COMPLETE_WITH_DOCUSIGN_UNITE_US_BAA_-_MARICO.PDF

Maricopa County — Formal (2025-07-04)

View PDF Item 74 Meeting page

Extracted text (via pymupdf) 17083 characters
HIPAA BUSINESS ASSOCIATE ADDENDUM  
  
THIS HIPAA BUSINESS ASSOCIATE ADDENDUM (the “Addendum”) to the underlying agreement (the “Underlying 
Agreement”) between the covered entity listed on the signature page (“Covered Entity” or “CE”) and Unite USA Inc. 
(”Unite Us” or “BA”), a Delaware corporation with offices located at 217 Broadway, Floor 8, New York, NY 10007 is 
effective as of the last date set forth on the signature page (the “Effective Date”). This Addendum supplements and 
is made a part of any agreements between CE and BA involving the use or disclosure of Protected Health Information 
(“PHI”).  
  
WITNESSETH:  
WHEREAS, BA wishes to or has entered into the Underlying Agreement whereby BA shall provide to CE case 
management and/or care coordination software services; and  
WHEREAS, CE wishes to disclose certain information to BA pursuant to the terms of the Underlying 
Agreement, some of which may constitute PHI;  
NOW, THEREFORE, in consideration of the premises and the mutual covenants set forth herein and for other 
good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties hereto 
covenant and agree as follows:  
1. 
DEFINITIONS  
The following terms used in this Addendum shall have the same meaning as those terms in the HIPAA Rules:  
Covered Entity, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum  
Necessary, required by Law, Secretary, Security Incident, Security Rule; Subcontractor, Unsecured Protected Health 
Information, and Use. Any other undefined term with a capital letter shall have the same meaning as such term in 
the HIPAA Rules.  
1.1. “Breach” shall mean any unauthorized acquisition, access, use or disclosure of PHI/ePHI that does not meet 
one of the three exceptions. Exceptions provided in the Final Rule are (a) Unintentional acquisition, access 
or use of PHI by a workforce member in the scope of duties and no further access or disclosure, (b) 
Inadvertent disclosure from one authorized person to another within the same CE/BA and no further access 
or disclosure, or (3) Disclosure of PHI where CE/BA has good faith belief that the recipient cannot retain the 
information.  
  
1.2. “Business Associate” shall generally have the same meaning as the term “business associate” at 45 CFR 
160.103, and in reference to the party to this Addendum, shall mean Unite USA Inc.  
  
1.3. “HIPAA Rules” shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 
160 and Part 164 including the Health Information Technology for Economic and Clinical Health Act 
(“HITECH Act”) codified at 42 U.S.C. §§17921-7954 and the Final Omnibus Rule (78 Fed. Reg. 5566) (Final 
Rule) as in effect or as amended from time to time.  
  
1.4. “Protected Health Information” or “PHI” shall have the meaning given to such term in 45 CFR §160.103 
and shall include, without limitation, any information, whether oral or recorded in any form or medium, 
created or received by Business Associate from or on behalf of Covered Entity: (a) that relates to the past, 
present or future physical or mental condition of an Individual; the provision of health care to an Individual; 
or the past, present or future payment for the provision of health care to an Individual, and (b) that 
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F

identifies the Individual or with respect to which there is a reasonable basis to believe the information can 
be used to identify the Individual.  
  
2. 
PURPOSE. The Parties hereby agree that except as otherwise limited in this Addendum, BA shall be 
permitted to use or disclose PHI provided or made available from CE to perform any function, activity or 
service for, or on behalf of, CE as specified in the Underlying Agreement.  
  
3. 
OBLIGATIONS OF BUSINESS ASSOCIATE. BA covenants and agrees that it shall:  
  
3.1. Not use or further disclose PHI other than as permitted or required under this Addendum or as required by 
law;  
  
3.2. Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI, 
to prevent use or disclosure of PHI other than as provided for by this Addendum;  
  
3.3. Maintain a written information security program consistent with HIPAA standards that include 
administrative, technical, and physical safeguards to maintain the security of and prevent unauthorized 
access to Covered Entity’s PHI;  
  
3.4. Conduct a security risk assessment in compliance with HIPAA and the HITECH Act;  
  
3.5. Report to CE any use or disclosure of PHI not provided for by this Addendum of which it becomes aware, 
including Breaches of unsecured PHI as required at 45 CFR 164.410, and any security incident of which it 
becomes aware as soon as possible and no later than within three business days of becoming aware of such 
Breach. Subsequent investigation shall include to the extent feasible, a prompt report to CE of the 
identification of each individual whose unsecured PHI has been, or is reasonably believed by BA to have 
been accessed, acquired, or disclosed during such Breach, and any other information that CE deems 
necessary to meet its breach notification obligations under HIPAA;  
  
3.6. In the event of a Breach, BA shall in consultation with CE, mitigate to the extent practical any harmful effect 
of such Breach that is known to BA;  
  
