HIPAA_Business_Associate.pdf

PDF 173 KB Posted

Attached to
Pinellas County Health Program Evaluation Services State and local contract opportunity
Solicitation number
25-0913-RFP
Issued by
Pinellas County, Clewiston City, Florida

About this file

This document is a HIPAA Business Associate Agreement between Pinellas County Human Services (the Covered Entity) and an unnamed Business Associate, effective October 1, 2024. The agreement establishes the terms and conditions for handling Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH Act). The Business Associate, primarily known for providing substance abuse treatment, will perform functions that involve receiving, accessing, or creating health information on behalf of Pinellas County.

The agreement outlines comprehensive obligations for the Business Associate, including strict protocols for protecting, using, and disclosing health information, reporting potential breaches, maintaining confidentiality of substance abuse patient records, and implementing robust security and privacy safeguards. Key requirements include conducting monthly exclusion testing of workforce members, notifying the Covered Entity of any suspected breaches within five business days, and potentially handling breach notifications to individuals and regulatory bodies. The contract includes provisions for potential termination, indemnification, and survival of certain obligations even after the agreement's conclusion, with all actions to be governed by Florida state law and litigated in Pinellas County courts.

View the file

Other files for this state and local contract opportunity

Other files attached to Pinellas County Health Program Evaluation Services, newest first.
File Type Posted
Pinellas_County_Health_Program_Evaluation_Services.pdf PDF
Pinellas_County_Health_Program_Evaluation_Services.pdf PDF
Pinellas_County_Health_Program_Evaluation_Services.pdf PDF
Pinellas_County_Health_Program_Evaluation_Services.pdf PDF
Pinellas_County_Health_Program_Evaluation_Services.pdf PDF
HIPAA_Business_Associate.pdf PDF
HIPAA_Business_Associate.pdf PDF
HIPAA_Business_Associate.pdf PDF
HIPAA_Business_Associate.pdf PDF
Notice_of_Intent_to_Sole_Source_07-25-2023.pdf PDF
Foreign_Countries_of_Concern_Affidavit_02.05.2025.pdf PDF
Non-Competitive_Oversight_Committee_Justification_Form.docx DOCX document
Foreign_Countries_of_Concern_Affidavit_02.05.2025.pdf PDF
Human_Trafficking_Affidavit_02.05.2025.pdf PDF
Human_Trafficking_Affidavit_02.05.2025.pdf PDF
Non-Competitive_Oversight_Committee_Justification_Form.docx DOCX document
Notice_of_Intent_to_Sole_Source_07-25-2023.pdf PDF
Common_Carrier_Attestation_02.05.2025.pdf PDF
Common_Carrier_Attestation_02.05.2025.pdf PDF
Foreign_Countries_of_Concern_Affidavit_02.05.2025.pdf PDF
Human_Trafficking_Affidavit_02.05.2025.pdf PDF
Common_Carrier_Attestation_02.05.2025.pdf PDF
Foreign_Countries_of_Concern_Affidavit_02.05.2025.pdf PDF
Common_Carrier_Attestation_02.05.2025.pdf PDF
Foreign_Countries_of_Concern_Affidavit_02.05.2025.pdf PDF
Human_Trafficking_Affidavit_02.05.2025.pdf PDF
Common_Carrier_Attestation_02.05.2025.pdf PDF
Non-Competitive_Oversight_Committee_Justification_Form.docx DOCX document
Human_Trafficking_Affidavit_02.05.2025.pdf PDF
Non-Competitive_Oversight_Committee_Justification_Form.docx DOCX document
Notice_of_Intent_to_Sole_Source_07-25-2023.pdf PDF
Non-Competitive_Oversight_Committee_Justification_Form.docx DOCX document
Notice_of_Intent_to_Sole_Source_07-25-2023.pdf PDF
Notice_of_Intent_to_Sole_Source_07-25-2023.pdf PDF
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HIPAA BUSINESS ASSOCIATE AGREEMENT

This Agreement (hereinafter referred to as AGREEMENT) is entered into by and between Pinellas County, a political subdivision of the State of Florida (hereinafter referred to as COVERED ENTITY) and the business associate named on the signature page hereof (hereinafter referred to as BUSINESS ASSOCIATE) (each hereinafter referred to as PARTY and collectively hereinafter referred to as the PARTIES) on this 1st day of October 2024.

