1.4 - Sample Business Associate Agreement.docx

DOCX document 399 KB Posted

Attached to
Third Party Administrator (TPA) for the Public Employees' Benefits Program (PEBP) State and local contract opportunity
Solicitation number
95PEBP-S1579
Issued by
Churchill County, Nevada

About this file

This document is a Business Associate Agreement between the State of Nevada on behalf of the Public Employees' Benefits Program (PEBP) and a Vendor Name for the provision of third party administrator (TPA) services. The agreement outlines the permitted and required uses and disclosures of protected health information (PHI) by the Business Associate in performing the TPA services for PEBP. Key details include requirements for safeguards, breach notification, audits, access to and amendment of PHI, and documentation of disclosures. The agreement has a term that continues until all PHI is returned or destroyed upon termination.

The related state and local contract opportunity is for a Third Party Administrator (TPA) for the Public Employees' Benefits Program (PEBP) in the state of Nevada, including the jurisdiction of Carson City. The contract involves the provision of TPA services such as claims administration, eligibility management, and data analytics. No specific quantities, response dates, or award details are provided in the information given.

View the file

Other files for this state and local contract opportunity

Other files attached to Third Party Administrator (TPA) for the Public Employees' Benefits Program (PEBP), newest first.
File Type Posted
1.3 - Insurance Schedule.docx DOCX document
95PEBP-S1579 Bid QA.xlsx XLSX spreadsheet
95PEBP-S1579 Presentation Notification~2.pdf PDF
2.2 - TPA RFP Revised 2021-05-07.xlsx XLSX spreadsheet
2.3 - References - CONFIDENTIAL.xlsx XLSX spreadsheet
1.6 - Enrollment Summary 202104.xlsx XLSX spreadsheet
1.5 - Paid Claims Summary 201901-202012.xlsx XLSX spreadsheet
2.1 - Intent to bid.pdf PDF
1.1 - RFP Information.docx DOCX document
1.2 - Standard Form Contract.docx DOCX document
1.7 - Discount Instructions.pdf PDF
95PEBP-S1579 Letter of Intent.pdf PDF
Quote Instructions.pdf PDF
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Business Associate Agreement

By and Between

State of Nevada on its own behalf and on behalf of the

Public Employees’ Benefits Program (PEBP) and

[VENDOR NAME]

Attachment EE

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement (“Agreement”) is effective [DATE] and made by and between the State of Nevada, acting by and through its Public Employees’ Benefits Program (together “PEBP” or “Covered Entity”), and [VENDOR NAME] (“Business Associate”), (collectively, the “Parties”). This Business Associate Agreement shall replace any prior Business Associates Agreement the Parties had entered into previously. Terms appearing below in the “Witnesseth” section with initial upper case letters shall have the respective meanings assigned to them in this introductory paragraph or in Section 1.02 of this Agreement, as applicable.

WITNESSETH:

WHEREAS, Business Associate has previously entered into an arrangement with the State of Nevada PEBP and/or the Covered Entity to provide Services to or on behalf of the Covered Entity;

WHEREAS, the Parties acknowledge and agree that in providing Services to or on behalf of the Covered Entity, Business Associate will create, receive, use, maintain, access, transmit, or disclose Protected Health Information;

WHEREAS, the Parties intend to enter into this Agreement to address the requirements of HIPAA, HITECH, the Privacy Rule, the Security Rule, the Breach Notification Standards, and the Enforcement Rule (including the applicable changes to the Privacy Rule, Security Rule, Breach Notification Standards, and Enforcement Rule as set forth in the omnibus final rules effective on March 26, 2013) as they apply to “business associates”, including the establishment of permitted and required uses and disclosures (and appropriate limitations and conditions on such uses and disclosures) of Protected Health Information by Business Associate that is created or received in the course of performing Services on behalf of the Covered Entity; and WHEREAS, the objective of this Agreement is to provide the State of Nevada and the Covered Entity with reasonable assurances that Business Associate will appropriately safeguard the Protected Health Information that it creates or receives in the course of providing Services to the Covered Entity;

NOW, THEREFORE, in connection with Business Associate’s creation, receipt, use or disclosure of Protected Health Information and in consideration for the mutual promises contained herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties hereby agree as follows:

ARTICLE I

Definitions

1.01General Definitions. All terms appearing in this Agreement with initial upper case letters that are not otherwise defined in this Agreement shall have the same meaning as that provided for the respective terms in 45 C.F.R. §§ 160.103, 160.202, 160.401, 164.103, 164.304, 164.402, and 164.501. To the extent that there are any conflicts between the meanings assigned to the respective terms in this Agreement and HIPAA, the HIPAA meanings shall control for purposes of this Agreement.
1.02Specific Definitions. For purposes of this Agreement, the following terms shall have the indicated meanings whenever the term appears with initial upper case letters in this Agreement:

“Business Associate” shall have the same meaning as the term “business associate” at 45 C.F.R. § 160.103, and, in reference to the party to this Agreement, shall mean Healthscope Benefits, Inc.

