Loading...
HomeMy WebLinkAbout2017-655 Health - UNC School of Medicine MOU for FIT programMEMORANDUM OF UNDERSTANDING BETWEEN ORANGE COUNTY HEALTH DEPARTMENT AND THE DEPARTMENT OF FAMILY MEDICINE WITHIN SCHOOL OF MEDICINE AT UNC- CHAPEL HILL THIS MEMORANDUM OF UNDERSTANDING ( "MOU "), made as of October 1, 2017, is by and between The University of North Carolina at Chapel Hill, for its Department of Family Medicine in the School of Medicine ( "UNC ") and Orange County North Carolina, a body politic and corporate, by and through its Orange County Health Department ( "OCHD "). WHEREAS, UNC runs a program titled the Formerly Incarcerated Transition ( "FIT ") program, which includes in its public service mission assisting former inmates with a successful reentry into the community after release from incarceration; WHEREAS, the FIT Program, though its UNC- employed medical director, Dr. Evan Ashkin ( "Physician ") has identified one significant barrier to successful re -entry as transitioning former inmates' health care to community providers and assuring access to and continuity of care; WHEREAS, UNC has recently received a grant from The Duke Endowment ( "TDE ") to pilot expansion of the FIT program in the community setting; WHEREAS, OCHD provides care coordination, service navigation, and nonclinical education through its employed Community Health Worker and desires to receive advisory services from UNC in its implementation of a FIT program at OCHD, with ongoing peer to peer guidance from Physician to its Community Health Worker and other relevant OCHD staff, in furtherance of facilitating proper care coordination and integrated service delivery to such clients; WHEREAS, UNC through Physician desires to provide such peer to peer care coordination and integrated service delivery guidance to OCHD, and assist OCHD with continuous quality improvement of the FIT program through the analysis of data assessing the performance of OCHD's FIT program and its impact on the health outcomes of OCHD's clients, each of which are consistent with the public service mission of the overall FIT program and the educational mission of UNC; and WHEREAS, this MOU will address the services and data sharing associated with implementation and continuous quality improvement of the FIT program at DCPDH, including as may relate to the TDE grant, but is separate and apart from (i) any sub -award with funding to OCHD that UNC's Office of Sponsored Research may issue for OCHD's participation in the TDE grant; and/or (ii) any separate documentation of the patties potential participation or collaboration in IRB- approved research relating to the FIT Program; including because the services and associated data sharing outlined in this MOU are intended to continue irrespective of the existence of the TDE grant, unless otherwise terminated as set forth herein; NOW, THEREFORE in consideration of the following mutual promises, covenants, and conditions, UNC and OCHD agree as follows: {00102384.DOCX} 1. Scope of Engagement. In furtherance of its public service mission, UNC agrees to provide, through the services of Physician, (i) instruction on the implementation of a FIT program at OCHD; (ii) periodic peer to peer guidance in a case conference setting to OCHD's Community Health Worker regarding facilitation and coordination of care for FIT program clients who are served by OCHD; and (iii) data analysis and feedback to OCHD on the performance and outcomes of its FIT Program in furtherance of continuous quality improvement of the program. OCHD acknowledges and agrees that Physician's services are limited and discrete in nature, do not involve the review or development of specific treatment plans for FIT program clients, and that as between the parties hereto, OCHD retains full authority and responsibility for the care and treatment of its patients, including FIT program clients. 2. Insurance. UNC agrees to provide professional liability self - insurance coverage for itself and Physician in amounts not less than $1,000,000 per occurrence and $3,000,000 annual aggregate. OCHD agrees to provide or assure professional liability coverage for itself and its health care professionals or other staff engaged in the performance of this MOU in amounts sufficient to cover its obligations hereunder. 3. No Compensation, No Referrals. The parties acknowledge and agree that there will be no compensation from OCHD to UNC for the services provided by Physician to OCHD pursuant to this MOU. The parties acknowledge and intend that this arrangement is in furtherance of their respective public service missions. The parties further acknowledge and agree that (1) clients of the FIT program who are patients of OC14D and the subject of the care coordination guidance contemplated in this MOU will remain patients of OCHD, as applicable; (2) neither party intends to induce or reward the referral of any item or service for which payment may be made in whole or in part under any governmental healthcare program; and (3) this arrangement is not entered into on the basis of any determination that takes into account the volume or value of referrals or business otherwise generated between the parties. 