WHEREAS, BUSINESS ASSOCIATE performs functions, activities, or services for, or on behalf of COVERED ENTITY, and BUSINESS ASSOCIATE receives, has access to or creates Health Information in order to perform such functions, activities or services; and

WHEREAS, COVERED ENTITY is subject to the Administrative Simplification requirements of the Health Insurance Portability and Accountability Act of 1996 and regulations promulgated there under (hereinafter referred to as HIPAA), including but not limited to, the Standards for Privacy of Individually Identifiable Health Information and the Security Standards for the Protection of Electronic Protected Health Information found at 45 Code of Federal Regulations Parts 160, 162 and 164; and

WHEREAS, HIPAA requires COVERED ENTITY to enter into a contract with

BUSINESS ASSOCIATE to provide for the protection of the privacy and security of Health Information, and HIPAA prohibits the disclosure to or use of Health Information by BUSINESS ASSOCIATE if such a contract is not in place; and

WHEREAS, as a result of the requirements of the Health Information Technology for

Economic and Clinical Health Act (hereinafter referred to as HITECH ACT), as incorporated in the American Recovery and Reinvestment Act of 2009, and its implementing regulations and guidance issued by the Secretary of the U.S. Department of Health and Human Services (hereinafter referred to as SECRETARY), all as amended from time to time, the PARTIES agree to this AGREEMENT in order to document the PARTIES’ obligations under the HITECH ACT.

WHEREAS, BUSINESS ASSOCIATE is primarily known for providing substance abuse treatment, COVERED ENTITY and BUSINESS ASSOCIATE shall comply with the applicable federal regulation governing the Confidentiality of Alcohol and Drug Abuse Patient Records, 42 CFR. Part 2 and may not use or disclose such records except as permitted 42 CFR.

Part 2.

NOW, THEREFORE, in consideration of the foregoing, and for other good and valuable consideration, the receipt and adequacy of which is hereby acknowledged, the PARTIES agree as follows:

ARTICLE I

DEFINITIONS

1.1 “Business Associate” shall generally have the same meaning as the term “business associate” at 45 CFR 160.103, and in reference to the party to this agreement, shall mean

1.2 “Covered Entity” shall generally have the same meaning as the term “covered entity” at 45 CFR 160.103, and in reference to the party to this agreement, shall mean Pinellas County by and through its Department of Human Services.

1.3 “Disclose” and “Disclosure” shall mean, with respect to Health Information, the release, transfer, provision of access to, or divulging in any other manner of Health Information outside BUSINESS ASSOCIATE’s internal operations or to other than its employees.

1.4 “Health Information” shall mean information that: (a) relates to the past, present or future physical or mental health or condition of an individual; the provision of health care to an individual, or the past, present or future payment for the provision of health care to an individual;

(b) identifies the individual (or for which there is a reasonable basis for believing that the information can be used to identify the individual); and (c) is received by BUSINESS ASSOCIATE from or on behalf of COVERED ENTITY, or is created by BUSINESS ASSOCIATE, or is made accessible to BUSINESS ASSOCIATE by COVERED ENTITY.

1.5 “HIPAA Rules”. “HIPAA Rules” shall mean the Privacy, Security, Breach

Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.

1.6 “Privacy Regulations” shall mean the Standards for Privacy of Covered Individually Identifiable Health Information, 45 Code of Federal Regulations Parts 160 and 164, promulgated under HIPAA.

1.7 “Services” shall mean the services provided by BUSINESS ASSOCIATE pursuant to the Underlying Agreement, or if no such agreement is in effect, the services BUSINESS ASSOCIATE performs with respect to the COVERED ENTITY.

