MCDPH NOAH BAA 01212020.PDF

Maricopa County — Formal (2020-02-12)

View PDF Item 32 Meeting page

Extracted text (via pymupdf) 27094 characters
NOAH Business Associate Agreement v 7 24 2017 
 
NEIGHBORHOOD OUTREACH ACCESS TO HEALTH 
BUSINESS ASSOCIATE AGREEMENT 
This Business Associate Agreement (“BAA”) sets out the responsibilities and obligations of 
Maricopa County by and through its Department of Public Health (“Associate”) as a Business Associate 
(as defined at 45 C.F.R.§ 160.103) of Neighborhood Outreach Access to Health (“NOAH”) pursuant to the 
agreement between Associate and NOAH dated on or about the date of last signature below, as well as all 
future agreements entered into by the Parties (collectively, the “Agreement”). Associate and NOAH 
(individually a “Party” and collectively the “Parties”) agree to the terms and conditions of this BAA in 
order to comply with the use and disclosure of Protected Health Information (“PHI”) (as defined at 45 
C.F.R.§ 160.103) provisions of the Standards for Privacy of Individually Identifiable Health Information, 
at 45 C.F.R. Parts 160 and 164, Subparts A and E, as amended from time to time (the “Privacy Rule”); the 
Security Standards for the Protection of Electronic PHI, 45 C.F.R. Parts 160 and 164, Subparts A and C 
(the “Security Rule”); and the standards for Notification in the Case of Breach of Unsecured PHI, 45 C.F.R. 
Part 164, Subpart D (the “Breach Notification Rule”) (collectively, the “HIPAA Rules”). Unless otherwise 
provided herein, all capitalized terms in this BAA will have the same meaning as provided under the HIPAA 
Rules and HITECH (as defined below). Associate and NOAH will comply with the terms of this BAA for 
the duration of the Agreement and for such other continuing periods as provided in this BAA. This BAA 
shall supersede any and all prior business associate agreements entered into between the Parties. 
 
1. USES AND DISCLOSURES OF PROTECTED HEALTH INFORMATION. 
 
a. Performance of Services. Associate will use and disclose PHI only for those purposes necessary 
to perform its duties, obligations and functions under the Agreement, or as otherwise expressly 
permitted or required by this BAA or as required by law. Associate will not use or further disclose 
any PHI in violation of this BAA or in a manner that, if done by NOAH, would violate the Privacy 
Rule. 
 
b. Limited Data Sets. Associate will limit any uses, disclosures, or requests of PHI to a Limited Data 
Set, as defined in 45 C.F.R. § 164.514(e)(2), or if needed by Associate to the minimum necessary 
PHI required to accomplish the intended purpose of the use, disclosure, or request, as defined by 
the Privacy Rule, pursuant to the Health Information Technology for Economic and Clinical Health 
Act (“HITECH”), and any regulations or guidance promulgated thereunder by the Secretary. For 
any disclosures of PHI pursuant to this BAA, the Party disclosing the PHI shall determine what 
constitutes the minimum necessary to accomplish the intended purpose of the disclosure. 
 
c. Data Aggregation. Associate may use PHI to perform data aggregation services as permitted by 
45 C.F.R. § 164.504(e)(2)(i)(B). 
 
d. Associate’s Management and Administration. Associate may use or disclose PHI for the 
necessary management and administration of Associate, or to carry out the legal responsibilities of 
Associate, provided that if Associate makes a disclosure of PHI: 
 
i. The disclosure is required by law; or 
 
ii. Associate first secures written assurances from the receiving party that the 
receiving party will: (i) hold the PHI confidentially; (ii) use or disclose the PHI 
only as required by law or for the purposes for which it was disclosed to the 
recipient; and (iii) notify the Associate of any breaches in the confidentiality of the 
PHI.

