About this file

This document contains a draft HIPAA Business Associate Agreement template to be incorporated into a solicitation for a Comprehensive Cost Avoidance, Coordination of Benefits, and Recovery Program for the World Trade Center Health Program.

The template outlines requirements for contractors to comply with HIPAA privacy and security rules when handling protected health information as part of performing functions on behalf of the covered entity. Contractors would be directly liable for impermissible uses and disclosures of PHI, failure to provide breach notification, failure to provide access to electronic PHI, failure to disclose PHI for compliance investigations, and failure to comply with accounting of disclosure and security rule requirements. Notification must be provided within 10 days of any security breach involving WTC Health Program members' information. The solicitation seeks to establish a comprehensive cost avoidance and recovery program through implementation of a primary insurance identification system and database, validation and facilitation of coordination of benefits, recovery of incorrectly paid claims from private insurers, participation in New York's workers compensation program for reimbursement identification, and provision of performance metrics and payment integrity services.

View the file

Other files for this federal contract opportunity

Other files attached to WTCHP Comprehensive Cost Avoidance, Coordination of Benefits, and Recovery Program, newest first.
File Type Posted
Attachment J.7 Business Template.xlsx XLSX spreadsheet
Attachment J.1 SOO.docx DOCX document
RFQ 75D301-20-R-67859 Amendment One .pdf PDF
Attachment J.2 Template Performance-Work-Statement.docx DOCX document
Attachment J.1 SOO.docx DOCX document
Attachment J.6 Responses to Pre-Solicitation Questions.xlsx XLSX spreadsheet
Attachment J.5 Past Performance .docx DOCX document
Attachment J.2 Template Performance-Work-Statement.docx DOCX document
Attachment J.1 SOO.docx DOCX document
Attachment J.4 HHS SubK Plan Template.pdf PDF
RFQ 75D301-20-R-67859.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment J.3 Draft Document Subject to Change Prior to Final Solicitation

HIPAA Compliance and Business Associate Agreement

To the extent that the Business Associate performs functions or activities on behalf of, or provides certain services to, the Covered Entity where the Business Associate creates, receives, maintains, or transmits “protected health information” (PHI), the following “HIPAA provisions” apply: the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub. L. 104–191; 42 U.S.C. § 1320d); the Health Information Technology for Economic and Clinical Health (HITECH) Act[footnoteRef:1][1] (Pub. L. 111-5; 42 U.S.C. §§ 300jj et seq.); the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (45 C.F.R. pts. 160, 162, and 164); and HHS HIPAA policies. [1: [1] The HITECH Act was passed as Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA). ]

For purposes of this contract, “Business Associate” shall mean the Comprehensive Cost Avoidance, Coordination of Benefits, and Recovery Program Contractor; “Covered Entity”[footnoteRef:2][2] shall mean the WTC Health Program and any other NIOSH, CDC, or HHS components to the extent that they assist in administering the WTC Health Program and where PHI is involved. These terms are used as defined in 45 C.F.R. § 160.103. [2: [2] The term “covered entity” is used in this section for ease of understanding. However, a more precise description of the application of HIPAA to the WTC Health Program is as follows:

HHS is a hybrid entity under HIPAA, meaning HHS is a covered entity that conducts business activities, including both covered and non-covered functions, and designates “health care components” in accordance with 45 C.F.R. § 164.105(a)(2)(iii)(D). 45 C.F.R. § 164.103. As a hybrid entity, HHS must designate any component that would “meet the definition of a covered entity or business associate if it were a separate legal entity” as a health care component; a health care component also may include a component only to the extent that it performs covered functions. 45 C.F.R. § 164.105(a)(2)(iii)(D). Accordingly, the WTC Health Program is a “health care component” of the covered entity, HHS; as are any other NIOSH, CDC, or HHS components if they would meet the definition of a covered entity or business associate if they were separate legal entities and only to the extent that they perform covered functions. ]

For any security/data breach that should occur (for WTC Health Program Members but is not reportable to NIOSH/WTC Health Program under the Business Associate Agreement) resulting in a reportable incident to the HHS Office for Civil Rights, the contractor shall notify the designated NIOSH/WTC Health Program HIPAA Compliance Officer within ten (10) days of the incident. Notification to the Compliance Officer should be provided prior to the WTC Health Program learning of said incident from outside sources (HHS Office for Civil Rights, Organizational Press Release, Letter sent to WTC Health Program member, etc.). Notification should include the date and nature of the incident (including the identification of each WTC Health Program member whose information was implicated in the incident and the extent of the information breached) and actions being taken by the contractor as a result of the breach.

The Business Associate Agreement provides the detailed legal obligations and requirements of the Business Associate and the Covered Entity, and will be incorporated into this contract as Attachment J-3 in Section J of the contract.

At all times throughout the duration of this contract and until the Business Associate fulfills its obligations under this contract and the Business Associate Agreement, the Business Associate is subject to and shall comply with all applicable HIPAA provisions regarding business associates, as well as any updates to those provisions.

The parties acknowledge that the Business Associate is directly liable under HIPAA for the following violations:[footnoteRef:3][3] [3: [3] Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act;

Other Modifications to the HIPAA Rules [Omnibus Rule], 78 Fed. Reg. 5566, 5598-99 (Jan. 25, 2013).]

· Impermissible uses and disclosures of PHI;

· Failure to provide breach notification to the Covered Entity;

· Failure to provide access to a copy of electronic PHI to either the Covered Entity, the individual, or the individual’s designee, as specified in the Business Associate Agreement;

· Failure to disclose PHI where required by the Secretary of HHS to investigate or determine the Business Associate’s compliance with HIPAA;

· Failure to provide an accounting of disclosures; and

· Failure to comply with the requirements of the Security Rule.

[1] The HITECH Act was passed as Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA).

[2] The term “covered entity” is used in this section for ease of understanding. However, a more precise description of the application of HIPAA to the WTC Health Program is as follows:

HHS is a hybrid entity under HIPAA, meaning HHS is a covered entity that conducts business activities, including both covered and non-covered functions, and designates “health care components” in accordance with 45 C.F.R. § 164.105(a)(2)(iii)(D). 45 C.F.R. § 164.103. As a hybrid entity, HHS must designate any component that would “meet the definition of a covered entity or business associate if it were a separate legal entity” as a health care component; a health care component also may include a component only to the extent that it performs covered functions. 45 C.F.R. § 164.105(a)(2)(iii)(D). Accordingly, the WTC Health Program is a “health care component” of the covered entity, HHS; as are any other NIOSH, CDC, or HHS components if they would meet the definition of a covered entity or business associate if they were separate legal entities and only to the extent that they perform covered functions.

[3] Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules [Omnibus Rule], 78 Fed. Reg. 5566, 5598-99 (Jan. 25, 2013).

_____________
Signature, Authorized to Sign on Behalf of VendorDate

Name:

Title:

Organization:

Signature, On behalf of World Trade Center Health Program

Name:

Title:Contracting Officer
Organization:Centers for Disease Control and Prevention

File details come from the government source that posted it. Updated .