I have an invitation code Click Here.

BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement (this “Agreement”) is by and between the HIPAA Covered Entity who signed the Terms of Service (the “Covered Entity”) and Aidin, Inc. (“Business Associate”), and is effective upon the date the Covered Entity signed the Terms of Service (the “Effective Date”). Covered Entity and Business Associate shall be referred collectively herein as the “Parties” and, individually, each a “Party.”

RECITALS

WHEREAS, the Parties have entered into that certain Terms of Service (the “Underlying Agreement”), pursuant to which the Business Associate may provide certain services (“Services”) to Covered Entity;

 

WHEREAS, as a result of providing the Services, Business Associate may have access to certain Protected Health Information (defined below) and Business Associate may be considered a “business associate” of Covered Entity as defined in the HIPAA Rules (defined below); 

 

WHEREAS, the Parties enter into this Agreement for the purposes of complying with the HIPAA Rules (defined below); and

 

WHEREAS, the Parties wish to address the requirements of the HIPAA Rules and ensure that Business Associate will establish appropriate safeguards, including without limitation certain administrative requirements with respect to such Protected Health Information.

 

             NOW, THEREFORE, in consideration of the foregoing and the covenants and promises contained in this Agreement and the Underlying Agreement, the Parties agree as follows.

1. DEFINITIONS

1.1    “Business Associate” shall generally have the same meaning as the term “business associate” at 45 C.F.R. § 160.103 and, in reference to this Agreement, shall mean the entity defined above as the Business Associate.

1.2    “Covered Entity” has the same meaning as the term “covered entity” at 45 C.F.R. § 160.103 and, in reference to this Agreement, shall mean the entity defined above as the Covered Entity. 

1.3    “ePHI” means PHI transmitted or maintained in Electronic Media.

1.4    “Minimum Necessary” means the minimum amount of PHI necessary to accomplish the intended purpose of the Use, Disclosure, or request or the amount of PHI described and defined by HHS from time to time as the “minimum necessary.”

1.5    “Protected Health Information” or “PHI” shall have the same meaning as the term “protected health information” at 45 C.F.R. § 160.103, limited to the protected health information created, received, maintained or transmitted by Business Associate from or on behalf of Covered Entity, including, but not limited to ePHI.

1.6    “Subcontractor” shall generally mean a subcontractor of Business Associate to whom Business Associate delegates a function, activity, or service, other than in the capacity of a member of the workforce of Business Associate.

1.7    Other Terms. Capitalized terms not specifically defined in this Agreement shall have the meanings attributed to them under HIPAA.

2. PRIVACY OF PROTECTED HEALTH INFORMATION

2.1 Permitted Uses & Disclosures.

(a)  Business Associate will not Use or further Disclose PHI other than to perform the Services set forth in the Underlying Agreement, as permitted or required by this Agreement or as Required by Law.  Business Associate shall limit its Use, Disclosure or request of PHI, to the extent practicable, to a Limited Data Set or to the Minimum Necessary.

(b)  Business Associate may Use or Disclose PHI for the proper management and administration of Business Associate or to carry out the legal responsibilities of Business Associate provided that, with respect to any such Disclosure, (i) the Disclosure is Required by Law; or (ii) Business Associate obtains reasonable assurances from the person to whom the PHI is Disclosed that it will be kept confidential and Used or further Disclosed only as Required by Law or for the purpose for which it was Disclosed to the person, and the person agrees to notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

(c)  Business Associate may not use or disclose PHI in a manner that would violate the Privacy Rule if Used or Disclosed by Covered Entity. Business Associate may provide data aggregation services to Covered Entity in a manner consistent with the HIPAA Rules. 

(d)  Except as otherwise set forth in the Underlying Agreement, Business Associate may not, and may not permit its agents or subcontractors to, de-identify PHI or Use or Disclose de-identified data derived from PHI without the prior written consent of Covered Entity.  To the extent Covered Entity consents to such Use, Business Associate may only Use and Disclose PHI as described above if such Use and Disclosure is in compliance with 45 C.F.R. § 164.504(e).

2.2 Safeguards for the Protection of PHI. 

 Business Associate shall comply with all requirements of HIPAA applicable to a “business associate.” Business Associate shall use reasonable and appropriate administrative, physical and technical safeguards in accordance with Subpart C of 45 C.F.R. § 164 et seq. to prevent the Use or Disclosure of PHI other than provided for by this Agreement and to protect the Confidentiality, Integrity and Availability of ePHI that it receives, maintains, creates, or transmits to or on behalf of the Covered Entity. Safeguards implemented by Business Associate shall be informed by recognized security industry frameworks (e.g., NIST or ISO 2700 series), as reasonably appropriate to Business Associate’s size and operations.

2.3 Reporting

Reporting of Unauthorized Uses or Disclosures and Unauthorized Attempts to Use or Disclose.

