ATT020_Template_BusinessAssociateAgreement.docx

DOCX document 76 KB Posted

Attached to
World Trade Center Health Program - National Program Administrator Federal contract opportunity
Solicitation number
75D30126R73374
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

This document is a Business Associate Agreement for the World Trade Center Health Program (WTC Health Program), detailing HIPAA compliance requirements for a business associate handling protected health information (PHI). The agreement outlines specific obligations for the business associate, including safeguarding PHI, preventing unauthorized disclosures, implementing security measures, reporting breaches, and maintaining confidentiality. Key requirements include conducting risk analyses, limiting PHI access, implementing workforce security measures, and ensuring subcontractors adhere to the same privacy and security standards. The agreement is designed to protect sensitive health information in compliance with HIPAA regulations, with provisions for termination in case of material breaches and requirements for PHI handling upon contract conclusion.

View the file

Other files for this federal contract opportunity

Other files attached to World Trade Center Health Program - National Program Administrator, newest first.
File Type Posted
HHSSubcontractingPlan.pdf PDF
Amendment_00004_NPA RFP 75D301-26-R-73374 -signed.pdf PDF
NPA Questions and Answers - 1-27-26.pdf PDF
Amendment_00003_NPA RFP 75D301-26-R-73374.pdf PDF
NPA Questions and Answers - Complete.pdf PDF
NPA - 75D301-26-R-73374 January 22 Marked Version.docx DOCX document
NPA - 75D301-26-R-73374 January 22 Clean Version.pdf PDF
Final - ReceivedNPA_QuestionsandAnswers_1-22-26.pdf PDF
Amendment_00002_NPA RFP 75D301-26-R-73374.pdf PDF
ATT026_NPA_OfferorNDA.pdf PDF
1. 75D301-26-R-73374 December 11.docx DOCX document
1. 75D301-26-R-73374 December 11.pdf PDF
ATT025_NPA_QuestionsandAnswersTemplate.xlsx XLSX spreadsheet
ATT024_OAS_FullyBurdenedLaborRates_Excel.xlsx XLSX spreadsheet
ATT016_ReferenceGuide_CMUM.pdf PDF
ATT008_BrandGuidelines.pdf PDF
ATT006_MandatoryNPA_Training.docx DOCX document
ATT005_TGD003_SemiAnnualReport.pdf PDF
2. 75D301-26-R-73374 December 11.pdf PDF
ATT023_OAS_LaborCategories_Vol1.docx DOCX document
ATT022_Final_NPASummaryVolumeData_20251113.xlsx XLSX spreadsheet
ATT017_XP005_PharmacyNetworkDispensing.pdf PDF
ATT014_BEAST_ Survivors.docx DOCX document
ATT012_XP012_DisruptiveMember.pdf PDF
ATT021_TGD-009-MonthlyReport.pdf PDF
ATT019_XP007_PharmacyProviderBlock.pdf PDF
ATT014_BEAST_Responders.docx DOCX document
ATT010_ TGD028_DataManagement.pdf PDF
ATT009_TranslationGuide.xlsx XLSX spreadsheet
ATT003_NPA_WrapUpCodes.xlsx XLSX spreadsheet
ATT001_NPA_Glossary.xlsx XLSX spreadsheet
1.75D301-26-R-73374 December 11.docx DOCX document
ATT018_XP001_PharmacyCAFA.pdf PDF
ATT015_TGD011_IHE_MonitoringExams.pdf PDF
ATT013_DisruptiveMember_IncidentReport (1).pdf PDF
ATT011_TransferHandbook.pdf PDF
ATT007_TGD020_CommsPlan.pdf PDF
ATT004_NPA_Template_RAIDLog.xlsx XLSX spreadsheet
ATT002_NPA_QASP.docx DOCX document
Show all 39

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

World Trade Center Health Program Business Associate Agreement

A. Definitions

All terms used herein and not otherwise defined shall have the same meaning as in the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) (Pub. L. 104–191; 42 U.S.C. § 1320d), as modified, and the corresponding implementing regulations, including the Privacy, Security, Breach Notification, and Enforcement Rules (45 C.F.R. pts. 160, 162, and 164). Non-HIPAA related provisions governing the Contractor’s duties and obligations, such as those under the Privacy Act and any applicable data use agreements, are covered elsewhere in the contract and other contract-related documents.

