Loading...
The URL can be used to link to this page
Your browser does not support the video tag.
Home
My WebLink
About
2017-650-E Health - Carolinas IT to conduct HIPAA security risk analysis
DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A [Departmental Use Only] TITLE Carolinas IT SRA FY 2017-2018 ORANGE COUNTY CONTRACT UNDER $15,000.00 NORTH CAROLINA THIS AGREEMENT, made and entered into this 20th day of November, 2017, ("Effective Date") by and between Orange County, North Carolina, a political subdivision of the State of North Carolina, (the "County"),party of the first part; and Carolinas IT (the "Provider"),party of the second part; WITNESSETH: For the purpose and subject to the terms and conditions hereinafter set forth, the County hereby contracts for the services of the Provider, and the Provider agrees to provide the following services to the County in accordance with the terms of this Agreement, time being of the essence: The services and/or materials (hereinafter referred to collectively as "Services") to be furnished under this Agreement are as follows: Conduct HIPAA security risk analysis as described in the attached Statement of Work,which is attached hereto as Exhibit A. The term of this agreement rendered shall be from November 20, 2017 to June 30,2017. Provider represents and agrees that Provider is qualified to perform and fully capable of performing and providing the services required or necessary under this Agreement in a fully competent, professional and timely manner to the satisfaction of the County. Provider shall be responsible for all errors or omissions, in the performance of the Agreement. Provider shall correct any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts at no additional cost to the County. Provider agrees that Provider shall not sub-contract any of the services to be provided in this Agreement, nor shall Provider assign any right or responsibility granted or required by this Agreement,without the prior written approval of the County. SPECIFIC TERMS 1. Payment: The County agrees to pay at the rates specified for Services satisfactorily performed in accord with this Agreement. The amount to be paid by the County shall not exceed Five Thousand Dollars, ($5,000). Payment shall be made within thirty(30) days of an invoice properly submitted to County. Should Provider fail to perform its duties under the terms of this Agreement, County may, without fault or penalty,withhold any payment associated with the work to be performed until such time as said work is completed. 2. Non—waiver: Failure by County at any time to require the performance by Provider of any of the provisions hereof shall in no way waive or affect the County's right hereunder to enforce the same, nor shall any waiver by the County of any breach be held to be a waiver of any succeeding breach or a waiver of this Non-Waiver Clause. 3. Independent Contractor: The Provider shall operate as an independent contractor and the County shall not be responsible for any of the Provider's acts or omissions. The Provider shall not be treated as an employee with respect to the Services performed hereunder for federal or state tax, unemployment or workers' compensation purposes. The Provider understands that neither federal, nor state, nor payroll tax of any kind shall be withheld or paid by the County on behalf of the Provider or the employees of the Provider. 4. Insurance: Provider shall obtain, at its sole expense, Commercial General Liability Insurance, Automobile Insurance, Workers' Compensation Insurance, and any additional insurance as may be required by County's Risk Manager as such insurance requirements are described in the Orange County Risk Transfer Policy and Orange County Minimum Insurance Coverage Requirements (each document is Revised 2/17 1 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing division/contra cts.php). If County's Risk Manager determines additional insurance coverage is required such additional insurance shall consist of Errors & Ommisions, Cyber Liability (if no additional insurance required mark N/A as being not applicable). Provider shall not commence work until such insurance is in effect and certification thereof has been received by the County's Risk Manager. 5. Indemnity: The Provider agrees to defend, indemnify, and hold harmless Orange County from all losses, liabilities, claims, demands, suits, costs, damages or expenses (including reasonable attorney's fees) arising from bodily injury, including death, to any person or persons or damage to or destruction of any property caused in whole or in part by any negligent or intentional act or omission on the part of the Provider, its agents, or assigns directly or indirectly related to the Services to be performed pursuant to this Agreement on the part of the Provider. 6. Termination: This Agreement may be terminated at any time by mutual written agreement of the parties or by the County upon written notice to the Provider. County may suspend this Agreement upon reasonable notice to the Provider. 7. Entire Agreement and Signatures: The parties have read this Agreement and agree to be bound by all of its terms, and further agree that it constitutes the complete and exclusive statement of the Agreement between the parties unless and until modified in writing and signed by the parties. This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with Article 11A and Article 40 of North Carolina General Statute Chapter 66. 8. Priority: In determining the basic services to be provided, should any documents be referenced in or attached to this Agreement, the terms of this Agreement shall have priority in any conflict between the terms of referenced documents and the terms of this Agreement. 9. Governing Law: Both parties agree that this Agreement shall be governed by the laws of the State of North Carolina. Provider shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal anti-discrimination laws, policies,rules, and regulations and the Orange County Non-Discrimination Policy and Orange County Living Wage Policy (each policy is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php.). Any violation of this requirement is a breach of this Agreement and County may immediately terminate this Agreement without further obligation on the part of the County. This paragraph is not intended to limit and does not limit the definition of breach to discrimination. By executing this Agreement Provider affirms that Provider is and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor, on the list created by the State Treasurer pursuant to G.S. 147-86.58. 10. Dispute Resolution: Any and all suits or actions to enforce, interpret, or seek damages with respect to any provision of, or the performance or non-performance of, this Agreement shall be brought in the General Court of Justice of North Carolina sitting in Orange County, North Carolina. It is agreed by the parties that no other court shall have jurisdiction or venue with respect to such suits or actions. Binding arbitration may not be initiated by either Party, however, the Parties may agree to nonbinding mediation of any dispute prior to the bringing of such suit or action. 