Exhibit 10_WV PEIA MASTER SERVICE AGREEMENT DRAFT_REV MAR2025.pdf

PDF 188 KB Posted

Attached to
PHARMACY BENEFITS MANAGEMENT State and local contract opportunity
Solicitation number
ARFP-0225-PEI2500000002-2
Issued by
Kanawha County, West Virginia

About this file

This document is a Master Service Agreement draft between the West Virginia Public Employees Insurance Agency (PEIA) and an unspecified vendor for health insurance and related services. The agreement establishes a one-year contract term with provisions for data management, security, and compliance with various federal and state regulations including HIPAA, HITECH, and GINA. The vendor will provide services to PEIA's member population, with PEIA reserving the right to seek competitive bids and potentially terminate the agreement with 30 days' notice.

The agreement includes comprehensive requirements for data security, including mandates for physical and electronic access controls, information security programs, access management, logging and monitoring, anti-virus protection, and security patching. The vendor is responsible for all compliance-related expenses and must maintain insurance coverage of at least $1,000,000 per occurrence/$2,000,000 aggregate, including data breach/cyber liability insurance. The vendor must also provide detailed incident response procedures, conduct annual security assessments, and ensure that all PEIA data is stored and accessed exclusively within the forty-eight contiguous United States.

View the file

Other files for this state and local contract opportunity

Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

WEST VIRGINIA PUBLIC EMPLOYEES INSURANCE AGENCY

MASTER SERVICE AGREEMENT

This document shall serve as the Master Level Service Agreement between the West Virginia Public Employees Insurance Agency (PEIA) and ___________________________________, hereafter referred to as the “Vendor”, for the provision of services in whole or in part to and for PEIA’s member population. PEIA and the Vendor, hereafter referred to as the “Parties” hereby agree to the following:

RECITALS

WHEREAS, PEIA provides health insurance benefits to statutorily eligible employer groups and their covered person(s) in the State of West Virginia under West Virginia Code §5-16-1 et. seq., hereinafter referred to collectively as "the Plan(s)."

WHEREAS, PEIA is a Covered Entity as defined by 45 CFR §160.103 of The Health Insurance Portability and Accountability Act of 1996 (HIPAA) (PUBLIC LAW 104-191).

WHEREAS, the PEIA Director is charged with identifying and implementing programs designed to promote the health and well-being of Plan covered members and dependents, and is permitted to contract for such services or programs that provide services to beneficiaries, are appropriate in care, and will be provided at an efficient cost.

WHEREAS, Vendor is a properly licensed, registered, insured, and competent service provider performing the programs and services outlined in this Agreement.

WHEREAS, the Vendor is performing an administrative and/or service level function on behalf of the Covered Entity as it relates to the treatment and healthcare operations of the Covered Entity.

WHEREAS, Vendor desires to accept the terms and conditions herein, as it relates to services performed and payment for services rendered to beneficiaries of the Plan.

NOW, THEREFORE, in consideration of these Recitals and the mutual promises contained herein below, the Parties agree as follows:

Definitions

1. Agreement. This Agreement between PEIA and the Vendor, and any amendments thereof made in accordance with this Agreement, including any response(s) to any Request(s) for Proposal(s) (RFPs) where language is incorporated by reference.

2. Breach. As defined in 45 CFR §164.402, a HIPAA breach means the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information.

3. Business Associate. Any entity as defined by 45 CFR Parts 164.502(e), 164.504(e), 164.532(d) and (e) who performs a service on behalf of a Covered Entity.

4. Business Associate Agreement. The State of West Virginia Executive Branch Business Associate Agreement which is hereby incorporated by reference as part of this Agreement.

5. Covered Person. Any individual person eligible for benefits under the Plan.

6. NIST. National Institute of Standards and Technology.

7. PEIA. The West Virginia Public Employees Insurance Agency, an agency of and for the State of West Virginia under the Department of Administration.

8. PHI. Protected Heath Information as defined by HIPAA.

9. PII. Personally Identifiable Information.

10. RFP. Request for Proposal whose terms and conditions are hereby incorporated by reference into this Agreement.

11. Vendor. The party, entity, and/or agent(s) being contracted with and/or being paid by PEIA for the product(s) and/or service(s) outlined in the Scope of Work section of the RFP that they responded to and/or the terms and conditions of this Agreement including, but not limited to: any employee(s) and/or agent(s) of the Vendor; any and/or all subcontractors and/or subcontractors of subcontractors of the Vendor; any and/or all collaborator(s) with and/or of the Vendor; or any other third party not a direct signature party to this Agreement who may be involved in the performance of the Scope of Work on this Agreement. If any conflict or inconsistency arises between the language of this Agreement and any Statement of Work, the RFP response and the terms of this Agreement shall control.

