BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement (“Agreement”), effective @{Date:37}, (“Effective Date”), is entered between @{Company Name:36} (“Covered Entity”) and Scribekick LLC, a Virginia Limited Liability company (“Business Associate”).
Recitals
WHEREAS, the parties have entered into an agreement dated @{Date:37} (“Services Agreement”), whereby Business Associate will provide certain services as outlined in the Services Agreement for Covered Entity (the “Designated Functions”), and pursuant to such Services Agreement, Business Associate may receive or have access to Protected Health Information (defined below) and be a “business associate” of Covered Entity as defined at 45 C.F.R. § 160.103 in the HIPAA Security and Privacy Rule (defined below); and
WHEREAS, the parties desire to enter into this Agreement to comply with the regulations promulgated by the U.S. Department of Health and Human Services (“HHS”) set forth at 45 C.F.R. Parts 160 and 164 (the “HIPAA Security and Privacy Rule”) regarding the security, confidentiality, and integrity of health information under the Administrative Simplification Provisions of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended and revised by the Health Information Technology for Economic and Clinical Health Act (“HITECH”), passed as part of the American Recovery and Reinvestment Act of 2009, as amended from time to time.
NOW, THEREFORE, for and in consideration of the foregoing recitals and the mutual promises and covenants hereinafter contained, the parties agree as follows:
Agreement
- DEFINITIONS
For purposes of this Agreement, the following definitions shall apply:
“Administrative Safeguards” shall mean administrative actions, policies and procedures to manage the selection, development, implementation and maintenance of reasonable and appropriate security measures to protect Electronic Protected Health Information (defined below) and to manage the conduct of Covered Entity’s or Business Associate’s workforce, as applicable, in relation to the protection of that information.
“Data Aggregation” shall mean, with respect to Protected Health Information created or received by Business Associate in its capacity as the business associate of Covered Entity, the combining of such Protected Health Information by Business Associate with the Protected Health Information received by Business Associate in its capacity as a business associate of another covered entity under the HIPAA Security and Privacy Rule, to permit data analyses that relate to the health care operations of the respective covered entities.
“Designated Record Set” shall mean a group of records maintained by or for Covered Entity that is (i) the medical records and billing records about individuals maintained by or for Covered Entity, (ii) the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan; or (iii) used, in whole or in part, by or for Covered Entity to make decisions about individuals. As used herein the term “record” means any item, collection, or grouping of information that includes Protected Health Information and is maintained, collected, used, or disseminated by or for Covered Entity.
“Electronic Protected Health Information” shall mean Protected Health Information that is transmitted by Electronic Media (as defined in the HIPAA Security and Privacy Rule) or maintained in Electronic Media.
“Individually Identifiable Health Information” shall mean information that is a subset of health information, including demographic information collected from an individual, and
(i) is created or received by a health care provider, health plan, employer, or health care clearinghouse; and
(ii) relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; and (a) identifies the individual, or (b) with respect to which there is a reasonable basis to believe that the information can be used to identify the individual.
“Physical Safeguards” shall mean reasonable and appropriate physical measures, policies and procedures to protect Covered Entity’s electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion.
“Privacy Standards” shall mean the Standard for Privacy of Individually Identifiable Health Information, 45 C.F.R. Parts 160 and 164, and related guidance and advice published by HHS or its designee.
“Protected Health Information” shall mean Individually Identifiable Health Information that is (i) transmitted electronically, (ii) maintained electronically, or (iii) transmitted or maintained in any other form or medium. “Protected Health Information” includes, without limitation, “Electronic Protected Health Information.”
“Secretary” shall mean the Secretary of HHS or any other officer or employee of HHS to whom the authority involved has been delegated.
“Security Incident” shall mean the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
“Technical Safeguards” shall mean the reasonable and appropriate technology and the policy and procedures for its use that protect Electronic Protected Health Information and control access to it.
II. OBLIGATIONS OF BUSINESS ASSOCIATE
Section 1. Permitted Uses of Protected Health Information.
