HomeMy WebLinkAbout2023-480-E-Health Dept-Mark Smith-Data analysis for CHARevised 04/23
1
[Departmental Use Only]
TITLE Smith CHA Data Analy
FY 2023-2024
NORTH CAROLINA
SERVICES AGREEMENT NO RFP/RFQ
ORANGE COUNTY
This Services Agreement (hereinafter “Agreement”), made and entered into this 30th day of
August, 2023, (“Effective Date”) by and between Orange County, North Carolina a political
subdivision of the State of North Carolina (hereinafter, the "County") and Mark H. Smith, Ph.D.,
(hereinafter, the "Provider").
WITNESSETH:
That the County and Provider, for the consideration herein named, do hereby agree as
follows:
1. Services
a. Scope of Work.
i) This Agreement is for services to be rendered by Provider to County with respect
to (insert type of project): Data analysis support.
ii) By executing this Agreement, the Provider represents and agrees that Provider is
qualified to perform and fully capable of performing and providing the services
required or necessary under this Agreement in a fully competent, professional and
timely manner.
iii) Time is of the essence with respect to this Agreement.
iv) The services to be performed under this Agreement consist of Basic Services, as
described and designated in Section 3 hereof. Compensation to the Provider for
Basic Services under this Agreement shall be as set forth herein.
2. Responsibilities of the Provider
a. Services to be provided. The Provider shall provide the County with all services
required in Section 3 to satisfactorily complete the Project within the time limitations set
forth herein and in accordance with the highest professional standards.
b. Standard of Care.
i) The Provider shall exercise reasonable care and diligence in performing services
under this Agreement in accordance with the highest generally accepted standards
of this type of Provider practice throughout the United States and in accordance
with applicable federal, state and local laws and regulations applicable to the
performance of these services. Provider is solely responsible for the professional
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
2
quality, accuracy and timely completion and submission of all work related to the
Basic Services.
ii) Provider shall be responsible for all errors or omissions of its agents, contractors,
employees, or assigns in the performance of the Agreement. Provider shall
correct any and all errors, omissions, discrepancies, ambiguities, mistakes or
conflicts at no additional cost to the County.
iii) The Provider shall not, except as otherwise provided for in this Agreement,
subcontract the performance of any work under this Agreement without prior
written permission of the County. No permission for subcontracting shall create,
between the County and the subcontractor, any contract or any other relationship.
iv) Provider is an independent contractor of County. Any and all employees of the
Provider engaged by the Provider in the performance of any work or services
required of the Provider under this Agreement, shall be considered employees or
agents of the Provider only and not of the County, and any and all claims that may
or might arise under any workers compensation or other law or contract on behalf
of said employees while so engaged shall be the sole obligation and responsibility
of the Provider.
v) If activities related to the performance of this Agreement require specific licenses,
certifications, or related credentials Provider represents that it or its employees,
agents and subcontractors engaged in such activities possess such licenses,
certifications, or credentials and that such licenses certifications, or credentials are
current, active, and not in a state of suspension or revocation.
vi) Should any documents, exhibits, or addenda be attached to this Agreement, the
terms of this Agreement shall have priority in any conflict with or among the
terms of such referenced documents, exhibits.
vii) Should this Agreement involve project designs, the construction or creation of
which is to be bid out or fulfilled by other contractors, and bidding or negotiation
with contractors produce prices which, when added to the other elements of the
approved total project cost, produce a cost that is in excess of the approved total
project cost, the Provider shall participate with the County in negotiation and
design adjustments to the extent such are necessary to obtain prices within the
approved total project cost. All activity of the Provider with respect to these
matters shall constitute Basic Services and shall be performed by the Provider
without additional compensation. If negotiation and design adjustments fail to
bring costs within the total project cost the County may reject all bids and
Provider will redesign or reduce portions of the project in an effort to reduce the
bid prices to within the total project cost and rebid the project. One such redesign
is included within Basic Services. If this second letting for bids does not produce
bids that are within the approved total project cost initially or after negotiations
with the contractor the cost is not reduced to an amount within the total project
cost, the Provider is not obligated to engage in further redesign.
3. Basic Services
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
3
a. Basic Services. The Services to be rendered pursuant to this Agreement are as follows
(fully describe services to be provided): Anlalyze Community Health Assesment 2023
data as described in Proposed Scope of Work: Data Analytical Support for 2023 Orange
County Community Health Assessment for the Orange County Health Department
which is attached hereto as Exhibit A, at a rate of $45.00 per hour.
4. Duration of Services
a. Term. The term of this Agreement shall be from September 8, 2023 to December 15,
2023.
b. Scheduling of Services.
i) The Provider shall schedule and perform its activities in a timely manner.
ii) Should the County determine that the Provider is behind schedule, it may require
the Provider to expedite and accelerate its efforts, including providing additional
resources and working overtime, as necessary, to perform its services in
accordance with the approved project schedule at no additional cost to the
County.
iii) The Commencement Date for the Provider's Basic Services shall be September 8,
2023.