2 
Notwithstanding the foregoing, the Parties explicitly agree that unless the de-identification 
requirements in Section 1(e) of this BAA are met, Associate’s use of PHI in demonstrating its 
services or product to an outside third party is strictly prohibited by this BAA. 
 
e. De-Identification. Associate may de-identify the PHI, provided that such de-identification is in 
accordance with 45 C.F.R. § 164.514(b)(2) and such resulting de-identified information is only 
used or disclosed for Associate’s internal business purposes. Associate may not commercialize or 
sell the de-identified information to a third party. 
 
f. Prohibition on Off-Shoring PHI. Associate agrees that no PHI may be created, received, 
maintained, accessed, or transmitted outside of the United States of America, which shall be 
construed as one of the fifty United States or one of the United States territories (i.e., American 
Samoa, Guam, Northern Mariana Islands, Puerto Rico, and Virgin Islands). 
 
2. 
SAFEGUARDS FOR PROTECTED HEALTH INFORMATION. Associate will implement 
appropriate safeguards to prevent any use or disclosure of PHI not otherwise permitted in this BAA. 
Associate also will implement administrative, physical and technical safeguards to protect the 
confidentiality, integrity, and availability of the electronic PHI, if any, that Associate creates, 
receives, maintains, or transmits on behalf of NOAH. Associate will also comply with the 
applicable requirements of Subpart C of Part 164 of the Security Rule in the same manner such 
provisions apply to NOAH. 
 
3. 
REPORTS OF IMPERMISSIBLE USE OR DISCLOSURE. 
 
a. Notification of an Impermissible Use or Disclosure of PHI. Associate will report to NOAH any 
use or disclosure of PHI not permitted by this BAA, including any Breach of Unsecured PHI, as 
soon as reasonably practicable but in all events, within five (5) business days of its discovery. 
 
b. Notification of Security Incidents. Associate also will report to NOAH any Security Incident of 
which it becomes aware within five (5) business days of its discovery. Notwithstanding the 
foregoing, Associate and NOAH acknowledge the ongoing existence and occurrence of attempted 
but unsuccessful Security Incidents that are trivial in nature, such as pings and port scans, and 
NOAH acknowledges and agrees no additional notification to NOAH of such unsuccessful Security 
Incidents is required. However, to the extent that Associate becomes aware of an unusually high 
number or pattern of unsuccessful Security Incidents due to the repeated acts of a single party, 
Associate shall notify NOAH of these attempts and provide the name, if available, of said party. At 
the request of NOAH, Associate shall use its best efforts to identify the date of the Security Incident, 
Associate’s response to the Security Incident and the identification of the party responsible for 
causing the Security Incident, if known. 
 
c. Content of Notifications. Associate’s notices provided under this Section 3 will include, to the 
extent possible, the identification of each Individual whose PHI has been, or is reasonably believed 
by Associate to have been, accessed, acquired, used, or disclosed during or as a result of the 
impermissible use or disclosure of PHI, or a Security Incident (“Security Event”). Associate shall 
also provide NOAH with at least the following information: a description of the Security Event, 
including the date of the Security Event and date of discovery, if known; a description of the types 
of PHI involved in the Security Event; any steps Individuals should take to protect themselves from 
potential harm as a result of the Security Event; and any other information requested by NOAH 
related to the Security Event. Associate shall supplement such notice with further information as it 
becomes available, even if such information becomes available after Individuals have been notified 
of the Security Event.

3 
d. Cooperation by Associate. Associate agrees to cooperate with NOAH in the investigation of a 
Security Event and understands and agrees that NOAH in its sole discretion will determine whether 
or not a Security Event is a Breach and/or triggers notification obligations. 
 
e. Obligation to Provide Notifications. In the event that Associate or its Workforce members or 
Subcontractors cause a Security Event or a Security Event occurs while PHI is in Associate’s 
possession or is being transmitted by Associate, Associate agrees that NOAH may, in its sole 
discretion, require Associate to provide all notifications that NOAH is required to make pursuant 
to the Breach Notification Rule and any other applicable laws. NOAH shall have the right to review, 
direct, and approve or reject the contents or manner of such notifications. 
 
f. 
Cost Reimbursement and Indemnification. Associate also agrees to indemnify and reimburse 
NOAH for any costs incurred in investigating, mitigating, and otherwise responding to a Security 
Event caused by Associate or its Workforce or Subcontractors, or a Security Event occurs while 
PHI is in Associate’s possession or is being transmitted by Associate, including costs related to 
providing legally required notifications, as well as credit monitoring services for at least one (1) 
year to the extent the Security Event involved social security numbers or financial account 
information. 
 
