ATTACHMENT P - Business Associate Agreement, Version 070623 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf
PDF 276 KB Posted
- Attached to
- Kentucky Analytics Platform Solution (KAPS) State and local contract opportunity
- Solicitation number
- RFP-758-2500000171-6
- Issued by
- Kentucky
About this file
This document is a Business Associate Agreement (BAA) for the Kentucky Analytics Platform Solution (KAPS) RFP issued by the Cabinet for Health and Family Services, Office of Administrative Services, Division of Procurement and Grant Oversight. The BAA is designed to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA) regulations, specifically addressing the handling of Protected Health Information (PHI) between a Covered Entity and a Business Associate. The document outlines the obligations, permitted uses, and disclosure requirements for PHI, including detailed provisions for data protection, breach notification, confidentiality, and the handling of sensitive health information.
The agreement establishes comprehensive guidelines for safeguarding electronic and non-electronic PHI, with specific requirements for security measures, reporting of incidents, and mitigation of potential breaches. Key provisions include the Business Associate's responsibilities to implement administrative, physical, and technical safeguards, report any unauthorized use or disclosure of PHI, provide access to PHI as needed, and ensure that any subcontractors or agents are bound by the same confidentiality and protection standards. The document also addresses termination conditions, survival of certain obligations, and mutual representations, with dispute resolution to be handled in Franklin Circuit Court or Federal District Court of Kentucky.
View the file
Other files for this state and local contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT P
BUSINESS ASSOCIATE AGREEMENT (STATE GOVERNMENT)
KAPS RFP
Version 07/06/23 1 The Cabinet for Health and Family Services Office of Administrative Services Division of Procurement and Grant Oversight
This Business Associate Agreement (Agreement) is entered into as of the effective date listed in the Service
Contract by and between the Department Listed in the Service Contract (“Covered Entity” hereinafter), whose principal place of business is located at the address listed in the Service Contract and the Vendor listed in the Service Contract (“Business Associate” hereinafter), whose principal place of business is located at the address listed in the Service Contract, in conformance with the Health Insurance Portability and Accountability Act of 1996, and its implementing regulations (“HIPAA RULES” hereinafter).
RECITALS
Whereas, the Covered Entity has engaged the services of the Business Associate for or on behalf of the
Covered Entity in the Service Contract # _____________________;
Whereas, the Covered Entity must disclose individually identifiable health information to the Business
Associate in the performance of services, as referenced in the Service Contract, for or on behalf of the
Covered Entity;
Whereas, such information is Protected Health Information (PHI) as defined by the Privacy, Security, and
Breach Notification and Enforcement Rules promulgated under HIPAA;
Whereas, the Parties agree to establish safeguards for the protection of such information;
Whereas, the Covered Entity and Business Associate desire to enter into this Agreement to address certain requirements under the HIPAA Rules as required by the implementing regulations;
Therefore, the parties agree as follows:
SECTION I – DEFINITIONS
Relevant terms used in this Agreement shall have the same meaning as those terms found in the HIPAA
Rules found at 45 CFR §164.402; 45 CFR § 164.501; §164.304; and §160.103. The following terms, as defined in the HIPAA implementing regulations and used herein, shall mean:
1.1 “Breach” is defined as any unauthorized acquisition, access, use or disclosure of PHI which compromises the security or privacy of the PHI, unless the Covered Entity or Business Associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based upon a risk assessment as required under 45 CFR § 164.402. The definition of Breach excludes the following uses and disclosures:
a. Unintentional acquisition, access or use of protected health information by a workforce member or person acting under the authority of a Covered Entity or Business Associate, if performed in good faith and within the scope of authority, and does not result in further unauthorized disclosures;
b. Inadvertent one time disclosure between Covered Entity or Business Associate work force member to another work force member at the same Covered Entity or Business Associate who
RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS)
KAPS RFP
Version 07/06/23 2 The Cabinet for Health and Family Services Office of Administrative Services Division of Procurement and Grant Oversight is authorized to access PHI and information received or disclosed is not further used or disclosed in a manner not permitted under Subpart E found at 45 CFR § 164.500, et seq.; and
c. The Covered Entity or Business Associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain the information.