(a) “Breach” shall mean the acquisition, access, use, or disclosure of Protected Health Information in a manner not permitted by HIPAA or 45 CFR Part 164, Subpart E which compromises the security or privacy of the Protected Health Information unless such acquisition, access, use, or disclosure is otherwise excluded under 45 C.F.R. § 164.402(1). For purposes of this Agreement, an acquisition, access, use or disclosure of Protected Health Information in a manner not permitted by HIPAA or 45 CFR Part 164, Subpart E is presumed to be a breach unless the Business Associate demonstrates to the satisfaction of the Covered Entity that there is a low probability that the Protected Health Information has been compromised based on the Business Associate’s risk assessment of at least the following factors: (i) the nature and extent of the Protected Health Information involved, including the types of identifiers and the likelihood of re-identification; (ii) the unauthorized person who used the Protected Health Information or to whom the disclosure was made; (iii) whether the Protected Health Information was actually acquired or viewed; and (iv) the extent to which the risk to the Protected Health Information has been mitigated.

(b) “Breach Notification Standards” shall mean the standards for notification of a breach of unsecured Protected Health Information by covered entities and business associates at 45 CFR Parts 160 and 164, Subparts A and D.

(c) “Covered Entity” shall mean the State of Nevada Public Employees’ Benefits Program (PEBP).

(d) “Data Aggregation” shall mean, with respect to Protected Health Information created or received by the Business Associate in its capacity as the Business Associate of the Covered Entity, the combining of such Protected Health Information by the Business Associate with the Protected Health Information received by the Business Associate in its capacity as business associate of another covered entity, to permit data analyses that relate to the health care operations of the respective entities and is within the meaning of 45 C.F.R. § 164.501.

(e) “Designated Record Set” shall mean a group of records maintained by or for the State of Nevada and/or the Covered Entity within the meaning of 45 C.F.R. § 164.501 that consists of: (i) the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or (ii) records that are used, in whole or in part, by or for the State of Nevada and/or the Covered Entity to make decisions about Individuals.

For purposes of this Section 1.02(f), the term “record” means any item, collection or grouping of information that includes Protected Health Information and is maintained, collected, used or disseminated by or for the Covered Entity.

(f) “Enforcement Rule” means the Enforcement Provisions at 45 CFR Part 160.

(g) “HHS-Approved Technology” shall mean, with respect to data in motion, the encryption guidelines in Federal Information Processing Standard 140-2. For data at rest, HHS-Approved Technology shall mean the encryption guidelines in National Institutes of Standards and Technology (NIST) Special Publication 800-111. With respect to the destruction of data containing Protected Health Information, an HHS-Approved Technology requires the destruction of the media on which the Protected Health Information is stored such that, for paper, film or other hard copy media, destruction requires shredding or otherwise destroying the media so that Protected Health Information cannot be read or reconstructed; for electronic media, destruction requires that the data be cleared, purged or destroyed consistent with NIST Special Publication 800-88 such that the information cannot be retrieved. HHS-Approved Technology may be updated from time to time based on guidance from the Secretary of HHS.

(h) “HIPAA” shall mean the Health Insurance Portability and Accountability Act of 1996, Pub. L. 104-191.

(i) “HITECH” shall mean the Health Information Technology for Economic and Clinical Health Act, Pub. L. 111-5.

(j) “Individual” shall have the same meaning as the term “individual” in 45 C.F.R. § 160.103, and shall include a person who qualifies as a personal representative in accordance with 45 C.F.R. § 164.502(g).

(k) “Privacy Rule” shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 C.F.R. Part 160 and Part 164, Subparts A and E.