“Business Associate” shall generally have the same meaning as the term “business associate” at 45 C.F.R. §

160.103 and, for the purpose of this agreement and any underlying contract between the parties, shall mean [Contractor], if/when the Business Associate performs functions or activities on behalf of the Covered Entity where the Business Associate creates, receives, maintains, or transmits “protected health information” or where the Business Associate provides certain services to or for the Covered Entity which require the disclosure of protected health information to the Business Associate by the Covered Entity.

“Covered Entity”1 shall generally have the same meaning as the term “covered entity” at 45 C.F.R. § 160.103 and, for the purpose of this agreement and any underlying contract between the parties, shall mean the World Trade Center Health Program (WTC Health Program) and any other NIOSH, CDC, or HHS components to the extent that they assist in administering the WTC Health Program where protected health information is involved.

“Protected Health Information” (PHI) shall generally have the same meaning as the term “protected health information” at 45 C.F.R. § 160.103. The HIPAA regulations define PHI as individually identifiable health information (health information, including demographic information, collected from an individual and created or received by a health care provider, health plan, employer, or health care clearinghouse that relates to the individual’s past, present, or future mental or physical health condition, provision of health care, or payment for care and which identifies the individual or is reasonably believed to make the individual identifiable) that is transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium. PHI excludes individually identifiable health information in certain education records, certain student medical records, employment records held by a covered entity in its role as employer, and records regarding a person who has been deceased for more than 50 years.

“Secretary” shall mean the Secretary of the Department of Health and Human Services or the Secretary’s designee.

B. Obligations and Activities of Business Associate

Business Associates, as well as their agents and subcontractors, shall meet all applicable HIPAA obligations. Furthermore, they shall document in writing the policies and procedures that will be used to meet such obligations.

1 The term “covered entity” is used in this section for ease of understanding. However, a more precise description of the application of HIPAA to the WTC Health Program is as follows:

HHS is a hybrid entity under HIPAA, meaning HHS is a covered entity that conducts business activities, including both covered and non-covered functions, and designates “health care components” in accordance with 45 C.F.R. § 164.105(a)(2)(iii)(D). 45 C.F.R. § 164.103. As a hybrid entity, HHS must designate any component that would “meet the definition of a covered entity or business associate if it were a separate legal entity” as a health care component; a health care component also may include a component only to the extent that it performs covered functions. 45 C.F.R. § 164.105(a)(2)(iii)(D). Accordingly, the WTC Health Program is a “health care component” of the covered entity, HHS; as are any other NIOSH, CDC, or HHS components if they would meet the definition of a covered entity or business associate if they were separate legal entities and only to the extent that they perform covered functions.

Last Updated: 04/28/2021
Last Reviewed: 10/20/2021

These obligations include the following:

1. Business Associate agrees to not use or disclose PHI other than as permitted or required by this Contract or as required by law.

2. Business Associate agrees to prevent use or disclosure of PHI other than as provided for by this Agreement through use of appropriate safeguards and complying with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI. In accordance with 45 C.F.R. §§ 164.306 and 164.316, Business Associate shall implement written policies and procedures to:

a. Prevent, detect, contain, and correct security violations2 through the use of:

i. Risk analyses (including periodic technical and nontechnical evaluations);3

ii. Appropriate risk management strategies (including information system activity review);4

iii. Information access procedures for approving individual’s access rights to PHI (including the implementation of workforce security measures to ensure continued appropriate role- based access to PHI over time), and technical policies and procedures to ensure compliance with grants of access (including unique user identification and emergency access procedures);5 and

iv. The imposition of sanctions of workforce members of Business Associate for violations.6

b. Limit physical access to its electronic information systems and the facility or facilities in which they are housed.7

c. Limit access to PHI through workstations and other devices, including access through mobile devices.8

d. Employ media controls covering the movement of devices containing PHI within or outside of the BA’s facility as well as the disposal and reuse of media containing PHI.9

3. Business Associate agrees to report to Covered Entity any use or disclosure of PHI not provided for by this Agreement which it discovers, including breaches of unsecured PHI as required at 45 C.F.R. § 164.410, and any security incident10 of which it becomes aware, including those of its agents and subcontractors.