1.2 “Business Associate” shall have the meaning given to such term under the HIPAA Rules, including, but not limited to, 45 CFR §160.103, and includes a person or entity who creates, receives, maintains, or transmits PHI for a function or activity of the covered entity as set out under the regulation, and includes any subcontractor of the business associate who creates, receives, maintains, or transmits PHI on behalf of the business associate under 45 CFR § 160.103 (3) (iii).
1.3 “Covered Entity” shall have the meaning given to such term under the HIPAA Rules, including, but not limited to, 45 CFR §160.103.
1.4 “Designated Record Set” shall have the meaning given to such term under the HIPAA Rules, including, but not limited to 45 CFR §164.501.
1.5 “Effective Date” shall be the Effective Date of this amended and restated Agreement.
1.6 "Electronic Protected Health Information" or "Electronic PHI" shall have the meaning given to such term at 45 CFR §160.103, limited to information of the Covered Entity that the Business Associate creates, receives, maintains or transmits in electronic media on behalf of the Covered Entity under the terms and conditions of this Agreement.
1.7 “Health Care Operations” shall have the meaning given to such term under the HIPAA Rules, including, but not limited to, 45 CFR §164.501. (The term “Health Care Operations” is not used in this agreement, but the term is included in the definition list because it appears in the regulations referenced by this agreement.)
1.8 “HIPAA Rules” shall mean the Privacy, Security, Breach Notification, and Enforcement Rules codified at 45 CFR Part 160 and Part 164.
1.9 “Individual” shall have the meaning given to such term in 45 CFR §160.103 and shall include a person who qualifies as a personal representative in accordance with 45 CFR §164.502(g).
1.10 “Individually Identifiable Health Information” shall have the meaning given to such term under the
HIPAA Rules, including, but not limited to 45 CFR §160.103.
1.11 A “Material Attempt” means attempted unauthorized access that results in Business Associate conducting a material and full-scale investigation.
1.12 “Protected Health Information” or “PHI” means any information, whether oral or recorded in any form or medium: (i) that relates to the past, present or future physical or mental condition of an
Individual; the provision of health care to an Individual; or the past, present or future payment for
Version 07/06/23 3
Office of Administrative Services Division of Procurement and Grant Oversight the provision of health care to an Individual; and (ii) that identifies the Individual or with respect to which there is a reasonable basis to believe the information can be used to identify the Individual, and shall have the meaning given to such term in 45 CFR §160.103, limited to the information created, received, maintained or transmitted by Business Associate from or on behalf of Covered
Entity.
1.13 “Required by Law” shall have the meaning given to such phrase in 45 CFR §164.103.
1.14 “Secretary” shall mean the Secretary of the Department of Health and Human Services or his or her designee.
1.15 “Security Incident” shall have the meaning given to such phrase in 45 CFR §164.304.
1.16 “Unsecured Protected Health Information” (Unsecured PHI) shall mean protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary. (45 CFR
§164.402), except that Unsecured Protected Health Information shall be limited to the information created, received, maintained or transmitted by Business Associate from or on behalf of Covered
Entity.
SECTION II – OBLIGATIONS AND ACTIVITIES OF THE BUSINESS ASSOCIATE
The Business Associate agrees to the following:
2.1 Not to use or further disclose PHI other than as permitted or required by this Agreement and to fulfill its responsibilities under the contract setting out the scope of work for the Business Associate, or as Required by Law, or for the proper management and administration of the Business Associate under the requirements set out in Section III below;
2.2 To use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to
Electronic PHI, to not use or disclosure of PHI other than as provided for by this Agreement;
2.3 To mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by the Business Associate in violation of the requirements of this
Agreement or the HIPAA Privacy and Security Rules;
2.4 To report to the Covered Entity any use or disclosure involving PHI not provided for by this
Agreement of which it becomes aware, including breaches of Unsecured Protected Health
Information as required at 45 CFR § 164.410, and any Security Incident of which it becomes aware.
