HomeMy WebLinkAbout2022-247-E-Health-ROBERT DUPUIS-PHARMACY SERVICESRevised 6/21
1
[Departmental Use Only]
TITLE Pharmacy Services
FY 2022-2023
ORANGE COUNTY
CONTRACT FOR PHARMACY SERVICES AT
OCHD- DUPUIS
NORTH CAROLINA
THIS AGREEMENT, made and entered into this 30th day of June, 2022, (“Effective Date”) by and
between Orange County, North Carolina, a body politic and corporate organized under the laws of the State of
North Carolina, (the "County"), party of the first part; and Robert E. Dupuis (the "Provider"), party of the
second part;
W I T N E S S E T H:
For the purpose and subject to the terms and conditions hereinafter set forth, the County hereby
contracts for the services of the Provider, and the Provider agrees to provide the following services to the
County in accordance with the terms of this Agreement, time being of the essence:
The term of this agreement shall be from July 1, 2022 to June 30, 2023.
Provider represents and agrees that Provider is qualified to perform and fully capable of performing and
providing the services required or necessary under this Agreement in a fully competent, professional and timely
manner to the satisfaction of the County. Provider shall be responsible for all errors or omissions, in the
performance of the Agreement. Provider shall correct any and all errors, omissions, discrepancies, ambiguities,
mistakes or conflicts at no additional cost to the County. Provider agrees that Provider shall not sub-contract
any of the services to be provided in this Agreement, nor shall Provider assign any right or responsibility
granted or required by this Agreement, without the prior written approval of the County.
SPECIFIC TERMS
1. Scope of Services. The services and/or materials (hereinafter referred to collectively as
“Services”) to be furnished under this Agreement are as follows:
A. Provider.
1) Scope of Work. Direct Pharmacy Services at the two pharmacy sites of the Health
Department as provided in Attachment A, Scope of Work.
2) Confidentiality. The Contractor agrees to sign the OCHD Personal Health Services
Division Confidentiality Agreement and Business Associate Agreement, and agrees
to maintain confidentiality per these Agreements. The Contractor will comply with
such confidentiality laws as may be applicable in the performance of these
agreements and acknowledges that in receiving, storing, processing or otherwise
dealing with any confidential information, Contractor will safeguard and not further
disclose the information except as permitted by the Health Insurance Portability and
Accountability Act of 1996, Public Law 104-191, as amended.
3) Licensure. The Contractor agrees to maintain North Carolina Pharmacy License and
to present proof of such license.
B. Orange County Health Department.
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
Revised 6/21
2
1) Designate a nursing supervisor to provide guidance and assistance with related
administrative or technical aspects of providing pharmacy services at Health
Department sites as requested.
2) Participate in the ongoing evaluation of the role of the pharmacist and provide an
annual evaluation of pharmacist’s performance of contract.
3) Enable the pharmacist to perform all activities mandated by laws, regulations and
standards.
4) Obtain required pharmacy licenses for all sites.
5) Allow the pharmacist to participate in other related activities in the Health Department
as agreed to by both parties
6) Comply with such non-discrimination laws and/or employment practices as may be
applicable in fulfilling this contract.
2. Payment: The County agrees to pay at the rates specified for Services satisfactorily performed in
accord with this Agreement. The amount to be paid by the County shall not exceed Twelve Thousand Six
Hundred Forty Five dollars, ($12,645). Payment shall be made in twelve (12) equal installments of One
Thousand Fifty-Three and 75/100 dollars ($1,053.75) within thirty (30) days of an invoice properly submitted
to County. Should Provider fail to perform its duties under the terms of this Agreement, County may, without
fault or penalty, withhold any payment associated with the work to be performed until such time as said work
is completed.
3. Non–waiver: Failure by County at any time to require the performance by Provider of any of
the provisions hereof shall in no way waive or affect the County's right hereunder to enforce the same, nor
shall any waiver by the County of any breach be held to be a waiver of any succeeding breach or a waiver of
this Non-Waiver Clause.
4. Independent Contractor: The Provider shall operate as an independent Provider, and the
County shall not be responsible for any of the Provider’s acts or omissions. The Provider shall not be treated
as an employee with respect to the Services performed hereunder for federal or state tax, unemployment or
workers' compensation purposes. The Provider understands that neither federal, nor state, nor payroll tax of
any kind shall be withheld or paid by the County on behalf of the Provider or the employees of the Provider.
The Provider understands that no benefits, including Worker’s Compensation coverage, will be provided to
him by the County.
5. Insurance.
A. General Requirements. The Provider shall purchase and maintain during the period of
performance of this Agreement Professional Liability Insurance, covering personal injury,
bodily injury and property damage and claims arising out of or related to the performance
under this Agreement by the Provider.