11. Non Appropriation: Provider acknowledges that County is a governmental entity, and the validity of this Agreement is based upon the availability of public funding under the authority of its statutory mandate. In the event that public funds are unavailable and not appropriated for the performance of County's Revised 2/17 2 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A obligations under this Agreement, then this Agreement shall automatically expire without penalty to County immediately upon written notice to Provider of the unavailability and non-appropriation of public funds. [SIGNATURE PAGE TO FOLLOW] Revised 2/17 3 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A IN WITNESS WHEREOF,County and the Provider have signed this Agreement, effective as of the day first written above. O o�,CQLINTY PRQIHFii f ned by: bblAAA,lt, lkamovt -rStu r. V' t'D A.A.Lt,Sb1A, By' 06379940755E477 By: ` 684389729212412... County Manager Title: Di rector of Audit and compliance 200 S. Cameron St. Carolinas IT P.O. Box 8181 1600 Hillsborough Street Hillsborough,NC 27278 Raleigh, NC 27605 Revised 2/17 4 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Carolinas IT 1600 Hillsborough Street Statement of Work Raleigh,NC 27605 PP,I(('Of 1\71;110 Corporate: (919)856-2300 Fax: (919)856-0420 Effective Date:20-Nov-2017 Expiration Date:31-Dec-2017 Client Information Client Contacts Carolinas IT Contacts Orange County Carla Julian Krista Cathey 300 West Tryon Street Phone/Ext.919-245-2434 Phone/Ext.919-573-4091 Hillsborough,NC 27278 Email:cjulian @orangecountync.gov Email:Krista.Cathey @CarolinaslT.com This Professional Services Agreement covers the services referenced herein. This Agreement shall be subject to all terms and conditions of the Master Agreement.To the extent any provisions of the Master Agreement conflict with the provisions of this Agreement,the provisions of the Master Agreement shall control, except to the extent that the applicable Statement of Work expressly and specifically states an intent to supersede the Master Agreement on a specific matter. The Master Agreement is hereby incorporated and made a part of this Agreement. This SOW defines exactly what work we are agreeing to do for you. Please DO NOT ASSUME that we are doing something as part of the project that is not specifically listed below. Overview:The goal of this project is to provide security risk assessments so the client is able to assess, identify and modify their overall security posture and to enable security, operations, organizational management and other personnel to collaborate and view the entire organization from an attacker's perspective. Initiation Phase:Carolinas IT will work with on-site IT staff/contractors to install and run a HIPAA Security specific data collection tool and gather information required for a complete assessment including: • Defining the client's Security Officer • Gaining required access to client's network • Installation of a network data collector • Installation of end-point device data collector • Delivery of a site survey including consultation on its use • Collection of public IP and wireless information Implementation Phase: Implementation of the assessments consist of one follow-up assessment and one on-site audit. The first scan, referred to as the annual on-site assessment,will be initiated immediately following the signing of this SOW or following the anniversary date of the original Security Risk Assessment. Carolinas IT will work with the on-site Security Officer, staff and contractors to complete the HIPAA Security specific data collection tool (installed during the initial assessment)and gather information required to assess progress made towards addressing the vulnerabilities identified in the initial HIPAA Security Management Plan and any subsequent updates to that plan. In addition to those steps, CIT Audit staff will conduct an annual on- site security audit required to validate the changes heretofore documented on the Management Plan. The second scan will be initiated at a scheduled time approximately six months after completion of the first scan mentioned above. The same steps will be followed to include working with the on-site Security Officer, staff and contractors to complete the HIPAA Security specific data collection tool and gather information required to assess progress made towards addressing the vulnerabilities identified in the most recent HIPAA Security Management Plan. The project will be implemented according to Carolinas IT best practices and manufacturers recommendations,while following the below steps: • On-going support of the data collecting tools • Interaction with Health Department staff to complete assessment of the environment • Report generation • On-site audit to validate mitigating tasks and documented improvements Deliverables and Closing: • Following the completion of each scan, the following versioned documents will be delivered: o Summary Risk Assessment including comparative risk score(documenting incremental improvement) o Risk Management Plan o Evidence of HIPAA Compliance Report • The reports will be presented via web conference. The objectives for the meeting include: o Review of the reports and identification of progress made towards mitigating vulnerabilities o Continued supervision and consulting of the Risk Management Plan 792094c7-3c00-42b2-aa97-9219813651e8.docx Page 1 of 4 11/20/2017 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Note: • The Client must provide available customer resources to provide console or network access to Internet router and fireweall and all servers..Alternatively, the customer may provide printed copied of the current software configurations, however this option will result in more limited discovery. • This audit/assessment is not meant to impact the network in any way. Every attempt will be made to protect the Client's production environment and avoid any interruption in service; however, the possibility of an interruption does exist during the scan. • No changes will be made to the Client's environment as a result of this engagement. This Assessment is meant to reveal any vulnerability and allow the Client to decide the most effective way to address them. • Carolinas IT does not recommend that any of the suggested"fixes"for discovered vulnerabilities be attempted without an assessment of the potential impact to the production network. Overall Client Responsibilities: • Client will provide security clearance and access to facilities, as required. This includes badges, user accounts, passwords, access cards and parking privileges.Any required network passwords will be provided to our technical resources and/or have an available resource to enter them at the time of the installation. • Client will provide Internet access for CIT engineers for the duration of the project. • Client will ensure accuracy of data/information supplied to CIT. • Client understands that CIT relies on immediate clarification and resolution regarding the integrity of data/information supplied to CIT. • CIT will require timely delivery of information from Client. This information includes, but is not limited to user names, extensions, map of user locations, and other pertinent information. • Client will provide a single point of contact for project coordination with CIT. • Client will be responsible for notifying users of any downtime they may experience during the course of the engagement. • Client will provide a list of key contacts and IT staff designated to support and/or assist CIT in the project prior to the kick- off meeting; including: Name, Title, Responsibility, Phone&E-mail wherever possible. • Client will provide any support related to the hardware and software being considered for inclusion in the design • Client will furnish CIT technical resources with requested information and data on Client operations, activities and existing systems, as required to achieve the project goals and provide CIT personnel with sufficient security access to said systems and facilities at all reasonable times during the performance of the Services. • Client shall provide network access as needed for the project(e.g., administrator access to servers included in scope, Internet access(FTP, HTTP), access to server consoles,etc.). *Client understands that any items listed under"Client Responsibilities"that are not in place or functioning when CIT engineers are