General Terms and Conditions

1. This Agreement shall be governed by the laws of the State of West Virginia regardless of the sites or locations of the Vendor and its contractors or subcontractors.

2. Vendor is in good standing under the laws, rules, and/or regulations of the State of West Virginia, and is duly licensed, registered, authorized and empowered to do business in the State of West Virginia as contemplated by this Agreement, including, but not limited to, the West Virginia Secretary of State’s Office, the West Virginia Tax Department, the West Virginia Insurance Commission, or any other state agency or political subdivision, as applicable. Vendor shall maintain such authorization at its own cost. Vendor's failure to maintain such authorization shall be sufficient cause for termination of this Agreement. Vendor shall maintain active Purchasing registration with the State of West Virginia through the Vendor Self Service portal available and viewable at https://prd311.wvoasis.gov/PRDVSS1X1/Advantage4. Upon request, the https://prd311.wvoasis.gov/PRDVSS1X1/Advantage4

Vendor must provide all necessary releases to obtain information to enable the Agency to verify that the Vendor is licensed and in good standing with any applicable entities.

3. The Vendor agrees and understands that it is a contractor to PEIA and that no employer/employee relationship is created, either expressed or implied, by this Agreement.

4. The terms and conditions of the RFP response by the vendor are hereby incorporated by reference into this Master Services Agreement. PEIA may, at its own discretion, engage in a solicitation to seek competitive bids for the product(s) and/or service(s) being provided under this Agreement.

5. If this is a “proof of concept” Agreement whereby the Vendor, through its products and/or services, is responsible for demonstrating the improved standards of care, clinical efficacy, cost savings, and/or other benefits to the Plan and covered persons.

The Vendor recognizes and acknowledges that PEIA reserves the right to go out to bid or otherwise seek to procure the same or similar services from other vendors.

6. The term of this Agreement shall be one (1) year commencing on the effective date, which shall be the last date upon which the Parties executed this Agreement.

7. Either party may terminate this Agreement, without cause, by giving thirty (30) days written notice to the other party.

8. This Agreement may be terminated upon thirty (30) days written notice by either party for any material breach by the other party. For purposes of this Agreement, the term "breach" shall mean and be specifically limited to the failure by either party to keep, observe or perform any covenant, agreement, term, covenant, or provision of this Agreement kept, observed or performed by such party, and the continuance of such breach for a period of thirty (30) days after notice thereof from the non-breaching party to the breaching party.

9. Except as otherwise provided herein, amendments, extensions or renewals of this Agreement shall be made in writing and executed by both Parties.

10. The waiver by either party of any breach or violation of any provision of this Agreement shall not operate as, or be construed to be, a waiver of any subsequent breach of the same or other provision hereof.

11. The following documents and their respective terms and conditions are hereby incorporated by reference into this Agreement:

a. State of West Virginia WV-96 Purchasing Agreement Addendum

b. State of West Virginia Purchasing Affidavit

c. State of West Virginia Executive Branch Business Associate Agreement and corresponding Appendix A

d. State of West Virginia Data Exchange – Data Management Addendum

The language of these documents shall supersede all terms and conditions to the contrary, either expressed or implied, in this Agreement.

12. The Vendor may not reassign the terms and conditions of this Agreement to any third party nor reassign its liability, roles and responsibilities for the performance of the Scope of Work of this Agreement to any third party without the express written permission of PEIA.

13. The pricing set forth in the Scope of Work herein is firm for the life of the Agreement, unless specified elsewhere within this Agreement.

14. Payment in advance is prohibited under this Agreement. Payment may only be made after services have been rendered. The Vendor shall submit invoices in arrears.

15. The Vendor shall pay any applicable sales, use, personal property or any other taxes arising out of this Agreement and the transactions contemplated thereby. PEIA is exempt from federal and state taxes and will not pay or reimburse such taxes.