B. Limits of Coverage. The Provider shall maintain professional liability insurance coverage
with coverage of at least $1 million, per occurrence, $3 million aggregate while providing
services to the County.
C. Evidence of Insurance. Evidence of such insurance shall be furnished to the County,
together with evidence that each policy provides the County with not less than thirty (30)
days prior written notice of any cancellation, non-renewal or reduction of coverage.
6. Indemnity: The Provider agrees to defend, indemnify, and hold harmless Orange County from
all losses, liabilities, claims, demands, suits, costs, damages or expenses (including reasonable attorney's fees)
arising from bodily injury, including death, to any person or persons or damage to or destruction of any
property caused in whole or in part by any negligent or intentional act or omission on the part of the Provider.
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
Revised 6/21
3
7. Termination: This Agreement may be terminated at any time without cause by either Party
upon sixty (60) days written notice. This agreement may be terminated with cause at any time by either party
upon at least 30 days prior written notice to the other party upon default of one or more of its obligations
hereunder, unless such default is cured within 30 days of the notice of termination.
8. Entire Agreement: The parties have read this Agreement and agree to be bound by all of its
terms, and further agree that it constitutes the complete and exclusive statement of the Agreement between the
parties unless and until modified in writing and signed by the parties. Modifications may be evidenced by
telefacsimile signature.
9. Governing Law: This Agreement and the duties, responsibilities, obligations and rights of
respective parties hereunder shall be governed by the laws of the State of North Carolina. Provider shall at all
times remain in compliance with all applicable local, state, and federal laws, rules, and regulations and the
Orange County Non-Discrimination Policy and Orange County Living Wage Policy (each policy is
incorporated herein by reference and may be viewed at
http://www.orangecountync.gov/departments/purchasing_division/contracts.php). Any violation of this
requirement is a breach of this Agreement and County may immediately terminate this Agreement without
further obligation on the part of the County. This paragraph is not intended to limit and does not limit the
definition of breach to discrimination. By executing this Agreement Provider affirms that Provider and any
subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter 64 of the North
Carolina General Statutes. By executing this Agreement Provider certifies that Provider has not been
identified, and has not utilized the services of any agent or subcontractor, on the list created by the State
Treasurer pursuant to G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not
been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by
the State Treasurer pursuant to G.S. 147-86.81.
10. Non Appropriation: Provider acknowledges that County is a governmental entity, and the
validity of this Agreement is based upon the availability of public funding under the authority of its statutory
mandate. In the event that public funds are unavailable and not appropriated for the performance of County’s
obligations under this Agreement, then this Agreement shall automatically expire without penalty to County
immediately upon written notice to Provider of the unavailability and non-appropriation of public funds.
11. Signature: This Agreement together with any amendments or modifications may be executed
electronically. All electronic signatures affixed hereto evidence the intent of the Parties to comply with Article
11A and Article 40 of North Carolina General Statute Chapter 66.
12. Priority: In determining the basic services to be provided, should any documents be referenced
in this Agreement, the terms herein shall have priority in any conflict between the terms of referenced
documents and the terms of this Agreement, except the Business Associate Agreement.
[SIGNATURES ON FOLLOWING PAGE]
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
Revised 6/21
4
IN WITNESS WHEREOF, Orange County and the Provider have signed this Agreement, effective
as of the day first written above.