5. Compensation
a. Compensation for Basic Services. Compensation for Basic Services shall include all
compensation due the Provider from the County for all services satisfactorily (as
determined by the County) performed pursuant to this Agreement. The maximum
amount payable for Basic Services shall not exceed Five Thousand Dollars ($5,000).
Payment for satisfactorily performed Basic Services shall become due and payable
within thirty (30) days of Provider properly invoicing County. Payment shall be subject
to provisions of Section 5(b).
b. Disputes. In the event the amount stated on an invoice is disputed by the County, the
County may withhold payment of all or a portion of the amount stated on an invoice
until the parties resolve the dispute. Should Provider fail to perform its duties under the
terms of this Agreement, County may, without fault or penalty, withhold any payment
associated with the work to be performed until such time as said work is completed.
c. Additional Services. County shall not be responsible for costs related to any services in
addition to the Basic Services performed by Provider unless County requests such
additional services in writing and such additional services are evidenced by a written
amendment to this Agreement.
6. Responsibilities of the County
a. Cooperation and Coordination. The County has designated (Dana Crews) to act as the
County's representative with respect to the Project who shall have the authority to render
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
4
decisions within guidelines established by the County Manager or the County Board of
Commissioners and who shall be available during working hours as often as may be
reasonably required to render decisions and to furnish information.
7. Insurance
a. General Requirements. Provider shall obtain, at its sole expense, Commercial General
Liability Insurance, Automobile Insurance, Workers’ Compensation Insurance, and any
additional insurance as may be required by County’s Risk Manager as such insurance
requirements are described in the Orange County Risk Transfer Policy and Orange
County Minimum Insurance Coverage Requirements (each document is incorporated
herein by reference and may be viewed at
http://www.orangecountync.gov/departments/purchasing_division/contracts.php). If
County’s Risk Manager determines additional insurance coverage is required such
additional insurance shall consist of N/A (if no additional insurance required mark N/A
as being not applicable). Provider shall not commence work until such insurance is in
effect and certification thereof has been received by the County's Risk Manager.
8. Indemnity
a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without
limitation, to defend, indemnify and hold harmless the County from all loss, liability,
claims or expense, including attorney's fees, arising out of or related to the Project and
arising from property damage or bodily injury including death to any person or persons
caused in whole or in part by the negligence or misconduct of the Provider except to the
extent same are caused by the negligence or willful misconduct of the County. It is the
intent of this provision to require the Provider to indemnify the County to the fullest
extent permitted under North Carolina law.
9. Amendments to the Agreement
a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional
compensation or a change in duration of this Agreement shall be made by a written
Amendment to this Agreement executed by the County and the Provider. The Provider
shall proceed to perform the Services required by the Amendment only after receiving a
fully executed Amendment from the County.
10. Termination
a. Termination for Convenience of the County. This Agreement may be terminated without
cause by the County and for its convenience upon seven (7) days’ prior written notice to
the Provider.
b. Other Termination. The Provider may terminate this Agreement based upon the County's
material breach of this Agreement; provided, the County has not taken all reasonable
actions to remedy the breach. The Provider shall give the County seven (7) days' prior
written notice of its intent to terminate this Agreement for cause. Either party may
terminate this Agreement upon notice to the other party that obligations pursuant to this
Agreement are made impractical due to declarations of emergency by Orange County or
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
5
by North Carolina due to events directly impacting Orange County. Both parties shall
remain responsible for all payment and performance due up to the receipt of such notice,
but shall have no further obligation or responsibility beyond that date provided the
terminating party has taken all reasonable steps to complete the performance of its
obligations.
c. Compensation After Termination.
i) In the event of termination, the Provider shall be paid that portion of the fees and
expenses that it has earned to the date of termination, less any costs or expenses
incurred or anticipated to be incurred by the County due to errors or omissions of
the Provider. Upon request of the County, the Provider shall submit to County all
relevant documentation, including but not limited to, job cost records, to support
its claims for final compensation.
ii) Should this Agreement be terminated, the Provider shall deliver to the County
within seven (7) days, at no additional cost, all deliverables including any
electronic data or files relating to the Project.
d. Waiver. The payment of any sums by the County under this Agreement or the failure of
the County to require compliance by the Provider with any provisions of this Agreement
or the waiver by the County of any breach of this Agreement shall not constitute a
waiver of any claim for damages by the County for any breach of this Agreement or a
waiver of any other required compliance with this Agreement.
e. Suspension. County may suspend the Basic Services and this Agreement at any time for
County’s convenience and without penalty to County upon three (3) days’ notice to
Provider. Upon any suspension by County, Provider shall discontinue work on the Basic
Services and shall not resume the Basic Services until notified to proceed by County.
