COMPLETE_WITH_DOCUSIGN_MERCY_CARE_AMENDMENT_.PDF
Extracted text (via pymupdf)
46759 characters
AMENDMENT No. 2 To MEMORANDUM OF UNDERSTANDING Between MERCY CARE & MARICOPA COUNTY, ARIZONA WHEREAS, Maricopa County (“County”) and Mercy Care (“Contractor”) entered into a Memorandum of Understanding, executed February 8th, 2024, for the purpose of establishing collaborative protocol for effective communication, coordination, and continuity of care for individuals eligible for services provided by Mercy Care who are also served by Correctional Health Services (the “MOU”). WHEREAS, the County and Mercy Care have agreed to modify this MOU. NOW, THEREFORE, the parties hereby agree to the following provision: Additions are in bold, and deletions are in strikethrough: Sections III-C-1,2,5,6, & 8: 1. The Mercy Care Point of Contact or designee will complete a Justice Transition Form (JTF) for SMI members and GMHSU members with designated chronic conditions and send the JTF to CHS: CHS will send a weekly Continuity of Care (COC) Report to Mercy Care. a. CHS will confirm diagnosis/chronic condition in the EHR. b. CHS will complete the CHS section of the JTF and return it to Mercy Care – scan it into the EHR. 2. If CHS identifies newly diagnosed chronic care conditions, CHS will complete a JTF and send it to the Mercy Care Point of Contact or designee. CHS will send a Justice Transition Notice (JTN) at the time the condition is identified for patients who are pregnant, HIV+, Hep C+ and OTP/MAT. 5. An Appointment will be made with member’s Primary Care Physician (PCP) to occur within 7 days of release. An appointment will be made with an appropriate physical or behavioral health provider based on individual needs and preferences within 7 days. 6. The Mercy Care Point of Contact or designee will forward to CHS an “Introduction Letter,” via secure email, with the following information: For General Mental Health (GMH) members referred to Targeted Investment Program - Justice or PCP, The Mercy Care Point of Contact or designee will forward to CHS an “Introduction Letter,” via secure email, with the following information: 8. CHS and the Mercy Care Point of Contact or other health staff may coordinate special needs prior to jail release (such as courtesy release third-party release, medical equipment, or specific medications). ALL OTHER TERMS AND CONDITIONS REMAIN UNCHANGED. If there is any conflict between the terms of the MOU and this Amendment, in all such events, the terms of this Amendment shall control. This Amendment is subject to cancellation pursuant to A.R.S. § 38-511. IN WITNESS WHEREOF, this Amendment is executed on the date set forth below when executed by both Parties' Authorized Representative. Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C MERCY CARE MARICOPA COUNTY BOARD OF SUPERVISORS Tad Gary Tad Gary (Sep 18, 2025 07:15:08 PDT) Authorized Signature Authorized Signature Tad Gary, Chief Executive Officer Printed Name and Title Chairman, Board of Supervisors 09/18/2025 Date Date ATTEST: Clerk of the Board Date: Approved as to form: Deputy County Attorney Date: Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C 9/23/2025 Business Associate Web Portal Agreement Page 1 of 10 Business Associate Secure Web Portal Government Agency Registration Form Thank you for your interest in registering for the Mercy Care Business Associate web portal. We are committed to protecting the privacy of our members and Business Associates who use our website. During registration, we ask you for specific information about you and your Authorized Representatives. We will only use the information you submit to us for the purpose of managing your access to the website. We do not disclose any of the information you provide to us to any outside parties, except to manage the health plan or when applicable law may require it. Registration Instructions: The information below and acceptance of the attached agreement is required to complete registration. Business Associate Name: Maricopa County Correctional Health Services Business Associate Tax ID # (TIN) (if applicable): 86-6000472 We caution against using your SSN in lieu of a TIN, as it presents unnecessary risks to your identity Address: 301 W Jefferson Street, 9th Floor City: Phoenix State: AZ Zip: 85003 Phone #: 602-506-3561 Fax #: N/A Business Associate must designate one primary representative (see Business Associate Web Portal Agreement attached for full definition). Please indicate the full name and contact information of the primary representative below: Primary Representative Name: Julie Wonsowicz Address: 2680 S 28th Drive City: Phoenix State: AZ Zip: 85009 Phone #: 602-876-1581 Fax #: N/A E-Mail address at Business Associate’s office: Julie.Wonsowiczmoore@Maricopa.Gov To submit a request for registration, please email your completed form, agreement and executed Business Associate Agreement to Mercy Care at BAWebPortal@mercycareaz.org. Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 2 of 10 Business Associate’s Web Portal Agreement Introduction This Business Associate’s Web Portal Agreement (“Agreement”) contains the terms and conditions that govern the use of this web portal service by Business Associate to access information relating to Mercy Care member/enrollee eligibility information. Definitions When used in this Agreement, all capitalized terms shall have the following meanings: • “Administrator” means any Aetna administrator, such as Aetna Medicaid Administrators, LLC, and any owners, affiliates or direct or indirect subsidiaries that administer or maintain the Service for a Plan. • “Authorized Representative” means an Employee of Business Associate that Business Associate has authorized to use the Web Portal Service under this Agreement on Business Associate’s behalf. Business Associate shall identify each authorized representative on the roster form provided in Attachment A to this agreement. Addition or removal of an Authorized Representative(s) shall be submitted, in writing, by the Primary Representative and shall include the information requested in Attachment A. • “Business Associate” means the individual or entity identified on the current Business Associate Agreement (“BAA”) attached to this Agreement as Attachment B. • “Government Sponsor” means a state agency or other governmental entity authorized to offer, issue and/or administer one or more plans, and which, to the extent applicable, has contracted with Plan to administer all or a portion of such Plan(s). • “Member/enrollee” includes, a person determined to be Seriously Mentally Ill in accordance with policies issued by the Arizona Health Care Cost Containment System (AHCCCS) and eligible to receive behavioral health services paid for, in whole or in part, from funds available to the AHCCCS designated Regional Behavioral Health Authority (RBHA) • “Plan” means “Mercy Care” and any owners, affiliates or direct or indirect subsidiaries. • “Primary Representative” means the Authorized Representative in the Business Associate’s office who has responsibility for requesting access, removing access and maintaining the names of Business Associate’s Authorized Representatives • “Service” means the web portal service under this Agreement and the website that supports it. Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 3 of 10 Use of the Web Portal Service The Service provides internet access to information on the Plan’s members’/enrollees’ eligibility and enrollment. The Plan and its Administrator agree to permit Business Associate and its Primary Representative and Authorized Representatives to use the Service, provided they comply with the terms and conditions of this Agreement. Business Associate shall use the Service solely in connection with its obligations under state and federal law, including court orders, for the provision of judicial and/or health care services to Plan members/enrollees. Business Associate shall not access the records or information of Plan members/enrollees to whom the Business Associate does not provide judicial and/or health care services. The Primary Representative and each Authorized Representative shall use the Service solely in the course and scope of employment or agency with Business Associate. Business Associate shall use, and shall cause the Primary Representative and each Authorized Representative to use, the Service subject to the following: 1. The terms and conditions of this Agreement; and 2. The applicable provisions of the BAA, including, but not limited to, use and disclosure of Protected Health Information under the HIPPA Privacy Standards, and member/enrollee eligibility and enrollment verification for the purposes identified in this Agreement. 3. In the event of a conflict between a term and condition under this Agreement and a provision under the BAA, the terms of the BAA shall govern. Business Associate shall require the Primary Representative and each Authorized Representative to: 1. Keep confidential and not disclose the Business Associate’s Service password to any person except Business Associate or the Primary Representative; 2. Use the Service solely in connection with Business Associate’s judicial or health care services to the Plan’s members/enrollees and within the course and scope of employment or agency with Business Associate; and 3. Use the Service pursuant to the terms and conditions of this Agreement. Upon learning that any Primary Representative or Authorized Representative has violated (1), (2) or (3) identified above, changes job responsibilities such that access is no longer necessary, or no longer works for or represents Business Associate, Business Associate shall immediately notify the Plan within 24 hours. The Plan will revoke such Primary Representative’s or Authorized Representative’s authority to use the Service. Changes to the Web Portal Service or This Agreement Administrator may, at any time, make changes to the Service, the terms and conditions in this Agreement, or any other policies or conditions that govern the use of the Service at any time. Business Associate should review the Service and these terms and conditions periodically for any updates or changes. Business Associate’s continued access or use of the Service site shall be deemed Business Associate’s notification and acceptance of these changes. Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 4 of 10 No Warranties or Liabilities There is no implied warranty of any kind under this Agreement, including any representation of accuracy, completeness, or appropriateness or fitness for a particular part of the Service, and non-infringement. Business Associate assumes full responsibility for using the Service, and understands and agrees that neither the Plan nor Administrator are responsible or liable for any claim, loss, or damage resulting from, or related to, Business Associate’s use. Business Associate uses the Service at its own risk, and agrees to use the Service on an “AS IS” and an “AS AVAILABLE” basis. Neither Plan nor Administrator will be liable for any delay, difficulty in use, inaccuracy or incompleteness of information, computer virus, malicious code, loss of data, compatibility issues, or otherwise. Plan and Administrator will not be liable for any direct, indirect, incidental, consequential, or punitive damages arising out of the Business Associate’s use of, or access to, the Service, or any link provided to another site, even if Plan or Administrator was advised of the possibility of such damages, or even if such damages were foreseeable. Ownership, License and Restrictions on Use of Materials All rights, title and interest (including all copyrights, trademarks and other intellectual property rights) in the Service belong to the Plan or Administrator. In addition, the names, images, pictures, logos, and icons are proprietary marks that belong to the Plan or Administrator. Except as expressly provided below, nothing contained herein shall be construed as conferring any license or right, by implication, estoppels or otherwise, under copyright or other intellectual property rights. The Business Associate is hereby granted a nonexclusive, nontransferable, limited license to view and use information retrieved from the Service solely in connection with its obligations under state and federal law, including court orders, for the provision of judicial and/or health care services to Plan members/enrollees. Except as expressly provided above, no part of the information in or about the Service, including but not limited to materials retrieved from it and the underlying code, may be reproduced, republished, copied, transmitted, or distributed in any form or by any means. In no event shall materials from this site be stored in any information storage and retrieval system without prior written permission from Administrator or Plan. Business Associate’s use of the site allows Plan and Administrator to gather certain limited information about the Business Associate and its usage of the Service. Business Associate agrees and consents to the use of such information in aggregated form. Site System Integrity The Business Associate may not use any device, software routine or agent to interfere or attempt to interfere with the proper working of the Service. The Business Associate may not take any action which imposes an unreasonable or disproportionately large load on Administrator’s or Plan’s infrastructure. The Business Associate may not disclose or share its password to or with third parties, or allow its password to be used, for any unauthorized purpose. The Business Associate shall take reasonable precautions to secure its password from any unauthorized use. The Business Associate may not attempt to log in with a username or password other than its own. The Business Associate shall require its Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 5 of 10 Primary Representative and Authorized Representative to take the same precautions and follow the same requirements identified in this Agreement. Continuous, uninterrupted access to the Service is not guaranteed. Numerous actions beyond our control may interfere with the Service. Confidential Information “Confidential Information” is any information that identifies a member and relates to the member’s participation in a Plan, the member’s physical or mental health or condition, the provision of health care to the member, or payment for the provision of health care to the member. Confidential information includes, without limitation, “individually identifiable health information,” as defined in 45 C.F.R. § 160.103 of HIPAA and “non-public personal information,” as defined in laws or regulations promulgated under the Gramm-Leach-Bliley Act of 1999. Business Associate acknowledges that Administrator or Plan will provide confidential information to Business Associate solely for those Business Associate’s uses expressly defined herein. Business Associate agrees to comply with the Business Associate’s Agreement executed prior to or concurrently with this Agreement. Governing Law and Venue The laws of the State of Arizona govern this Agreement, without regard to conflict of law principals, and the Business Associate’s access to and use of the Service under this Agreement. The Business Associate submits to the exclusive jurisdiction of the courts in the State of Arizona and waives any jurisdictional venue or inconvenient forum objections to such court. Before Business Associate may seek legal recourse for any harm Business Associate believes it has suffered from use of the Service, Business Associate will give Plan or Administrator written notice specifying the harm and allow Plan or Administrator thirty (30) days from the date of notice to cure the harm. Business Associate must initiate any cause of action under this Agreement or related to the Service within one (1) year after the claim has arisen or Business Associate is barred from pursuing any cause of action. Termination Plan or Administrator may issue Business Associate a warning, temporarily suspend, or indefinitely suspend, Business Associate’s access to the Service if, in the sole discretion of Plan or Administrator, Business Associate breaches this Agreement. Notwithstanding the foregoing, Plan and Administrator reserve the right to immediately suspend or deny, in their singular or joint discretion, Business Associate’s access to all, or any portion of, the Service if required to do so to prevent violation of law, court order, Government Sponsor requirement, or threat to the Service. Business Associate acknowledges and agrees that Plan or Administrator may immediately bar any further access to the Service. Business Associate agrees that neither Plan nor Administrator shall be liable to Business Associate or any third-party for any termination of Business Associate’s access to the Service. Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 6 of 10 Except where required to be maintained or retained by state or federal law, upon termination of this Agreement, Business Associate agrees to destroy, as required by the BAA, all information and materials, in any format or capacity, obtained or retained from the Service. Notices All notices that are required or permitted to be given by one party to the other in connection with this Agreement shall be in writing to the addresses below: If to Business Associate: Notices shall be sent to the attention of the “Primary Representative” identified on the first page. If to the Plan: Mercy Care BA Web Portal Administration 4750 S. 44th Pl, Suite 150 Phoenix, AZ 85040 Email: BAWebPortal@mercycareaz.org The person(s) signing this Agreement warrants that he or she has full authority to do so and that the signature below binds the Business Associate, including the Business Associate’s owners, employees, agents and representatives, on whose behalf the person below signs. [Signature page follows] Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 7 of 10 AGREED AND ACCEPTED: MARICOPA COUNTY BOARD OF SUPERVISORS Authorized Signature Chairman, Board of Supervisors Date ATTEST: Clerk of the Board Date: Approved as to form: Deputy County Attorney Date: Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C 9/23/2025 Business Associate Web Portal Agreement Page 8 of 10 Attachment A Correctional Health Services Authorized Representative Roster LASTNAME FIRSTNAME EMAIL 1 Bitsuie Karla karla.bitsuie@maricopa.gov 2 Burrer Rachel rachel.burrer@maricopa.gov 3 Campas Lori lori.campas@maricopa.gov 4 Carbajal Andrea Andrea.Carbajal@Maricopa.gov 5 Castillo Yessenia yessenia.castillo@maricopa.gov 6 Conseen Kyrie kyrie.conseen@maricopa.gov 7 Crowe Sandra sandra.crowe@maricopa.gov 8 Cruz Faviola Faviola.Cruz@Maricopa.gov 9 Curtis Iman iman.curtis@maricopa.gov 10 Devorkin Lynn lynn.devorkin@maricopa.gov 11 Fairbairn Elizabeth elizabeth.fairbairn@maricopa.gov 12 Fangohr Patricia Patricia.Fangohr@maricopa.gov 13 Goldring Dallas dallas.goldring@maricopa.gov 14 Guzman Heather heather.guzman@maricopa.gov 15 Johnson Kathryn kathryn.johnson@maricopa.gov 16 Kissell Shanoa shanoa.kissell@maricopa.gov 17 Kolean Rebecca rebecca.kolean@maricopa.gov 18 Kramer Jennifer jennifer.kramer@maricopa.gov 19 Lawrence Daro daro.lawrence@maricopa.gov 20 Magana Joanna Joanna.Magana@maricopa.gov 21 Marshall Melanie melanie.marshall@maricopa.gov 22 Mcgilvery Harlee harlee.mcgilvery@maricopa.gov 23 Moonjelly Annees annees.moonjelly@maricopa.gov 24 O'Connell Kristen Kristen.Oconnell@maricopa.gov 25 Owuama Uzoma uzo.owuama@maricopa.gov 26 Owuana Uzoma uzo.owuama@maricopa.gov 27 Parker Michelle Michelle.Parker@maricopa.gov 28 Perez Feliciano feliciano.perez@maricopa.gov 29 Petrovic Bridget bridget.petrovic@maricopa.gov 30 Preciado Eduardo eduardo.preciado@maricopa.gov 31 Provins Kat kathlyn.provins@maricopa.gov 32 Rhoades Christina Christina.Rhoades@maricopa.gov 33 Roston Valencia valencia.roston@maricopa.gov 34 Scroggins Annette Annette.Scroggins@maricopa.gov 35 Shaheed Rasheedah rasheedah.shaheed@maricopa.gov 36 Short Joseph joseph.short@maricopa.gov 37 Small Tina christina.small@maricopa.gov 38 Sneed Mairena mairena.sneed@maricopa.gov 39 Spotts Barbra barbra.spotts@maricopa.gov Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 9 of 10 LASTNAME FIRSTNAME EMAIL 40 Stubblefield Tonia tonia.stubblefield@maricopa.gov 41 Suarez Lynnette lynnette.suarez@maricopa.gov 42 Talley Kamari kamari.talley@maricopa.gov 43 Tenney Mike michael.tenney@maricopa.gov 44 Tenuda Nadege nadege.tenuda@maricopa.gov 45 Valencia Yesenia Yesenia.Valencia@maricopa.gov 46 Willis Patricia patricia.willis@maricopa.gov 47 Willis Phillip phillip.willis@maricopa.gov 48 Wonsowicz Julie julie.wonsowiczmoore@maricopa.gov 49 Young Ken ken.young@maricopa.gov Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Business Associate Web Portal Agreement Page 10 of 10 Attachment B BUSINESS ASSOCIATE AGREEMENT HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) [To be executed separately and attached] Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C ATTACHMENT B BUSINESS ASSOCIATE AGREEMENT HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) This Business Associate Agreement (the “Agreement”) is effective as of the date of the last signature (the “Effective Date”), by and between Mercy Care, organized under the laws of the state of Arizona (hereinafter the “Covered Entity”) and Maricopa County, by and through Correctional Health Services organized under the laws of the state of Arizona (hereinafter the “Business Associate”). In conformity with the regulations at 45 C.F.R. Parts 160-164 (the “Privacy and Security Rules”), Covered Entity will provide Business Associate with access to, or have