ORANGE COUNTY PROVIDER
By: _________________________ By: _________________________
Bonnie Hammersley., County Manager Robert E. Dupuis, Pharm.D, BCPS
200 S. Cameron St. 205 Kenilworth Place
P.O. Box 8181 Chapel Hill, NC 27516
Hillsborough, NC 27278
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
Revised 6/21
5
ORANGE COUNTY—DEPARTMENT USE ONLY
______________________________________________________________________________
Party/Vendor Name: ROBERT DUPUIS Party/Vendor Contact Person: ROBERT DUPUIS Contact Phone: 919-966-
4131 Party/Vendor Address: 205 KENIL WORTH PLACE City CHAPEL HILL State: NC Zip: 27516 Department:
HEALTH Amount: $12,645 Purpose: PHARMACY SERVICES Budget Code(s): 10414020-630000/programs Vendor
# 47361 (N/A if new vendor) Vendor is a BOCC consultant? Yes No Contract Type: (Check one) New
Renewal Amendment Effective Date 7/1/2022 Approved by Board Yes No Agenda Date: 6-21-22 --- For
Section XIV. c. contracts only, Approved by Board in Current FY Budget Yes No
This agreement is approved as to technical form and content and I as Department Director affirmatively state work on
this project has not been initiated prior to execution of the agreement:
Department Director’s Signature ________________________________________ Date: ________
Agreements for emergency services or repair are not subject to the above affirmation. If services related to this
agreement have already begun or been completed please briefly describe the nature of the emergency condition that was
addressed:
Information Technologies
(Applicable only to hardware/software purchases or related services) This agreement has been reviewed and is
approved as to information technology content and specifications:
Office of the Chief Information Officer___________________________________ Date: ________
Risk Management
This agreement is approved for sufficiency of insurance standards, specifications, and requirements:
Office of the Risk Management Officer___________________________________ Date: _________
Financial Services
This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control Act:
Office of the Chief Financial Officer ____________________________________ Date: _________
Legal Services
This agreement is approved as to legal form and sufficiency:
Office of the County Attorney __________________________________________Date: ________
Clerk to the Board
Received for record retention:
All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov
The following signature block is for hard copies only and is not required for Docusign contracts:
Office of the Clerk to the Board __________________________________________Date:_________
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
6/30/2022
6/30/2022
6/30/2022
7/1/2022
Attachment A - Pharmacy Contract July 1, 2022– June 30, 2023
PHARMACY SERVICES
Scope of Work
Scope of Services for the Agreement between Robert E. Dupuis and Orange County by and
through the Orange County Health Department for Pharmacy Services effective, July 1, 2022 and
shall terminate on June 30, 2023. It is understood that the Contractor will provide direct
pharmacy services at the two pharmacy sites of the Health Department.
I. The Contractor to provide the following Services:
.
A. Administrative Duties
1. Assist in the development of written policies and procedures for legal,
safe and effective drug therapy, distribution, control and use.
2. Work with the Department pharmacy nurse in:
a. Developing and maintaining a formulary
b. Evaluating and improving procedures for drug procurement,
storage, packaging and labeling
3. Work with the Department Assurance Nurse in the Medication Assistance
Program (MAP) in:
a. Verifying correct drug and dosage sent by drug companies
b. Splitting drugs as requested by clinician
c. Labeling drugs
d. Notifying Assurance Nurse when drugs are ready for dispensing
4. Oversee all activities related to the operation of the pharmacies at the
Hillsborough Whitted Center and Chapel Hill Southern Human Services
Center.
5. Prepare and submit a quarterly report reviewing pharmacy activities and
related issues.
6. Prepare and submit an annual report summarizing pharmacy activities
and accomplishments for the current year and goals/plans for the next
year.
7. Assist the Clinical Services Nursing Supervisor in budget preparation for
pharmaceuticals and related supplies, when requested.
8. Assist the Clinical Services Nursing Supervisor in acquiring
pharmaceuticals in a cost-efficient manner.
9. Evaluate and improve therapeutics within the Health Department.
10. Provide pharmacy training for new public health nurses and nurse
practitioners.
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
Attachment A - Pharmacy Contract July 1, 2022– June 30, 2023
11. Evaluate pharmaceutical software for Health Department pharmacy
functions as requested by the Division Director.
12. To the extent the Contractor keeps records, the Contractor agrees to
make all such records available to the Department for auditing, reporting
or any other purpose deemed necessary by the Department.
B. Drug Distribution:
1. Prepack stock formulary pharmaceuticals adhering to pharmacy law
requirements and ensuring maintenance of adequate prepacked
supplies.
2. Label medications received through the Medication Assistance Program
(MAP).
3. Review dispensing logs at all Health Department sites weekly.
4. Review dispensing logs within 24 hours when more than 30 prescriptions
have been distributed.
5. Maintain the drug distribution system in compliance with all laws,
regulations and standards.
6. Provide drug information on an on-call basis when needed by staff.
7. Assist with the development and/or the procurement of necessary drug
information/patient education materials to include information in
languages other than English when needed.
8. Be available to directly dispense medications not approved for public
health nurse dispensing in times of communicable disease outbreaks.
9. Review at least 3 clinical charts from each site monthly, comparing them
to the dispensing log for accuracy and completeness. Document
findings in the “OCHD Pharmacy Quality Assurance Indicator, Chart
Review” log.
10. Complete pharmacy incident report on all errors and forward to the
Clinical Nursing Supervisor for development of corrective actions.
11. Comply with such non-discrimination laws and/or employment practices
as may be applicable in fulfilling this contract.
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
1
October 2013
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement (“Agreement”) is made effective the first day of July, 2022,
by and between Orange County Government through its Orange County Health Department (“Covered
Entity”), and Robert E. Dupuis, (“Business Associate”). Covered Entity and Business Associate may be
referred herein individually as a “Party” or collectively as the “Parties”. This Agreement supersedes any
previously executed Business Associate Agreement between the Parties.