(l) “Protected Health Information/ Electronic Protected Health Information (PHI/EPHI)” shall mean individually identifiable health information that is transmitted by electronic media (within the meaning of 45 C.F.R. § 160.103), maintained in electronic media, or maintained or transmitted in any form or medium including, without limitation, all information (including demographic, medical, and financial information), data, documentation, and materials that are created or received by Business Associate from or on behalf of the Covered Entity in connection with the performance of Services, and relates to:

(A)The past, present or future physical or mental health or condition of an Individual;
(B)The provision of health care to an Individual; or
(C)The past, present or future payment for the provision of health care to an Individual;

and that identifies or could reasonably be used to identify an Individual and shall otherwise have the meaning given to such term under the Privacy Rule including, but not limited to, 45 C.F.R. § 160.103. Protected Health Information does not include health information that has been de-identified in accordance with the standards for de-identification provided for in the Privacy Rule including, but not limited to, 45 C.F.R. § 164.514 or Individually Identifiable Health Information: (i) in education records covered by the Family Educational Rights and Privacy Act, as amended, 20 U.S.C. 1232g; (ii) in records described at 20 U.S.C. 1232g(a)(4)(B)(iv); (iii) in employment records held by a Covered Entity in its role as employer; and (iv) regarding a person who has been deceased for more than 50 years.

(m) “Required By Law” shall have the same meaning as the term “required by law” in 45 C.F.R. § 164.103.

(n) “Secretary” shall mean the Secretary of the United States Department of Health and Human Services (“HHS”) or his designee.

(o) “Secured Protected Health Information” shall mean Protected Health Information to the extent that the information is protected by using an HHS-Approved Technology identified by HHS for rendering Protected Health Information unusable, unreadable or indecipherable to unauthorized individuals.

(p) “Security Rule” shall mean the Security Standards at 45 C.F.R. Part 160, Part 162, and Part 164.

(q) “Services” shall mean the functions, activities or services to be provided to the State of Nevada and/or the Covered Entity under the terms of an arrangement between the State of Nevada and/or the Covered Entity and Business Associate.

(r) “Subcontractor” shall mean a person to whom Business Associate delegates a function, activity, or service, other than in the capacity of a member of the workforce of Business Associate.

(s) “Unsecured Protected Health Information” shall mean Protected Health Information that is not rendered unusable, unreadable or indecipherable to unauthorized individuals through the use of an HHS-Approved Technology.