16. Vendor agrees and understands that it is their responsibility to provide the product(s) and/or service(s) in the timeframe(s) and/or schedule for deliverables outlined in the then-current Scope of Work between the Parties. Failure to adhere to defined timelines and/or deliverable schedule(s) shall be grounds for termination of this Agreement.

Confidentiality

The Parties shall maintain this Agreement and the compensation arrangements agreed to herein in the strictest confidence and shall not disclose them to any person except as required by law and to further the purposes of this Agreement. Notwithstanding the foregoing, this Agreement may be subject to release or disclosure under applicable provisions of the West Virginia Freedom of Information Act (“FOIA”) under West Virginia Code §29B-1-1, et. seq. should such a request be filed with PEIA. PEIA shall promptly notify Vendor of any FOIA request relating to this Agreement. It shall be the sole responsibility of the Vendor to defend against any release of information it deems to be confidential, proprietary, and/or a trade secret and/or otherwise protected from further disclosure under the applicable provisions of West Virginia Code §29B-1- 1, et. seq.

Work Product – Ownership of Data

For all services provided by the Vendor, the concept of work product shall apply. Such concept shall mean and intend that all data provided, shared, gathered, garnered or obtained, and the results of all work performed with said data, shall be the sole property of PEIA with no rights of ownership, expressed or implied, conveyed to the Vendor. PEIA data may not be used, either in identified or de-identified format, for any purpose other than for the performance of the scope of work outlined in this Agreement.

Data Exchange

For purposes of the Scope of Work on this Agreement, only the minimum necessary Covered Persons’ data will be disclosed to the Vendor for the meaningful use of performing the tasks, duties, or services outlined in this Agreement. The data may be provided in an identified or de-identified format, depending on the services outlined in the then-current Scope of Work between the Parties. PEIA reserves the right to limit the data elements in keeping with accepted minimum necessary guidance. PEIA shall transmit the data to the Vendor in a secure and encrypted format in compliance with all applicable provisions of the HIPAA Security Rules.

Compliance

A. Vendor agrees to be compliant with all any and/or all applicable provisions of the following:

1. The Genetic Information Non-discrimination Act of 2008 (GINA) - (Pub.L. 110– 233, 122 Stat. 881, enacted May 21, 2008

2. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) (PUBLIC LAW 104-191) including both the Privacy and Security Rule(s) of

HIPAA

3. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as part of the American Recovery and Reinvestment Act of 2009

4. The Privacy Act of 1974, as amended, 5 U.S.C. § 552a

5. NIST Guidance referenced in and as applicable to compliance with the above referenced law, e.g. NIST SP 800-53; NIST SP 800-66; NIST 800-88

B. Further, Vendor agrees to full compliance with the State of West Virginia Executive Branch Business Associate Agreement (WV BAA) and corresponding Appendix A as incorporated by reference into this Agreement. Vendor shall be responsible for ensuring that all subcontractors performing any of the scope of work related to this Agreement are informed of the terms and conditions of the WV BAA and agree to compliance thereto.

Subcontractors

The Vendor agrees to provide PEIA with the names of any and/or all subcontractors and/or collaborators who may perform any portion of the Scope of Work on this Agreement and/or who may have access to PEIA member PII/PHI. Further, the Vendor agrees to accept responsibility and liability for the actions, errors, and performance of any subcontractors who perform any portion of the scope of work on this Agreement. The Vendor shall be responsible for ensuring that any and/or all subcontractors and/or collaborators have been made aware of and are in compliance with the terms and conditions of this Agreement and the documents incorporated by reference into this Agreement.

Insurance

Vendor shall procure and maintain, at its sole cost and expense, policies of comprehensive general liability and other insurance in the minimum amounts of $1,000,000 per occurrence/$2,000,000 aggregate to insure such party and its officers, agents, and employees against liability, claims or damages in connection with the performance its responsibilities under this Agreement, and shall provide copies of such policies to PEIA. Said insurance shall include, at a minimum, coverage of $1,000,000 per occurrence/$2,000,000 aggregate, data breach/cyber breach liability insurance naming PEIA as a co-insured on said policy as it relates to the scope of work on this Agreement.

Legal Defense

PEIA shall have no obligation to defend the Vendor, or any subcontractors of the Vendor, in any legal action instituted on a claim of malpractice relating to Vendor services provided through this Agreement.

