COMPLETE_WITH_DOCUSIGN_MERCY_CARE_AMENDMENT_.PDF

Maricopa County — Formal (2025-09-12)

View PDF Item 60 Meeting page

Extracted text (via pymupdf) 46759 characters
AMENDMENT No. 2 
To 
MEMORANDUM OF UNDERSTANDING 
Between 
 
MERCY CARE 
& 
MARICOPA COUNTY, ARIZONA 
 
 
WHEREAS, Maricopa County (“County”) and Mercy Care (“Contractor”) entered into a Memorandum of 
Understanding, executed February 8th, 2024, for the purpose of establishing collaborative protocol for effective 
communication, coordination, and continuity of care for individuals eligible for services provided by Mercy Care who 
are also served by Correctional Health Services (the “MOU”). 
 
WHEREAS, the County and Mercy Care have agreed to modify this MOU. 
NOW, THEREFORE, the parties hereby agree to the following provision: 
Additions are in bold, and deletions are in strikethrough: 
Sections III-C-1,2,5,6, & 8: 
1. The Mercy Care Point of Contact or designee will complete a Justice Transition Form (JTF) for 
SMI members and GMHSU members with designated chronic conditions and send the JTF to 
CHS: CHS will send a weekly Continuity of Care (COC) Report to Mercy Care. 
 
a. CHS will confirm diagnosis/chronic condition in the EHR. 
b.  CHS will complete the CHS section of the JTF and return it to Mercy Care – scan it 
into the EHR. 
 
2. If CHS identifies newly diagnosed chronic care conditions, CHS will complete a JTF and send 
it to the Mercy Care Point of Contact or designee. CHS will send a Justice Transition Notice 
(JTN) at the time the condition is identified for patients who are pregnant, HIV+, Hep C+ 
and OTP/MAT. 
 
5. An Appointment will be made with member’s Primary Care Physician (PCP) to occur within 7 
days of release. An appointment will be made with an appropriate physical or behavioral 
health provider based on individual needs and preferences within 7 days. 
6. The Mercy Care Point of Contact or designee will forward to CHS an “Introduction Letter,” via 
secure email, with the following information: For General Mental Health (GMH) members 
referred to Targeted Investment Program - Justice or PCP, The Mercy Care Point of 
Contact or designee will forward to CHS an “Introduction Letter,” via secure email, with 
the following information: 
 
8. CHS and the Mercy Care Point of Contact or other health staff may coordinate special needs 
prior to jail release (such as courtesy release third-party release, medical equipment, or specific 
medications). 
 
ALL OTHER TERMS AND CONDITIONS REMAIN UNCHANGED. If there is any conflict between the 
terms of the MOU and this Amendment, in all such events, the terms of this Amendment shall control. 
 
This Amendment is subject to cancellation pursuant to A.R.S. § 38-511. 
IN WITNESS WHEREOF, this Amendment is executed on the date set forth below when executed by both Parties' 
Authorized Representative. 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

MERCY CARE 
MARICOPA COUNTY 
BOARD OF SUPERVISORS 
 Tad Gary 
 
Tad Gary (Sep 18, 2025 07:15:08 PDT) 
 
Authorized Signature 
Authorized Signature 
 
Tad Gary, Chief Executive Officer 
 
Printed Name and Title 
Chairman, Board of Supervisors 
 
09/18/2025 
Date 
Date 
 
ATTEST: 
 
Clerk of the Board 
Date:  
 
 
Approved as to form: 
 
Deputy County Attorney 
 
Date:  
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C
9/23/2025

Business Associate Web Portal Agreement 
Page 1 of 10 
 
 
 
Business Associate Secure Web Portal 
Government Agency 
Registration Form 
 
Thank you for your interest in registering for the Mercy Care Business Associate web portal. We are 
committed to protecting the privacy of our members and Business Associates who use our website. 
During registration, we ask you for specific information about you and your Authorized Representatives. 
We will only use the information you submit to us for the purpose of managing your access to the 
website.  We do not disclose any of the information you provide to us to any outside parties, except to 
manage the health plan or when applicable law may require it. 
 
Registration Instructions: The information below and acceptance of the attached agreement is required 
to complete registration. 
 
Business Associate Name: Maricopa County Correctional Health Services 
Business Associate Tax ID # (TIN) (if applicable): 86-6000472 
We caution against using your SSN in lieu of a TIN, as it presents unnecessary risks to your identity 
Address: 301 W Jefferson Street, 9th Floor 
City: Phoenix 
State: AZ 
Zip: 85003 
Phone #:  602-506-3561 
Fax #: N/A 
 
Business Associate must designate one primary representative (see Business Associate Web Portal 
Agreement attached for full definition).  Please indicate the full name and contact information of the 
primary representative below: 
 
Primary Representative Name:  Julie Wonsowicz 
Address:    2680 S 28th Drive  
City: Phoenix 
State: AZ 
Zip: 85009 
Phone #: 602-876-1581 
Fax #: N/A 
E-Mail address at Business Associate’s office:  Julie.Wonsowiczmoore@Maricopa.Gov 
 
To submit a request for registration, please email your completed form, agreement and executed 
Business Associate Agreement to Mercy Care at BAWebPortal@mercycareaz.org.     
 