4. 
SUBCONTRACTORS. In accordance with 45 C.F.R. §§ 164.308(b)(2) and 164.502(e)(1)(ii), if 
Associate provides PHI to a Subcontractor, Associate shall ensure that the Subcontractor agrees in 
writing to substantially the same, but at least as stringent and protective as to NOAH and the PHI, 
as the restrictions and conditions that apply in this BAA to Associate with respect to such 
information, including the safeguards required by Section 2. Associate shall maintain a list of its 
Subcontractors and will provide NOAH with a copy of such list upon reasonable request. 
 
5. 
OBLIGATIONS REGARDING ASSOCIATE PERSONNEL. Associate will appropriately 
inform and train all of its Workforce members (“Associate Personnel”), whose services may be 
used to satisfy Associate’s obligations under the Agreement and this BAA of such Associate 
Personnel’s HIPAA Rule and HITECH obligations so as to enable Associate to comply with the 
terms of this BAA. Associate represents and warrants that the Associate Personnel are under legal 
obligation to Associate, by contract or otherwise, sufficient to enable Associate to fully comply 
with the provisions of this BAA. 
 
6. 
ACCESS TO PHI. 
 
a. NOAH Access. Within five (5) business days of a request by NOAH for access to PHI held by 
Associate in a Designated Record Set, Associate will make the requested PHI available to NOAH, 
in the time, manner, and format requested by NOAH, including electronically if Associate 
maintains the PHI electronically and the requested form and format is readily producible, or, if not, 
in a readable electronic form and format as agreed to by NOAH and the Individual. Any fee that 
Associate may charge for providing the access required hereunder must be reasonable, cost-based, 
and determined in accordance with 45 C.F.R. § 164.524(c)(4). 
 
b. Individual Access. If an Individual requests access to PHI directly from Associate, Associate will 
notify the Individual that it will forward the request to NOAH. Within five (5) business days of the 
request, Associate will forward such request in writing to NOAH. NOAH will be responsible for 
making all determinations regarding the grant or denial of an Individual’s request for PHI and 
Associate will make no such determinations. Only NOAH will release PHI to the Individual 
pursuant to such a request.

4 
7. 
AMENDMENT OF PHI. Within five (5) business days of receiving a request from NOAH to 
amend an Individual’s PHI held by Associate in a Designated Record Set, Associate will provide 
such information to NOAH for amendment. If NOAH’s request includes specific information to be 
included in the PHI as an amendment, Associate will incorporate such amendment within five (5) 
business days of receipt of NOAH’s request. Associate will forward to NOAH within five (5) 
business days any requests by Individuals to Associate to amend PHI within its or NOAH’s 
possession. NOAH will be responsible for making all determinations regarding amendments to PHI, 
and Associate will make no such determinations. 
 
8. 
ACCOUNTING OF DISCLOSURES; REQUESTS FOR DISCLOSURE. 
 
a. Disclosure Records. Associate agrees to document such disclosures of PHI and information related 
to such disclosures as would be required for NOAH to respond to a request by an Individual for an 
accounting of disclosures of PHI in accordance with 45 C.F.R. § 164.528. As of the compliance 
date set forth in the regulations promulgated under HITECH or as otherwise determined by the 
Secretary, in addition to the accounting of disclosure obligations required under 45 C.F.R. § 
164.528, Associate shall account for all disclosures of PHI made through an Electronic Health 
Record in accordance with all applicable regulations. 
 
b. Data Regarding Disclosures. For each disclosure for which Associate must maintain 
documentation under Section 8(a), Associate will record and maintain the following information: 
 
 
The date of disclosure;  
 
The name of the entity or person who received the PHI, and, the address of such 
entity or person, if known;  
 
A description of the PHI disclosed; and  
 
A brief statement of the purpose of the disclosure. 
 
c. Individual Request for Disclosure Records. Within five (5) business days of receipt of a notice 
from NOAH to Associate of an Individual’s request for an accounting of disclosures, Associate 
will provide NOAH with the record of disclosures requested in the notice. 
 
