Loading...
HomeMy WebLinkAbout2023-489-E-IT Dept-Catalis Courts & Land Records-Licenses and technical support for AIMS PreTrial and AIMS Specialty Court applicationsRevised 04/23 edited to terminate prior agreement 1 [Departmental Use Only] TITLE AIMSPretrial/SpecCrt FY 24 NORTH CAROLINA AUTOMON SERVICES AGREEMENT ORANGE COUNTY This Services Agreement (hereinafter “Agreement”), made and entered into this 31st day of August, 2023, (“Effective Date”) by and between Orange County, North Carolina a political subdivision of the State of North Carolina (hereinafter, the "County") and Catalis Courts & Land Records, LLC, (hereinafter, the "Provider"). WITNESSETH: That the County and Provider, for the consideration herein named, do hereby agree as follows: 1. Services a. Scope of Work. i) This Agreement is for services to be rendered by Provider to County with respect to (insert type of project): Licenses and technical support for AIMS PreTrial and AIMS Specialty Court applications (see Attachment A) ii) By executing this Agreement, the Provider represents and agrees that Provider is qualified to perform and fully capable of performing and providing the services required or necessary under this Agreement in a fully competent, professional and timely manner. iii) Time is of the essence with respect to this Agreement. iv) The services to be performed under this Agreement consist of Basic Services, as described and designated in Section 3 hereof. Compensation to the Provider for Basic Services under this Agreement shall be as set forth herein. 2. Responsibilities of the Provider a. Services to be provided. The Provider shall provide the County with all services required in Section 3 to satisfactorily complete the Project within the time limitations set forth herein and in accordance with the highest professional standards. b. Standard of Care. i) The Provider shall exercise reasonable care and diligence in performing services under this Agreement in accordance with the highest generally accepted standards of this type of Provider practice throughout the United States and in accordance with applicable federal, state and local laws and regulations applicable to the performance of these services. Provider is solely responsible for the professional DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Revised 04/23 edited to terminate prior agreement 2 quality, accuracy and timely completion and submission of all work related to the Basic Services. ii) Provider shall be responsible for all errors or omissions of its agents, contractors, employees, or assigns in the performance of the Agreement. Provider shall correct any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts at no additional cost to the County. iii) The Provider shall not, except as otherwise provided for in this Agreement, subcontract the performance of any work under this Agreement without prior written permission of the County. No permission for subcontracting shall create, between the County and the subcontractor, any contract or any other relationship. iv) Provider is an independent contractor of County. Any and all employees of the Provider engaged by the Provider in the performance of any work or services required of the Provider under this Agreement, shall be considered employees or agents of the Provider only and not of the County, and any and all claims that may or might arise under any workers compensation or other law or contract on behalf of said employees while so engaged shall be the sole obligation and responsibility of the Provider. v) If activities related to the performance of this Agreement require specific licenses, certifications, or related credentials Provider represents that it or its employees, agents and subcontractors engaged in such activities possess such licenses, certifications, or credentials and that such licenses certifications, or credentials are current, active, and not in a state of suspension or revocation. vi) Should any documents, exhibits, or addenda be attached to this Agreement, the terms of this Agreement shall have priority in any conflict with or among the terms of such referenced documents, exhibits. vii) Should this Agreement involve project designs, the construction or creation of which is to be bid out or fulfilled by other contractors, and bidding or negotiation with contractors produce prices which, when added to the other elements of the approved total project cost, produce a cost that is in excess of the approved total project cost, the Provider shall participate with the County in negotiation and design adjustments to the extent such are necessary to obtain prices within the approved total project cost. All activity of the Provider with respect to these matters shall constitute Basic Services and shall be performed by the Provider without additional compensation. If negotiation and design adjustments fail to bring costs within the total project cost the County may reject all bids and Provider will redesign or reduce portions of the project in an effort to reduce the bid prices to within the total project cost and rebid the project. One such redesign is included within Basic Services. If this second letting for bids does not produce bids that are within the approved total project cost initially or after negotiations with the contractor the cost is not reduced to an amount within the total project cost, the Provider is not obligated to engage in further redesign. 3. Basic Services DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Revised 04/23 edited to terminate prior agreement 3 a. Basic Services. The Services to be rendered pursuant to this Agreement are as follows (fully describe services to be provided): Licenses and technical support for AIMS PreTrial and AIMS Specialty Court applications (see Attachment A) 4. Duration of Services a. Term. The term of this Agreement shall be from 5/1/2023 to 7/31/2024. b. Scheduling of Services. i) The Provider shall schedule and perform its activities in a timely manner. ii) Should the County determine that the Provider is behind schedule, it may require the Provider to expedite and accelerate its efforts, including providing additional resources and working overtime, as necessary, to perform its services in accordance with the approved project schedule at no additional cost to the County. iii) The Commencement Date for the Provider's Basic Services shall be 5/1/2023. 5. Compensation a. Compensation for Basic Services. Compensation for Basic Services shall include all compensation due the Provider from the County for all services satisfactorily (as determined by the County) performed pursuant to this Agreement. The maximum amount payable for Basic Services shall not exceed Nine-thousand-two-hundred- seventy-three and 68/100 Dollars ($9,273.68) (See Attachment A). Payment for satisfactorily performed Basic Services shall become due and payable within thirty (30) days of Provider properly invoicing County. Payment shall be subject to provisions of Section 5(b). b. Disputes. In the event the amount stated on an invoice is disputed by the County, the County may withhold payment of all or a portion of the amount stated on an invoice until the parties resolve the dispute. Should Provider fail to perform its duties under the terms of this Agreement, County may, without fault or penalty, withhold any payment associated with the work to be performed until such time as said work is completed. c. Additional Services. County shall not be responsible for costs related to any services in addition to the Basic Services performed by Provider unless County requests such additional services in writing and such additional services are evidenced by a written amendment to this Agreement. 6. Responsibilities of the County a. Cooperation and Coordination. The County has designated (Sonia Ensenat) to act as the County's representative with respect to the Project who shall have the authority to render decisions within guidelines established by the County Manager or the County Board of Commissioners and who shall be available during working hours as often as may be reasonably required to render decisions and to furnish information. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Revised 04/23 edited to terminate prior agreement 4 7. Insurance a. General Requirements. Provider shall obtain, at its sole expense, Commercial General Liability Insurance, Automobile Insurance, Workers’ Compensation Insurance, and any additional insurance as may be required by County’s Risk Manager as such insurance requirements are described in the Orange County Risk Transfer Policy and Orange County Minimum Insurance Coverage Requirements (each document is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php). If County’s Risk Manager determines additional insurance coverage is required such additional insurance shall consist of $2 million cyber-liability insurance (if no additional insurance required mark N/A as being not applicable). Provider shall not commence work until such insurance is in effect and certification thereof has been received by the County's Risk Manager. 8. Indemnity a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without limitation, to defend, indemnify and hold harmless the County from all loss, liability, claims or expense, including attorney's fees, arising out of or related to the Project and arising from property damage or bodily injury including death to any person or persons caused in whole or in part by the negligence or misconduct of the Provider except to the extent same are caused by the negligence or willful misconduct of the County. It is the intent of this provision to require the Provider to indemnify the County to the fullest extent permitted under North Carolina law. 9. Amendments to the Agreement a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional compensation or a change in duration of this Agreement shall be made by a written Amendment to this Agreement executed by the County and the Provider. The Provider shall proceed to perform the Services required by the Amendment only after receiving a fully executed Amendment from the County. 