Loading...
HomeMy WebLinkAbout2017-716-E Health - Health Ascent Associates consulting DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A [Departmental Use Only] TITLE Health Ascent- Coaching FY 2017-2018 NORTH CAROLINA CONSULTING SERVICES AGREEMENT UNDER $90,000 ORANGE COUNTY This Agreement, made and entered into this 20th day of November, 2017, ("Effective Date") by and between Orange County, North Carolina a body politic and corporate of the State of North Carolina (hereinafter, the "County") and Health Ascent Associates, LLC, (hereinafter, the "Consultant"). WITNESSETH: That the County and Consultant, for the consideration herein named, do hereby agree as follows: ARTICLE 1 SCOPE OF WORK 1.1 Scope of Work 1.1.1 This Services Agreement ("Agreement") is for professional consulting services to be rendered by Consultant to County with respect to (insert type of project) Provide support and/or coaching to new Health Director. 1.1.2 By executing this Agreement, the Consultant represents and agrees that Consultant is qualified to perform and fully capable of performing and providing the services required or necessary under this Agreement in a fully competent,professional and timely manner. 1.1.3 Time is of the essence with respect to this Agreement. 1.1.4 The services to be performed under this Agreement consist of Basic Services, as described and designated in Article 3 hereof. Compensation to the Consultant for Basic Services under this Agreement shall be as set forth herein. ARTICLE 2 RESPONSIBILITIES OF THE CONSULTANT 2.1 Services to be Provided. The Consultant shall provide the County with all services required in Article 3 to satisfactorily complete the Project within the time limitations set forth herein and in accordance with the highest professional standards. 2.2. Standard of Care 2.2.1 The Consultant shall exercise reasonable care and diligence in performing services under this Agreement in accordance with the highest generally accepted standards of this type of Consultant practice throughout the United States and in accordance with applicable federal, state and local laws and regulations applicable to the performance of these services. Consultant is solely responsible for the professional quality, accuracy and timely completion and submission Revised 10/17 1 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A of all reports, drawings, specifications, plans, documents and services (hereinafter "Deliverables") related to the Basic Services. 2.2.2 The Consultant shall be responsible for all errors or omissions, in the deliverables prepared by the Consultant. 2.2.3 The Consultant shall correct at no additional cost to the County any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts in any Deliverables prepared by the Consultant. 2.2.4 The Consultant shall assure that all Deliverables prepared by it hereunder are in accordance with applicable laws, statutes, and that any necessary or appropriate applications for approvals are submitted to federal, state and local governments or agencies in a timely manner so as not to delay the Project. 2.2.5 The Consultant shall not, except as otherwise provided for in this Agreement, subcontract the performance of any work under this Agreement without prior written permission of the County. No permission for subcontracting shall create, between the County and the subcontractor, any contract or any other relationship. 2.2.6 Any and all employees of the Consultant engaged by the Consultant in the performance of any work or services required of the Consultant under this Agreement, shall be considered employees or agents of the Consultant only and not of the County, and any and all claims that may or might arise under any workers compensation or other law or contract on behalf of said employees while so engaged shall be the sole obligation and responsibility of the Consultant. 2.2.7 If activities related to the performance of this agreement require specific licenses, certifications, or related credentials Consultant represents that it and/or its employees, agents and subcontractors engaged in such activities possess such licenses, certifications, or credentials and that such licenses certifications, or credentials are current, active, and not in a state of suspension or revocation. ARTICLE 3 BASIC SERVICES 3.1 Basic Services 3.1.1 The Consultant shall perform as Basic Services the work and services described herein : Provide transition support and/or coaching to the Health Director from December 18, 2017 through June 30, 2018 and other additional activities as needed under the direction of the Health Director and/or Board of Health. ARTICLE 4 DURATION OF SERVICES 4.1 Scheduling of Services 4.1.1 The Consultant shall schedule and perform its activities in a timely manner. Revised 10/17 2 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A 4.1.2 Should the County determine that the Consultant is behind the agreed upon schedule, it may require the Consultant to expedite and accelerate his efforts, including providing additional resources and working overtime, as necessary, to perform his services in accordance with the approved project schedule at no additional cost to the County. 4.1.3 The Commencement Date for the Consultant's Basic Services shall be December 18, 2017. ARTICLE 5 COMPENSATION 5.1 Compensation for Basic Services 5.1.1 Compensation for Basic Services shall include all compensation due the Consultant from the County for all services under this Agreement except for any authorized Reimbursable Expenses which are defined herein. The maximum amount payable for Basic Services is Eight Thousand Seven Hundred Dollars ($8,700.00). Payment for Basic Services shall become due and payable in direct proportion to satisfactory services performed and work accomplished. ARTICLE 6 RESPONSIBILITIES OF THE COUNTY 6.1 Cooperation and Coordination 6.1.1 The County has designated Rebecca Crawford to act as the County's representative with respect to the Project and shall have the authority to render decisions within guidelines established by the County Manager and the County Board of Commissioners and shall be available during working hours as often as may be reasonably required to render decisions and to furnish information. 