The Business Associate shall report any violation in use or disclosure involving PHI, any security incidents, and any breaches involving unsecured PHI to Covered Entity (designated WTC Health Program point of contact for HIPAA concerns) within three (3) business days of discovery. Upon reporting of a potential breach by Business Associate, Covered Entity may engage Business Associate in coordinating notification actions.

4. Business Associate agrees to ensure, in accordance with 45 C.F.R. § 164.502(e)(1)(ii) and, if applicable, 45 C.F.R. § 164.308(b)(2), that any agents or subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree through a written contract or other arrangement to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information.

2 See 45 C.F.R. § 164.308(a)(1)(i).

3 See 45 C.F.R. § 164.308(a)(1)(ii)(A) and (B).

4 See 45 C.F.R. § 164.308(a)(1)(ii)(D) and (a)(8).

5 See 45 C.F.R. § 164.308(a)(3) and (4); 45 C.F.R. § 164.312(a)(2).

6 See 45 C.F.R. § 164.308(a)(1)(ii)(C).

7 See 45 C.F.R. § 164.310(a)(1).

8 See 45 C.F.R. § 164.310(b), (c), and (d).

9 See 45 C.F.R. § 164.310(d).

10 “Security incident” is defined as the “attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.” 45 C.F.R. § 164.304.

5. Business Associate agrees to provide access, at the request of Covered Entity, to PHI in a designated record set to Covered Entity or, as directed by Covered Entity, to an Individual or an Individual’s designee in order to meet the requirements under 45 C.F.R. § 164.524.11

6. Business Associate agrees to make any amendment(s) to PHI in a designated record set that Covered Entity directs or agrees to pursuant to 45 C.F.R. § 164.526 upon request of Covered Entity, or take other measures as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.526.12

7. Business Associate agrees to maintain and make available any information required to provide an accounting of disclosures to Covered Entity, or to an individual identified by Covered Entity as requesting such an accounting, as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. § 164.528.13

8. Business Associate agrees that, to the extent the Business Associate carries out one or more of Covered Entity’s obligation(s) under Subpart E of 45 C.F.R. Part 164, including providing access, making amendments, or providing an accounting of disclosures, as referenced in this Agreement, it will comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s).

9. Business Associate agrees to make its facilities, books, records, accounts, and other sources of information, including PHI, that are pertinent to ascertaining its own or Covered Entity’s compliance with the applicable HIPAA provisions, available to Covered Entity; or, in the context of an investigation or compliance review, to the Secretary for purposes of the Secretary determining Business Associate’s or Covered Entity's compliance with the various rules implementing HIPAA.

10. Business Associate agrees to designate a security official who will be responsible for development and implementation of its security policies and procedures, including workforce security measures to ensure proper security awareness and training (including security incident response and reporting), and security incident procedures.

11. Business Associate agrees to use appropriate administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability (including the use of contingency plans) of the electronic PHI, as defined in 45 C.F.R. §160.103, that it creates, receives, maintains, or transmits on behalf of the Covered Entity to prevent impermissible use or disclosure of such electronic PHI. In establishing such safeguards, Business Associate shall consider its size, complexity, and capabilities, as well as its technical infrastructure and its hardware and software security capabilities.

12. Business Associate agrees to assess and, where appropriate, implement any addressable implementation specifications associated with applicable PHI security standards.

13. Business Associate agrees not to threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action against any individual for the following: filing a complaint under 45 C.F.R. § 160.306; testifying, assisting, or participating in an investigation, compliance review, proceeding, or hearing under 45 C.F.R. Part 160; or opposing any act or practice that is unlawful under HIPAA, provided there is a good faith belief that the practice is unlawful, the manner of opposition is reasonable, and the opposition does not involve the disclosure of PHI in violation of subpart E of Part 164.