1.8 “Underlying Agreement” shall mean the services agreement executed by the

COVERED ENTITY and BUSINESS ASSOCIATE, if any.

1.9 “Use” or “Uses” shall mean, with respect to Health Information, the sharing, employment, application, utilization, examination or analysis of such Health Information within BUSINESS ASSOCIATE’s internal operations.

1.10 “42 CFR Part 2” refers to the federal regulations that protect the confidentiality of substance use disorder (SUD) patient records. These regulations ensure that records related to the identity, diagnosis, prognosis, or treatment of patients in federally assisted SUD programs are kept confidential

1.11 Catch-all definition: The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use, unless otherwise specifically https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html defined or referred under this Agreement.

ARTICLE II

OBLIGATIONS OF BUSINESS ASSOCIATE

2.1 Initial Effective Date of Performance. The obligations created under this

AGREEMENT shall become effective immediately upon execution of this AGREEMENT or the agreement to which it is appended.

2.2 Obligations and Activities of Business Associate. Business Associate agrees to:

a. Not use or disclose protected health information other than as permitted or required by the Agreement or as required by law.

b. When dealing with records subject to 42 CFR. Part 2, shall resist any efforts in judicial proceedings to obtain access to the protected information except as expressly provided for in the regulations governing the Confidentiality of Alcohol and Drug Abuse Patient Records, 42 CFR. Part 2.

c. Use appropriate safeguards, and comply with Subpart C of 45 CFR Part

164 with respect to electronic protected health information, to prevent use or disclosure of protected health information other than as provided for by the Agreement.

d. Report to COVERED ENTITY any unauthorized acquisition, access, use or disclosure of protected health information not provided for by the Agreement of which it becomes aware, including breaches of unsecured protected health information as required at 45 CFR 164.410, and any security incident of which it becomes aware.

e. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate agree to the same restrictions, conditions, and requirements that apply to the business associate with respect to such information.

f. Make available protected health information in a designated record set to the COVERED ENTITY as necessary to satisfy COVERED ENTITY‘s obligations under 45 CFR 164.524.

1) Requests received by the BUSINESS ASSOCIATE directly from an individual seeking access to protected health information in a designated record set will be forwarded to the COVERED ENTITY within two (2) business days to allow the COVERED ENTITY to process the request

g. Make any amendment(s) to protected health information in a designated record set as directed or agreed to by the COVERED ENTITY pursuant to 45 CFR 164.526, or take other measures as necessary to satisfy covered entity’s obligations under 45 CFR 164.526.

h. Maintain and make available the information required to provide an accounting of disclosures to the “COVERED ENTITY” as necessary to satisfy COVERED ENTITY’s obligations under 45 CFR 164.528.

i. To the extent the business associate is to carry out one or more of COVERED ENTITY ‘s obligation(s) under Subpart E of 45 CFR Part 164, comply with the requirements of Subpart E that apply to the COVERED ENTITY in the performance of such obligation(s).

j. Make its internal practices, books, and records available to the Secretary for purposes of determining compliance with the HIPAA Rules.

k. Seek Patient Consent: A single, mutually agreed upon consent form can be used for all future uses and disclosures for treatment, payment, and healthcare operations. Consent must be obtained for any use or disclosure of Substance Use Disorder (SUD) records in civil, criminal, administrative, or legislative proceedings unless a court order is obtained.

2.3 Permitted Uses and Disclosures of Health Information. BUSINESS ASSOCIATE is authorized to:

a. Use and Disclose Health Information as necessary to perform Services for, or on behalf of COVERED ENTITY.

b. Use Health Information to create aggregated or de-identified information consistent with the requirements of the Privacy Regulations.

c. Use or Disclose Health Information (including aggregated or de-identified information) as otherwise directed by COVERED ENTITY provided that COVERED ENTITY shall not request BUSINESS ASSOCIATE to use or disclose Health Information in a manner that would not be permissible under 42 CFR Part 2 or if done by COVERED

ENTITY.

d. To the extent required by the HITECH ACT, BUSINESS ASSOCIATE shall limit its use, disclosure or request of PHI to the Limited Data Set or, if needed, to the minimum necessary to accomplish the intended use, disclosure or request, respectively.