6.1.2 The County shall be solely responsible for determining whether Consultant as satisfactorily completed Tasks. It is agreed that County shall not unreasonably withhold its determination of satisfactory completion of any Task. In the event the amount of an invoice is disputed County may withhold payment until the dispute is resolved by the parties. County may also withhold payment on an invoice until the satisfactory completion of a Task by Consultant. ARTICLE 7 INSURANCE AND INDEMNITY 7.1 General Requirements 7.1.1 Consultant shall obtain, at its sole expense, Commercial General Liability Insurance, Automobile Insurance, Workers' Compensation Insurance, Professional Liability Insurance, and any additional insurance as may be required by Owner's Risk Manager as such insurance requirements are described in the Orange County Risk Transfer Policy and Orange County Minimum Insurance Coverage Requirements (each document is incorporated herein by reference and may be viewed at http://www.orangecountVnc.gov/departments/purchasing division/contracts.php). If Owner's Risk Manager determines additional insurance coverage is required such additional insurance shall be designated here N/A (if no additional insurance required mark N/A as being not Revised 10/17 3 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A applicable). Consultant shall not commence work until such insurance is in effect and certification thereof has been received by the Owner's Risk Manager. 7.2 Indemnity 7.2.1 The Consultant agrees, without limitation, to indemnify and hold harmless the County from all loss, liability, claims or expense, including attorney's fees, arising out of or related to the Project and arising from property damage or bodily injury including death to any person or persons caused in whole or in part by the negligence or misconduct of the Consultant except to the extent same are caused by the negligence or willful misconduct of the County. It is the intent of this provision to require the Consultant to indemnify the County to the fullest extent permitted under North Carolina law. ARTICLE 8 AMENDMENTS TO THE AGREEMENT 8.1 Changes in Basic Services 8.1.1 Changes in the Basic Services and entitlement to additional compensation or a change in duration of this Agreement shall be made by a written Amendment to this Agreement executed by the County and the Consultant. The Consultant shall proceed to perform the Services required by the Amendment only after receiving a fully executed Amendment from the County. ARTICLE 9 TERMINATION 9.1 Termination for Convenience of the County 9.1.1 This Agreement may be terminated without cause by the County and for its convenience upon seven(7) days prior written notice to the Consultant. 9.2 Other Termination 9.2.1 The Consultant may terminate this Agreement based upon the County's material breach of this Agreement; provided the County has not taken all reasonable actions to remedy the breach. The Consultant shall give the County seven (7) days' prior written notice of its intent to terminate this Agreement for cause. 9.3 Compensation After Termination 9.3.1 In the event of termination, the Consultant shall be paid that portion of the fees and expenses that it has earned to the date of termination, less any costs or expenses incurred or anticipated to be incurred by the County due to errors or omissions of the Consultant. 9.3.2 Should this Agreement be terminated, the Consultant shall deliver to the County within seven (7) days, at no additional cost, all Deliverables including any electronic data or files relating to the Project. 9.4 Waiver Revised 10/17 4 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A 9.4.1 The payment of any sums by the County under this Agreement or the failure of the County to require compliance by the Consultant with any provisions of this Agreement or the waiver by the County of any breach of this Agreement shall not constitute a waiver of any claim for damages by the County for any breach of this Agreement or a waiver of any other required compliance with this Agreement. 9.5 Suspension 9.5.1 County may suspend the work at any time for County's convenience and without penalty to County upon three (3) days' notice to Consultant. Upon any suspension by County, Consultant shall discontinue the work and shall not resume the work until notified to proceed by County. ARTICLE 10 ADDITIONAL PROVISIONS 10.1 Relationship of Parties 10.1.1 Consultant is an independent contractor of the County. Neither Consultant nor any employee of the Consultant shall be deemed an officer, employee or agent of the County. Consultant's personnel shall not be employees of, or have any contractual relationship with, the County. 10.2 Limitation and Assignment 10.2.1 The County and the Consultant each bind themselves, their successors, assigns, and legal representatives to the terms of this Agreement. Neither the County nor the Consultant shall assign or transfer its interest in this Agreement without the written consent of the other. 