The parties acknowledge that this section does not require Business Associate to report attempted unauthorized access that results in Business Associate investigating solely for the purpose of reviewing and or noting the attempt, but rather, requires notification only when such attempted unauthorized access results in Business Associate conducting a material and full-scale investigation (“Material Attempt”). The Business Associate shall immediately report to the Covered
Entity any breach of Unsecured PHI, except as provided by 45 CFR § 164.412 based upon a request from law enforcement to delay the notice in that such would impede a criminal investigation
Version 07/06/23 4
Office of Administrative Services Division of Procurement and Grant Oversight or cause damage to national security. The Business Associate shall provide to the Covered Entity the following information: (1) a brief description of what happened; including the date of the breach and date of discovery of the breach, if known; (2) identification of each Individual whose
a. Unsecured PHI has been affected by the breach; (3) description of the type of Unsecured PHI involved in the breach; (4) any steps the Individuals should take to protect themselves from harm from the breach; and (5) steps the Business Associate is taking to investigate the breach, to mitigate harm and protect against other breaches. The Business Associate shall report immediately to the Covered Entity any Security Incident of which it becomes aware as required by 45 CFR § 164.314 (a) (2) (i) (C). The Business Associate shall report to the Covered Entity the operative facts surrounding the Security Incident, what steps are to be taken to address the
Security Incident, and other information that may be requested by the Covered Entity relative to the Security Incident.
b. The Business Associate, in consultation with the Covered Entity, shall be responsible for breach notifications to Individuals affected by the unauthorized use or disclosure no later than sixty (60) days following its discovery or by exercise of reasonable due diligence would have been known to the Business Associate, as required by 45 CFR § 164.404. The Business
Associate shall be solely responsible for any and all costs associated with the notification requirements to the Individuals as provided herein. The Business Associate shall be responsible for any penalties, assessments or fees assessed by the Office for Civil
Rights/Department of Health & Human Services due to any breach caused by the Business
Associate or based upon the failure of the Business Associate to comply with the HIPAA
Privacy and Security Rules. The Covered Entity, in consultation with the Business Associate, shall make all needed notices to the media and the Secretary of HHS.
2.5 In accordance with 45 CFR §§164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any agent, including a subcontractor, that creates, receives, maintains, or transmits PHI on behalf of the Business Associate agrees in writing to the same restrictions, conditions and requirements that apply to the Business Associate with respect to such PHI;
2.6 To provide access to PHI in a Designated Record Set, at the request of the Covered Entity, and in the time and manner designated by the Covered Entity, to the Covered Entity, or as directed by the
Covered Entity, to the Individual or the Individual’s designee as necessary to meet the Covered
Entity’s obligations under 45 CFR §164.524; provided, however, that this Section 2.6 is applicable only to the extent the Designated Record Set is maintained by the Business Associate for the
Covered Entity;
2.7 To make any amendment(s) to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 CFR §164.526 at the request of the Covered Entity or an Individual, and in the time and manner designated by the Covered Entity; provided, however, that this Section 2.7 is applicable only to the extent the Designated Record Set is maintained by the Business Associate for the Covered Entity;
2.8 To make internal practices, books and records, including policies and procedures on PHI, relating to the use and disclosure of PHI received from, or created or received by the Business Associate on behalf of, the Covered Entity available to the Covered Entity, or at the request of the Covered
Version 07/06/23 5
Office of Administrative Services Division of Procurement and Grant Oversight
Entity to the Secretary, in a time and manner designated by the Covered Entity or the Secretary, for purposes of the Secretary’s determining the Covered Entity’s and the Business Associate’s compliance with the HIPAA Rules;
2.9 To document non-routine disclosures of PHI and information related to such disclosures as would be required for the Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR §164.528, where applicable;