WITNESSETH:
WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and
Accountability Act of 1996 (“HIPAA”), Public Law 104-191, as modified by the Health Information
Technology for Economic and Clinical Health Act (“HITECH”), Public Law 111-5, known as “the
Administrative Simplification provisions,” direct the Department of Health and Human Services to
develop standards to protect the security, confidentiality and integrity of health information; and
WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and
Human Services (“Secretary”) has issued regulations modifying the Privacy, Security, Breach
Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from
time to time (the “HIPAA Security and Privacy Rule”); and
WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business
Associate will provide certain services to Covered Entity, and, pursuant to such arrangements, Business
Associate may be considered a “Business Associate” of Covered Entity as defined in the HIPAA Security
and Privacy Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred
to as the “Service Agreement(s)”); and
WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in
fulfilling its responsibilities under such arrangement;
THEREFORE, in consideration of the Parties’ continuing obligations under the Service Agreement,
compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the
receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this
Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect
the interests of both Parties.
I. DEFINITIONS
(a) Service Agreement. Agreement(s) for services affected by this HIPAA Business
Associate Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby
incorporated by reference, and which shall be taken and considered as a part of this document the same as
if fully set out herein:
Pharmacy Services
(b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in
this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule, 45 CFR Parts
160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement
and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA Security and
Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the
HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy
Rule, the provisions of this Agreement shall control.
(c) Electronic Protected Health Information. Protected Health Information that is transmitted
by or maintained in Electronic Media (as defined in the HIPAA Security and Privacy Rule).
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
2
October 2013
(d) Protected Health Information. “Protected Health Information” shall have the same
meaning as the term in 45 CFR § 160.103, limited to the information created or received by Business
Associate from or on behalf of Covered Entity and includes without limitation “Electronic Protected
Health Information.” Business Associate acknowledges and agrees that all Protected Health Information
that is created or received by Covered Entity and disclosed or made available in any form, including paper
record, oral communication, audio recording, and electronic display by Covered Entity or its operating
units to Business Associate or is created or received by Business Associate on Covered Entity’s behalf
shall be subject to this Agreement.
(e) Required by Law. “Required by Law” shall have the same meaning as the term in 45
CFR § 164.103.
II. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE
(a) Use and Disclosure. Business Associate agrees to fully comply with the requirements
under the HIPAA Security and Privacy Rule applicable to Business Associates and not to use or disclose
Protected Health Information other than as permitted or required by this Agreement, the Service
Agreement or as Required by Law. To the extent Business Associate carries out obligations of Covered
Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable
provisions of the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered
Entity. Business Associate agrees to comply with Covered Entity’s policies regarding the minimum
necessary use or disclosure of Protected Health Information.
(b) Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to
prevent use or disclosure of Protected Health Information other than as provided for by this Service
Agreement(s), this Agreement or as Required by Law. This includes the implementation physical,
technical and administrative safeguards to prevent use or disclosure of Protected Health Information other
than as permitted in this Agreement or Required by Law and reasonably and appropriately protect the
confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates,
receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and
Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with
the HIPAA Security and Privacy Rule, including, but not limited to, its policies, pr ocedures, records of
training and sanctions of members in its workforce.
(c) Assurances. Business Associate agrees to provide Covered Entity with written
assurances that any Protected Health Information placed on any type of mobile media, including, but by
no means limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with
guidance issued by the Secretary.
(d) Agents and Subcontractors. Business Associate shall require any agents, including any
subcontractors, to whom it provides Protected Health Information from Covered Entity that is created,
received, maintained or transmitted on behalf of Business Associate to agree by written contract with
Business Associate to the same (or greater) restrictions, conditions and requirements that apply to
Business Associate with respect to such information, and to agree to implement reasonable and
appropriate safeguards to protect any of such information that is Electronic Protected Health Information.
In addition, Business Associate agrees to take reasonable steps to ensure that its employees’ actions or
omissions do not cause Business Associate to breach the terms of this Agreement.
(e) Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable,
any harmful effect that is known to Business Associate of a use or disclosure of Protected Health
Information by Business Associate in violation of the requirements of this Agreement, as well as to
provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate such
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
3
October 2013
noncompliance or Security Incident. Business Associate shall cooperate in Covered Entity’s breach
analysis and/or risk assessment, if requested. Furthermore, Business Associate shall cooperate with
Covered Entity in the event that Covered Entity determines that any third parties must be notified of a
Breach, provided that Business Associate shall not provide any such notification except at the direction of
Covered Entity.