Effective on the date the SECRETARY issues guidance on what constitutes “minimum necessary” for purposes of HIPAA, BUSINESS ASSOCIATE shall limit its use, disclosure or request of PHI to only the minimum necessary as set forth in such guidance.

e. BUSINESS ASSOCIATE shall not use Health Information for any other purpose that would violate Subpart E of 45 CFR Part 164 or 42 CFR Part 2, except that if necessary, BUSINESS ASSOCIATE may use Health Information for the proper management and administration of BUSINESS ASSOCIATE or to carry out its legal responsibilities; provided that any use or disclosure described herein will not violate the Privacy Regulations or Florida law if done by COVERED ENTITY. Except as otherwise limited in this Agreement, BUSINESS ASSOCIATE may disclose Health Information for the proper management and administration of the BUSINESS ASSOCIATE, provided that with respect to any such disclosure either: (a) the disclosure is required by law (within the meaning of the Privacy Regulations) or (b) the disclosure would not otherwise violate Florida law and BUSINESS ASSOCIATE obtains reasonable written assurances from the person to whom the information is to be disclosed that such person will hold the information in confidence and will not use or further disclose such information except as required by law or for the purpose(s) for which it was disclosed by BUSINESS ASSOCIATE to such person, and that such person will notify BUSINESS ASSOCIATE of any instances of which it is aware in which the confidentiality of the information has been breached.

2.4 Compliance with Security Provisions. BUSINESS ASSOCIATE shall:

a. Implement and maintain administrative safeguards as required by 45 CFR § 164.308, physical safeguards as required by 45 CFR § 164.310 and technical safeguards as required by 45 CFR § 164.312.

b. Implement and document reasonable and appropriate policies and procedures as required by 45 CFR § 164.316.

c. Be in compliance with all requirements of the HITECH ACT related to security and applicable as if BUSINESS ASSOCIATE were a covered entity, as such term is defined in HIPAA.

d. BUSINESS ASSOCIATE shall use its best efforts to implement and maintain technologies and methodologies that render PHI unusable, unreadable or indecipherable to unauthorized individuals as specified in the HITECH ACT.

2.5 Compliance with Privacy Provisions. BUSINESS ASSOCIATE shall only use and disclose PHI in compliance with each applicable requirement of 45 CFR § 164.504(e) and 42 CFR Part 2.BUSINESS ASSOCIATE shall comply with all requirements of the HITECH ACT related to privacy and applicable as if BUSINESS ASSOCIATE were a covered entity, as such term is defined in HIPAA.

2.6 Mitigation. BUSINESS ASSOCIATE agrees to mitigate, to the extent practicable, any harmful effect that is known to BUSINESS ASSOCIATE of a use or disclosure of Health Information by BUSINESS ASSOCIATE in violation of the requirements of this AGREEMENT.

2.7 Exclusion Testing. BUSINESS ASSOCIATE herby represents and warrants to

COVERED ENTITY that none of its current or future members, shareholders, directors, officers, agents, employees, or workforce members are or have even been excluded from participation in Medicare, Medicaid, or any other Federal Health Program or State Health Program. BUSINESS ASSOCIATE agrees that it shall conduct ongoing exclusion testing throughout the Term of this Agreement on a monthly basis, which exclusion testing shall consist of, at a minimum, checking of its current or future members, shareholders, directors, officers, agents, employees, or workforce members against the U.S. Department of Health and Human Services Office of Inspector General’s List of Excluded Individuals/Entities and any corresponding state database. BUSINESS ASSOCIATE agrees to notify COVERED ENTITY immediately after BUSINESS ASSOCIATE first becomes aware that any of the foregoing representations and warranties has become or may become inaccurate. BUSINESS ASSOCIATE further agrees to fully indemnify COVERED ENTITY for any and all breaches of representations and covenants set forth above

