Attachment J.3 BAA Template.docx
DOCX document 20 KB Posted
- Attached to
- WTCHP Comprehensive Cost Avoidance, Coordination of Benefits, and Recovery Program Federal contract opportunity
- Solicitation number
- 75D301-20-R-67859
About this file
This document is a draft template for a HIPAA compliance and business associate agreement to be included in a federal contract for comprehensive cost avoidance, coordination of benefits, and recovery program services for the World Trade Center Health Program. The agreement outlines requirements for contractors to comply with HIPAA privacy and security rules when handling protected health information of program members. Contractors would be directly liable for impermissible disclosures, failure to provide breach notifications, lack of access to electronic health information, and noncompliance with other HIPAA requirements. The contractor must notify the designated HIPAA compliance officer within 10 days of any security breaches involving program members' data. This agreement would be incorporated into the contract as an attachment.
The related federal contract opportunity is a pre-solicitation notice seeking industry and stakeholder feedback on a draft solicitation for comprehensive cost avoidance, coordination of benefits, and recovery program services for the World Trade Center Health Program. Responses to the draft solicitation using the provided template must be submitted to the Centers for Disease Control and Prevention by January 17, 2020. The final solicitation is planned for release in January 2020.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment J.4 HHS SubK Plan Template.pdf | ||
| Attachment J.2 Template-Statement-of-Work.docx | DOCX document | |
| Attachment J.1 SOO.docx | DOCX document | |
| Draft Solicitation Response Template.xlsx | XLSX spreadsheet | |
| Draft Solicitation RFQ 75D301-20-R-67859.pdf | ||
| Original Presolicitation Notice FBO.gov.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment J.3 Draft Document Subject to Change Prior to Final Solicitation
HIPAA Compliance and Business Associate Agreement
To the extent that the Business Associate performs functions or activities on behalf of, or provides certain services to, the Covered Entity where the Business Associate creates, receives, maintains, or transmits “protected health information” (PHI), the following “HIPAA provisions” apply: the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub. L. 104–191; 42 U.S.C. § 1320d); the Health Information Technology for Economic and Clinical Health (HITECH) Act[footnoteRef:1][1] (Pub. L. 111-5; 42 U.S.C. §§ 300jj et seq.); the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (45 C.F.R. pts. 160, 162, and 164); and HHS HIPAA policies. [1: [1] The HITECH Act was passed as Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA). ]
For purposes of this contract, “Business Associate” shall mean the Comprehensive Cost Avoidance, Coordination of Benefits, and Recovery Program Contractor; “Covered Entity”[footnoteRef:2][2] shall mean the WTC Health Program and any other NIOSH, CDC, or HHS components to the extent that they assist in administering the WTC Health Program and where PHI is involved. These terms are used as defined in 45 C.F.R. § 160.103. [2: [2] The term “covered entity” is used in this section for ease of understanding. However, a more precise description of the application of HIPAA to the WTC Health Program is as follows:
HHS is a hybrid entity under HIPAA, meaning HHS is a covered entity that conducts business activities, including both covered and non-covered functions, and designates “health care components” in accordance with 45 C.F.R. § 164.105(a)(2)(iii)(D). 45 C.F.R. § 164.103. As a hybrid entity, HHS must designate any component that would “meet the definition of a covered entity or business associate if it were a separate legal entity” as a health care component; a health care component also may include a component only to the extent that it performs covered functions. 45 C.F.R. § 164.105(a)(2)(iii)(D). Accordingly, the WTC Health Program is a “health care component” of the covered entity, HHS; as are any other NIOSH, CDC, or HHS components if they would meet the definition of a covered entity or business associate if they were separate legal entities and only to the extent that they perform covered functions. ]
For any security/data breach that should occur (for WTC Health Program Members but is not reportable to NIOSH/WTC Health Program under the Business Associate Agreement) resulting in a reportable incident to the HHS Office for Civil Rights, the contractor shall notify the designated NIOSH/WTC Health Program HIPAA Compliance Officer within ten (10) days of the incident. Notification to the Compliance Officer should be provided prior to the WTC Health Program learning of said incident from outside sources (HHS Office for Civil Rights, Organizational Press Release, Letter sent to WTC Health Program member, etc.). Notification should include the date and nature of the incident (including the identification of each WTC Health Program member whose information was implicated in the incident and the extent of the information breached) and actions being taken by the contractor as a result of the breach.
The Business Associate Agreement provides the detailed legal obligations and requirements of the Business Associate and the Covered Entity, and will be incorporated into this contract as Attachment J-3 in Section J of the contract.
At all times throughout the duration of this contract and until the Business Associate fulfills its obligations under this contract and the Business Associate Agreement, the Business Associate is subject to and shall comply with all applicable HIPAA provisions regarding business associates, as well as any updates to those provisions.
The parties acknowledge that the Business Associate is directly liable under HIPAA for the following violations:[footnoteRef:3][3] [3: [3] Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act;
Other Modifications to the HIPAA Rules [Omnibus Rule], 78 Fed. Reg. 5566, 5598-99 (Jan. 25, 2013).]
· Impermissible uses and disclosures of PHI;
· Failure to provide breach notification to the Covered Entity;
· Failure to provide access to a copy of electronic PHI to either the Covered Entity, the individual, or the individual’s designee, as specified in the Business Associate Agreement;
· Failure to disclose PHI where required by the Secretary of HHS to investigate or determine the Business Associate’s compliance with HIPAA;
· Failure to provide an accounting of disclosures; and
· Failure to comply with the requirements of the Security Rule.
[1] The HITECH Act was passed as Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA).
[2] The term “covered entity” is used in this section for ease of understanding. However, a more precise description of the application of HIPAA to the WTC Health Program is as follows:
HHS is a hybrid entity under HIPAA, meaning HHS is a covered entity that conducts business activities, including both covered and non-covered functions, and designates “health care components” in accordance with 45 C.F.R. § 164.105(a)(2)(iii)(D). 45 C.F.R. § 164.103. As a hybrid entity, HHS must designate any component that would “meet the definition of a covered entity or business associate if it were a separate legal entity” as a health care component; a health care component also may include a component only to the extent that it performs covered functions. 45 C.F.R. § 164.105(a)(2)(iii)(D). Accordingly, the WTC Health Program is a “health care component” of the covered entity, HHS; as are any other NIOSH, CDC, or HHS components if they would meet the definition of a covered entity or business associate if they were separate legal entities and only to the extent that they perform covered functions.
[3] Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules [Omnibus Rule], 78 Fed. Reg. 5566, 5598-99 (Jan. 25, 2013).
| _____________ | ||
| Signature, Authorized to Sign on Behalf of Vendor | Date |
Name:
Title:
Organization:
Signature, On behalf of World Trade Center Health Program
Name:
| Title: | Contracting Officer |
| Organization: | Centers for Disease Control and Prevention |
File details come from the government source that posted it. Updated .