2.10 To provide to the Covered Entity or an Individual, in a time and manner designated by the Covered
Entity, information collected in accordance with Section 2.9 of this Agreement, to permit the
Covered Entity to respond to a request by an accounting of disclosures of PHI in accordance with
45 CFR §164.528;
2.11 That if it creates, receives, maintains, or transmits any Electronic PHI (other than enrollment/disenrollment information and Summary Health Information, which are not subject to these restrictions) on behalf of the Covered Entity, it will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information, and it will ensure that any agents
(including subcontractors) to whom it provides such Electronic PHI agrees to implement reasonable and appropriate security measures to protect the information;
2.12 Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to
Electronic Protected Health Information, to prevent the use or disclosure of Protected Health
Information other than is permitted for under this Agreement or Required by Law;
2.13 To retain records related to the PHI hereunder for a period of six (6) years unless the Agreement is terminated prior thereto. In the event of termination of this Agreement, the provisions of Section
V of this Agreement shall govern record retention, return or destruction;
2.14 Implement administrative safeguards in accordance with 45 CFR §164.308, physical safeguards in accordance with 45 CFR §164.310, technical safeguards in accordance with 45 CFR §164.312, and policies and procedures in accordance with 45 CFR §164.316;
2.15 Shall appropriately safeguard any and all PHI provided by the Covered Entity to the Business
Associate under the service contract or agreement as required under the HIPAA Rules and this
Agreement herein, as set out in 45 CFR § 164.502 (e) (1) and (2);
2.16 Not to make any fundraising communication on behalf of Covered Entity or to Covered Entity’s participants and beneficiaries;
2.17 Not to receive any remuneration, either directly or indirectly, in exchange for PHI, except as may be permitted by 45 CFR §164.502(a)(5) and §164.508(a)(4);
2.18 Not to make any marketing communication on behalf of Covered Entity or to Covered Entity’s participants and beneficiaries, except as may be permitted by 45 CFR §164.501; and
Version 07/06/23 6
Office of Administrative Services Division of Procurement and Grant Oversight
2.19 To the extent Business Associate is to carry out one or more of the Covered Entity’s obligations under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to the
Covered Entity in the performance of such obligations.
SECTION III – THE PARTIES AGREE TO THE FOLLOWING
PERMITTED USES AND DISCLOSURES BY THE BUSINESS ASSOCIATE
3.1 Business Associate agrees to make uses and disclosures and requests for PHI consistent with the
Covered Entity’s minimum necessary policies and procedures.
3.2 Except as otherwise limited in this Agreement, the Business Associate may use or disclose PHI to perform functions, activities or services for, or on behalf of, the Covered Entity as specified in the
Agreement, provided that such use or disclosure would not violate the HIPAA Rules if done by the
Covered Entity; and
3.3 Except as otherwise limited in this Agreement, the Business Associate may:
a. Use for management and administration. Use PHI for the proper management and administration by the Business Associate or to carry out the legal responsibilities of the
Business Associate; and,
b. Disclose for management and administration. Disclose PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the
Business Associate, provided that disclosures are Required by Law, or the Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and will be used or further disclosed only as Required by Law or for the purposes for which it was disclosed to the person, and the person notifies the Business
Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
SECTION IV – NOTICE OF PRIVACY PRACTICES
4.1 The Covered Entity shall (a) provide the Business Associate with the notice of privacy practices that the Covered Entity produces in accordance with 45 CFR §164.520, as well as any changes to such notice; (b) provide the Business Associate with any changes in, or revocation of, permission by an Individual to use or disclose PHI, if such changes affect the Business Associate’s permitted or required uses and disclosures; (c) notify the Business Associate of any restriction to the use or disclosure of PHI that the Covered Entity has agreed to in accordance with 45 CFR §164.522, to the extent that such restrictions may affect the Business Associate’s use or disclosure of PHI; and
(d) refrain from requesting the Business Associate use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by the Covered Entity, except as provided herein.
