COMPUMED - BUSINESS ASSOCIATE AGREEMENT - SIGNED.PDF
Extracted text (via pymupdf)
23742 characters
5777 W Century Blvd
Suite 360
Main: 310.258.5000
Los Angeles, CA 90045
Fax: 310.694.3963
TM
Business Associate Agreement
This BUSINESS ASSOCIATE AGREEMENT ("Agreement") is entered
into by and between Maricopa County Correctional Health
Service (Maricopa Co.) (the "COVERED ENTITY") and CompuMed,
Inc. (the "BUSINESS ASSOCIATE") as of the date fully executed
below.
WHEREAS the U.S. Department of Health and Human Services
issued regulations on "Standards for Privacy of Individually
Identifiable Health Information" comprising 45 C.F.R. Parts 160
and 164, Subparts A and E (the "Privacy Standards"), "Security
Standards for the Protection of Electronic Protected Health
Information" comprising 45 C.F.R. Parts 160 and 164, Subpart C
(the "Security Standards"), and "Standards for Notification in the
Case of Breach of Unsecured Protected Health Information"
comprising 45 C.F.R. Parts 160 and 164, Subpart D (the "Breach
Notification Standards"), promulgated pursuant to the Health
Insurance Portability and Accountability Act of 1996 (the Privacy
Standards, the Security Standards, and the Breach Notification
Standards are collectively referred to herein as the "HIPAA
Standards").
WHEREAS, COVERED ENTITY is an organization engaged in
providing health care services;
WHEREAS, COVERED ENTITY will make available and/or transfer
to BUSINESS ASSOCIATE certain Protected Health Information, in
conjunction with services to be provided by BUSINESS
ASSOCIATE to COVERED ENTITY as specified in the underlying
services agreement between the Parties ("Services Agreement"),
that is confidential and must be afforded special treatment and
protection;
WHEREAS, BUSINESS ASSOCIATE will have access to and discover
or create confidential PHI that can be used or disclosed only in
accordance with this Agreement and the HIPAA Standards.
NOW THEREFORE, for and in consideration of the mutual
promises and covenants contained herein and in order to assure
compliance with the HIPAA Standards, the Parties agree as
follows:
1. Definitions. The following terms shall have the meaning
ascribed to them in this Section. Other capitalized terms shall
have the meaning ascribed to them in the context in which they
first appear.
a) Individual shall mean the person who is the subject of the
PHI and shall include a person who qualifies as a personal
representative in accordance with 45 C.F.R. § 164.502(g).
b) Individually identifiable health information is information
that is a subset of health information, including demographic
information collected from an individual, and: (1) is created or
received by a health care provider, health plan, employer, or
health care clearinghouse; and (2) relates to the past, present, or
future physical or mental health or condition of an individual;
the provision of health care to an individual; or the past, present,
or future payment for the provision of health care to an
individual; and (i) that identifies the individual; or (ii) with
respect to which there is a reasonable basis to believe the
information can be used to identify the individual.
c) Protected Health Information ("PHI") means individually
identifiable health information that is: (i) transmitted by
electronic media; (ii) maintained in electronic media; or (iii)
transmitted or maintained in any other form or medium,
including any individually identifiable health information
exchanged between COVERED ENTITY and BUSINESS ASSOCIATE
relating to a patient of COVERED ENTITY or a patient referred to
COVERED ENTITY for whom COVERED ENTITY is providing or has
provided services in accordance with 45 C.F.R. § 164.501. PHI
includes without limitation Electronic Protected Health
Information ("EPHI"). EPHI means PHI which is transmitted by
Electronic Media or maintained in Electronic Media.
d) Breach means the acquisition, access, use, or disclosure of
unsecured PHI which compromises the security or privacy of the
PHI.
e) Secretary shall mean the Secretary of the Department of
Health and Human Services ("HHS") and any other officer or
employee of HHS to whom the authority involved has been
delegated.
2.
Limits on Use and Disclosure Established by Terms of
Agreement. BUSINESS ASSOCIATE agrees that it will not use or
disclose PHI for any purpose other than as expressly permitted
or required by this Agreement or the Services Agreement. (45
C.F.R. § 164.504(e)(2)(i)).
3.