 
 
 
 
 
 
 
 
 
 
 
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 2 of 10 
 
Business Associate’s Web Portal Agreement 
 
 
Introduction 
 
This Business Associate’s Web Portal Agreement (“Agreement”) contains the terms and conditions that 
govern the use of this web portal service by Business Associate to access information relating to Mercy 
Care member/enrollee eligibility information.   
 
Definitions 
 
 When used in this Agreement, all capitalized terms shall have the following meanings: 
• “Administrator” means any Aetna administrator, such as Aetna Medicaid Administrators, LLC, 
and any owners, affiliates or direct or indirect subsidiaries that administer or maintain the Service 
for a Plan.   
 
• “Authorized Representative” means an Employee of Business Associate that Business Associate 
has authorized to use the Web Portal Service under this Agreement on Business Associate’s 
behalf.  Business Associate shall identify each authorized representative on the roster form 
provided in Attachment A to this agreement.   Addition or removal of an Authorized 
Representative(s) shall be submitted, in writing, by the Primary Representative and shall include 
the information requested in Attachment A. 
 
• “Business Associate” means the individual or entity identified on the current Business Associate 
Agreement (“BAA”) attached to this Agreement as Attachment B. 
 
• “Government Sponsor” means a state agency or other governmental entity authorized to offer, 
issue and/or administer one or more plans, and which, to the extent applicable, has contracted 
with Plan to administer all or a portion of such Plan(s). 
 
• “Member/enrollee” includes, a person determined to be Seriously Mentally Ill in accordance with 
policies issued by the Arizona Health Care Cost Containment System (AHCCCS) and eligible to 
receive behavioral health services paid for, in whole or in part, from funds available to the 
AHCCCS designated Regional Behavioral Health Authority (RBHA) 
 
• “Plan” means “Mercy Care” and any owners, affiliates or direct or indirect subsidiaries. 
 
• “Primary Representative” means the Authorized Representative in the Business Associate’s office 
who has responsibility for requesting access, removing access and maintaining the names of 
Business Associate’s Authorized Representatives  
 
• “Service” means the web portal service under this Agreement and the website that supports it. 
 
 
 
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 3 of 10 
 
Use of the Web Portal Service 
 
The Service provides internet access to information on the Plan’s members’/enrollees’ eligibility and 
enrollment.  The Plan and its Administrator agree to permit Business Associate and its Primary 
Representative and Authorized Representatives to use the Service, provided they comply with the terms 
and conditions of this Agreement.  Business Associate shall use the Service solely in connection with its 
obligations under state and federal law, including court orders, for the provision of judicial and/or health 
care services to Plan members/enrollees.  Business Associate shall not access the records or 
information of Plan members/enrollees to whom the Business Associate does not provide judicial 
and/or health care services. The Primary Representative and each Authorized Representative shall use 
the Service solely in the course and scope of employment or agency with Business Associate.   Business 
Associate shall use, and shall cause the Primary Representative and each Authorized Representative to 
use, the Service subject to the following: 
 
1. The terms and conditions of this Agreement; and 
2. The applicable provisions of the BAA, including, but not limited to, use and disclosure of 
Protected Health Information under the HIPPA Privacy Standards, and member/enrollee 
eligibility and enrollment verification for the purposes identified in this Agreement. 
3. In the event of a conflict between a term and condition under this Agreement and a provision 
under the BAA, the terms of the BAA shall govern. 
 
Business Associate shall require the Primary Representative and each Authorized Representative to:  
 
1. Keep confidential and not disclose the Business Associate’s Service password to any person 
except Business Associate or the Primary Representative;  
2. Use the Service solely in connection with Business Associate’s judicial or health care services to 
the Plan’s members/enrollees and within the course and scope of employment or agency with 
Business Associate; and 
3. Use the Service pursuant to the terms and conditions of this Agreement. 
 
Upon learning that any Primary Representative or Authorized Representative has violated (1), (2) or 
(3) identified above, changes job responsibilities such that access is no longer necessary, or no longer 
works for or represents Business Associate, Business Associate shall immediately notify the Plan 
within 24 hours. The Plan will revoke such Primary Representative’s or Authorized Representative’s 
authority to use the Service.    
 
Changes to the Web Portal Service or This Agreement 
 
Administrator may, at any time, make changes to the Service, the terms and conditions in this 
Agreement, or any other policies or conditions that govern the use of the Service at any time.  Business 
Associate should review the Service and these terms and conditions periodically for any updates or 
changes. Business Associate’s continued access or use of the Service site shall be deemed Business 
Associate’s notification and acceptance of these changes.  
 
 
 
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 4 of 10 
 
No Warranties or Liabilities 
There is no implied warranty of any kind under this Agreement, including any representation of accuracy, 
completeness, or appropriateness or fitness for a particular part of the Service, and non-infringement.  
Business Associate assumes full responsibility for using the Service, and understands and agrees that 
neither the Plan nor Administrator are responsible or liable for any claim, loss, or damage resulting from, 
or related to, Business Associate’s use.  Business Associate uses the Service at its own risk, and agrees to 
use the Service on an “AS IS” and an “AS AVAILABLE” basis.  Neither Plan nor Administrator will be liable 
for any delay, difficulty in use, inaccuracy or incompleteness of information, computer virus, malicious 
code, loss of data, compatibility issues, or otherwise.  Plan and Administrator will not be liable for any 
direct, indirect, incidental, consequential, or punitive damages arising out of the Business Associate’s 
use of, or access to, the Service, or any link provided to another site, even if Plan or Administrator was 
advised of the possibility of such damages, or even if such damages were foreseeable. 
 