Business Associate agrees to use Protected Health Information received by Business Associate from Covered Entity or created by Business Associate on behalf of Covered Entity solely in its capacity as a business associate to Covered Entity, and only to the extent necessary: (i) to perform the Designated Functions subject to the restrictions herein; (ii) for the proper management and administration of Business Associate; and (iii) to carry out Business Associate’s legal responsibilities. Business Associate shall not use Protected Health Information for any other purpose, or in any manner that would constitute a violation of the Privacy Standards.
Section 2. Disclosure of Protected Health Information.
Business Associate shall not, and shall ensure that its directors, officers, employees, contractors and agents do not, disclose Protected Health Information received from Covered Entity in any manner that would constitute a violation of the Privacy Standards if disclosed by Covered Entity, except that Business Associate may disclose Protected Health Information in a manner permitted pursuant to this Agreement or as required by law. Business Associate shall immediately report to the Privacy Officer of Covered Entity, in writing, any Security Incident and/or any use and/or disclosure of Protected Health Information that is not permitted or required by this Agreement or by applicable law of which Business Associate becomes aware, and provide notice to Covered Entity in accordance with Section 4.
Business Associate agrees that it shall disclose to third parties only the minimum Protected Health Information necessary to perform or fulfill a specific function required or permitted hereunder. To the extent Business Associate discloses Protected Health Information to a third party, Business Associate must obtain, prior to making any such disclosure, (i) the agreement of such third party to the same restrictions and conditions that apply to Business Associate with respect to such Protected Health Information, (ii) reasonable assurances from such third party that such Protected Health Information will be held confidential as provided pursuant to this Agreement and only disclosed as required by law or for the purposes for which it was disclosed to such third party, and (iii) an agreement from such third party (a) to immediately notify Business Associate of any breaches of the confidentiality of the Protected Health Information, to the extent it has obtained knowledge of such breach, (b) to provide information regarding the breach to Business Associate so that Business Associate and Covered Entity may comply with the requirements set forth at 45 C.F.R. § 164.400 et seq. as more fully described in Section 4 below, and (c) to take reasonable steps to mitigate the harm to the individual impacted by the breach and to protect against future breaches.
Section 3. Safeguards Against Misuse of Information.
Business Associate agrees that it will implement all appropriate and commercially reasonable safeguards to maintain the security of and prevent the use or disclosure of Protected Health Information other than use or disclosure by Covered Entity or Business Associate pursuant to the terms and conditions of this Agreement. Business Associate further agrees to comply with all legal requirements affecting the use and disclosure of Protected Health Information, including, without limitation, any applicable requirements of 45 C.F.R. § 164.504 et seq. Business Associate will also establish and implement procedures for mitigating the harmful effects from any improper use and/or disclosure of such Protected Health Information. Business Associate agrees to assume all costs associated with mitigation of any improper use and/or disclosure of Protected Health Information.
Section 4. Reporting of Inappropriate Disclosures of Protected Health Information.
Business Associate agrees to implement reasonable systems for the discovery and prompt reporting of any “breach” of “unsecured Protected Health Information” as those terms are defined by 45 C.F.R. §164.402 (hereinafter a “HIPAA Breach”). The parties acknowledge and agree that 45 C.F.R. §164.404, as described below in this Section 4, governs the determination of the date of a HIPAA Breach. In the event of any conflict between this Section 4 and the requirements set forth in HIPAA, HITECH, or their implementing regulations, the more stringent requirements shall govern.