Data Disposition

Within sixty (60) days of the termination of this Agreement the Vendor shall provide to PEIA a detailed data disposition plan compliant with the applicable provisions of the HIPAA Security Rules that renders any and all PEIA data received, created, transmitted, stored, or otherwise maintained by Vendor unreadable, indecipherable, and/or otherwise unusable. This term and condition would also apply to any data held or stored by any subcontractor(s) and/or collaborators.

Such plan shall outline the means and modes of data disposition and the means and modes of verifying or validating the proper disposition of the data.

Data Security Requirements

Vendor shall implement reasonable administrative, physical, and technical safeguards and/or restrictions regarding physical and electronic access to PEIA data, including but not limited to the following

I. Vendor Information Security Program

a. Physical access controls, secure user authentication protocols, secure access control methods, firewall protection, malware protection, and use of encryption for laptops, mobile devices and PEIA Data being transmitted across the public Internet or wirelessly, and as otherwise required by applicable law.

b. To the extent it does not already employ one, Vendor shall develop and maintain a reasonable and appropriate written data security policy that includes technological, physical, administrative and procedural controls to protect the confidentiality, integrity and availability of PEIA Data that encompasses access, retention and transport of PEIA Data, and that provides for disciplinary action in the event of its violation;

c. Vendor shall prevent terminated employees from accessing PEIA Data by immediately terminating their physical and electronic access to such PEIA Data;

d. Vendor shall employ assessment, monitoring and auditing procedures to ensure internal compliance with these safeguards;

e. Vendor shall conduct a complete assessment of these safeguards at least annually and, upon written request, provide a report on the results of the assessment, including but not limited to any discrepancies, to PEIA.

f. Vendor must have system hardening standards such that default configurations and deployments are appropriately modified to protect PEIA data.

II. Access Management and Authentication

a. The addition, deletion, and modification of user access must be formally defined processes, restricted to appropriate personnel, and must generate and retain an audit trail of applied changes.

b. Vendor must remove access for any terminated employees and any third party that no longer require access.

c. Vendor must employ least privilege user access.

d. User identity must be verified before performing any password reset.

e. Vendor must employ enhanced protections for privileged administration accounts

f. Industry best practices and security controls must be used throughout any Single Sign

On and federated identity connections.

g. Passwords, including temporary passwords, must be systematically required to be strong and complex.

h. Passwords must be restricted from reuse.

i. Login and password change mechanisms must be protected against attack including account lockouts, throttling, activity logging and alerting or other effective protections.

j. Passwords should be stored using a strong password hashing function.

k. Vendor users with remote access to PEIA Data are required to use two-factor authentication.

III. Data Management

a. Vendor shall store PEIA Data in a manner allowing its identification, access, and destruction without inadvertently affecting or including another customer’s data.

b. At termination of the Agreement, Vendor must provide a certificate of destruction of

PEIA data.

c. No PEIA owned data shall be stored, used, transmitted, and/or otherwise accessed from any location outside the United States.

IV. Logging and Monitoring

a. Event logging must be in place for network, system, and application access. Logging must also be in place for access to secured physical location.

b. Logging should collect sufficient information to monitor an event including event type, timestamp, user origin, destination resource, and activity

c. Logs must be retained for a minimum of two hundred seventy (270) days and must be backed up in case of accidental deletion or corruption

d. Access to logs must be restricted to select administrators who have a business need to access.

V. Anti-virus Protection

a. Anti-malware software standards such that any equipment that transmits, receives, stores or processes PEIA Data has current anti-virus software and signatures installed

VI. Security Patching Management

a. Patch management standards must be in place to ensure that all infrastructure devices, operating systems and software are updated regularly, and updates are expedited when deemed critical. All new systems and devices must be configured with current security updates/patches and hardened before being put into production.

VII. Application Development

a. Industry best practices and security controls must be used throughout the software development life cycle (SDLC) for any development necessary to work with PEIA Data.

Vendor must have a formal and documented SDLC policy that outlines release/development methodology as well as appropriate segregation of duties.

b. The SDLC must consider sufficient security testing of code at the unit, integrated, and production phases.

c. Vendor must maintain a formal change management process that includes segregation of duties between roles implementing and approving changes.

d. For internally developed applications (including web or mobile applications), there must be processes in place to control, monitor, and log developers' access and changes to the production environment.

e. Vendor must not use software with known high-risk vulnerabilities in any Vendor applications or services. All software components used in the application must be versions currently supported by the respective software vendors.

f. There should be separate development, test, and production environments.

g. Applications are to be scanned for vulnerabilities using effective tools or competent third parties.

h. Production data is not to be used for development, sales, marketing, and/or any other purposes not specifically outlined in this Agreement.