SECTION V – BREACH NOTIFICATION REQUIREMENTS
5.1 With respect to any Breach by the Business Associate as provided in Section 2.4 above, the
Business Associate, in consultation with the Covered Entity, shall notify each Individual whose
Version 07/06/23 7
Office of Administrative Services Division of Procurement and Grant Oversight
Unsecured Protected Health Information has been, or is reasonably believed by the Covered Entity to have been, accessed, acquired, used, or disclosed as a result of such Breach, except when law enforcement requires a delay pursuant to 45 CFR §164.412:
a. Without unreasonable delay and in no case later than sixty (60) days after discovery of a
Breach or from the time it should have reasonable been discovered.
b. By notice in plain language including and to the extent possible:
1) A brief description of what happened, including the date of the Breach and the date of the discovery of the Breach, if known;
2) A description of the types of Unsecured Protected Health Information that were accessed, acquired, used or disclosed in the Breach (such as full name, social security number, date of birth, home address, account number, diagnosis, disability code, or other types of information that were involved);
3) Any steps Individuals should take to protect themselves from potential harm resulting from the Breach;
4) A brief description of what the Covered Entity involved is doing to investigate the Breach, to mitigate harm to Individuals, and to protect against any further Breaches; and,
5) Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, web site, or postal address.
c. Use a method of notification that meets the requirements of 45 CFR §164.404(d).
d. If required by 45 CFR §164.404 (2)(i or ii) The Business Associate shall provide for substitute notice, as required by the HIPAA Rules, by providing a toll-free phone number that remains active for at least ninety (90) days where an individual can learn whether the Individual’s
Unsecured PHI may be included in the breach and a posting as required by 45 CFR § 164.404
(d) (2). The costs of the substituted notice and notifications set out in this Section shall be the responsibility of the Business Associate.
SECTION VI – TERM AND TERMINATION
6.1 Term. This Agreement shall be effective as of the Effective Date and shall terminate when all of the PHI provided by the Covered Entity to the Business Associate, or created or received by the
Business Associate on behalf of the Covered Entity, is destroyed or returned to the Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information, in accordance with the termination provisions in this Section.
6.2 Termination for Cause. Upon the Covered Entity becoming aware of a material breach of this
Agreement by the Business Associate, the Covered Entity shall provide an opportunity for the
Business Associate to cure the breach or end the violation. The Covered Entity shall terminate this
Version 07/06/23 8
Office of Administrative Services Division of Procurement and Grant Oversight
Agreement and the Service Contract if the Business Associate does not cure the breach or end the violation within the time specified by the Covered Entity, or terminate this Agreement immediately if a cure is not possible.
If the Business Associate fails to cure a breach for which cure is reasonably possible, the Covered
Entity may take action to cure the breach, including but not limited to obtaining an injunction that will prevent further improper use or disclosure of PHI. Should such action be taken, the Business
Associate agrees to indemnify the Covered Entity for any costs, including court costs and attorneys' fees, associated with curing the breach.
Upon the Business Associate becoming aware of a material breach of this Agreement by the
Covered Entity, the Business Associate shall provide an opportunity for the Covered Entity to cure the breach or end the violation. The Business Associate shall terminate this Agreement if the
Covered Entity does not cure the breach or end the violation within the time specified by the
Business Associate, or terminate this Agreement immediately if the Covered Entity has breached a material term of this Agreement if a cure is not possible.
6.3 Effect of Termination.
a. Return or Destruction of PHI. Except as provided in Section 6.3(b), upon termination of this
Business Agreement, for any reason, the Business Associate shall return, or if agreed to by the Covered Entity, destroy all PHI received from the Covered Entity, or created or received by the Business Associate on behalf of the Covered Entity. This provision shall apply to PHI that is in the possession of subcontractors or agents of the Business Associate. The Business
Associate shall retain no copies of PHI.
b. Return or Destruction of PHI Infeasible. In the event that the Business Associate determines that returning or destroying PHI is infeasible, the Business Associate shall provide to the
Covered Entity notification of the conditions that make return or destruction not feasible. Upon mutual agreement of the parties that return or destruction of the PHI is infeasible, the Business
Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as the Business Associate maintains such PHI. In addition, the Business Associate shall continue to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 to prevent use or disclosure of the PHI, for as long as the Business Associate retains the PHI.