Business Associate will, following the discovery of a HIPAA Breach, notify Covered Entity immediately and in no event later than five (5) business days after Business Associate discovers such HIPAA Breach, unless Business Associate is prevented from doing so by 45 C.F.R. §164.412 concerning law enforcement investigations. For purposes of reporting a HIPAA Breach to Covered Entity, the discovery of a HIPAA Breach shall occur as of the first day on which such HIPAA Breach is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate. Business Associate will be considered to have had knowledge of a HIPAA Breach if the HIPAA Breach is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing the HIPAA Breach) who is an employee, officer, or other agent of Business Associate. No later than fourteen (14) business days following a HIPAA Breach, Business Associate shall provide Covered Entity with sufficient information to permit Covered Entity to comply with the HIPAA Breach notification requirements set forth at 45 C.F.R. §164.400 et seq. Specifically, if the following information is known to (or can be reasonably obtained by) Business Associate, Business Associate will provide Covered Entity with: (i) contact information for individuals who were or who may have been impacted by the HIPAA Breach (e.g., first and last name, mailing address, street address, phone number, email address); (ii) a brief description of the circumstances of the HIPAA Breach, including the date of the HIPAA Breach and the date of discovery; (iii) a description of the types of unsecured Protected Health Information involved in the HIPAA Breach (e.g., names, social security number, date of birth, address(es), account numbers of any type, disability codes, diagnostic and/or billing codes and similar information); (iv) a brief description of what Business Associate has done or is doing to investigate the HIPAA Breach, mitigate harm to the individual impacted by the HIPAA Breach, and protect against future HIPAA Breaches; and (v) appoint a liaison and provide contact information for same so that Covered Entity may ask questions or learn additional information concerning the HIPAA Breach. Following a HIPAA Breach, Business Associate will have a continuing duty to inform Covered Entity of new information learned by Business Associate regarding the HIPAA Breach, including, but not limited to, the information described in items (i) through (v) above.
Section 5. Agreements with Third Parties. If Business Associate enters into an agreement with any agent or subcontractor that will have access to Protected Health Information that is received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, Business Associate shall enter into an agreement with such agent or subcontractor that requires such agent or subcontractor to be bound by the same restrictions, terms, and conditions that apply to Business Associate pursuant to this Agreement with respect to such Protected Health Information.
Section 6. Access to Information. Within five (5) days of a request by Covered Entity for access to Protected Health Information about an individual contained in a Designated Record Set, Business Associate shall make available to Covered Entity such Protected Health Information for so long as such information is maintained in the Designated Record Set. In the event that any individual requests access to Protected Health Information directly from Business Associate, Business Associate shall within two (2) days forward such request to Covered Entity. Any denials of access to the Protected Health Information requested shall be the responsibility of Covered Entity.
Section 7. Availability of Protected Health Information for Amendment. Within ten (10) days of receipt of a request from Covered Entity for the amendment of an individual’s Protected Health Information or a record regarding an individual contained in a Designated Record Set (for so long as the Protected Health Information is maintained in the Designated Record Set), Business Associate shall provide such information to Covered Entity for amendment and incorporate any such amendment into the Protected Health Information as required by 45 C.F.R. § 164.526. In the event that any individual requests an amendment of Protected Health Information directly from Business Associate, Business Associate shall within two (2) business days forward such request to Covered Entity.
Section 8. Accounting of Disclosures. Within ten (10) days of notice by Covered Entity to Business Associate that it has received a request for an accounting of disclosures of Protected Health Information regarding an individual, Business Associate shall make available to Covered Entity such information as is in Business Associate’s possession and is required for Covered Entity to make the accounting required by 45 C.F.R. § 164.528. At a minimum, Business Associate shall provide Covered Entity with the following information: (i) the date of the disclosure, (ii) the name of the entity or person who received the Protected Health Information, and, if known, the address of such entity or person, (iii) a brief description of the Protected Health Information disclosed, and (iv) a brief statement of the purpose of such disclosure, which includes an explanation of the basis for such disclosure. In the event that the request for an accounting is delivered directly to Business Associate, Business Associate shall, within two (2) business days, forward such request to Covered Entity. It shall be Covered Entity’s responsibility to prepare and deliver any such accounting requested. Business Associate hereby agrees to implement an appropriate recordkeeping process to enable it to comply with the requirements of this Section 8 and shall maintain the accounting records relating to any disclosure required to be included in the accounting described in this Section 8 for a period of six (6) years from and after the date of such disclosure.