Ownership, License and Restrictions on Use of Materials 
 
All rights, title and interest (including all copyrights, trademarks and other intellectual property rights) 
in the Service belong to the Plan or Administrator.  In addition, the names, images, pictures, logos, and 
icons are proprietary marks that belong to the Plan or Administrator.  Except as expressly provided 
below, nothing contained herein shall be construed as conferring any license or right, by implication, 
estoppels or otherwise, under copyright or other intellectual property rights. 
 
The Business Associate is hereby granted a nonexclusive, nontransferable, limited license to view and 
use information retrieved from the Service solely in connection with its obligations under state and 
federal law, including court orders, for the provision of judicial and/or health care services to Plan 
members/enrollees.   
 
Except as expressly provided above, no part of the information in or about the Service, including but 
not limited to materials retrieved from it and the underlying code, may be reproduced, republished, 
copied, transmitted, or distributed in any form or by any means.  In no event shall materials from this 
site be stored in any information storage and retrieval system without prior written permission from 
Administrator or Plan. 
 
Business Associate’s use of the site allows Plan and Administrator to gather certain limited information 
about the Business Associate and its usage of the Service. Business Associate agrees and consents to the 
use of such information in aggregated form. 
 
Site System Integrity 
 
The Business Associate may not use any device, software routine or agent to interfere or attempt to 
interfere with the proper working of the Service. The Business Associate may not take any action which 
imposes an unreasonable or disproportionately large load on Administrator’s or Plan’s infrastructure. 
The Business Associate may not disclose or share its password to or with third parties, or allow its 
password to be used, for any unauthorized purpose. The Business Associate shall take reasonable 
precautions to secure its password from any unauthorized use.  The Business Associate may not attempt 
to log in with a username or password other than its own.  The Business Associate shall require its 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 5 of 10 
 
Primary Representative and Authorized Representative to take the same precautions and follow the 
same requirements identified in this Agreement. 
 
Continuous, uninterrupted access to the Service is not guaranteed.  Numerous actions beyond our 
control may interfere with the Service. 
 
Confidential Information 
 
“Confidential Information” is any information that identifies a member and relates to the member’s 
participation in a Plan, the member’s physical or mental health or condition, the provision of health care 
to the member, or payment for the provision of health care to the member.  Confidential information 
includes, without limitation, “individually identifiable health information,” as defined in 45 C.F.R. § 
160.103 of HIPAA and “non-public personal information,” as defined in laws or regulations promulgated 
under the Gramm-Leach-Bliley Act of 1999. 
Business Associate acknowledges that Administrator or Plan will provide confidential information to 
Business Associate solely for those Business Associate’s uses expressly defined herein.  Business 
Associate agrees to comply with the Business Associate’s Agreement executed prior to or concurrently 
with this Agreement. 
 
Governing Law and Venue 
 
The laws of the State of Arizona govern this Agreement, without regard to conflict of law principals, and 
the Business Associate’s access to and use of the Service under this Agreement. The Business Associate 
submits to the exclusive jurisdiction of the courts in the State of Arizona and waives any jurisdictional 
venue or inconvenient forum objections to such court. 
 
Before Business Associate may seek legal recourse for any harm Business Associate believes it has 
suffered from use of the Service, Business Associate will give Plan or Administrator written notice 
specifying the harm and allow Plan or Administrator thirty (30) days from the date of notice to cure the 
harm.  Business Associate must initiate any cause of action under this Agreement or related to the 
Service within one (1) year after the claim has arisen or Business Associate is barred from pursuing any 
cause of action. 
 
Termination 
 
Plan or Administrator may issue Business Associate a warning, temporarily suspend, or indefinitely 
suspend, Business Associate’s access to the Service if, in the sole discretion of Plan or Administrator, 
Business Associate breaches this Agreement.  Notwithstanding the foregoing, Plan and Administrator 
reserve the right to immediately suspend or deny, in their singular or joint discretion, Business 
Associate’s access to all, or any portion of, the Service if required to do so to prevent violation of law, 
court order, Government Sponsor requirement, or threat to the Service.  Business Associate 
acknowledges and agrees that Plan or Administrator may immediately bar any further access to the 
Service.  Business Associate agrees that neither Plan nor Administrator shall be liable to Business 
Associate or any third-party for any termination of Business Associate’s access to the Service.  
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 6 of 10 
 
Except where required to be maintained or retained by state or federal law, upon termination of this 
Agreement, Business Associate agrees to destroy, as required by the BAA, all information and materials, 
in any format or capacity, obtained or retained from the Service. 
 
Notices 
 
All notices that are required or permitted to be given by one party to the other in connection with this 
Agreement shall be in writing to the addresses below: 
 
If to Business Associate: 
 
Notices shall be sent to the attention of the “Primary Representative” identified on the 
first page.   
 