d. Individual Request to Associate. If an Individual requests an accounting of disclosures directly 
from Associate, Associate will notify the Individual that he or she will receive such accounting 
from NOAH. Associate will forward the request to NOAH within five (5) business days of 
Associate’s receipt of the request, and will make its records of disclosures available to NOAH as 
otherwise provided in this Section. NOAH will be responsible for preparation and delivery of the 
records of disclosure to the Individual. Associate will not provide an accounting of its disclosures 
directly to the Individual. 
 
e. Survival of Obligations. Associate’s obligations related to maintaining a disclosure record and 
providing the disclosure record to NOAH as required by this Section 8 shall survive for six (6) 
years from the effective date of the relevant Agreement, Associate shall provide NOAH with its 
disclosure record which reflects disclosures made by Associate over the six (6) years immediately 
preceding the date of termination. 
 
9. 
REQUESTS FOR RESTRICTIONS. If NOAH advises Associate of any changes in, or 
restrictions to the permitted use or disclosure of PHI provided to Associate, Associate will restrict 
use or disclosure of PHI consistent with NOAH’s instructions. If Associate receives a request to 
restrict the disclosure of PHI directly from an Individual, Associate shall promptly notify NOAH 
of such request, and NOAH shall be responsible for making the determination as to whether 
Associate shall comply with the Individual’s request.

5 
 
10. 
DELEGATION OF OBLIGATIONS. To the extent Associate is clearly required by the terms of 
the Agreement to carry out NOAH’s obligations under the Privacy Rule, Associate shall comply 
with the requirements of the Privacy Rule that apply to NOAH in the performance of such delegated 
obligations. 
 
11. 
MITIGATION PROCEDURES. Associate will mitigate, to the maximum extent practicable, any 
harmful effect that is known to Associate arising from its, its Workforce’s, or its Subcontractors’ 
Use or Disclosure of PHI in a manner that violates this BAA. 
 
12. 
INDEMNIFICATION. The following indemnification provisions shall apply to this BAA and 
shall survive the termination of the Agreement or this BAA: 
 
a. To the fullest extent permitted by law, each Party and its successors and assigns (each an 
“Indemnitor”) shall defend, indemnify and hold harmless the other, its agents, representatives, 
officers, directors, employees and authorized volunteers (each an “Indemnitee”) from and against 
all allegations, demands, proceedings, investigations or audits by state or federal government 
agencies, suits, actions, claims, damages, liability, penalties, losses, expenses, including but not 
limited to reasonable attorney fees, defense costs, court costs, cost of appellate proceedings and 
costs of responding to and defending against an investigation or audit, each solely to the extent 
arising from or out of or resulting from any unauthorized use or disclosure of PHI in breach of the 
terms of this BAA (a “Loss”). 
b. If any claim, action or proceeding is brought against an Indemnitee with respect to a Loss, upon 
written demand made by such Indemnitee, Indemnitor, at its sole cost and expense, shall pay, resist 
or defend such claim or action on behalf of Indemnitee by an attorney hired by Indemnitor, or if 
covered by insurance, Indemnitor’s insurer. Indemnitee shall cooperate with all reasonable efforts 
in the handling and defense of such claim. An Indemnitee may engage its own attorney to defend 
or assist in its defense at its sole expense and without right of reimbursement from Indemnitor. Any 
settlement of claims shall fully release and discharge Indemnitee(s) from any further liability for 
those claims that are the subject of the settlement. If any proposed settlement will materially and 
adversely affect Indemnitee by (1) a statement as to, or an admission of, fault, culpability or failure 
to act by or on behalf of Indemnitee; and/or (2) a requirement that Indemnitee contribute its own 
funds to the settlement, then no settlement thereof shall be made without the written consent of 
Indemnitee, which consent shall not be unreasonably withheld. 
 
c. Any limitations of liability contained in the Agreement shall not apply to the indemnification 
requirements of this Section. 
 
