COMPUMED - BUSINESS ASSOCIATE AGREEMENT - SIGNED.PDF

Maricopa County — Formal (2020-03-25)

View PDF Item 25 Meeting page

Extracted text (via pymupdf) 23742 characters
5777 W Century Blvd 
Suite 360 	
Main: 310.258.5000 
Los Angeles, CA 90045 	
Fax: 310.694.3963 
TM 	
Business Associate Agreement 
This BUSINESS ASSOCIATE AGREEMENT ("Agreement") is entered 
into by and between Maricopa County Correctional Health 
Service (Maricopa Co.) (the "COVERED ENTITY") and CompuMed, 
Inc. (the "BUSINESS ASSOCIATE") as of the date fully executed 
below. 
WHEREAS the U.S. Department of Health and Human Services 
issued regulations on "Standards for Privacy of Individually 
Identifiable Health Information" comprising 45 C.F.R. Parts 160 
and 164, Subparts A and E (the "Privacy Standards"), "Security 
Standards for the Protection of Electronic Protected Health 
Information" comprising 45 C.F.R. Parts 160 and 164, Subpart C 
(the "Security Standards"), and "Standards for Notification in the 
Case of Breach of Unsecured Protected Health Information" 
comprising 45 C.F.R. Parts 160 and 164, Subpart D (the "Breach 
Notification Standards"), promulgated pursuant to the Health 
Insurance Portability and Accountability Act of 1996 (the Privacy 
Standards, the Security Standards, and the Breach Notification 
Standards are collectively referred to herein as the "HIPAA 
Standards"). 
WHEREAS, COVERED ENTITY is an organization engaged in 
providing health care services; 
WHEREAS, COVERED ENTITY will make available and/or transfer 
to BUSINESS ASSOCIATE certain Protected Health Information, in 
conjunction with services to be provided by BUSINESS 
ASSOCIATE to COVERED ENTITY as specified in the underlying 
services agreement between the Parties ("Services Agreement"), 
that is confidential and must be afforded special treatment and 
protection; 
WHEREAS, BUSINESS ASSOCIATE will have access to and discover 
or create confidential PHI that can be used or disclosed only in 
accordance with this Agreement and the HIPAA Standards. 
NOW THEREFORE, for and in consideration of the mutual 
promises and covenants contained herein and in order to assure 
compliance with the HIPAA Standards, the Parties agree as 
follows: 
1. Definitions. The following terms shall have the meaning 
ascribed to them in this Section. Other capitalized terms shall 
have the meaning ascribed to them in the context in which they 
first appear. 
a) Individual shall mean the person who is the subject of the 
PHI and shall include a person who qualifies as a personal 
representative in accordance with 45 C.F.R. § 164.502(g). 
b) Individually identifiable health information is information 
that is a subset of health information, including demographic 
information collected from an individual, and: (1) is created or 
received by a health care provider, health plan, employer, or 
health care clearinghouse; and (2) relates to the past, present, or 
future physical or mental health or condition of an individual; 
the provision of health care to an individual; or the past, present,  
or future payment for the provision of health care to an 
individual; and (i) that identifies the individual; or (ii) with 
respect to which there is a reasonable basis to believe the 
information can be used to identify the individual. 
c) Protected Health Information ("PHI") means individually 
identifiable health information that is: (i) transmitted by 
electronic media; (ii) maintained in electronic media; or (iii) 
transmitted or maintained in any other form or medium, 
including any individually identifiable health information 
exchanged between COVERED ENTITY and BUSINESS ASSOCIATE 
relating to a patient of COVERED ENTITY or a patient referred to 
COVERED ENTITY for whom COVERED ENTITY is providing or has 
provided services in accordance with 45 C.F.R. § 164.501. PHI 
includes without limitation Electronic Protected Health 
Information ("EPHI"). EPHI means PHI which is transmitted by 
Electronic Media or maintained in Electronic Media. 
d) Breach means the acquisition, access, use, or disclosure of 
unsecured PHI which compromises the security or privacy of the 
PHI. 
e) Secretary shall mean the Secretary of the Department of 
Health and Human Services ("HHS") and any other officer or 
employee of HHS to whom the authority involved has been 
delegated. 
