24-8280S_Business_Assocate_Agreement.pdf

PDF 4 MB Posted

Attached to
Services for Seniors - Supplemental - Grant Funded State and local contract opportunity
Solicitation number
24-8280S
Issued by
Collier County, Florida

About this file

This document is a Business Associate Agreement between Collier County ("Covered Entity") and an unnamed Business Associate, designed to comply with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. The agreement establishes the terms and conditions for the Business Associate's handling of Protected Health Information (PHI), including requirements for appropriate safeguards, permitted uses and disclosures, reporting of security incidents, and breach notification procedures. The document outlines the Business Associate's obligations to protect the confidentiality, integrity, and availability of electronic PHI created, received, maintained, or transmitted on behalf of the Covered Entity.

The agreement includes comprehensive provisions for data security, privacy compliance, and mitigation of potential risks, with specific requirements for encryption, minimum necessary use of PHI, and limitations on marketing and remuneration. The Business Associate is required to implement administrative, physical, and technical safeguards to prevent unauthorized use or disclosure of PHI, and must notify the Covered Entity of any security incidents or breaches. The document also addresses termination conditions, amendment processes, and indemnification, with the Business Associate holding liability for any non-permitted disclosures or breaches of the agreement. The governing law is specified as the laws of the State of Florida, and the agreement is designed to be interpreted broadly to ensure compliance with evolving state and federal data privacy regulations.

View the file

Other files for this state and local contract opportunity

Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BUSINI,SS ASSOCIATE AGREEMENT

This Business Associate COUNTY("Covered Entity") and

Agreement ("Agreement'') is entered into bettveen COLLIER ("Business Associatc"), effective as of this _ day of _, 20 I 6(the "Effective Date")

WHEREAS, Covered Entity and Business Associate have enlered into, or plan to enter into, an arrangement pursuant to which Business Associate may provide services for Covered Entity that require Business Associate to access. create and use Protected Health Information C'PHI') that is confidential under state and/or federal law; and

WHEREAS, Covered Entify" and Business Associate intend to protect the privacy and provide for the security of PHI disclosed by Covered Entity to Business Associate, or collected or created by Business Associate. in compliance with the Health Insurance Portabilhy and Accountability Act of 1996, Public Law 104-191 ("HlPAA"), and the regulations promulgated ther.e under, including. without linritation, the regulations codified at 45 CFR Parts 160 and 164 ("HIPAA Regulations")l rhe Health Infonnation Technology for Economic and Clinical Health Act, as incorporated in the American Recovery and Reinvestment Act of 2009. and its implementing regulations and guidance issued by thc Secretary of the Department of Health and Human Services (the "Secretary") (the "HITECH Act"): and other applicable state and federal laws, all as amended liom time to time, including as amended by the Final Rule issued by the Secretary on January 17.2013 titled "Modifications to the HIPAA l,rivacy, Security, Enforcement, and Breach Notification Rules under the Health lnformation Technology for Econorric and Clinical Health Act and the Cenetic Information Nondiscrimination Act: Other Modifications to the HIPAA Rules": and

WHEREAS, the HIPAA Regulations require Covered Entity Io enter into an agreement with Business Associate meeting certain requirements with respect to the Use and Disclosure of PHl. which are met by this Agreement.

l. Definitions

Capitalized terms used herein without definition shall have the meanings ascribed to them in the HIPAA Regulations or the HITECH Act, as applicable unless otherwise defined herein.