10. Termination a. Termination for Convenience of the County. This Agreement may be terminated without cause by the County and for its convenience upon seven (7) days’ prior written notice to the Provider. b. Other Termination. The Provider may terminate this Agreement based upon the County's material breach of this Agreement; provided, the County has not taken all reasonable actions to remedy the breach. The Provider shall give the County seven (7) days' prior written notice of its intent to terminate this Agreement for cause. Either party may terminate this Agreement upon notice to the other party that obligations pursuant to this Agreement are made impractical due to declarations of emergency by Orange County or by North Carolina due to events directly impacting Orange County. Both parties shall remain responsible for all payment and performance due up to the receipt of such notice, DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Revised 04/23 edited to terminate prior agreement 5 but shall have no further obligation or responsibility beyond that date provided the terminating party has taken all reasonable steps to complete the performance of its obligations. c. Compensation After Termination. i) In the event of termination, the Provider shall be paid that portion of the fees and expenses that it has earned to the date of termination, less any costs or expenses incurred or anticipated to be incurred by the County due to errors or omissions of the Provider. Upon request of the County, the Provider shall submit to County all relevant documentation, including but not limited to, job cost records, to support its claims for final compensation. ii) Should this Agreement be terminated, the Provider shall deliver to the County within seven (7) days, at no additional cost, all deliverables including any electronic data or files relating to the Project. d. Waiver. The payment of any sums by the County under this Agreement or the failure of the County to require compliance by the Provider with any provisions of this Agreement or the waiver by the County of any breach of this Agreement shall not constitute a waiver of any claim for damages by the County for any breach of this Agreement or a waiver of any other required compliance with this Agreement. e. Suspension. County may suspend the Basic Services and this Agreement at any time for County’s convenience and without penalty to County upon three (3) days’ notice to Provider. Upon any suspension by County, Provider shall discontinue work on the Basic Services and shall not resume the Basic Services until notified to proceed by County. 11. Additional Provisions a. Limitation and Assignment. The County and the Provider each bind themselves, their successors, assigns and legal representatives to the terms of this Agreement. Neither the County nor the Provider shall assign or transfer its interest in this Agreement without the written consent of the other. b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights of respective parties hereunder shall be governed by the laws of the State of North Carolina. By executing this Agreement Provider affirms that Provider and any subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.81. c. Non-Discrimination. Provider shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal non-discrimination laws, policies, rules, and regulations and the Orange DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Revised 04/23 edited to terminate prior agreement 6 County Non-Discrimination Policy and Orange County Living Wage Policy (each policy is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php.) Any violation of the Orange County Non-Discrimination Policy is a breach of this Agreement and County may immediately terminate this Agreement without further obligation on the part of the County. This paragraph is not intended to limit and does not limit the definition of breach to discrimination. d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages with respect to any provision of, or the performance or non-performance of, this Agreement shall be brought in the General Court of Justice of North Carolina sitting in Orange County, North Carolina. It is agreed by the parties that no other court shall have jurisdiction or venue with respect to such suits or actions. Binding arbitration may not be initiated by either Party, however, the Parties may agree to nonbinding mediation of any dispute prior to the bringing of such suit or action. e. Entire Agreement. This Agreement represents the entire and integrated agreement between the County and the Provider and supersedes all prior negotiations, representations or agreements, either written or oral. This Agreement may be amended only by written instrument signed by both parties. Modifications may be evidenced by facsimile signatures. f. Severability. If any provision of this Agreement is held as a matter of law to be unenforceable, the remainder of this Agreement shall be valid and binding upon the Parties. g. Ownership of Work Product. Should Provider’s performance of this Agreement generate documents, items or things that are specific to this Project such documents, items or things shall become the property of the County and may be used on any other project without additional compensation to the Provider. The use of the documents, items or things by the County or by any person or entity for any purpose other than the Project as set forth in this Agreement shall be at the full risk of the County. h. Non-Appropriation. Provider acknowledges that County is a governmental entity, and the validity of this Agreement is based upon the availability of public funding under the authority of its statutory mandate. In the event that public funds are unavailable or not appropriated for the performance of County’s obligations under this Agreement, then this Agreement shall automatically expire without penalty to County immediately upon written notice to Provider of the unavailability or non-appropriation of public funds. It is expressly agreed that County shall not activate this non-appropriation provision for its convenience or to circumvent the requirements of this Agreement. In the event of a change in the County’s statutory authority, mandate or mandated functions, by state or federal legislative or regulatory action, which adversely affects County’s authority to continue its obligations under this Agreement, then this Agreement shall automatically terminate without penalty to County upon written notice to Provider of such limitation or change in County’s legal authority. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Revised 04/23 edited to terminate prior agreement 7 i. Signatures. This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with Article 11A and Article 40 of North Carolina General Statute Chapter 66. j. Notices. Any notice required by this Agreement shall be in writing and delivered by certified or registered mail, return receipt requested to the following: Orange County Provider’s Name Attention:Sonia Ensenat CatalisCourts&LandRecords LLC P.O. Box 8181 3025Windward Plaza,Ste 200 Hillsborough, NC 27278 Alpharetta, GA 30005 k. Termination of Prior Agreement. The County and the Provider entered an agreement January 14th, 2019 for Drug Treatment Case Management Software (“Original Agreement”) for which the software in this current agreement is intended to replace as an upgrade. As such, this agreement hereby terminates and supersedes that Original Agreement. All obligations, payments and debts related to that Original Agreement shall be considered fulfilled as of June 30, 2023. [SIGNATURE PAGE TO FOLLOW] DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Revised 04/23 edited to terminate prior agreement 8 IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have hereunder set their hands and seal, all as of the day and year first above written. ORANGE COUNTY: PROVIDER: By: _________________________________ Bonnie Hammersley, County Manager By: __________________________________ Darrin Rasmussen, EVP Printed Name and Title DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 9/11/20239/12/2023 Revised 04/23 edited to terminate prior agreement 9 ORANGE COUNTY—INTERNAL USE ONLY ______________________________________________________________________________ Finance Information Vendor Name: Catalis Courts & Land Records, LLC Vendor Contact Person: Darrin Rasmussen Phone: 833-781- 8282 Address: 3025 Windward Plaza, Suite 200 City Alpharetta State: GA Zip: 30005 Department: IT Amount: $9,273.68 Purpose: Licenses and technical support for AIMS PreTrial and AIMS Specialty Court applications Budget Code(s): 10315020-625010 Vendor # 67938 Vendor Status with NCSOS: N/A Vendor is a BOCC consultant: Yes No Contract Details Contract Type: New Amendment (Original Contract: ) (Most Recent Amendment ) Effective Date 8/31/2023 End Date 7/31/2024 Notice Date 3/30/2024; 6/30/2024 (Notice Purpose Non- renewal) Award Approved by Board (Agenda Date: ); Made or Administered by Sonia Ensenat Signature Authority - BOCC Express Delegation (Agenda Date: ) - Policy 9.4: Under $5,000; Service Under $90,000; Construction Under $250,000 - Budget Policy Section XV (Capital Improvement Project: ) Bidding Informal Bidding ($30k-$90k); Formal RFP ($90k+); Other (<$30k); Exception(# ) Department Affirmation This agreement is approved as to technical form and content and I as Department Director affirmat ively state work on this project has not been initiated prio r to execution of the agreement. Services related to this agreement have already begun or been completed. Description of the nature of the emergency condition that was addressed: Software is currently in use in the county and subscription for one of the applications renewed on 5/1/23. We had been working with the vendor since November of 2022 to renew the contract and first received the contract documents from the vendor on June 16. We requested a revised quote for fewer licenses and just received those. Department Director’s Signature ________________________________________ Date: ________ Information Technologies