2. 
Limits on Use and Disclosure Established by Terms of 
Agreement. BUSINESS ASSOCIATE agrees that it will not use or 
disclose PHI for any purpose other than as expressly permitted 
or required by this Agreement or the Services Agreement. (45 
C.F.R. § 164.504(e)(2)(i)). 
3. 
Purposes for which BUSINESS ASSOCIATE May Use or 
Disclose Information. BUSINESS ASSOCIATE may use or disclose 
PHI for the following additional purpose(s): 
a) Use of PHI for Management, Administration and Legal 
Responsibilities. BUSINESS ASSOCIATE may use PHI for the 
proper management and administration of the services provided 
by BUSINESS ASSOCIATE to COVERED ENTITY. (45 C.F.R. § 
164.504(e)(4)(1)(A-B)). 
b) Disclosure of PHI for Management, Administration and 
Legal Responsibilities. BUSINESS ASSOCIATE may disclose PHI for 
the proper management and administration of the Services 
Agreement provided that the disclosure is required by law; or 
BUSINESS ASSOCIATE obtains reasonable assurances from the 
person to whom the PHI is disclosed that it will be held 
confidentially and used or further disclosed only as required by 
law or for the purposes for which it was disclosed to the person, 
the person will use appropriate safeguards to prevent use or 
disclosure of the PHI, and the person within five (5) business 
days after becoming aware notifies the disclosing Party of any 
instance of which it is aware in which the confidentiality of the 
PHI has been breached. (45 C.F.R. § 164.504(e)(4)(ii)); or 
BUSINESS ASSOCIATE may use or disclose PHI to provide data 
aggregation services, as that term is defined by 45 C.F.R. § 
164.501, relating to the health care operations of COVERED 
CompuMed Inc., Proprietary and Confidential 	
-1- 	
R2016-9A

comp 	
Business Associate Agreement 
5777 W Century Blvd 
Suite 360 	
Main: 310.258.5000 
Los Angeles, CA 90045 	
Fax: 310.694.3963 
ENTITY. (45 C.F.R. § 164.504(e)(2)(i)(B). 
4. 
Additional Obligations: 
a) Limits on Use and Further Disclosure. BUSINESS ASSOCIATE 
agrees that the PHI shall not be further used or disclosed other 
than as permitted or required by the Agreement or by law. (45 
C.F.R. § 164.504(e)(2)(ii)(A)). 
b) PHI Safeguards. BUSINESS ASSOCIATE will establish and 
maintain appropriate safeguards to ensure the security of and 
prevent any use or disclosure of the PHI, other than as provided 
for by this Agreement. (45 C.F.R. § 164.306 and 45 C.F.R. § 
164.504(e)(2)(ii)(B)). Specifically, BUSINESS ASSOCIATE shall 
comply with all standards and implementation specifications set 
forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316. 
c) EPHI Safeguards. BUSINESS ASSOCIATE shall use 
administrative, physical and technical safeguards to reasonably 
and appropriately protect the security, confidentiality, integrity 
and availability of EPHI. (45 C.F.R. § 164.314(a)(2)(1)(A)). 
d) Security Incident. BUSINESS ASSOCIATE shall report to 
COVERED ENTITY within five (5) business days after BUSINESS 
ASSOCIATE discovers any use or disclosure of PHI not provided 
for or allowed by the Services Agreement or by this Agreement. 