Purposes for which BUSINESS ASSOCIATE May Use or
Disclose Information. BUSINESS ASSOCIATE may use or disclose
PHI for the following additional purpose(s):
a) Use of PHI for Management, Administration and Legal
Responsibilities. BUSINESS ASSOCIATE may use PHI for the
proper management and administration of the services provided
by BUSINESS ASSOCIATE to COVERED ENTITY. (45 C.F.R. §
164.504(e)(4)(1)(A-B)).
b) Disclosure of PHI for Management, Administration and
Legal Responsibilities. BUSINESS ASSOCIATE may disclose PHI for
the proper management and administration of the Services
Agreement provided that the disclosure is required by law; or
BUSINESS ASSOCIATE obtains reasonable assurances from the
person to whom the PHI is disclosed that it will be held
confidentially and used or further disclosed only as required by
law or for the purposes for which it was disclosed to the person,
the person will use appropriate safeguards to prevent use or
disclosure of the PHI, and the person within five (5) business
days after becoming aware notifies the disclosing Party of any
instance of which it is aware in which the confidentiality of the
PHI has been breached. (45 C.F.R. § 164.504(e)(4)(ii)); or
BUSINESS ASSOCIATE may use or disclose PHI to provide data
aggregation services, as that term is defined by 45 C.F.R. §
164.501, relating to the health care operations of COVERED
CompuMed Inc., Proprietary and Confidential
-1-
R2016-9A
comp
Business Associate Agreement
5777 W Century Blvd
Suite 360
Main: 310.258.5000
Los Angeles, CA 90045
Fax: 310.694.3963
ENTITY. (45 C.F.R. § 164.504(e)(2)(i)(B).
4.
Additional Obligations:
a) Limits on Use and Further Disclosure. BUSINESS ASSOCIATE
agrees that the PHI shall not be further used or disclosed other
than as permitted or required by the Agreement or by law. (45
C.F.R. § 164.504(e)(2)(ii)(A)).
b) PHI Safeguards. BUSINESS ASSOCIATE will establish and
maintain appropriate safeguards to ensure the security of and
prevent any use or disclosure of the PHI, other than as provided
for by this Agreement. (45 C.F.R. § 164.306 and 45 C.F.R. §
164.504(e)(2)(ii)(B)). Specifically, BUSINESS ASSOCIATE shall
comply with all standards and implementation specifications set
forth in 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316.
c) EPHI Safeguards. BUSINESS ASSOCIATE shall use
administrative, physical and technical safeguards to reasonably
and appropriately protect the security, confidentiality, integrity
and availability of EPHI. (45 C.F.R. § 164.314(a)(2)(1)(A)).
d) Security Incident. BUSINESS ASSOCIATE shall report to
COVERED ENTITY within five (5) business days after BUSINESS
ASSOCIATE discovers any use or disclosure of PHI not provided
for or allowed by the Services Agreement or by this Agreement.
(45 C.F.R. § 164.504(e)(2)(ii)(C) and 45 C.F.R. § 164.308(a)(6)).
e) Breach Notification. BUSINESS ASSOCIATE shall within five
(5) business days after becoming aware of a breach of unsecured
PHI notify COVERED ENTITY of such breach, including the
identification of each individual whose unsecured PHI has been,
or is reasonably believed by BUSINESS ASSOCIATE to have been,
accessed, acquired, or disclosed during such breach. BUSINESS
ASSOCIATE shall cooperate and assist COVERED ENTITY at no
cost to COVERED ENTITY in making the notification to third
Parties required by law in the event of a breach due to BUSINESS
ASSOCIATE.
f) Subcontractors and Agents. BUSINESS ASSOCIATE agrees
that anytime PHI is provided or made available to any
subcontractors or agents, BUSINESS ASSOCIATE shall enter into
an agreement with the subcontractor or agent that contains the
same terms, conditions and restrictions on the use and
disclosure of PHI as contained in this Agreement. (45 C.F.R. §
164.504(e)(2)(ii)(D))
g) Right of Access to Information. BUSINESS ASSOCIATE
agrees to make available and provide a right of access to PHI by
respective Individual. This right of access shall conform with and
meet all of the requirements of 45 C.F.R. § 164.524. To the
extent that COVERED ENTITY is obligated by contract or by law
to provide Individuals access to PHI, BUSINESS ASSOCIATE will
provide such access on behalf of COVERED ENTITY. (45 C.F.R. 5
164.524 and 45 C.F.R. § 164.504(e)(2)(ii)(E)).
h) Amendment and Incorporation of Amendments. BUSINESS
ASSOCIATE agrees to make PHI available for amendment and to
incorporate any amendments to PHI in accordance with 45 C.F.R.