Business Associate create, maintain, transmit and/or receive certain Protected Health Information (as defined below), thus necessitating a written agreement that meets the applicable requirements of the Privacy and Security Rules. This BAA is limited to the purpose of the agreement it is attached to and does not replace or modify any other existing BAA that Business Associate may have entered into with Mercy Care or an affiliate. Covered Entity and Business Associate agree as follows: 1. Definitions. The following terms shall have the meaning set forth below: (a) ARRA. “ARRA” means the American Recovery and Reinvestment Act of 2009 (b) Breach. “Breach” has the same meaning as the term “breach” in 45 C.F.R. 164.402. (c) C. F. R. “C.F. R.” means the Code of Federal Regulations. (d) Designated Record Set. “Designated Record Set” has the meaning assigned to such term in 45 C. F. R. 160.501. (e) Discovery. “Discovery” shall mean the first day on which a Breach is known to Business Associate (including any person, other than the individual committing the breach, that is an employee, officer, or other agent of Business Associate), or should reasonably have been known to Business Associate, to have occurred. (f) Electronic Protected Health Information. “Electronic Protected Health Information” means information that comes within paragraphs 1 (i) or 1 (ii) of the definition of “Protected Health Information”, as defined in 45 C. F. R. 160.103. (g) Individual. “Individual” shall have the same meaning as the term “individual” in 45 C. F. R. 160.103 and shall include a person who qualifies as personal representative in accordance with 45 C. F. R. 164.502 (g). (h) Protected Health Information. “Protected Health Information” shall have the same meaning as the term “Protected Health Information”, as defined by 45 C. F. R. 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity. (i) Required by Law. “Required by Law” shall have the same meaning as the term “required by law” in 45 C. F. R. 164.103. (j) Secretary. “Secretary” shall mean the Secretary of the Department of Health and Human Services or his designee. (k) Security Incident. “Security Incident” shall have the same meaning as the term “security incident” in 45 C.F.R. 164.304. (l) Standard Transactions. “Standard Transactions” means the electronic health care transactions for which HIPAA standards have been established, as set forth in 45 C. F. R., Parts 160-162. (m) Unsecured Protected Health Information. “Unsecured Protected Health Information” means Protected Health Information that is not secured through the use of a technology or methodology specified by guidance issued by the Secretary from time to time. 2. Obligations and Activities of Business Associate. (a) Business Associate agrees to not use or further disclose Protected Health Information other than as permitted or required by this Agreement or as Required by Law. Business Associate shall also comply with any further limitations on uses and disclosures agreed by Covered Entity in accordance with 45 C.F.R. 164.522 provided that such agreed upon limitations have been communicated to Business Associate in accordance with Section 4.1(c) of this Agreement. (b) Business Associate agrees to use appropriate safeguards to prevent use or disclosure of the Protected Health Information other than as provided for by this Agreement, including but not limited to the safeguards described in Section 2(m) of this Agreement. (c) Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement. Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Page 2 BAA – Mercy Care BA Web Portal rev 07.2025 (d) Business Associate agrees to promptly report to Covered Entity any use or disclosure of the Protected Health Information not provided for by this Agreement of which it becomes aware. (e) Business Associate agrees to report to Covered Entity any Breach of Unsecured Protected Health Information without unreasonable delay and in no case later than five (5) calendar days after Discovery of a Breach. Such notice shall include the identification of each Individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate, to have been, accessed, acquired, or disclosed In connection with such Breach. In addition, Business Associate shall provide any additional information reasonably requested by Covered Entity for purposes of investigating the Breach. Business Associate’s notification of a Breach under this section shall comply in all respects with each applicable provision of Section 13400 of Subtitle D (Privacy) of ARRA, 45 CFR 164.410, and related guidance issued by the Secretary from time to time. Without limiting Covered Entity’s remedies under Section 6 or any other provision of this Agreement, in the event of a Breach involving Unsecured Protected Health Information maintained, used or disclosed by Business Associate, Business Associate shall reimburse Covered Entity for the cost of providing any legally required notice to affected Individuals and the cost of credit monitoring for such Individuals to extent deemed necessary by Covered Entity in its reasonable discretion. (f) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, Business Associate agrees to ensure that any subcontractors that create, receive, maintain, or transmit Protected Health Information on behalf of Business Associate agree in writing to the same restrictions and conditions that apply through this Agreement to