ARTICLE II

Obligations and Activities of Business Associate

2.01Non-Disclosure of Protected Health Information. Business Associate agrees not to use or disclose Protected Health Information other than as permitted or required by this Agreement or as Required By Law.
2.02Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of Protected Health Information other than as provided for by this Agreement or the Privacy Rule. Business Associate agrees to implement administrative, physical, and technical safeguards that satisfy the standards set forth in the Security Rule at 45 C.F.R. §§ 164.308, 164.310, and 164.312, along with corresponding policies and procedures, that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic Protected Health Information that it creates, receives, maintains, accesses, or transmits on behalf of the Covered Entity. Business Associate agrees to adopt and apply such safeguards, policies, and procedures to the electronic Protected Health Information to the same extent that such electronic Protected Health Information would have to be safeguarded if created, received, maintained, accessed, or transmitted by the Covered Entity. Business Associate shall also utilize Secured Protected Health Information in connection with the performance of Services under this Agreement.
2.03Mitigation. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate relating to a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement.
2.04Reporting of Violations. Subject to Section 2.05, Business Associate agrees to report to the State of Nevada and the Covered Entity any use or disclosure of Protected Health Information not provided for by this Agreement within thirty (30) days of such disclosure or Business Associate’s knowledge of such disclosure. Business Associate agrees to report to the State of Nevada and the Covered Entity any security incident (within the meaning of 45 C.F.R. § 164.304) of which Business Associate becomes aware.
2.05Breach of Unsecured Protected Health Information. To the extent that the Business Associate knows or has reason to know (within the meaning of 45 C.F.R. § 164.410(a)(2)) that there has been a Breach or suspected Breach of Unsecured Protected Health Information, the Business Associate is required to identify the Individual whose Unsecured Protected Health Information has been acquired, accessed, used or disclosed and to notify the Covered Entity of such Breach without unreasonable delay, but no later than five (5) days after discovery of the Breach. Upon discovering the Breach, the Business Associate is required to identify and communicate to the Covered Entity (a) the nature and extent of the Protected Health Information involved, including the types of identifiers and the likelihood of re-identification; (b) the unauthorized person who used the Protected Health Information or to whom the disclosure was made; (c) whether the Protected Health Information was actually acquired or viewed; and (d) the extent to which the risk to the Protected Health Information has been mitigated.
2.06Notice of a Breach of Unsecured Protected Health Information. In the event of a Breach involving Unsecured Protected Health Information, the Business Associate, with the prior written approval of the Covered Entity, will notify the affected Individuals without unreasonable delay, but no later than sixty (60) days after discovery of the Breach (“notice date”). The notice will include (a) a brief description of the incident, (b) the date the Breach occurred, (c) the date the Breach was discovered, (d) the type of Protected Health Information involved, (e) steps the Individual should take to protect him/herself from potential harm resulting from the Breach, (f) a brief description of steps the Covered Entity has taken to investigate, mitigate losses and protect against further Breaches, and (g) contact information for Individuals to ask questions, including a toll-free number, e-mail address, website or postal address. To the extent that the Breach involves more than 500 residents of a single state or jurisdiction, the Business Associate shall provide to Covered Entity, no later than fifteen (15) days before the notice date, the information necessary for the Covered Entity to prepare the notice to media outlets as set forth in 45 C.F.R. § 164.406. To the extent that the Breach involves 500 or more Individuals, the Business Associate shall provide to the Covered Entity, no later than fifteen (15) days before the notice date, the information necessary for the Covered Entity to prepare the notice to the Secretary of HHS, as set forth in 45 C.F.R. § 164.408. To the extent that the Breach involves less than 500 Individuals, the Business Associate shall maintain a log of such Breaches and provide such log to the Covered Entity on an annual basis, not later than forty-five (45) days after the end of the calendar year. Upon the written request of the Covered Entity (including faxed and e-mailed requests), Business Associate shall provide such Breach log to the Secretary of HHS, in accordance with the requirements set forth in 45 C.F.R. § 164.408.
2.07Audits. Business Associate shall permit the State of Nevada and the Covered Entity to audit Business Associate’s compliance with the Privacy Rule, Security Rule and this Agreement upon reasonable prior notice and in a reasonable manner. The State of Nevada and/or the Covered Entity shall pay for any such audits.
2.08Agents and Contractors. Business Associate agrees to ensure that any Business Associate agent, including a Subcontractor, to whom it provides Protected Health Information received from, or created or received by Business Associate on behalf of the State of Nevada and/or the Covered Entity agrees to the same restrictions and conditions that apply through this Agreement to Business Associate with respect to such information. Business Associate also agrees to ensure that any Business Associate employee or agent, including any subcontractor to whom it provides Protected Health Information received from, or created or received by Business Associate on behalf of the State of Nevada and/or the Covered Entity agrees to implement reasonable and appropriate safeguards to protect such Protected Health Information. Business Associate, the State of Nevada, and the Covered Entity agree that the Business Associate is not the agent of the Covered Entity or the State of Nevada at any time under this Agreement.
2.09Sanctions. Business Associate agrees to apply appropriate sanctions against any Business Associate employee or agent, including a subcontractor, with access to Individuals’ Protected Health Information who fails to comply with the State of Nevada’s, the Covered Entity’s, or the Business Associate’s health information privacy policies and procedures.
2.10Amendment of Protected Health Information. Business Associate agrees to make appropriate amendments to Protected Health Information in a Designated Record Set that either the Covered Entity or an Individual requests pursuant to procedures established under 45 C.F.R. § 164.526. To the extent Business Associate is requested by an Individual to amend his or her Protected Health Information, Business Associate shall communicate its approval or denial of such request to the Individual pursuant to procedures to be mutually agreed upon in advance by the Parties.
2.11Disclosure of Internal Practices, Books, and Records. Business Associate agrees to make internal practices, books, and records (including policies and procedures) relating to the use and disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of the State of Nevada or the Covered Entity, available to the Covered Entity or, at the request of the Covered Entity, to the Secretary, in a time and manner mutually agreed to by the Parties or designated by the Secretary, for purposes of the Secretary determining the Covered Entity’s compliance with the Privacy Rule.