Section 9. Availability of Books and Records. Business Associate hereby agrees to make its internal practices, books, and records relating to the use and disclosure of Protected Health Information received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, available to Covered Entity and the Secretary for purposes of determining Covered Entity’s and Business Associate’s compliance with the Privacy Standards, subject to attorney-client and other applicable privileges. Business Associate hereby agrees to give Covered Entity immediate notice if Business Associate is contacted by Secretary or any third party regarding Business Associate’s compliance with HIPAA and/or the Privacy Standards. Business Associate agrees to make any and all records in question immediately available to Covered Entity for review.
Section 10. Security Standards. Business Associate agrees to implement Administrative Safeguards, Physical Safeguards, and Technical Safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity as required by 45 C.F.R. Part 164, Subpart C.
III. OBLIGATIONS OF COVERED ENTITY
Section 1. Notice of Privacy Practices. Upon written request of Business Associate, Covered Entity shall provide Business Associate with a copy of its Notice of Privacy Practices (“NPP”) that Covered Entity provides or makes available to individuals pursuant to Section 164.520 of the Privacy Standards. If Covered Entity modifies or amends its NPP, Covered Entity shall so inform Business Associate and provide an updated/current copy of its NPP.
Section 2. Revocation/Restrictions. Covered Entity shall notify Business Associate as soon as practicable of any request for restrictions by an individual of the use or disclosure of the individual’s Protected Health Information that Covered Entity has agreed to accept. Covered Entity shall notify Business Associate of any change in, withdrawal, or revocation of any authorization or other permission(s) granted to Covered Entity by an individual for the use and/or disclosure of the individual’s Protected Health Information, to the extent that such change, withdrawal or revocation affects Business Associate.
IV. TERMINATION
Section 1. Automatic Termination. This Agreement will automatically terminate upon the termination or expiration of the Services Agreement between the parties.
Section 2. Material Breach by Business Associate. Notwithstanding any provision in this Agreement or the Services Agreement to the contrary, Covered Entity may, immediately and without penalty to Covered Entity, terminate this Agreement and the Services Agreement if Covered Entity determines that Business Associate has breached a material term of this Agreement. Alternatively, Covered Entity may choose to allow Business Associate to cure the alleged breach upon terms and conditions acceptable to Covered Entity, in its sole discretion. If any such breach is not thereafter cured within thirty (30) days, Covered Entity may terminate this Agreement and the Services Agreement without penalty to Covered Entity. If termination is not feasible, Covered Entity shall report Business Associate’s breach to the Secretary.
Section 3. Effect of Termination. Upon the termination of this Agreement and/or the Services Agreement, Business Associate shall, if feasible, return or destroy all Protected Health Information received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, that Business Associate or any contractor, agent or associate of Business Associate still maintains in any form and retain (and permit any such contractor, agent, or associate to retain) no copies of such information or, if such return or destruction is not feasible, extend (and cause any such contractor, agent, or associate to extend) the protections of this Agreement to such Protected Health Information and limit further uses and disclosures thereof to those purposes that make the return or destruction of the information infeasible.
V. MISCELLANEOUS
Section 1. Independent Contractors. In performing the services herein specified, Business Associate will be acting as an independent contractor. Business Associate and Covered Entity agree that neither Business Associate nor any of its directors, employees, or agents is an employee of Covered Entity. Nothing contained in this Agreement shall be construed to create a partnership or a joint venture or to authorize Business Associate to act as a general or special agent except as specifically set forth in this Agreement or the Services Agreement between the parties.