§ 164.526. Any changes to this Agreement shall be in writing and
signed by both Parties.
i) Provide Accounting. BUSINESS ASSOCIATE will document
such disclosures of PHI and information related to such
disclosures as would be required for COVERED ENTITY to
respond to a request by an Individual for an accounting of
disclosures of PHI in accordance with 45 C.F.R. § 164.528. (45
C.F.R. § 164.504(e)(2)(ii)(G)).
j) Provide Accounting from Electronic Health Record. In the
event that COVERED ENTITY uses or maintains an electronic
health record with respect to PHI, BUSINESS ASSOCIATE shall
provide an accounting of disclosures of such PHI to an individual
during the three years prior to the date of the request upon sixty
(60) days after BUSINESS ASSOCIATE's receipt of such a request.
k) Remuneration for PHI. Except for the purposes set forth in
the Services Agreement and as otherwise provided by law,
BUSINESS ASSOCIATE shall not directly or indirectly receive
remuneration in exchange for any PHI of an individual unless
COVERED ENTITY obtains a valid HIPAA authorization.
I) Access to Books and Records. BUSINESS ASSOCIATE agrees
to make internal practices, books, and records relating to the use
and disclosure of PHI received from, or created or received on
behalf of COVERED ENTITY, available to COVERED ENTITY and to
the Secretary for purposes of determining compliance with the
Privacy and Security Rules. (45 C.F.R. § 164.504(e)(2)(ii)(I))
m) Return or Destruction of Information. Upon request or at
termination of this Agreement, BUSINESS ASSOCIATE agrees to
return or destroy all PHI received from COVERED ENTITY, or
created or received by BUSINESS ASSOCIATE on COVERED
ENTITY's behalf. If return or destruction of the PHI is not
feasible, BUSINESS ASSOCIATE agrees to extend the protections
of this Agreement for as long as necessary to protect the PHI and
to limit any further use or disclosure. If BUSINESS ASSOCIATE
elects to destroy the PHI, it shall certify to COVERED ENTITY that
the PHI has been destroyed. (45 C.F.R. § 164.504(e)(2)(ii)(J))
n) Mitigation Procedures. BUSINESS ASSOCIATE agrees to
have procedures in place for mitigating, to the maximum extent
practicable, any deleterious effect from the use or disclosure of
PHI in a manner contrary to this Agreement or the Privacy and
Security Rules. (45 C.F.R. § 164.530(0)
o) Sanction Process. BUSINESS ASSOCIATE will develop and
implement a system of sanctions for any employee,
subcontractor or agent who violates the terms of this Agreement
or the Privacy and Security Rules. (45 C.F.R. § 164.308(a)(1)(ii)(C)
and 45 C.F.R. § 1:64.530(e)(1)).
p) Property Rights. The PHI shall be and remain the property
of COVERED ENTITY. BUSINESS ASSOCIATE agrees that it acquires
no title or rights to the PHI, including any de-identified
information, as a result of this Agreement.
q) Prevention of Identity Theft. BUSINESS ASSOCIATE shall
provide services in accordance with COVERED ENTITY's policies
and procedures that prevent and protect data from identity theft
and shall notify COVERED ENTITY of any actual or suspected
identity theft.
5. Term and Termination. The Term of this Agreement shall
commence on the execution date of the Agreement and shall
terminate when all of the PHI provided by BUSINESS ASSOCIATE
CompuMed Inc., Proprietary and Confidential
-2-
R2016-9A
CULIEE)
Business Associate Agreement
5777 W
Blvd
Suite 360
Main: 310.258.5000
Los Angeles, CA 90045
Fax: 310.694.3963
to COVERED ENTITY, or created or received by BUSINESS
ASSOCIATE on behalf of COVERED ENTITY, is destroyed or
returned to COVERED ENTITY, or, if it is infeasible to return or
destroy, protections are extended to such information.