2. Oblisations and Activities of Business Associate

Further, Business Associate shall not Use or Disclose PHI in any manner that would constitute a violation of the HIPAA Regulations or the HITECH Act if so used by Covered Entity, except that Business Associate may Use PHI (i) for tlre proper management and administration of Business Associate; and (ii) to carry out the legal responsibilities of Business Associate. Business Associate may Disclose PHI for the proper management and administration of Business Associate, to carry out its legal respons ibilities or for

Page I of 9

CAO

NOW, THEREFORE, in consideration of the mutual prornises contained herein and the exchange of information pursuant to this Agreement, the parlies agree as follows:

a. Permi$ed Uses and Disclosures. Business Associate shall only Use or Disclose PHI for the purposes of (i) performing Business Associate's obligations under Exhibit A of this Agreernent ("Exhibit A") and as permitted by this Agreernent; or (ii) as permitted or Required By Lawl or

(iii) as otherwise permined by this Agreement. Business Associate shall not Use or further Disclose PHI other than as permitted or required by this Agreement or as Required By Law.

payment purposes as specified in 45 CFR $ 164.506(c)(1) and (3), including but not limited to Disclosure to a business associate on behalf of a covered entity or health care provider for payment purposes of such covered entity or health care provider, with the expectation that such parties will provide reciprocal assistance to Covered Entity, provided that with respect to any such Disclosure either: (i) the Disclosure is Required By Law; or (ii) for permitted Disclosures when Required By Law. Business Associate shall obtain a written agreement from the person to whom the PHI is to be Disclosed that such person will hold the PHI in confidence and will not use and fufther disclose such PHI except as Required By Law and for the purpose(s) for which it was Disclosed by Business Associate to such person, and that such person will notify Business Associate ofany instances of which it is aware in which the confidentiality ofthe PHI has been breached.

b. Aooronriate Sat'eguards. Business Associate shall inr plement administrative.

physical and technical safeguards that (i) reasonably and appropriately protect the confidentiality, integrity and availability of electronic Plll that it creates, receives, maintains or transmits on behalfof Covered Entity; and (ii) prevent the Use or Disclosure of PHI other than as contemplated by Exhibit A and this Agreement.

c. Compliance with Securit_v Provisions. Business Associate shall: 1i) irnplement and maintain adrninistrative safeguards as required by 45 CFR S 164.308, physical safeguards as required by 45 CFR $ 164.3 l0 and technical safeguards as required by 45 CFR g 164.3 12; (ii) implement and document reasonable and appropriate policies and procedures as required by 45 CFR $ 164.3 l6; and (iii) be in compliance with all requirements of the tlITECH Act related to security and applicable as if Business Associate were a "covered enliN." as such term is defined in HIPAA.

d. Compliance with Privacy Provisions. Business Associate shall only Use and Disclose PHI in compliance rvith each applicable requirement of 45 CFR $ I6a.50a(e). Business Associate shall comply with all requirements of the HITECFI Act related to privacy and applicable as if Business Associate were a "covered entity." as such term is defined in HIPAA. To the extent Business Associate is to carry out one or more of Covered tntity's obligation(s) under Subpart E of 45 CFR Part 164, Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s).

f. Encrvption. To facilitate Business Associate's compliance u,ith this Agreement and to assure adequate data seculity, Covered Entity agrees that all PHI provided or transmittcd to Business Associate pursuant to Exhibit A shall he provided or transmitted in a manner which renders such PHI unusable, unreadable or indecipherable to unauthorized persons, through the use ofa technology or methodology specified by the Secretary in the guidance issued under section 13402(h)(2) of the HTTECH Act. Covered Entity acknowledges that failure to do so could contribute to or permit a Breach requiring patient notification under the HITECH Act and further agrees lhat Business Associate shall have no liability for any Breach caused by such failure.

a c

IlgpoftinsJ.

tl /. or OSLI , Business Associate shall report to Covered Entity a successful Securiry" lncident or any Use and/or Disclosure of PHI other than as

CAO

e. DUN to Mitiaate. Business Associate agrees to mitigate, to the extent practicable and mandated by law, any harmful effect that is known to Business Associate of a Use or Disclosure of PHI by Business Associate in violation ofthe requirements of this Agreernent.