If to the Plan:  
Mercy Care 
BA Web Portal Administration 
4750 S. 44th Pl, Suite 150 
Phoenix, AZ 85040 
Email:  BAWebPortal@mercycareaz.org 
 
The person(s) signing this Agreement warrants that he or she has full authority to do so and that the 
signature below binds the Business Associate, including the Business Associate’s owners, employees, 
agents and representatives, on whose behalf the person below signs. 
 
[Signature page follows] 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 7 of 10 
 
AGREED AND ACCEPTED: 
 
MARICOPA COUNTY  
BOARD OF SUPERVISORS 
 
 
 
 
 
 
 
 
 
 
Authorized Signature 
 
 
 
 
 
 
 
 
 
 
 
 
Chairman, Board of Supervisors 
 
 
 
 
 
 
 
 
 
   
Date 
 
ATTEST: 
 
 
 
 
 
 
 
 
Clerk of the Board 
 
Date:   
 
 
 
 
 
Approved as to form: 
 
 
 
 
 
 
 
 
Deputy County Attorney 
 
Date:   
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C
9/23/2025

Business Associate Web Portal Agreement 
Page 8 of 10 
 
Attachment A 
Correctional Health Services 
Authorized Representative Roster 
 
  
LASTNAME 
FIRSTNAME 
EMAIL 
1 
Bitsuie 
Karla 
karla.bitsuie@maricopa.gov 
2 
Burrer 
Rachel 
rachel.burrer@maricopa.gov 
3 
Campas 
Lori 
lori.campas@maricopa.gov 
4 
Carbajal 
Andrea 
Andrea.Carbajal@Maricopa.gov 
5 
Castillo 
Yessenia 
yessenia.castillo@maricopa.gov 
6 
Conseen 
Kyrie 
kyrie.conseen@maricopa.gov 
7 
Crowe 
Sandra 
sandra.crowe@maricopa.gov 
8 
Cruz 
Faviola 
Faviola.Cruz@Maricopa.gov 
9 
Curtis 
Iman 
iman.curtis@maricopa.gov 
10 
Devorkin 
Lynn 
lynn.devorkin@maricopa.gov 
11 
Fairbairn 
Elizabeth 
elizabeth.fairbairn@maricopa.gov 
12 
Fangohr 
Patricia 
Patricia.Fangohr@maricopa.gov 
13 
Goldring 
Dallas 
dallas.goldring@maricopa.gov 
14 
Guzman 
Heather 
heather.guzman@maricopa.gov 
15 
Johnson 
Kathryn 
kathryn.johnson@maricopa.gov 
16 
Kissell 
Shanoa 
shanoa.kissell@maricopa.gov 
17 
Kolean 
Rebecca 
rebecca.kolean@maricopa.gov 
18 
Kramer 
Jennifer 
jennifer.kramer@maricopa.gov 
19 
Lawrence 
Daro 
daro.lawrence@maricopa.gov 
20 
Magana 
Joanna 
Joanna.Magana@maricopa.gov 
21 
Marshall 
Melanie 
melanie.marshall@maricopa.gov 
22 
Mcgilvery 
Harlee 
harlee.mcgilvery@maricopa.gov 
23 
Moonjelly 
Annees 
annees.moonjelly@maricopa.gov 
24 
O'Connell 
Kristen 
Kristen.Oconnell@maricopa.gov 
25 
Owuama 
Uzoma 
uzo.owuama@maricopa.gov 
26 
Owuana 
Uzoma 
uzo.owuama@maricopa.gov 
27 
Parker 
Michelle 
Michelle.Parker@maricopa.gov 
28 
Perez 
Feliciano 
feliciano.perez@maricopa.gov 
29 
Petrovic 
Bridget 
bridget.petrovic@maricopa.gov 
30 
Preciado 
Eduardo 
eduardo.preciado@maricopa.gov 
31 
Provins 
Kat 
kathlyn.provins@maricopa.gov 
32 
Rhoades 
Christina 
Christina.Rhoades@maricopa.gov 
33 
Roston 
Valencia 
valencia.roston@maricopa.gov 
34 
Scroggins 
Annette 
Annette.Scroggins@maricopa.gov 
35 
Shaheed 
Rasheedah 
rasheedah.shaheed@maricopa.gov 
36 
Short 
Joseph 
joseph.short@maricopa.gov 
37 
Small 
Tina 
christina.small@maricopa.gov 
38 
Sneed 
Mairena 
mairena.sneed@maricopa.gov 
39 
Spotts 
Barbra 
barbra.spotts@maricopa.gov 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 9 of 10 
 
  
LASTNAME 
FIRSTNAME 
EMAIL 
40 
Stubblefield Tonia 
tonia.stubblefield@maricopa.gov 
41 
Suarez 
Lynnette 
lynnette.suarez@maricopa.gov 
42 
Talley 
Kamari 
kamari.talley@maricopa.gov 
43 
Tenney 
Mike 
michael.tenney@maricopa.gov 
44 
Tenuda 
Nadege 
nadege.tenuda@maricopa.gov 
45 
Valencia 
Yesenia 
Yesenia.Valencia@maricopa.gov 
46 
Willis 
Patricia 
patricia.willis@maricopa.gov 
47 
Willis 
Phillip 
phillip.willis@maricopa.gov 
48 
Wonsowicz 
Julie 
julie.wonsowiczmoore@maricopa.gov 
49 
Young 
Ken 
ken.young@maricopa.gov 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Business Associate Web Portal Agreement 
Page 10 of 10 
 
