Exhibit_E_-_Business_Associate_Agreement_DRAFT_25-P-147JRD.pdf
PDF 397 KB Posted
- Attached to
- Jail Management System (JMS) State and local contract opportunity
- Solicitation number
- 25-P-147JRD
- Issued by
- Volusia County, Florida
About this file
This document is a Business Associate Agreement (BAA) drafted between the County of Volusia, Florida (the Covered Entity) and an unnamed Contractor (the Business Associate) to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA), the HITECH Act, and related regulations. The agreement establishes the terms and conditions for handling Protected Health Information (PHI), with a commencement date of July 2017. The primary purpose is to define the responsibilities of the Business Associate in safeguarding PHI, including implementing appropriate administrative, physical, and technical safeguards, reporting any security incidents or breaches, and ensuring that any subcontractors or agents adhere to the same privacy and security standards.
The agreement outlines detailed obligations for the Business Associate, including providing evidence of information security assessments, maintaining written policies and procedures related to PHI security, and taking specific actions in the event of a breach. Key provisions include the requirement to report any unauthorized use or disclosure of PHI within 10 calendar days, mitigate potential harmful effects of such disclosures, and indemnify the Covered Entity for any costs incurred as a result of a breach. The document includes an exhibit (Exhibit 1) that provides a template for notifying the Covered Entity of any breach of unsecured PHI, ensuring a standardized approach to reporting and managing potential privacy incidents.
View the file
Other files for this state and local contract opportunity
Show all 50
Jail Management System (JMS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Exhibit E 25-P-147JRD
BUSINESS ASSOCIATE AGREEMENT - DRAFT
This BUSINESS ASSOCIATE AGREEMENT (the “Agreement”), is entered by and between Name of Contractor (“Business Associate”), with the address of Contractor’s address, and the County of Volusia (“Covered Entity”), a Florida political subdivision with the address of 123 West Indiana Avenue, DeLand, Florida 32720 (collectively referred to as “Parties”), for the purpose of enter the service to be performed.
WITNESSETH
WHEREAS, Covered Entity is a health care provider and a “covered entity” as defined in the Health Insurance Portability and Accountability Act of 1996 and related regulations, as amended from time to time (“HIPAA”); and
WHEREAS, Business Associate is a “business associate” as defined in HIPAA; and
WHEREAS, Covered Entity wishes to commence or continue a business relationship with Business Associate that shall be/has been memorialized in a separate agreement (the “Underlying Agreement”), and the nature of the Underlying Agreement may involve the exchange of Protected Health Information (“PHI”) as that term is defined in HIPAA; and
WHEREAS, the HIPAA Privacy Standards, as amended from time to time (the “Privacy Rule”), require Covered Entity to obtain and document satisfactory assurances from the Business Associate that the Business Associate shall appropriately safeguard PHI through a written contract; and
WHEREAS, the HIPAA Security Standards, as amended from time to time (the “Security Rule”), govern the security of PHI obtained, created or maintained electronically by covered entities and business associates as defined in HIPAA; and
WHEREAS, the Health Information Technology for Economic and Clinical Health (“HITECH”) Act, found in Titles XIII and XIV of the American Recovery and Reinvestment Act of 2009, modifies certain provisions of HIPAA relating to the privacy and security of PHI; and
WHEREAS, the parties acknowledge that, in the event of a violation of HIPAA or the HITECH Act by Business Associate, Business Associate may be subject to the same civil and criminal penalties as Covered Entity would be for such violation by Covered Entity; and
WHEREAS, the parties desire to enter into this Agreement for the purpose of ensuring compliance with the requirements of HIPAA, it’s implementing regulations, the HITECH Act and Florida law.
NOW THEREFORE, in consideration of their mutual promises made herein, and the foregoing recitals which are material to this Agreement and incorporated hereby together with other good and valuable consideration, receipt of which is hereby acknowledged by each party, the Parties, intending to be legally bound, herein agree as follows:
1. Definitions for Use in This Agreement. Capitalized terms and acronyms used but not otherwise defined in this Agreement shall have the same meaning ascribed to those terms in HIPAA, the HITECH Act, and any current and future regulations promulgated under HIPAA or the HITECH Act.
2. Obligations and Activities of Business Associate. Upon request by Covered Entity, Business Associate shall provide to Covered Entity evidence of the performance of an information security assessment as required by the HIPAA Security Rule, which evidence shall be satisfactory to Covered Entity.
a. Upon request by Covered Entity, Business Associate shall provide to Covered Entity a copy of its written policies and procedures relating to the security of PHI and the name of the person responsible for implementing the HIPAA Security Rule and this Agreement on
Exhibit E behalf of Business Associate.
b. Except as otherwise limited in this Agreement, Business Associate may use or disclose PHI to perform functions, activities or services for, or on behalf of, Covered Entity as specified in the Underlying Agreement provided that such use or disclosure would not violate the Privacy Rule. Business Associate agrees to not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law, as that term is defined in HIPAA, the HITECH Act and/or applicable regulations.
c. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement.
d. Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of PHI that it creates, receives, maintains or transmits on behalf of the Covered Entity.
e. Business Associate agrees to mitigate, to the extent practicable, any harmful effect known to Business Associate of its use or disclosure of PHI in violation of the requirements of this Agreement and/or the Privacy Rule.
f. Business Associate agrees to report in writing to Covered Entity any use or disclosure of PHI not provided for by this Agreement within ten (10) calendar days after becoming aware of such use or disclosure.
g. Business Associate shall report to Covered Entity within ten (10) calendar days after becoming aware of any “security incident,” as that term is defined in the HIPAA Security Rule. In its report to Covered Entity, the Business Associate shall identify: the date of the security incident, the scope of the security incident, the Business Associate’s response to the security incident and the identification of the party responsible for causing the security incident, if known.
h. Business Associate shall report in writing to Covered Entity any breach involving PHI, as the term “breach” is defined in the HITECH Act, by completing the Breach Notification form attached hereto as Exhibit “1” and by reference made a part hereof. Business Associate shall provide said notification to Covered Entity of any such breach within 10 calendar days after such breach.
i. Business Associate shall indemnify, hold harmless, and reimburse Covered Entity for any costs incurred by the Covered Entity as a result of a “breach,” as defined in the HITECH Act, by Business Associate, including but not limited to the cost of notification to individuals made by Covered Entity pursuant to 45 C.F.R. § 164.404 and the cost of remedial actions taken to protect individuals whose information was disclosed in violation of this Agreement HIPAA, the HITECH Act, or the regulations promulgated thereunder. Business Associate further agrees to defend, indemnify, and hold harmless Covered Entity, its officers, directors, employees, and agents, from and against all claims, liabilities, suits, judgments, fines, assessments, penalties, damages, costs, and other expenses of any kind or nature whatsoever, including without limitation, attorney’s fees, expert witness fees, and costs of investigation, litigation or dispute resolution, related in any manner to or arising out of any material breach of this Agreement by Business Associate, its agents, representatives, officers, directors, employees, or subcontractors. These indemnities shall continue in full force and effect subsequent to and notwithstanding the expiration or termination of the Agreement.
j. Business Associate agrees to ensure that any agent, including a subcontractor, to whom it provides PHI received from, created by, or received by Business Associate on behalf of Covered Entity agrees to the same restrictions and conditions that apply through this
25-P-147JRD
Agreement to Business Associate with respect to such information.
k. Within ten (10) business days after a written request from Covered Entity, Business Associate agrees to provide access to PHI in a Designated Record Set (“DRS”), as that term is defined in HIPAA, to Covered Entity or, as directed by Covered Entity, to an Individual, as that term is defined in HIPAA, in order to meet the requirements under 45 CFR §164.524. In the event any Individual requests access to PHI directly from Business Associate, Business Associate shall forward written notice of such request to Covered Entity within ten business (10) days after such request. Any denials of access to the PHI requested shall be the responsibility of Covered Entity.
l. Business Associate agrees to make any amendment(s) to PHI in a DRS that the Covered Entity directs or agrees to pursuant to 45 CFR §164.526 at the written request of Covered Entity or an Individual, within twenty (20) business days of the written request.
m. Business Associate agrees to make internal practices, books, and records, including policies and procedures and PHI, relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of Covered Entity, available to the Covered Entity and to the Secretary, within fifteen (15) business days after notice of the Secretary’s request or in the time and manner designated by the Secretary, for purposes of the Secretary determining Covered Entity's compliance with the Privacy Rule and the Security Rule.
n. Business Associate agrees to document disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR §164.528.
o. Business Associate agrees to provide to Covered Entity, or to an Individual at the request of the Covered Entity, or to the Individual if the request is made directly to the Business Associate by the Individual within fifteen (15) business days of written notice from Covered Entity to Business Associate, information collected in accordance with Section 2.o. of this Agreement, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of in accordance with 45 CFR §164.528.
p. Business Associate shall comply with the privacy, security and security breach notification provisions applicable to a business associate under the HITECH Act and any regulations promulgated thereunder, including but not limited to compliance with each of the Standards and Implementation Specifications of 45 §§ C.F.R. 164.308 (Administrative Safeguards),
164.310 (Physical Safeguards), 164.312 (Technical Safeguards), 164.316 (Policies and Procedures and Documentation Requirements), and 164.410 (Notification by a Business Associate).
3. Permitted Uses and Disclosures by Business Associate - General Use and Disclosure Provisions.
Except as otherwise limited in this Agreement, Business Associate may use or disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the Agreement, provided that such use or disclosure would not violate the Privacy Rule if done by Covered Entity or the minimum necessary policies and procedures of Covered Entity.
4. Permitted Uses and Disclosures by Business Associate - Specific Use and Disclosure Provisions.
a. Except as otherwise limited in this Agreement, Business Associate may use PHI for the proper management and administration of Business Associate or to carry out Business Associate’s legal responsibilities.
b. Except as otherwise limited in this Agreement, Business Associate may disclose PHI for the proper management and administration of Business Associate, provided that disclosures are Required By Law or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as Required By Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
c. Except as otherwise limited in this Agreement, Business Associate may use PHI to provide Data Aggregation services to Covered Entity as permitted by 42 C.F.R.