(45 C.F.R. § 164.504(e)(2)(ii)(C) and 45 C.F.R. § 164.308(a)(6)). 
e) Breach Notification. BUSINESS ASSOCIATE shall within five 
(5) business days after becoming aware of a breach of unsecured 
PHI notify COVERED ENTITY of such breach, including the 
identification of each individual whose unsecured PHI has been, 
or is reasonably believed by BUSINESS ASSOCIATE to have been, 
accessed, acquired, or disclosed during such breach. BUSINESS 
ASSOCIATE shall cooperate and assist COVERED ENTITY at no 
cost to COVERED ENTITY in making the notification to third 
Parties required by law in the event of a breach due to BUSINESS 
ASSOCIATE. 
f) Subcontractors and Agents. BUSINESS ASSOCIATE agrees 
that anytime PHI is provided or made available to any 
subcontractors or agents, BUSINESS ASSOCIATE shall enter into 
an agreement with the subcontractor or agent that contains the 
same terms, conditions and restrictions on the use and 
disclosure of PHI as contained in this Agreement. (45 C.F.R. § 
164.504(e)(2)(ii)(D)) 
g) Right of Access to Information. BUSINESS ASSOCIATE 
agrees to make available and provide a right of access to PHI by 
respective Individual. This right of access shall conform with and 
meet all of the requirements of 45 C.F.R. § 164.524. To the 
extent that COVERED ENTITY is obligated by contract or by law 
to provide Individuals access to PHI, BUSINESS ASSOCIATE will 
provide such access on behalf of COVERED ENTITY. (45 C.F.R. 5 
164.524 and 45 C.F.R. § 164.504(e)(2)(ii)(E)). 
h) Amendment and Incorporation of Amendments. BUSINESS 
ASSOCIATE agrees to make PHI available for amendment and to 
incorporate any amendments to PHI in accordance with 45 C.F.R. 
§ 164.526. Any changes to this Agreement shall be in writing and 
signed by both Parties. 
i) Provide Accounting. BUSINESS ASSOCIATE will document 
such disclosures of PHI and information related to such  
disclosures as would be required for COVERED ENTITY to 
respond to a request by an Individual for an accounting of 
disclosures of PHI in accordance with 45 C.F.R. § 164.528. (45 
C.F.R. § 164.504(e)(2)(ii)(G)). 
j) Provide Accounting from Electronic Health Record. In the 
event that COVERED ENTITY uses or maintains an electronic 
health record with respect to PHI, BUSINESS ASSOCIATE shall 
provide an accounting of disclosures of such PHI to an individual 
during the three years prior to the date of the request upon sixty 
(60) days after BUSINESS ASSOCIATE's receipt of such a request. 
k) Remuneration for PHI. Except for the purposes set forth in 
the Services Agreement and as otherwise provided by law, 
BUSINESS ASSOCIATE shall not directly or indirectly receive 
remuneration in exchange for any PHI of an individual unless 
COVERED ENTITY obtains a valid HIPAA authorization. 
I) Access to Books and Records. BUSINESS ASSOCIATE agrees 
to make internal practices, books, and records relating to the use 
and disclosure of PHI received from, or created or received on 
behalf of COVERED ENTITY, available to COVERED ENTITY and to 
the Secretary for purposes of determining compliance with the 
Privacy and Security Rules. (45 C.F.R. § 164.504(e)(2)(ii)(I)) 
m) Return or Destruction of Information. Upon request or at 
termination of this Agreement, BUSINESS ASSOCIATE agrees to 
return or destroy all PHI received from COVERED ENTITY, or 
created or received by BUSINESS ASSOCIATE on COVERED 
ENTITY's behalf. If return or destruction of the PHI is not 
feasible, BUSINESS ASSOCIATE agrees to extend the protections 
of this Agreement for as long as necessary to protect the PHI and 
to limit any further use or disclosure. If BUSINESS ASSOCIATE 
elects to destroy the PHI, it shall certify to COVERED ENTITY that 
the PHI has been destroyed. (45 C.F.R. § 164.504(e)(2)(ii)(J)) 
n) Mitigation Procedures. BUSINESS ASSOCIATE agrees to 
have procedures in place for mitigating, to the maximum extent 
practicable, any deleterious effect from the use or disclosure of 
PHI in a manner contrary to this Agreement or the Privacy and 
Security Rules. (45 C.F.R. § 164.530(0) 
o) Sanction Process. BUSINESS ASSOCIATE will develop and 
implement a system of sanctions for any employee, 
subcontractor or agent who violates the terms of this Agreement 
or the Privacy and Security Rules. (45 C.F.R. § 164.308(a)(1)(ii)(C) 
and 45 C.F.R. § 1:64.530(e)(1)). 