Physical Security

a. Physical security standards shall be in place to protect information from unauthorized physical and electronic access. Physical security standards, at a minimum, should be in accordance with relevant NIST Guidance found in and as applicable to compliance with the above referenced law, e.g. NIST SP 800-53; NIST SP 800-66; NIST 800-88

b. Vendor shall be able to provide upon request documentation of its administrative, procedural, and technical safeguards designed and intended to meet the Physical

Security requirements of the HIPAA Security Rule(s).

c. Under no circumstance is any PEIA and/or State data, either in identified or a deidentified format(s), allowed to be transmitted, stored, used, viewed, and/or otherwise accessed outside of the forty-eight (48) contiguous states of the United

States.

Personnel Security

Background verification checks on all candidates for employment shall be carried out in accordance with relevant laws, regulations, and ethics and should be proportional to the business requirements, the classification of the information to be accessed, and the perceived risks.

Business Continuity

Vendor must have Business Continuation, Disaster Recovery, and Data Restoration plans in place that are updated and tested on at least an annual basis.

Security Training

Vendor must have a program in place to ensure employees and subcontractors are periodically trained on information security principles and failure to comply will be addressed through appropriate discipline imposed by Vendor or its subcontractors, as applicable.

Security Incident Response Procedures.

If Vendor (or Vendor’s personnel, including contractors and/or subcontractors) discovers or suspects that an unauthorized access, use, copying, alteration, transfer, or other violation, compromise, breach or attempted breach of security (electronic or physical) involving or related to PEIA Data within its (or its personnel’s) possession or control has occurred, whether the incident originates within Vendor’s organization or externally (“Security Incident”), Vendor shall:

(a) immediately conduct a reasonable investigation of the reasons for and circumstances surrounding such Security Incident or reasonably suspected Security Incident;

(b) use best efforts and take all necessary actions to prevent, contain, and mitigate the impact of such Security Incident or reasonably suspected Security Incident;

(c) provide notice to PEIA at PEIAPrivacy@wv.gov within twelve (12) hours after the Vendor discovers or reasonably suspects a Security Incident;

(d) promptly, and in no event more than two (2) business days after the date Vendor discovers or reasonably suspects a Security Incident, provide a written report to PEIA concerning such Security Incident or reasonably suspected Security Incident;

(e) collect and preserve all evidence concerning the discovery, cause, vulnerability, remedial actions, and impact related to such Security Incident or reasonably suspected a Security Incident, which shall meet reasonable expectations of forensic admissibility;

(f) document the incident response and remedial actions taken in detail, which shall meet reasonable expectations of forensic admissibility;

(g) retain a qualified contractor to conduct a security assessment to determine whether Vendor was compliant with Applicable Law at the time of the Security Incident; and

(i) if requested by PEIA, provide notice to individuals or entities whose PEIA Data was or may have been affected, in a manner and format specified by PEIA.

(ii) Security Incident Status Reports. If PEIA is notified of any Security Incident or reasonably suspected Security Incident, or otherwise discovers or suspects that Vendor has suffered a Security Incident, upon PEIA’s request Vendor shall provide PEIA with:

(a) a written status report concerning such Security Incident or reasonably suspected Security Incident; and

(b) any documents requested by PEIA related to such Security Incident or reasonably suspected Security Incident, including without limitation, any security assessment and security control audit reports, logs, and any forensic analysis of such Security Incident or reasonably suspected Security Incident.

mailto:PEIAPrivacy@wv.gov

(iii) Security Incident Information. In addition to any other information requested by PEIA, such written report as required in Section (x) shall include the following:

(a) the amount or number of records and type of PEIA Data reasonably suspected as having been accessed, compromised or misused;

(b) a list identifying the individuals or entities whose PEIA Data is at issue, including with respect to individuals, the name, address, phone number, and e-mail address of such individuals;

(c) a description of any wrongdoing or harm caused by the actual or reasonably suspected Security Incident, including without limitation, identity theft;

(d) a description of the Security Incident or reasonably suspected Security Incident, including without limitation, the findings of Vendor’s investigation, the cause and timeframe of such Security Incident, the source of such Security Incident, and the vulnerability that led to the Security Incident;

(e) the remedial actions taken to date by Vendor and the results of such remedial actions;

and

(f) the remedial actions planned by Vendor going forward and the timeframe for completing such remedial actions.