(f) Breach Reporting. Business Associate shall report in writing to Covered Entity’s Privacy
Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance
with the terms of this Agreement, as well as any Security Incident and any actual or suspected Breach, of
which it becomes aware, without unreasonable delay, and in no event later than forty-eight (48) hours of
such discovery. For purposes of this Agreement, “Security Incident” means the attempted or successful
unauthorized access, use, disclosure, modification, or destruction of information or interference with
system operations in an information system. Such notification shall contain the elements required by 45
C.F.R. § 164.410.
(g) Compliance. To the extent applicable, Business Associate will comply with (i) Covered
Entity’s Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to
an Individual’s permission to use or disclose his or her Protected Health Information; and (iii) any
restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed
or is required to agree.
(h) Government Access. Business Associate will make its internal practices, books and
records available to the Secretary of the Department of Health and Human Services for purposes of
determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of
the Secretary, will comply with any investigations and compliance reviews, permit access to information,
and cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event,
no more than 48 hours of receipt of the request or notification, Business Associate will notify Covered
Entity in writing of any request by any governmental entity, or its designee, to review Business
assessment of any kind.
(i) Electronic Transactions. If Business Associate conducts any Standard Transactions for or
on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic
Transaction Rule.
(j) Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an
audit of Business Associate’s compliance with this Agreement, HIPAA, and HITECH. Such audit may
consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate
shall promptly and completely respond to Covered Entity’s requests for information in support of the
audit, which shall not be conducted more than once annually except in cases of an actual or reasonably
suspected Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or
HITECH. Each Party shall bear its own costs associated with the audit.
(k) Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies
and Procedures to protect any patient information that may be breached by the Business Associate to the
extent applicable under the Federal Trade Commission’s Red Flag Rules.
(l) HITECH Compliance. Business Associate shall:
A. Not receive, directly or indirectly, any impermissible remuneration in exchange
for Protected Health Information or Electronic Protected Health Information,
except as permitted by HITECH § 13405(d) or the HIPAA Regulations;
B. Comply with the marketing and other restrictions applicable to Business
Associates contained in HITECH § 13406 and the HIPAA Regulations;
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
4
October 2013
C. To the extent required under HITECH § 13404, fully comply with the applicable
requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected
Health Information;
D. To the extent required under HITECH § 13401, fully comply with 45 CFR §§
164.308, 164.310, 164.312, and 164.316;
E. To the extent required under HITECH §§13401 and 13404, comply with the
additional privacy and security requirements that apply to Covered Entities in the
same manner and to the same extent as Covered Entity is required to do so; and
F. To the extent required under the HIPAA Regulations, comply with the privacy
and security requirements that apply to Business Associates.
(m) State Privacy Laws. Business Associate shall understand and comply with state privacy
laws to the extent that such privacy laws are not preempted by HIPAA or HITECH.
III. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
(a) Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise
limited in this Agreement, Business Associate may use or disclose Protected Health Information to
perform functions, activities or services for, or on behalf of, Covered Entity described in the Service
Agreement, provided that such use or disclosure would not violate the HIPAA Security and Privacy Rule
if it were made by Covered Entity or would not violate the Covered Entities minimum necessary policies.
(b) Other Uses of Protected Health Information. Except as otherwise limited in this
Agreement, Business Associate may use Protected Health Information within its workforce for the proper
management and administration of Business Associate not to include Marketing or Commercial Use and
to carry out the legal responsibilities of Business Associate; and
(c) Third Party Confidentiality. Except as otherwise limited in this Agreement, Business
Associate may disclose Protected Health Information for the proper management and administration of
Business Associate or to carry out the legal responsibilities of Business Associate, provided that if
Business Associate discloses any Protected Health Information to a third party for such purpose, the
Business Associate shall enter into a written agreement with such third party requiring the following:
A. Disclosure only as Required by Law; or
B. Business Associate obtains reasonable assurances from the person to whom the
information is disclosed that the information will remain confidential and will be used or
further disclosed only as Required by Law or for the purpose for which it was disclosed
to the person, and the person notifies Business Associate of any instances of which it is
aware in which the confidentiality, integrity, and or availability of the Protected Health
Information has been breached immediately upon becoming aware.
(d) Business Associate may provide data aggregation services relating to the health care
operations of Covered Entity pursuant to any agreements between the Parties evidencing their business
relationship as permitted by 45 CFR § 164.504(e)(2)(i)(B).
(e) Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business
Associate to share Protected Health Information with Business Associate’s affiliates or contractors except
for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s)
identified in Section I (a) of this Agreement.