§164.504(e)(2)(i)(B).
d. Business Associate may use PHI to report violations of law to appropriate Federal and State authorities, consistent with 42 C.F.R. §164.502(j)(1).
5. Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions.
a. Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices of Covered Entity in accordance with 45 CFR §164.520, to the extent that such limitation(s) may affect Business Associate's use or disclosure of PHI.
b. Covered Entity shall notify Business Associate of any changes in, or revocation of permission by Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.
c. Covered Entity shall notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR §164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.
6. Permissible Requests by Covered Entity. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity.
7. Term and Termination.
a. Term. The commencement date for the term of this Agreement shall be July __, 2017.
This Agreement shall terminate when all of the PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information in accordance with the termination provisions in this Section.
b. Termination for Cause. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity shall:
1) Provide an opportunity for Business Associate to cure the breach or end the violation within thirty (30) days after written notice and, if Business Associate does not cure the breach or end the violation within that time, terminate this Agreement;
or
2) Immediately terminate this Agreement upon written notice if Business Associate has breached a material term of this Agreement and cure is not possible as determined at the sole discretion of Covered Entity; or
3) If neither termination nor cure is feasible, report the violation to the Secretary of the Department of Health and Human Services.
c. Effect of Termination.
1) Except as provided in paragraph (2) of this subsection, upon termination of this Agreement, for any reason, Business Associate shall return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity. This provision shall apply to PHI that is in the possession of any subcontractors or agents of Business Associate, and Business Associate has the duty to ensure that any and all of its subcontractors or agents comply with these termination provisions. Neither Business Associate, nor any of its subcontractors or agents, shall retain any copies of PHI upon termination of this Agreement.
2) In the event that Business Associate determines that returning or destroying the PHI is infeasible, Business Associate shall provide to Covered Entity written notification of the conditions that make return or destruction infeasible thirty (30) calendar days prior to the termination of the Agreement or within thirty (30) calendar days of Business Associate’s receipt of notice from Covered Entity of a material breach of this Agreement by Business Associate. Upon mutual agreement of the parties that return or destruction of PHI is infeasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.
8. Effect on Prior Business Associate Agreements: This Agreement supersedes and replaces any existing Business Associate Agreement in effect between Business Associate and Covered Entity.
Any PHI Business Associate has received from Covered Entity prior to, on, or after the date of this Agreement is subject to the terms and conditions of this Agreement.
9. Miscellaneous.
a. Regulatory References. A reference in this Agreement to a section in the Privacy Rule means the section as in effect or as amended.
b. Amendment. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the Privacy Rule and HIPAA; amendments are not effective unless in writing, signed by both Parties.
Survival. The respective rights and obligations of Business Associate under Section 7.c., “Effect of Termination,” and Section 2.j., regarding Indemnification, of this Agreement shall survive the termination of this Agreement.
c. Interpretation. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with the Privacy Rule.
d. Notice. Any notice required under this Agreement shall be sent by certified mail, return receipt requested or by hand delivery to the following persons:
e. Retroactivity. Business Associate warrants that there have been no violations of HIPAA or HITECH Act from the date of execution of the Underlying Agreement through the commencement date of this Agreement.
Covered Entity:
With copies to:
Suzanne Konchan, Deputy County Manager County of Volusia 123 West Indiana Avenue, Rm 300 DeLand, Florida 32720
Kevin Captain, Emergency Medical Services Director County of Volusia 112 Carswell Avenue Holly Hill, Florida 32117
Pamela Wilsky, Purchasing and Contracts Director County of Volusia 123 West Indiana Avenue, Rm 302 DeLand, Florida 32720
Business Associate:
Add Contact, name and address of Contractor.
IN WITNESS THEREOF, the parties have caused this Business Associate Agreement to be duly executed by their duly authorized representatives on the respective dates under each signature.
BUSINESS ASSOCIATE: CONTRACTOR NAME ATTEST:
By: By:
Name: Name:
Title:
Date:
COVERED ENTITY: COUNTY OF VOLUSIA, FL
By:
Name:
Title:
Date:
Title:
Date:
By:
Name:
Title:
Date:
Exhibit 1 Form of Notification to Covered Entity of
Breach of Unsecured PHI
Business Associate hereby notifies Covered Entity that there has been a breach of unsecured protected health information (PHI) that Business Associate has used or has had access to under the terms of the Business Associate Agreement.
Description of the breach:
Date of the breach:
Date of the discovery of the breach:
Name of each individual affected by the breach: _____________________________________________
The types of unsecured PHI that were involved in the breach (such as full name, Social Security number, date of birth, home address, account number, or disability code):
Description of what Business Associate is doing to investigate the breach, to mitigate losses, and to protect against any further breaches:
Contact information to ask questions or learn additional information:
Name:
Title:
Address:
Email Address:
Phone Number:
File details come from the government source that posted it. Updated .