provided for by this Agreement or permitted by applicable law within a reasonable time of becoming aware of such Security Incident and/or unauthorized Use or Disclosure (but not later than five (5) days thereafter), in accordance with the notice provisions set forth herein. Business Associate shall take (i) prompt action to cure any such deficiencies as reasonably requested by Covered Entity, and (ii) any action pertaining to such Security Incident and/or unauthorized Use or Disclosure required by applicable federal and state laws and regulations. If such successful Security lncident or unauthorized Use or Disclosure results in a Breach as defined in the HITECH Acr, then Covered Entity shall comply with the requirements of Section 3.b below.

b, Breach ofUnsecured Plll. The plovisions of this Section 3.b are effective with respect to the Discovery ofa Breach ofUnsecured PHI occurling on or after September 23, 2009. With respect to any unauthorized acquisition, access, Use or Disclosure ofCovcred Entity's PHI by Business Associate, its agents or subcontractors, Business Associale shall (i) investigate such unauthorized acquisition. access, Use or Disclosure; (ii) detennine whether such unauthorized acquisition, access, Use or Disclosure constitutes a reportable Breach under the HITECH Act: and (iii) document and retain its findings under clauses (i) and (ii). If Business Associate Discovers that a reportable Breach has occurred. Business Associate shall notifo Covered Entity ofsuch reportable Breach in writing within five (5) days ofthe date Business Associate Discovers such Breach. Business Associate shall be deemed to have discovered a

Breach as of the first day that the Breach is either known to Business Associate or any of its employees.

officers or agents, other than the person who committed the Breach, or by exercising reasonable diligence should have been known to Business Associate or any of its employees. officers or agents, other than the person who committed the Breach. To the extent the informalion is available to Business Associate, Business Associate's written notice shall include the inlormation required by 45 CFR $ 164.410(c).

Business Associate shall promptly supplement the written report with additional information regarding the Breach as it obtains such infonnation. Business Associate shall cooperate with Covered Entity in meeting Covered Entity's obligations under the HITECH Act with respect to such Breach.

Business Associate's Agents. To the extent that Business Associate uses one or more subcontractors or agents to provide services under Exhibit A, and such subcontractors or agents receive or have access to PHI, Business Associale shall sign an agreement with such subcontractors or agents containing substantially the same provisions as this Agreement.

5. Rights of Individuals.

a. Access to PHI. Within ten (10) days of receipt of a request by Covered Entity.

Business Associate shall make PHI rnaintained in a Designated Record Set available to Covered Entity or.

as directed by Covered Entity, to an lndividual to enable Covered Entity to fulfill its obligations under 45 CFR $ 164.i2./. Subject to Section 5.b below, (i) in the event that any Individual requests access to PHI directly from Business Associate in connection with a routine billing inquiry, Business Associate shall directly respond to such request in compliance with 45 CFR S 164.5241 and (ii) in the event such request appears to be for a purpose other than a routine billing inquiry, Business Associate shall forward a copy ofsuch request to Covered Entity and shall fLrlly cooperate with Covered Entity in responding to such request. In either case, a denial of'access to requested PHI shall not be made without the prior uritten consent of Covered Entity.

b. Access to Electronic Health Records. If Business Associate is deemed to use or maintain an Electronic Health Record on behalfofCovered Entity with respect to PHl, then, to the extent an Individual has the right to request a copy of the PHI maintained in such Electronic Health Record pursuant to 45 CFR $ 164.524 and makes such a request to Business Associate, Business Associate shall provide such individual with a copy of the infonnation contained in such Electronic Health Record in an

4.