Attachment B 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
BUSINESS ASSOCIATE AGREEMENT 
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) 
 
[To be executed separately and attached] 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

ATTACHMENT B 
BUSINESS ASSOCIATE AGREEMENT 
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) 
This Business Associate Agreement (the “Agreement”) is effective as of the date of the last signature (the “Effective 
Date”), by and between Mercy Care, organized under the laws of the state of Arizona (hereinafter the “Covered 
Entity”) and Maricopa County, by and through Correctional Health Services organized under the laws of the state of 
Arizona (hereinafter the “Business Associate”). In conformity with the regulations at 45 C.F.R. Parts 160-164 (the 
“Privacy and Security Rules”), Covered Entity will provide Business Associate with access to, or have Business 
Associate create, maintain, transmit and/or receive certain Protected Health Information (as defined below), thus 
necessitating a written agreement that meets the applicable requirements of the Privacy and Security Rules. This BAA 
is limited to the purpose of the agreement it is attached to and does not replace or modify any other existing BAA 
that Business Associate may have entered into with Mercy Care or an affiliate. Covered Entity and Business 
Associate agree as follows: 
1. Definitions. The following terms shall have the meaning set forth below: 
(a) ARRA. “ARRA” means the American Recovery and Reinvestment Act of 2009 
(b) Breach. “Breach” has the same meaning as the term “breach” in 45 C.F.R. 164.402. 
(c) C. F. R. “C.F. R.” means the Code of Federal Regulations. 
(d) Designated Record Set. “Designated Record Set” has the meaning assigned to such term in 45 C. F. R. 
160.501. 
(e) Discovery. “Discovery” shall mean the first day on which a Breach is known to Business Associate 
(including any person, other than the individual committing the breach, that is an employee, officer, or other 
agent of Business Associate), or should reasonably have been known to Business Associate, to have occurred. 
(f) Electronic Protected Health Information. “Electronic Protected Health Information” means information that 
comes within paragraphs 1 (i) or 1 (ii) of the definition of “Protected Health Information”, as defined in 45 
C. F. R. 160.103. 
(g) Individual. “Individual” shall have the same meaning as the term “individual” in 45 C. F. R. 160.103 and 
shall include a person who qualifies as personal representative in accordance with 45 C. F. R. 164.502 (g). 
(h) Protected Health Information. “Protected Health Information” shall have the same meaning as the term 
“Protected Health Information”, as defined by 45 C. F. R. 160.103, limited to the information created or 
received by Business Associate from or on behalf of Covered Entity. 
(i) Required by Law. “Required by Law” shall have the same meaning as the term “required by law” in 45 
C. F. R. 164.103. 
(j) Secretary. “Secretary” shall mean the Secretary of the Department of Health and Human Services or his 
designee. 
(k) Security Incident. “Security Incident” shall have the same meaning as the term “security incident” in 45 
C.F.R. 164.304. 
(l) Standard Transactions. “Standard Transactions” means the electronic health care transactions for which 
HIPAA standards have been established, as set forth in 45 C. F. R., Parts 160-162. 
(m) Unsecured Protected Health Information. “Unsecured Protected Health Information” means Protected Health 
Information that is not secured through the use of a technology or methodology specified by guidance issued 
by the Secretary from time to time. 
2. Obligations and Activities of Business Associate. 
(a) Business Associate agrees to not use or further disclose Protected Health Information other than as permitted 
or required by this Agreement or as Required by Law. Business Associate shall also comply with any further 
limitations on uses and disclosures agreed by Covered Entity in accordance with 45 C.F.R. 164.522 provided 
that such agreed upon limitations have been communicated to Business Associate in accordance with Section 
4.1(c) of this Agreement. 
(b) Business Associate agrees to use appropriate safeguards to prevent use or disclosure of the Protected Health 
Information other than as provided for by this Agreement, including but not limited to the safeguards 
described in Section 2(m) of this Agreement. 
(c) Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business 
Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the 
requirements of this Agreement. 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Page 2 
BAA – Mercy Care BA Web Portal rev 07.2025 
 
