APPENDIX-BSA.pdf

PDF 100 KB Posted

Attached to
EAP SERVICES State and local contract opportunity
Solicitation number
5400022442
Issued by
Richland County, South Carolina

About this file

This is a Business Associate Agreement appendix for Employee Assistance Program (EAP) Services between the South Carolina Department of Health and Human Services (SC DHHS) and contractors, issued under IFB 5400022442. The agreement establishes terms for protecting privacy of individually identifiable health information under the Health Insurance Portability and Accountability Act (HIPAA) while performing EAP functions and services on behalf of SC DHHS. The contractor, designated as a Business Associate, must comply with all HIPAA Rules including Privacy, Security, Breach Notification, and Enforcement Rules under 45 CFR Parts 160 and 164. The agreement outlines the term and termination provisions, with the contract term matching the underlying EAP Services contract between the parties, and SC DHHS retaining the right to terminate for cause if the Business Associate violates a material term and fails to cure the breach within thirty calendar days.

The Business Associate shall not use or disclose protected health information except as permitted by the contract or required by law, must implement appropriate safeguards for electronic protected health information, and must report any breaches within fifteen calendar days of discovery and security incidents on a quarterly basis. The contractor is responsible for breach notifications to individuals, the HHS Office of Civil Rights, and media on behalf of SC DHHS unless otherwise directed. Upon termination, the Business Associate must return or destroy all protected health information and retain no copies, with obligations surviving contract termination. The agreement includes provisions requiring subcontractors to comply with identical restrictions and conditions regarding protected health information, and prohibits disclosure of Social Security Administration data without written approval from SSA.

View the file

Other files for this state and local contract opportunity

Other files attached to EAP SERVICES, newest first.
File Type Posted
HIPPA COMPLIANCE.pdf PDF
ATTACHMENT Q and A.xlsx XLSX spreadsheet
AMENDMENT 1.pdf PDF
5400022442.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

APPENDIX --- BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT & SPECIAL SECURITY CLAUSES FOR SC DHHS CONTACTORS

IFB: 5400022442 -- EAP SERVICES FOR SC DHHS

A. Purpose:

The South Carolina Department of Health and Human Services (Covered Entity) and Business Associate agree to the terms of this

Agreement for the purpose of protecting the privacy of individually identifiable health information under the Health Insurance

Portability and Accountability Act of 1996 (HIPAA) in performing the functions, activities, or services for, or on behalf of, Covered Entity as specified in the Contract between the parties.

B. Definitions:

General Statement

The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data

Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy

Practices, Protected Health Information, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health

Information, and Use.

Specific definitions:

(a) Business Associate. “Business Associate” shall generally have the same meaning as the term “business associate” at 45 CFR

160.103, and in reference to the party to this Agreement, shall mean Contractor

(b) Covered Entity. “Covered Entity” shall generally have the same meaning as the term “covered entity” at 45 CFR 160.103, and in reference to the party to this Agreement, shall mean SCDHHS.

(c) HIPAA Rules. “HIPAA Rules” shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part

160 and Part 164.

C. Obligations and Activities of Business Associate:

Business Associate agrees to:

(a) Not use or disclose protected health information other than as permitted or required by the Agreement or as required by law;

(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic protected health information, to prevent use or disclosure of protected health information other than as provided for by the Agreement;

(c) Report to Covered Entity any use or disclosure of protected health information not provided for by the Agreement of which it becomes aware, including breaches of unsecured protected health information as required at 45 CFR 164.410, and any security incident of which it becomes aware;

(d) Notwithstanding the requirements of 45 CFR 164.410, Business Associate shall notify Covered Entity of potential breaches within fifteen (15) calendar days of discovery and include Covered Entity’s designee in their breach determination process;

(e) Business Associate shall report security incidents on a quarterly basis, unless the severity of the security incident elevates the risk to a potential breach, in which case paragraph (d) takes precedence;

(f) Unless otherwise directed by Covered Entity, Business Associate shall be responsible for breach notifications to individuals, the HHS Office of Civil Rights (OCR), and the media, if applicable, on behalf of Covered Entity and shall include Covered