BUSINESS ASSOCIATE agrees that COVERED ENTITY has the right
to immediately terminate this Agreement and seek relief if
COVERED ENTITY reasonably determines that BUSINESS
ASSOCIATE has violated and failed to cure a material term of this
Agreement within a reasonable time specified by the COVERED
ENTITY. (45 C.F.R. § 164.504(e)(2)(ii)(1))
6. Termination for Cause. Upon COVERED ENTITY's knowledge
of a material breach by BUSINESS ASSOCIATE of the terms of this
Agreement, the COVERED ENTITY shall either:
a) Provide an opportunity for BUSINESS ASSOCIATE to cure
the breach or to end the violation within a reasonable time
specified by the COVERED ENTITY; or
b) Immediately terminate the Agreement if BUSINESS
ASSOCIATE has breached a material term of this Agreement and
cure is not possible; or
c) Immediately terminate the Agreement or suspend access
to PHI, in whole or in part, immediately upon providing Business
Associate written notice when Covered Entity deems the health
or welfare of an Individual is endangered, or to prevent the
unauthorized access to or use of an Individual's confidential
information or unauthorized use of the service or data system.
d) immediately terminate upon providing written notice when
it deems that performance would be in violation of the law or
order of a court of law.
e) Parties may terminate this Agreement as provided in A.R.S.
§ 38-511.
f) If neither termination nor cure is feasible, COVERED ENTITY
shall report the violation to the Secretary of the U.S. Department
of Health and Human Services.
7. Termination for Unavailability of Funds. Although this
Agreement is non-financial, if any action is taken by any federal,
state, local agency or any other agency or instrumentality to
suspend, decrease or terminate its fiscal obligation affecting the
capacity of the County to continue this Agreement, any party
hereto may amend, suspend, decrease or terminate its
obligations under or in connection with this Agreement.
8. Compliance. The parties warrant they are in compliance
with the provisions in A.R.S. § 41-4401 (e- verify).
9. Warranty. There is no implied warranty of any kind under
this Agreement, including any representation of accuracy,
timeliness, completeness, or appropriateness of the information
provided. Continuous, uninterrupted access to the information
to be provided hereunder is not guaranteed. In the event of
delay caused by system issues, the Parties agree to work
together in a reasonable manner to share information via a
reasonable alternative means, if possible, until any system issues
are resolved.
10. Indemnity.
To the fullest extent permitted by law, Business Associate shall,
indemnify, defend save and hold harmless the County, including
its officers, officials, agents, and employees (hereinafter referred
to as "County") from and against any and all claims, actions,
liabilities, damages, losses, or expenses (including court costs,
attorneys' fees, and costs of claim processing, investigation and
litigation) (hereinafter referred to as "Claims") caused, or alleged
to be caused, in whole or in part, by Business Associate's breach
of this Agreement. It is the specific intention of the Parties that
the County shall, in all instances, except for Claims arising from
the negligent or willful acts or omissions of the County, be
indemnified by Business Associate against any and all claims
described in this paragraph. It is agreed that SHCA will be
responsible for primary loss investigation, defense and judgment
costs where this paragraph is applicable.
To the fullest extent permitted by law, the County shall,
indemnify, defend save and hold harmless Business Associate,
including their officers, officials, agents, and employees
(hereinafter referred to as "Indemnitee") from and against any
and all claims, actions, liabilities, damages, losses, or expenses
(including court costs, attorneys' fees, and costs of claim
processing, investigation and litigation) (hereinafter referred to
as "Claims") caused, or alleged to be caused, in whole or in part,
by the County's breach of this Agreement. It is the specific
intention of the Parties that Business Associate shall, in all
instances, except for Claims arising from the negligent or willful
acts or omissions of the Business Associate, be indemnified by
the County against any and all claims described in this
paragraph. It is agreed that the County will be responsible for
primary loss investigation, defense and judgment costs where
this paragraph is applicable.
11. Insurance. Business Associate shall maintain insbrance as
follows: (i) commercial general liability insurance coverage with
minimum limits of $1,000,000 per occurrence and $2,000,000
annual aggregate; and (ii) technology errors & omissions
insurance coverage with minimum limits of $5,000,000 per
occurrence. Such insurance shall cover any and all errors,
omissions, or negligent acts in the delivery of products, services,
and/or licensed programs under this agreement. (iii) cyber,
network security and privacy liability insurance coverage with
minimum limits of $5,000,000. The policy shall include, but not
be limited to; coverage for all directors, officers, agents and
employees of the contractor, losses with respect to network
risks (such as data breaches, unauthorized access or use, and ID
theft of data), invasion of privacy (regardless of the type of
CompuMed Inc., Proprietary and Confidential
-3-
R2016-9A
Cornpul
mc
Business Associate Agreement
5777 W Century Blvd
Suite 360
Main: 310.258.5000
Los Angeles, CA 90045
Fax: 310.694.3963
media involved in the loss of private information), crisis
management, identity theft response costs, breach notification
costs, credit remediation, and credit monitoring, defense, and
claims expenses, regulatory defense costs plus fines and
penalties, cyber extortion, electronic data restoration expenses
(data asset protection), network business interruption, computer
fraud coverage, funds transfer loss, third-party fidelity, theft, no
requirement for arrest and conviction, and loss outside the
premises of the named insured. In the event that the insurance
required is written on a claims-made basis, contractor warrants
that any retroactive date under the policy shall precede the
effective date of this contract and either continuous coverage
will be maintained, or an extended discovery period will be
exercised for a period of two years beginning at the time work
under this contract is completed. Upon written request, a Party
shall provide to the other Party a certificate of insurance
evidencing such insurance coverage. Each Party shall provide
thirty (30) calendar days prior written notice to the other Party
of any modification or termination of required insurance.