3.7. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any subcontractors 
that create, receive, maintain, or transmit PHI on behalf of BA agree to the same restrictions, conditions, 
and requirements that apply to it with respect to such information;  
  
3.8. Make available PHI in a designated record set to CE or to an individual patient as necessary to satisfy CE’s 
obligations under 45 CFR 164.524;  
  
3.9. Make any amendment(s) to PHI in a designated record set as directed or agreed to by CE pursuant to 45 
CFR 164.526, or to an individual patient as necessary or take other measures as necessary to satisfy its 
obligations under 45 CFR 164.526;  
  
3.10. Maintain and make available the information required to provide an accounting of disclosures to CE or to 
an individual patient as necessary to satisfy its obligations under 45 CFR 164.528;  
  
3.11. To the extent BA is to carry out one or more of CE’s obligation(s) under Subpart E of 45 CFR Part 164, comply 
with the requirements of Subpart E that apply to its performance of such obligation(s);  
  
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F

3.12. Adopt and implement a policy and procedure for adhering to the HIPAA rules, if BA performs marketing or 
fundraising services on behalf of CE and uses or discloses PHI in furtherance of those services, and shall 
remove the names of all Individuals who have expressly opted out of receiving future marketing or 
fundraising materials from BA on CE’s behalf. If CE receives information of an Individual’s request to opt  
out of future mailings, CE agrees to notify BA of such request as soon as reasonably practicable;  
  
3.13. Make its internal practices, books, records and policies and procedures and documentation requirements 
relating to the use and disclosure of PHI received from, or created by, BA on behalf of CE available to the 
Secretary for purposes of determining compliance with the HIPAA Rules; and  
  
3.14. In the event BA receives a valid order issued by a judicial, governmental or regulatory entity or mandate for 
release of PHI, BA shall be permitted to disclose such PHI after notifying CE of the request as soon as 
commercially practicable. At the sole cost of CE, BA provide reasonable assistance to CE in seeking a 
protective order or. BA shall, to the extent reasonably practicable, consult with CE prior to responding and 
shall advise CE of how it intends to respond as soon as such determination is made.  
4. 
PERMITTED USES AND DISCLOSURES BY BA.  
  
4.1. BA may only use or disclose PHI as necessary to perform the services set forth in the Underlying Agreement, 
including for reporting on and evaluating the network or as required by law.  
  
4.2. BA may use or disclose PHI as required by law.  
  
4.3. BA agrees to make uses and disclosures and requests for PHI consistent with CE’s minimum necessary 
policies and procedures.  
  
4.4. BA may not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by CE.  
  
4.5. BA may use PHI in its possession to provide data aggregation services relating to the health care operations 
of CE, as provided for in 45 C.F.R. § 164.501.  
4.6. BA may disclose PHI in its possession to third parties (subcontractors) for the purpose of its proper 
management and administration or to fulfill any of its present or future legal responsibilities provided that 
the disclosures are required by law or BA has entered into an agreement with subcontractor for the 
protection and use of PHI with substantially similar terms to this one.  
  
4.7. BA may disclose PHI to other health care providers for the treatment purposes of such provider.  
5. 
NOTIFICATION OF PRIVACY PRACTICES AND RESTRICTIONS.  
  
5.1. CE shall notify BA of any changes in, or revocation of, the permission by an individual to use or disclose 
his/her PHI, to the extent that such changes may affect BA’s use or disclosure of PHI.  
  
5.2. CE shall notify BA of any restriction on the use or disclosure of PHI that CE has agreed to or is required to 
abide by 45 CFR 164.522, to the extent that such restriction may affect BA’s use or disclosure of PHI.  
6. 
UNILATERAL TERMINATION. Notwithstanding any other provision under this Addendum and pursuant to 
federal law, BA agrees that this Addendum and the Underlying Agreement may be terminated by CE without 
penalty should CE, in its sole discretion, determine that BA has violated a material obligation under this 
Addendum, provided that, CE provides BA with adequate prior notice for BA to remedy the violation.  
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F

7. 
JUDICIAL OR ADMINISTRATIVE PROCEEDINGS. CE may terminate this Addendum and the Underlying  
Agreement, effective immediately, if (a) BA is named as a defendant in a criminal proceeding for a violation of HIPAA 
or (b) a finding or stipulation that BA has violated any standard or requirement of HIPAA or other security or privacy 
laws is made in any administrative or civil proceeding in which BA has been named.  
  