(d) Business Associate agrees to promptly report to Covered Entity any use or disclosure of the Protected Health 
Information not provided for by this Agreement of which it becomes aware. 
(e) Business Associate agrees to report to Covered Entity any Breach of Unsecured Protected Health Information 
without unreasonable delay and in no case later than five (5) calendar days after Discovery of a Breach. Such 
notice shall include the identification of each Individual whose Unsecured Protected Health Information has 
been, or is reasonably believed by Business Associate, to have been, accessed, acquired, or disclosed In 
connection with such Breach. In addition, Business Associate shall provide any additional information 
reasonably requested by Covered Entity for purposes of investigating the Breach. Business Associate’s 
notification of a Breach under this section shall comply in all respects with each applicable provision of 
Section 13400 of Subtitle D (Privacy) of ARRA, 45 CFR 164.410, and related guidance issued by the 
Secretary from time to time. Without limiting Covered Entity’s remedies under Section 6 or any other 
provision of this Agreement, in the event of a Breach involving Unsecured Protected Health Information 
maintained, used or disclosed by Business Associate, Business Associate shall reimburse Covered Entity for 
the cost of providing any legally required notice to affected Individuals and the cost of credit monitoring for 
such Individuals to extent deemed necessary by Covered Entity in its reasonable discretion. 
(f) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, Business Associate agrees to 
ensure that any subcontractors that create, receive, maintain, or transmit Protected Health Information on 
behalf of Business Associate agree in writing to the same restrictions and conditions that apply through this 
Agreement to Business Associate with respect to such information. In no event shall Business Associate, 
without Covered Entity’s prior written approval, provide Protected Health Information received from, or 
created or received by Business Associate on behalf of Covered Entity, to any employee or agent, including 
a subcontractor, if such employee, agent or subcontractor receives, processes or otherwise has access to the 
Protected Health Information outside of the United States. 
(g) Business Associate agrees to provide access, at the request of Covered Entity, and in the time and manner 
designated by Covered Entity, to Protected Health Information in a Designated Record Set, to Covered Entity 
or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 C.F.R. 164.524. 
Covered Entity’s determination of what constitutes “Protected Health Information” or a “Designated Record 
Set” shall be final and conclusive. If Business Associate provides copies or summaries of Protected Health 
Information to an Individual it may impose a reasonable, cost-based fee in accordance with 45 C.F.R. 164.524 
(c)(4). 
(h) Business Associate agrees to make any amendment(s) to Protected Health Information in a Designated 
Record Set that the Covered Entity directs or agrees to pursuant to 45 C.F.R. 164.526 at the request of 
Covered Entity or an Individual, and in the time and manner designated by Covered Entity. Business 
Associate shall not charge any fee for fulfilling requests for amendments. Covered Entity’s determination of 
what Protected Health Information is subject to amendment pursuant to 45 C.F.R. 164.526 shall be final and 
conclusive. 
(i) Business Associate agrees to make (i) internal practices, books, and records, including policies and 
procedures, relating to the use and disclosure of Protected Health Information received from, or created or 
received by Business Associate on behalf of, Covered Entity, and (ii) policies, procedures, and documentation 
relating to the safeguarding of Electronic Protected Health Information available to the Covered Entity, or at 
the request of the Covered Entity to the Secretary, in a time and manner designated by the Covered Entity or 
the Secretary, for purposes of the Secretary determining Covered Entity’s or Business Associate’s compliance 
with the Privacy and Security Rules. 
(j) Business Associate agrees to document such disclosures of Protected Health Information as would be 
required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of 
Protected Health Information in accordance with 45 C.F.R. 164.528. 
(k) Business Associate agrees to provide to Covered Entity, in the time and manner described below, the 
information collected in accordance with Section 2(j) of this Agreement, to permit Covered Entity to respond 
to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance 
with 45 C.F.R. 164.528. Business Associate agrees to provide such information to Covered Entity through a 
quarterly report. 
(l) Business Associate acknowledges that it shall request from the Covered Entity and so disclose to its affiliates, 
agents and subcontractors or other third parties, (i) the information contained in a “limited data set,” as such 
term is defined at 45 C.F.R. 164.514(e)(2), or, (ii) if needed by Business Associate, to the minimum necessary 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Page 3 
BAA – Mercy Care BA Web Portal rev 07.2025 
 