2.12Access to Protected Health Information. To the extent that either the Covered Entity or an Individual requests to inspect or obtain a copy of Protected Health Information (as provided for in 45 C.F.R. § 164.524) that may be in the possession or control of the Business Associate or its agents or subcontractors, or that exists in a Designated Record Set, Business Associate shall respond within thirty (30) days of its receipt of the request by Business Associate, provided that compliance with the request would not result in a violation of HIPAA or the Privacy Rule.
2.13Documentation of Disclosures. Business Associate agrees to document disclosures of Protected Health Information and information related to such disclosures as would be required for a Covered Entity to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 C.F.R. § 164.528. At a minimum, such documentation shall include: (i) the date of each disclosure; (ii) the name of the entity or person who received Protected Health Information and, if known, the address of the entity or person; (iii) a brief description of the Protected Health Information disclosed; (iv) the disclosures of Protected Health Information that occurred during the six-year period prior to the date of the request for an accounting (or any shorter period of time requested by the Individual) and that are otherwise subject to the accounting requirement in 45 C.F.R. § 164.528; (v) a brief statement of the purpose of the disclosure that reasonably informs the Individual of the basis for the disclosure or, if applicable, in lieu of such a statement, a copy of the Individual’s authorization and a copy of the written request for disclosure; and (vi) the form and format (electronic or paper) of such disclosure.
2.14Accounting for Disclosures. Business Associate agrees to provide to the Covered Entity or an Individual, in a time and manner mutually determined by the Parties, information collected in accordance with Section 2.13 of this Agreement so as to permit the Covered Entity to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 C.F.R. § 164.528, provided, however, that to the extent that the Business Associate uses or maintains an electronic health record (within the meaning of 42 U.S.C. § 17921) with respect to Protected Health Information, Business Associate shall provide such accounting to the Individual (or, upon the request of the Covered Entity, to the Covered Entity for delivery to the Individual) of the disclosures required for the three-year period immediately preceding the date on which the accounting is requested. The accounting of disclosures through electronic health records shall not be required earlier than the earliest applicable date established by the Secretary of HHS.
2.15Facilitate the Exercise of Privacy Rights. Business Associate agrees to establish procedures that allow Individuals to exercise their rights under the Privacy Rule, including the right to (i) inspect and obtain copies of records and documents within the possession or control of the Business Associate that contain the Individual’s Protected Health Information; (ii) request amendments to their Protected Health Information; (iii) receive an accounting of disclosures of their Protected Health Information by Business Associate; (iv) request restrictions on the use or disclosure of Protected Health Information; and (v) receive communications regarding Protected Health Information at alternative locations or by alternative means.
2.16No Waiver of Rights. Business Associate agrees to not require Individuals to waive their health information privacy rights as a condition for treatment, payment or enrollment in the Covered Entity, or eligibility for its benefits.
2.17Responses to Subpoenas. In the event that Business Associate receives a subpoena, discovery request or other lawful process, with or without an order from a court or administrative tribunal, arising out of or in connection with the Covered Entity or this Agreement including, but not limited to, any use or disclosure of Protected Health Information or any failure in Business Associate’s health data security measures, Business Associate shall fully comply with the notice and protective action obligations set forth in 45 C.F.R. § 164.512(e) in accordance with Business Associate’s standard policy and procedures regarding subpoenas, discovery requests, and other lawful processes which shall be communicated to the Covered Entity upon request.
2.18Electronic Transactions. To the extent required under HIPAA (including the Standards for Electronic Transactions at 45 C.F.R. Parts 160 and 162), Business Associate agrees to use or conduct, in whole or part, standard transactions and utilize code sets or identifiers under the Privacy Rule for or on behalf of the State of Nevada or the Covered Entity as detailed under the Privacy Rule or HIPAA (including the Standards for Electronic Transactions at 45 C.F.R. Parts 160 and 162). Business Associate shall also require any Subcontractor or agent to also comply with such electronic transaction requirements under HIPAA (including the Standards for Electronic Transactions at 45 C.F.R. Parts 160 and 162).
2.19Security Standards. Business Associate acknowledges that it may need to issue and change procedures from time to time to improve electronic data and file security, and agrees that such measures shall be at least as stringent as may be required by the Privacy Rule or the Security Rule, as applicable. Notwithstanding the foregoing, Business Associate agrees and acknowledges that it shall at all times use an HHS-Approved Technology for all Protected Health Information that is in motion, stored or to be destroyed, and to use appropriate safeguards including, but not limited to, complying with 45 C.F.R. Part 164 Subpart C with respect to electronic Protected Health Information so as to prevent access, use or disclosure of Protected Health Information other than as provided for by this Agreement.
2.20Disclosures to Designated Plan Sponsor Representatives. The State of Nevada shall identify for Business Associate, in writing, certain State of Nevada employees who are authorized to discuss Protected Health Information with Business Associate in connection with an Individual’s claim for benefits from the Covered Entity. To the extent that Business Associate is contacted by any such designated the State of Nevada representative in connection with an Individual’s claim for benefits from the Covered Entity, Business Associate shall treat such inquiry as relating to “treatment, payment or healthcare operations” within the meaning of the Privacy Rule and shall provide the information permitted under such Privacy Rule.
2.21Notice of Privacy Practices. Covered Entity shall prepare and distribute a notice of privacy practices as required by the Privacy Rule. If Business Associate maintains a web site on behalf of the State of Nevada or the Covered Entity that provides information about the Covered Entity’s participant services or benefits, Business Associate shall make the notice of privacy practices available electronically through the web site. Notwithstanding the foregoing, following the Covered Entity’s revision to the Notice of Privacy Practices, the Business Associate shall post the change or the revised Notice on its web site by the effective date of any material change to the Notice. At the request of the Covered Entity, the Business Associate shall provide the revised Notice or information about the material change and how to obtain the revised Notice, in its next applicable mailing to Individuals then covered by the Covered Entity.