2.8 Breach of Unsecured PHI. The provisions of this Section are effective with respect to the discovery of a breach of unsecured PHI occurring on or after September 23, 2009.

a. With respect to any unauthorized acquisition, access, use or disclosure of COVERED ENTITY’s PHI by BUSINESS ASSOCIATE, its agents or subcontractors, BUSINESS ASSOCIATE shall:

1) Investigate such unauthorized acquisition, access, use or disclosure;

2) Determine whether such unauthorized acquisition, access, use or disclosure constitutes a reportable breach under the HITECH ACT; and

3) Document and retain its findings under clauses 1) and 2) of this

Section.

b. BUSINESS ASSOCIATE shall notify COVERED ENTITY of all suspected breaches within five (5) business days of discovery. If the BUSINESS ASSOCIATE discovers that a reportable breach has occurred, BUSINESS ASSOCIATE shall notify COVERED ENTITY of such reportable breach in writing within three (3) days of the date BUSINESS ASSOCIATE discovers and determines that such breach is reportable. BUSINESS ASSOCIATE shall notify COVERED ENTITY immediately upon discovering a reportable breach of more than 500 individuals.

c. BUSINESS ASSOCIATE shall be deemed to have discovered a breach as of the first day that breach is either known to BUSINESS ASSOCIATE or any of its employees, officers or agents, other than the person who committed the breach, or through exercise of reasonable diligence, should have been known to BUSINESS ASSOCIATE or any of its employees, officers or agents, other than the person who committed the breach.

d. To the extent the information is available to BUSINESS ASSOCIATE, it’s written notice shall include the information required by 45 CFR §164.410.

e. BUSINESS ASSOCIATE shall promptly supplement the written report with additional information regarding the breach as it obtains such information.

f. BUSINESS ASSOCIATE shall cooperate with COVERED ENTITY in meeting the COVERED ENTITY’s obligations under the HITECH ACT with respect to such breach. COVERED ENTITY shall have sole control over the timing and method of providing notification of such breach to the affected individual(s), the SECRETARY and, if applicable, the media, as required by the HITECH ACT.

g. BUSINESS ASSOCIATE shall reimburse COVERED ENTITY for its reasonable costs and expenses in providing the notification, including, but not limited to, any administrative costs associated with providing notice, printing and mailing costs, and costs of mitigating the harm for affected individuals whose PHI has or may have been compromised as a result of the breach. In order to be reimbursed by BUSINESS ASSOCIATE, COVERED ENTITY must provide to BUSINESS ASSOCIATE a written accounting of COVERED ENTITY’s actual costs and to the extent applicable, copies of receipts or bills with respect thereto.

h. BUSINESS ASSOCIATE will handle breach notifications to individuals, the HHS Office for Civil Rights (OCR), and potentially the media, on behalf of the Covered

Entity only when so directed by the Covered Entity or required by law

2.9 Availability of Internal Practices, Books and Records. BUSINESS ASSOCIATE agrees to make its internal practices, books and records relating to the use and disclosure of Health Information available to the SECRETARY, for purposes of determining COVERED ENTITY’s compliance with the Privacy Regulations.

2.10 Agreement to Restriction on Disclosure. If COVERED ENTITY is required to comply with a restriction on the disclosure of PHI pursuant to Section 13405 of the HITECH ACT, then COVERED ENTITY shall, to the extent needed to comply with such restriction, provide written notice to BUSINESS ASSOCIATE of the name of the individual requesting the restriction and the PHI affected thereby. BUSINESS ASSOCIATE shall, upon receipt of such notification, not disclose the identified PHI to any health plan for the purposes of carrying out payment or health care operations, except as otherwise required by law.