11. Additional Provisions
a. Limitation and Assignment. The County and the Provider each bind themselves, their
successors, assigns and legal representatives to the terms of this Agreement. Neither the
County nor the Provider shall assign or transfer its interest in this Agreement without the
written consent of the other.
b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights
of respective parties hereunder shall be governed by the laws of the State of North
Carolina. By executing this Agreement Provider affirms that Provider and any
subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter
64 of the North Carolina General Statutes. By executing this Agreement Provider
certifies that Provider has not been identified, and has not utilized the services of any
agent or subcontractor identified, on the list created by the State Treasurer pursuant to
G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not
been identified, and has not utilized the services of any agent or subcontractor identified,
on the list created by the State Treasurer pursuant to G.S. 147-86.81.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
6
c. Non-Discrimination. Provider shall at all times remain in compliance with all applicable
local, state, and federal laws, rules, and regulations including but not limited to all state
and federal non-discrimination laws, policies, rules, and regulations and the Orange
County Non-Discrimination Policy and Orange County Living Wage Policy (each policy
is incorporated herein by reference and may be viewed at
http://www.orangecountync.gov/departments/purchasing_division/contracts.php.) Any
violation of the Orange County Non-Discrimination Policy is a breach of this Agreement
and County may immediately terminate this Agreement without further obligation on the
part of the County. This paragraph is not intended to limit and does not limit the
definition of breach to discrimination.
d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages
with respect to any provision of, or the performance or non-performance of, this
Agreement shall be brought in the General Court of Justice of North Carolina sitting in
Orange County, North Carolina. It is agreed by the parties that no other court shall have
jurisdiction or venue with respect to such suits or actions. Binding arbitration may not
be initiated by either Party, however, the Parties may agree to nonbinding mediation of
any dispute prior to the bringing of such suit or action.
e. Entire Agreement. This Agreement represents the entire and integrated agreement
between the County and the Provider and supersedes all prior negotiations,
representations or agreements, either written or oral. This Agreement may be amended
only by written instrument signed by both parties. Modifications may be evidenced by
facsimile signatures.
f. Severability. If any provision of this Agreement is held as a matter of law to be
unenforceable, the remainder of this Agreement shall be valid and binding upon the
Parties.
g. Ownership of Work Product. Should Provider’s performance of this Agreement generate
documents, data, items, or things that are specific to this Project such documents, data,
items, or things shall become the property of the County and may be used on any other
project without additional compensation to the Provider. The use of the documents,
items, or things by the County or by any person or entity for any purpose other than the
Project as set forth in this Agreement shall be at the full risk of the County. All items
supplied to the Provider for the execution of this Project shall remain the property of the
County.
h. Non-Appropriation. Provider acknowledges that County is a governmental entity, and
the validity of this Agreement is based upon the availability of public funding under the
authority of its statutory mandate.
In the event that public funds are unavailable or not appropriated for the performance of
County’s obligations under this Agreement, then this Agreement shall automatically
expire without penalty to County immediately upon written notice to Provider of the
unavailability or non-appropriation of public funds. It is expressly agreed that County
shall not activate this non-appropriation provision for its convenience or to circumvent
the requirements of this Agreement.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
7
In the event of a change in the County’s statutory authority, mandate or mandated
functions, by state or federal legislative or regulatory action, which adversely affects
County’s authority to continue its obligations under this Agreement, then this Agreement
shall automatically terminate without penalty to County upon written notice to Provider
of such limitation or change in County’s legal authority.
i. Signatures. This Agreement together with any amendments or modifications may be
executed electronically. All electronic signatures affixed hereto evidence the consent of
the Parties to utilize electronic signatures and the intent of the Parties to comply with
Article 11A and Article 40 of North Carolina General Statute Chapter 66.
j. Notices. Any notice required by this Agreement shall be in writing and delivered by
certified or registered mail, return receipt requested to the following:
Orange County Provider’s Name
Attention: Kimberlee Quatrone Mark Smith, Ph.D.
P.O. Box 8181 3909 New Garden Park
Hillsborough, NC 27278 Greensboro, NC 27410
[SIGNATURE PAGE TO FOLLOW]
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
8
IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have
hereunder set their hands and seal, all as of the day and year first above written.
ORANGE COUNTY: PROVIDER:
By: _________________________________
Bonnie Hammersley, County Manager
By: __________________________________
Mark Smith, Ph.D.
Printed Name and Title
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Revised 04/23
9
ORANGE COUNTY—INTERNAL USE ONLY
______________________________________________________________________________
Finance Information
Vendor Name: Mark Smith Vendor Contact Person: Mark Smith Phone: 336-669-6108 Address: 3909 New
Garden Park City Greensboro State: NC Zip: 27410 Department: Health Amount: $5,000 Purpose: Data analysis
for CHA Budget Code(s): 10411020-630000-71451 Vendor # 68171
Vendor Status with NCSOS: Vendor is a BOCC consultant: Yes No
Contract Details
Contract Type: New Amendment (Original Contract: ) (Most Recent Amendment )
Effective Date 9/8/23 End Date 12/15/23 Notice Date (Notice Purpose )
Award
Approved by Board (Agenda Date: ); Made or Administered by
Signature Authority
- BOCC Express Delegation (Agenda Date: )
- Policy 9.4: Under $5,000; Service Under $90,000; Construction Under $250,000
- Budget Policy Section XV (Capital Improvement Project: )
Bidding
Informal Bidding ($30k-$90k); Formal RFP ($90k+); Other (<$30k); Exception(# )
Department Affirmation
This agreement is approved as to technical form and content and I as Department Director affirmatively state
work on this project has not been initiated prio r to execution of the agreement.
