAL LIABILITY CPO948721606 06/15/2017 06/15/2018 EACH OCCURRENCE $1,000,000 CLAIMS-MADE X OCCUR DAMAGE TO RENTED $1,000,000 PREMISES(Ea occurrence) MED EXP(Any one person) $10,006 PERSONAL&ADV INJURY $1,000,000 0 GE AGGREGATE LIMIT APPLIES PER: GENERAL AGGREGATE $2,000,000 r X POLICY PRO- I LOC PRODUCTS-COMP/OP AGG $2,000,000 co OTHER: o N- A AUTOMOBILE LIABILITY BAP 9487215-06 06/15/2017 06/15/2018 COMBINED SINGLE LIMIT $1,000,000 (Ea accident) .. X ANY AUTO BODILY INJURY(Per person) 0 - OWNED —SCHEDULED BODILY INJURY(Per accident) 'Ol AUTOS ONLY AUTOS +' HIRED AUTOS NON-OWNED PROPERTY DAMAGE U ONLY —AUTOS ONLY (Per accident) y:. j- no B X UMBRELLA LIAB X OCCUR 6049723206 06/15/2017 06/15/2018 EACH OCCURRENCE $10,000,000 0 i? EXCESS LIAB CLAIMS-MADE AGGREGATE $10,000,000 DED I RETENTION A WORKERS COMPENSATION AND WC948721706 06/15/2017 06/15/2018 I PER oTH- EMPLOYERS'LIABILITY Y/N X STATUTE ER ANY PROPRIETOR/PARTNER I EXECUTIVE E.L.EACH ACCIDENT $1,000,000 OFFICER/MEMBER EXCLUDED? N N I A (Mandatory in NH) E.L.DISEASE-EA EMPLOYEE $1,000,000 E yes,describe under DESCRIPTION OF OPERATIONS below E.L.DISEASE-POLICY LIMIT $1,000,000— c ManageCare Liab 03047047 06/15/2017 06/15/2018 Per Claim Limit $1,000,000— E&O-Claims-Made Policy Aggregate $1,000,000 i SIR applies per policy terns & condi'ions DESCRIPTION OF OPERATIONS I LOCATIONS I VEHICLES(ACORD 101,Additional Remarks Schedule,may be attached if more space is required) Retro Date: 09/23/1957. 311... i.e n CERTIFICATE HOLDER CANCELLATION SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN ACCORDANCE WITH THE POLICY PROVISIONS. r 1-2 Brenda Bartholomew AUTHORIZED REPRESENTATIVE Orange County Human Resources Department Ems'. 200 south Cameron street Hillsborough NC 27278 USA ` ..a,c s p i . - n�4 cJ - ©1988-2015 ACORD CORPORATION.All rights reserved. ACORD 25(2016/03) The ACORD name and logo are registered marks of ACORD 1 DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1 DCE5DA7 ..44C0/20® DAT 0(M 3/DDD1 ) CERTIFICATE OF LIABILITY INSURANCE THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED REPRESENTATIVE OR PRODUCER,AND THE CERTIFICATE HOLDER. IMPORTANT:If the certificate holder is an ADDITIONAL INSURED,the policy(ies)must have ADDITIONAL INSURED provisions or be endorsed.If SUBROGATION IS WAIVED,subject to the terms and conditions of the policy,certain policies may require an endorsement.A statement on this la= certificate does not confer rights to the certificate holder in lieu of such endorsement(s). . PRODUCER CONTACT 13 NAME: Aon Risk Services Central, Inc. PHONE FAX '-' Southfield MI Office (A/C.No.Ext): (866) 283-7122 (A/C.No.): (800) 363-0105 a 3000 Town Center E-MAIL p Suite 3000 ADDRESS: _ southfield MI 48075 USA INSURER(S)AFFORDING COVERAGE NAIC# INSURED INSURER A: Allied World National Assurance company 10690 Delta Dental of North Carolina INSURER B: 4242 six Forks Road, suite 970 Raleigh NC 27609 USA INSURER C: INSURER D: INSURER E: INSURER F: COVERAGES CERTIFICATE NUMBER:570068354078 REVISION NUMBER: THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED.NOTWITHSTANDING ANY REQUIREMENT,TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN,THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES.LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. Limits shown are as requested INSR TYPE OF INSURANCE ADDL SUER POLICY NUMBER POLICY EFF POLICY EXP LIMITS LTR INSR MD (MMIDD/YYYYI (MM/DD/YYYY) COMMERCIAL GENERAL LIABILITY EACH OCCURRENCE DAMAGE TO RENTED CLAIMS-MADE OCCUR PREMISES(Ea occurrence) MED EXP(Any one person) J PERSONAL&ADV INJURY r GEN'L AGGREGATE LIMIT APPLIES PER: GENERAL AGGREGATE POLICY JECOT- I (LOC