onsite,that Client will be billed outside this statement of work for additional time needed. Completion Criteria: Carolinas IT will have fulfilled its obligations under this SOW upon completion of delivery of reports outlined in the Deliverables and Closing section of this SOW. Acceptance of Services: Upon completion of the Services/Tasks outlined under the Carolinas IT Responsibilities section(s)and any subsequent change orders, Carolinas IT shall request that the Client sign the Acknowledgement of Completion section of this work order indicating such completion and requesting Client's written acceptance of the Services. The Client shall promptly review the notification and provide a written response. If the Client's response indicates that Carolinas IT has not satisfactorily completed the Services/Tasks as outlined in the document and/or any subsequent change orders,the parties will meet and use good faith to resolve the issues. If the Client does not respond in writing within twelve (12)business days of receipt of Carolinas IT's notice,then the Services will be deemed accepted. Non-Disclosure Notice:This SOW includes information that cannot be disclosed outside of Client and will not be duplicated, used, or disclosed, in whole or in part, for any purpose other than to evaluate this SOW.To the extent permitted by North Carolina law, Client agrees not to reveal any of its contents to anyone not directly responsible for its evaluation without first obtaining the express written consent of CAROLINAS IT. This restriction does not limit Client's right to use information contained in this proposal if it is obtained from another source without restrictions or if already known to Client. Project Costs: This is a fixed fee engagement. Customer is responsible paying 50%of the total fee prior to the start of the project, with the balance being billed net 30-days upon completion of the annual on-site report. Should unexpected issues be discovered that could change the scope of the project, Client and CIT will jointly review the project status. Changes in services requirements to this SOW shall be approved in writing by the Client, and will be billed at CIT's T& M published rates. A copy of the Change Order is attached, (Appendix A-1). Scheduling: Project scheduling will typically occur within seven (7)to ten (10)working days after the signed Statement of Work and deposit(if applicable)has been received by Carolinas IT. 792094c7-3c00-42b2-aa97-9219813651e8.docx Page 2 of 4 11/20/2017 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Resources Include: • CISA • Associate Auditors Total Time and Resources Resources are typically available approximately 4-6 weeks from signature Phase Estimated Time Travel& Billing Code* Resource Description Charges Expenses Complete Security Risk Assessment—Two N/A Included Fixed Price CISA $5,000.00 Assessments including One Associate Auditors On-Site Audit *Professional Consulting and any other additional services listed in proposal may be provided ad-hoc for additional charges. Total Charges: $5,000.00 *One additional assessment may be added for a fee of$1,500.00. Client Authorization: DocuSigned by: 12/7/2017 Approved By: �jblabut, Ru.l AKA v�s(,t,li Date: 55799457fC477... __ I Printed Name: Bonnie Hammersley By signing this Statement of Work, the Client understands Carolinas IT Acceptance: the tasks that are in scope and agrees that tasks not listed are considered out of scope. This is a fixed fee engagement. r--DocuSigned by: Customer is responsible paying a minimum of 50% of the Approved By: r avto ('t sbtn, total fee prior to the start of the project, with the balance being billed net 10-days upon completion of the annual on- '--- Printed Printed Name: site report. As indicated in the HIPAA Security Rule, R. Greg Manson assessments should be conducted periodically. We believe best practice is to re-assess at least annually. As such, this SOW may be renewed for HIPAA SRA Basic Services (one scan and on-site audit, one scan with guidance) annually by written amendment duly executed by authorized Date: 11/20/2017 representatives of both parties. Client will be notified of the renewal option at least 30 days in advance. Acknowledgement of Completion: Approved By: Date: Printed Name: Date: Client hereby acknowledges the Services were completed as specified in this Statement of Work. Date: 792094c7-3c00-42b2-aa97-9219813651e8.docx Page 3 of 4 11/20/2017 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A APPENDIX A-1 CHANGE ORDER Client: Date: Change Requested By: Phone: Project/Service Name: Account Manager: Change Requested: Action Required: Projected Impact: Impact(High, Medium,Low): Importance to Completion(High,Medium,Low): Effect on Schedule(Extension, Reduction,No Effect): Original Completion Date: New Completion Date: Notes: Additional Resources Required: Resource Name Hours Cost Expenses Totals Totals: Authorization: Client hereby authorizes Carolinas IT to proceed in accordance with this Change Order and is still governed by the terms and conditions of the original document referenced above. Note: No work is to be done on the change(s) until this Change Control form is approved. A revised copy of the project plan will be provided if applicable. Signature Client Name: Date: 792094c7-3c00-42b2-aa97-9219813651e8.docx Page 4 of 4 11/20/2017 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Carolinas IT I,roC�:MSarui wt�,. I,�,di r �;Y IVfirir NON-DISCLOSURE AGREEMENT During business discussions or communications between the Parties it may be necessary for Carolinas IT, Inc. ("Carolinas IT"), having its primary place of business located at 1600 Hillsborough St, Raleigh, NC 27605 and Orange County, a body politic and corporate of the State of North Carolina, by and through its Orange County Health Department("Company") having its primary place of business located at 300 West Tryon Street, Hillsborough,NC 27278, to provide proprietary information to the other. WHEREAS, Carolinas IT owns certain trade secrets, proprietary information, and confidential technical and commercial information, intellectual property, expertise, and know-how relating to its business and/or business initiatives, collectively referred to as "Proprietary Information," which it expects to disclose to Company for certain limited purposes described herein; WHEREAS, Company owns certain trade secrets, proprietary information, and confidential technical and commercial information, intellectual property, expertise, and know-how relating to its business and/or business initiatives of potential use or value in connection with Carolinas ITs' business and/or business initiatives, collectively referred to as "Proprietary Information," which it expects to disclose to Carolinas IT for certain limited purposes described herein; NOW THEREFORE, in consideration of the mutual covenants and agreements set forth herein, the Parties hereby agree as follows: 1. Proprietary Information: shall mean any and all confidential, proprietary, or trade secret information or material of the Parties and any derivatives, portions, or copies thereof, whether in oral, written, visual, graphic, electronic, machine recognizable, or other form or medium, including, but not limited to, information resulting from or in any way related to (i) the business strategy and affairs, property, methods of operation, future plans, financial information, customer or supplier information, or other data of the Parties, (ii) the development, systems, discoveries, ideas, concepts, improvements, inventions, designs, drawings, specifications, techniques, data, software, documentation, research, product, processes, procedures, "know-how," or other works of the Parties, and (iii) any information or material that the Parties designate in writing to be Proprietary Information or which bears or contains a marking or legend indicating that it is confidential,proprietary, or trade secret information or material. 