Services related to this agreement have already begun or been completed. Description of the nature of the
emergency condition that was addressed:
Department Director’s Signature ________________________________________ Date: ________
Information Technologies
This agreement has been reviewed and is approved as to information technology content and specifications:
Office of the Chief Information Officer___________________________________ Date: ________
Inapplicable because no hardware/software purchases or related services
Risk Management
This agreement is approved for sufficiency of insurance standards, specifications, and req uirements:
Office of the Risk Management Officer___________________________________ Date: _________
Financial Services
This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control
Act:
Office of the Chief Financial Officer ____________________________________ Date: _________
Legal Services
This agreement is approved as to legal form and sufficiency:
Office of the County Attorney __________________________________________Date: ________
Clerk to the Board
All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov
The following signature block is for hard copies only and is not required for Docusign contracts:
Received for record retention:
Office of the Clerk to the Board __________________________________________Date:_________
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
8/31/2023
9/1/2023
9/1/2023
9/1/2023
Revised 04/23
10
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
Exhibit A
Proposed Scope of Work
Data Analytical Support for 2023 Orange County Community Health Assessment
for the Orange County Health Department
CHA Support Activities:
Analyze the randomized and online sample survey results in a manner that is clear, concise, and
understandable for community presentations and final document.
Develop informative frequency tables, rates, graphs and charts using results of analyses of the
randomized and online community surveys.
Conduct secondary data analysis with comparisons made to peer and neighboring comparison
counties, and the state of NC using leading causes of death and HNC 2030 as indicators.
Provide information, numbers and descriptions of methodology, analysis, and results of the random
sample survey.
Geolocate/code addresses to develop maps showing census blocks and survey locations for
randomized community survey.
Submit request to the NC State Center for Health Statistics for address-identified detailed birth
certificate and death certificate files for Orange County.
Acquire address-identified data files for most recently available pregnancy, birth and mortality data.
Recode variables and prepare datasets for geocoding and analysis.
Geocode—i.e., assign addresses to residential location-- in geographic information system software.
Aggregate births and deaths by residence to larger geographic levels, including ZIP Codes and census
tracts.
Geocode addresses and create maps displaying sub-county geographic variation for selected measures
such as distribution of low-birthweight and preterm births and leading causes of death to identify areas
where poor health outcomes are concentrated.
Provide GIS/mapping information for geographically identified data collected.
Other data and GIS analysis as needed.
Work Process and Reimbursement
Communicate with Orange County HD staff via emails, phone calls and web-conferencing to develop
plan of work and discuss findings.
Orange County CHA project work will be documented and reimbursed at the rate of $45.00 per hour.
Invoices will be submitted to the Orange County HD on a monthly basis.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
1
October 2013
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement (“Agreement”) is made effective the 30th day of August, 2023,
by and between Orange County Government through its Orange County Health Department (“Covered
Entity”), and Mark H, (“Business Associate”). Covered Entity and Business Associate may be referred
herein individually as a “Party” or collectively as the “Parties”. This Agreement supersedes any previously
executed Business Associate Agreement between the Parties.
WITNESSETH:
WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and
Accountability Act of 1996 (“HIPAA”), Public Law 104-191, as modified by the Health Information
Technology for Economic and Clinical Health Act (“HITECH”), Public Law 111-5, known as “the
Administrative Simplification provisions,” direct the Department of Health and Human Services to develop
standards to protect the security, confidentiality and integrity of health information; and
WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human
Services (“Secretary”) has issued regulations modifying the Privacy, Security, Breach Notification, and
Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from time to time (the
“HIPAA Security and Privacy Rule”); and
WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business Associate
will provide certain services to Covered Entity, and, pursuant to such arrangements, Business Associate
may be considered a “Business Associate” of Covered Entity as defined in the HIPAA Security and Privacy
Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred to as the
“Service Agreement(s)”); and
WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in
fulfilling its responsibilities under such arrangement;
THEREFORE, in consideration of the Parties’ continuing obligations under the Service Agreement,
compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the
receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this
Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect the
interests of both Parties.
I. DEFINITIONS
(a) Service Agreement. Agreement(s) for services affected by this HIPAA Business Associate
Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby incorporated
by reference, and which shall be taken and considered as a part of this document the same as if fully set out
herein:
Smith CHA Data Analy
(b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in
this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule, 45 CFR Parts
160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement
and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA Security and
Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the
HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule,
the provisions of this Agreement shall control.
(c) Electronic Protected Health Information. Protected Health Information that is transmitted
by or maintained in Electronic Media (as defined in the HIPAA Security and Privacy Rule).
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
2
October 2013
(d) Protected Health Information. “Protected Health Information” shall have the same meaning
as the term in 45 CFR § 160.103, limited to the information created or received by Business Associate from
or on behalf of Covered Entity and includes without limitation “Electronic Protected Health Information.”