d. In addition to the indemnification obligations set forth herein, (i) Associate shall make itself and 
any of its employees, authorized volunteers and agents assisting Associate in the performance of 
its obligations under the Agreement or this BAA available to NOAH to testify as witnesses, or 
otherwise, in the event of litigation or administrative proceedings being commenced against 
NOAH, its directors, officers or employees based upon a claim of violation of HIPAA, the HITECH 
Act, the HIPAA Rules, or other laws related to the security and privacy of the PHI under this BAA, 
and to the extent Associate has not been joined as an adverse party in such litigation or proceeding; 
and (ii) NOAH shall make itself and any of its employees, authorized volunteers or agents available 
to Associate to testify as witnesses, or otherwise, in the event of litigation or administrative 
proceedings being commenced against Associate, its directors, officers or employees based upon a 
claim of violation of HIPAA, the HITECH Act, the HIPAA Rules, or other laws related to the 
security and privacy of the PHI under this BAA, and to the extent NOAH has not been joined as an 
adverse party in such litigation or proceeding.

6 
13. 
RESPONSIBILITIES UPON TERMINATION. 
 
a. Return of PHI; Destruction. Within fifteen (15) days of termination of this BAA, Associate will 
return to NOAH all PHI received from NOAH or created or received by Associate on behalf of 
NOAH which Associate maintains in any form or format (including copies thereof), and Associate 
will not maintain or keep in any form or format any portion of the PHI. Alternatively, Associate 
may, upon NOAH’s written consent, destroy all such PHI and provide written documentation of 
such destruction to Associate. The requirement to return or destroy such PHI will apply to all 
Subcontractors of Associate. Associate will be responsible for recovering any PHI from such 
Subcontractors. If Associate cannot obtain the PHI from any Subcontractor, Associate will so notify 
NOAH and will require that such Subcontractor directly return PHI to NOAH or otherwise destroy 
such PHI, subject to the terms of this Section. 
 
b. Return or Destruction of PHI Infeasible. If Associate believes that returning or destroying PHI 
in its or its Subcontractors’ possession at the termination of this BAA is infeasible, it will provide 
written notice to NOAH within five (5) business days of the effective date of termination of this 
BAA. Such notice will set forth the circumstances that Associate believes makes the return or 
destruction of PHI infeasible and the alternative measures that Associate recommends for assuring 
the continued confidentiality and security of the PHI. NOAH promptly will notify Associate of 
whether it agrees that the return or destruction of PHI is infeasible. If NOAH agrees that return or 
destruction of PHI is infeasible, Associate agrees to extend all protections, limitations and 
restrictions of this BAA to the PHI retained after termination of this BAA and to limit further uses 
or disclosures to those purposes that make the return or destruction of the PHI infeasible. Any such 
extended protections, limitations and restrictions will apply to any Subcontractors of Associate for 
whom return or destruction of PHI is determined by NOAH to be infeasible. If NOAH does not 
agree that the return or destruction of PHI from Associate or its Subcontractors is infeasible, NOAH 
will provide Associate with written notice of its decision, and Associate and its Subcontractors will 
proceed with the return or destruction of the PHI pursuant to the terms of this Section within fifteen 
(15) days of the date of NOAH’s notice. 
 
14. 
TERMINATION. NOAH and Associate may immediately terminate this BAA upon written notice 
to the other Party if NOAH or Associate determines in its discretion that the other Party has 
breached a material term of this BAA. Alternatively, the non-breaching Party may elect to provide 
the breaching Party with thirty (30) days’ advance written notice of the breaching Party’s breach 
of any term or condition of this BAA, and afford the breaching Party the opportunity to cure the 
breach to the satisfaction of the non-breaching Party within twenty (20) days of such notice. If the 
breaching Party fails to timely cure the breach, as determined by the non-Breaching Party, the BAA 
will terminate this BAA as provided in the non-breaching Party’s notice. This BAA will 
automatically terminate upon expiration or termination of the last effective Agreement between the 
Parties, unless the Parties explicitly agree in writing to extend the term of this BAA beyond the 
expiration or termination of the last effective Agreement. 
 