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
5
October 2013
(f) Covered Entity Authorization for Additional Uses. Any use of Protected Health
Information by Business Associate, its affiliate or Contractor, other than those purposes of this
Agreement, shall require express written authorization by the Covered Entity, and a Business Associate
Agreement or amendment as necessary. Activities which are prohibited include, but are not limited to,
Marketing, as defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed
by Covered Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal
or state laws.
(g) Business Associate may de-identify Protected Health Information only at the specific
direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health
Information except at the direction of Covered Entity and in compliance with the requirements of the
HIPAA Security and Privacy Rule.
IV. AVAILABILITY OF PHI
(a) Access to Protected Health Information. Business Associate agrees, in the event the
Business Associate maintains protected health information in a Designated Record Set, to make available,
within ten (10) days of a request by Covered Entity in a time and manner designated by Covered Entity,
Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered
Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security
and Privacy Rule.
(b) Amendments to Protected Health Information. In the event that the Business Associate
maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make
any amendment(s) to Protected Health Information in a designated record set that the Covered Entity
directs or agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of
an individual, within ten (10) days of receipt of a request from Covered Entity and in the time and manner
designated by Covered Entity.
(c) Accounting of Disclosures. Business Associate agrees to maintain and make available
the information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the
HIPAA Security and Privacy Rule. Business Associate will comply with Covered Entity’s policy
regarding accounting of disclosures.
(d) Document Disclosures. In the event an Individual makes a request under this Section of
the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such
request within three (3) business days and shall cooperate with, and act only at the direction of Covered
Entity in responding to such request.
V. OBLIGATIONS OF COVERED ENTITY
(a) Notice of Privacy Practices. Covered Entity shall provide Business Associate with the
notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as
any changes to that notice.
(b) Notice of Changes in Individual’s Access or Protected Health Information. Covered
Entity shall provide Business Associate with any changes in, or revocation of, permission by an
Individual to use or disclose Protected Health Information, is such changes affect Business Associate’s
permitted or required uses.
(c) Notice of Restriction in Individual’s Access to Protected Health Information. Covered
Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health
Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such
restriction may affect Business Associate’s use of Protected Health Information.
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
6
October 2013
VI. PERMISSABLE REQUESTS BY COVERED ENTITY
Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use
or disclose Protected Health Information in any manner that would not be permissible under the Privacy
or Security Rule.
VII. TERMINATION
(a) Term. This Agreement shall be effective as of the date first set forth above and shall
terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the
termination by Covered Entity for cause as provided herein.
(b) Termination for Cause. Notwithstanding anything in this Agreement to the contrary,
Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately
if Covered Entity determines that Business Associate has or will violated any material term of this
Agreement. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered
Entity shall provide an opportunity for Business Associate to cure the breach or end the violation.
Covered Entity may terminate this Agreement if Business Associate does not cure the breach or end the
violation within the time period specified by Covered Entity. If termination, cure or end of the violation
is not feasible, Covered Entity may report the violation to the Secretary.
(c) Obligation of Business Associate Upon Termination. At termination of this Agreement,
the Service Agreement (or any similar documentation of the business relationship of the Parties), or upon
request of Covered Entity, whichever occurs first, Business Associate, shall:
A. if feasible, return (in a manner or process approved by the Covered Entity) or destroy
all Protected Health Information, regardless of form, including but not limited to
paper or electronic format, received from Covered Entity, or created, maintained or
received by Business Associate on behalf of Covered Entity. Business Associate
shall retain no copies of the Protected Health Information. This provision shall also
apply to Protected Health Information and other confidential information in the
possession of sub-contractors or agents of Business Associate.
B. If such return or destruction is not feasible, Business Associate shall (i) retain only
that Protected Health Information necessary for Business Associate to continue its
proper management and administration or to carry out its legal responsibilities ; (ii)
return or destroy the remaining Protected Health Information that the Business
Associate still maintains in any form; (iii) extend the protections of this Agreement to
the retained Protected Health Information; (iv) limit further uses and disclosures to
those purposes that make the return or destruction of the Protected Health
Information not feasible; and (v) return or destroy the retained Protected Health
Information when it is no longer needed by Business Associate.
(d) Survival. This paragraph shall survive the termination of this Agreement and shall apply
to Protected Health Information created, maintained, or received by Business Associate and any of its
subcontractors.