SECTION VII – GENERAL PROVISIONS
7.1 Regulatory References. A reference in this Agreement to the HIPAA Rules or a section in the
HIPAA Rules means that Rule or Section as in effect or as amended from time to time.
7.2 Compliance with Law. In connection with its performance under this Agreement, Business
Associate shall comply with all applicable laws, including but not limited to laws protecting the privacy of personal information about Individuals.
Version 07/06/23 9
Office of Administrative Services Division of Procurement and Grant Oversight
7.3 Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for the Parties to comply with the HIPAA Rules and any other applicable law. This Agreement may not be modified, nor shall any provision herein be waived or amended, except in a writing duly signed by the authorized representatives of the Parties. A waiver with respect to one event shall not be construed as continuing, or as a bar to or waiver of any right or remedy as to subsequent events.
7.4 Confidentiality Obligations. In the course of performing under this Agreement, each Party may receive, be exposed to or acquire “Confidential Information,” including but not limited to, all information, data, reports, summaries, tables and studies, whether written or oral, fixed in hard copy or contained in a computer data base or computer readable form, as well as any information identified as “Confidential Information” of the other Party. For purposes of this Agreement
“Confidential Information” shall not apply to PHI, the privacy and security of which is the subject of this Agreement and addressed throughout the terms herein. Except as a record that requires disclosure under the Kentucky Open Records Act, the parties including their employees, agents and representatives shall: (a) not disclose to any third party “Confidential Information” of the other party except as permitted under this Agreement; (b) only permit use of “Confidential Information” of employees, agents or representatives having a need to know in connection with performance under this Agreement, and (c) advise each of its employees, agents and representatives of their obligations to keep such “Confidential Information” confidential. This provision shall not apply to
“Confidential Information”: (i) after it becomes publicly available through no fault of either party; (ii) which is later publicly released, in writing, by the party that owned the material; (iii) which is lawfully obtained by the third parties without restriction; or (iv) which can be shown to be previously known or developed by either party independently of the other party.
7.5 No Third-Party Beneficiary. The parties do not express or imply by any terms in this Agreement to confer any rights, remedies or entitlements upon any third person not a party to this Agreement herein. The parties agree that there are no third-party beneficiaries intended to be benefited by this
Agreement.
7.6 Survival. The respective rights and obligations of Business Associate under Section II and Section
6.3(b) of this Agreement shall survive the termination of this Agreement.
7.7 Interpretation. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with the HIPAA Rules.
7.8 Notices. Notices to be given hereunder to a Party shall be made via U.S. Mail or express courier to such Party’s address listed in the Service contract, and/or (other than for delivery fees) via facsimile to the facsimile telephone numbers listed in the Service Contract.
Each party named in the Service Contract may change update its address and that of its representative for notice by giving notice thereof in the manner herein provided.
7.9 Counterparts: Facsimiles. This Agreement may be executed in any number of counterparts, each of which shall be deemed an original. Facsimile copies hereof shall be deemed to be originals.
Version 07/06/23 10
Office of Administrative Services Division of Procurement and Grant Oversight
7.10 Disputes. If any controversy, dispute or claim arises between the Parties with respect to this
Agreement, the parties shall make good faith efforts to resolve such matters informally. Any dispute that cannot be mutually settled may be brought in the Franklin Circuit Court or Federal District Court of Kentucky.
7.11 Mutual Representations and Warranties. Each party represents and warrants to the other party that is duly organized and validly existing, and in good standing under the laws of the jurisdiction under which it is organized or licensed, it has the full power to enter into this Agreement and to perform the obligations hereunder, and that the performance of it of its obligations under this
Agreement have been duly authorized by all necessary corporate or other actions and will not violate any provisions of any license, corporate charter, or bylaws.
In Witness wherefore, the Parties acknowledge agreement with the terms herein and have duly executed this Agreement as of the Effective Date, and set their signatures below.
Covered Entity Business Associate
By:_______________________________ By:_________________________________
Title:______________________________ Title:________________________________
Date:______________________________ Date:________________________________
File details come from the government source that posted it. Updated .