PRODUCTS-COMP/OP AGG el 0 OTHER: r AUTOMOBILE LIABILITY COMBINED SINGLE LIMIT in (Ea accident) ANY AUTO BODILY INJURY(Per person) 0 z OWNED —SCHEDULED BODILY INJURY(Per accident) 01 AUTOS ONLY AUTOS al HIRED AUTOS NON-OWNED PROPERTY DAMAGE 0) ONLY —AUTOS ONLY (Per accident) F. l.. 0 w UMBRELLA LIAB OCCUR EACH OCCURRENCE U EXCESS LIAB CLAIMS-MADE AGGREGATE DED I RETENTION EMPLOY RS'COMPENSATION AND I PER ERH EMPLOYERS'LIABILITY ANY PROPRIETOR/PARTNER/EXECUTIVE Y/N E.L.EACH ACCIDENT OFFICER/MEMB ER EXCLUDED? N/A (Mandatory in NH) E.L.DISEASE-EA EMPLOYEE If yes,describe under DESCRIPTION OF OPERATIONS below E.L.DISEASE-POLICY LIMIT A Cyber Liability 03101972 06/15/2017 06/15/2018 Each claim $10,000,000 Claims Made Aggregate Limit $10,000,000 M SIR applies per policy terns & conditions Retention $1,000,000 DESCRIPTION OF OPERATIONS/LOCATIONS/VEHICLES(ACORD 101,Additional Remarks Schedule,may be attached if more space is required) 'rir- k Retro Date: 09/23/1957. a.a nail i' 71.! W CERTIFICATE HOLDER CANCELLATION SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN ACCORDANCE WITH THE POLICY PROVISIONS. ll a Brenda Bartholomew AUTHORIZED REPRESENTATIVE Orange County Human Resources Department 200 south Cameron street ar Hil lsborough NC 27278 USA (i clp cVs a M I. ®1988-2015 ACORD CORPORATION.All rights reserved. ACORD 25(2016/03) The ACORD name and logo are registered marks of ACORD DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1DCE5DA7 - i-'. • FLEXBEN-01 BECKYM '`�A,�...• - L" CERTIFICATE OF LIABILITY INSURANCE DATEtMM/2017Y) 03/13/2017 THIS CERTIFICATE IS ISSUED AS A IVIATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER.THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S),AUTHORIZED REPRESENTATIVE OR PRODUCER,AND THE CERTIFICATE HOLDER. IMPORTANT: If the certificate holder is an ADDITIONAL INSURED,the policy(ies)must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy,certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). PRODUCER gaiiiiRCT Rebecca T.Moore Morgan-Marrow Company PHONE 21 Manhattan Square {Arc,No,)xI):(757)232-2219 FAX No): Hampton,VA 23666 a nAhss:BeckyM @m0rganmarr0W.COm INSURERS)AFFORDING COVERAGE NAIC# • _._-__- INSURER A:State Auto Property&Casualty Insurance Co. 25127 INSURED INSURER a:Meridian Security Insurance Company 23353 • Flexible Benefit Administrators,Inc. INSURER c:Landmark American Insurance Company 33138 P.O.Box 8188 INSURER D:Federal insurance Company 120281 Virginia Beach,VA 23450 __•____ _.._-_. w .�. _ _ ____! INSURER Ems•�_ . . INSURER F: 1 COVERAGES CERTIFICATE NUMBER: REVISION NUMBER: THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPEOTTO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES.LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. 1LTR TYPE OF INSURANCE DD SWVD` POLICY NUMBER I POUCYEFF-I POLICY EXP UNITS {MOLIC YEPP'I IPOLICY EYY) A X COMMERCIAL GENERALLfABILITY I 1,000,000 EACH OCCURRENCE S I CLAIMS-MADE 1 X I OCCUR 8OP2828079 0111112017 0111112018 DAMAGETEREN7ED 300,000 I PREMISE�S�Eaoccurrence� S ___..__ _.... _— ._�_ ,___ MEDEXP(Anyone person) _ $ 10,000 '_ J PERSONALBADVINJURY•_- S 0 IGEN'L AGGREGATE LIMIT APPLIES PER, GENERAL AGGREGATE S 2,000,000 I ]POLICY LJ PRO. LOO PRODUCTS-COMP/OP AGG s 2,000,000 II OTHER I S A AUTOMOBILE LIABILITY COMBINED SINGLE LIMIT 1,000,000 X ANY AUTO ) BAP2396224 01/11/2017 01/11/2018 GODILYINJURY(Per.arson S OWED t SCHEDULED , _, AUTOS t AUTOS BODILY INJURY "et accident), S W HIREp NON WNEp PROPERTY.AMAGE �_� AiJT'OSONLY , AUTO ONLY t {Peraccidenl 5 I li I S A X UMBRELLA LIAB I X OCCUR I I 1 9,000,000 E EACH OCCURRENCE S EXCESS LIAO I CLAIMS-MADE CXS2129634 01/11/2017 