VIII. MISCELLANEOUS
(a) Indemnification. Business Associate agrees to indemnify, defend, and hold harmless
Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims,
losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur
by reason of Business Associate’s breach of or failure to perform any its obligations pursuant to this
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
7
October 2013
Agreement, including but not limited to any injury or damages arising from any noncompliance with this
Agreement or any Security Incident attributable to the negl igence of Business Associate, including
failure to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend,
and hold harmless Covered Entity, its officers, employees, contractors and agents, against all costs and
expenses, including but not limited to, reasonable legal expenses, which are incurred by or on behalf of
Business Associate in connection with the defense of such claims.
(b) Disclaimer. Covered Entity makes no warranty or representation that compliance by
Business Associate with this Agreement, HIPAA, HITECH, or the HIPAA Regulations will be adequate
or satisfactory for Business Associate’s own purposes. Business Associate is solely responsible for all
decisions made by Business Associate regarding the safeguarding of Protected Health Information.
(c) Assistance in Litigation or Administrative Proceedings. Business Associate shall make
itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the
performance of its obligations under this Agreement, available to Covered Entity, at no cost to Covered
Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being
commenced against Covered Entity, its directors, officers or employees based upon a claimed violation
of HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy, except
where Business Associate or its subcontractor, employee or agent is named adverse party.
(d) Survival. The obligations of Business Associate under this Agreement shall survive the
expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business
relationship of the parties, and shall continue to bind Business Associate, its agents, employees,
contractors, successors, and assigns as set forth herein.
(e) Ownership of Information. Covered Entity holds all right, title, and interest in and to the
Protected Health Information and Business Associate does not hold and will not acquire by virtue of this
Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or
to the PHI or any portion thereof.
(f) Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that
the breach, or threatened breach, by it of any provision of this Agreement may cause Covered Entity to be
irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore, Business
Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek
injunctive relief to prevent Business Associate from commencing or continuing any action constituting
such breach without having to post a bond or other security and without having to prove the inadequacy
of any other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other
remedy available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA
Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third
parties.
(g) Amendment. The Parties agree to take such action as is necessary to amend this
Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the
HIPSS Regulations. In addition, this Agreement may be amended or modified by the Parties only in
writing.
(h) Assignment. No Party may assign its respective rights and obligations under this
Agreement without the prior written consent of the other Party.
(i) Independent Contractor. None of the provisions of this Agreement are intended to create,
nor will they be deemed to create any relationship between the Parties other than that of independent
parties contracting with each other solely for the purposes of effecting the provisions of this Agreement
and any other agreements between the Parties evidencing their business relationship. This Agreement
will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
8
October 2013
liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance
of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other
occasion.
(j) Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH
or the HIPAA Regulations means the section as it currently is in effect or as amended.
(k) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning
that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event
that any documentation of the arrangement pursuant to which Business Associate provides services to
Covered Entity contains provisions relating to the use or disclosure of Protected Health Inf ormation that
are more restrictive than the provisions of this Agreement, the more restrictive provisions will control.
The provisions of this Agreement are intended to establish the minimum requirements regarding Business
Associate’s use and disclosure of Protected Health Information.
(l) Severability. In the event any part or parts of this Agreement are held to be
unenforceable, the remainder of this Agreement will continue in effect. In addition, in the event a party
believes in good faith that any provision of this Agreement fails to comply with the then-current
requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing.
For a period of up to (30) thirty days, the parties shall address in good faith such concern and amend the
terms of this Agreement, if necessary to bring it into compliance. If, after such thirty-day period, a party
believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule,
then either party has the right to terminate upon written notice to the other party.
(m) Notices and Communications. All instructions, notices, consents, demands, or other
communications required or contemplated by this Agreement shall be in writing and shall be delivered to
the Party at the address below:
For Covered Entity: For Business Associate
Orange County Health Department Robert E. Dupuis, Pharm. D, BCPS
300 W. Tryon Street 205 Kenilworth Place
Hillsborough, NC 27278 Chapel Hill, NC 27516
(n) Strict compliance. No failure by any Party to insist upon strict compliance with any
terms or provisions of this Agreement, to exercise any option, to enforce any right, or to seek any remed y
upon any default of any other Party shall affect, or constitute a waiver of, any Party’s right to insist upon
such strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that
default or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at
variance with any provisions of this Agreement shall affect, or constitute a waiver of, any Party’s right to
demand strict compliance with all provisions of this Agreement.
(o) Governing Law. This Agreement shall be governed and construed in accordance with the
laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by
HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County,
North Carolina, for purposes of litigation resulting from disagreements of the Parties for purposes of this
Agreement and the Service Agreement(s).
