HomeMy WebLinkAbout2017-655 Health - UNC School of Medicine MOU for FIT programMEMORANDUM OF UNDERSTANDING BETWEEN
ORANGE COUNTY HEALTH DEPARTMENT
AND
THE DEPARTMENT OF FAMILY MEDICINE
WITHIN SCHOOL OF MEDICINE AT UNC- CHAPEL HILL
THIS MEMORANDUM OF UNDERSTANDING ( "MOU "), made as of October 1, 2017, is
by and between The University of North Carolina at Chapel Hill, for its Department of Family Medicine
in the School of Medicine ( "UNC ") and Orange County North Carolina, a body politic and corporate, by
and through its Orange County Health Department ( "OCHD ").
WHEREAS, UNC runs a program titled the Formerly Incarcerated Transition ( "FIT ") program,
which includes in its public service mission assisting former inmates with a successful reentry into the
community after release from incarceration;
WHEREAS, the FIT Program, though its UNC- employed medical director, Dr. Evan Ashkin
( "Physician ") has identified one significant barrier to successful re -entry as transitioning former
inmates' health care to community providers and assuring access to and continuity of care;
WHEREAS, UNC has recently received a grant from The Duke Endowment ( "TDE ") to pilot
expansion of the FIT program in the community setting;
WHEREAS, OCHD provides care coordination, service navigation, and nonclinical education
through its employed Community Health Worker and desires to receive advisory services from UNC in
its implementation of a FIT program at OCHD, with ongoing peer to peer guidance from Physician to its
Community Health Worker and other relevant OCHD staff, in furtherance of facilitating proper care
coordination and integrated service delivery to such clients;
WHEREAS, UNC through Physician desires to provide such peer to peer care coordination and
integrated service delivery guidance to OCHD, and assist OCHD with continuous quality improvement
of the FIT program through the analysis of data assessing the performance of OCHD's FIT program and
its impact on the health outcomes of OCHD's clients, each of which are consistent with the public
service mission of the overall FIT program and the educational mission of UNC; and
WHEREAS, this MOU will address the services and data sharing associated with
implementation and continuous quality improvement of the FIT program at DCPDH, including as may
relate to the TDE grant, but is separate and apart from (i) any sub -award with funding to OCHD that
UNC's Office of Sponsored Research may issue for OCHD's participation in the TDE grant; and/or (ii)
any separate documentation of the patties potential participation or collaboration in IRB- approved
research relating to the FIT Program; including because the services and associated data sharing outlined
in this MOU are intended to continue irrespective of the existence of the TDE grant, unless otherwise
terminated as set forth herein;
NOW, THEREFORE in consideration of the following mutual promises, covenants, and
conditions, UNC and OCHD agree as follows:
{00102384.DOCX}
1. Scope of Engagement. In furtherance of its public service mission, UNC agrees to provide,
through the services of Physician, (i) instruction on the implementation of a FIT program at
OCHD; (ii) periodic peer to peer guidance in a case conference setting to OCHD's
Community Health Worker regarding facilitation and coordination of care for FIT program
clients who are served by OCHD; and (iii) data analysis and feedback to OCHD on the
performance and outcomes of its FIT Program in furtherance of continuous quality
improvement of the program. OCHD acknowledges and agrees that Physician's services are
limited and discrete in nature, do not involve the review or development of specific treatment
plans for FIT program clients, and that as between the parties hereto, OCHD retains full
authority and responsibility for the care and treatment of its patients, including FIT program
clients.
2. Insurance. UNC agrees to provide professional liability self - insurance coverage for itself and
Physician in amounts not less than $1,000,000 per occurrence and $3,000,000 annual
aggregate. OCHD agrees to provide or assure professional liability coverage for itself and its
health care professionals or other staff engaged in the performance of this MOU in amounts
sufficient to cover its obligations hereunder.