ARTICLE IIIPermitted Uses and Disclosures By Business Associate

3.01General Uses and Disclosures. Except as otherwise limited by this Agreement, Business Associate agrees to create, receive, maintain, access, use, or disclose Protected Health Information only in a manner that is consistent with this Agreement, the Privacy Rule and the Security Rule, and only in connection with providing Services to the State of Nevada and/or the Covered Entity, provided that such creation, receipt, maintenance, access, use, or disclosure would not violate the Privacy Rule or Security Rule if done by the Covered Entity, or the minimum necessary policies and procedures of the Covered Entity. Covered Entity shall limit its disclosures of Protected Health Information to Business Associate to the minimum necessary to accomplish the Services, and Business Associate shall limit its access, use and disclosures of Protected Health Information to any Subcontractor or other third party to the minimum necessary to accomplish the Services.
3.02Use and Disclosure for Treatment, Payment and Health Care Operations. In providing Services, Business Associate shall be permitted to use and disclose Protected Health Information for purposes of “treatment, payment and health care operations” in accordance with the Privacy Rule, including, but not limited to, using or disclosing Protected Health Information (i) to investigate, pay, audit and otherwise administer and facilitate the payment of health plan claims; (ii) to enroll or disenroll participants and beneficiaries in and/or confirm or deny participant and beneficiary eligibility for participation in the Covered Entity; and (iii) to coordinate the payment of benefits from the Covered Entity when a participant or beneficiary is enrolled in another health plan which provides similar benefits, provided, however, that any communication by Business Associate that is about a product or service and that encourages recipients of the communication to purchase or use the product or service shall not be considered a health care operation for purposes of 45 C.F.R. Part 164, subpart E, unless the communication is made in accordance with 45 C.F.R. § 164.501 and is approved in writing by Covered Entity.
3.03Use and Disclosure for Public Health, Health Oversight and Law Enforcement Purposes. In providing Services, Business Associate shall be permitted to use and disclose Protected Health Information, in accordance with the Privacy Rule, (i) to provide needed information to government agencies engaged in public health, health oversight, law enforcement, and otherwise as Required by Law; and (ii) to report violations of law to appropriate Federal and State authorities, consistent with 45 C.F.R. § 164.502(j)(1).
3.04Use for Management and Administration of Business Associate. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information for the proper management and administration of the Business Associate (defined as those uses arising in the ordinary course of its business and as is customary in its industry) or to carry out the legal responsibilities of the Business Associate. Any such use shall be in accordance with the uses and disclosures permitted by the Privacy Rule.
3.05Disclosure for Management and Administration of Business Associate. Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of the Business Associate provided that the disclosures are Required by Law, or Business Associate (i) obtains the prior written approval of the Covered Entity for such use or disclosure, and (ii) obtains reasonable assurances from the person to whom the information is to be disclosed that (A) the information shall remain confidential, (B) the information shall be accessed, used, or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and (C) the person shall notify the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
3.06Use for Data Aggregation Services. Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information to provide Data Aggregation services relating to the health care operations of the Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
3.07Prohibition on Marketing or Sale of Electronic Health Records or Protected Health Information. Except as provided in this Agreement or otherwise excepted under HIPAA, Business Associate shall not directly or indirectly receive remuneration from or on behalf of the recipient of the Protected Health Information in exchange for the marketing (within the meaning of 45 C.F.R. § 164.501) or sale (within the meaning of 45 C.F.R. § 164.501) of any Protected Health Information of an Individual unless the Covered Entity has received a valid authorization (within the meaning of 45 C.F.R. § 164.508(a)(4)) from the Individual that includes a statement that the disclosure will result in remuneration to the Covered Entity or Business Associate.