CAO

electronic format and, if the lndividual so chooses, transmit such copy directly to an entity or person designated by the lndividual. Business Associate may charge a fee to the individual for providing a copy of such information, but such fee may not exceed Business Associate's labor costs in responding to the request for the copy. The provisions of 45 CFR S I 64.524, including the exceptions to the requirement to provide a copy of PHI, shall otherwise apply and Business Associate shall comply therewith as if Business Associate were the "covered entity," as such term is defined in HIPAA. At Covered Entity's request. Business Associate shall provide Covered Entity u,ith a copy of an Individual's PIll maintained in an E,lectronic Health Record in an electronic format and in a time and manner designated by Covered Entity in order for Covered Entity to comply with 45 CFR $ 164.524, as amended by the HITECH Act.

c. Amendment of PHL Business Associate agrees to rnake any amendrnent(s) to PHI in a Designated Record Sel that Covered Entiry directs or agrees to pursuant to 45 CFR $ 164.526 at the request of Covered Entity or an Individual, and in the time and manner designated by Covered Entity.

d. Accountine Riehts. This Section 5.d is subiect to Section 5.e belorv. Business Associate shall make available to Covered E,ntity, in response lo a request from an Individual, infomration required for an accounting ol disclosures of PHI with respect to the Individual, in accordance with 45 CFR $ 164.528. incorporating exceptions to such accounting designated under such regulation. Such accounting is limited to disclosures that were made in the six (6) years prior to the request and shall not include any disclosures that were made prior to the compliance date of the HIPAA Regulations. Business Associate shall provide such infonnation as is necessary to provide an accounting within ten ( l0) days of Covered Entity's request. Such accounting must he provided without cost to the Individual or to Covered Entity if it is the first accounting requested by an Individual within any six (6) month period; however. a reasonable, cost-based fee may be charged for subsequent accountings during that period if Business Associate informs Covered Entity and Covered Entity informs the lndividual in advance of the fee. the Individual is afforded an oppoftunity to rvithdrall'or modify the request and charging such fee is not otherwise contrary to law. Such accounting obligations shall survive termination of this Agreement and shall continue as long as Business Associate maintains PHl.

e. AccountinB of Disclosures of Electronic Health Records. The provisions of this Section 5.e shall be effective on the date specified in the HITECH Act. If Business Associate is deemed to use or maintain an Electronic Health Record on behalf of Covered Entity, then, in addition to cornplying with the requirements set forth in Section 5.d above, Business Associate shall maintain an accounting of any Disclosures made through such Electronic Health Record for Treatment, Payment and Health Care Operations, as applicable. Such accounting shall comply with the requirements ofthe HITECH Act. Upon request by Covered Entity, Business Associate shall provide such accounting to Covered Entity in the time and manner specified by Covered Entity and in compliance with the HITECU Act. Altematively, if Covered Entity responds to an Individual's request for an accounting of Disclosures made through an Electronic Health Record by providing the requesting Individual with a list of all business associates acting on behalf of Covered Entity, then Business Associate shall provide such accounting directly to the requesting Individual in the time arrd manner specified by the HITECH. Act.

f. Agreement to Restrict Disclosure. If Covered Entity is required to comply rvith a restriction on the Disclosure of PHI pursuant to Section 13405 of the HITECH Act, then Covered Entity shall, to the extent necessary to conrply with such restriction, provide written notice to Business Associate of the name ofthe Individual requesting the restriction and the PHI affected thereby. Business Associate shall. upon receipt of suoh notification, not Disclose the identified PHI to any health plan for the purposes of carrying out Payment or Health Care Operations. except as otherwise required by law. Covered Entity shall also notify Business Associate of any other restriction to the Use or Disclosure of PHI that Covered Entitl" has agreed to in accordance with 45 CFR I 164.522,

it. Rerruneration tbr PHl. '[his Section 6.a shall bc eff'ectir c with rcspect to exchanges of PHI occurring six (6) rnonths after the date of the promulgation of final regulations implernenting the provisions of Section 13405(d) of the HITECII Act. C)n and after such date, Business Associate agrees that it shall not, directly or indirectly, receive remuneration in exchange for any PHI of Coveted Entity except as otherwise perrnitted by the HITECH Act.

b. Lirnitations on Use of PH I lor Marketing Purposes. Business Associate shall not Use or Disclose PHI for the purpose of making a communication about a product or service that encourages recipients of the communication to purchase or use the product or scrvice, unless such communication: (l) complies with the requirernents of subparagraph (i), (ii) or ( iii) of paragraph ( I ) of the definition of marketing contained in 45 CFR $ 164.501, and (2) complies with the requiremenrs of subparagraphs (A), (B) or (C) ofSection 13406(a)(2) ofthe HITECH Act, and implementing regulations or guidance that may be issued or anrended from time to time. Covered Entity agrees to assist Business Associate in determining if the foregoing requirements are mel with respect to any such marketing communication.