12. Injunctive Relief. Notwithstanding any rights or remedies
provided for in this Agreement, COVERED ENTITY retains all
rights to seek injunctive relief to prevent or stop the
unauthorized use or disclosure of PHI by BUSINESS ASSOCIATE or
any agent, contractor or third party that received PHI from
BUSINESS ASSOCIATE.
13.
Miscellaneous.
a.
Binding Nature. This Agreement shall be binding on
the Parties hereto and their successors and assigns.
b. Article Headings. The article headings used
are for reference and convenience only, and shall not
enter into the interpretation of this Agreement.
14.
Notices. Any notice required or permitted under this
Agreement shall be in writing and shall be deemed to have been
duly given when (a) delivered by hand, courier, or express mail
service (with written confirmation of receipt), (b) sent by
facsimile (with provision for assurance of receipt in a manner
typical with respect to . communications of that type), or (c)
mailed by registered or certified first class mail, return receipt
requested, to the address set forth below (or to such other
Person, address, or facsimile (fax) number as a Party may, from
time to time, designate by written notice):
If to Correctional Health Services:
Correctional Health Services Attn: Department Director
234 N. Central Avenue, Suite 5000
Phoenix, AZ 85003
If to Business Associate:
Compumed
Attn: toc c Wit
Title: CFO
15.
Severability. The invalidity, in whole or in part, of any
provision of this Agreement shall not void or affect the validity of
any other provision of this Agreement.
16.
Rights In Data. The County shall have the use of data
and reports resulting from this Agreement without additional
cost or other restriction except as may be established by law or
applicable regulation. Each party shall supply to the other party,
upon reasonable request, any available information that is
directly relevant to this Agreement and to the performance
thereunder. Requests shall be made in writing and may not be
requested any more frequently than once a year (a year shall
begin from the effective date of this Agreement), unless required
to investigate material breach of this Agreement which shall be
described in the written request.
17.
Relationships. For all purposes relating to this
Agreement, the Parties shall be independent contractors and not
agents or employees of the other party.
18.
CONTRACTOR LICENSE REQUIREMENT. Business
Associate shall procure all permits, insurance, licenses and pay
the charges and fees necessary and incidental to the lawful
conduct of its business, and as necessary complete any required
certification requirements, required by any and all governmental
or non-governmental entities as mandated to maintain
compliance with and in good standing for all permits and/or
licenses. Business Associate shall keep fully informed of existing
and future trade or industry requirements, Federal, State and
Local laws, ordinances, and regulations which in any manner
affect the fulfillment of this Agreement and shall comply with
the same. Business Associate shall immediately notify the
County of any and all changes concerning permits, insurance or
licenses affecting performance under this Agreement.
ACKNOWLEDGEMENT
By signing below, the Parties acknowledge their roles and
responsibilities pursuant to this Agreement. The individuals
signing below have the authcirity to bind their respective -parties
and execute this Agreement by affixing their signatures to the
Agreement.
*** REMAINDER OF PAGE INTENTIONALLY LEFT BLANK***
CompuMed Inc., Proprietary and Confidential
-4-
R2016-9A
5777W Century Blvd
Suite 360
Main: 310.258.5000
Los Angeles, CA 90045
Fax: 310.694.3963
Compu,
Business Associate Agreement
Printed Name U--=0
/z6 (-2-07-0
MARICOPA COUNTY
BOARD OF SUPERVISORS
By:
Name:
Title: Chairman, Board of Supervisors
Date:
ATTEST:
By:
Name:
Clerk of the Board
Date:
Title: Deputy County Attorney
Date:
Title
Date
CompuMed Inc., Proprietary and Confidential
-5-
R2016-9A