10.3 Governing Law 10.3.1 This Agreement and the duties, responsibilities, obligations and rights of respective parties hereunder shall be governed by the laws of the State of North Carolina. Consultant shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal anti-discrimination laws, policies, rules, and regulations and the Orange County Non-Discrimination Policy and Orange County Living Wage Policy (each policy is incorporated herein by reference and may be viewed at http://www.orangecountVnc.gov/departments/purchasing division/contracts.php). Any violation of this requirement is a breach of this Agreement and County may immediately terminate this Agreement without further obligation on the part of the County. This paragraph is not intended to limit the definition of breach to discrimination. By executing this Agreement Consultant affirms that Consultant and any subcontractors of Consultant are and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. Where applicable, failure to maintain compliance with the requirements of Article 2 of Chapter 64 of the General Statutes constitutes Consultant's breach of this Agreement. By executing this Agreement Consultant affirms Consultant is in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement, Consultant certifies that Consultant has not been identified, and has not utilized the services of any agent or subcontractor, on the Iran divestment list created by the State Treasurer pursuant to G.S. 147- 86.58 and the Israel boycott list created pursuant to G.S. 147-86.81. Revised 10/17 5 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A 10.4 Dispute Resolution 10.4.1 Any and all suits or actions to enforce, interpret or seek damages with respect to any provision of, or the performance or non-performance of, this Agreement shall be brought in the General Court of Justice of North Carolina sitting in Orange County, North Carolina and it is agreed by the parties that no other court shall have jurisdiction or venue with respect to such suits or actions. The Parties may agree to nonbinding mediation of any dispute prior to the bringing of such suit or action. Under no circumstances shall any dispute be addressed through binding arbitration. 10.5 Extent of Agreement 10.5.1 This Agreement, together with the Request for Proposals together with attachments distributed by the County and the Consultant's submitted Proposal, all of which constitute the Contract Documents, represents the entire and integrated agreement between the County and the Consultant and supersedes all prior negotiations, representations or agreements, either written or oral. In the event of a conflict among the terms of the Contract Documents, the priority of documents shall be This Agreement, the County's Request for Proposals, attachments to the County's Request for Proposals, the Consultant's Proposal. This Agreement may be amended only by written instrument signed by both parties. Modifications may be evidenced by facsimile signatures. 10.6 Severability 10.6.1 If any provision of this Agreement is held as a matter of law to be unenforceable, the remainder of this Agreement shall be valid and binding upon the Parties. 10.7 Ownership of Deliverables 10.7.1 All Deliverables, together with all supporting materials, source documentation, data collected, field notes, and working drafts, developed in the performance of this Agreement shall become the property of the County and may be used on any other project without additional compensation to the Consultant. The use of the Deliverables by the County or by any person or entity for any purpose other than the Project as set forth in this Agreement shall be at the full risk of the County. 10.8 Non-Appropriation 10.8.1 Consultant acknowledges that County is a governmental entity, and the validity of this Agreement is based upon the availability of public funding under the authority of its statutory mandate. In the event that public funds are unavailable and not appropriated for the performance of County's obligations under this Agreement, then this Agreement shall automatically expire without penalty to County immediately upon written notice to Consultant of the unavailability and non-appropriation of public funds. It is expressly agreed that County shall not activate this non-appropriation provision for its convenience or to circumvent the requirements of this Agreement,but only as an emergency fiscal measure during a substantial fiscal crisis. Revised 10/17 6 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A In the event of a change in the County's statutory authority, mandate and/or mandated functions, by state and/or federal legislative or regulatory action, which adversely affects County's authority to continue its obligations under this Agreement, then this Agreement shall automatically terminate without penalty to County upon written notice to Consultant of such limitation or change in County's legal authority. 10.9 Notices and Signatures 10.9.1 This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with Article 11A and Article 40 of North Carolina General Statute Chapter 66. 10.9.2 Any notice required by this Agreement shall be in writing and delivered by certified or registered mail, return receipt requested to the following: Orange County Consultant's Name &Address Attention: Kimbelee Quatrone Health Ascent Associates, LLC P.O. Box 8181 238 Trout Lily Lane Hillsborough,NC 27278 Pittsboro,NC 27312 [SIGNATURE PAGE TO FOLLOW] Revised 10/17 7 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have hereunder set their hands and seal, all as of the day and year first above written. COUNTY: Orange County CONSULTANT: Health Ascent Associates, LLC DocuSigned by: OocuSigned by: E66WAA, 0637994B755E477... 