7 rnmental s. BLrsiness Associate shall nrake its intclnal practices, books and records relating to the Use and Disclosure of PHI available to the Secretary for purposes of determining Covered Entity's compliance with the HIPAA Regulations and the HITECH Act. Except to the extent prohibited by law, Business Associate agrees to notify Covered Entity of all requests serued upon Business Associate for information or documentation by or on behalfofthe Secretary. Business Associate shall provide to Covered Entity a copy of any ['Hl that Business Associate provides to the Secretary concurrently with providing such PHI to the Secretary.

8. Minimum Necessarv. To the extent required by the HITECH Act, Business Associate shall linrit its Use, Disclosure or request of PHI to the Limited Data Set or', if needed. to the minimum necessary to accomplish the intended Use, Disclosure or request, respectively. Effective on the date the Secretary issues guidance on rvhat constitules "minimum necessary" for purposes of the HIPAA Regulations, Business Associate shall limit its Use. Disclosure or request of PHI to only the minimum necessary as set fonh in such guidance.

9. State Privacr Laws. Business Associate shall cornply rvith state laws to extent that such state privacy laws are not preempted by HIPAA or the HITECII Act il Breach by Business Associate. IfCovered Ent ity knows of a pattern of activity or practice of Business Associate that constitutes a material breach or violation of Business Associate's obligations under this Agreement, then Covered Entity shall promptly notiry Business Associate. With respect to such breach or violation. Business Associate shall take reasonable steps to cure suclr breach or end such violation, if possible. If such steps are either not possible or are unsuccessful. upon written notice to Business Associate, Covered Entity may terminate its relationship with Business Associate,

b. Breach by Covered Entity. If Business Associate knorvs of a pattern of activity or practice of Covered Entity that conslitutes a material breach or violation of Covered Entity's obligations under this Agreement, then Business Associate shall promptly notif,i Covered Entity. With respect to such breach or violation, Covered Entity shall take reasonable steps to cure such breach or end such

CAO

6. Rem uneration and Marketing.

10. Termination.

violation, if possible. lf such steps are eilher not possible or are unsuccessful, upon written notice to Covered Entity, Business Entity may terminate its relationship with Covered Entiry-.

Automatic Termination. This Agleemenl rvill automatically, tenninate. withoutc.

any further action by the parties hereto, at such time as there are no longer any Service Agreements by and between the panies hereto.

d. Effect of 'fermination. U pon tenrination of this Agreement for any reason.

Business Associate shall either return or destroy all PHl, as requested by Covered Entiry". that Business Associate or its agents or subcontractors still rnaintain in any fbnn, and shall retain no copies ofsuch PHl.

lf Covered Entity requests that Business Associate return PHI. such PHI shall be returned in a mutually agreed upon format and timefrarne. I1' Business Associate reasonably detemines that return or destruction is not feasible, Business Associate shall continue to extend the protections of this Agreement to such PHl, and limit fu(her uses and disclosures of such PHI to those purposes that make the return or destruction of such PHI not leasible. ll Business Associate is asked to destroy the PHl. Business Associate shall destroy PHI in a nranner that renders the PHI unusable. unreadable or indecipherable to unauthorized persons as specified in the HITECII Act.

I l. Amendment, The parties acknowledge that state and federal laws relating to data security and privacy are rapidly evolving and that amendment of this Agreement may be required to ensure compliance with such developments. The parties specifically agree to take such action as is necessary to implement any new or modified standards or requirements of HIPAA, the HIPAA Regulations, the HITECH Act and other applicable laws relating to the security or confidentiality ofPHI. Upon the request of Covered Entity, Business Associate agrees to promptly enter into negotiation concerning the terms of an amendment to this Agreement incorporating any such changes.