Business Associate with respect to such information. In no event shall Business Associate, without Covered Entity’s prior written approval, provide Protected Health Information received from, or created or received by Business Associate on behalf of Covered Entity, to any employee or agent, including a subcontractor, if such employee, agent or subcontractor receives, processes or otherwise has access to the Protected Health Information outside of the United States. (g) Business Associate agrees to provide access, at the request of Covered Entity, and in the time and manner designated by Covered Entity, to Protected Health Information in a Designated Record Set, to Covered Entity or, as directed by Covered Entity, to an Individual in order to meet the requirements under 45 C.F.R. 164.524. Covered Entity’s determination of what constitutes “Protected Health Information” or a “Designated Record Set” shall be final and conclusive. If Business Associate provides copies or summaries of Protected Health Information to an Individual it may impose a reasonable, cost-based fee in accordance with 45 C.F.R. 164.524 (c)(4). (h) Business Associate agrees to make any amendment(s) to Protected Health Information in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 C.F.R. 164.526 at the request of Covered Entity or an Individual, and in the time and manner designated by Covered Entity. Business Associate shall not charge any fee for fulfilling requests for amendments. Covered Entity’s determination of what Protected Health Information is subject to amendment pursuant to 45 C.F.R. 164.526 shall be final and conclusive. (i) Business Associate agrees to make (i) internal practices, books, and records, including policies and procedures, relating to the use and disclosure of Protected Health Information received from, or created or received by Business Associate on behalf of, Covered Entity, and (ii) policies, procedures, and documentation relating to the safeguarding of Electronic Protected Health Information available to the Covered Entity, or at the request of the Covered Entity to the Secretary, in a time and manner designated by the Covered Entity or the Secretary, for purposes of the Secretary determining Covered Entity’s or Business Associate’s compliance with the Privacy and Security Rules. (j) Business Associate agrees to document such disclosures of Protected Health Information as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 C.F.R. 164.528. (k) Business Associate agrees to provide to Covered Entity, in the time and manner described below, the information collected in accordance with Section 2(j) of this Agreement, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 C.F.R. 164.528. Business Associate agrees to provide such information to Covered Entity through a quarterly report. (l) Business Associate acknowledges that it shall request from the Covered Entity and so disclose to its affiliates, agents and subcontractors or other third parties, (i) the information contained in a “limited data set,” as such term is defined at 45 C.F.R. 164.514(e)(2), or, (ii) if needed by Business Associate, to the minimum necessary Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Page 3 BAA – Mercy Care BA Web Portal rev 07.2025 to accomplish the intended purpose of such requests or disclosures. In all cases, Business Associate shall request and disclose Protected Health Information only in a manner that is consistent with guidance issued by the Secretary from time to time (m) With respect to Electronic Protected Health Information, Business Associate shall implement and comply with (and ensure that its subcontractors implement and comply with) the administrative safeguards set forth at 45 C.F.R. 164.308, the physical safeguards set forth at 45 C.F.R. 310, the technical safeguards set forth at 45 C.F.R. 164.312, and the policies and procedures set forth at 45 C.F.R. 164.316 to reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic Protected Health Information that it creates, receives, maintains, or transmits on behalf of Covered Entity. Business Associate acknowledges that, (i) the foregoing safeguard, policies and procedures requirements shall apply to Business Associate in the same manner that such requirements apply to Covered Entity, and (ii) Business Associate shall be liable under the civil and criminal enforcement provisions set forth at 42 U.S.C. 1320d-5 and 1320d- 6, as amended from time to time, for failure to comply with the safeguard, policies and procedures requirements and any guidance issued by the Secretary from time to time with respect to such requirements. (n) With respect to Electronic Protected Health Information, Business Associate shall ensure that any subcontractors that create, receive, maintain, or transmit Electronic Protected Health Information on behalf of Business Associate, agree to comply with the applicable requirements of Subpart C of 45 C.F.R. Part 164 by entering into a contract that complies with 45 C.F.R. Section 164.314. (o) Business Associate shall report to Covered Entity any Security Incident of which it becomes aware, including Breaches of Unsecured Protected Health Information as required by 45 C.F.R. Section 164.410. (p) If Business Associate conducts any Standard Transactions on behalf of Covered Entity, Business Associate shall comply with the applicable requirements of 45 C.F.R. Parts 160-162. (q) During the term