Business Associate acknowledges and agrees that all Protected Health Information that is created or
received by Covered Entity and disclosed or made available in any form, including paper record, oral
communication, audio recording, and electronic display by Covered Entity or its operating units to Business
Associate or is created or received by Business Associate on Covered Entity’s behalf shall be subject to this
Agreement.
(e) Required by Law. “Required by Law” shall have the same meaning as the term in 45 CFR
§ 164.103.
II. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE
(a) Use and Disclosure. Business Associate agrees to fully comply with the requirements
under the HIPAA Security and Privacy Rule applicable to Business Associates and not to use or disclose
Protected Health Information other than as permitted or required by this Agreement, the Service Agreement
or as Required by Law. To the extent Business Associate carries out obligations of Covered Entity under
the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of
the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. Business
Associate agrees to comply with Covered Entity’s policies regarding the minimum necessary use or
disclosure of Protected Health Information.
(b) Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to
prevent use or disclosure of Protected Health Information other than as provided for by this Service
Agreement(s), this Agreement or as Required by Law. This includes the implementation physical, technical
and administrative safeguards to prevent use or disclosure of Protected Health Information other tha n as
permitted in this Agreement or Required by Law and reasonably and appropriately protect the
confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates,
receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and
Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with the
HIPAA Security and Privacy Rule, including, but not limited to, its policies, procedures, records of training
and sanctions of members in its workforce.
(c) Assurances. Business Associate agrees to provide Covered Entity with written assurances
that any Protected Health Information placed on any type of mobile media, including, but by no means
limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with guidance issued
by the Secretary.
(d) Agents and Subcontractors. Business Associate shall require any agents, including any
subcontractors, to whom it provides Protected Health Information from Covered Entity that is created,
received, maintained or transmitted on behalf of Business Associate to agree by written contract with
Business Associate to the same (or greater) restrictions, conditions and requirements that apply to Business
Associate with respect to such information, and to agree to implement reasonable and appropriate
safeguards to protect any of such information that is Electronic Protected Health Information. In addition,
Business Associate agrees to take reasonable steps to ensure that its employees’ actions or omissions do
not cause Business Associate to breach the terms of this Agreement.
(e) Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable, any
harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information
by Business Associate in violation of the requirements of this Agreement, as well as to provide complete
cooperation to Covered Entity should Covered Entity elect to review or investigate such noncompliance or
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
3
October 2013
Security Incident. Business Associate shall cooperate in Covered Entity’s breach analysis and/or risk
assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the event
that Covered Entity determines that any third parties must be notified of a Breach, provided that Business
Associate shall not provide any such notification except at the direction of Covered Entity.
(f) Breach Reporting. Business Associate shall report in writing to Covered Entity’s Privacy
Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance
with the terms of this Agreement, as well as any Security Incident and any actual or suspected Breach, of
which it becomes aware, without unreasonable delay, and in no event later than forty-eight (48) hours of
such discovery. For purposes of this Agreement, “Security Incident” means the attempted or successful
unauthorized access, use, disclosure, modification, or destruction of information or interference with system
operations in an information system. Such notification shall contain the elements required by 45 C.F.R. §
164.410.
(g) Compliance. To the extent applicable, Business Associate will comply with (i) Cove red
Entity’s Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an
Individual’s permission to use or disclose his or her Protected Health Information; and (iii) any restrictions
to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required
to agree.
(h) Government Access. Business Associate will make its internal practices, books and
records available to the Secretary of the Department of Health and Human Services for purposes of
determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the
Secretary, will comply with any investigations and compliance reviews, permit access to information, and
cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event, no
more than 48 hours of receipt of the request or notification, Business Associate will notify Covered Entity
in writing of any request by any governmental entity, or its designee, to review Business assessment of any
kind.
(i) Electronic Transactions. If Business Associate conducts any Standard Transactions for or
on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic
Transaction Rule.
(j) Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an
audit of Business Associate’s compliance with this Agreement, HIPAA, and HITECH. Such audit may
consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate
shall promptly and completely respond to Covered Entity’s requests for information in support of the audit,
which shall not be conducted more than once annually except in cases of an actual or reasonably suspected
Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or HITECH. Each
Party shall bear its own costs associated with the audit.
(k) Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies and
Procedures to protect any patient information that may be breached by the Business Associate to the extent
applicable under the Federal Trade Commission’s Red Flag Rules.
(l) HITECH Compliance. Business Associate shall:
A. Not receive, directly or indirectly, any impermissible remuneration in exchange
for Protected Health Information or Electronic Protected Health Information,
except as permitted by HITECH § 13405(d) or the HIPAA Regulations;
B. Comply with the marketing and other restrictions applicable to Business
Associates contained in HITECH § 13406 and the HIPAA Regulations;
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
4
October 2013
C. To the extent required under HITECH § 13404, fully comply with the applicable
requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected
Health Information;
D. To the extent required under HITECH § 13401, fully comply with 45 CFR §§
164.308, 164.310, 164.312, and 164.316;
E. To the extent required under HITECH §§13401 and 13404, comply with the
additional privacy and security requirements that apply to Covered Entities in the
same manner and to the same extent as Covered Entity is required to do so; and
F. To the extent required under the HIPAA Regulations, comply with the privacy and
security requirements that apply to Business Associates.