2.11 Accounting of Disclosures. Upon COVERED ENTITY’s request, BUSINESS

ASSOCIATE shall:

a. Provide to COVERED ENTITY an accounting of each disclosure of Health Information made by BUSINESS ASSOCIATE or its employees, agents, representatives or subcontractors as required by the Privacy Regulations. For each Disclosure that requires an accounting under this Section 2.10, BUSINESS ASSOCIATE shall track the information required by the Privacy Regulations and shall securely maintain the information for six (6) years from the date of the Disclosure.

b. If BUSINESS ASSOCIATE is deemed to use or maintain an Electronic

Health Record on behalf of COVERED ENTITY, then BUSINESS ASSOCIATE shall maintain an accounting of any disclosures made through an Electronic Health Record for treatment, payment and health care operations, as applicable. Such accounting shall comply with the requirements of the HITECH ACT.

c. Upon request by COVERED ENTITY, BUSINESS ASSOCIATE shall provide such accounting to COVERED ENTITY in the time and manner specified by the

HITECH ACT.

d. Where COVERED ENTITY responds to an individual’s request for an accounting of disclosures made through an Electronic Health Record by providing the requesting individual with a list of all business associates acting on behalf of COVERED ENTITY; BUSINESS ASSOCIATE shall provide such accounting directly to the requesting individual in the time and manner specified by the HITECH ACT.

2.12 Use of Subcontractors and Agents. BUSINESS ASSOCIATE shall require each of its agents and subcontractors that receive Health Information from BUSINESS ASSOCIATE to execute a written agreement obligating the agent or subcontractor to comply with all the terms of this AGREEMENT with respect to such Health Information.

2.13 Access to Electronic Health Records.

a. If BUSINESS ASSOCIATE is deemed to use or maintain an Electronic Health Record on behalf of COVERED ENTITY with respect to PHI, BUSINESS ASSOCIATE shall provide an individual with a copy of the information contained in such

Electronic Health Record in an electronic format and, if the individual so chooses, transmit such copy directly to an entity or person designated by the individual upon request, to the extent an individual has the right to request a copy of the PHI maintained in such Electronic Health Record pursuant to 45 CFR § 164.524 and makes such a request to BUSINESS

ASSOCIATE.

b. BUSINESS ASSOCIATE may charge a fee to the individual for providing a copy of such information, but such fee may not exceed BUSINESS ASSOCIATE’s labor costs in responding to the request for the copy.

c. The provisions of 45 CFR § 164.524, including the exceptions to the requirement to provide a copy of PHI shall otherwise apply and BUSINESS ASSOCIATE shall comply therewith as if BUSINESS ASSOCIATE were the COVERED ENTITY.

At COVERED ENTITY’s request, BUSINESS ASSOCIATE shall provide COVERED ENTITY with a copy of an individual’s PHI maintained in an Electronic Health Record in an electronic format in a time and manner designated by COVERED ENTITY in order for COVERED ENTITY to comply with 45 CFR

§ 164.524, as amended by the HITECH ACT.

2.14 Limitations on Use of PHI for Marketing Purposes.

a. BUSINESS ASSOCIATE shall not use or disclose PHI for the purpose of making a communication about a product or service that encourages recipients of the communication to purchase or use the product or service, unless such communication:

1) Complies with the requirements the definition of marketing contained in 45 CFR § 164.501; and

2) Complies with the requirements of Subparagraphs a, b or c of Section 13406(a)(2) of the HITECH ACT.

b. COVERED ENTITY shall cooperate with BUSINESS ASSOCIATE to determine if the foregoing requirements are met with respect to any such marketing communication.

ARTICLE III

OBLIGATIONS OF COVERED ENTITY

3.1 Privacy Notice. COVERED ENTITY shall notify BUSINESS ASSOCIATE of any limitation(s) in COVERED ENTITY’s notice of privacy practices to the extent such limitation(s) may affect BUSINESS ASSOCIATE’s Use or Disclosure of Health Information.

ARTICLE IV

TERM AND TERMINATION

4.1 Term. Subject to the provisions of Sections 4.2 and 4.3, the term of this AGREEMENT shall be the term of the Underlying Agreement.