5A3MAME80146A... County Manager Dr. Dorothy Cilenti, Owner Printed Name and Title Revised 10/17 8 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ("Agreement") is made effective the 20`h day of November, 2017, by and between Orange County Government through its Orange County Health Department ("Covered Entity"), and Health Ascent Associates, LLC, ("Business Associate"). Covered Entity and Business Associate may be referred herein individually as a"Party" or collectively as the "Parties". This Agreement supersedes any previously executed Business Associate Agreement between the Parties. WITNESSETH: WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), Public Law 104-191, as modified by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), Public Law 111-5, known as "the Administrative Simplification provisions," direct the Department of Health and Human Services to develop standards to protect the security, confidentiality and integrity of health information; and WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human Services ("Secretary") has issued regulations modifying the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from time to time(the"HIPAA Security and Privacy Rule"); and WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangements, Business Associate may be considered a"Business Associate" of Covered Entity as defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred to as the"Service Agreement(s)"); and WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in fulfilling its responsibilities under such arrangement; THEREFORE, in consideration of the Parties' continuing obligations under the Service Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect the interests of both Parties. 1. DEFINITIONS (a) Service Agreement. Agreement(s) for services affected by this HIPAA Business Associate Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby incorporated by reference, and which shall be taken and considered as a part of this document the same as if fully set out herein: Health Ascent—Coaching (b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule,45 CFR Parts 160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended,the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule,the provisions of this Agreement shall control. (c) Electronic Protected Health Information. Protected Health Information that is transmitted by or maintained in Electronic Media(as defined in the HIPAA Security and Privacy Rule). 1 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A (d) Protected Health Information. "Protected Health Information" shall have the same meaning as the term in 45 CFR § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity and includes without limitation "Electronic Protected Health Information." Business Associate acknowledges and agrees that all Protected Health Information that is created or received by Covered Entity and disclosed or made available in any form, including paper record, oral communication, audio recording, and electronic display by Covered Entity or its operating units to Business Associate or is created or received by Business Associate on Covered Entity's behalf shall be subject to this Agreement. (e) Required by Law. "Required by Law" shall have the same meaning as the term in 45 CFR§ 164.103. Il. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE (a) Use and Disclosure. Business Associate agrees to fully comply with the requirements under the HIPPA Security and Privacy Rule applicable to Business Associates and not to use or disclose Protected Health Information other than as permitted or required by this Agreement, the Service Agreement or as Required by Law. To the extent Business Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. Business Associate agrees to comply with Covered Entity's policies regarding the minimum necessary use or disclosure of Protected Health Information. (b) Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of Protected Health Information other than as provided for by this Service Agreement(s), this Agreement or as Required by Law. This includes the implementation physical, technical and administrative safeguards to prevent use or disclosure of Protected Health Information other than as permitted in this Agreement or Required by Law and reasonably and appropriately protect the confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with the HIPPA Security and Privacy Rule, including, but not limited to, its policies, procedures, records of training and sanctions of members in its workforce. (c) Assurances. Business Associate agrees to provide Covered Entity with written assurances that any Protected Health Information placed on any type of mobile media, including, but by no means limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with guidance issued by the Secretary. (d) Agents and Subcontractors. Business Associate shall require any agents, including any subcontractors, to whom it provides Protected Health Information from Covered Entity that is created, received, maintained or transmitted on behalf of Business Associate to agree by written contract with Business Associate to the same (or greater) restrictions, conditions and requirements that apply to Business Associate with respect to such information, and to agree to implement reasonable and appropriate safeguards to protect any of such information that is Electronic Protected Health Information. In addition, Business Associate agrees to take reasonable steps to ensure that its employees' actions or omissions do not cause Business Associate to breach the terms of this Agreement. (e) Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement, as well as to provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate such 2 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A noncompliance or Security Incident. Business Associate shall cooperate in Covered Entity's breach analysis and/or risk assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the event that Covered Entity determines that any third parties must be notified of a Breach,provided that Business Associate shall not provide any such notification except at the direction of Covered Entity. (f) Breach Reporting. Business Associate shall report in writing to Covered Entity's Privacy Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance with the terms of this Agreement, as well as any Security Incident and any actual or suspected Breach, of which it becomes aware, without unreasonable delay, and in no event later than