p) Property Rights. The PHI shall be and remain the property 
of COVERED ENTITY. BUSINESS ASSOCIATE agrees that it acquires 
no title or rights to the PHI, including any de-identified 
information, as a result of this Agreement. 
q) Prevention of Identity Theft. BUSINESS ASSOCIATE shall 
provide services in accordance with COVERED ENTITY's policies 
and procedures that prevent and protect data from identity theft 
and shall notify COVERED ENTITY of any actual or suspected 
identity theft. 
5. Term and Termination. The Term of this Agreement shall 
commence on the execution date of the Agreement and shall 
terminate when all of the PHI provided by BUSINESS ASSOCIATE 
CompuMed Inc., Proprietary and Confidential 	
-2- 	
R2016-9A

CULIEE) 	
Business Associate Agreement 
5777 W 
	Blvd 
Suite 360 	
Main: 310.258.5000 
Los Angeles, CA 90045 	
Fax: 310.694.3963 
to COVERED ENTITY, or created or received by BUSINESS 
ASSOCIATE on behalf of COVERED ENTITY, is destroyed or 
returned to COVERED ENTITY, or, if it is infeasible to return or 
destroy, protections are extended to such information. 
BUSINESS ASSOCIATE agrees that COVERED ENTITY has the right 
to immediately terminate this Agreement and seek relief if 
COVERED ENTITY reasonably determines that BUSINESS 
ASSOCIATE has violated and failed to cure a material term of this 
Agreement within a reasonable time specified by the COVERED 
ENTITY. (45 C.F.R. § 164.504(e)(2)(ii)(1)) 
6. Termination for Cause. Upon COVERED ENTITY's knowledge 
of a material breach by BUSINESS ASSOCIATE of the terms of this 
Agreement, the COVERED ENTITY shall either: 
a) Provide an opportunity for BUSINESS ASSOCIATE to cure 
the breach or to end the violation within a reasonable time 
specified by the COVERED ENTITY; or 
b) Immediately terminate the Agreement if BUSINESS 
ASSOCIATE has breached a material term of this Agreement and 
cure is not possible; or 
c) Immediately terminate the Agreement or suspend access 
to PHI, in whole or in part, immediately upon providing Business 
Associate written notice when Covered Entity deems the health 
or welfare of an Individual is endangered, or to prevent the 
unauthorized access to or use of an Individual's confidential 
information or unauthorized use of the service or data system. 
d) immediately terminate upon providing written notice when 
it deems that performance would be in violation of the law or 
order of a court of law. 
e) Parties may terminate this Agreement as provided in A.R.S. 
§ 38-511. 
f) If neither termination nor cure is feasible, COVERED ENTITY 
shall report the violation to the Secretary of the U.S. Department 
of Health and Human Services. 
7. Termination for Unavailability of Funds. Although this 
Agreement is non-financial, if any action is taken by any federal, 
state, local agency or any other agency or instrumentality to 
suspend, decrease or terminate its fiscal obligation affecting the 
capacity of the County to continue this Agreement, any party 
hereto may amend, suspend, decrease or terminate its 
obligations under or in connection with this Agreement. 
8. Compliance. The parties warrant they are in compliance 
with the provisions in A.R.S. § 41-4401 (e- verify). 
9. Warranty. There is no implied warranty of any kind under 
this Agreement, including any representation of accuracy, 
timeliness, completeness, or appropriateness of the information 
provided. Continuous, uninterrupted access to the information 
to be provided hereunder is not guaranteed. In the event of 
delay caused by system issues, the Parties agree to work 
together in a reasonable manner to share information via a 
reasonable alternative means, if possible, until any system issues 
are resolved. 
10. Indemnity. 
To the fullest extent permitted by law, Business Associate shall, 
indemnify, defend save and hold harmless the County, including 
its officers, officials, agents, and employees (hereinafter referred 
to as "County") from and against any and all claims, actions, 
liabilities, damages, losses, or expenses (including court costs, 
attorneys' fees, and costs of claim processing, investigation and 
litigation) (hereinafter referred to as "Claims") caused, or alleged 
to be caused, in whole or in part, by Business Associate's breach 
of this Agreement. It is the specific intention of the Parties that 
the County shall, in all instances, except for Claims arising from 
the negligent or willful acts or omissions of the County, be 
indemnified by Business Associate against any and all claims 
described in this paragraph. It is agreed that SHCA will be 
responsible for primary loss investigation, defense and judgment 
costs where this paragraph is applicable. 
To the fullest extent permitted by law, the County shall, 
indemnify, defend save and hold harmless Business Associate, 
including their officers, officials, agents, and employees 
(hereinafter referred to as "Indemnitee") from and against any 
and all claims, actions, liabilities, damages, losses, or expenses 
(including court costs, attorneys' fees, and costs of claim 
processing, investigation and litigation) (hereinafter referred to 
as "Claims") caused, or alleged to be caused, in whole or in part, 
by the County's breach of this Agreement. It is the specific 
intention of the Parties that Business Associate shall, in all 
instances, except for Claims arising from the negligent or willful 
acts or omissions of the Business Associate, be indemnified by 
the County against any and all claims described in this 
paragraph. It is agreed that the County will be responsible for 
primary loss investigation, defense and judgment costs where 
this paragraph is applicable. 
11. Insurance. Business Associate shall maintain insbrance as 
follows: (i) commercial general liability insurance coverage with 
minimum limits of $1,000,000 per occurrence and $2,000,000 
annual aggregate; and (ii) technology errors & omissions 
insurance coverage with minimum limits of $5,000,000 per 
occurrence. Such insurance shall cover any and all errors, 
omissions, or negligent acts in the delivery of products, services, 
and/or licensed programs under this agreement. (iii) cyber, 
network security and privacy liability insurance coverage with 
minimum limits of $5,000,000. The policy shall include, but not 
be limited to; coverage for all directors, officers, agents and 
employees of the contractor, losses with respect to network 
risks (such as data breaches, unauthorized access or use, and ID 
theft of data), invasion of privacy (regardless of the type of 
CompuMed Inc., Proprietary and Confidential 	
-3- 	
R2016-9A

Cornpul 
mc 
Business Associate Agreement 
5777 W Century Blvd 
Suite 360 	
Main: 310.258.5000 
Los Angeles, CA 90045 	
Fax: 310.694.3963 
media involved in the loss of private information), crisis 
management, identity theft response costs, breach notification 
costs, credit remediation, and credit monitoring, defense, and 
claims expenses, regulatory defense costs plus fines and 
penalties, cyber extortion, electronic data restoration expenses 
(data asset protection), network business interruption, computer 
fraud coverage, funds transfer loss, third-party fidelity, theft, no 
requirement for arrest and conviction, and loss outside the 
premises of the named insured. In the event that the insurance 
required is written on a claims-made basis, contractor warrants 
that any retroactive date under the policy shall precede the 
effective date of this contract and either continuous coverage 
will be maintained, or an extended discovery period will be 
exercised for a period of two years beginning at the time work 
under this contract is completed. Upon written request, a Party 
shall provide to the other Party a certificate of insurance 
evidencing such insurance coverage. Each Party shall provide 
thirty (30) calendar days prior written notice to the other Party 
of any modification or termination of required insurance. 
12. Injunctive Relief. Notwithstanding any rights or remedies 
provided for in this Agreement, COVERED ENTITY retains all 
rights to seek injunctive relief to prevent or stop the 
unauthorized use or disclosure of PHI by BUSINESS ASSOCIATE or 
any agent, contractor or third party that received PHI from 
BUSINESS ASSOCIATE. 
13. 
Miscellaneous. 
a. 
Binding Nature. This Agreement shall be binding on 
the Parties hereto and their successors and assigns. 
b. Article Headings. The article headings used 
are for reference and convenience only, and shall not 
enter into the interpretation of this Agreement. 
14. 
Notices. Any notice required or permitted under this 
Agreement shall be in writing and shall be deemed to have been 
duly given when (a) delivered by hand, courier, or express mail 
service (with written confirmation of receipt), (b) sent by 
facsimile (with provision for assurance of receipt in a manner 
typical with respect to . communications of that type), or (c) 
mailed by registered or certified first class mail, return receipt 
requested, to the address set forth below (or to such other 
Person, address, or facsimile (fax) number as a Party may, from 
time to time, designate by written notice): 
If to Correctional Health Services: 
Correctional Health Services Attn: Department Director 
234 N. Central Avenue, Suite 5000 
Phoenix, AZ 85003 
If to Business Associate: 
Compumed 
Attn: toc c Wit  
Title: CFO 
15. 
Severability. The invalidity, in whole or in part, of any 
provision of this Agreement shall not void or affect the validity of 
any other provision of this Agreement. 
16. 
Rights In Data. The County shall have the use of data 
and reports resulting from this Agreement without additional 
cost or other restriction except as may be established by law or 
applicable regulation. Each party shall supply to the other party, 
upon reasonable request, any available information that is 
directly relevant to this Agreement and to the performance 
thereunder. Requests shall be made in writing and may not be 
requested any more frequently than once a year (a year shall 
begin from the effective date of this Agreement), unless required 
to investigate material breach of this Agreement which shall be 
described in the written request. 
17. 
Relationships. For all purposes relating to this 
Agreement, the Parties shall be independent contractors and not 
agents or employees of the other party. 
18. 
CONTRACTOR LICENSE REQUIREMENT. Business 
Associate shall procure all permits, insurance, licenses and pay 
the charges and fees necessary and incidental to the lawful 
conduct of its business, and as necessary complete any required 
certification requirements, required by any and all governmental 
or non-governmental entities as mandated to maintain 
compliance with and in good standing for all permits and/or 
licenses. Business Associate shall keep fully informed of existing 
and future trade or industry requirements, Federal, State and 
Local laws, ordinances, and regulations which in any manner 
affect the fulfillment of this Agreement and shall comply with 
the same. Business Associate shall immediately notify the 
County of any and all changes concerning permits, insurance or 
licenses affecting performance under this Agreement. 
ACKNOWLEDGEMENT 
By signing below, the Parties acknowledge their roles and 
responsibilities pursuant to this Agreement. The individuals 
signing below have the authcirity to bind their respective -parties 
and execute this Agreement by affixing their signatures to the 
Agreement. 
*** REMAINDER OF PAGE INTENTIONALLY LEFT BLANK*** 
CompuMed Inc., Proprietary and Confidential 	
-4- 	
R2016-9A

5777W Century Blvd 
Suite 360 	
Main: 310.258.5000 
Los Angeles, CA 90045 	
Fax: 310.694.3963 
Compu, 
Business Associate Agreement 
Printed Name U--=0 
 
/z6 (-2-07-0  
MARICOPA COUNTY 
BOARD OF SUPERVISORS 
By: 
Name: 	
 
Title: Chairman, Board of Supervisors 
Date: 
ATTEST: 
By: 
Name: 
Clerk of the Board 
Date: 
Title: Deputy County Attorney 
Date: 
Title 
Date 
CompuMed Inc., Proprietary and Confidential 	
-5- 
R2016-9A