01/11/2018 II AGGREGATE_ _S 9,000,000 DED 1 I RETENTIONS i I S f B WORKERS COMPENSATION X I AND EMPLOYERS'LIABILITY �,!N STATUTE f I ERH ANY PROPRIETOR/PARTNER/EXECUTIVE I �NCP2233581 '01/11/2017 01/1'1/2018 EL EACH ACCIDENT S 500,000 OFFICER/MEMBER R I EXCLUDED? I N I N 1A ; E.L.DISEASE-EA EMPLOYEE S �_ 500,000 If yes,describe under 600,000 DESCRIPTION OF OPERATIONS below • _E.L,DISEASE-POLICY UNIT $ C Professional/E&O LHR756684 04/01/2016 04/01/2017 Each Claim 1,000,000 0 Client Crime/Theft 18241-8996 01/01/2017 01101/2018 .1,000,000 , DESCRIPTION OF OPERATIONS/LOCATIONS/VEHICLES(ACORD 101,Additional Remarks Sehedufe,may be attached if more apace Is required) j. 7 CERTIFICATE HOLDER CANCELLATION SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE For Information Purposes Only THE EXPIRATION DATE THEREOF, NOTICE,WILL BE DELIVERED IN P y ACCORDANCE WITH THE POLICY PROVISIONS. AUTHORIZED REPRESENTATIVE ACORD 25(2016/03) ©1988-2015 ACORD CORPORATION. All rights reserved. The ACORD name and logo are registered marks of ACORD DocuSign Envelope ID:B156146B-0400-4433-84BD-A56E1 DCE5DA7 FLEXBEN-01 BECKYM ACQRO"` DATE(MM/DD/YYYY) CERTIFICATE OF LIABILITY INSURANCE 08/30/2017 THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER.THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S),AUTHORIZED REPRESENTATIVE OR PRODUCER,AND THE CERTIFICATE HOLDER. IMPORTANT: If the certificate holder is an ADDITIONAL INSURED,the policy(ies)must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy,certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). PRODUCER CONTACT Rebecca T. Moore Morgan-Marrow Company 21 Manhattan Square (NC,ANo,Ext):(757)232-2219 FAX No): Hampton,VA 23666 ADDRESS:BeckyM @morganmarrow.com INSURER(S)AFFORDING COVERAGE NAIC# INSURER A:Federal Insurance Company 20281 INSURED INSURER B: Flexible Benefit Administrators,Inc. INSURER C: 509 Viking Drive,Suite F INSURER D: Virginia Beach,VA 23452 INSURER E: INSURER F: COVERAGES CERTIFICATE NUMBER: REVISION NUMBER: THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES.LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. INSR TYPE OF INSURANCE ADDL SUBR POLICY NUMBER POLICY EFF POLICY EXP LIMITS LTR INSD WVD (MMIDD/YYYYI (MM/DD/YYYY) COMMERCIAL GENERAL LIABILITY _EACH OCCURRENCE $ CLAIMS-MADE OCCUR DAMAGE TO RENTED PREMISES(Ea occurrence) $ MED EXP(Any one person) $ _PERSONAL&ADV INJURY $ GE 'L AGGREGATE LIMIT APPLIES PER: GENERAL AGGREGATE $ POLICY JECT LOC PRODUCTS-COMP/OP AGG $ OTHER: $ A COMBINED SINGLE LIMIT AU LIABILITY (Ea accident) ANY AUTO BODILY INJURY(Per person) $ OWNED UT ONLY SCHEDULED BODILY INJURY(Per accident) $ H RED NON-OWNED PROPERTY DAMAGE AUTOS ONLY AUTOS ONLY (Per accident) $ $ UMBRELLA LIAB OCCUR EACH OCCURRENCE $ E EXCESS LIAB CLAIMS-MADE AGGREGATE $ DED RETENTION$ $ WORKERS COMPENSATION PER AND EMPLOYERS'LIABILITY STATUTE EH ER ANY PROPRIETOR/PARTNER/EXECUTIVE Y/N NIA E.L.EACH ACCIDENT $ OFFICER/MEMBER EXCLUDED? (Mandatory in NH) E.L.DISEASE-EA EMPLOYEE $ If yes,describe under DESCRIPTION OF OPERATIONS below E.L.DISEASE-POLICY LIMIT $ A Cyber Liability 8236-9218 08/13/2017 08/13/2018 1,000,000 DESCRIPTION OF OPERATIONS/LOCATIONS/VEHICLES (ACORD 101,Additional Remarks Schedule,may be attached if more space is required) GG CERTIFICATE HOLDER CANCELLATION SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE Orange County North Carolina THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN 9 Y ACCORDANCE WITH THE POLICY PROVISIONS. P.O.Box 8181 Hillsborough,NC 27278 AUTHORIZED REPRESENTATIVE 25(2016/03) ©1988-2015 ACORD CORPORATION. All rights reserved. The ACORD name and logo are registered marks of ACORD