15. 
ASSOCIATE BOOKS AND RECORDS. 
 
a. NOAH Access. Following a Security Event, or for purposes of NOAH responding to a government 
inquiry or judicial or administrative process, Associate will, within five (5) business days of 
NOAH’s written request, make available during normal business hours at Associate’s offices, all 
records, books, agreements, policies and procedures relating to the use or disclosure of PHI for the 
purpose of allowing NOAH to determine Associate’s compliance with the Agreement and this 
BAA.

7 
b. Government Access. Associate will make its internal practices, books and records on the use and 
disclosure of PHI available to the Secretary to the extent required for determining compliance with 
the Privacy Rule. Notwithstanding this provision, no attorney-client, accountant-client or other 
legal privilege will be deemed waived by Associate or NOAH as a result of this Section. Associate 
shall also make its policies and procedures, and documentation required by the Security Rule 
relating to the safeguards in Section 2, available to the Secretary for purposes of determining 
NOAH’s and Associate’s compliance with the Security Rule. 
 
16. 
NOTICES. 
 
a. Any notices required under this BAA will be sent to the Parties at the following address by first 
class mail, fax or hand delivery: 
 
NOAH: 
Maricopa County Department of Public Health 
3634 N. Drinkwater Blvd. 
4041 N. Central Ave, Suite 700 
Scottsdale, AZ 85251 
Phoenix, AZ 85012 
Attn: Wendy Armendariz, CEO 
Attn: Carrie Zavala 
 
 
with a copy to: 
with a copy to: 
HonorHealth 
Grants/Contracts  
8125 N. Hayden Road 
4041 N. Central Ave, Suite 1400 
Scottsdale, AZ 85258 
Phoenix, AZ 85012 
Attn: Compliance Department, 
 
Privacy Officer 
 
 
b. Any notice, report or other communication required under this BAA shall be in writing and shall 
be delivered personally, telegraphed, emailed, sent by facsimile transmission, or sent by U.S. mail. 
 
17. 
MISCELLANEOUS. 
 
a. Relationship of Parties. In the performance of the work, duties and obligations described in this 
BAA or the Agreement, the Parties acknowledge and agree that each Party is at all times acting and 
performing as an independent contractor and at no time shall the relationship between the Parties 
be construed as a partnership, joint venture, employment, principal / agent relationship, or master / 
servant relationship. 
 
b. Regulatory References. A reference in this BAA to a section in the HIPAA Rules means the 
section as in effect or as amended and for which compliance is required. 
 
c. Amendment. No change, amendment, or modification of this BAA shall be valid unless set forth 
in writing and agreed to by both Parties. Notwithstanding the foregoing, the Parties acknowledge 
that state and federal laws relating to electronic data security and privacy are rapidly evolving and 
that amendment of this BAA may be required to ensure compliance with such developments. The 
Parties specifically agree to take such action as may be necessary from time to time for the Parties 
to comply with the requirements of the HIPAA Rules and HITECH. NOAH shall provide written 
notice to Associate to the extent that any final regulation or amendment to the HIPAA Rules 
promulgated by the Secretary requires an amendment to this BAA. The Parties agree to negotiate 
an amendment to this BAA in good faith; however, either Party may terminate this BAA upon 
ninety (90) days written notice to the other Party if the Parties are unable to reach an agreement. 
 
d. Interpretation. Any ambiguity in this BAA shall be resolved to permit NOAH and Associate to 
comply with the HIPAA Rules and HITECH. The provisions of this BAA shall prevail over any

8 
provisions in the Agreement that may conflict or appear inconsistent with any provision in this 
BAA, provided that any provision in the Agreement that is more stringent or protective of PHI than 
the terms of this BAA shall govern. 
 
IN WITNESS WHEREOF, each Party has cause this BAA to be executed by its duly authorized    
representative. 
 
NEIGHBORHOOD OUTREACH ACCESS 
TO HEALTH 
ASSOCIATE: MARICOPA COUNTY BY 
AND THROUGH ITS DEPARTMENT OF 
PUBLIC HEALTH 
 
 
By: 
 
 
 
 
 
 
 
 
By: 
 
 
 
 
 
 
Name: Wendy Armendariz 
Name: Clint Hickman 
Title: Chief Executive Officer 
Title: Chairman, Board of Supervisors 
Date: 
Date: