COMPLETE_WITH_DOCUSIGN_UNITE_US_BAA_-_MARICO.PDF
Extracted text (via pymupdf)
17083 characters
HIPAA BUSINESS ASSOCIATE ADDENDUM
THIS HIPAA BUSINESS ASSOCIATE ADDENDUM (the “Addendum”) to the underlying agreement (the “Underlying
Agreement”) between the covered entity listed on the signature page (“Covered Entity” or “CE”) and Unite USA Inc.
(”Unite Us” or “BA”), a Delaware corporation with offices located at 217 Broadway, Floor 8, New York, NY 10007 is
effective as of the last date set forth on the signature page (the “Effective Date”). This Addendum supplements and
is made a part of any agreements between CE and BA involving the use or disclosure of Protected Health Information
(“PHI”).
WITNESSETH:
WHEREAS, BA wishes to or has entered into the Underlying Agreement whereby BA shall provide to CE case
management and/or care coordination software services; and
WHEREAS, CE wishes to disclose certain information to BA pursuant to the terms of the Underlying
Agreement, some of which may constitute PHI;
NOW, THEREFORE, in consideration of the premises and the mutual covenants set forth herein and for other
good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties hereto
covenant and agree as follows:
1.
DEFINITIONS
The following terms used in this Addendum shall have the same meaning as those terms in the HIPAA Rules:
Covered Entity, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum
Necessary, required by Law, Secretary, Security Incident, Security Rule; Subcontractor, Unsecured Protected Health
Information, and Use. Any other undefined term with a capital letter shall have the same meaning as such term in
the HIPAA Rules.
1.1. “Breach” shall mean any unauthorized acquisition, access, use or disclosure of PHI/ePHI that does not meet
one of the three exceptions. Exceptions provided in the Final Rule are (a) Unintentional acquisition, access
or use of PHI by a workforce member in the scope of duties and no further access or disclosure, (b)
Inadvertent disclosure from one authorized person to another within the same CE/BA and no further access
or disclosure, or (3) Disclosure of PHI where CE/BA has good faith belief that the recipient cannot retain the
information.
1.2. “Business Associate” shall generally have the same meaning as the term “business associate” at 45 CFR
160.103, and in reference to the party to this Addendum, shall mean Unite USA Inc.
1.3. “HIPAA Rules” shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part
160 and Part 164 including the Health Information Technology for Economic and Clinical Health Act
(“HITECH Act”) codified at 42 U.S.C. §§17921-7954 and the Final Omnibus Rule (78 Fed. Reg. 5566) (Final
Rule) as in effect or as amended from time to time.
1.4. “Protected Health Information” or “PHI” shall have the meaning given to such term in 45 CFR §160.103
and shall include, without limitation, any information, whether oral or recorded in any form or medium,
created or received by Business Associate from or on behalf of Covered Entity: (a) that relates to the past,
present or future physical or mental condition of an Individual; the provision of health care to an Individual;
or the past, present or future payment for the provision of health care to an Individual, and (b) that
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F
identifies the Individual or with respect to which there is a reasonable basis to believe the information can
be used to identify the Individual.
2.
PURPOSE. The Parties hereby agree that except as otherwise limited in this Addendum, BA shall be
permitted to use or disclose PHI provided or made available from CE to perform any function, activity or
service for, or on behalf of, CE as specified in the Underlying Agreement.
3.