4.2 Termination of AGREEMENT.

a. Upon becoming aware of a pattern of activity or practice of either PARTY that constitutes a material breach or violation of obligations under the AGREEMENT, the non-breaching PARTY shall immediately notify the PARTY in breach.

b. Notification shall be provided in writing and shall specify the nature of the breach.

c. With respect to such breach or violation, upon receiving notice of the violation the non-breaching PARTY shall:

1) Allow the breaching PARTY thirty (30) days to take reasonable steps to cure such breach or end such violation; and

2) Terminate this AGREEMENT, if cure is either not possible or unsuccessful; and

3) Report the breach or violation to the SECRETARY if such termination is not feasible.

d. Upon termination of this AGREEMENT for any reason, BUSINESS

ASSOCIATE shall return or destroy all PHI consistent with Section 4.4 as follows:

1) BUSINESS ASSOCIATE shall destroy PHI in a manner that renders the PHI unusable, unreadable or indecipherable to unauthorized individuals as specified in the HITECH ACT and shall certify in writing to COVERED ENTITY that such PHI has been destroyed in compliance with such standards; or

2) Return of PHI shall be made in a mutually agreed upon format and timeframe and at no additional cost to BUSINESS ASSOCIATE.

e. Where return or destruction are not feasible, BUSINESS ASSOCIATE shall continue to extend the protections of the AGREEMENT to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction of such PHI not feasible.

4.3 Termination for Breach. COVERED ENTITY may terminate the Underlying

Agreement and this AGREEMENT upon thirty (30) days written notice in the event: (a) BUSINESS ASSOCIATE does not promptly enter into negotiations to amend this AGREEMENT when requested by COVERED ENTITY pursuant to Section 5.2 or (b) BUSINESS ASSOCIATE does not enter into an amendment to this AGREEMENT providing assurances regarding the safeguarding of Health Information that the COVERED ENTITY, deems sufficient to satisfy the standards and requirements of HIPAA and the HITECH ACT.

4.4 Disposition of Health Information Upon Termination or Expiration. Upon termination or expiration of this AGREEMENT, BUSINESS ASSOCIATE shall either return or destroy, in COVERED ENTITY’s sole discretion and in accordance with any instructions by COVERED ENTITY, all Health Information in the possession or control of BUSINESS ASSOCIATE and its agents and subcontractors. In such event, BUSINESS ASSOCIATE shall retain no copies of such Health Information. If BUSINESS ASSOCIATE determines that neither return nor destruction of Health Information is feasible, BUSINESS ASSOCIATE shall notify

COVERED ENTITY of the conditions that make return or destruction infeasible, and may retain Health Information provided that BUSINESS ASSOCIATE: (a) continues to comply with the provisions of this AGREEMENT for as long as it retains Health Information, and (b) further limits uses and disclosures of Health Information to those purposes that make the return or destruction of Health Information infeasible.

4.5 Survival. The obligations of BUSINESS ASSOCIATE under this Article IV shall survive the termination of this Agreement.

ARTICLE V

MISCELLANEOUS

Indemnification. Notwithstanding anything to the contrary in the Underlying Agreement, BUSINESS ASSOCIATE agrees to indemnify, defend and hold harmless COVERED ENTITY and COVERED ENTITY’s employees, directors, officers, subcontractors or agents against all damages, losses, lost profits, fines, penalties, costs or expenses (including reasonable attorneys’ fees) and all liability to third parties arising from any breach of this AGREEMENT by BUSINESS ASSOCIATE or its employees, directors, officers, subcontractors, agents or other members of BUSINESS ASSOCIATE’s workforce. BUSINESS ASSOCIATE’s obligation to indemnify shall survive the expiration or termination of this AGREEMENT.