to accomplish the intended purpose of such requests or disclosures. In all cases, Business Associate shall 
request and disclose Protected Health Information only in a manner that is consistent with guidance issued 
by the Secretary from time to time 
(m) With respect to Electronic Protected Health Information, Business Associate shall implement and comply 
with (and ensure that its subcontractors implement and comply with) the administrative safeguards set forth 
at 45 C.F.R. 164.308, the physical safeguards set forth at 45 C.F.R. 310, the technical safeguards set forth at 
45 C.F.R. 164.312, and the policies and procedures set forth at 45 C.F.R. 164.316 to reasonably and 
appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health 
Information that it creates, receives, maintains, or transmits on behalf of Covered Entity. Business Associate 
acknowledges that, (i) the foregoing safeguard, policies and procedures requirements shall apply to Business 
Associate in the same manner that such requirements apply to Covered Entity, and (ii) Business Associate 
shall be liable under the civil and criminal enforcement provisions set forth at 42 U.S.C. 1320d-5 and 1320d- 
6, as amended from time to time, for failure to comply with the safeguard, policies and procedures 
requirements and any guidance issued by the Secretary from time to time with respect to such requirements. 
(n) With respect to Electronic Protected Health Information, Business Associate shall ensure that any 
subcontractors that create, receive, maintain, or transmit Electronic Protected Health Information on behalf 
of Business Associate, agree to comply with the applicable requirements of Subpart C of 45 C.F.R. Part 164 
by entering into a contract that complies with 45 C.F.R. Section 164.314. 
(o) Business Associate shall report to Covered Entity any Security Incident of which it becomes aware, including 
Breaches of Unsecured Protected Health Information as required by 45 C.F.R. Section 164.410. 
(p) If Business Associate conducts any Standard Transactions on behalf of Covered Entity, Business Associate 
shall comply with the applicable requirements of 45 C.F.R. Parts 160-162. 
(q) During the term of this Agreement, Business Associate may be asked to complete a security survey and/or 
attestation document designed to assist Covered Entity in understanding and documenting Business 
Associate’s security procedures and compliance with the requirements contained herein. Business 
Associate’s failure to complete either of these documents within the reasonable timeframe specified by 
Covered Entity shall constitute a material breach of this Agreement. 
(r) Business Associate acknowledges that, as of the Effective Date of this Agreement, it shall be liable under the 
civil and criminal enforcement provisions set forth at 42 U.S.C. 1320d-5 and 1320d-6, as amended from time 
to time, for failure to comply with any of the use and disclosure requirements of this Agreement and any 
guidance issued by the Secretary from time to time with respect to such use and disclosure requirements. 
(s) To the extent Business Associate is to carry out one or more of Covered Entity’s obligation(s) under Subpart 
E of 45 CFR Part 164, Business Associate shall comply with the requirements of Subpart E that apply to 
Covered Entity in the performance of such obligation(s). 
3. Permitted Uses and Disclosures by Business Associate. 
3.1 General Use and Disclosure. Except as otherwise limited in this Agreement, Business Associate may use or 
disclose Protected Health Information to perform its obligations and services to Covered Entity, provided 
that such use or disclosure would not violate the Privacy and Security Rules if done by Covered Entity or the 
minimum necessary policies and procedures of the Covered Entity. 
3.2 Specific Use and Disclosure Provisions. 
(a) Except as otherwise prohibited by this Agreement, Business Associate may use Protected Health 
Information for the proper management and administration of the Business Associate or to carry out the 
legal responsibilities of the Business Associate. 
(b) Except as otherwise prohibited by this Agreement, Business Associate may disclose Protected Health 
Information for the proper management and administration of the Business Associate, provided that 
disclosures are Required By Law, or Business Associate obtains reasonable assurances from the person 
to whom the information is disclosed that it will remain confidential and used or further disclosed only 
as Required By Law or for the purpose for which it was disclosed to the person, and the person notifies 
the Business Associate of any instances of which it is aware in which the confidentiality of the 
information has been breached in accordance with the Breach and Security Incident notifications 
requirements of this Agreement. 
(c) Business Associate shall not directly or indirectly receive remuneration in exchange for any Protected 
Health Information of an Individual without Covered Entity’s prior written approval and notice from 
Covered Entity that it has obtained from the Individual, in accordance with 45 C.F.R. 164.508, a valid 
authorization that includes a specification of whether the Protected Health Information can be further 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Page 4 
BAA – Mercy Care BA Web Portal rev 07.2025 
 
exchanged for remuneration by Business Associate. The foregoing shall not apply to Covered Entity’s 
payments to Business Associate for services delivered by Business Associate to Covered Entity. 
(d) Business Associate shall not de-identify any Protected Health Information except as authorized by 
Covered Entity to provide data aggregation services to Covered Entity as permitted by 42 C.F.R. 
164.504(e)(2)(i)(B). 
(e) Business Associate may use Protected Health Information to report violation of law to appropriate Federal 
and State authorities, consistent with 164.502 (j)(1). 
4. Obligations of Covered Entity. 
4.1 Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions. 
(a) Covered Entity shall notify Business Associate of any limitation(s) in Covered Entity’s notice of privacy 
practices that Covered Entity produces in accordance with 45 C.F.R. 164.520 (as well as any changes to that 
notice), to the extent that such limitation(s) may affect Business Associate’s use or disclosure of Protected 
Health Information. 
(b) Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by 
Individual to use or disclose Protected Health Information, to the extent that such changes affect Business 
Associate’s use or disclosure of Protected Health Information. 
(c) Covered Entity shall notify Business Associate of any restriction to the use or disclosure of Protected Health 
Information that Covered Entity has agreed to in accordance with 45 C.F.R. 164.522, to the extent that such 
restriction may affect Business Associate’s use or disclosure of Protected Health Information. 
4.2 Permissible Requests by Covered Entity. Except as may be set forth in Section 3.2, Covered Entity shall not 
request Business Associate to use or disclose Protected Health Information in any manner that would not be 
permissible under the Privacy and Security Rules if done by Covered Entity. 
5. Term and Termination. 
(a) Term. The provisions of this Agreement shall take effect on the Agreement’s Effective Date and shall 
terminate when all of the Protected Health Information provided by Covered Entity to Business Associate, 
or created, maintained, transmitted or received by Business Associate on behalf of Covered Entity, is 
destroyed or returned to Covered Entity, or, in accordance with Section 5(c)(2). 
(b) Termination for Cause. Without limiting the termination rights of the Parties pursuant to the Agreement and 
upon Covered Entity’s knowledge of a material breach of this Agreement by Business Associate, Covered 
Entity shall either: 
(i) Provide an opportunity for Business Associate to cure the breach or end the violation, or terminate the 
Agreement if Business Associate does not cure the breach or end the violation within the time specified by 
Covered Entity, 
(ii) Immediately terminate the Agreement, if cure of such breach is not possible. 
(c) Effect of Termination. 
(1) Except as provided in Section 5(c), upon termination of this Agreement, for any reason, Business 
Associate shall return or destroy all Protected Health Information received from Covered Entity, or 
created, maintained, transmitted or received by Business Associate on behalf of Covered Entity. This 
provision shall apply to Protected Health Information that is in the possession of subcontractors or agents 
of Business Associate. Business Associate shall retain no copies of the Protected Health Information. 
(2) In the event the Business Associate determines that returning or destroying the Protected Health 
Information is infeasible, Business Associate shall provide to Covered Entity notification of the 
conditions that make return or destruction infeasible. Upon mutual agreement of the Parties that return 
or destruction of Protected Health Information is infeasible, per Section 5(a) above, Business Associate 
shall continue to extend the protection of this Agreement to such Protected Health Information and limit 
further uses and disclosures of such Protected Health Information for so long as Business Associate 
maintains such Protected Health Information. 
 