OBLIGATIONS OF BUSINESS ASSOCIATE. BA covenants and agrees that it shall:
3.1. Not use or further disclose PHI other than as permitted or required under this Addendum or as required by
law;
3.2. Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI,
to prevent use or disclosure of PHI other than as provided for by this Addendum;
3.3. Maintain a written information security program consistent with HIPAA standards that include
administrative, technical, and physical safeguards to maintain the security of and prevent unauthorized
access to Covered Entity’s PHI;
3.4. Conduct a security risk assessment in compliance with HIPAA and the HITECH Act;
3.5. Report to CE any use or disclosure of PHI not provided for by this Addendum of which it becomes aware,
including Breaches of unsecured PHI as required at 45 CFR 164.410, and any security incident of which it
becomes aware as soon as possible and no later than within three business days of becoming aware of such
Breach. Subsequent investigation shall include to the extent feasible, a prompt report to CE of the
identification of each individual whose unsecured PHI has been, or is reasonably believed by BA to have
been accessed, acquired, or disclosed during such Breach, and any other information that CE deems
necessary to meet its breach notification obligations under HIPAA;
3.6. In the event of a Breach, BA shall in consultation with CE, mitigate to the extent practical any harmful effect
of such Breach that is known to BA;
3.7. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any subcontractors
that create, receive, maintain, or transmit PHI on behalf of BA agree to the same restrictions, conditions,
and requirements that apply to it with respect to such information;
3.8. Make available PHI in a designated record set to CE or to an individual patient as necessary to satisfy CE’s
obligations under 45 CFR 164.524;
3.9. Make any amendment(s) to PHI in a designated record set as directed or agreed to by CE pursuant to 45
CFR 164.526, or to an individual patient as necessary or take other measures as necessary to satisfy its
obligations under 45 CFR 164.526;
3.10. Maintain and make available the information required to provide an accounting of disclosures to CE or to
an individual patient as necessary to satisfy its obligations under 45 CFR 164.528;
3.11. To the extent BA is to carry out one or more of CE’s obligation(s) under Subpart E of 45 CFR Part 164, comply
with the requirements of Subpart E that apply to its performance of such obligation(s);
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F
3.12. Adopt and implement a policy and procedure for adhering to the HIPAA rules, if BA performs marketing or
fundraising services on behalf of CE and uses or discloses PHI in furtherance of those services, and shall
remove the names of all Individuals who have expressly opted out of receiving future marketing or
fundraising materials from BA on CE’s behalf. If CE receives information of an Individual’s request to opt
out of future mailings, CE agrees to notify BA of such request as soon as reasonably practicable;
3.13. Make its internal practices, books, records and policies and procedures and documentation requirements
relating to the use and disclosure of PHI received from, or created by, BA on behalf of CE available to the
Secretary for purposes of determining compliance with the HIPAA Rules; and
3.14. In the event BA receives a valid order issued by a judicial, governmental or regulatory entity or mandate for
release of PHI, BA shall be permitted to disclose such PHI after notifying CE of the request as soon as
commercially practicable. At the sole cost of CE, BA provide reasonable assistance to CE in seeking a
protective order or. BA shall, to the extent reasonably practicable, consult with CE prior to responding and
shall advise CE of how it intends to respond as soon as such determination is made.
4.
PERMITTED USES AND DISCLOSURES BY BA.
4.1. BA may only use or disclose PHI as necessary to perform the services set forth in the Underlying Agreement,
including for reporting on and evaluating the network or as required by law.
4.2. BA may use or disclose PHI as required by law.
4.3. BA agrees to make uses and disclosures and requests for PHI consistent with CE’s minimum necessary
policies and procedures.
4.4. BA may not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by CE.
4.5. BA may use PHI in its possession to provide data aggregation services relating to the health care operations
of CE, as provided for in 45 C.F.R. § 164.501.
4.6. BA may disclose PHI in its possession to third parties (subcontractors) for the purpose of its proper
management and administration or to fulfill any of its present or future legal responsibilities provided that
the disclosures are required by law or BA has entered into an agreement with subcontractor for the
protection and use of PHI with substantially similar terms to this one.
4.7. BA may disclose PHI to other health care providers for the treatment purposes of such provider.
5.
NOTIFICATION OF PRIVACY PRACTICES AND RESTRICTIONS.
5.1. CE shall notify BA of any changes in, or revocation of, the permission by an individual to use or disclose
his/her PHI, to the extent that such changes may affect BA’s use or disclosure of PHI.
5.2. CE shall notify BA of any restriction on the use or disclosure of PHI that CE has agreed to or is required to
abide by 45 CFR 164.522, to the extent that such restriction may affect BA’s use or disclosure of PHI.
6.
UNILATERAL TERMINATION. Notwithstanding any other provision under this Addendum and pursuant to
federal law, BA agrees that this Addendum and the Underlying Agreement may be terminated by CE without
penalty should CE, in its sole discretion, determine that BA has violated a material obligation under this
Addendum, provided that, CE provides BA with adequate prior notice for BA to remedy the violation.
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F
7.
JUDICIAL OR ADMINISTRATIVE PROCEEDINGS. CE may terminate this Addendum and the Underlying
Agreement, effective immediately, if (a) BA is named as a defendant in a criminal proceeding for a violation of HIPAA
or (b) a finding or stipulation that BA has violated any standard or requirement of HIPAA or other security or privacy
laws is made in any administrative or civil proceeding in which BA has been named.
8.
RETURN OR DESTRUCTION OF PHI. Upon termination, cancellation, or expiration of the Underlying
Agreement, it will be infeasible to return or destroy any and all PHI which has been stored via Unite Us
system as it is needed to provide consumer care and services; the terms of this Addendum shall extend to
all such PHI and any further use or disclosure of the PHI by BA shall be limited to that purpose which renders
the return or destruction of the PHI infeasible, namely providing consumer care and services. If returning
the PHI to CE is not feasible, BA shall destroy any and all PHI maintained by BA in any form whatsoever,
including any copies thereof, with the exception of historical data which must be maintained in order to
provide continuity of service to consumers. Should the return or destruction of the PHI be determined by
BA to not be feasible, the terms of this Addendum shall extend to the PHI until otherwise indicated by CE,
and any further use or disclosure of the PHI by BA shall be limited to that purpose which renders the return
or destruction of the PHI infeasible. Destruction of PHI must be in accordance with HHS standards and
processes for rendering PHI unusable, unreadable, or indecipherable to unauthorized individuals so that it
is no longer Unsecured PHI. BA shall complete such return or destruction as promptly as possible, but not
later than thirty (30) days after the effective date of termination, cancellation, or expiration of the Underlying
Agreement. Within such thirty (30) days, BA shall certify in writing to CE that such return or destruction has
been completed, will deliver to CE identification of PHI for which return or destruction is infeasible and, for
that PHI, will certify that it will only use or disclose such PHI for those purposes that make return or
destruction infeasible.
9.
INDEMNIFICATION. Each Party agrees to indemnify, defend and hold harmless the other Party, its affiliates
and each of their respective directors, officers, employees, agents or assigns from and against any and all
other actions, causes of action, claims, suits and demands whatsoever, and from all damages, liabilities,
costs, charges, debts, and expenses whatsoever (including costs associated with providing required
notifications in the event of BA’s breach of Unsecured PHI, and reasonable attorneys’ fees and expenses
related to any litigation or other defense of any claims), which may be asserted, up to the amount of
payment made to BA from CE, or for which they may now or hereafter become subject arising in connection
with (a) any misrepresentation, breach of warranty or non- fulfillment of any undertaking on the part of the
Party under this Addendum; and (b) any claims, demands, awards, judgments, actions, and proceedings
made by any person or organization arising out of or in any way connected with the Party’s performance
under this Addendum. Notwithstanding the foregoing, neither Party shall be required to indemnify the other
Party for any action, claim, suit, or demand that arises from the gross negligence or willful or intentional
misconduct of the other Party.
10.
LIMITATION OF LIABILITY. Except for liability arising as a result of a Party’s gross negligence or willful or
intentional misconduct, in no other event shall either Party’s aggregate liability under this Addendum exceed
two times the aggregate fees for services under the Underlying Agreement.
11.
NO THIRD-PARTY BENEFICIARIES. Nothing express or implied in this Addendum is intended to confer, nor
shall anything herein confer, upon any person other than CE, BA, and their respective successors or assigns,
any rights, remedies, obligations, or liabilities whatsoever.
12.
TERM. This Addendum shall become effective on the Effective Date and shall expire when the entire PHI
provided by CE to BA is destroyed or returned to CE pursuant to Section 8 above. The Parties agree that
Sections 2, 3, 4, 10 and 11 of this Addendum shall survive the termination or expiration of this Addendum.
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F
Either Party may terminate this Addendum immediately in the event of (a) a material breach that cannot
reasonably be cured within fourteen days, (b) repeated breaches of the same material obligation or (c) a
breach that would expose the non- breaching Party to civil or criminal liability or would otherwise cause a
violation of applicable laws, rules, regulations or accreditation standards applicable to the non-breaching
Party.
[remainder of this page intentionally left blank]
IN WITNESS THEREOF, the parties have caused this Addendum to be duly executed by their duly authorized
representatives as of the Effective Date.
BA:
Covered Entity:
UNITE USA INC.
MARICOPA COUNTY
Authorized Signature
Authorized Signature
Printed Name and Title
Chairman, Board of Supervisors
Date
Date
ATTEST:
Clerk of the Board
Date:
Approved as to form:
Deputy County Attorney
Date:
Unite Us Address for Notices: Covered Entity Address for Notices:
Unite USA Inc. Maricopa County Correctional Health Services 217 Broadway, Floor 8 2670 S 28th Dr.
New York, NY 10007
Phoenix, AZ 85009
Attn: Finance;
Attn: Community Transitions
General Counsel
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Apollinaire Amondji
CFO
7/10/2025
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F
7/14/2025
With a copy to:
With a copy to:
Email: finance@uniteus.com
Email:
communitytreatmentservices@maricopa.gov
Email: legal@uniteus.com
Email: chsmasteragreements@maricopa.gov
Docusign Envelope ID: 0BA3E990-5D5A-4B39-A1B1-6587FEB60110
Docusign Envelope ID: 571DFEC4-FD78-4F90-8AC4-751D9676928F