Entity’s designee as part of the breach response team;

(g) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the Business Associate agree to the same restrictions, conditions, and requirements that apply to the Business Associate with respect to such information;

(h) Make available protected health information in a designated record set to the Covered Entity as necessary to satisfy Covered

Entity’s obligations under 45 CFR 164.524;

(i) Make any amendment(s) to protected health information in a designated record set as directed or agreed to by the Covered

Entity pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 CFR

164.526;

(j) Maintain and make available the information required to provide an accounting of disclosures to Covered Entity, or an individual if directed by Covered Entity, as necessary to satisfy Covered Entity’s obligations under 45 CFR 164.528;

(k) Notify Covered Entity within five (5) business days of receipt of any request covered under paragraphs (h), (i) or (j) above;

(l) To the extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under Subpart E of 45 CFR

Part 164, comply with the requirements of Subpart E that apply to the Covered Entity in the performance of such obligation(s);

and

(m) Make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the

HIPAA Rules.

D. Permitted Uses and Disclosures by Business Associate

(a) Business associate may only use or disclose protected health information as necessary to perform the services set forth in the

Contract to which this Agreement is appended, including, if applicable, authorization to use protected health information to de-identify the information in accordance with 45 CFR 164,514(a)-(c);

(b) Business Associate may use or disclose protected health information as required by law;

(c) Business Associate agrees to make uses and disclosures and requests for protected health information consistent with

Covered Entity’s minimum necessary policies and procedures;

(d) Business Associate may not use or disclose protected health information in a manner that would violate Subpart E of 45 CFR

Part 164 if done by Covered Entity;

(e) Business Associate may disclose protected health information for the proper management and administration of Business

Associate or to carry out the legal responsibilities of the Business Associate, provided the disclosures are required by law, or

Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(f) Business Associate may not disclose or duplicate protected health information identified by Covered Entity as provided by the Social Security Administration (SSA) without written approval and permission from SSA. If the need for such disclosure and/or duplication arises, Business Associate must notify Covered Entity and work with Covered Entity to obtain approval and permission from SSA.

E. Term and Termination

(a) Term. The Term of this Agreement shall be effective as of and shall terminate on the effective and termination dates of the

Contract to which this Agreement is appended, or on the date Covered Entity terminates for cause as authorized in paragraph (b) of this Section, whichever is sooner;

(b) Termination for Cause. Business Associate authorizes termination of this Agreement by Covered Entity, if Covered Entity determines Business Associate has violated a material term of the Agreement and Business Associate has not cured the breach or ended the violation within thirty (30) calendar days.

(c) Obligations of Business Associate Upon Termination.

(1) Upon termination of this Agreement for any reason, Business Associate shall return to Covered Entity, or, if agreed to by

Covered Entity, destroy all protected health information received from Covered Entity, or created, maintained, or received by

Business Associate on behalf of Covered Entity that the Business Associate still maintains in any form. Business Associate shall retain no copies of the protected health information;

(2) In the event that Business Associate determine that returning or destroying the protected health information is not practical or possible, Business Associate shall notify Covered Entity of the conditions and reasons return of the protected health information is not practical or possible. Upon concurrence by Covered Entity that return is not practical, Business

Associate shall:

(i) Continue to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to electronic protected health information to prevent use or disclosure of the protected health information, other than as provided for in this Section, for as long as Business Associate retains the protected health information;

(ii) Not use or disclose the protected health information retained by Business Associate other than for the purposes for which such protected health information was retained and subject to the same conditions set out at Section D of this Appendix.

(3) Business Associate shall obtain or ensure the destruction of protected health information created, received, or maintained by any subcontractors;

(4) Business Associate shall transmit the protected health information to another Business Associate of the Covered Entity at termination, if requested to do so by Covered Entity.

(d) Survival. The obligations of Business Associate under this Section shall survive the termination of this Agreement.

F. Miscellaneous

(a) Regulatory References. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended.

(b) Interpretation. Any ambiguity in this Agreement shall be interpreted to permit compliance with the HIPAA Rules.

File details come from the government source that posted it. Updated .