4. HIPAA. Since the provision of (i) advisory services for the implementation of the FIT Program; (ii) ongoing peer to peer care coordination guidance; and (iii) data analysis in support of OCI °ID's healthcare operations of assuring continuous quality improvement of its FIT Program necessarily require the use and disclosure of OCHD- maintained protected health information ( "PHI "), as defined under the Health Insurance Portability and Accountability Act of 1996 (as amended), to UNC, including information on FIT program participants' healthcare utilization, access and outcomes, the parties agree, concurrent with the execution of this MOU, to execute the Business Associate Agreement attached hereto as Attachment 1. OCHD further acknowledges and agrees that UNC may additionally report to TDE on the performance of OCHD's FIT Program; provided, however, that all such reports shall be fully de- identified within the meaning of HIPAA. The parties also acknowledge and agree that UNC shall not collect, use or disclose any PHI of OCHD's clients for a research purpose unless (i) such research is IRB- approved; and (ii) the individual whose information is to be collected, used and /or disclosed (including to potential third party research collaborators) has first given his or her individual HIPAA authorizations in a form approved by the IRB. 5. Term. This MOU shall run from October 1, 2017 to September 30. 2018, and may be renewed thereafter by written agreement of the parties. {00102384.DOCX} h. Termination. This MOU may be terminated at any time without penalty by either party provided that written notice of such termination is furnished to the other party at least thirty (30) days prior to termination, except in the event of a material breach, in which case the non - breaching party shall have the right to terminate the agreement immediately upon notice to the breaching party. This provision may be waived in certain circumstances by written agreement of the parties. 7. Merger; Waiver. This MOU represents the entire agreement of UNC and OCHD with respect to the subject. matter hereof; and is separate and apart from any sub -award that may be entered into between UNC and OCHD with respect to funding under the TDE grant. Any waiver by UNC or OCHD of a breach of any provision of this MOU shall not be deemed to be a waiver of any preceding or subsequent breach of the same or any other provision. 8. Amendment. This MOU shall not be amended except through a mutual written agreement executed by duly authorized representatives of the parties hereto. 9. Assignment. Neither party may assign this MOU to a third party without the prior written consent of the other; any assignment in contravention of this provision shall be void. 10. Governing Law. The laws of the State of North Carolina shall govern the validity and interpretation of the terms and conditions of this MOU. REMAINDER OF PAGE INTENTIONALLY LEI T BLANK 00102 -84.DOCX IN WITNESS WHEREOF, the parties haVe hereunto signed this MOU in their official capacities on the day and year listed first listed above. THE UNIVERSITY OF NORTH CAROLINA AT ORANGE COUNTY HEALTH DEPARTMENT CHAPEL HILL William L. Roper, MD, MPI -I G?QMt0Lna S5- WWa(+ Dean, School of Medicine Iffteri Health Director Vice Chan -ell r jforl-lalth Affairs Orange County Health Department Matthew A, Mauro. MD, FACR, FSIR, FAHA CEO, UNC Faculty Physicians ,00102384.DOCX} ATTACHMENT 1 BUSINESS ASSOCIATE AGREEMENT This Agreement is made effective the I" of October 2017, by and between Orange County Government through its Orange County Health Department, hereinafter referred to as "Covered Entity ", and The University of North Carolina at Chapel Hill, on behalf of its Department of Family Medicine in the School of Medicine, hereinafter referred to as "Business Associate ", (individually, a "Party" and collectively, the "Parties "). This Agreement supersedes any previously executed Business Associate Agreement between the parties. WITNESSETH: WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability Act of 1996, Public Law 104 -191, as modified by the Health Information Technology for Economic and Clinical Health Act, known collectively as "the Administrative Simplification provisions," direct the Department of Health and Human Services to develop standards to protect the security, confidentiality and integrity of health information; and WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human Services has issued regulations at 45 CPR Parts 160 and 164, as the same may be amended fi-om time to time (the "HIPAA Security and Privacy Rule "); and WHEREAS, the Parties, contemporaneously with the signing of this Agreement, have entered into an arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangement, Business Associate may be considered a "business associate" of Covered Entity as defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is hereby referred to as the "Arrangement Agreement "); and WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in fulfilling its responsibilities under such arrangement; THEREFORE, in consideration of the Parties' continuing obligations under the Arrangement Agreement, .compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this Agreement in order to address the requirements of the IIIPAA Security and Privacy Rule and to protect the interests of both Parties. 