8. 
RETURN OR DESTRUCTION OF PHI. Upon termination, cancellation, or expiration of the Underlying 
Agreement, it will be infeasible to return or destroy any and all PHI which has been stored via Unite Us 
system as it is needed to provide consumer care and services; the terms of this Addendum shall extend to 
all such PHI and any further use or disclosure of the PHI by BA shall be limited to that purpose which renders 
the return or destruction of the PHI infeasible, namely providing consumer care and services. If returning 
the PHI to CE is not feasible, BA shall destroy any and all PHI maintained by BA in any form whatsoever, 
including any copies thereof, with the exception of historical data which must be maintained in order to 
provide continuity of service to consumers. Should the return or destruction of the PHI be determined by 
BA to not be feasible, the terms of this Addendum shall extend to the PHI until otherwise indicated by CE, 
and any further use or disclosure of the PHI by BA shall be limited to that purpose which renders the return 
or destruction of the PHI infeasible. Destruction of PHI must be in accordance with HHS standards and 
processes for rendering PHI unusable, unreadable, or indecipherable to unauthorized individuals so that it 
is no longer Unsecured PHI. BA shall complete such return or destruction as promptly as possible, but not 
later than thirty (30) days after the effective date of termination, cancellation, or expiration of the Underlying 
Agreement. Within such thirty (30) days, BA shall certify in writing to CE that such return or destruction has 
been completed, will deliver to CE identification of PHI for which return or destruction is infeasible and, for 
that PHI, will certify that it will only use or disclose such PHI for those purposes that make return or 
destruction infeasible.  
9. 
INDEMNIFICATION. Each Party agrees to indemnify, defend and hold harmless the other Party, its affiliates 
and each of their respective directors, officers, employees, agents or assigns from and against any and all 
other actions, causes of action, claims, suits and demands whatsoever, and from all damages, liabilities, 
costs, charges, debts, and expenses whatsoever (including costs associated with providing required 
notifications in the event of BA’s breach of Unsecured PHI, and reasonable attorneys’ fees and expenses 
related to any litigation or other defense of any claims), which may be asserted, up to the amount of 
payment made to BA from CE, or for which they may now or hereafter become subject arising in connection 
with (a) any misrepresentation, breach of warranty or non- fulfillment of any undertaking on the part of the 
Party under this Addendum; and (b) any claims, demands, awards, judgments, actions, and proceedings 
made by any person or organization arising out of or in any way connected with the Party’s performance 
under this Addendum. Notwithstanding the foregoing, neither Party shall be required to indemnify the other 
Party for any action, claim, suit, or demand that arises from the gross negligence or willful or intentional 
misconduct of the other Party.  
  
10. 
LIMITATION OF LIABILITY. Except for liability arising as a result of a Party’s gross negligence or willful or 
intentional misconduct, in no other event shall either Party’s aggregate liability under this Addendum exceed 
two times the aggregate fees for services under the Underlying Agreement.  
  
11. 
NO THIRD-PARTY BENEFICIARIES. Nothing express or implied in this Addendum is intended to confer, nor 
shall anything herein confer, upon any person other than CE, BA, and their respective successors or assigns, 
any rights, remedies, obligations, or liabilities whatsoever.  
  
12. 
TERM. This Addendum shall become effective on the Effective Date and shall expire when the entire PHI 
provided by CE to BA is destroyed or returned to CE pursuant to Section 8 above. The Parties agree that 
Sections 2, 3, 4, 10 and 11 of this Addendum shall survive the termination or expiration of this Addendum. 
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F

Either Party may terminate this Addendum immediately in the event of (a) a material breach that cannot 
reasonably be cured within fourteen days, (b) repeated breaches of the same material obligation or (c) a 
breach that would expose the non- breaching Party to civil or criminal liability or would otherwise cause a 
violation of applicable laws, rules, regulations or accreditation standards applicable to the non-breaching 
Party.  
[remainder of this page intentionally left blank]  
IN WITNESS THEREOF, the parties have caused this Addendum to be duly executed by their duly authorized 
representatives as of the Effective Date.  
  
 
BA:   
  
  
  
  
  
        Covered Entity:  
 
UNITE USA INC.     
  
  
  
  
MARICOPA COUNTY   
  
  
  
   
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
 
Authorized Signature  
  
  
  
  
Authorized Signature  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
 
Printed Name and Title  
  
  
  
  
Chairman, Board of Supervisors  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
 
Date  
  
  
  
  
  
  
Date  
  
ATTEST:  
  
  
  
  
  
  
  
  
Clerk of the Board  
  
 
Date:     
  
  
  
  
  
  
Approved as to form:  
  
  
  
  
  
  
  
  
Deputy County Attorney  
  
 
Date:     
  
  
  
  
  
  
Unite Us Address for Notices:                                                  Covered Entity Address for Notices:  
  
Unite USA Inc.     Maricopa County Correctional Health Services  217 Broadway, Floor 8     2670 S 28th Dr.  
 
New York, NY 10007    
  
  
  
Phoenix, AZ 85009  
  
  
  
  
 
Attn: Finance;  
  
  
  
  
Attn: Community Transitions  
General Counsel  
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Apollinaire Amondji
CFO
7/10/2025
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F
7/14/2025

With a copy to:  
  
  
  
  
With a copy to:  
Email: finance@uniteus.com    
  
  
Email: 
communitytreatmentservices@maricopa.gov 
Email: legal@uniteus.com   
  
  
Email: chsmasteragreements@maricopa.gov  
  
  
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F