forty-eight (48) hours of such discovery. For purposes of this Agreement, "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Such notification shall contain the elements required by 45 C.F.R. § 164.410. (g) Compliance. To the extent applicable, Business Associate will comply with (i) Covered Entity's Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual's permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to agree. (h) Government Access. Business Associate will make its internal practices, books and records available to the Secretary of the Department of Health and Human Services for purposes of determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations and compliance reviews, permit access to information, and cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event, no more than 48 hours of receipt of the request or notification, Business Associate will notify Covered Entity in writing of any request by any governmental entity, or its designee, to review Business assessment of any kind. (i) Electronic Transactions. If Business Associate conducts any Standard Transactions for or on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic Transaction Rule. 0) Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an audit of Business Associate's compliance with this Agreement, HIPAA, and HITECH. Such audit may consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate shall promptly and completely respond to Covered Entity's requests for information in support of the audit, which shall not be conducted more than once annually except in cases of an actual or reasonably suspected Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or HITECH. Each Party shall bear its own costs associated with the audit. (k) Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies and Procedures to protect any patient information that may be breached by the Business Associate to the extent applicable under the Federal Trade Commission's Red Flag Rules. (1) HITECH Compliance. Business Associate shall: A. Not receive, directly or indirectly, any impermissible remuneration in exchange for Protected Health Information or Electronic Protected Health Information, except as permitted by HITECH § 13405(d) or the HIPPA Regulations; B. Comply with the marketing and other restrictions applicable to Business Associates contained in HITECH § 13406 and the HIPPA Regulations; 3 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A C. To the extent required under HITECH § 13404, fully comply with the applicable requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected Health Information; D. To the extent required under HITECH § 13401, fully comply with 45 CFR §§ 164.308, 164.310, 164.312, and 164.316; E. To the extent required under HITECH §§13401 and 13404, comply with the additional privacy and security requirements that apply to Covered Entities in the same manner and to the same extent as Covered Entity is required to do so; and F. To the extent required under the HIPPA Regulations, comply with the privacy and security requirements that apply to Business Associates. (m) State Privacy Laws. Business Associate shall understand and comply with state privacy laws to the extent that such privacy laws are not preempted by HIPPA or HITECH. III. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE (a) Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities or services for, or on behalf of, Covered Entity described in the Service Agreement, provided that such use or disclosure would not violate the HIPPA Security and Privacy Rule if it were made by Covered Entity or would not violate the Covered Entities minimum necessary policies. (b) Other Uses of Protected Health Information. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information within its workforce for the proper management and administration of Business Associate not to include Marketing or Commercial Use and to carry out the legal responsibilities of Business Associate; and (c) Third Party Confidentiality. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that if Business Associate discloses any Protected Health Information to a third party for such purpose, the Business Associate shall enter into a written agreement with such third party requiring the following: A. Disclosure only as Required by Law; or B. Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality, integrity, and or availability of the Protected Health Information has been breached immediately upon becoming aware. (d) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity pursuant to any agreements between the Parties evidencing their business relationship as permitted by 45 CFR§ 164.504(e)(2)(i)(B). (e) Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business Associate to share Protected Health Information with Business Associate's affiliates or contractors except for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s) identified in Section I(a) of this Agreement. 4 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A (f) Covered Entity Authorization for Additional Uses. Any use of Protected Health Information by Business Associate, its affiliate or Contractor, other than those purposes of this Agreement, shall require express written authorization by the Covered Entity, and a Business Associate Agreement or amendment as necessary. Activities which are prohibited include, but are not limited to, Marketing, as defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed by Covered Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal or state laws. (g) Business Associate may de-identify Protected Health Information only at the specific direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health Information except at the direction of Covered Entity and in compliance with the requirements of the HIPAA Security and Privacy Rule. IV. AVAILABILITY OF PHI (a) Access to Protected