(iv) Preservation, Return, and Destruction of Documents. Vendor shall preserve information in accordance with PEIA’s instructions and requests, including without limitation any retention schedules and litigation hold instructions provided by PEIA to Vendor, independent of where the information is stored (specifically, and without limitation, even where such information resides with or is held, processed or stored by a sub-contractor, vendor, or other third party). Vendor shall take reasonable steps to ensure proper destruction (such that information is rendered unusable and unreadable) and return of information to PEIA in a format requested by PEIA and at Vendor’s expense when it is no longer needed to perform services pursuant to the Agreement or thirty (30) days following termination of the Agreement.

Vendor shall provide written certification that all such information has been returned and deleted.

(v) Control and Access. Vendor shall cooperate with PEIA in responding to any party, non-party, or government request for information. In the event that such requests are served on PEIA, Vendor shall provide PEIA with access to such information in the format in which it is maintained in the ordinary course of business (or, on PEIA’s request, with copies) within twelve (12) hours of receipt of any request by PEIA for such access or copies. In the event that such a request (in the form of a subpoena, order or otherwise) is provided to or served on Vendor, Vendor shall notify PEIA in writing by electronic mail to PEIAPrivacy@wv.gov immediately and in no event more than twenty-four (24) hours after receiving the request, subpoena, or order. Such notification must include a copy of the request, subpoena, or court order. Vendor also shall immediately inform in writing the third party who caused the request, subpoena, or order to issue or be provided or served on Vendor that some or all the material covered by the request, subpoena, or order is the subject of a nondisclosure agreement.

Vendor shall cooperate with PEIA in seeking any protection from disclosure for such information that PEIA shall deem appropriate.

(vi) Document Authentication. In the event that PEIA is required to authenticate any document or information, Vendor shall cooperate with PEIA in providing any requested assistance with such authentication, including without limitation testifying (by affidavit, declaration, deposition, in court, or otherwise) as a custodian of records to authenticate the mailto:PEIAPrivacy@wv.gov information, establish chain of custody, and provide any other requested information or assistance.

(vii) Indemnification.

(a) In addition to any indemnification obligations contained in other parts of the Agreement, Vendor agrees to indemnify, defend, and hold harmless PEIA and its affiliates, subsidiaries, successors, and assigns (and the officers, directors, employees, sublicensees, clients, and agents of PEIA, and its affiliates, subsidiaries, successors, and assigns) from and against any and all claims, losses, demands, liabilities, damages, settlements, expenses, and costs (including without limitation attorneys’ fees and costs), and any and all threatened claims, losses, demands, liabilities, damages, settlements, expenses, and costs alleged, sustained or incurred by a third party, arising from, in connection with, or based on allegations of, any Security Incident or reasonably suspected Security Incident, any breach of the Data Security Requirements of this Agreement by Vendor, any failure of Vendor to comply with Applicable Law, including without limitation:

i. expenses incurred to provide warning or notice to PEIA’s clients and employees, law-enforcement agencies, regulatory bodies, or other third parties;

ii. expenses incurred to investigate, assess, or remediate a Security Incident, reasonably suspected Security Incident, or failure to comply with any Applicable Law;

iii. expenses incurred to hire any public relations consultants to respond to a Security Incident or reasonably suspected Security Incident;

iv. expenses incurred to provide credit monitoring services to individuals affected by a Security Incident or reasonably suspected Security Incident;

v. expenses incurred to retain a call center to respond to inquiries regarding a Security Incident or reasonably suspected Security Incident;

vi. fines, penalties, or recovery amounts; and

vii. expenses incurred to respond or address any investigation by law-enforcement agencies, regulatory bodies, or other third parties.