3. No Compensation, No Referrals. The parties acknowledge and agree that there will be no
compensation from OCHD to UNC for the services provided by Physician to OCHD
pursuant to this MOU. The parties acknowledge and intend that this arrangement is in
furtherance of their respective public service missions. The parties further acknowledge and
agree that (1) clients of the FIT program who are patients of OC14D and the subject of the
care coordination guidance contemplated in this MOU will remain patients of OCHD, as
applicable; (2) neither party intends to induce or reward the referral of any item or service for
which payment may be made in whole or in part under any governmental healthcare
program; and (3) this arrangement is not entered into on the basis of any determination that
takes into account the volume or value of referrals or business otherwise generated between
the parties.
4. HIPAA. Since the provision of (i) advisory services for the implementation of the FIT
Program; (ii) ongoing peer to peer care coordination guidance; and (iii) data analysis in
support of OCI °ID's healthcare operations of assuring continuous quality improvement of its
FIT Program necessarily require the use and disclosure of OCHD- maintained protected
health information ( "PHI "), as defined under the Health Insurance Portability and
Accountability Act of 1996 (as amended), to UNC, including information on FIT program
participants' healthcare utilization, access and outcomes, the parties agree, concurrent with
the execution of this MOU, to execute the Business Associate Agreement attached hereto as
Attachment 1. OCHD further acknowledges and agrees that UNC may additionally report to
TDE on the performance of OCHD's FIT Program; provided, however, that all such reports
shall be fully de- identified within the meaning of HIPAA. The parties also acknowledge and
agree that UNC shall not collect, use or disclose any PHI of OCHD's clients for a research
purpose unless (i) such research is IRB- approved; and (ii) the individual whose information
is to be collected, used and /or disclosed (including to potential third party research
collaborators) has first given his or her individual HIPAA authorizations in a form approved
by the IRB.
5. Term. This MOU shall run from October 1, 2017 to September 30. 2018, and may be
renewed thereafter by written agreement of the parties.
{00102384.DOCX}
h. Termination. This MOU may be terminated at any time without penalty by either party
provided that written notice of such termination is furnished to the other party at least thirty
(30) days prior to termination, except in the event of a material breach, in which case the
non - breaching party shall have the right to terminate the agreement immediately upon notice
to the breaching party. This provision may be waived in certain circumstances by written
agreement of the parties.
7. Merger; Waiver. This MOU represents the entire agreement of UNC and OCHD with
respect to the subject. matter hereof; and is separate and apart from any sub -award that may
be entered into between UNC and OCHD with respect to funding under the TDE grant. Any
waiver by UNC or OCHD of a breach of any provision of this MOU shall not be deemed to
be a waiver of any preceding or subsequent breach of the same or any other provision.
8. Amendment. This MOU shall not be amended except through a mutual written agreement
executed by duly authorized representatives of the parties hereto.
9. Assignment. Neither party may assign this MOU to a third party without the prior written
consent of the other; any assignment in contravention of this provision shall be void.
10. Governing Law. The laws of the State of North Carolina shall govern the validity and
interpretation of the terms and conditions of this MOU.
REMAINDER OF PAGE INTENTIONALLY LEI T BLANK
00102 -84.DOCX
IN WITNESS WHEREOF, the parties haVe hereunto signed this MOU in their official capacities on the
day and year listed first listed above.
THE UNIVERSITY OF NORTH CAROLINA AT ORANGE COUNTY HEALTH DEPARTMENT
CHAPEL HILL
William L. Roper, MD, MPI -I G?QMt0Lna S5- WWa(+
Dean, School of Medicine Iffteri Health Director
Vice Chan -ell r jforl-lalth Affairs Orange County Health Department
Matthew A, Mauro. MD, FACR, FSIR, FAHA
CEO, UNC Faculty Physicians
,00102384.DOCX}
ATTACHMENT 1
BUSINESS ASSOCIATE AGREEMENT
This Agreement is made effective the I" of October 2017, by and between Orange County
Government through its Orange County Health Department, hereinafter referred to as "Covered Entity ",
and The University of North Carolina at Chapel Hill, on behalf of its Department of Family Medicine in the
School of Medicine, hereinafter referred to as "Business Associate ", (individually, a "Party" and collectively,
the "Parties "). This Agreement supersedes any previously executed Business Associate Agreement between
the parties.