1. DEFINITIONS Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are different from those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule, the provisions of this Agreement shall control. The term "Protected Health Information" means individually identifiable health information including, without limitation, all information, data, documentation, and materials, including without limitation, demographic, medical and financial information, that relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or {00102384.DOCX} future payment for the provision of health care to an individual; and that identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual. "Protected Health Information" includes without limitation "Electronic Protected Health Information" as defined below. The term "Electronic Protected Health Information- means Protected Health Information that is transmitted by Electronic Media (as defined in the I- 1111AA Security and Privacy Rule) or maintained in Electronic Media. II. PERMITTED USES AND DISCLOSURES (a) Business Associate may use or disclose Protected Health Information only as permitted or required by this Agreement or as required by law. Except as specifically set forth herein, Business Associate may not use or disclose Protected Health Information in a manner that would violate the HIPAA Security and Privacy Rule if such use or disclosure were done by Covered Entity. Specifically, Business Associate may use or disclose Protected Health Information (l) for meeting its obligations as set forth in any agreements between the Parties evidencing their business relationship, including the Arrangement Agreement, or (2) as required by applicable law, rule or regulation, or by an accrediting or credentialing organization to whom Covered Entity is required to disclose such information, or (3) as otherwise permitted under this Agreement, the Arrangement Agreement (if consistent with this Agreement and the HIPAA Security and Privacy Rule), or the HIPAA Security and Privacy Rule, or (4) as would be permitted by the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. (b) Business Associate may de- identify Protected Health Information only at the specific direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health Information except at the direction of Covered Entity and in compliance with the requirements of the I II PAA Security and Privacy Rule. (c) Notwithstanding the prohibitions set forth in this Agreement, (i) Business Associate may use Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate; (ii) Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that as to any such disclosure, the following requirements are met: (A) The disclosure is required by law; or (B) Business Associate obtains reasonable assurances from the person to whcnn the information is disclosed that the information will remain confidential and will be used or further disclosed only as required by law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached; (iii) Business Associate may provide data aggregation services relating to the health care operations of Covered Entity pursuant to any agreements between the Parties evidencing their business relationship. For purposes of this Agreement, data aggregation means the combining of Protected Health Information by Business Associate with the Protected Health Information received by Business Associate in its capacity as a business associate of another covered entity, to permit data analyses that relate to the health care operations of the respective covered entities. (00102384.DOCX) CONFIDENTIALITY AND SECURITY REOUIREMENTS (a) Business Associate agrees not to use or disclose Protected Health Information other than as permitted or required by this Agreement or as required by law. To the extent Business Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule that apply to Covered Entity in the performance of such obligation. Covered Entity will not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the HIPAA Security and Privacy Rule if done by Covered Entity, except as otherwise provided herein. Business Associate agrees to comply with Covered Entity's policies regarding the minimum necessary use or disclosure of Protected Health Information, provided such policies are furnished in advance in writing to Business Associate. (b) At termination of this Agreement, the Arrangement Agreement (or any similar documentation of the business relationship of the Parties), if feasible, Business Associate will return or destroy all Protected Health Information received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form. If such return or destruction is not feasible, Business Associate will (i) retain only that Protected Health Information necessary under the circumstances; (ii) return or destroy the remaining Protected Health Information that the Business Associate still maintains in any form; (iii) extend the protections of this Agreement to the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or destruction of the Protected Health Information not feasible; and (v) return or destroy the retained Protected Health Information when it is no longer needed by Business Associate. This paragraph shall survive the termination of this Agreement and shall apply to Protected Health Information created, maintained, or received by Business Associate. (c) Business Associate agrees to ensure that its agents, including any subcontractors, that create, receive, maintain or transmit Protected Health Information of Covered Entity on behalf of Business Associate agree to the same (or greater) restrictions and conditions that apply to Business Associate with respect to such information, and agree to implement reasonable and appropriate safeguards to protect any of such information that is Electronic Protected Health information. Business Associate agrees to enter into written agreements with any subcontractors to the extent required by the HIPAA Security and Privacy Rule. (d) Business Associate will implement appropriate safeguards to prevent use or disclosure of Protected Health Information other then as permitted in this Agreement. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy Rule. (e) To the extent such information is provided in advanced by Covered Entity, and to the extent that such information would affect Business Associate's use /disclosure of Protected Health Information, Business Associate will comply with (i) Covered Entity's Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual's permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to agree. (f) Business Associate will make its internal practices, books and records available to the Secretary of the Department of Health and Human Services for purposes of determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations {00102384.DOCX} and compliance reviews, permit access to information, and cooperate with any complaints, as required by law. (g) Business Associate shall report to Covered Entity (see Attachment A) any use or disclosure of Protected Health Information that is not in compliance with the terms of this Agreement, as well as any successful or pattern of unsuccessful Security Incident(s) and /or Breach(es) of unsecured Protected Health Information, of which it becomes aware, without unreasonable delay. Security Incidents and Breaches shall be treated as discovered by Business Associate as of the first day on which such Security Incident or Breach is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate. For purposes of this Agreement, "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. As to any Breach(es) of unsecured Protected Health Information, such notification shall contain the elements required by 45 C.F.R. § 164.410. IV. AVAILABILITY OF PI -11 (a) Business Associate agrees to make available Protected Health InfOrmatimi in a Designated Record Set to Covered Entity to the extent and in the manner required by Section 164.524 of the HIPAA Security and Privacy Rule. (b) Business Associate agrees to make available Protected Health Information in a Designated Record Set to Covered Entity for amendment and to incorporate any amendments to Protected Health Information in accordance with the requirements of Section 164.526 of the HIPAA Security and Privacy Rule and at the direction of Covered Entity. (c) Business Associate agrees to nnaimain and male available the information required for Covered Entity to provide an accounting of disclosures, as required by Section 161.528 of tlic 141PAA Security and Privacy Rule. (d) Business Associate agrees to comply with any requests by Covered Entity for restriction on certain disclosures of Protected Health Information pursuant to Section 164.522 of the HIPAA Security and Privacy Rule to which Covered Entity has agreed and of which Business Associate is notified by Covered Entity. (e) In the event an Individual makes a request under this Section IV directly to Business Associate, Business Associate will noti[ }r Covered Entity in writing of such request so that Covered Entity may respond to such request. V. TERMINATION This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the termination by either party for cause as provided herein. Notwithstanding anything in this Agreement to the contrary, each party shall have the right to terminate this Agreement and the Arrangement Agreement immediately if such party determines that the other party has violated any material term of this Agreement and the other party has not cured the breach or ended the violation within thirty (30) days of receipt of written notification of such violation from the notifying party. Notwithstanding anything in this Agreement to the contrary, Business Associate shall have the right to terminate this Agreement and the Arrangement Agreement immediately if Covered Entity agrees to restrictions on the use or disclosure of Protected Health Information that materially affect Business Associate's ability to perform or the cost of Business Associate's performance under this Agreement or the Arrangement Agreement. {00102384.DOCX} VI. MISCELLANEOUS Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties. The obligations of the parties under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the Arrangement Agreement and/or the business relationship of the parties, and shall continue to bind the parties, their agents, employees. contractors, successors, and assigns as set forth herein. This Agreement may be amended or modified only in a writing signed by the Parties. No Party may assign its respective rights and obligations under this Agreement without the prior written consent of the other Party. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any relationship between the Parties other than that of independent parties contracting with each other solely for the purposes of effecting the provisions of this Agreement and any other agreements between the Parties evidencing their business relationship. This Agreement will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion. In the event that any provision of this Agreement is held by a court of competent jurisdiction to be invalid or unenforceable, the remainder of the provisions of this Agreement will remain in full force and effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with the then - current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty -day period, a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to terminate upon written notice to the other party. IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above. COVERED ENTITY: BUSINESS ASSOCIATE: By: r By: qL&L koo for Title: '(�� � �JI if-u OIL _ Title: Will L—Ro x-j• I Dean, School of Medicine Vice Chancellor for Medical Affairs {00102384.DOCX} ATTACHMENT A CONTACT INFORMATION To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with the terms of this Agreement that might be considered a privacy breach, Business Associate should contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident (as defined in the Agreement), Business Associate should contact Carla Julian (919) 245 -2434, or the Security Officer at The Orange County Health Department. {00102 384.DUCX}