ARTICLE IV

Obligations of the Covered Entity

4.01Obligations to Notify Business Associate.
(a)Limitations in Notice of Privacy Practices. Covered Entity shall notify Business Associate of any limitations in the Covered Entity’s notice of privacy practices provided in accordance with the requirements of 45 C.F.R. § 164.520, to the extent such limitations may affect Business Associate’s use or disclosure of Protected Health Information.
(b)Changes in Permission by Individual for Use of Disclosure. Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, if and to the extent that such changes affect Business Associate’s use or disclosure of Protected Health Information.
(c)Agreements to Restrict Use or Disclosure. Covered Entity shall notify Business Associate of any restrictions on the use or disclosure of Protected Health Information or a request for confidential communication that the Covered Entity has agreed to pursuant to and in accordance with the requirements of 45 C.F.R. § 164.522, or shall direct Individuals to make any such request directly to Business Associate if and to the extent that such restriction or request may affect Business Associate’s use or disclosure of Protected Health Information.
4.02Permissible Requests by Covered Entity. Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy Rule or Security Rule if done by the Covered Entity, except that the Covered Entity may request that Business Associate perform Data Aggregation services pursuant to the provisions of Section 3.06 of this Agreement.

ARTICLE V

Term and Termination

5.01Protected Health Information Following Termination of Agreement. This Agreement shall terminate when all of the Protected Health Information received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity that the Business Associate still maintains in any form is destroyed or returned to the Covered Entity or, if it is infeasible to return or destroy Protected Health Information, protections shall be extended to such information, in accordance with the termination provisions in this Article V.
5.02Termination for Cause. Upon the Covered Entity’s knowledge of a material breach of this Agreement by Business Associate, the Covered Entity shall either (i) provide an opportunity for Business Associate to cure the breach or end the violation, and terminate this Agreement if Business Associate does not cure the breach or end the violation within the time agreed to by the Parties; or (ii) immediately terminate this Agreement if a cure is not possible.
5.03Effect of Termination.
(a)Return or Destruction of Protected Health Information. Except as provided in Section 5.03(b) of this Agreement, upon termination of this Agreement for any reason, Business Associate shall return or destroy (in accordance with the HHS-Approved Technology) all Protected Health Information received from the Covered Entity, or created, received, or maintained by Business Associate on behalf of the Covered Entity. This provision shall apply also to Protected Health Information that is in the possession of Subcontractors or agents of Business Associate. Business Associate shall retain no copies of the Protected Health Information.

(b) Extension of Protections for Retained Protected Health Information. In the event that Business Associate determines that returning or destroying the Protected Health Information is infeasible, Business Associate shall provide to the Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Parties that return or destruction of Protected Health Information is infeasible, Business Associate shall extend the protections of this Agreement to such Protected Health Information and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such Protected Health Information, and for as long as the Business Associates can access Protected Health Information. The obligations of the Business Associate under this Agreement shall survive termination of this Agreement with respect to that Protected Health Information that Business Associate is unable to return or destroy, or Protected Health Information that the Business Associate may continue to access.