Health Information. Business Associate agrees, in the event the Business Associate maintains protected health information in a Designated Record Set, to make available, within ten (10) days of a request by Covered Entity in a time and manner designated by Covered Entity, Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security and Privacy Rule. (b) Amendments to Protected Health Information. In the event that the Business Associate maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make any amendment(s) to Protected Health Information in a designated record set that the Covered Entity directs or agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of an individual,within ten(10) days of receipt of a request from Covered Entity and in the time and manner designated by Covered Entity. (c) Accounting of Disclosures. Business Associate agrees to maintain and make available the information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the HIPAA Security and Privacy Rule. Business Associate will comply with Covered Entity's policy regarding accounting of disclosures. (d) Document Disclosures. In the event an Individual makes a request under this Section of the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such request within three (3) business days and shall cooperate with, and act only at the direction of Covered Entity in responding to such request. V. OBLIGATIONS OF COVERED ENTITY (a) Notice of Privacy Practices. Covered Entity shall provide Business Associate with the notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as any changes to that notice. (b) Notice of Changes in Individual's Access or Protected Health Information. Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, is such changes affect Business Associate's permitted or required uses. (c) Notice of Restriction in Individual's Access to Protected Health Information. Covered Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such restriction may affect Business Associate's use of Protected Health Information. 5 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A VI. PERMISSABLE REQUESTS BY COVERED ENTITY Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy or Security Rule. VII. TERMINATION (a) Term. This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the termination by Covered Entity for cause as provided herein. (b) Termination for Cause. Notwithstanding anything in this Agreement to the contrary, Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately if Covered Entity determines that Business Associate has or will violated any material term of this Agreement. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall provide an opportunity for Business Associate to cure the breach or end the violation. Covered Entity may terminate this Agreement if Business Associate does not cure the breach or end the violation within the time period specified by Covered Entity. If termination, cure or end of the violation is not feasible, Covered Entity may report the violation to the Secretary. (c) Obligation of Business Associate Upon Termination. At termination of this Agreement, the Service Agreement(or any similar documentation of the business relationship of the Parties), or upon request of Covered Entity,whichever occurs first,Business Associate, shall: A. if feasible,return (in a manner or process approved by the Covered Entity) or destroy all Protected Health Information, regardless of form, including but not limited to paper or electronic format, received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity. Business Associate shall retain no copies of the Protected Health Information. This provision shall also apply to Protected Health Information and other confidential information in the possession of sub-contractors or agents of Business Associate. B. If such return or destruction is not feasible, Business Associate shall (i) retain only that Protected Health Information necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities; (ii) return or destroy the remaining Protected Health Information that the Business Associate still maintains in any form; (iii)extend the protections of this Agreement to the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or destruction of the Protected Health Information not feasible; and (v) return or destroy the retained Protected Health Information when it is no longer needed by Business Associate. (d) Survival. This paragraph shall survive the termination of this Agreement and shall apply to Protected Health Information created, maintained, or received by Business Associate and any of its subcontractors. VIII. MISCELLANEOUS (a) Indemnification. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims, losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur by reason of Business Associate's breach of or failure to perform any its obligations pursuant to this 6 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A Agreement, including but not limited to any injury or damages arising from any noncompliance with this Agreement or any Security Incident attributable to the negligence of Business Associate, including failure to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, employees, contractors and agents, against all costs and expenses, including but not limited to, reasonable legal expenses, which are incurred by or on behalf of Business Associate in connection with the defense of such claims. (b) Disclaimer. Covered Entity makes no warranty or representation that compliance by Business Associate with this Agreement, HIPAA,HITECH, or the HIPAA Regulations will be adequate or satisfactory for Business Associate's own purposes. Business Associate is solely responsible for all decisions made by Business Associate regarding the safeguarding of Protected Health Information. (c) Assistance in Litigation or Administrative Proceedings. Business Associate shall make itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the performance of its obligations under this Agreement, available to Covered Entity, at no cost to Covered Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being commenced against Covered Entity, its directors, officers or employees based upon a claimed violation of HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy, except where Business Associate or its subcontractor, employee or agent is named adverse party. (d) Survival. The obligations of Business Associate under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business relationship of the parties, and shall continue to bind Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein. (e) Ownership of Information. Covered Entity holds all right, title, and interest in and to the Protected Health Information and Business Associate does not hold and will not acquire by virtue of this Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or to the PHI or any portion thereof. (f) Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that the breach, or threatened breach,by it of any provision of this Agreement may cause Covered Entity to be irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore, Business Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek injunctive relief to prevent Business Associate from commencing or continuing any action constituting such breach without having to post a bond or other security and without having to prove the inadequacy of any other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other remedy available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties. (g) Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPSS Regulations. In addition, this Agreement may be amended or modified by the Parties only in writing. (h) Assignment. No Party may assign its respective rights and obligations under this Agreement without the prior written consent of the other Party. (i) Independent Contractor. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any relationship between the Parties other than that of independent parties contracting with each other solely for the purposes of effecting the provisions of this Agreement and any other agreements between the Parties evidencing their business relationship. This Agreement will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any 7 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion. 0) Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH or the HIPAA Regulations means the section as it currently is in effect or as amended. (k) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event that any documentation of the arrangement pursuant to which Business Associate provides services to Covered Entity contains provisions relating to the use or disclosure of Protected Health Information that are more restrictive than the provisions of this Agreement, the more restrictive provisions will control. The provisions of this Agreement are intended to establish the minimum requirements regarding Business Associate's use and disclosure of Protected Health Information. (1) Severability. In the event any part or parts of this Agreement are held to be unenforceable, the remainder of this Agreement will continue in effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to (30) thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty-day period, a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to terminate upon written notice to the other party. (m) Notices and Communications. All instructions, notices, consents, demands, or other communications required or contemplated by this Agreement shall be in writing and shall be delivered to the Party at the address below: For Covered Entity: For Business Associate Orange County Health Department Health Ascent Associates, LLC 300 W. Tryon Street 238 Trout Lily Lane Hillsborough,NC 27278 Pittsboro,NC 27312 (n) Strict compliance. No failure by any Party to insist upon strict compliance with any terms or provisions of this Agreement, to exercise any option,to enforce any right, or to seek any remedy upon any default of any other Party shall affect, or constitute a waiver of, any Party's right to insist upon such strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that default or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at variance with any provisions of this Agreement shall affect, or constitute a waiver of, any Party's right to demand strict compliance with all provisions of this Agreement. (o) Governing Law. This Agreement shall be governed and construed in accordance with the laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County, North Carolina, for purposes of litigation resulting from disagreements of the Parties for purposes of this Agreement and the Service Agreement(s). (p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract with governmental units. E-Verify is a Federal program operated by the United States Department of Homeland Security and other federal agencies, or any successor or equivalent program used to verify the work authorization of newly hired employees pursuant to federal law. Where applicable, failure to maintain compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General Statutes shall constitute breach of this Agreement. If applicable, by executing this Agreement, Business 8 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A Associate affirms that they are in compliance with Article 3 of Chapter 64 if the North Carolina General Statutes. IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above. COX rnnnr%ni.rrrrv. $U OocuSignedby: _ DocuSigned by, B 06375946755E477... By•. 6A37BAME80946A... Title: County Manager Title: Owner 9 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A EXHIBIT A COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with the terms of this Agreement that might be considered a privacy breach, Business Associate should contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident(as defined in the Agreement), Business Associate should contact Carla Julian(919)245-2434,or the Security Officer at The Orange County Health Department. 