5.1 Amendment to Comply with Law. The PARTIES acknowledge that state and federal laws relating to electronic data security and privacy are rapidly evolving and that amendment of this AGREEMENT may be required to provide for procedures to ensure compliance with such developments. The PARTIES specifically agree to take such action as is necessary to implement the standards and requirements of HIPAA, the HITECH ACT, 42 CFR Part 2, and other applicable laws relating to the security or confidentiality of Health Information. The PARTIES understand and agree that COVERED ENTITY must receive satisfactory written assurance from BUSINESS ASSOCIATE that BUSINESS ASSOCIATE will adequately safeguard all Health Information that it receives or creates on behalf of COVERED ENTITY. Upon COVERED ENTITY’s request, BUSINESS ASSOCIATE agrees to promptly enter into negotiations with COVERED ENTITY, concerning the terms of any amendment to this AGREEMENT embodying written assurances consistent with the standards and requirements of HIPAA, the HITECH ACT or other applicable laws.

5.2 Preemption. In the event of an inconsistency between the provisions of this Agreement and mandatory provisions of the Privacy Standards, Security Standards, HIPAA or 42 CFR. Part 2, as amended, the Privacy Standards, Security Standards, HIPAA and 42 CFR. Part 2 shall control. In the event of an inconsistency between the provisions of the Privacy Standards, Security Standards, HIPAA, 42 CFR. Part 2 and other applicable confidentiality laws, including Florida law, the provisions of the more restrictive rule or law will control.

5.3 Modification of Agreement. No alteration, amendment, or modification of this

AGREEMENT shall be valid or effective unless in writing and signed the PARTIES.

5.4 Non-Waiver. A failure of any PARTY to enforce at any time any term, provision or condition of this AGREEMENT, or to exercise any right or option herein, shall in no way operate as a waiver thereof, nor shall any single or partial exercise preclude any other right or option herein. Waiver of any term, provision or condition of this AGREEMENT shall not be valid unless in writing, signed by the waiving PARTY and only to the extent set forth in such writing.

5.5 Agreement Drafted By All Parties. This AGREEMENT is the result of arm’s length negotiations between the PARTIES and shall be construed to have been drafted by all PARTIES such that any ambiguities in this AGREEMENT shall not be construed against either PARTY.

5.6 Severability. If any provision of this AGREEMENT is found to be invalid or unenforceable by any court, such provision shall be ineffective only to the extent that it is in contravention of applicable laws without invalidating the remaining provisions hereof.

5.7 Section Headings. The Section headings contained herein are for convenience in reference and are not intended to define or limit the scope of any provision of this Agreement.

5.8 No Third-Party Beneficiaries. There are no third-party beneficiaries to this

AGREEMENT.

5.9 Counterparts. This AGREEMENT may be executed in one or more counterparts, each of which shall be deemed an original and will become effective and binding upon the PARTIES as of the effective date at such time as all the signatories hereto have signed a counterpart of this AGREEMENT.

5.10 Notices. The PARTIES designate the following to accept notice on their behalf:

If to BUSINESS ASSOCIATE:

If to COVERED ENTITY:

Human Services HIPAA Liaison 440 Court Street, 2nd Floor Clearwater, FL 33756

(727) 464-8452 HSContracts@pinellas.gov

5.11 Applicable Law and Venue. This AGREEMENT shall be governed by and construed in accordance with the laws of the State of Florida. The PARTIES agree that all actions or proceedings arising in connection with this AGREEMENT shall be tried and litigated exclusively in the state or federal courts located in or nearest to Pinellas County, Florida.

5.12 Interpretation. This AGREEMENT shall be construed in a manner that will cause the PARTIES to comply with the requirements of HIPAA and the HITECH ACT.

IN WITNESS WHEREOF, each of the undersigned has caused this AGREEMENT to be duly executed in its name and on its behalf effective as of this day of , 2024.

COVERED ENTITY: BUSINESS ASSOCIATE:

Pinellas County Human Services

By: By:

Print Name:

Print Title:

Karen B. Yatchum

Director

Print Name:

Print Title:

HIPAA BUSINESS ASSOCIATE AGREEMENT
ARTICLE I DEFINITIONS
ARTICLE II OBLIGATIONS OF BUSINESS ASSOCIATE
ARTICLE IV
ARTICLE V MISCELLANEOUS
COVERED ENTITY: BUSINESS ASSOCIATE:

File details come from the government source that posted it. Updated .