2. The Parties agree that all information defined in Article 1, whether oral or written is Proprietary Information when communicated or transmitted to the receiving party. Within 10 business days of an oral disclosure, the disclosing party will provide the receiving party with a written listing or summary that is marked with a proprietary legend. Non-Disclosure Agreement Page 1 of 5 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Carolinas IT I,roC�:MSarui wt�,. I,�,di r �;Y IVfirir 3. All Proprietary Information of the providing party remains its sole and exclusive property, regardless of its disclosure to the receiving party. Upon the expiration of this Agreement, or at an earlier time as requested by the providing party, the receiving party shall return to the providing party or destroy, at the providing party's direction, all of the written or tangible Proprietary Information in its possession and all copies and derivatives thereof. Nothing in this Agreement shall be construed as to grant to the receiving party any right or license under any patent,patent application, copyright, know-how, or any other operation of U. S. or international law. 4. The receiving party shall accept and retain Proprietary Information in the strictest confidence and in accordance with any restrictive marking or legend thereon. To the extent allowable by North Carolina law, the receiving party may not disclose to any third party any of the providing party's Proprietary Information without first obtaining the express prior written approval of the providing party and requiring the third party to protect such Proprietary Information in accordance with the terms of this Agreement. The receiving party shall permit the dissemination of the providing party's Proprietary Information within the receiving party's own organization only on a need-to-know basis, according to its need to conduct the activities contemplated herein, and governed by reasonable agreements with its own employees who are permitted access to the Proprietary Information of the providing party. 5. In no event may any Proprietary Information be used, directly or indirectly, for any purpose in connection with the receiving party's business or to compete directly or indirectly in any manner with the providing party. The receiving party shall make no commercial or other use whatsoever of the providing party's Proprietary Information, and shall not mechanically copy or otherwise reproduce such Proprietary Information except for the express purposes set forth herein, which copies shall contain the same restrictive marking or legend as the original. 6. The receiving party shall use its best efforts to prevent the inadvertent disclosure of the providing party's Proprietary Information to third Parties or the public, directly or indirectly. The receiving party will be considered to have used its best efforts if it has applied the same degree of care the receiving party applies to prevent disclosure of its own proprietary, confidential, or trade secret information, and at least as much care as a normally prudent businessperson would apply under the circumstances. 7. The Parties shall adhere to all U.S. Export Laws and Regulations and shall not export or re-export any technical data, received or disclosed under this agreement, or the product of such technical data to any foreign person (as such term is defined in the International Traffic in Arms Regulations (22 CFR 120.16)) unless properly authorized by the U.S. Government. The Parties shall provide prior written notice to the other Party of any foreign person who is an employee, Non-Disclosure Agreement Page 2 of 5 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Carolinas IT I,roC�:MSarui wt�,. I,�,di r �;Y IVfirir consultant or has such other relationship with the Party such that he or she will have access to the Confidential Information disclosed under this Agreement. Upon receipt of such written notice, the disclosing Party shall have the right to require the recipient to refrain from any such further disclosure to the foreign person if in the reasonable opinion of the disclosing Party such disclosure would be in violation of the U.S. Export Laws and Regulations. 8. The receiving party acknowledges and agrees that the Proprietary Information is the confidential, proprietary and trade secret information of the providing party and that the unauthorized use or disclosure of the Proprietary Information could cause irreparable harm and significant injury to the providing party for which the providing party would have no adequate remedy at law. Therefore, the providing party shall have the right, in addition to any other rights it may have at law or in equity, to seek and obtain immediate injunctive relief enjoining any breach or potential breach of this Agreement by the receiving party. 9. Notwithstanding the foregoing, the receiving party shall not be liable for the unauthorized use or disclosure of the providing party's Proprietary Information if the same: a. Was in the public domain at the time it was disclosed, as evidenced by written publication; b. Was known to the receiving party at the time of disclosure as shown in the receiving party's written records; c. The receiving party can show was independently developed; d. Becomes known to the receiving party from a source other than the providing party who is not a party to secrecy or similar agreement with the providing party; e. Is approved in writing for use or disclosure by the providing party, but only to the extent of such written approval; or f. Is required by law to be disclosed on a restricted basis pursuant to a judicial or other government order or the North Carolina Public Records Act, set forth at Chapter 132 of the North Carolina General Statutes, but only to the extent of such order or statute; provided, however, that the receiving party shall, immediately upon receiving notice of such impending or effective order, notify the providing party thereof. CIT agrees to indemnify and hold harmless Client and each of its officers, employees, and agents from all costs, damages, and expenses incurred in connection with refusing to disclose any material which CIT has designated Proprietary Information. 10. Each of the Parties to this Agreement shall appoint one representative. These Non-Disclosure Agreement Page 3 of 5 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Carolinas IT I,roC�:MSarui wt�,. I,�,di r �;Y IVfirir appointments shall be kept current during the period of this Agreement. All communication relating to this Agreement shall be directed only to the specific person(s) designated to represent Carolinas IT and Company. All notices shall be addressed to: For Carolinas IT: For Orange County: Carolinas IT Orange County Public Health 1600 Hillsborough St Department Raleigh,NC 27605 300 West Tryon Street Hillsborough NC27278 Attn: Greg Manson Attn: Carla Julian Phone: 919-573-4084 Phone: 919-245-2434 Fax: 919-856-0420 Fax: 919-245-1015 Email: Greg.Manson @CarolinasIT.com Email: cjulian @orangecountync.gov Notices given by mail shall be effective seven (7) calendar days after mailing first class, postage prepaid. Any notice, demand, request, statement, or other writing required or permitted by this Agreement shall be deemed to have been sufficiently given either when personally delivered, transmitted by facsimile and acknowledged as received, or mailed by any carrier providing a receipt. Changes in any of the above contact personnel for any Party must be made in writing. 