(m) State Privacy Laws. Business Associate shall understand and comply with state privacy
laws to the extent that such privacy laws are not preempted by HIPAA or HITECH.
III. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
(a) Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise
limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform
functions, activities or services for, or on behalf of, Covered Entity described in the Service Agreement,
provided that such use or disclosure would not violate the HIPAA Security and Privacy Rule if it were made
by Covered Entity or would not violate the Covered Entities minimum necessary policies.
(b) Other Uses of Protected Health Information. Except as otherwise limited in this
Agreement, Business Associate may use Protected Health Information within its workforce for the proper
management and administration of Business Associate not to include Marketing or Commercial Use and to
carry out the legal responsibilities of Business Associate; and
(c) Third Party Confidentiality. Except as otherwise limited in this Agreement, Business
Associate may disclose Protected Health Information for the proper management and administration of
Business Associate or to carry out the legal responsibilities of Business Associate, provided that if Business
Associate discloses any Protected Health Information to a third party for such purpose, the Business
Associate shall enter into a written agreement with such third party requiring the following:
A. Disclosure only as Required by Law; or
B. Business Associate obtains reasonable assurances from the person to whom the
information is disclosed that the information will remain confidential and will be used or
further disclosed only as Required by Law or for the purpose for which it was disclosed to
the person, and the person notifies Business Associate of any instances of which it is aware
in which the confidentiality, integrity, and or availability of the Protected Health
Information has been breached immediately upon becoming aware.
(d) Business Associate may provide data aggregation services relating to the health care
operations of Covered Entity pursuant to any agreements between the Parties evidencing their business
relationship as permitted by 45 CFR § 164.504(e)(2)(i)(B).
(e) Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business
Associate to share Protected Health Information with Business Associate’s affiliates or contractors except
for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s)
identified in Section I (a) of this Agreement.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
5
October 2013
(f) Covered Entity Authorization for Additional Uses. Any use of Protected Health
Information by Business Associate, its affiliate or Contractor, other than those purposes of this Agreement,
shall require express written authorization by the Covered Entity, and a Business Associate Agreement or
amendment as necessary. Activities which are prohibited include, but are not limited to, Marketing, as
defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed by Covered
Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal or state laws.
(g) Business Associate may de-identify Protected Health Information only at the specific
direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health
Information except at the direction of Covered Entity and in compliance with the requirements of the
HIPAA Security and Privacy Rule.
IV. AVAILABILITY OF PHI
(a) Access to Protected Health Information. Business Associate agrees, in the event the
Business Associate maintains protected health information in a Designated Record Set, to make available,
within ten (10) days of a request by Covered Entity in a time and manner designated by Covered Entity,
Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered
Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security and
Privacy Rule.
(b) Amendments to Protected Health Information. In the event that the Business Associate
maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make any
amendment(s) to Protected Health Information in a designated record set that the Covered Entity directs or
agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of an individual,
within ten (10) days of receipt of a request from Covered Entity and in the time and manner designated by
Covered Entity.
(c) Accounting of Disclosures. Business Associate agrees to maintain and make available the
information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the
HIPAA Security and Privacy Rule. Business Associate will comply with Covered Entity’s policy regarding
accounting of disclosures.
(d) Document Disclosures. In the event an Individual makes a request under this Section of
the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such
request within three (3) business days and shall cooperate with, and act only at the direction of Covered
Entity in responding to such request.
V. OBLIGATIONS OF COVERED ENTITY
(a) Notice of Privacy Practices. Covered Entity shall provide Business Associate with the
notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as
any changes to that notice.
(b) Notice of Changes in Individual’s Access or Protected Health Information. Covered Entity
shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use
or disclose Protected Health Information, is such changes affect Business Associate’s permitted or required
uses.
(c) Notice of Restriction in Individual’s Access to Protected Health Information. Covered
Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health
Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such
restriction may affect Business Associate’s use of Protected Health Information.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
6
October 2013
VI. PERMISSABLE REQUESTS BY COVERED ENTITY
Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use
or disclose Protected Health Information in any manner that would not be permissible under the Privacy or
Security Rule.
VII. TERMINATION
(a) Term. This Agreement shall be effective as of the date first set forth above and shall
terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the
termination by Covered Entity for cause as provided herein.
(b) Termination for Cause. Notwithstanding anything in this Agreement to the contrary,
Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately if
Covered Entity determines that Business Associate has or will violated any material term of this Agreement.
Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity shall provide
an opportunity for Business Associate to cure the breach or end the violation. Covered Entity may terminate
this Agreement if Business Associate does not cure the breach or end the violation within the time period
specified by Covered Entity. If termination, cure or end of the violation is not feasible, Covered Entity may
report the violation to the Secretary.