6. Indemnification. Business Associate shall indemnify and hold harmless Covered Entity and any of Covered 
Entity’s affiliates, directors, officers, employees and agents from and against any claim, cause of action, liability, 
damage, cost or expense (including reasonable attorneys’ fees) arising out of or relating to any non-permitted use or 
disclosure of Protected Health Information, failure to safeguard Electronic Protected Health Information, or other 
breach of this Agreement by Business Associate or any affiliate, director, officer, employee, agent or subcontractor of 
Business Associate. 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Page 5 
BAA – Mercy Care BA Web Portal rev 07.2025 
 
7. Notices. Any notices or communications to be given under this Agreement shall be made to the address and/or 
fax numbers given below: 
 
To Business Associate: 
To Covered Entity: 
Maricopa County 
Mercy Care c/o Aetna 
Correctional Health Services 
HIPAA Member Rights Team 
234 N. Central Avenue, Suite 5000 
151 Farmington Avenue, AN33 
Phoenix, AZ 85004 
Hartford, CT 06156 
Fax: (859) 280-1272 
Copy to: 
chsmasteragreements@maricopa.gov 
communitytreatmentservices@maricopa.gov 
HIPAAFulfillment@aetna.com 
Copy to: 
Mercy Care 
Attn: Legal Dept. 
4750 S. 44th Pl, Suite 150 
Phoenix, AZ 85040 
 
 
Each Party named above may change its address upon thirty (30) days written notice to the other Party. 
 
8. Miscellaneous. 
(a) Regulatory References. A reference in this Agreement to a section in the Privacy and Security Rules means 
the section as in effect or as amended, and for which compliance is required. 
(b) Amendment. Upon the enactment of any law or regulation affecting the use or disclosure of Protected Health 
Information or the safeguarding of Electronic Protected Health Information, or the publication of any decision 
of a court of the United States or any state relating to any such law or the publication of any interpretive 
policy or opinion of any governmental agency charged with the enforcement of any such law or regulation, 
either Party may, by written notice to the other Party, amend the Agreement in such manner as such Party 
determines necessary to comply with such law or regulation. If the other Party disagrees with such 
amendment, it shall so notify the first Party in writing within thirty (30) days of the notice. If the Parties are 
unable to agree on an amendment within thirty (30) days thereafter, then either of the Parties may terminate 
the Agreement on thirty (30) days written notice to the other Party. 
(c) Survival. The respective rights and obligations of Business Associate under Sections 5(c) and 6 of this 
Agreement shall survive the termination of this Agreement. 
(d) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered 
Entity to comply with the Privacy and Security Rules. In the event of any inconsistency or conflict between 
this Agreement and any other agreement between the Parties, the terms, provisions and conditions of this 
Agreement shall govern and control. 
(e) No third party beneficiary. Nothing express or implied in this Agreement is intended to confer, nor shall 
anything herein confer, upon any person other than the Parties and the respective successors or assigns of the 
Parties, any rights, remedies, obligations, or liabilities whatsoever. 
(f) Governing Law. This Agreement shall be governed by and construed in accordance with the laws of Arizona. 
(g) Scope. This BAA is limited to the purpose of the agreement it is attached to and does not replace or modify 
any other existing BAA that Business Associate may have entered into with Mercy Care or an affiliate. 
 
[This portion of the page has been left intentionally blank and is followed by the signature page.] 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C

Page 6 
BAA – Mercy Care BA Web Portal rev 07.2025 
 
IN WITNESS WHEREOF, this Agreement is executed on the date set forth below when executed by both Parties' Authorized 
Representative. 
 
 
MERCY CARE 
MARICOPA COUNTY 
BOARD OF SUPERVISORS 
 Tad Gary 
 
Tad Gary (Sep 18, 2025 07:14:37 PDT) 
 
Authorized Signature 
Authorized Signature 
Tad Gary, Chief Executive Officer 
 
Printed Name and Title 
Chairman, Board of Supervisors 
 
09/18/2025 
 
Date 
Date 
 
ATTEST: 
 
Clerk of the Board 
 
Date:  
 
 
 
Approved as to form: 
 
Deputy County Attorney 
 
Date:  
 
Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C
9/23/2025