(a)  Breach and Other Privacy Rule Violations.  With the exception of law enforcement delays that satisfy the requirements under 45 C.F.R. § 164.412 or as otherwise required by applicable State law, Business Associate shall report to Covered Entity any Breach of unsecured PHI as required by 45 C.F.R. § 164.410 within five (5) days following the date on which Business Associate learns of such occurrence.  In its report to Covered Entity, Business Associate will identify, at a minimum, to the extent known, (i) the nature of the nonpermitted Use or Disclosure; (ii) the PHI Used or Disclosed; (iii) the party or parties who made the non-permitted Use or received the non-permitted Disclosure; (iv) what corrective action Business Associate took or will take to prevent further non-permitted Uses or Disclosures; (v) what Business Associate did or will do to mitigate any harmful effect of the non-permitted Use or Disclosure; (vi) such other information, including a written report, as Covered Entity may request; and (vii) such other information as HHS may prescribe by regulation.  Business Associate shall reasonably cooperate with Covered Entity to determine whether any Breach requires notice to Individuals, and will reasonably cooperate with Covered Entity as may be necessary to allow Covered Entity to provide notification of such Breach to Individuals as required by the Breach Notification Rule.  

(b)  Security Incidents.  Business Associate shall report all Security Incidents to Covered Entity, in accordance with the following reporting procedures for (i) Security Incidents that result in unauthorized access, Use, Disclosure, modification or destruction of ePHI or interference with system operations (“Successful Security Incidents”); and (ii) Security Incidents that do not result in unauthorized access, Use, Disclosure, modification or destruction of ePHI or interference with system operations (“Unsuccessful Security Incidents”).

(c)  Successful Security Incidents.  Business Associate shall provide notice to Covered Entity of any Successful Security Incident of which it becomes aware within five (5) days. At a minimum, such report shall contain the following information, to the extent known: (A) date and time when the Security Incident occurred and/or was discovered; (B) cause (e.g., phishing, malware, network intrusion); (C) names of systems, programs, or networks affected by the Security Incident; (D) preliminary impact analysis; (E) description of and scope of ePHI Used, Disclosed, modified, or destroyed; and (E) any mitigation steps taken by Business Associate. 

(d)  Unsuccessful Security Incidents. The Parties acknowledge and agree that this Section 2.3 constitutes notice by Business Associate to Covered Entity of the ongoing existence and occurrence of attempted but Unsuccessful Security Incidents, and no additional notice or report of any specific Unsuccessful Security Incident shall be required.

2.4 Use of Subcontractors.

To the extent that Business Associate uses one or more Subcontractors to perform its obligations under any agreement with Business Associate and such Subcontractors create, receive, maintain or transmit PHI on behalf of Business Associate, Business Associate shall cause each such Subcontractor to agree to comply with the applicable provisions of the Security Rule and to agree to substantially similar restrictions, conditions and requirements that apply to the Business Associate with respect to such PHI.

2.5 No Off-Shoring of PHI.

Absent prior written approval of Covered Entity, Business Associate shall neither provide access nor transmit Covered Entity’s PHI, for any purpose, to any person or entity located outside the borders and jurisdiction of the United States, including to employees, agents or other representatives of that person or entity.

2.6 Training.

Business Associate shall provide training regarding the HIPAA Privacy, Security and Breach Notification Rules to each member of its Workforce, as necessary and appropriate for each Workforce member to carry out his assigned duties, within thirty (30) days of the Workforce member’s start date. Following the initial training, Business Associate shall provide periodic security reminders; annual refresher training; and training regarding any material changes in applicable law regarding individually identifiable health information within thirty (30) days of the change’s effective date. Business Associate shall maintain documentation verifying completion of any training as required by applicable law and for a period of not less than six (6) years.

2.7 Authorized Access to PHI.

To the extent that Business Associate maintains PHI in a Designated Record Set, Business Associate shall provide Covered Entity with access to such PHI in accordance with Covered Entity’s written request no later than ten (10) business days after receipt of such written request by Business Associate pursuant to 45 C.F.R. § 164.524.

2.8 Amendment to PHI.

To the extent that Business Associate maintains PHI in a Designated Record Set, Business Associate shall amend such PHI in accordance with Covered Entity’s written request no later than thirty (30) business days after receipt of such request by Business Associate pursuant to 45 C.F.R. § 164.526.

2.9 Accounting of Disclosures of PHI.

(a)  Disclosure Tracking.  Business Associate shall retain a record of each disclosure of PHI that Business Associate makes to a third party to the extent required by HIPAA, including (i) the disclosure date; (ii) the name and (if known) address of the person or entity to whom Business Associate made the disclosure; (iii) a brief description of the PHI disclosed; and (iv) a brief statement of the purpose of the disclosure.

(b)  Disclosure Accounting.  Business Associate shall provide an accounting of disclosure of PHI to Covered Entity (i) no later than thirty (30) calendar days after receipt of a written request for such disclosure accounting by Covered Entity pursuant to 45 C.F.R. § 164.528, or (ii) in accordance with HIPAA.

2.10 Performance of Obligation of Covered Entity.

 To the extent Business Associate is to carry out an obligation of Covered Entity under the Privacy Rule, Business Associate shall comply with the requirements of the Privacy Rule that apply to Covered Entity in performance of such obligation and may not Use or Disclose PHI in a manner that would violate the Privacy Rule if done by Covered Entity.