(c) Obligation of Business Associate Upon Termination. At termination of this Agreement,
the Service Agreement (or any similar documentation of the business relationship of the Parties), or upon
request of Covered Entity, whichever occurs first, Business Associate, shall:
A. if feasible, return (in a manner or process approved by the Covered Entity) or destroy
all Protected Health Information, regardless of form, including but not limited to paper
or electronic format, received from Covered Entity, or created, maintained or received
by Business Associate on behalf of Covered Entity. Business Associate shall retain no
copies of the Protected Health Information. This provision shall also apply to Protected
Health Information and other confidential information in the possession of sub-
contractors or agents of Business Associate.
B. If such return or destruction is not feasible, Business Associate shall (i) retain only that
Protected Health Information necessary for Business Associate to continue its proper
management and administration or to carry out its legal responsibilities; (ii) return or
destroy the remaining Protected Health Information that the Business Associate still
maintains in any form; (iii) extend the protections of this Agreement to the retained
Protected Health Information; (iv) limit further uses and disclosures to those purposes
that make the return or destruction of the Protected Health Information not feasible;
and (v) return or destroy the retained Protected Health Information when it is no longer
needed by Business Associate.
(d) Survival. This paragraph shall survive the termination of this Agreement and shall apply
to Protected Health Information created, maintained, or received by Business Associate and any of its
subcontractors.
VIII. MISCELLANEOUS
(a) Indemnification. Business Associate agrees to indemnify, defend, and hold harmless
Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims,
losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur by
reason of Business Associate’s breach of or failure to perform any its obligations pursuant to this
Agreement, including but not limited to any injury or damages arising from any noncompliance with this
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
7
October 2013
Agreement or any Security Incident attributable to the negligence of Business Associate, including failure
to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend, and hold
harmless Covered Entity, its officers, employees, contractors and agents, against all costs and expenses,
including but not limited to, reasonable legal expenses, which are incurred by or on behalf of Business
Associate in connection with the defense of such claims.
(b) Disclaimer. Covered Entity makes no warranty or representation that compliance by
Business Associate with this Agreement, HIPAA, HITECH, or the HIPAA Regulations will be adequate
or satisfactory for Business Associate’s own purposes. Business Associate is solely responsible for all
decisions made by Business Associate regarding the safeguarding of Protected Health Information.
(c) Assistance in Litigation or Administrative Proceedings. Business Associate shall make
itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the
performance of its obligations under this Agreement, available to Covered Entity, at no cost to Covered
Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being
commenced against Covered Entity, its directors, officers or employees based upon a claimed violation of
HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy, except where
Business Associate or its subcontractor, employee or agent is named adverse party.
(d) Survival. The obligations of Business Associate under this Agreement shall survive the
expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business
relationship of the parties, and shall continue to bind Business Associate, its agents, employees, contractors,
successors, and assigns as set forth herein.
(e) Ownership of Information. Covered Entity holds all right, title, and interest in and to the
Protected Health Information and Business Associate does not hold and will not acquire by virtue of this
Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or
to the PHI or any portion thereof.
(f) Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that the
breach, or threatened breach, by it of any provision of this Agreement may cause Covered Entity to be
irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore, Business
Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek
injunctive relief to prevent Business Associate from commencing or continuing any action constituting such
breach without having to post a bond or other security and without having to prove the inadequacy of any
other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other remedy
available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA Security
and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties.
(g) Amendment. The Parties agree to take such action as is necessary to amend this
Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the
HIPSS Regulations. In addition, this Agreement may be amended or modified by the Parties only in writing.
(h) Assignment. No Party may assign its respective rights and obligations under this
Agreement without the prior written consent of the other Party.
(i) Independent Contractor. None of the provisions of this Agreement are intended to create,
nor will they be deemed to create any relationship between the Parties other than that of independent parties
contracting with each other solely for the purposes of effecting the provisions of this Agreement and any
other agreements between the Parties evidencing their business relationship. This Agreement will be
governed by the laws of the State of North Carolina. No change, waiver or discharge of any liability or
obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any
continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
8
October 2013
(j) Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH or
the HIPAA Regulations means the section as it currently is in effect or as amended.
(k) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning
that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event
that any documentation of the arrangement pursuant to which Business Associate provides services to
Covered Entity contains provisions relating to the use or disclosure of Protected Health Information that
are more restrictive than the provisions of this Agreement, the more restrictive provisions will control. The
provisions of this Agreement are intended to establish the minimum requirements regarding Business
Associate’s use and disclosure of Protected Health Information.
(l) Severability. In the event any part or parts of this Agreement are held to be unenforceable,
the remainder of this Agreement will continue in effect. In addition, in the event a party believes in good
faith that any provision of this Agreement fails to comply with the then-current requirements of the HIPAA
Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to (30)
thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if
necessary to bring it into compliance. If, after such thirty-day period, a party believes in good faith that the
Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to
terminate upon written notice to the other party.
(m) Notices and Communications. All instructions, notices, consents, demands, or other
communications required or contemplated by this Agreement shall be in writing and shall be delivered to
the Party at the address below:
For Covered Entity: For Business Associate
Orange County Health Department Mark Smith, Ph.D.
