Attachment 8 - BUSINESS ASSOCIATE AGREEMENT - BAA.docx

DOCX document 30 KB Posted

Attached to
G004-- HUD VASH Case Management Federal contract opportunity
Solicitation number
36C24525Q0087
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 5

About this file

This is a Business Associate Agreement (BAA) template that establishes requirements for protecting Protected Health Information (PHI) between the Department of Veterans Affairs Veterans Health Administration and contractors providing HUD VASH Support Services. The BAA outlines specific obligations for handling PHI in accordance with HIPAA Privacy and Security Rules, including requirements for data safeguards, incident reporting, training, and proper disposal of information.

The agreement requires contractors to implement administrative, physical, and technical safeguards compliant with FISMA and VA policies, report any privacy/security incidents within 24 hours, provide annual privacy and security training to staff, and either return or destroy PHI upon contract completion. Key provisions include restrictions on PHI use/disclosure, requirements for subcontractor compliance, and specifications that contractors must be physically located within U.S. jurisdiction. The agreement is subject to biennial review and includes provisions for termination in case of material breach.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BUSINESS ASSOCIATE AGREEMENT BETWEEN THE DEPARTMENT OF VETERANS AFFAIRS VETERANS HEALTH ADMINISTRATION

AND

(Business Associate)

Whereas, _______________________ (Business Associate) provides HUD VASH Support Services (ie. Interviews, assessments, referrals etc.) services to the Department of Veterans Affairs Veterans Health Administration (Covered Entity), and

Whereas, in order for Business Associate to provide HUD VASH Support Services (ie. Interviews, assessments, referrals etc.) services to the Covered Entity, Covered Entity discloses to Business Associate Protected Health Information (PHI) and Electronic Protected Health Information (EPHI) that is subject to protection under regulations issued by the Department of Health and Human Services, as mandated by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), 45 CFR Parts 160 and 164, Subparts A and E, the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”), and 45 CFR Parts 160 and 164, Subparts A and C, the Security Standard (“Security Rule”); and

Whereas, Department of Veterans Affairs Veterans Health Administration is a “Covered Entity” as that term is defined in the HIPAA implementing regulations, 45 CFR 160.103, and

Whereas, ___________________________ as a recipient of PHI from Covered Entity in order to provide HUD VASH Support Services (ie. Interviews, assessments, referrals etc.) services to Covered Entity, is a “Business Associate” of Covered Entity as the term “Business Associate” is defined in the HIPAA implementing regulations, 45 CFR 160.103; and

Whereas, pursuant to the Privacy and Security Rules, all Business Associates of Covered Entities must agree in writing to certain mandatory provisions regarding the Use and Disclosure of PHI and EPHI; and

Whereas, the purpose of this Business Associate Agreement (BAA) is to comply with the requirements of the Privacy and Security Rules, including, but not limited to, the Business Associate Agreement requirements at 45 CFR 164.308(b), 164.314(a), 164.502(e), and 164.504(e), and as may be amended.

NOW, THEREFORE, the Covered Entity and Business Associate agree as follows:

1. Definitions. Unless otherwise provided in this BAA, capitalized terms and phrases that are defined in the Privacy and Security Rules have the same meanings as set forth in the Privacy and Security Rules. When the phrase “Protected Health Information” and the abbreviation “PHI” are used in this BAA, they include the phrase “Electronic Protected Health Information” and the abbreviation “EPHI”.

2. Ownership of PHI. PHI provided by Covered Entity to Business Associate and its agents and subcontractors, or gathered by them on behalf of the Covered Entity, under this BAA are the property of Covered Entity.

3. Scope of Use and Disclosure by Business Associate of Protected Health Information

A. Business Associate is permitted to make Use and Disclosure of PHI that is disclosed to it by Covered Entity, or received by Business Associate on behalf of Covered Entity, as necessary to perform its obligations under all applicable agreements and this BAA with covered entity, provided that the Covered Entity may make such Use or Disclosure under the Privacy and Security Rules, and the Use or Disclosure complies with the Covered Entity’s minimum necessary policies and procedures.

B. Unless otherwise limited herein, in addition to any other Uses and/or Disclosures permitted or authorized by this BAA or Required by Law, Business Associate may:

(1) Use the PHI in its possession for its proper management and administration and to fulfill any legal responsibilities of Business Associate;

(2) Make a Disclosure of the PHI in its possession to a third party for the purpose of Business Associate’s proper management and administration or to fulfill any legal responsibilities of Business Associate; provided, however, that the Disclosure is permitted by the Privacy Rule if made by the Covered Entity, or Required by Law; and provided further that where the Disclosure is not permitted by the Privacy Rule, or Required by Law, Business Associate has received from the third party written assurances that (a) the information will be held confidentially and Used or further Disclosed only as Required By Law or for the purposes for which it was disclosed to the third party; and (b) the third party will notify the Business Associate of any instances of which it becomes aware in which the confidentiality of the information has been breached;

(3) Engage in Data Aggregation activities, consistent with the Privacy Rule; and

(4) De-identify any and all PHI created or received by Business Associate under this BAA; provided that the de-identification conforms to the requirements of the Privacy Rule.