(b) PEIA shall notify Vendor promptly of any claims or demands made by a third party against, or losses, demands, liabilities, damages, settlements, expenses, and costs incurred by, PEIA for which indemnification is sought; provided, however, that the failure to give such notice shall not relieve Vendor of its obligations under this Agreement except to the extent that Vendor was actually and materially prejudiced by such failure. PEIA may, at its option and expense, participate and appear on an equal footing with Vendor in the defense of any claim that is conducted by Vendor as set forth in in this Agreement. Vendor may not settle any claim without the prior written approval of PEIA. From the date of written notice from PEIA to Vendor of any such claim, PEIA shall have the right to withhold from any payments due Vendor under this Agreement the amount of any defense costs, plus additional reasonable amounts as security for Vendor’s obligations under the Insurance Section of this Agreement.

(viii) Cooperation and Coordination. Vendor agrees to reasonably cooperate and coordinate with PEIA concerning:

(a) PEIA’s investigation, enforcement, monitoring, document preparation, notification requirements, and reporting concerning Security Incidents, reasonably suspected Security Incidents, and Vendor’s and PEIA’s compliance with applicable law; and

(b) any other activities or duties set forth under this Agreement for which cooperation between PEIA and Vendor may be reasonably required.

(c) Any investigation and/or inquiry by an authority having jurisdiction in matters related to the enforcement of any state and/or federal privacy and/or security law(s), rule(s) and/or regulation(s), e.g. the U.S. D.H.H.S. Office of Civil Rights and/or the State of West Virginia Executive Branch Privacy Office.

(ix) Vendor’s Expense. Vendor’s compliance with Data Security Compliance Section of this Agreement and any actions required of Vendor by the Data Security Compliance Section of the Agreement shall be at Vendor’s sole and exclusive expense and shall be included as part of the price of the services provided by Vendor for no additional fee, including without limitation, any PEIA requests authorized by Section (x) of the Agreement.

(x) Vendor Assurances. Nothing in this Agreement shall prohibit PEIA from performing or conducting additional vendor assurance reviews and/or audits designed and intended to ensure vendor compliance with applicable provisions of the HIPAA Security Rule(s).

Force Majeure

Neither party shall be liable or deemed to be in default for any delay or failure to perform under this Agreement which results, directly or indirectly, from acts of God, civil or military authority, acts of public enemy, war, accidents, fires, explosions, earthquake, flood, failure of transportation, strikes, pandemics or other work interruptions by either party's employees or any other cause beyond the reasonable control of either party.

Notice

Any notice, demand or communication which are, or may be, required, permitted, or desired by any party given to the other in connection with this Agreement, shall be in writing and shall be deemed to have been properly given when delivered personally or when sent by certified mail, return receipt requested, addressed as follows:

If to PEIA: Jason A. Haught, Acting Director, CFO West Virginia Public Employees Insurance Agency 601 57th Street, SE Charleston, West Virginia 25304 jason.a.haught@wv.gov

Cc: william.b.hicks@wv.gov

If to Vendor: ______________________________ or to such other address, and to the attention of such other person or officer as the receiving party may designate, with copies thereof to the respective counsel thereof as designated by such party.

mailto:jason.a.haught@wv.gov mailto:william.b.hicks@wv.gov

Agreement

This Agreement and any attachments, addenda or exhibits, including the State of West Virginia WV-96 Agreement Addendum which are incorporated herein by reference, constitute the entire agreement between the Parties relating to the subject matter of this Agreement. No party shall be entitled to benefits other than those specified herein. Together they supersede all previous contracts and all prior representations or agreements between the Parties, whether written or oral, pertaining to the subject matter of this Agreement. No changes in or additions to this Agreement shall be of any effect unless and until made in writing and signed by both Parties.

Rosters

Vendor agrees that PEIA, the State of West Virginia, or its designees may use Vendor's name, address, and other information in rosters of participating providers and marketing materials.

Scope of Work

The Vendor agrees and understands that PEIA shall not be responsible for any cost(s), fee(s), charge(s), and/or other liabilities not expressly defined in the Scope of Work between the Parties. Terms such as, “plus expenses”, “plus travel”, and/or any other non-fixed and/or undetermined shall be non-applicable to this Agreement.

For issues with regard to payment for product(s) and/or service(s), please refer to the State of West Virginia WV-96 Form incorporated by reference into this Agreement.

IN WITNESS WHEREOF, the Parties have caused this Agreement to be executed in multiple originals by their duly authorized officers.

Vendor PEIA

By: _____________________________ By:________________________________

Its:_____________________________ Its:________________________________

Date:___________________________ Date:______________________________

File details come from the government source that posted it. Updated .