WITNESSETH:
WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability
Act of 1996, Public Law 104 -191, as modified by the Health Information Technology for Economic and
Clinical Health Act, known collectively as "the Administrative Simplification provisions," direct the
Department of Health and Human Services to develop standards to protect the security, confidentiality and
integrity of health information; and
WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and
Human Services has issued regulations at 45 CPR Parts 160 and 164, as the same may be amended fi-om time
to time (the "HIPAA Security and Privacy Rule "); and
WHEREAS, the Parties, contemporaneously with the signing of this Agreement, have entered into an
arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to
such arrangement, Business Associate may be considered a "business associate" of Covered Entity as
defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is hereby
referred to as the "Arrangement Agreement "); and
WHEREAS, Business Associate may have access to Protected Health Information (as defined below)
in fulfilling its responsibilities under such arrangement;
THEREFORE, in consideration of the Parties' continuing obligations under the Arrangement
Agreement, .compliance with the HIPAA Security and Privacy Rule, and other good and valuable
consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the
provisions of this Agreement in order to address the requirements of the IIIPAA Security and Privacy Rule
and to protect the interests of both Parties.
1. DEFINITIONS
Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions
set forth in the HIPAA Security and Privacy Rule. In the event of an inconsistency between the provisions of
this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA
Security and Privacy Rule shall control. Where provisions of this Agreement are different from those
mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security
and Privacy Rule, the provisions of this Agreement shall control.
The term "Protected Health Information" means individually identifiable health information including,
without limitation, all information, data, documentation, and materials, including without limitation,
demographic, medical and financial information, that relates to the past, present, or future physical or mental
health or condition of an individual; the provision of health care to an individual; or the past, present, or
{00102384.DOCX}
future payment for the provision of health care to an individual; and that identifies the individual or with
respect to which there is a reasonable basis to believe the information can be used to identify the individual.
"Protected Health Information" includes without limitation "Electronic Protected Health Information" as
defined below.
The term "Electronic Protected Health Information- means Protected Health Information that is transmitted
by Electronic Media (as defined in the I- 1111AA Security and Privacy Rule) or maintained in Electronic
Media.
II. PERMITTED USES AND DISCLOSURES
(a) Business Associate may use or disclose Protected Health Information only as permitted or required
by this Agreement or as required by law. Except as specifically set forth herein, Business Associate may not
use or disclose Protected Health Information in a manner that would violate the HIPAA Security and Privacy
Rule if such use or disclosure were done by Covered Entity. Specifically, Business Associate may use or
disclose Protected Health Information (l) for meeting its obligations as set forth in any agreements between
the Parties evidencing their business relationship, including the Arrangement Agreement, or (2) as required
by applicable law, rule or regulation, or by an accrediting or credentialing organization to whom Covered
Entity is required to disclose such information, or (3) as otherwise permitted under this Agreement, the
Arrangement Agreement (if consistent with this Agreement and the HIPAA Security and Privacy Rule), or
the HIPAA Security and Privacy Rule, or (4) as would be permitted by the HIPAA Security and Privacy
Rule as if such use or disclosure were made by Covered Entity.
(b) Business Associate may de- identify Protected Health Information only at the specific direction of and
only for the use of Covered Entity. Business Associate may not sell Protected Health Information except at
the direction of Covered Entity and in compliance with the requirements of the I II PAA Security and Privacy
Rule.
(c) Notwithstanding the prohibitions set forth in this Agreement,
(i) Business Associate may use Protected Health Information for the proper management and
administration of Business Associate or to carry out the legal responsibilities of Business Associate;
(ii) Business Associate may disclose Protected Health Information for the proper management
and administration of Business Associate or to carry out the legal responsibilities of Business Associate,
provided that as to any such disclosure, the following requirements are met:
(A) The disclosure is required by law; or
(B) Business Associate obtains reasonable assurances from the person to whcnn the
information is disclosed that the information will remain confidential and will be used or
further disclosed only as required by law or for the purpose for which it was disclosed to the
person, and the person notifies Business Associate of any instances of which it is aware in
which the confidentiality of the information has been breached;
(iii) Business Associate may provide data aggregation services relating to the health care
operations of Covered Entity pursuant to any agreements between the Parties evidencing their business
relationship. For purposes of this Agreement, data aggregation means the combining of Protected Health
Information by Business Associate with the Protected Health Information received by Business Associate in
its capacity as a business associate of another covered entity, to permit data analyses that relate to the health
care operations of the respective covered entities.
