1. Definitions:
The following terms used in this Business Associate Agreement ("BAA") shall have the meanings set forth in the HIPAA Rules (45 CFR Parts 160 and 164): Breach, Business Associate, Covered Entity, Designated Record Set, Disclosure, Electronic Protected Health Information (ePHI), HIPAA Rules, Individual, PHI, Protected Health Information, Required By Law, Secretary, Security Incident, State, Subcontractor, Unsecured PHI. Any term not otherwise defined in this BAA shall have the meaning ascribed to it in the HIPAA Rules. "Business Associate" means Vectis Revenue Group, LLC. "Covered Entity" means the clinic or provider entity executing this BAA through the Vectis registration process.
2. Obligations and Activities of Business Associate:
Business Associate agrees not to Use or Disclose PHI other than as permitted or required by this BAA or as Required By Law. Business Associate shall Use appropriate safeguards to prevent Use or Disclosure of PHI other than as provided for by this BAA. Business Associate shall comply with the obligations applicable to it under Subtitle A of Title XIII of the HITECH Act and the HIPAA Security Rule (45 CFR Part 164, Subpart C) with respect to ePHI. Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity. Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees to the same restrictions and conditions that apply to Business Associate with respect to such PHI. Business Associate shall report to Covered Entity any Security Incident of which it becomes aware without unreasonable delay and in no case later than sixty (60) calendar days after discovery. Business Associate shall report to Covered Entity any Use or Disclosure of PHI not provided for by this BAA of which Business Associate becomes aware without unreasonable delay and in no case later than sixty (60) calendar days after discovery. Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a Use or Disclosure of PHI by Business Associate or its Subcontractors in violation of the requirements of this BAA. Business Associate shall maintain written documentation of all Security Incidents and any Use or Disclosure of PHI not permitted by this BAA for a period of not less than six (6) years from the date of its creation or the date when it last was in effect, whichever is later.
3. Permitted Uses and Disclosures by Business Associate:
Business Associate may only Use or Disclose PHI as necessary to perform Services for Covered Entity as described in the underlying Master Services Agreement or Order Form, or as Required By Law. Business Associate may not Use or Disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by Covered Entity. Business Associate may Use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that any Disclosure for such purposes is limited to the minimum necessary and is subject to reasonable efforts to protect against further Use or Disclosure. Business Associate may Use PHI to create de-identified data in accordance with 45 CFR § 164.514(a)-(c), and such de-identified data is not subject to this BAA. Business Associate may Use or Disclose PHI for data aggregation purposes relating to the health care operations of Covered Entity. Business Associate shall not Use or Disclose PHI for any commercial purpose not permitted by this BAA or the underlying agreement, including the sale of PHI or the use of PHI for marketing, without the prior written authorization of Covered Entity.
4. Safeguards:
Business Associate shall implement and maintain administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the ePHI it creates, receives, maintains, or transmits on behalf of Covered Entity, in compliance with the HIPAA Security Rule (45 CFR Part 164, Subpart C). Such safeguards shall include, at a minimum: (a) administrative safeguards including risk analysis, risk management, sanction policies, and workforce training; (b) physical safeguards including facility access controls, workstation use and security, and device and media controls; and (c) technical safeguards including access controls, audit controls, integrity controls, transmission security, and encryption where appropriate. Business Associate shall document and maintain the safeguards implemented hereunder and shall review and update such safeguards in response to environmental or operational changes affecting the security of ePHI.
5. Breach Notification by Business Associate:
Business Associate shall notify Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery of a Breach of Unsecured PHI in accordance with 45 CFR §§ 164.410 and 164.404. Such notification shall include, to the extent known: (a) a description of what happened, including the identification of any individuals whose PHI was involved; (b) the steps individuals should take to protect themselves from potential harm; (c) what Business Associate is doing to investigate, mitigate, and protect against further Breaches; and (d) contact procedures for individuals to ask questions or learn additional information. Business Associate shall provide the information necessary for Covered Entity to fulfill its obligations under 45 CFR §§ 164.404, 164.406, and 164.408. Business Associate shall also notify Covered Entity of any Security Incident of which it becomes aware without unreasonable delay. The parties acknowledge and agree that the discovery of a Security Incident is not a Breach of Unsecured PHI, and that the notification obligations for a Security Incident are separate from and independent of the notification obligations for a Breach.
6. Subcontractors:
Business Associate shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such PHI. Business Associate remains liable for the acts and omissions of its Subcontractors to the same extent it would be liable for its own acts and omissions under this BAA. Business Associate shall provide a copy of its Subcontractor agreements involving PHI to Covered Entity upon request. Business Associate shall terminate any Subcontractor agreement if Business Associate determines that the Subcontractor has violated a material term of such agreement or this BAA and has failed to cure such violation within a reasonable period of time.
7. Termination and Return/Destruction of PHI:
This BAA shall terminate upon the earlier of: (a) the termination of the underlying Master Services Agreement or Order Form between the parties; or (b) the mutual written agreement of the parties. Upon termination of this BAA for any reason, Business Associate shall return or, if return is not feasible, destroy all PHI received from, or created or received by Business Associate on behalf of, Covered Entity within sixty (60) days. Business Associate shall retain no copies of the PHI. If return or destruction is not feasible, Business Associate shall provide written notification of the conditions making it infeasible, extend the protections of this BAA to the PHI, and limit further Uses and Disclosures to those purposes, returning or destroying it at the earliest opportunity. Business Associate shall provide written certification to Covered Entity that it has complied with these obligations. Notwithstanding the foregoing, Business Associate may retain PHI where Required By Law, provided the protections of this BAA continue to apply. Either party may terminate this BAA and the underlying agreement if the other party has materially breached this BAA and has failed to cure such breach within thirty (30) days of written notice.
8. Miscellaneous Provisions:
This BAA shall be construed as broadly as necessary to comply with the HIPAA Rules and the HITECH Act. Any ambiguity in this BAA shall be resolved in favor of a meaning that complies with the HIPAA Rules. If any provision of this BAA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. The parties acknowledge that the HIPAA Rules and the HITECH Act may be amended from time to time, and Business Associate shall comply with such amendments as they become effective. This BAA may not be amended except by a written agreement signed by both parties. This BAA shall be governed by the laws of the State of Arizona, without regard to its conflict of laws principles. Any dispute arising out of or relating to this BAA shall be resolved in the state or federal courts located in Maricopa County, Arizona. This BAA shall be binding upon and inure to the benefit of the parties and their respective successors and permitted assigns. Neither party may assign this BAA without the prior written consent of the other party. This BAA constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior or contemporaneous agreements, understandings, and communications, whether written or oral, with respect to such subject matter. This BAA shall be effective as of the date the Covered Entity accepts this BAA through the Vectis registration process. The parties acknowledge that this BAA is entered into pursuant to 45 CFR § 164.504(e) and is intended to comply with the requirements of the HIPAA Rules and the HITECH Act.