of this Agreement, Business Associate may be asked to complete a security survey and/or attestation document designed to assist Covered Entity in understanding and documenting Business Associate’s security procedures and compliance with the requirements contained herein. Business Associate’s failure to complete either of these documents within the reasonable timeframe specified by Covered Entity shall constitute a material breach of this Agreement. (r) Business Associate acknowledges that, as of the Effective Date of this Agreement, it shall be liable under the civil and criminal enforcement provisions set forth at 42 U.S.C. 1320d-5 and 1320d-6, as amended from time to time, for failure to comply with any of the use and disclosure requirements of this Agreement and any guidance issued by the Secretary from time to time with respect to such use and disclosure requirements. (s) To the extent Business Associate is to carry out one or more of Covered Entity’s obligation(s) under Subpart E of 45 CFR Part 164, Business Associate shall comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s). 3. Permitted Uses and Disclosures by Business Associate. 3.1 General Use and Disclosure. Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform its obligations and services to Covered Entity, provided that such use or disclosure would not violate the Privacy and Security Rules if done by Covered Entity or the minimum necessary policies and procedures of the Covered Entity. 3.2 Specific Use and Disclosure Provisions. (a) Except as otherwise prohibited by this Agreement, Business Associate may use Protected Health Information for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate. (b) Except as otherwise prohibited by this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of the Business Associate, provided that disclosures are Required By Law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as Required By Law or for the purpose for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached in accordance with the Breach and Security Incident notifications requirements of this Agreement. (c) Business Associate shall not directly or indirectly receive remuneration in exchange for any Protected Health Information of an Individual without Covered Entity’s prior written approval and notice from Covered Entity that it has obtained from the Individual, in accordance with 45 C.F.R. 164.508, a valid authorization that includes a specification of whether the Protected Health Information can be further Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Page 4 BAA – Mercy Care BA Web Portal rev 07.2025 exchanged for remuneration by Business Associate. The foregoing shall not apply to Covered Entity’s payments to Business Associate for services delivered by Business Associate to Covered Entity. (d) Business Associate shall not de-identify any Protected Health Information except as authorized by Covered Entity to provide data aggregation services to Covered Entity as permitted by 42 C.F.R. 164.504(e)(2)(i)(B). (e) Business Associate may use Protected Health Information to report violation of law to appropriate Federal and State authorities, consistent with 164.502 (j)(1). 4. Obligations of Covered Entity. 4.1 Provisions for Covered Entity to Inform Business Associate of Privacy Practices and Restrictions. (a) Covered Entity shall notify Business Associate of any limitation(s) in Covered Entity’s notice of privacy practices that Covered Entity produces in accordance with 45 C.F.R. 164.520 (as well as any changes to that notice), to the extent that such limitation(s) may affect Business Associate’s use or disclosure of Protected Health Information. (b) Covered Entity shall provide Business Associate with any changes in, or revocation of, permission by Individual to use or disclose Protected Health Information, to the extent that such changes affect Business Associate’s use or disclosure of Protected Health Information. (c) Covered Entity shall notify Business Associate of any restriction to the use or disclosure of Protected Health Information that Covered Entity has agreed to in accordance with 45 C.F.R. 164.522, to the extent that such restriction may affect Business Associate’s use or disclosure of Protected Health Information. 4.2 Permissible Requests by Covered Entity. Except as may be set forth in Section 3.2, Covered Entity shall not request Business Associate to use or disclose Protected Health Information in any manner that would not be permissible under the Privacy and Security Rules if done by Covered Entity. 5. Term and Termination. (a) Term. The provisions of this Agreement shall take effect on the Agreement’s Effective Date and shall terminate when all of the Protected Health Information provided by Covered Entity to Business Associate, or created, maintained, transmitted or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, in accordance with Section 5(c)(2). (b) Termination for Cause. Without limiting the termination rights of the Parties pursuant to the Agreement and upon Covered Entity’s knowledge of a material breach of this Agreement by Business Associate, Covered Entity shall either: (i) Provide an opportunity for Business Associate to cure the breach or end the violation, or terminate the Agreement if Business Associate does not cure the breach or end the violation within the time specified by Covered Entity, (ii) Immediately terminate the