(00102384.DOCX)
CONFIDENTIALITY AND SECURITY REOUIREMENTS
(a) Business Associate agrees not to use or disclose Protected Health Information other than as permitted
or required by this Agreement or as required by law. To the extent Business Associate carries out
obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply
with the applicable provisions of the HIPAA Security and Privacy Rule that apply to Covered Entity in the
performance of such obligation. Covered Entity will not request Business Associate to use or disclose
Protected Health Information in any manner that would not be permissible under the HIPAA Security and
Privacy Rule if done by Covered Entity, except as otherwise provided herein. Business Associate agrees to
comply with Covered Entity's policies regarding the minimum necessary use or disclosure of Protected
Health Information, provided such policies are furnished in advance in writing to Business Associate.
(b) At termination of this Agreement, the Arrangement Agreement (or any similar
documentation of the business relationship of the Parties), if feasible, Business Associate will return or
destroy all Protected Health Information received from Covered Entity, or created, maintained or received by
Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form. If such
return or destruction is not feasible, Business Associate will (i) retain only that Protected Health Information
necessary under the circumstances; (ii) return or destroy the remaining Protected Health Information that the
Business Associate still maintains in any form; (iii) extend the protections of this Agreement to the retained
Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or
destruction of the Protected Health Information not feasible; and (v) return or destroy the retained Protected
Health Information when it is no longer needed by Business Associate. This paragraph shall survive the
termination of this Agreement and shall apply to Protected Health Information created, maintained, or
received by Business Associate.
(c) Business Associate agrees to ensure that its agents, including any subcontractors, that create,
receive, maintain or transmit Protected Health Information of Covered Entity on behalf of Business
Associate agree to the same (or greater) restrictions and conditions that apply to Business Associate with
respect to such information, and agree to implement reasonable and appropriate safeguards to protect any of
such information that is Electronic Protected Health information. Business Associate agrees to enter into
written agreements with any subcontractors to the extent required by the HIPAA Security and Privacy Rule.
(d) Business Associate will implement appropriate safeguards to prevent use or disclosure of Protected
Health Information other then as permitted in this Agreement. Business Associate will implement
administrative, physical, and technical safeguards that reasonably and appropriately protect the
confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates,
receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy
Rule.
(e) To the extent such information is provided in advanced by Covered Entity, and to the extent that such
information would affect Business Associate's use /disclosure of Protected Health Information, Business
Associate will comply with (i) Covered Entity's Notice of Privacy Practices; (ii) any limitations to which
Covered Entity has agreed in regard to an Individual's permission to use or disclose his or her Protected
Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to
which Covered Entity has agreed or is required to agree.
(f) Business Associate will make its internal practices, books and records available to the Secretary of
the Department of Health and Human Services for purposes of determining compliance with the terms of the
HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations
{00102384.DOCX}
and compliance reviews, permit access to information, and cooperate with any complaints, as required by
law.
(g) Business Associate shall report to Covered Entity (see Attachment A) any use or disclosure of
Protected Health Information that is not in compliance with the terms of this Agreement, as well as any
successful or pattern of unsuccessful Security Incident(s) and /or Breach(es) of unsecured Protected Health
Information, of which it becomes aware, without unreasonable delay. Security Incidents and Breaches shall
be treated as discovered by Business Associate as of the first day on which such Security Incident or Breach
is known to Business Associate or, by exercising reasonable diligence, would have been known to Business
Associate. For purposes of this Agreement, "Security Incident" means the attempted or successful
unauthorized access, use, disclosure, modification, or destruction of information or interference with system
operations in an information system. As to any Breach(es) of unsecured Protected Health Information, such
notification shall contain the elements required by 45 C.F.R. § 164.410.