11. In providing any Proprietary Information hereunder, the providing party makes no representation, express or implied, as to its adequacy, sufficiency, or freedom from defect of any kind. 12. The protection, rights, and obligations of this Agreement shall expire two (2) years from the termination date hereof This Agreement may be terminated by the Parties at any time giving thirty (30) days written notification of termination to the other party. Notwithstanding such expiration or termination, the Parties' obligations with respect to the protection of Proprietary Information disclosed shall survive for a period of three (3) years from the termination date of this agreement, or the effective date written notification to terminate the Agreement was provided. The obligations with respect to the protection of Proprietary Information marked or otherwise identified as a trade secret shall be for so long as such trade secret Proprietary Information remains secret and confidential. 13. Each party shall bear all costs and expenses incurred by it in complying with this Non-Disclosure Agreement. This Non-Disclosure Agreement is only for the Non-Disclosure Agreement Page 4 of 5 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Carolinas IT roi:iraruiw u I'(%di r (rY IVfirrr purpose of protecting Proprietary Information and shall not be construed as a teaming agreement, joint venture, or other contractual arrangement or as an obligation to enter into a contract, subcontract, or other business relationship. 14. This Agreement shall be governed by, interpreted, and enforced in accordance with the laws of the State of North Carolina, without respect to its conflicts of laws provisions. For purposes of any dispute for which resort to the courts is permitted by the terms of this Agreement the Parties consent to the jurisdiction of the Federal and State courts located in or serving Orange County,North Carolina. 15. Neither Party shall assign or transfer any of its rights or obligations hereunder without prior written consent of the other Party (except to a legally recognized successor in interest to all or substantially all of the Party's assets); any attempted assignment shall be null and void and without force and effect. 16. This Agreement, including any and all Exhibits hereto which are incorporated herein by reference, constitutes the entire agreement and understanding between the Parties hereto, and supersedes and replaces any and all previous or contemporaneous understandings, commitments, agreements,proposals or representations of any kind, whether oral or written, relating to the subject matter hereof This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with Article 11A and Article 40 of the North Carolina General Statutes Chapter 66. 17. If any terms, conditions or provisions of this Agreement is held or finally determined to be void, invalid illegal, or unenforceable in any respect, in whole or in part, such term, condition or provision shall be severed from this Agreement, and the remaining terms, conditions and provisions contained herein shall continue in force and effect, and shall in no way be affected, prejudiced or disturbed thereby. IN WITNESS WHEREOF, the Parties hereto have executed this Agreement as of the dates appearing below. Orange County Carolinas IT DocuSigned by: r--DocuSigned by: rt561AAAA, �cuMwtt.rstui r. "'td Atousa A, By• "-'- - By:,-0134309729212412 Name: Bonnie Hammersl ey Name:R. Greg Manson Title: County Manager Title: Director of Audit and Compliance Date: 12/7/2017 Date: 11/20/2017 Non-Disclosure Agreement Page 5 of 5 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ("Agreement") is made effective the 20th day of November, 2017, by and between Orange County Health Department("Covered Entity"), and Carolinas IT,including its affiliates and/or subsidiaries, ("Business Associate"). Covered Entity and Business Associate may be referred herein individually as a"Party" or collectively as the "Parties". This Agreement supersedes any previously executed Business Associate Agreement between the Parties. WITNESSETH: WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), Public Law 104-191, as modified by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), Public Law 111-5, known as "the Administrative Simplification provisions," direct the Department of Health and Human Services to develop standards to protect the security, confidentiality and integrity of health information; and WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human Services ("Secretary") has issued regulations modifying the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from time to time (the"HIPAA Security and Privacy Rule"); and WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangements, Business Associate may be considered a"Business Associate" of Covered Entity as defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred to as the"Service Agreement(s)"); and WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in fulfilling its responsibilities under such arrangement; THEREFORE, in consideration of the Parties' continuing obligations under the Service Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect the interests of both Parties. I. DEFINITIONS (a) Service Agreement. Agreement(s) for services affected by this HIPAA Business Associate Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby incorporated by reference, and which shall be taken and considered as a part of this document the same as if fully set out herein: Carolinas IT SRA (b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule, 45 CFR Parts 160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended,the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule,the provisions of this Agreement shall control. 1 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A (c) Electronic Protected Health Information. Protected Health Information that is transmitted by or maintained in Electronic Media(as defined in the HIPAA Security and Privacy Rule). (d) Protected Health Information. "Protected Health Information" shall have the same meaning as the term in 45 CFR § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity and includes without limitation "Electronic Protected Health Information." Business Associate acknowledges and agrees that all Protected Health Information that is created or received by Covered Entity and disclosed or made available in any form,including paper record, oral communication, audio recording, and electronic display by Covered Entity or its operating units to Business Associate or is created or received by Business Associate on Covered Entity's behalf shall be subject to this Agreement. (e) Required by Law. "Required by Law" shall have the same meaning as the term in 45 CFR § 164.103. II. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE (a) Use and Disclosure. Business Associate agrees to fully comply with the requirements under the HIPPA Security and Privacy Rule applicable to Business Associates and not to use or disclose Protected Health Information other than as permitted or required by this Agreement, the Service Agreement or as Required by Law. To the extent Business Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. Business Associate agrees to comply with Covered Entity's policies regarding the minimum necessary use or disclosure of Protected Health Information. (b) Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of Protected Health Information other than as provided for by this Service Agreement(s), this Agreement or as Required by Law. This includes the implementation physical, technical and administrative safeguards to prevent use or disclosure of Protected Health Information other than as permitted in this Agreement or Required by Law and reasonably and appropriately protect the confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with the HIPPA Security and Privacy Rule, including, but not limited to, its policies, procedures, records of training and sanctions of members in its workforce. (c) Assurances. Business Associate agrees to provide Covered Entity with written assurances that any Protected Health Information placed on any type of mobile media, including, but by no means limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with guidance issued by the Secretary. (d) Agents and Subcontractors. Business Associate shall require any agents, including any subcontractors, to whom it provides Protected Health Information from Covered Entity that is created, received, maintained or transmitted on behalf of Business Associate to agree by written contract with Business Associate to the same (or greater) restrictions, conditions and requirements that apply to Business Associate with respect to such information, and to agree to implement reasonable and appropriate safeguards to protect any of such information that is Electronic Protected Health Information. In addition, Business Associate agrees to take reasonable steps to ensure that its employees' actions or omissions do not cause Business Associate to breach the terms of this Agreement. (e) Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health 2 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Information by Business Associate in violation of the requirements of this Agreement, as well as to provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate such noncompliance or Security Incident. Business Associate shall cooperate in Covered Entity's breach analysis and/or risk assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the event that Covered Entity determines that any third parties must be notified of a Breach,provided that Business Associate shall not provide any such notification except at the direction of Covered Entity. (f) Breach Reporting. Business Associate shall report in writing to Covered Entity's Privacy Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance with the terms of this Agreement, as well as any Security Incident and any actual or suspected Breach, of which it becomes aware, without unreasonable delay, and in no event later than five (5) days of such discovery. For purposes of this Agreement, "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Such notification shall contain the elements required by 45 C.F.R. § 164.410. (g) Compliance. To the extent applicable, Business Associate will comply with (i) Covered Entity's Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual's permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to agree. (h) Government Access. Business Associate will make its internal practices, books and records available to the Secretary of the Department of Health and Human Services for purposes of determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations and compliance reviews,permit access to information, and cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event, no more than 48 hours of receipt of the request or notification, Business Associate will notify Covered Entity in writing of any request by any governmental entity, or its designee, to review Business assessment of any kind. (i) Electronic Transactions. If Business Associate conducts any Standard Transactions for or on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic Transaction Rule. (j) Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an audit of Business Associate's compliance with this Agreement, HIPAA, and HITECH. Such audit may consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate shall promptly and completely respond to Covered Entity's requests for information in support of the audit, which shall not be conducted more than once annually except in cases of an actual or reasonably suspected Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or HITECH. Each Party shall bear its own costs associated with the audit. (k) Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies and Procedures to protect any patient information that may be breached by the Business Associate to the extent applicable under the Federal Trade Commission's Red Flag Rules. (1) HITECH Compliance. Business Associate shall: A. Not receive, directly or indirectly, any impermissible remuneration in exchange for Protected Health Information or Electronic Protected Health Information, except as permitted by HITECH § 13405(d) or the HIPPA Regulations; 3 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A B. Comply with the marketing and other restrictions applicable to Business Associates contained in HITECH § 13406 and the HIPPA Regulations; C. To the extent required under HITECH § 13404, fully comply with the applicable requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected Health Information; D. To the extent required under HITECH § 13401, fully comply with 45 CFR §§ 164.308, 164.310, 164.312, and 164.316; E. To the extent required under HITECH §§13401 and 13404, comply with the additional privacy and security requirements that apply to Covered Entities in the same manner and to the same extent as Covered Entity is required to do so; and F. To the extent required under the HIPPA Regulations, comply with the privacy and security requirements that apply to Business Associates. (m) State Privacy Laws. Business Associate shall understand and comply with state privacy laws to the extent that such privacy laws are not preempted by HIPPA or HITECH. III. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE (a) Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities or services for, or on behalf of, Covered Entity described in the Service Agreement,provided that such use or disclosure would not violate the HIPPA Security and Privacy Rule if it were made by Covered Entity or would not violate the Covered Entities minimum necessary policies. (b) Other Uses of Protected Health Information. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information within its workforce for the proper management and administration of Business Associate not to include Marketing or Commercial Use and to carry out the legal responsibilities of Business Associate; and (c) Third Party Confidentiality. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that if Business Associate discloses any Protected Health Information to a third party for such purpose, the Business Associate shall enter into a written agreement with such third party requiring the following: A. Disclosure only as Required by Law; or B. Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality, integrity, and or availability of the Protected Health Information has been breached immediately upon becoming aware. (d) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity pursuant to any agreements between the Parties evidencing their business relationship as permitted by 45 CFR§ 164.504(e)(2)(i)(B). (e) Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business Associate to share Protected Health Information with Business Associate's affiliates or contractors except 4 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s) identified in Section 1(a) of this Agreement. (f) Covered Entity Authorization for Additional Uses. Any use of Protected Health Information by Business Associate, its affiliate or Contractor, other than those purposes of this Agreement, shall require express written authorization by the Covered Entity, and a Business Associate Agreement or amendment as necessary. Activities which are prohibited include, but are not limited to, Marketing, as defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed by Covered Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal or state laws. (g) Business Associate may de-identify Protected Health Information only at the specific direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health Information except at