Agreement, if cure of such breach is not possible. (c) Effect of Termination. (1) Except as provided in Section 5(c), upon termination of this Agreement, for any reason, Business Associate shall return or destroy all Protected Health Information received from Covered Entity, or created, maintained, transmitted or received by Business Associate on behalf of Covered Entity. This provision shall apply to Protected Health Information that is in the possession of subcontractors or agents of Business Associate. Business Associate shall retain no copies of the Protected Health Information. (2) In the event the Business Associate determines that returning or destroying the Protected Health Information is infeasible, Business Associate shall provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon mutual agreement of the Parties that return or destruction of Protected Health Information is infeasible, per Section 5(a) above, Business Associate shall continue to extend the protection of this Agreement to such Protected Health Information and limit further uses and disclosures of such Protected Health Information for so long as Business Associate maintains such Protected Health Information. 6. Indemnification. Business Associate shall indemnify and hold harmless Covered Entity and any of Covered Entity’s affiliates, directors, officers, employees and agents from and against any claim, cause of action, liability, damage, cost or expense (including reasonable attorneys’ fees) arising out of or relating to any non-permitted use or disclosure of Protected Health Information, failure to safeguard Electronic Protected Health Information, or other breach of this Agreement by Business Associate or any affiliate, director, officer, employee, agent or subcontractor of Business Associate. Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Page 5 BAA – Mercy Care BA Web Portal rev 07.2025 7. Notices. Any notices or communications to be given under this Agreement shall be made to the address and/or fax numbers given below: To Business Associate: To Covered Entity: Maricopa County Mercy Care c/o Aetna Correctional Health Services HIPAA Member Rights Team 234 N. Central Avenue, Suite 5000 151 Farmington Avenue, AN33 Phoenix, AZ 85004 Hartford, CT 06156 Fax: (859) 280-1272 Copy to: chsmasteragreements@maricopa.gov communitytreatmentservices@maricopa.gov HIPAAFulfillment@aetna.com Copy to: Mercy Care Attn: Legal Dept. 4750 S. 44th Pl, Suite 150 Phoenix, AZ 85040 Each Party named above may change its address upon thirty (30) days written notice to the other Party. 8. Miscellaneous. (a) Regulatory References. A reference in this Agreement to a section in the Privacy and Security Rules means the section as in effect or as amended, and for which compliance is required. (b) Amendment. Upon the enactment of any law or regulation affecting the use or disclosure of Protected Health Information or the safeguarding of Electronic Protected Health Information, or the publication of any decision of a court of the United States or any state relating to any such law or the publication of any interpretive policy or opinion of any governmental agency charged with the enforcement of any such law or regulation, either Party may, by written notice to the other Party, amend the Agreement in such manner as such Party determines necessary to comply with such law or regulation. If the other Party disagrees with such amendment, it shall so notify the first Party in writing within thirty (30) days of the notice. If the Parties are unable to agree on an amendment within thirty (30) days thereafter, then either of the Parties may terminate the Agreement on thirty (30) days written notice to the other Party. (c) Survival. The respective rights and obligations of Business Associate under Sections 5(c) and 6 of this Agreement shall survive the termination of this Agreement. (d) Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with the Privacy and Security Rules. In the event of any inconsistency or conflict between this Agreement and any other agreement between the Parties, the terms, provisions and conditions of this Agreement shall govern and control. (e) No third party beneficiary. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than the Parties and the respective successors or assigns of the Parties, any rights, remedies, obligations, or liabilities whatsoever. (f) Governing Law. This Agreement shall be governed by and construed in accordance with the laws of Arizona. (g) Scope. This BAA is limited to the purpose of the agreement it is attached to and does not replace or modify any other existing BAA that Business Associate may have entered into with Mercy Care or an affiliate. [This portion of the page has been left intentionally blank and is followed by the signature page.] Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C Page 6 BAA – Mercy Care BA Web Portal rev 07.2025 IN WITNESS WHEREOF, this Agreement is executed on the date set forth below when executed by both Parties' Authorized Representative. MERCY CARE MARICOPA COUNTY BOARD OF SUPERVISORS Tad Gary Tad Gary (Sep 18, 2025 07:14:37 PDT) Authorized Signature Authorized Signature Tad Gary, Chief Executive Officer Printed Name and Title Chairman, Board of Supervisors 09/18/2025 Date Date ATTEST: Clerk of the Board Date: Approved as to form: Deputy County Attorney Date: Docusign Envelope ID: D5F40F3C-C1FA-481B-8BFC-EF69F8C60E3C 9/23/2025