This agreement has been reviewed and is approved as to information technology content and specifications: Office of the Chief Information Officer___________________________________ Date: ________ Inapplicable because no hardware/software purchases or related services Risk Management This agreement is approved for sufficiency of insurance standards, specifications, and requirements: Office of the Risk Management Officer___________________________________ Date: _________ Financial Services This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control Act: Office of the Chief Financial Officer ____________________________________ Date: _________ Legal Services This agreement is approved as to legal form and sufficiency: Office of the County Attorney __________________________________________Date: ________ DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 9/12/2023 9/12/2023 9/12/2023 9/12/2023 Revised 04/23 edited to terminate prior agreement 10 Clerk to the Board All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov The following signature block is for hard copies only and is not required for Docusign contracts: Received for record retention: Office of the Clerk to the Board __________________________________________Date:_________ DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 1 of 8 ATTACHMENT A PURCHASED SERVICES – ANNUAL SUBSCRIPTION FEES Product Annual Subscription Term/Notes Amount AIMS Pretrial (Upgrade from Ce Pretrial) Annual Subscription dates 5/1/2023-4/30/2024. Pricing is per user for 3 Users. $4,550.00 AIMS Specialty Court Annual Subscription dates 8/1/2023-7/31/2024. Pricing is agency wide. $4,723.68 Services are limited for use by Orange County (NC) Pretrial Services. Subscription includes unlimited read-only licenses. 1.1 Term of Purchased User Subscriptions. User subscriptions purchased by County commence on the start date specified and continue for the subscription term specified herein. All User subscriptions are subject to an annual 4% annual price escalation, unless either party gives the other notice of non-renewal at least 30 days before the end of the relevant subscription term. 1.2 Refund upon Termination. Upon any termination for cause by County, Provider shall refund County any prepaid fees covering the remainder of the term of all subscriptions after the effective date of termination. 1.3 Return of County Data. Upon request by County made on or before the effective date of the expiration of County subscriptions or within 30 days after any of termination of a Purchased Services subscription, Provider will make available to County for download a file containing County Data in a MS SQL bacpac file along with attachments in their native format. If Provider does not receive a timely request to provide County with a copy of County Data, Provider shall have no obligation to maintain County Data and shall promptly thereafter, unless legally prohibited, delete all of County Data in Provider systems or otherwise in Provider possession or under Provider control. 1.4 Additional Services: Additional mutually-agreed-to Professional Services and/or additional Projects (i.e., Data Conversion, Interfaces with 3rd party systems) may be offered under a separate billable Work Order at a Time and Materials rate of $225/hour (2023 pricing). DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 2 of 8 SCHEDULE A : Description of Software and Scope of Authorized Use PRODUCT DESCRIPTION Hosting Services (Microsoft Azure Government) & System Administration Catalis Courts & Land Records has partnered with Microsoft’s Azure Government Cloud Hosting Platform to provide Hosting Services to our government agency customers. Azure Government is a government-community cloud designed to support strategic government scenarios that require speed, scale, security, compliance, and economics for U.S. government organizations. In addition, Azure Government is designed to meet the higher-level security and compliance needs for sensitive, dedicated, U.S. Public Sector workloads found in regulations such as United States Federal Risk and Authorization Management Program (FedRAMP), Department of Defense Enterprise Cloud Service Broker (ECSB), Criminal Justice Information Services (CJIS) Security Policy and Health Insurance Portability and Accountability Act (HIPAA). Azure Government includes the core components of Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS). This includes infrastructure, network, storage, data management, identity management, and similar services. Your Azure Government hosting includes Geo-Synchronous data replication and auto-scaling. Microsoft has been identified as the leader in both IaaS and PaaS by leading industry analysts. System Administration applicable to Your Services, to include: • SQL Server Licensing • Set-up and Maintain SQL backups with 30-day retention policy • Set-up and Maintain continuous geo replication to a separate Azure Government Data Center • TDE encryption enabled • Apply System Software Patches and Updates (as released by Microsoft) • Disk cleanup (as needed for performance) • Re-boot (as needed for performance) • Monitor (CPU, Memory, and SQL Performance); Resolve Issues • Install updates (new Releases and Versions, as published) • Verify Backup existence (Monthly) • Restore/Verity backup (semi- annually) • Infrastructure Security Audit and Review (Monthly) AIMS-Specialty Court AIMS blends today’s latest technologies with Specialty Court best practices and standards to provide a comprehensive case and data management system for Drug Courts, DUI Courts, Veterans Courts, Mental Health Courts, Family Courts and Tribal Healing to Wellness Courts. A SaaS solution, AIMS automates all aspects of Specialty Court operations from referral, screening, intake, case file management, graduated responses, treatment, drug/alcohol testing, Phase progression, document creating and management, report generation, and data analysis. AIMS is hosted on Microsoft Azure Government AIMS-Pretrial (Upgrade from Ce Pretrial) AIMS-Pretrial is a SaaS case and data management system designed specifically for Pretrial Services agencies to manage all phases of Pretrial efficiently and effectively. With a focus on providing tools to effectively measure and manage risk, AIMS-Pretrial leverages today’s most modern technologies and a high level of configuration to reflect industry best practices married closely with local policies and procedures. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 3 of 8 DESCRIPTION OF SERVICES Annual Subscription shall include all software licenses, hosting services, updates, upgrades, maintenance, and support. Additional users may be added at the current annual per-user pricing. Additional mutually-agreed-to Professional Services and/or additional Projects (i.e., Data Conversion, Interfaces with 3rd party systems) may be offered under a separate billable Work Order at a Time and Materials rate of $225/hour. Additional Modules and Services may become available in future product development releases and may incur additional Subscription licenses and Training/Implementation costs. Purchased Services are subject to an annual price escalation equal to 4%. Provision of Purchased Services. Provider shall make the Purchased Services available to County pursuant to this Agreement and the relevant Order Forms during a subscription term. County agrees that County purchases hereunder are neither contingent on the delivery of any future additional functionality or features nor dependent on any oral or written public comments made by Provider regarding future functionality or features. User Subscriptions. Unless otherwise specified in the applicable Order Form, (i) Services are purchased as User subscriptions and may be accessed by no more than the specified number of Users or if County is a government or corporate entity, the employees who are employed by County or persons under County direct control who provide technical or research services to County, (ii) additional User subscriptions may be added during the applicable subscription term at the same pricing as that for the pre-existing subscriptions thereunder, prorated for the remainder of the subscription term in effect at the time the additional User subscriptions are added or if County are a government or corporate entity, based on pricing negotiated with Provider and reflected in an additional Order Form, and (iii) the added User subscriptions shall terminate on the same date as the pre-existing subscriptions. Unless otherwise specified in the Order Form, User subscriptions are for designated Users only and cannot be shared or used more than one User but may be reassigned to new Users replacing former Users who no longer require ongoing use of the Services. USE OF THE SERVICES 1.1. Our Responsibilities. Provider shall: (i) provide Our basic support for the Purchased Services to County, (ii) use commercially reasonable efforts to make the Services available 24 hours a day, 7 days a week, except for (a) planned downtime of which Provider shall give County notice, or (b) any unavailability of the Services caused by circumstances beyond Our reasonable control, and (iii) provide the Services only in accordance with applicable laws and government regulations. The Services may be subject to limitations, delays, and other problems inherent in the use of the internet and electronic communications. We are not responsible for any delays, delivery failures, or other damages resulting from such problems. 1.2. Our Protection of County Data. Provider shall maintain, or cause to be maintained, commercially reasonable and appropriate administrative, physical, and technical safeguards for protection of the security, confidentiality, and integrity of County Data stored with Our hosting vendor. Provider shall not (a) modify County Data, (b) disclose, provide, rent, or sell County Data except as compelled by law or as expressly permitted in writing by County, or (c) access County Data except to provide the Services and prevent or address service or technical problems, or at Your request in connection with customer support matters. 