the direction of Covered Entity and in compliance with the requirements of the HIPAA Security and Privacy Rule. IV. AVAILABILITY OF PHI (a) Access to Protected Health Information. Business Associate agrees, in the event the Business Associate maintains protected health information in a Designated Record Set,to make available, within ten (10) days of a request by Covered Entity in a time and manner designated by Covered Entity, Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security and Privacy Rule. (b) Amendments to Protected Health Information. In the event that the Business Associate maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make any amendment(s) to Protected Health Information in a designated record set that the Covered Entity directs or agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of an individual, within ten(10) days of receipt of a request from Covered Entity and in the time and manner designated by Covered Entity. (c) Accounting of Disclosures. Business Associate agrees to maintain and make available the information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the HIPAA Security and Privacy Rule. Business Associate will comply with Covered Entity's policy regarding accounting of disclosures. (d) Document Disclosures. In the event an Individual makes a request under this Section of the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such request within three (3) business days and shall cooperate with, and act only at the direction of Covered Entity in responding to such request. V. OBLIGATIONS OF COVERED ENTITY (a) Notice of Privacy Practices. Covered Entity shall provide Business Associate with the notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as any changes to that notice. (b) Notice of Changes in Individual's Access or Protected Health Information. Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, is such changes affect Business Associate's permitted or required uses. 5 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A (c) Notice of Restriction in Individual's Access to Protected Health Information. Covered Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such restriction may affect Business Associate's use of Protected Health Information. VI. PERMISSABLE REQUESTS BY COVERED ENTITY Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy or Security Rule. VII. TERMINATION (a) Term. This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the termination by Covered Entity for cause as provided herein. (b) Termination for Cause. Notwithstanding anything in this Agreement to the contrary, Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately if Covered Entity determines that Business Associate has or will violated any material term of this Agreement. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall provide an opportunity for Business Associate to cure the breach or end the violation. Covered Entity may terminate this Agreement if Business Associate does not cure the breach or end the violation within the time period specified by Covered Entity. If termination, cure or end of the violation is not feasible, Covered Entity may report the violation to the Secretary. (c) Obligation of Business Associate Upon Termination. At termination of this Agreement, the Service Agreement(or any similar documentation of the business relationship of the Parties), or upon request of Covered Entity,whichever occurs first, Business Associate, shall: A. if feasible, return(in a manner or process approved by the Covered Entity) or destroy all Protected Health Information, regardless of form, including but not limited to paper or electronic format, received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity. Business Associate shall retain no copies of the Protected Health Information. This provision shall also apply to Protected Health Information and other confidential information in the possession of sub-contractors or agents of Business Associate. B. If such return or destruction is not feasible, Business Associate shall (i) retain only that Protected Health Information necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities; (ii) return or destroy the remaining Protected Health Information that the Business Associate still maintains in any form; (iii) extend the protections of this Agreement to the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or destruction of the Protected Health Information not feasible; and (v) return or destroy the retained Protected Health Information when it is no longer needed by Business Associate. (d) Survival. This paragraph shall survive the termination of this Agreement and shall apply to Protected Health Information created, maintained, or received by Business Associate and any of its subcontractors. VIII. MISCELLANEOUS 6 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A (a) Indemnification. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims, losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur by reason of Business Associate's breach of or failure to perform any the obligations pursuant to this Agreement, including but not limited to any injury or damages arising from any noncompliance with this Agreement or any Security Incident attributable to the negligence of Business Associate, including failure to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, employees, contractors and agents, against all costs and expenses, including but not limited to, reasonable legal expenses, which are incurred by or on behalf of the Breaching Party in connection with the defense of such claims. (b) Disclaimer. Covered Entity makes no warranty or representation that compliance by Business Associate with this Agreement, HIPAA, HITECH, or the HIPAA Regulations will be adequate or satisfactory for Business Associate's own purposes. Business Associate is solely responsible for all decisions made by Business Associate regarding the safeguarding of Protected Health Information. (c) Assistance in Litigation or Administrative Proceedings. Business Associate shall make itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the performance of its obligations under this Agreement, available to Covered Entity, at no cost to Covered Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being commenced against Covered Entity, its directors, officers or employees based upon a claimed violation of HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy, except where Business Associate or its subcontractor, employee or agent is named adverse party. (d) Survival. The obligations of Business Associate under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business relationship of the parties, and shall continue to bind Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein. (e) Ownership of Information. Covered Entity holds all right, title, and interest in and to the Protected Health Information and Business Associate does not hold and will not acquire by virtue of this Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or to the PHI or any portion thereof. (f) Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that the breach, or threatened breach,by it of any provision of this Agreement may cause Covered Entity to be irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore,Business Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek injunctive relief to prevent Business Associate from commencing or continuing any action constituting such breach without having to post a bond or other security and without having to prove the inadequacy of any other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other remedy available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties. (g) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPAA Regulations. In addition, this Agreement may be amended or modified by the Parties only in writing. (h) Assignment. No Party may assign its respective rights and obligations under this Agreement without the prior written consent of the other Party. 