2.11 Inspection of Books and Records.

Business Associate shall make its internal practices, books, and records, relating to the Use and Disclosure of all such PHI, available to HHS to determine Business Associate’s or Covered Entity’s compliance with HIPAA.

2.12 Obligations of Covered Entity.

Covered Entity shall not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the Privacy Rule or Security
Rule Standards if done by Covered Entity; except for the management and administrative and legal responsibilities of Business Associate under this Agreement. Covered Entity shall promptly notify Business Associate of any restriction on the Use or Disclosure of PHI to which Covered Entity has agreed in accordance with the relevant provisions of HIPAA, to the extent that such restriction may affect Business Associate’s Use or Disclosure of PHI. In addition, Covered Entity shall promptly notify Business Associate of any changes in, or revocation of, permission by an Individual to Use or Disclose such Individual’s PHI to the extent that such change may affect Business Associate’s Use or Disclosure of PHI.

3. TERM AND TERMINATION

3.1    Term.  The term of this Agreement shall commence as of the effective date of the Underlying Agreement and shall continue in effect until termination of the Underlying Agreement.

3.2    Termination for Breach.  Upon either Party’s knowledge of a material breach of this Agreement by the other Party, the non-breaching Party shall provide written notice of such breach to the breaching Party and shall afford the breaching Party an opportunity to cure the breach within thirty (30) days of receipt of such notice. If the breaching Party fails to cure the breach within such thirty (30) day period, the non-breaching Party may terminate this Agreement and, to the extent the Underlying Agreement cannot be performed without the Use or Disclosure of PHI, the Underlying Agreement, upon written notice to the breaching Party. If cure of the material breach is not possible, the non-breaching Party may terminate this Agreement and, to the extent the Underlying Agreement cannot be performed without the Use or Disclosure of PHI, the Underlying Agreement, immediately upon written notice to the breaching Party. Termination pursuant to this Section 3.2 shall trigger the obligations set forth in Sections 3.3 and 3.4 of this Agreement.

3.3    Return or Destruction of PHI.  Upon termination of the Underlying Agreement for any reason, to the extent feasible, Business Associate shall return or destroy all PHI or any copies thereof received from Covered Entity that Business Associate or its agents or Subcontractors still maintain in any form.  Business Associate shall notify Covered Entity in writing of the method of disposition selected. Within ten (10) business days of receiving a request from Covered Entity, Business Associate’s authorized representative shall provide written certification to Covered Entity that all PHI has been returned or destroyed in compliance with this Agreement and in accordance with industry standards.

3.4    Continuing Privacy and Security Obligation.  If Business Associate determines that return or destruction is infeasible, Business Associate or its agents or Subcontractors shall: (i) provide to Covered Entity notification of the conditions that make return or destruction infeasible; (ii) continue to extend the protections of this Agreement to such information; and (iii) limit further Use of such PHI to those purposes that make the return or destruction of such PHI infeasible.

3.5    Survival.  The obligations of Business Associate under this Article shall survive the termination of the Underlying Agreement solely with respect to PHI Business Associate retains in accordance with this Article.

4. MISCELLANEOUS

4.1    Applicability.  This Agreement shall be applicable to PHI created, received, maintained or transmitted by Business Associate from or on behalf of Covered Entity. 

4.2       Amendments.  This Agreement may not be modified, nor shall any provision hereof be waived or amended, except in a writing duly signed by authorized representatives of the Parties. The Parties acknowledge that state and federal laws relating to data security and privacy are rapidly evolving and that amendment of this Agreement may be required to provide for procedures to ensure compliance with such developments.  The Parties specifically agree to take such action as is necessary to implement the standards and requirements of HIPAA and other applicable laws relating to the security or confidentiality of PHI. 

4.3    No Third-Party Beneficiaries.  Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than Covered Entity, Business Associate and their respective successors or assigns, any rights, remedies, obligations or liabilities whatsoever.

4.4    Conflicts. The terms and conditions of this Agreement will override and control any conflicting term or condition of any other agreements that may be in place between the Parties; provided, however, that should any of the terms or conditions contained herein conflict with those contained in the Underlying Agreement, the Underlying Agreement shall control. All non-conflicting terms and conditions of this Agreement and any other agreement between the Parties remain in full force and effect. For the avoidance of doubt, the limitation of liability provision contained in the Underlying Agreement shall apply to this Agreement.

4.5    Construction. This Agreement shall be construed as broadly as necessary to implement and comply with HIPAA. Any ambiguity in this Agreement shall be resolved in favor of a meaning that complies with HIPAA. 

4.6 Subpoenas.  Each Party shall provide written notice to the other Party of any subpoena or other legal process it receives seeking PHI (a) received by Business Associate from Covered Entity; (b) created, received, maintained or transmitted by Business Associate on behalf of Covered Entity; or (c) otherwise relating to Business Associate’s services under the Underlying Agreement.  Such written notice shall be provided within three (3) business days of receipt of a subpoena or other legal process. 

4.7    Notices.  Except as otherwise provided for in this Agreement, all notices required to be given to either Party under this Agreement will be in writing and sent in accordance with the notice provisions in the Underlying Agreement.