1.3. County’s Responsibilities. County shall (i) be responsible for Users’ compliance with this Agreement, (ii) be responsible for the accuracy, quality and legality of County Data and of the means by which County acquired County Data, (iii) if applicable to County, maintain processes, controls and procedures to ensure County and County Users compliance with the current version of the CJIS Security Policy, HIPAA regulations and similar statutory and regulatory requirements, (iv) prevent unauthorized access to or use of the Services, and notify Provider promptly of any such unauthorized access or use of any password or account or any other breach of security, (v) use the Services only in accordance with the User Guide and applicable laws and government regulations, (vi) provide all hardware, systems software and third party software for Services that run on County servers, and (vii) provide desktop computers and related software to operate the Services. County shall not (a) use the Services to store or transmit infringing, libelous, or otherwise unlawful or tortious material, or to store or transmit material in violation of third-party privacy rights, (d) use the Services to store or transmit Malicious Code, (e) interfere with or disrupt the integrity or performance of the Services or third-party data contained therein, or (f) attempt to gain unauthorized access to the Services or their related systems or networks. County are responsible for all activities undertaken by County, or County Users which result in unauthorized access to County data. County are solely responsible for any and all costs, expenses, and third party claims or losses related to a data breach, data loss, release of County Data, damage to County Data or similar outcome that results from (1) misuse or unauthorized disclosure of County Data by County or County Users, (2) any unauthorized access to the Services via County Users’ logons or passwords caused by the negligence of County or County Users, (3) DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 4 of 8 any loss of or misuse of an electronic device belonging to County or County Users (e.g. phone, laptop, tablet, computer), (4) an unauthorized disclosure of County Data resulting from County or County Users loss or negligent handling of County Data in electronic or paper form, or (5) ransomware, phishing scam or similar malicious activity emanating from County or any of County Users, or (6) County or County Users’ failure to comply with the provisions of any privacy statutes or regulations that apply to County or County Data (e.g. CJIS, HIPAA and similar), For clarity, this provision is not an obligation for County to indemnity to Us, but rather, is an allocation of risk and responsibility for any resulting costs and expenses associated with the listed actions. 1.4. Usage Limitations. Services may be subject to other limitations or additional charges, such as, for example, on the calls County are permitted to make against Our application programming interface and similar limitations. Any such limitations or charges are specified in the Purchased Services (Attachment A). DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 5 of 8 SCHEDULE B : Service Level Agreement Support Services Handbook – AIMS & Ce Connect Products 1. DESCRIPTION OF SERVICE Catalis is committed to ensuring our customers’ success by offering direct, knowledgeable, and responsive technical support. We strive to create a support environment that will provide you with timely information and prompt resolutions resulting in maximized availability and increased performance of our Software. This handbook provides guidelines and reference materials that describe Catalis’s Software support, system and application upgrade process, certain customer responsibilities and Service Level response times. In most cases, the delivery of our support and maintenance for Catalis Software products and services are governed by the terms and conditions herein. In some cases, you or your firm, company or government agency has executed a separate License, Support and Maintenance Agreement with Catalis. If you have a separate Agreement, to the extent this Handbook and your Agreement differ, your Agreement will govern your support and maintenance arrangements with Catalis. Some of Catalis Software products may be installed locally/on-premise on a customer’s servers or alternatively in Microsoft Azure Cloud; others are hosted exclusively on Microsoft Azure Cloud. Catalis’s responsibilities will depend in some instances on where the Software is installed. For example, if the customer has the Software locally installed on servers they control, database backups, system and Software upgrades, encryption, anti-virus and fraud detection software are the responsibility of the customer. If the Software is hosted on Microsoft Azure Cloud by Catalis, then those same responsibilities will be borne by Catalis. See Customer Responsibilities section for additional responsibilities. The Customer is responsible for First Line Support of any Catalis Software product, without regard to where the Software is hosted. 2. CONTACTING SUPPORT Once a Customer is using an Catalis product or service, support is handled by Catalis’s Help Desk. Support may be requested using Catalis’s toll-free phone number, or via TeamSupport, an online portal for reporting issues or errors. After-hours support is available for an additional hourly fee and only offered on a non-guaranteed response time. The Catalis Help Desk may be reached by calling 1-888-726-8110, ext 2. Catalis’s Standard Support Hours are: Europe and South America Mon-Fri 9 a.m. to 5 p.m. (ET); North America (except for Alaska and Hawaii) Mon-Fri 9 a.m. to 5 p.m. (Local Time Zone); Alaska and Hawaii Mon-Fri 6 a.m. to 5 p.m. (Pacific Time). In all cases, excluding weekends and holidays. Alternatively, TeamSupport can be accessed via the Catalis website Support page at: https://automonllc.na1.teamsupport.com/ Logons and Passwords to Catalis’s TeamSupport are issued through the portal itself. To receive a password, visit the URL above and select “Log In” to create an account. During the Term of your License, Maintenance and Support Agreement or your Master Subscription Agreement, there is no limit to the amount of Standard Business Hours Support so long as you provide Front Line Support in accordance with the terms described below. 3. CUSTOMER RESPONSIBILITES You are required to establish and maintain an internal help desk to provide First Line Support for the Software. This means that you are responsible for your internal network, local hardware, systems software on your servers, desktop configuration and support and basic user questions or problems regarding the features and functions of the Software. In all cases, First Line Support requires you to investigate and provide initial response to your users for the following: ● First call response respecting performance, functionality or operation of the system and Software; ● Attempt to recreate the reported problem; DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 6 of 8 ● Document the reported problem, including, when possible, screenshots and/or detailed descriptions with reproduction steps; ● Document the steps taken by your First Line Support to troubleshoot the problem; ● Resolve, when possible, the problems your users have reported. If after reasonable commercial efforts your First Line Support is unable to diagnose or resolve the issues, your designated representative will contact Catalis Support to report the issue. In the event that you do not establish and maintain First Line Support for your users throughout the term of your Maintenance or Subscription agreement, Catalis reserves the right to request an increase to your current subscription or maintenance fees and/or assess charges for out of scope work. Any additional charges, referred to in the previous sentence, will constitute a change order that must be signed by both parties. Additionally, customers will, at your own expense: ● For customers hosting their Software locally, upgrade all system software on or before the end of Mainstream support from Microsoft (Recommended); ● Update, maintain and patch all system software, security, anti-virus, and fraud detection software to the current releases from the licensor on all customer servers used in connection with the Software; ● Consistent with government regulations (e.g. HIPAA, CJIS), apply database encryption software to secure all private or personal data stored locally while at rest or in transit; ● When the Software is locally installed, implement and perform appropriate data backup and data recovery procedures; ● Secure a high speed internet connection for use by Catalis to perform support services and for your users to access the Software. 4. SERVICE LEVEL DEFINITIONS Service requests for Software may be submitted by your designated representative online via Catalis’s web-based customer support system, TeamSupport, or by telephone. The Service Level shall be determined based on the severity definitions specified below. Service Level Service Level Definition Initial Response Time Resolution 1 Your production use of the Software is stopped or severely impacted such that you cannot continue to work. The operation is mission critical to the business and no Circumvention Procedures are available. 2 hours 2 business days 2 You experience a severe loss of service where essential functionality is unavailable, however, operations can continue in a restricted fashion or by use of a Circumvention Procedure. 1 business day 5 business days 3 You experience a loss of service where nonessential functionality is unavailable and a workaround is not available to restore functionality. 2 business days 25 business days 4 You experience a loss of service where non-essential functionality is unavailable. The impact is an inconvenience, or a Circumvention Procedure is available. 2 business days Within next two version releases 5 A cosmetic or minor issue that does not impact the operation of a Software. 