300 W. Tryon Street 3909 New Garden Park
Hillsborough, NC 27278 Greensboro, NC 27410
(n) Strict compliance. No failure by any Party to insist upon strict compliance with any terms
or provisions of this Agreement, to exercise any option, to enforce any right, or to seek any remedy upon
any default of any other Party shall affect, or constitute a waiver of, any Party’s right to insist upon such
strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that default
or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at variance
with any provisions of this Agreement shall affect, or constitute a waiver of, any Party’s rig ht to demand
strict compliance with all provisions of this Agreement.
(o) Governing Law. This Agreement shall be governed and construed in accordance with the
laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by
HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County,
North Carolina, for purposes of litigation resulting from disagreements of the Parties for purposes of this
Agreement and the Service Agreement(s).
(p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in
Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract
with governmental units. E-Verify is a Federal program operated by the United States Department of
Homeland Security and other federal agencies, or any successor or equivalent program used to verify the
work authorization of newly hired employees pursuant to federal law. Where applicable, failure to maintain
compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General Statutes shall
constitute breach of this Agreement. If applicable, by executing this Agreement, Business Associate affirms
that they are in compliance with Article 3 of Chapter 64 if the North Carolina General Statutes.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
9
October 2013
IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above.
COVERED ENTITY: BUSINESS ASSOCIATE:
By:_________________________________ By:___________________________________
Title:________________________________ Title:__________________________________
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
8/31/2023Orange County Health Director
10
October 2013
EXHIBIT A
COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION
To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with
the terms of this Agreement that might be considered a privacy breach, Business Associate should contact
the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident (as defined
in the Agreement), Business Associate should contact Ashley Rawlinson (919) 245-2440, or the Security
Officer at The Orange County Health Department.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
From:Melissa Tegeder
To:Kimberlee Quatrone
Cc:Quintana Stewart
Subject:RE: Mark Smith - Waiver of Liability Insurance
Date:Thursday, August 31, 2023 11:31:07 AM
Attachments:image002.png
image010.png
image013.png
image014.png
Hi,
Good to go, thank you!
Could you add in the description of the DocuSign: waiver approved by RM/CM, see email on 8-30-
2023, just so I remember and don’t come back and ask?
Melissa Tegeder
Risk Management Director
131 W Margaret Street,3rd Floor, Hillsborough, NC 27278(919) 245-2155www.orangecountync.gov
CONFIDENTIALITY NOTICE: All email messages, including any attachments, generated from or received by thisaccount are the property of Orange County Government and as such are considered public domain and aresubject to the North Carolina Public Records Law. Certain confidential information may be transmitted and anyunauthorized review, use, disclosure or distribution is prohibited. If you are not the intended recipient, pleasecontact the sender by reply email and destroy all copies of the original message.
From: Kimberlee Quatrone <kquatrone@orangecountync.gov>
Sent: Wednesday, August 30, 2023 12:10 PM
To: Melissa Tegeder <mtegeder@orangecountync.gov>
Cc: Quintana Stewart <qstewart@orangecountync.gov>
Subject: RE: Mark Smith - Waiver of Liability Insurance
Melissa,
I have been told that Mark will not be on-site and he will not have access to any County
systems. We will be giving him raw data which he will assist us in analyzing. I have attached his
scope of work. Please let me know next steps. I’m sorry I was not aware of the new process
regarding insurance waivers.
Kim
Kimberlee Quatrone
Business Officer II
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438
From: Quintana Stewart <qstewart@orangecountync.gov>
Sent: Monday, August 28, 2023 1:32 PM
To: Kimberlee Quatrone <kquatrone@orangecountync.gov>
Cc: Dana Crews <dcrews@orangecountync.gov>
Subject: RE: Mark Smith - Waiver of Liability Insurance
Hi Kim,
Yes, I am willing to assume liability for Mark Smith.
Quintana
Quintana Stewart, MPA
Health Director
Orange County Health Department
300 West Tryon Street
Hillsborough, NC 27278
Phone: 919-245-2412
CONFIDENTIALITY NOTICE: All email messages, including any attachments, generated from or received by this site are the
property of Orange County Government and are considered public domain subject to the North Carolina Public Record
Law. The Orange County Health Department transmits minimal confidential client/patient information via email, and any
unauthorized review, use, disclosure or distribution is prohibited. If you are not the intended recipient, please contact the
sender by reply email and destroy all copies of the original message. If you believe there has been an inappropriate
disclosure, please contact Carla Julian, OCHD HIPAA Privacy and Security Officer, at cjulian@orangecountync.gov.
From: Kimberlee Quatrone <kquatrone@orangecountync.gov>
Sent: Monday, August 28, 2023 12:45 PM
To: Quintana Stewart <qstewart@orangecountync.gov>
Cc: Dana Crews <dcrews@orangecountync.gov>
Subject: Mark Smith - Waiver of Liability Insurance
Importance: High
Quintana,
I don’t believe Mark has Liability insurance. Will you assume liability for Mark Smith and waive
the insurance requirement? He will be crunching numbers into meaningful metrics and data
around the Community Health Assessment. Please let me know by responding to this email. If
so, I will attach it to the contract in lieu of a certificate of insurance.
Thank you.
DocuSign Envelope ID: D980F6A6-30F8-487E-BF23-9297B07E2438