ARTICLE VI

Miscellaneous

6.01Regulatory References. A reference in this Agreement to a section in the Privacy Rule, Security Rule, Breach Notification Standards, or Enforcement Rule means the section in the respective regulations, as amended and in effect at the relevant time.
6.02Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time in order for the Covered Entity to comply with the requirements of the Privacy Rule, the Security Rule, and HIPAA. All references to “C.F.R.” are to the Code of Federal Regulations as amended and in effect at the relevant time.
6.03Survival. The respective rights and obligations of Business Associate under Article VI of this Agreement shall survive the termination of this Agreement.
6.04Interpretation.
(a)Ambiguity. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits the Covered Entity to comply with the Privacy Rule or the Security Rule, as applicable.
(b)Inconsistency. In the event of an inconsistency between the provisions of this Agreement and the Privacy Rule or the Security Rule, as may be amended from time to time, as a result of interpretations by HHS, a court or another regulatory agency with authority over the Parties, the interpretation of HHS, such other court or regulatory agency shall prevail.
(c)Non-Mandatory Provisions. In the event provisions of this Agreement are not the same as those mandated by the Privacy Rule or the Security Rule, but are nonetheless permitted by the Privacy Rule or the Security Rule, the provisions of this Agreement shall control.
6.05Complete Integration. This Agreement constitutes the entire agreement between the Parties with respect to HIPAA, the Privacy Rule, and the Security Rule, and supersedes all prior negotiations, discussions, representations or proposals, whether oral or written, unless expressly incorporated herein, related to the subject matter of the Agreement. Unless expressly provided otherwise herein, this Agreement may not be modified unless in writing signed by the duly authorized representatives of the Parties.
6.06Severability. If any provision or part of this Agreement is found to be invalid, the remaining provisions of this Agreement shall remain in full force and effect.
6.07No Third-Party Beneficiaries. Except as expressly provided for in the Privacy Rule, the Security Rule, and the Agreement, there are no third-party beneficiaries to this Agreement. Business Associate’s obligations, unless expressly noted herein, are only to the State of Nevada and the Covered Entity.
6.08Successors and Assigns. This Agreement shall inure to the benefit of and be binding upon the successors and assigns of the State of Nevada, the Covered Entity, and Business Associate. However, this Agreement is not assignable by any Party without the prior written consent of the other Parties, which shall not be unreasonably withheld, except that (i) Business Associate, the Covered Entity, and the State of Nevada may assign or transfer this Agreement to any entity owned or under common control with Business Associate, the Covered Entity or the State of Nevada, respectively; and (ii) this Agreement shall automatically be assigned to any entity to which the agreement for provision of Services is properly assigned.
6.09Confidentiality. Except as otherwise provided for in the Privacy Rule, the Security Rule, or this Agreement, no Party shall disclose the terms of this Agreement to any third party without the remaining Parties’ written consent.
6.10Counterparts. This Agreement may be executed in two or more counterparts, each of which may be deemed an original.
6.11Applicable Laws. Business Associate represents and warrants that it shall comply with all applicable laws and regulatory requirements in the performance of this Agreement. The Parties agree to enter into good faith discussions aimed at amending this Agreement from time to time to comply with the requirements of HIPAA, the Privacy Rule, the Standards for Electronic Transactions at 45 C.F.R. Parts 160 and 162, the Security Rule, and related regulations and technical pronouncements, provided, however, that Business Associate shall also be responsible for complying with any state privacy or data security rules that are not contrary (within the meaning of 45 C.F.R. § 160.202) to HIPAA, the Privacy Rule, the Security Rule and related regulations and technical pronouncements and, to the extent applicable, that are more stringent (within the meaning of 45 C.F.R. §§ 160.202 and 160.203(b)) than a standard, requirement or implementation specification adopted under 45 C.F.R. Part 164.

6.12 Governing Law. This Agreement shall be governed by and construed in accordance with the same internal laws governing the Services provided to the State of Nevada or the Covered Entity by Business Associate.

6.13Applicability to Separate Covered Entities. If, and to the extent that this Agreement applies to two or more separate “covered entities” (as defined in the Privacy Rule), the provisions of this Agreement regarding the permitted and required uses and disclosures (and limitations and conditions on such uses and disclosures) of Protected Health Information shall apply separately and independently to each such “covered entity”, except to the extent otherwise agreed to by the Parties.
6.14Indemnification. The State of Nevada, Covered Entity and Business Associate agree to indemnify and hold each other harmless from any and all liability, damages, costs (including reasonable attorneys’ fees and costs), fines, penalties and expenses imposed upon or asserted against the non-indemnifying party arising out of the indemnifying party’s use or disclosure of Protected Health Information contrary to the provisions of HIPAA, the Privacy Rule, the Security Rule, HITECH, this Agreement or other applicable law.

IN WITNESS WHEREOF, the Parties have caused this Agreement to be executed by their duly authorized representatives.

THE PARTIES ACKNOWLEDGE THAT THEY HAVE READ THIS AGREEMENT, UNDERSTAND IT, AND AGREE TO BE BOUND BY ITS TERMS.

[VENDOR NAME]

State of Nevada on behalf of the Public Employees Benefits Program (PEBP)

By:_______________________________ Signature By:________________________________ Signature

Print Name:________________________

Print Name: Laura Rich _

Title:_____________________________
Title: PEBP Executive Officer _

Date:_____________________________

Date:______________________________ image1.png

File details come from the government source that posted it. Updated .