1. Obligations of Business Associate. In connection with its Use and Disclosure of PHI under this BAA, Business Associate agrees that it will:

1. Use or make further Disclosure of PHI only as permitted or required by the Privacy Rule, or this BAA or as Required by Law;

1. Ensure any employee of BA, contractor, subcontractor or agent of BA receives at least annual privacy training that conforms to the requirements of VHA Privacy Training;

1. Ensure any employee of BA, contractor, subcontractor or agent of BA, receives at least annual security awareness training that conforms to the requirements of the Department of Veterans Affairs Office of Cyber and Information Security Training;

1. Use reasonable and appropriate safeguards to prevent Use or Disclosure of PHI other than as provided by this BAA;

E. To the extent practicable, mitigate any harmful effect of a Use or Disclosure of PHI by Business Associate in violation of this BAA that is known to Business Associate;

F. Maintain a system or process to account for any Security Incident, Privacy Incident, or Use or Disclosure of PHI not provided for by this BAA of which Business Associate becomes aware;

1. Within 24 hours of Business Associate first becoming aware of a HIPAA Electronic Transactions and Code Sets, Privacy, Security or Standard Identifier Incident, or Use or Disclosure of PHI not provided for by this BAA, notify the Covered Entity and promptly provide a report to Covered Entity.

0. An incident will be considered any physical, technical or personal activity or event that increases the Covered Entity’s risk to inappropriate or unauthorized use or disclosure of PHI or causes the Covered Entity to be considered non-compliant with the Administrative Simplification provisions of HIPAA as determined by the Department of Health and Human Services.

0. Notification will be made by Business Associate to the Director, Health Data & Informatics by telephone, 202-461-5839 or secure fax of any HIPAA Electronic Transactions and Code Sets, Privacy, Security or Standard Identifier Incident, or Use or Disclosure of PHI not provided for by this BAA.

(3) A written report of the incident, submitted to the Director, Health Data & Informatics within ten (10) business days after initial notification, will document specifics surrounding the incident, what mitigation procedures were implemented to lessen the impact of the incident and what processes have been established to prevent the incident from occurring in the future (reasonable and appropriate safeguards). This report should be documented as a letter and sent to:

Director, Health Data & Informatics Department of Veterans Affairs – Veterans Health Administration Office of Information (19F) 810 Vermont Avenue NW Washington, DC 20420 Phone: 202-461-5839 Fax: 202-273-9386

H. Require contractors, subcontractors or agents to whom Business Associate provides PHI received from the CE to agree to the same restrictions and conditions that apply to Business Associate pursuant to this BAA, including implementation of reasonable and appropriate safeguards to protect PHI. Such third party shall be required to adopt and implement information security controls and safeguards that comply with the Federal Information Security Management Act (FISMA), Title III, Pub. L. No. 107-347, codified at 44 U.S.C. § 3541, and other applicable laws pertaining to the VA, including, without limitation, 38 U.S.C. § 5725, together with applicable VA policies pertaining to safeguarding VA Sensitive Data.

I. Make available to the Secretary of Health and Human Services Business Associate’s internal practices, books and records, including policies and procedures, relating to the Use or Disclosure of PHI for purposes of determining Covered Entity’s compliance with the Privacy and Security Rules, subject to any applicable legal privileges;

J. If the Business Associate maintains PHI in a Designated Record Set, maintain the information necessary to document the Disclosures of PHI sufficient to make an accounting of those Disclosures as required under the Privacy rule and the Privacy Act, 5 USC 552a, and within ten (10) days of receiving a request from Covered Entity, make available the information necessary for Covered Entity to make an accounting of Disclosures of PHI about an individual in the Designated Record Set or Covered Entity’s Privacy Act System of Records;

K. If the Business Associate maintains PHI in a Designated Record Set or Privacy Act System of Records, within ten (10) days of receiving a written request from Covered Entity, make available PHI in the Designated Record Set or System of Records necessary for Covered Entity to respond to individuals’ requests for access to PHI about them that is not in the possession of Covered Entity;

L. If the Business Associate maintains PHI in a Designated Record Set or Privacy Act System of Records, within ten (10) days of receiving a written request from Covered Entity, incorporate any amendments or corrections to the PHI in the Designated Record Set or System of Records in accordance with the Privacy Rule and Privacy Act;

M. Not make any Uses or Disclosures of PHI that Covered Entity would be prohibited from making.

N. Utilize only contractors, subcontractors, or agents who are physically located within a jurisdiction subject to the laws of the United States. Business associate will ensure that it does not use or disclose PHI received from Covered Entity in any way that will remove the PHI from such jurisdiction.