2 business days Issue may be resolved at Catalis’s discretion at a future date 6 All Enhancement requests, usage questions, or requests for training. Also reported problems that are caused by customer computers, local environments, networks or third-party software. 4 business days These requests are outside the scope of our maintenance obligations DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 7 of 8 5. PRODUCT VERSION RELEASES All of Catalis’s Software products include the right to Version Releases throughout the term of any maintenance or subscription agreement. If you host the Software on your servers, you will be responsible for installing Version Releases on your servers. You may contract Catalis to assist with installation at an additional charge. If your Software is hosted by Catalis on Microsoft Azure, Catalis will install the Version Releases. The term “Version Releases” means new versions of the Software you have licensed from Catalis that contain technical repairs, improvements, functional enhancements, updates, and/or maintenance changes to existing functionality. When appropriate, Vers ion Releases will be accompanied by release notes describing the new features or functionality, and where appropriate, an installation guide (locally installed Software only) shall be provided. The Customer shall be responsible for training with respect to each Version Release, or you may contract with Catalis to perform these services. UPGRADE PROCESS For hosted Software, the steps are: 1. Catalis notifies customers via email that a new version or release is ready and when it is scheduled to be deployed. Du ring deployment of new versions or releases, the Software may be unavailable for use for a short period of time; the accompanying release notice will indicate if there is anticipated downtime. In most cases these deployments will occur after business hours. 2. Catalis deploys the Version Release. For on-premise Software (Software that resides on customer owned or controlled servers) the steps are: 1. Catalis will notify customers that a new Version Release to their Software is ready to be deployed. 2. Download the required installation files from the Catalis SFTP site or as otherwise directed by Catalis. Instructions for obtaining and installing those updates will be provided by Catalis. 3. Prepare your servers for implementation, with updates to your servers’ system software, and run the installation files. For a time and materials charge, Catalis will assist with updating local servers and running the installation programs associated with updates. See your Agreement with Catalis for applicable hourly rates. 4. In an increasing number of instances, Version Releases will be installed without active assistance of the customer, via Catalis’s automated update process using Ce Sync. When Ce Sync is utilized to install updates to your Software, you will be notified in advance by Catalis and provided release notes describing the changes that will be implemented. 6. OTHER SUPPORT SERVICES Customers may request additional services by submitting a work or enhancement request through TeamSupport or through the Catalis Sales department (sales@catalisgov.com). Other such services include: (a) additional training; (b) programming or configuration services; and (c) business analysts. Catalis shall provide to Customer a written response to the request which describes in detail the anticipated impact of the request on the existing Software, the time required to perform such services, an implementatio n plan, and a schedule of expected costs. 7. SERVICE LEVEL DEFINITIONS a) “Circumvention” or “Circumvention Procedures” shall mean, as applied to a Documented Defect, a change in operating procedures whereby the Customer can reasonably avoid any deleterious effects of such Documented Defect. b) “Documented Defect” means a failure of the Software to properly perform any of its intended functions. The Customer must use reasonable effort to document a Documented Defect with sufficient information to recreate the defect, including, but not limited to, the operating environment, data set, and user, and the Customer must deliver such information to Catalis concurrently with its notification to Catalis of such defect. The Customer shall use all reasonable efforts to eliminate any non-application related issues prior to its notification to Catalis of such defect, including, but not limited to, issues related to the network, user DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 Page 8 of 8 training and data problems not caused by the Software. Any technical or other issue for which the Customer requests services, but which is not a Documented Defect, shall be treated as a request for additional services requiring a Change Order. c) “Documentation” means the training materials, user’s manuals and other materials in any form or medium provided by Catalis to the users of the Software regarding the use or maintenance of Software. d) "Enhancement." Any modification or addition that, when made or added to the Software, changes its utility, efficiency, functional capability, or application, but that does not constitute an Error Correction. e) "Error." Any failure of the Software to materially conform to its functional specifications as agreement in writing with the Customer or Documentation as published from time to time by Catalis. Any nonconformity resulting from Customer's misuse, improper use, alteration, or damage of the Licensed Program shall not be considered an Error. f) "Error Correction." Either a modification or an addition that, when made or added to the Software, establishes material conformity of the Software to the Documentation, or a procedure or routine that, when observed in the regular operation of the Software, eliminates the practical adverse effect on Customer of such nonconformity. g) “Software” includes any and all Software you license from Catalis under a License, Maintenance and Support agreement or a Master Subscription Agreement. h) “Systems or Third-Party Software” means software licensed by a party other than Catalis. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 1 October 2013 BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (“Agreement”) is made effective the 31st day of August, 2023, by and between Orange County Government through its Orange County Health Department (“Covered Entity”), and Catalis Court & Land Records, LLC, (“Business Associate”). Covered Entity and Business Associate may be referred herein individually as a “Party” or collectively as the “Parties”. This Agreement supersedes any previously executed Business Associate Agreement between the Parties. WITNESSETH: WHEREAS, Sections 261 through 264 of the federal Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), Public Law 104-191, as modified by the Health Information Technology for Economic and Clinical Health Act (“HITECH”), Public Law 111-5, known as “the Administrative Simplification provisions,” direct the Department of Health and Human Services to develop standards to protect the security, confidentiality and integrity of health information; and WHEREAS, pursuant to the Administrative Simplification provisions, the Secretary of Health and Human Services (“Secretary”) has issued regulations modifying the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164, as the same may be amended from time to time (the “HIPAA Security and Privacy Rule”); and WHEREAS, the Parties wish to enter into or have entered into an arrangement whereby Business Associate will provide certain services to Covered Entity, and, pursuant to such arrangements, Business Associate may be considered a “Business Associate” of Covered Entity as defined in the HIPAA Security and Privacy Rule (the agreement evidencing such arrangement is detailed below and hereinafter referred to as the “Service Agreement(s)”); and WHEREAS, Business Associate may have access to Protected Health Information (as defined below) in fulfilling its responsibilities under such arrangement; THEREFORE, in consideration of the Parties’ continuing obligations under the Service Agreement, compliance with the HIPAA Security and Privacy Rule, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree to the provisions of this Agreement in order to address the requirements of the HIPAA Security and Privacy Rule and to protect the interests of both Parties. I. DEFINITIONS (a) Service Agreement. Agreement(s) for services affected by this HIPAA Business Associate Agreement, which this Business Associate Agreement shall be attached to, and is (are) hereby incorporated by reference, and which shall be taken and considered as a part of this document the same as if fully set out herein: Name of Agreement(s) (b) Catch-all Provision. Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the HIPAA Security and Privacy Rule, 45 CFR Parts 160 and 164, subparts A and E. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the HIPAA Security and Privacy Rule, as amended, the HIPAA Security and Privacy Rule shall control. Where provisions of this Agreement are different than those mandated in the HIPAA Security and Privacy Rule, but are nonetheless permitted by the HIPAA Security and Privacy Rule, the provisions of this Agreement shall control. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 2 October 2013 (c)Electronic Protected Health Information. Protected Health Information that is transmitted by or maintained in Electronic Media (as defined in the HIPAA Security and Privacy Rule). (d)Protected Health Information. “Protected Health Information” shall have the same meaning as the term in 45 CFR § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity and includes without limitation “Electronic Protected Health Information.” Business Associate acknowledges and agrees that all Protected Health Information that is created or received by Covered Entity and disclosed or made available in any form, including paper record, oral communication, audio recording, and electronic display by Covered Entity or its operating units to Business Associate or is created or received by Business Associate on Covered Entity’s behalf shall be subject to this Agreement. (e)Required by Law. “Required by Law” shall have the same meaning as the term in 45 CFR § 164.103. II.OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE (a)Use and Disclosure. Business Associate agrees to fully comply with the requirements under the HIPPA Security and Privacy Rule applicable to Business Associates and not to use or disclose Protected Health Information other than as permitted or required by this Agreement, the Service Agreement or as Required by Law. To the extent Business Associate carries out obligations of Covered Entity under the HIPAA Security and Privacy Rule, Business Associate shall comply with the applicable provisions of the HIPAA Security and Privacy Rule as if such use or disclosure were made by Covered Entity. Business Associate agrees to comply with Covered Entity’s policies regarding the minimum necessary use or disclosure of Protected Health Information. (b)Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of Protected Health Information other than as provided for by this Service Agreement(s), this Agreement or as Required by Law. This includes the implementation physical, technical and administrative safeguards to prevent use or disclosure of Protected Health Information other than as permitted in this Agreement or Required by Law and reasonably and appropriately protect the confidentiality, integrity, and availability of any Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity as required by the HIPAA Security and Privacy Rule. The Business Associate shall maintain appropriate documentation of its compliance with the HIPPA Security and Privacy Rule, including, but not limited to, its policies, procedures, records of training and sanctions of members in its workforce. (c)Assurances. Business Associate agrees to provide Covered Entity with written assurances that any Protected Health Information placed on any type of mobile media, including, but by no means limited to, lap top computers, Ipads and mobile phones, is encrypted in accordance with guidance issued by the Secretary. (d)Agents and Subcontractors. Business Associate shall require any agents, including any subcontractors, to whom it provides Protected Health Information from Covered Entity that is created, received, maintained or transmitted on behalf of Business Associate to agree by written contract with Business Associate to the same (or greater) restrictions, conditions and requirements that apply to Business Associate with respect to such information, and to agree to implement reasonable and appropriate safeguards to protect any of such information that is Electronic Protected Health Information. In addition, Business Associate agrees to take reasonable steps to ensure that its employees’ actions or omissions do not cause Business Associate to breach the terms of this Agreement. (e)Mitigation of Breach. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 3 October 2013 by Business Associate in violation of the requirements of this Agreement, as well as to provide complete cooperation to Covered Entity should Covered Entity elect to review or investigate such noncompliance or Security Incident. Business Associate shall cooperate in Covered Entity’s breach analysis and/or risk assessment, if requested. Furthermore, Business Associate shall cooperate with Covered Entity in the event that Covered Entity determines that any third parties must be notified of a Breach, provided that Business Associate shall not provide any such notification except at the direction of Covered Entity. (f)Breach Reporting. Business Associate shall report in writing to Covered Entity’s Privacy Officer (see Exhibit A), any use or disclosure of Protected Health Information that is not in compliance with the terms of this Agreement, as well as any Security Incident and any actual or suspected Breach, of which it becomes aware, without unreasonable delay, and in no event later than forty-eight (48) hours of such discovery. For purposes of this Agreement, “Security Incident” means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Such notification shall contain the elements required by 45 C.F.R. § 164.410. (g)Compliance. To the extent applicable, Business Associate will comply with (i) Covered Entity’s Notice of Privacy Practices; (ii) any limitations to which Covered Entity has agreed in regard to an Individual’s permission to use or disclose his or her Protected Health Information; and (iii) any restrictions to the use or disclosure of Protected Health Information to which Covered Entity has agreed or is required to agree. (h)Government Access. Business Associate will make its internal practices, books and records available to the Secretary of the Department of Health and Human Services for purposes of determining compliance with the terms of the HIPAA Security and Privacy Rule, and, at the request of the Secretary, will comply with any investigations and compliance reviews, permit access to information, and cooperate with any complaints, as Required by Law. Without unreasonable delay and, in any event, no more than 48 hours of receipt of the request or notification, Business Associate will notify Covered Entity in writing of any request by any governmental entity, or its designee, to review Business assessment of any kind. (i)Electronic Transactions. If Business Associate conducts any Standard Transactions for or on behalf of Covered Entity, Business Associate shall comply with the requirements under the Electronic Transaction Rule. (j)Audit. Business Associate shall permit Covered Entity, in its discretion, to conduct an audit of Business Associate’s compliance with this Agreement, HIPAA, and HITECH. Such audit may consist of an onsite visit, a series of inquiries that require written responses, or both. Business Associate shall promptly and completely respond to Covered Entity’s requests for information in support of the audit, which shall not be conducted more than once annually except in cases of an actual or reasonably suspected Security Incident or reasonably suspected noncompliance with this Agreement, HIPAA or HITECH. Each Party shall bear its own costs associated with the audit. (k)Identity Theft. Business Associate shall implement Identity Theft Monitoring Policies and Procedures to protect any patient information that may be breached by the Business Associate to the extent applicable under the Federal Trade Commission’s Red Flag Rules. (l)HITECH Compliance. Business Associate shall: A.Not receive, directly or indirectly, any impermissible remuneration in exchange for Protected Health Information or Electronic Protected Health Information, except as permitted by HITECH § 13405(d) or the HIPPA Regulations; B.Comply with the marketing and other restrictions applicable to Business Associates contained in HITECH § 13406 and the HIPPA Regulations; DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 4 October 2013 C.To the extent required under HITECH § 13404, fully comply with the applicable requirements of 45 CFR 164.502(e)(2) for each use and disclosure of Protected Health Information; D.To the extent required under HITECH § 13401, fully comply with 45 CFR §§ 164.308, 164.310, 164.312, and 164.316; E.To the extent required under HITECH §§13401 and 13404, comply with the additional privacy and security requirements that apply to Covered Entities in the same manner and to the same extent as Covered Entity is required to do so; and F.To the extent required under the HIPPA Regulations, comply with the privacy and security requirements that apply to Business Associates. (m)State Privacy Laws. Business Associate shall understand and comply with state privacy laws to the extent that such privacy laws are not preempted by HIPPA or HITECH. III.PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE (a)Use of Protected Health Information on Behalf of Covered Entity. Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities or services for, or on behalf of, Covered Entity described in the Service Agreement, provided that such use or disclosure would not violate the HIPPA Security and Privacy Rule if it were made by Covered Entity or would not violate the Covered Entities minimum necessary policies. (b)Other Uses of Protected Health Information. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information within its workforce for the proper management and administration of Business Associate not to include Marketing or Commercial Use and to carry out the legal responsibilities of Business Associate; and (c)Third Party Confidentiality. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided that if Business Associate discloses any Protected Health Information to a third party for such purpose, the Business Associate shall enter into a written agreement with such third party requiring the following: A.Disclosure only as Required by Law; or B.Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and will be used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality, integrity, and or availability of the Protected Health Information has been breached immediately upon becoming aware. (d)Business Associate may provide data aggregation services relating to the health care operations of Covered Entity pursuant to any agreements between the Parties evidencing their business relationship as permitted by 45 CFR § 164.504(e)(2)(i)(B). (e)Other Uses Strictly Limited. Nothing in this Agreement shall permit the Business Associate to share Protected Health Information with Business Associate’s affiliates or contractors except for the purposes of the Service Agreement(s) between the Covered Entity and Business Associate(s) identified in Section I (a) of this Agreement. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 5 October 2013 (f)Covered Entity Authorization for Additional Uses. Any use of Protected Health Information by Business Associate, its affiliate or Contractor, other than those purposes of this Agreement, shall require express written authorization by the Covered Entity, and a Business Associate Agreement or amendment as necessary. Activities which are prohibited include, but are not limited to, Marketing, as defined by 45 CFR § 164.503 or the sharing for Commercial Use or any purpose construed by Covered Entity as Marketing or Commercial Use, even if such sharing would be permitted by federal or state laws. (g)Business Associate may de-identify Protected Health Information only at the specific direction of and only for the use of Covered Entity. Business Associate may not sell Protected Health Information except at the direction of Covered Entity and in compliance with the requirements of the HIPAA Security and Privacy Rule. IV.AVAILABILITY OF PHI (a)Access to Protected Health Information. Business Associate agrees, in the event the Business Associate maintains protected health information in a Designated Record Set, to make available, within ten (10) days of a request by Covered Entity in a time and manner designated by Covered Entity, Protected Health Information in a Designated Record Set, to Covered Entity or as directed by Covered Entity, to an individual in order to meet the requirements of 45 CFR § 164.524 of the HIPAA Security and Privacy Rule. (b)Amendments to Protected Health Information. In the event that the Business Associate maintains Protected Health Information in a Designated Record Set, Business Associate agrees to make any amendment(s) to Protected Health Information in a designated record set that the Covered Entity directs or agrees to pursuant to the HIPAA Security and Privacy Rule at the request of Covered Entity of an individual, within ten (10) days of receipt of a request from Covered Entity and in the time and manner designated by Covered Entity. (c)Accounting of Disclosures. Business Associate agrees to maintain and make available the information required to provide an accounting of disclosures, as required by 45 CFR § 164.528 of the HIPAA Security and Privacy Rule. Business Associate will comply with Covered Entity’s policy regarding accounting of disclosures. (d)Document Disclosures. In the event an Individual makes a request under this Section of the Agreement directly to Business Associate, Business Associate will notify Covered Entity of such request within three (3) business days and shall cooperate with, and act only at the direction of Covered Entity in responding to such request. V. OBLIGATIONS OF COVERED ENTITY (a)Notice of Privacy Practices. Covered Entity shall provide Business Associate with the notice of privacy practice that Covered Entity produces in accordance with 45 CFR § 164.520, as well as any changes to that notice. (b)Notice of Changes in Individual’s Access or Protected Health Information. Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, is such changes affect Business Associate’s permitted or required uses. (c)Notice of Restriction in Individual’s Access to Protected Health Information. Covered Entity shall notify Business Associate of any restrictions to the use or disclosure of Protected Health Information that Covered Entity has agreed in accordance with 45 CFR § 164.522 to the extent that such restriction may affect Business Associate’s use of Protected Health Information. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 6 October 2013 VI.PERMISSABLE REQUESTS BY COVERED ENTITY Requests Permissible Under HIPAA. Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy or Security Rule. VII.TERMINATION (a)Term. This Agreement shall be effective as of the date first set forth above and shall terminate upon the earlier of (i) the termination of all agreements between the parties, and (ii) the termination by Covered Entity for cause as provided herein. (b)Termination for Cause. Notwithstanding anything in this Agreement to the contrary, Covered Entity shall have the right to terminate this Agreement and the Service Agreement immediately if Covered Entity determines that Business Associate has or will violated any material term of this Agreement. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity shall provide an opportunity for Business Associate to cure the breach or end the violation. Covered Entity may terminate this Agreement if Business Associate does not cure the breach or end the violation within the time period specified by Covered Entity. If termination, cure or end of the violation is not feasible, Covered Entity may report the violation to the Secretary. (c)Obligation of Business Associate Upon Termination. At termination of this Agreement, the Service Agreement (or any similar documentation of the business relationship of the Parties), or upon request of Covered Entity, whichever occurs first, Business Associate, shall: A.if feasible, return (in a manner or process approved by the Covered Entity) or destroy all Protected Health Information, regardless of form, including but not limited to paper or electronic format, received from Covered Entity, or created, maintained or received by Business Associate on behalf of Covered Entity. Business Associate shall retain no copies of the Protected Health Information. This provision shall also apply to Protected Health Information and other confidential information in the possession of sub- contractors or agents of Business Associate. B.If such return or destruction is not feasible, Business Associate shall (i) retain only that Protected Health Information necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities; (ii) return or destroy the remaining Protected Health Information that the Business Associate still maintains in any form; (iii) extend the protections of this Agreement to the retained Protected Health Information; (iv) limit further uses and disclosures to those purposes that make the return or destruction of the Protected Health Information not feasible; and (v) return or destroy the retained Protected Health Information when it is no longer needed by Business Associate. (d)Survival. This paragraph shall survive the termination of this Agreement and shall apply to Protected Health Information created, maintained, or received by Business Associate and any of its subcontractors. VIII.MISCELLANEOUS (a)Indemnification. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, agents, contractors and agents, against, and in respect of, any and all claims, losses, expenses, costs, damages, obligations, penalties, and liabilities which Covered Entity may incur by reason of Business Associate’s breach of or failure to perform any its obligations pursuant to this DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 7 October 2013 Agreement, including but not limited to any injury or damages arising from any noncompliance with this Agreement or any Security Incident attributable to the negligence of Business Associate, including failure to execute the terms of this Agreement. Further, Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, employees, contractors and agents, against all costs and expenses, including but not limited to, reasonable legal expenses, which are incurred by or on behalf of Business Associate in connection with the defense of such claims. (b)Disclaimer. Covered Entity makes no warranty or representation that compliance by Business Associate with this Agreement, HIPAA, HITECH, or the HIPAA Regulations will be adequate or satisfactory for Business Associate’s own purposes. Business Associate is solely responsible for all decisions made by Business Associate regarding the safeguarding of Protected Health Information. (c)Assistance in Litigation or Administrative Proceedings. Business Associate shall make itself, and any subcontractors, employees, affiliates or agents assisting Business Associate in the performance of its obligations under this Agreement, available to Covered Entity, at no cost to Covered Entity, to testify as witnesses, or otherwise, in the event of litigation or administrative proceedings being commenced against Covered Entity, its directors, officers or employees based upon a claimed violation of HIPAA, HITECH, the HIPAA Regulations, or other laws relating to security and privacy, except where Business Associate or its subcontractor, employee or agent is named adverse party. (d)Survival. The obligations of Business Associate under this Agreement shall survive the expiration, termination, or cancellation of this Agreement, the Service Agreement and/or the business relationship of the parties, and shall continue to bind Business Associate, its agents, employees, contractors, successors, and assigns as set forth herein. (e)Ownership of Information. Covered Entity holds all right, title, and interest in and to the Protected Health Information and Business Associate does not hold and will not acquire by virtue of this Agreement or by virtue of providing goods or services to Covered Entity, any right, title, or interest in or to the PHI or any portion thereof. (f)Right to Injunctive Relief. Business Associate expressly acknowledges and agrees that the breach, or threatened breach, by it of any provision of this Agreement may cause Covered Entity to be irreparably harmed and that Covered Entity may not have an adequate remedy at law. Therefore, Business Associate agrees that upon such breach, or threatened breach, Covered Entity will be entitled to seek injunctive relief to prevent Business Associate from commencing or continuing any action constituting such breach without having to post a bond or other security and without having to prove the inadequacy of any other available remedies. Nothing in this paragraph will be deemed to limit or abridge any other remedy available to Covered Entity at law or in equity. Except as expressly stated herein or in the HIPAA Security and Privacy Rule, the parties to this Agreement do not intend to create any rights in any third parties. (g)Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the HIPSS Regulations. In addition, this Agreement may be amended or modified by the Parties only in writing. (h)Assignment. No Party may assign its respective rights and obligations under this Agreement without the prior written consent of the other Party. (i)Independent Contractor. None of the provisions of this Agreement are intended to create, nor will they be deemed to create any relationship between the Parties other than that of independent parties contracting with each other solely for the purposes of effecting the provisions of this Agreement and any other agreements between the Parties evidencing their business relationship. This Agreement will be governed by the laws of the State of North Carolina. No change, waiver or discharge of any liability or obligation hereunder on any one or more occasions shall be deemed a waiver of performance of any continuing or other obligation, or shall prohibit enforcement of any obligation, on any other occasion. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 8 October 2013 (j)Regulatory References. A reference in this Agreement to a section in HIPAA, HITECH or the HIPAA Regulations means the section as it currently is in effect or as amended. (k)Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the HIPAA Regulations. The parties agree that, in the event that any documentation of the arrangement pursuant to which Business Associate provides services to Covered Entity contains provisions relating to the use or disclosure of Protected Health Information that are more restrictive than the provisions of this Agreement, the more restrictive provisions will control. The provisions of this Agreement are intended to establish the minimum requirements regarding Business Associate’s use and disclosure of Protected Health Information. (l)Severability. In the event any part or parts of this Agreement are held to be unenforceable, the remainder of this Agreement will continue in effect. In addition, in the event a party believes in good faith that any provision of this Agreement fails to comply with the then-current requirements of the HIPAA Security and Privacy Rule, such party shall notify the other party in writing. For a period of up to (30) thirty days, the parties shall address in good faith such concern and amend the terms of this Agreement, if necessary to bring it into compliance. If, after such thirty-day period, a party believes in good faith that the Agreement fails to comply with the HIPAA Security and Privacy Rule, then either party has the right to terminate upon written notice to the other party. (m)Notices and Communications. All instructions, notices, consents, demands, or other communications required or contemplated by this Agreement shall be in writing and shall be delivered to the Party at the address below: For Covered Entity: For Business Associate (n)Strict compliance. No failure by any Party to insist upon strict compliance with any terms or provisions of this Agreement, to exercise any option, to enforce any right, or to seek any remedy upon any default of any other Party shall affect, or constitute a waiver of, any Party’s right to insist upon such strict compliance, exercise that option, enforce that right, or seek that remedy with respect to that default or any prior, or contemporaneous, or subsequent default. No custom or practice of the Parties at variance with any provisions of this Agreement shall affect, or constitute a waiver of, any Party’s right to demand strict compliance with all provisions of this Agreement. (o) Governing Law. This Agreement shall be governed and construed in accordance with the laws of the State of North Carolina except to the extent that North Carolina laws have been pre-empted by HIPAA and without giving effect to principals of conflicts of law. Jurisdiction shall be Orange County, North Carolina, for purposes of litigation resulting from disagreements of the Parties for purposes of this Agreement and the Service Agreement(s). (p) E-Verify. Employers and their subcontractors with 25 or more employees as defined in Article 2 of Chapter 64 of the NC General Statutes must comply with E-Verify requirements to contract with governmental units. E-Verify is a Federal program operated by the United States Department of Homeland Security and other federal agencies, or any successor or equivalent program used to verify the work authorization of newly hired employees pursuant to federal law. Where applicable, failure to maintain compliance with the requirements of Article 2 of Chapter 64 of the North Carolina General Statutes shall constitute breach of this Agreement. If applicable, by executing this Agreement, Business Associate affirms that they are in compliance with Article 3 of Chapter 64 if the North Carolina General Statutes. IN WITNESS WHEREOF, the Parties have executed this Agreement as of the day and year written above. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 9 October 2013 BUSINESS ASSOCIATE: By:___________________________________ COVERED ENTITY: By:_________________________________ Title: Deputy County Manager Title:__________________________________ DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 EVP, Courts and Land Records 9/11/20239/12/2023 10 October 2013 EXHIBIT A COVERED ENTITY PRIVACY OFFICER CONTACT INFORMATION To report to Covered Entity any use or disclosure of Protected Health Information not in compliance with the terms of this Agreement that might be considered a privacy breach, Business Associate should contact the Privacy Officer at the applicable entity. To report to Covered Entity any Security Incident (as defined in the Agreement), Business Associate should contact , or the Security Officer at The Orange County Health Department. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN ACCORDANCE WITH THE POLICY PROVISIONS. INSURER(S) AFFORDING COVERAGE INSURER F : INSURER E : INSURER D : INSURER C : INSURER B : INSURER A : NAIC # NAME:CONTACT (A/C, No):FAX E-MAILADDRESS: PRODUCER (A/C, No, Ext):PHONE INSURED REVISION NUMBER:CERTIFICATE NUMBER:COVERAGES IMPORTANT: If the certificate holder is an ADDITIONAL INSURED, the policy(ies) must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy, certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED REPRESENTATIVE OR PRODUCER, AND THE CERTIFICATE HOLDER. OTHER: (Per accident) (Ea accident) $ $ N / A SUBR WVD ADDL INSD THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES. LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. $ $ $ $PROPERTY DAMAGE BODILY INJURY (Per accident) BODILY INJURY (Per person) COMBINED SINGLE LIMIT AUTOS ONLY AUTOSAUTOS ONLY NON-OWNED SCHEDULEDOWNED ANY AUTO AUTOMOBILE LIABILITY Y / N WORKERS COMPENSATION AND EMPLOYERS' LIABILITY OFFICER/MEMBER EXCLUDED? (Mandatory in NH) DESCRIPTION OF OPERATIONS below If yes, describe under ANY PROPRIETOR/PARTNER/EXECUTIVE $ $ $ E.L. DISEASE - POLICY LIMIT E.L. DISEASE - EA EMPLOYEE E.L. EACH ACCIDENT EROTH-STATUTEPER LIMITS(MM/DD/YYYY)POLICY EXP(MM/DD/YYYY)POLICY EFFPOLICY NUMBERTYPE OF INSURANCELTRINSR DESCRIPTION OF OPERATIONS / LOCATIONS / VEHICLES (ACORD 101, Additional Remarks Schedule, may be attached if more space is required) EXCESS LIAB UMBRELLA LIAB $EACH OCCURRENCE $AGGREGATE $ OCCUR CLAIMS-MADE DED RETENTION $ $PRODUCTS - COMP/OP AGG $GENERAL AGGREGATE $PERSONAL & ADV INJURY $MED EXP (Any one person) $EACH OCCURRENCE DAMAGE TO RENTED $PREMISES (Ea occurrence) COMMERCIAL GENERAL LIABILITY CLAIMS-MADE OCCUR GEN'L AGGREGATE LIMIT APPLIES PER: POLICY PRO-JECT LOC CERTIFICATE OF LIABILITY INSURANCE DATE (MM/DD/YYYY) CANCELLATION AUTHORIZED REPRESENTATIVE ACORD 25 (2016/03) © 1988-2015 ACORD CORPORATION. All rights reserved. CERTIFICATE HOLDER The ACORD name and logo are registered marks of ACORD HIRED AUTOS ONLY 6/20/2023 Arthur J.Gallagher Risk Management Services,LLC Six Desta Drive,Suite 5900 Midland TX 79705 432-570-3456 432-570-3450 Hartford Fire Insurance Company 19682 CATALIS-01 Trumbull Insurance Company 27120CatalisCourts&Land Records,LLC 3025 Windward Plaza Ste 200 Alpharetta GA 30005 Hartford Casualty Insurance Company 29424 The Harford Mutual Insurance Company 14141 Associated Industries Insurance Co,Inc 23140 847732103 A X 1,000,000 X 300,000 10,000 1,000,000 2,000,000 X Y Y 20UUNEL6049 6/20/2023 6/20/2024 2,000,000 B 1,000,000 X X X Y Y 46UENEL7176 6/20/2023 6/20/2024 C X X 5,000,000Y46XHUEL65306/20/2023Y 6/20/2024 X 10,000 D X N Y 20 WE AH8FBG 1/1/2023 1/1/2024 1,000,000 1,000,000 1,000,000 E Professional Liability Cyber Liability Y Y Y Y AES1234141-00 6/20/2023 6/20/2024 Professional Cyber $5,000,000 $5,000,000 Certificate Holder is an Additional Insured as respects to the General Liability,Automobile,Cyber/Professional policies,pursuant to the policy’s terms, definitions,conditions and exclusions,as per endorsement HG0001 edition (09 16),HA9916,edition (12-21),TRD443 edition (09-17). Waiver of Subrogation applies to certificate holder,as respects to the General Liability,Automobile,Cyber/Professional policies,pursuant to the policy’s terms, definitions,conditions and exclusions,as per endorsement HG0001 edition (09 16),HA9916,edition (12-21),TRD443 edition (09-17). The insurance provided in the General Liability policy is primary and noncontributing as per endorsement HG0001 edition (09 16). See Attached... Orange County Pretrial Services 100 N Churton St #207 Hillsborough NC 27278 DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199 ACORD 101 (2008/01) The ACORD name and logo are registered marks of ACORD © 2008 ACORD CORPORATION. All rights reserved. THIS ADDITIONAL REMARKS FORM IS A SCHEDULE TO ACORD FORM, FORM NUMBER:FORM TITLE: ADDITIONAL REMARKS ADDITIONAL REMARKS SCHEDULE Page of AGENCY CUSTOMER ID: LOC #: AGENCY CARRIER NAIC CODE POLICY NUMBER NAMED INSURED EFFECTIVE DATE: CATALIS-01 1 1 Arthur J.Gallagher Risk Management Services,LLC Catalis Courts &Land Records,LLC 3025 Windward Plaza Ste 200 Alpharetta GA 30005 25 CERTIFICATE OF LIABILITY INSURANCE Orange County Pretrial Services is an additional insured for any and all work performed by the named insured as respects general liability and automobile liability,as per written contract or agreement,subject to the policy's terms,conditions and exclusions.Waiver of subrogation is applicable to the general liability, automobile liability and workers compensation,as per written contract or agreement,subject to the policy's terms,conditions and exclusions. DocuSign Envelope ID: DB3028D2-AD5E-4CCF-84B3-305C2A760199