Section 2. Indemnification and Insurance. Without limiting any other provision of the Services Agreement or this Agreement, Business Associate hereby agrees to indemnify, hold harmless and defend Covered Entity from and against any and all claims, losses, liabilities, costs and other expenses incurred as a result of, or arising directly or indirectly out of or in connection with performance or failure to perform under the terms of this Agreement or the Privacy Standards. The obligation to indemnify shall survive the expiration or termination of this Agreement and/or the Services Agreement between the parties. Business Associate agrees that Business Associate shall maintain commercial insurance coverage sufficient to satisfy any claims or indemnification requirements potentially arising under the terms of this Agreement in amounts satisfactory to Covered Entity. Business Associate agrees to provide proof or certification of coverage upon request by Covered Entity.
Section 3. Assignment. Nothing contained in this Agreement shall be construed to permit the assignment or delegation by Business Associate of any rights or obligations hereunder and such assignment is expressly prohibited.
Section 4. Notices. Whenever under this Agreement, a provision is made for notice of any kind, it shall be deemed sufficient notice and service thereof if such notice is hand delivered or mailed to Covered Entity or Business Associate at the following addresses by certified mail, return receipt requested or by overnight delivery by a nationally recognized overnight courier (any notice sent by mail or overnight courier shall be deemed to be given on the date that it is received or rejected):
If to Covered Entity:
@{Company Name:36}
@{Address (Street Address):34.1}
@{Address (Address Line 2):34.2}
@{Address (City):34.3}, @{Address (State / Province):34.4} @{Address (ZIP / Postal Code):34.5}
@{Address (Country):34.6}
If to Business Associate:
Scribekick LLC
501 East Franklin St, Suite 305
Richmond, VA 23219
ATTN: Bradley Barr
Each party may change the person to whom and the address to which such communications are to be directed by giving written notice to the other party in the manner provided in this Section.
Section 5. Governing Law; Venue. This Agreement shall be governed by the federal law and the laws of the Commonwealth of Virginia. Any arbitration authorized hereunder shall be conducted in either the General District Court or the Circuit Court of the County of Chesterfield, Virginia. Exclusive venue for any other dispute arising hereunder shall be resolved in the state or federal courts in the County of Chesterfield, Virginia or its immediately surrounding counties.
Section 6. Section Heading; Preamble. The section headings in this Agreement are for reference purposes only and shall not be given any legal effect or affect in any way the meaning or interpretation of this Agreement. The preamble language of this Agreement shall be considered part of this Agreement and shall be considered in the interpretation hereof.
Section 7. Entire Agreement. This Agreement supersedes all previous contracts or agreements between the parties with respect to the subject matter hereof and constitutes the entire agreement between the parties related to this subject matter.
Section 8. Amendments. This Agreement, and any provision hereof, may be amended, modified or deleted only by written agreement of the parties. The parties agree to take such action to amend this Agreement from time to time as is necessary for Covered Entity to comply with the Privacy Standards and all other applicable laws or regulations.
Section 9. Severability. If any clause or provision herein shall be judged invalid or unenforceable by a court of competent jurisdiction or by operation of any applicable law, the validity of any other clause or provision shall not be affected and the remainder of this Agreement and the Services Agreement between the parties shall remain in full force and effect. Each of the provisions of this Agreement shall be enforceable independent of any other provision of this Agreement and independent of any other claim or cause of action.
Section 10. Survival. The provisions of this Agreement, which, by their terms, contain continuing obligations, shall survive the termination of this Agreement. The respective obligations of Business Associate as well as the effects of termination of this Agreement, including the return of all Protected Health Information, and indemnification, shall specifically survive termination of this Agreement.
Section 11. Waiver. The failure or delay of any party to enforce or pursue any right or remedy existing pursuant to this Agreement shall not be deemed a waiver of such right or remedy and shall not limit such party’s ability to pursue or enforce such right or remedy or any future right or remedy.
Section 12. Interpretation. This Agreement shall be interpreted as broadly as necessary to implement and comply with HIPAA, HITECH, and the Privacy Standards. The parties hereby agree that any ambiguity in this Agreement shall be resolved in favor of a meaning that complies with HIPAA, HITECH, and the Privacy Standards.
IN WITNESS WHEREOF, the parties hereto have signed this Agreement as of the Effective Date.