7 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A (i) Independent Contractor. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any relationship between the Parties other than that of independent parties contracting with each other solely for the purposes of effecting the provisions of this Agreement and any other agreements between the Parties evidencing their business relationship. This Agreement will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion. (j) Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH or the HIPAA Regulations means the section as it currently is in effect or as amended. (k) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event that any documentation of the arrangement pursuant to which Business Associate provides services to Covered Entity contains provisions relating to the use or disclosure of Protected Health Information that are more restrictive than the provisions of this Agreement, the more restrictive provisions will control. The provisions of this Agreement are intended to establish the minimum requirements regarding Business Associate's use and disclosure of Protected Health Information. (1) Severability. In the event any part or parts of this Agreement are held to be unenforceable, the remainder of this Agreement will continue in effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to (30) thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty-day period, a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to terminate upon written notice to the other party. (m) Notices and Communications. All instructions, notices, consents, demands, or other communications required or contemplated by this Agreement shall be in writing and shall be delivered to the Party at the address below: For Covered Entity: For Business Associate: Orange County Health Department Carolinas IT 200 W. Tryon Street 1600 Hillsborough Street Hillsborough,NC 27278 Raleigh,NC 27605 (n) Strict compliance. No failure by any Party to insist upon strict compliance with any terms or provisions of this Agreement, to exercise any option, to enforce any right, or to seek any remedy upon any default of any other Party shall affect, or constitute a waiver of, any Party's right to insist upon such strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that default or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at variance with any provisions of this Agreement shall affect, or constitute a waiver of, any Party's right to demand strict compliance with all provisions of this Agreement. (o) Governing Law. This Agreement shall be governed and construed in accordance with the laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County, North Carolina for the purposes of litigation resulting from disagreements of the Parties for purposes of this Agreement and the Service Agreement(s). (p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract with governmental units. E-Verify is a Federal program operated by the United States Department of 8 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A Homeland Security and other federal agencies, or any successor or equivalent program used to verify the work authorization of newly hired employees pursuant to federal law. Where applicable, failure to maintain compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General Statutes shall constitute breach of this Agreement. If applicable, by executing this Agreement, Business Associate affirms that they are in compliance with Article 3 of Chapter 64 if the North Carolina General Statutes. (q) Iran Divestment Certification. By executing this Agreement, Business Associate certifies that Business Associate has not been identified, and has not utilized the services of any agent or subcontractor, on the list created by the State Treasurer pursuant to G.S. 147-86.58. IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above. CO; t :ITY: BUS FES$. SSvOCIATE: ��, S ,/�,�Ln,, , r, avto ALA.Lt,SbiiL By: 63271s EUSKUOr... By:• 6B4?697292 2,1,2 Title: Health Di rector Title: Di rector of Audit and compliance 9 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A EXHIBIT A COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with the terms of this Agreement that might be considered a privacy breach, Business Associate should contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident(as defined in the Agreement), Business Associate should contact Carla Julian, or the Security Officer at The Orange County Health Department. 10 October 2013 DocuSign Envelope ID:88577424-D976-4534-82EF-EEA3A41BAB2A CAROITO-01 SPIKE `" "" `' CERTIFICATE OF LIABILITY INSURANCE DATE(MM/DD/YYYY) ►�' 10/18/2017 THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER.THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S),AUTHORIZED REPRESENTATIVE OR PRODUCER,AND THE CERTIFICATE HOLDER. IMPORTANT: If the certificate holder is an ADDITIONAL INSURED,the policy(ies)must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy,certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). PRODUCER CONTACT NAME: Hub International Southeast PHONE FAX (a/c,No,Ext):(919)337-0000 (A/C,No):(866)553-5124 E-MAIL ADDRESS: INSURER(S)AFFORDING COVERAGE NAIC# INSURER A:Hanover American Insurance 36064 INSURED INSURER B:Allmerica Financial Benefit Insurance Company 41840 Carolinas IT,Inc. INSURERC: 1600 Hillsborough St INSURERD: Raleigh,NC 27605 INSURER E: INSURER F: COVERAGES CERTIFICATE NUMBER: REVISION NUMBER: THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES.LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. INSR TYPE OF INSURANCE ADDL SUBR POLICY NUMBER POLICY EFF POLICY EXP LIMITS LTR INSD WVD (MM/DD/YYYY) (MM/DD/YYYY) A X COMMERCIAL GENERAL LIABILITY EACH OCCURRENCE $ 1,000,000 CLAIMS-MADE X OCCUR X OZ6 D104240 00 11/25/2016 11/25/2017 PREMISES(Ea occur ante) $ 300,000 MED EXP(Any one person) $ 10,000 PERSONAL&ADV INJURY $ 1,000,000 GE 'L AGGREGATE LIMIT APPLIES PER: GENERAL AGGREGATE $ 2,000,000 X POLICY PRO- JECT LOC PRODUCTS-COMP/OPAGG $ 2,000,000 OTHER: HNO Auto $ Included A COMBINED SINGLE LIMIT AU LIABILITY (Ea accident) $ ANY AUTO BODILY INJURY(Per person) $ OWNED SCHEDULED AUTOS ONLY AUTOS BODILY INJURY(Per accident) $ HIRED NON-OWNED PROPERTY DAMAGE AUTOS ONLY AUTOS ONLY (Per accident) $ A X UMBRELLA LIAB X OCCUR EACH OCCURRENCE $ 2,000,000 EXCESS LIAB CLAIMS-MADE OZ6 D104240 00 11/25/2016 11/25/2017 AGGREGATE $ 2,000,000 DED X RETENTION$ 0 $ B WORKERS COMPENSATION X PER OTH- AND EMPLOYERS'LIABILITY STATUTE ER Y/N W26D 104234 11/25/2016 11/25/2017 500,000 ANY OFFICER/MEMBER EXCCLUDEDXECUTIVE N N/A E.L.EACH ACCIDENT $ (Mandatory in NH) E.L.DISEASE-EA EMPLOYEE $ 500,000 If yes,describe under 500,000 DESCRIPTION OF OPERATIONS below E.L.DISEASE-POLICY LIMIT $ A Professional Liabili OZ6 D104240 00 11/25/2016 11/25/2017 Each Claim 4,000,000 DESCRIPTION OF OPERATIONS/LOCATIONS/VEHICLES (ACORD 101,Additional Remarks Schedule,may be attached if more space is required) Prof Liability- Deductible$25,000. Professional Liability policy includes Information Security as defined by the policy forms. Orange County,its officers,offical agents and employees are named as additional insured as respects the general liabiltiy policy as required by written contract. CERTIFICATE HOLDER CANCELLATION SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE Orange County THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN 9 y ACCORDANCE WITH THE POLICY PROVISIONS. Attn: Risk Management PO Box 8181 Hillsborough,NC 27278 AUTHORIZED REPRESENTATIVE ACORD 25(2016/03) ©1988-2015 ACORD CORPORATION. All rights reserved. The ACORD name and logo are registered marks of ACORD