O. When Business Associate is uncertain whether it may make a particular Use or Disclosure of PHI in performance of this BAA, the Business Associate will consult with the Covered Entity before making the Use or Disclosure.

P. The Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality and integrity, and availability of the PHI that Business Associate receives, maintains, or transmits on behalf of the Covered Entity as required by the Privacy and Security Rules and shall also be required to adopt and implement information security controls and safeguards that comply with FISMA, and other applicable laws pertaining to the VA, including, without limitation, 38 U.S.C. § 5725, together with applicable VA policies pertaining to safeguarding VA Sensitive Data.

Q. The BA will provide satisfactory assurances that the confidentiality, integrity, and availability of the PHI, which it receives, creates, transmits or maintains, is reasonably and appropriately protected.

R. The BA will provide satisfactory assurances that any agent, including a subcontractor, to whom it provides such information agrees to implement reasonable and appropriate safeguards to protect the data.

S. Upon completion of the applicable contract(s) or agreement(s), the Business Associate shall return and/or destroy the PHI gathered, created, received or processed during the performance of the contract(s) or agreement(s), and no data will be retained by the Business Associate, or any agents or subcontractors of the Business Associate, unless retention is required by law or regulation. The Business Associate shall assure that all PHI has been returned to the Covered Entity, destroyed by the Business Associate, or both; as deemed appropriate by the Covered Entity. If immediate return or destruction of all data is not possible, the Business Associate shall assure that all PHI retained will be safeguarded to prevent unauthorized Uses or Disclosures. Until the Business Associate provides assurance, Covered Entity may withhold 15% of the final payment of the contract(s) or agreement(s).

5. Obligations of Covered Entity. Covered Entity agrees that it:

1. Has obtained, and will obtain, from Individuals any consents, authorizations and other permissions necessary or required by laws applicable to Covered Entity for Business Associate and Covered Entity to fulfill their obligations under this BAA.

1. Will promptly notify Business Associate in writing of any restrictions on the Use and Disclosure of PHI about Individuals that Covered Entity has agreed to that may affect Business Associate’s ability to perform its obligations under this BAA;

1. Will promptly notify Business Associate in writing of any change in, or revocation of, permission by an Individual to use or disclose PHI, if such change or revocation may affect Business Associate’s ability to perform its obligations under this BAA.

6. Material Breach of the BAA. Upon Covered Entity’s determination of a material breach of this BAA by Business Associate, Covered Entity shall provide an opportunity for Business Associate to cure the breach; and if cure is not possible, Covered Entity shall report the violation to the Secretary of Health and Human Services.

7. Termination.

A. Termination for Cause. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity shall either:

(1) Provide an opportunity for Business Associate to cure the breach or end the violation and terminate this Agreement and underlying contract(s) if Business Associate does not cure the breach or end the violation within the time specified by Covered Entity;

(2) Immediately terminate this Agreement and underlying contract(s) if Business Associate has breached a material term of this Agreement and cure is not possible;

(3) If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary of Health and Human Services.

(4) This BAA may be terminated by the Covered Entity, if appropriate, upon review as defined in Section 13 of this BAA.

B. Automatic Termination. This Agreement will automatically terminate upon completion of the Business Associate’s duties under all underlying agreements or by mutual written agreement to terminate underlying agreements.

C. Effect of Termination. Termination of this Agreement will result in cessation of activities by the Business Associate, and any agents or subcontractors of it involving PHI under this Agreement.

8. Amendment. Business Associate and Covered Entity agree to take such action as is necessary to amend this BAA for Covered Entity to comply with the requirements of the Privacy and Security Rules or other applicable law.

9. No Third Party Beneficiaries. Nothing expressed or implied in this BAA is intended to confer, nor shall anything herein confer, upon any person other than the parties and their respective successors or assigns, any rights, remedies, obligations or liabilities whatsoever.

10. Other Applicable Law. This BAA does not, and is not intended to, abrogate any responsibilities of the parties under any other applicable law.

11. Effect of Agreement. With respect solely to the subject matter herein, in the case of any conflict in terms between this BAA and any other previous agreement or addendum between the parties, the terms of this BAA shall control and supersede and nullify any conflicting terms as it relates to the parties in a business associate relationship.

12. Effective Date. This BAA shall be effective on _____________________.

13. Review Date. The provisions of this BAA will be reviewed by the Covered Entity every two years from Effective Date to determine the applicability of the agreement based on the relationship of the parties at the time of review.

Department of Veterans Affairs _______________________ Veterans Health Administration (Business Associate)

By: By:

Name: Name:

Title:Title:
Date:Date:

File details come from the government source that posted it. Updated .