14. Business Associate agrees not to sell PHI other than as permitted by 45 C.F.R. § 164.508(a)(4).

15. Business Associate agrees to make reasonable efforts to limit the PHI it uses, discloses, or requests to the minimum necessary to accomplish the intended purpose of the permitted use, disclosure, or request in accordance with 45 C.F.R. § 164.502(b).

11 See 45 C.F.R. § 164.504(e)(2)(ii)(E).

12 See 45 C.F.R. § 164.504(e)(2)(ii)(F).

13 See 45 C.F.R. § 164.504(e)(2)(ii)(G).

16. Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate.

17. Business Associate may disclose PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate, provided the disclosures are required by law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that the information will remain confidential and used or further disclosed only as required by law or for the purposes for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it discovers that the confidentiality of the information has been breached.

C. Permitted Uses and Disclosures by Business Associate

Except as otherwise limited in this Agreement, Business Associate may use or disclose PHI on behalf of, or to provide services to, Covered Entity for purposes of the performance of this Agreement, if such use or disclosure of PHI would not violate either the HIPAA Privacy or Security Rules if done by Covered Entity or the minimum necessary policies and procedures of Covered Entity.

D. Obligations of Covered Entity

1. Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices of Covered Entity in accordance with 45 C.F.R. § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI.

2. Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.

3. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 C.F.R. § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

E. Term and Termination

1. The term of this Agreement, which is fully incorporated into the overall Contract as an Exhibit, shall be effective as of the date of contract award, and shall terminate when all of the PHI provided by Covered Entity to Business Associate, or created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity or, if Business Associate needs to retain PHI for its own management and administration or to carry out its legal responsibilities, in accordance with the termination provisions in this Section.

2. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall take one of the following actions:

a. Provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination terms of this Agreement. Covered Entity may terminate this Agreement, which would result in terminating the overall Contract with Business Associate, for default if the Business Associate does not cure the breach or end the violation within fifteen (15) business days; or,

b. Consistent with the terms of this Agreement, terminate this Agreement, as well as the overall Contract, for default if Business Associate has breached a material term of this Agreement and cure is not possible.

3. Effect of Termination.

a. Upon termination of this Agreement and overall Contract for any reason, Business Associate, with respect to PHI created, received, maintained, or transmitted by Business Associate on behalf of

Covered Entity, shall:

i. Retain only that PHI which is necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities;

ii. Return to Covered Entity or destroy the remaining PHI that the Business Associate still maintains in any form;

iii. Continue to use appropriate safeguards and comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI to prevent use or disclosure of the PHI, other than as provided for in this Section, for as long as Business Associate retains the PHI;

iv. Not use or disclose the PHI retained by Business Associate other than for the purposes for which such PHI was retained and subject to the same conditions set out at Paragraphs b.16 and 17 above which applied prior to termination; and

v. Return to Covered Entity or destroy the PHI retained by Business Associate when it is no longer needed by Business Associate for its proper management and administration or to carry out its legal responsibilities.

b. Upon termination of this Agreement and overall Contract for any reason, Business Associate shall obtain PHI created, received, maintained, or transmitted by agents and subcontractors of Business Associate on behalf of Covered Entity.

F. Miscellaneous

1. A reference in this Agreement to a section in the Rules issued under HIPAA means the section as in effect or as amended.

2. PHI provided by Covered Entity to Business Associate and its contractors, subcontractors, or other agents, or gathered by them on behalf of the Covered Entity under this Agreement is the property of the Covered Entity.

3. The Parties agree to take such action as is necessary to amend this Contract from time to time as is necessary for Covered Entity to comply with the requirements of the Rules issued under HIPAA and any other applicable law.

4. The respective rights and obligations of Business Associate under paragraph E.3 of the section titled “Term and Termination” shall survive the termination of this Agreement.

5. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with the Rules implemented under HIPAA.

Signature, On behalf of vendor

Name: Title: Organization:

Date:

On behalf of the World Trade Center Health Program Dr. John Howard, Program Administrator

Page 4 of5

File details come from the government source that posted it. Updated .