(p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in
Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract
with governmental units. E-Verify is a Federal program operated by the United States Department of
Homeland Security and other federal agencies, or any successor or equivalent program used to verify the
work authorization of newly hired employees pursuant to federal law. Where applicable, failure to
maintain compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General
Statutes shall constitute breach of this Agreement. If applicable, by executing this Agreement, Business
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
9
October 2013
Associate affirms that they are in compliance with Article 3 of Chapter 64 if the North Carolina General
Statutes.
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written
above.
COVERED ENTITY: BUSINESS ASSOCIATE:
By:_________________________________ By:___________________________________
Title:________________________________ Title:__________________________________
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
pharmacistOrange County Health Director
10
October 2013
EXHIBIT A
COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION
To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with
the terms of this Agreement that might be considered a privacy breach, Business Associate should contact
the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident (as defined
in the Agreement), Business Associate should contact Carla Julian (919) 245-2434, or the Security
Officer at The Orange County Health Department.
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
HCPL-2037D (11/09)
Healthcare Professional Liability
LIBERTY INSURANCE UNDERWRITERS INC.
(A Stock Insurance Company, hereinafter the “ Company” )
55 Water Street, 18th Floor
New York, NY 10041
DECLARATIONS
SECTION I
Item
1. Named Insured:
Mailing Address:
3. Policy Period:From:To:
12:01 A. M. Standard Time At Location of Designated Premises
4. Business or Profession:Affiliation:
5. The Named Insured is a(n): Partnership Corporation Individual LLC
Sole Proprietor (with employees) Professional Association Other
This policy is made and accepted subject to the printed conditions of this policy together with the provisions, stipulations
and agreements contained in the following form(s) or endorsements(s):
SECTION II
Item COVERAGE Premium
A.Professional Liability [ ]
B.General Liability [ ]
Terrorism Risk Insurance Act
C.Endorsements [ ]
TOTAL:
LIMITS OF LIABILITY
Each Incident and Each Occurrence Aggregate
SECTION III
SUPPLEMENTARY PAYMENTS
A.First Party Assault
B.Licensing Board Reimbursement
C.Wage Loss and Expense
D.Deposition Expense
E.First Aid Reimbursement
Representative Agent:
Policy Number: AHY-768247008 Renewal Of: AHY-768247007
Robert E. Dupuis
c/o NCAIA
PO Box 1165
Cary, NC 27512
12/22/2021 12/22/2022
Pharmacist
X
X
X
$2,000,000 $4,000,000
Mercer Consumer, a service of
Mercer Health & Benefits Administration LLC
P.O. Box 14576
3452- American Soc. of Health Sys. Pharmacists Des Moines, IA 50306-3576
HCPL-2037i (01/14), HCPL-2038 (11/09), HCPL-8101A (04/14)
HCPL-2037-9000-NC (11/09)
ADM-OFAC-0419, HCPL-8103 (05/15),
HCPL-8320 (01/15), HCPL-8321 (01/15), HCPL-8324 (01/15), HCPL-8328 (02/15)
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1
MEMORANDUM OF INSURANCE Date Issued
Producer
coverages afforded by the Certificate listed below.
Company Affording Coverage
Insured
This is to certify that the Certificate listed below has been issued to the insured named above for the policy period indicated, not
withstanding any requirement, term or condition of any contract or other document with respect to which this memorandum may be
issued or may pertain, the insurance afforded by the Certificate described herein is subject to all the terms, exclusions and conditions of
such Certificate. The limits shown may have been reduced by paid claims.
The Memorandum of Insurance and verification of payment are your evidence of coverage. No coverage is afforded unless the premium
is successfully paid in full.
Type of Insurance Certificate Number Effective Date Expiration Date Limits
Professional Liability Per Incident/
Occurrence
Annual Aggregate
PROOF OF INSURANCE
Memorandum Holder:Should the above describe
of any kind up
representatives.
Authorized Representative
Joan O’Sullivan
North Carolina Assoc of Ins Agents Inc
101 Weston Oaks Court
Cary NC 27513
Client # 484672
11/09/2021
Robert E. Dupuis
c/o NCAIA
PO Box 1165
Cary, NC 27512
Pharmacist E
Pharmacist
AHY-768247008 12/22/2021 12/22/2022 $2,000,000
$4,000,000
Mercer Consumer, a service of Mercer Health & Benefits Administration LLC. In CA d/b/a Mercer Health & Benefits Insurance Services LLC. CA License #0G39709
PROOF OF COVERAGE ONLY
Mercer Consumer, a service of
Mercer Health & Benefits Administration LLC
P.O. Box 14576
Des Moines, IA 50306-3576
1-800-375-2764
Liberty Insurance Underwriters Inc.
Mark Brostowitz
DocuSign Envelope ID: 9626C6F3-65DD-4E0D-A501-6A3A939E2BA1