IV. AVAILABILITY OF PI -11
(a) Business Associate agrees to make available Protected Health InfOrmatimi in a Designated Record
Set to Covered Entity to the extent and in the manner required by Section 164.524 of the HIPAA Security
and Privacy Rule.
(b) Business Associate agrees to make available Protected Health Information in a Designated Record
Set to Covered Entity for amendment and to incorporate any amendments to Protected Health Information in
accordance with the requirements of Section 164.526 of the HIPAA Security and Privacy Rule and at the
direction of Covered Entity.
(c) Business Associate agrees to nnaimain and male available the information required for Covered
Entity to provide an accounting of disclosures, as required by Section 161.528 of tlic 141PAA Security and
Privacy Rule.
(d) Business Associate agrees to comply with any requests by Covered Entity for restriction on certain
disclosures of Protected Health Information pursuant to Section 164.522 of the HIPAA Security and Privacy
Rule to which Covered Entity has agreed and of which Business Associate is notified by Covered Entity.
(e) In the event an Individual makes a request under this Section IV directly to Business Associate,
Business Associate will noti[ }r Covered Entity in writing of such request so that Covered Entity may respond
to such request.
V. TERMINATION
This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i)
the termination of all agreements between the parties, and (ii) the termination by either party for cause as
provided herein. Notwithstanding anything in this Agreement to the contrary, each party shall have the right
to terminate this Agreement and the Arrangement Agreement immediately if such party determines that the
other party has violated any material term of this Agreement and the other party has not cured the breach or
ended the violation within thirty (30) days of receipt of written notification of such violation from the
notifying party. Notwithstanding anything in this Agreement to the contrary, Business Associate shall have
the right to terminate this Agreement and the Arrangement Agreement immediately if Covered Entity agrees
to restrictions on the use or disclosure of Protected Health Information that materially affect Business
Associate's ability to perform or the cost of Business Associate's performance under this Agreement or the
Arrangement Agreement.
{00102384.DOCX}
VI. MISCELLANEOUS
Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement
do not intend to create any rights in any third parties. The obligations of the parties under this Agreement
shall survive the expiration, termination, or cancellation of this Agreement, the Arrangement Agreement
and/or the business relationship of the parties, and shall continue to bind the parties, their agents, employees.
contractors, successors, and assigns as set forth herein.
This Agreement may be amended or modified only in a writing signed by the Parties. No Party may assign
its respective rights and obligations under this Agreement without the prior written consent of the other
Party. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any
relationship between the Parties other than that of independent parties contracting with each other solely for
the purposes of effecting the provisions of this Agreement and any other agreements between the Parties
evidencing their business relationship. This Agreement will be governed by the laws of the State of North
Carolina. No change, waiver or discharge of any liability or obligation hereunder on any one or more
occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit
enforcement of any obligation, on any other occasion.
In the event that any provision of this Agreement is held by a court of competent jurisdiction to be invalid or
unenforceable, the remainder of the provisions of this Agreement will remain in full force and effect. In
addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with
the then - current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other
party in writing. For a period of up to thirty days, the parties shall address in good faith such concern and
amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty -day period,
a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule,
then either party has the right to terminate upon written notice to the other party.
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above.
COVERED ENTITY: BUSINESS ASSOCIATE:
By: r By: qL&L
koo for
Title: '(�� � �JI if-u OIL _ Title: Will L—Ro x-j•
I
Dean, School of Medicine
Vice Chancellor for Medical Affairs
{00102384.DOCX}
ATTACHMENT A
CONTACT INFORMATION
To report to Covered Entity any use or disclosure of Protected Health Information not in compliance
with the terms of this Agreement that might be considered a privacy breach, Business Associate should
contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident (as
defined in the Agreement), Business Associate should contact Carla Julian (919) 245 -2434, or the
Security Officer at The Orange County Health Department.
{00102 384.DUCX}