10 October 2013 DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A w ISSUE DATE November 28,2017 c PRODUCP-R �ON Is cElrflrWATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND coNlrERs NO RIGHTS "THEIR CERT]FICATT�:HOLDER. 'TEAS CERTIFICATE.DOES NOT AMEND,EXTEND OR ALTER E COVBRAGL AFFORDED BY THE POLICIES BELOW. The Snowden Company PO Box 5319 COMPANIES AFFORDING COVERAGE Florence, South Carolina 29502-5319 t7C)MPANY A Markel Insurance Company I ETTER I INSURED OMPANY R >ETTI R HEALTH ASCENTS ASSOCIATES, LLC gOMPANY C 238 TROUT LILY LAME FETTER PITTSBORO NC 27312 QCLVIPANY D iETTER OMPANY E I.,ETTER THIS IS TO CERTIFY THAT POLICIES OF INSURANCE(IISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR. THE POLICY PERIOD INDICATED, NOTWITHSTAND G ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH'THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN. THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED I-II'REIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS, AND CONDITIONS OF SUCH POLICIES. CO TYPE OF TNSTIRANCE POLICYNUMBER POLICYSFI'ECTTVE PbLIC1 EXPIRATION ALL LIMITS 1N THOUSANDSLIRA ! A"47 '8 IN' "J"YY) DATE"(Mill GENERAL LIABILITY OEiNERAf.ACOREGA'Il CO[vfA'f1:RCl lL GENERAL LIAR lL1TY PRODUCTS-COMPIOPS AGGREGATE £LA€III NIADE F—] OCCURRENCE O PERSONAL m ADVE'KI'ISiNG INJURY I OWNER'S&CONTRACTORS FROTECTi VE i EACH OCCURSNCE ��. FIRE DAMAGE(ANY ONE FIRE) Il nIMICAL ESPYNSC(-ANY ONC PCR&]N7 AUTOMOBILE LIAIIILrry CSL ANY AUTO ALL OWNED AUTOS j BODILY INJURY SaFEDUI.ED AUTOS (P PERSON) $ HIRED AUTOS BODILY [Ni NON-OWNED AUTOS (PLR $ I Al GARAGE LIABILITY rRowrRTY DAMAGE $ EXCESS LIABILITY EACH AGCRE OCCURRENCE LATE $ $ OTHER THAN UMBRELLA FORM STATUTORY WORKERS'COMPENSATION � $ (VACHACI AND $ (DISEASE-POI ICY LIi EMPLOYERS' LIABILITY � $ (DISEASE-EACH E-NmI.oYERI A OTHER M680616 11/28/2017 11/28/2018 LIMITS, $1,000,000 Each Claim Professional liability $3,000,000 Aggregate DESCRIPTION OF OPERATION S/LOCATION S/VEII CLES/RESTRICTIONS/SPECIAL ITEMS; Dorothy Cilenti and Health Ascent Associates, LLC is provided professional liabilityi coverage within the scope of contract services provided to the Orange County Health Department, Retro Date: 11/28/2017 SHOULD ANY OF TIiH ABOVF. DESCRIBED POLICES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF, THE ISSUING COMPANY WILL ENDEAVOR 1.0 MAIL 10 DAYS WR1lTEh NOTICE TO THF. CERTIFICATE HOLDER NAMED TO THr Lrrr, BUT FAILURE'TO MAIL SUM NOTICE Si IMPOSE NO OBLIGATION OR LIABILTTY 01, NY ORANGE COUNTY HEALTH DEPARTMENT KIND CohtP.AN)',ITS Al OR REPRE,>ENTA'lvas 300 W. TRYON STREET AUTHORIZED REPRESENTATIVE � HILLSBOROUGH,NC 27278 TERREE 1, SNOWDEN, CPC�t7 r i DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A M r i-I NORTH CAROLINA FARM BUREAU MUTUAL INSURANCE COMPANY PART B DECLARATION PAGE P.O.BOX 27427 RALEIGH,NORTH CAROLINA 27611-7427 PERSONAL AUTO POLICY POLICY RENEWAL DECLARATION - COVERAGE WILL EXPIRE ON 08/22/17 IF PREMIUM IS NOT PAID. e >' r6 - APM 8388077 08/22/17 02/22/18 2125827 APM DECL 0515 0195880 MA S. .....:.._ ......... DOROTHY CILENTI 238 TROUT LILY LN PITTSBORO, NC 27312-8483 DENISE MARTIN, FSCP TELE : (919) 542-2142 PO BOX 1030 j1 e- g ( PITTSBORO, NC 2 312 VEHICLES COVERED TYPE SYMBOL STATED ...........:.... VEH ZIPCD YR MAKE VEH...SERIAL NUMBER CMP\COL OCN AMT. CLA SDIP 001 R7312 05 TYTA CAMRY BASE PP 4T1BE32K35U576607 11\11 1B 00 002 27312 10 NSSN ROGUE S AW PP JN8AS5MV8AW117183 14\14 1.A 00 003 27312 12 TYTA RAV4 PP JTMZF4DV7C5047035 18\18 1B 02 INSURANCE IS PROVIDED WHERE A PREMIUM IS SHOWN FOR THE COVERAGE . COVERAGE LIMITS OF LIABILITY PREMIUMS UNIT 1 2 3 A BODILY INJURY $ 100 , 000 EA PERSON $300 , 000 EA ACC 83 . 66 78 . 66 83 . 66 A PROPERTY DAMAGE $50 , 000 EACH ACCIDENT 59 . 66 56 . 66 59 . 66 D OTHER THAN COLLISION $ 100 DEDUCTIBLE 49 . 00 58 . 00 70 . 00 D COLLISION 0500 DEDUCTIBLE 134 . 00 155. 00 TOTAL BY UNIT 192. 32 327 . 32 368. 32 C2 UNINS/UNDERINS MTR BI $ 100 ,000 EA PER $300 ,000 EA AC $64. 00 UNINSURED MOTORIST - PROPERTY DAMAGE $50 ,000 $4. 00 TOTAL TERM PREMIUM $955 . 96 THIS PREMIUM REFLECTS A FARM BUREAU DISCOUNT FOR THE FOLLOWING: PREMIER -MULTICAR POLICY -PROPERTY COVERAGE WITH FARM BUREAU -FULL PAY PLAN PROTECTION PLUS DRIVER ID DRIVER NAME 01 DOROTHY CILENTI 02 LUCAS GRIFFIN 03 OLIVIA GRIFFIN - ----------------------------------------------------------------------- PLEASE i�E1ll Yfll POCKY IlCLttATON -Aft I*fJLII;Yivr I PQVSI [S IAEFULLY CF)NTCT -YOUR AGENT I YI)U SAVE ANY !.:::.:.............::::::::. . .::.:: QUESTIONS 0 CHANGES �.- i ! WE APPRECIATE YOUR BUSINESS. i i rE ri r ,. r DocuSign Envelope ID:92EFA578-CE94-4EDA-BAE5-D7664F2BE88A NORTH CAROL INA FARM BUREAU MUTUAL INSURANCE COMPANY PART B DECLARATION PAGE P.O.BOX 27427 RALEIGH,NORTH CAROLINA 27611-7427 PERSONAL AUTO POLICY POLICY RENEWAL DECLARATION — COVERAGE WILL EXPIRE ON 08/22/17 IF PREMIUM IS NOT PAID. �a� PIQA #E�a£ tT € E PC}LI .NUkBE . .:: ora......: Yt�...::. fstHIP N APM 8388077 08/22/17 02/22/18 2125827 APM DECL 0515 0195880 NS H-,:,p ADD;:`" 13OD,.; ... :::. ...... F%4�a;E . .......:- DOROTHY CILENTI 238 TROUT LILY LN PITTSBORO, NC 27312-8483 DENISE MARTIN, FSCP TELE : (919) 542-2142 PO BOX 1030 1 PITTSBORO, NC 27312 APPLICABLE FORMS FORM ; DATE UNIT FORM # DATE UNIT FORM # DATE UNIT FORM # DATE UNIT APMNC 01/10 ALL NCO301 07/87 ALL NCO013 04/16 ALL LOSS PAYEE — UNIT 002 LOSS PAYEE — UNIT 003 SECU SECU PO BOX 27528 PO BOX 27528 RALEIGH , NC 27611-7528 RALEIGH , NC 27611-7528 DESC: 2010 NSSN ROGUE S AW DESC: 2012 TYTA RAV4 OTHER POLICIES FOR MEMBERSHIP NUMBER 2125827 : POLICY INSURED NAME HP 6294526 DOROTHY CILENTI -------------------------------------------------- i i I