13. Effect on Underlying Arraneement. In the event ofany conflict between this Agreement and any underlying arrangement between Covered Entity and Business Associate, the terms ofthis Agreemenl shall control.

14. Survival. The provisions ofthis Agreement shall survive the termination or expiration ofany underlying atrangement between Covered Entity and Business Associate.

I5. Interpretation. This Agreement shall he interpreted as broadly as necessary to implement and comply with HIPAA, the HIPAA Regulations and the HITECH Act. The pafiies agree that any arnbiguity in this Agreement shall be resolved in favor ofa meaning tlrat complies and is consistent with such laws.

16. Goveming Law. This Agreernent shall be construed in accordance with the laws of the State of Florida.

17. Notices. All notices required or permitted under this Agreement shall be in writing and sent to the other party as directed below or as otherwise directed by either party, from time to time. by written notice to the other. All such notices shall be deemed validly given upon receipt ofsuch notice by certified mail. postage prepaid, facsirnile transmission. e-rnail or personal or courier delivery:

Page 6 ol9 cAo

12. No Third Partv- Beneficiaries. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer. upon any person other than Covered Entity, Business Associate and lheir respective successors or assigns. any rights. remedies, obligations or liabilities whatsoever.

If to Covered Entitv Collier County Govemment Center 3301 Tamiarni Trial E.

Naples, FL 34 I 12

Attn: Risk Management Director Telephone no: 239-252-8461 Facsimile no: 239-252-8048 lf to Business Associate:

18. Indemnification. The Business Associate shall indemnify and hold harmless Covered Entity and any of Covered Entity's afllliates, directors, officers, employees and agents from and against any claim. cause ofaction, liability, damage, cosl or expense (including reasonable attomey's fees) arising out of or directly relating to any non-permitted disclosure of Protected Health lnformation or other breach of this Agreement by Business Associate or any affiliate, director, officer, employee, agent or subcontractor of Business Associate.

19. M iscellaneous

Severabilitv. ln the evenl that any provision ofthis Agreement is adjudged by any court of competent jurisdiction to be void or unenforceable, all remaining provisions hereof shall continue to be binding on the pafties hereto with the same force and effect as though such void or unenforceable provision had been deleted.

a

b. Waiver. No failure or delay in exercising any right, power ol rentedy hereunder shall operate as a lvaiver thereof; nor shall any single or parrial exercise of any right, power or remedy hereunder preclude any other further exercise thereof or the exercise of any other right, power or remedy. The rights provided hereunder are cumulative and not exclusive ofany rights provided by law.

c, Entire Agreement,'fhis Agreement constitutes the entire agreement between the parties hereto relating to the subjcct mafter hereof. and supercedes any prior or contetnporaneous verbal or written agreements, communications and representations relating 10 the subject matter hereof.

d. Counterpats, Facsimile. This agreement may be signed in two or nrore counterparts, each of which shall be deemed an original and all of which taken together shall constitute one and the same instrument. A copy of this Agreement bearing a facsimile signature shall be deemed to be an original.

Pase 7 of 9 cAo

Attn:

Telephone no:

Facsimile no:

IN WITNESS WHEREOF, the parties hereto have caused this Agreement 1o be signed as olthe date first set forth above.

COVERED ENTITY:

By:

Print Name:

Title:

BI.JSINESS ASSOCIATE:

By:

Print Name:

l-itle:

First Witness:

Witness (Signature)_

Print Name:

Second Witness:

Witness l Signature )_

Print Name:

EXH I I}I1' A

The following services to be performed by Business Associale require Business Associate to access. create and use PHI on behalf of Covered Entity in accordance with the ABreement:

Page 9 of9

File details come from the government source that posted it. Updated .