IGA + BAA - DOMESTIC MEDICAL EXAMINATIONS FOR LEGAL NEWLY ARRIVED REFUGEES.PDF
Extracted text (via pymupdf)
81815 characters
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 1 of 19
Intergovernmental Agreement between the Arizona Department of Economic Security ("ADES") and the
Maricopa County Department of Public Health ("Contractor").
WHEREAS ADES is duly authorized to execute and administer contracts under A.R.S. § 41-1954 and,
The Contractor is duly authorized to execute and administer contracts under A.R.S. § 11-201 and,
ADES and the Contractor are authorized by A.R.S. § 11-952 et seq. to enter into Agreements for joint or cooperative
action to contract for the services specified in this Agreement.
The term of this Agreement shall begin on the date of last signature and shall end on 9/30/2026, unless otherwise
amended.
THEREFORE, ADES and Contractor (the “Parties”) agree to abide by all the terms and conditions set forth in this
Agreement.
BY SIGNING THIS FORM ON BEHALF OF A PARTY, THE SIGNATORY CERTIFIES POSSESSING THE AUTHORITY TO BIND THE
PARTY TO THIS AGREEMENT.
FOR AND ON BEHALF OF THE ARIZONA
DEPARTMENT OF ECONOMIC SECURITY:
FOR AND ON BEHALF OF THE MARICOPA COUNTY
DEPARTMENT OF PUBLIC HEALTH:
Procurement Officer Signature
Signature
Printed Name
Printed Name
Title
Title
Date
Date
ADES Contract Number
DI24-002411
Contractor’s Contract Number (If applicable)
IN ACCORDANCE WITH A.R.S. § 11-952, THIS AGREEMENT IS IN APPROPRIATE FORM AND WITHIN THE POWERS AND
AUTHORITY GRANTED TO EACH RESPECTIVE PUBLIC BODY.
ARIZONA ATTORNEY GENERAL’S OFFICE
By: ___________________________________
By: _________________________________________
Assistant Attorney General
Public Agency Legal Counsel
Date: __________________________________
Date: ________________________________________
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 2 of 19
1.0
ADES VISION AND MISSION STATEMENTS
1.1
ADES Mission: To strengthen individuals, families, and communities for a better quality of life.
1.2
ADES Vision: A thriving Arizona.
2.0
PURPOSE OF AGREEMENT
2.1
The purpose of this Agreement is to provide the coordination of comprehensive medical
screenings to be referred to as the Domestic Medical Examination for Newly Arrived Refugees
(DME) program for refugees and other eligible beneficiaries referred to Maricopa County
Department of Public Health. The purpose of the DME program is to follow up on medical issues
identified in the overseas medical screenings, identify persons with communicable diseases of
potential public health significance, enable refugees to successfully resettle by identifying health
conditions that threaten their well-being, and refer Clients to primary care providers or specialists
for ongoing health care.
3.0
DEFINITIONS
3.1
The Arizona Refugee Resettlement Online Data System (ARRPODS): RRP’s online Client
database and service reporting portal. ARRPODS is the designated electronic case file of
services rendered. Refugee ARRPODS case files contain copies of legal immigration
documentation for a refugee or other eligible beneficiary. Client Service Records are maintained
as confidential records only for use in the performance of duties under this contract, and readily
identifiable as the Client Service Record under this contract, and clearly delineate services as
specified in the source of funding from the Arizona Refugee Resettlement Program (RRP).
3.2
Class A Health Conditions: Illnesses of public health importance that, without a grant of waiver,
prohibit a person from entering the U.S. Examples of Class A health conditions are active
tuberculosis, Hansen's disease, and Severe Acute Respiratory Syndrome (SARS).
3.3
Client: An individual who is considered an eligible beneficiary as described in Section 5.1.1.
3.4
Domestic Medical Examination for Newly Arrived Refugees (DME): A medical screening for all
refugees and other eligible beneficiaries entering the U.S. The DME was established as part of
the Refugee Act of 1980 and is federally funded. The Centers for Disease Control and
Prevention (CDC) has developed clinical guidance for domestic medical screenings, highlighting
the health conditions that should be evaluated and addressed soon after arrival.
3.5
Limited English Proficiency (LEP): Individuals who do not speak English as their primary
language and who have a limited ability to read, speak, write, or understand English.
3.6
Linguistically Appropriate and Culturally Responsive: Respectful of and responsive to explicit
linguistic cultural needs of individuals, that is reflective of a set of congruent behaviors, attitudes,
and policies that come together in a system, agency, or among professionals and enables that
system, agency, or those professionals to work effectively in cross-cultural situations. Culturally
compatible R&P services reflect service delivery in cross-cultural settings that take into account
distinct nuances and differing values, behaviors, expectations, and life skills that are often rooted
in varied cultures.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 3 of 19
3.7
Local Resettlement Agency (LRA): A local affiliate of a national voluntary agency that operates
under a cooperative agreement with the U.S. Department of State to provide Reception and
Placement (R&P) services to refugees.
3.8
Office of Refugee Resettlement (ORR): The U.S. Department of Health and Human Services
(DHHS), Office of Refugee Resettlement, within the Administration for Children and Families
has responsibility for the domestic program of refugee resettlement services. Among these
services are Refugee Cash Assistance (RCA) and Refugee Medical Assistance (RMA) and a
broad range of time-limited employment and social services for refugees in the U.S.
3.9
Arizona Refugee Resettlement Program (RRP): An administration of ADES, Division of Aging
and Adult Services (DAAS), overseen by the federally mandated position of State Refugee
Coordinator. RRP overseas the DME program and any associated RMA funding.
3.10
Private Sponsor Group (PSG): A group of 5 (five) or more individuals who commit to providing
initial resettlement services to support refugee(s), including but not limited to financial, logistical,
and emotional support during the first 90 days of resettlement.
3.11
Refugee Medical Assistance (RMA): Provides short-term medical coverage to refugees who are
ineligible for Medicaid.
4.0
SERVICE DESCRIPTION
4.1
To provide the coordination of services for the DME program for Clients referred to Maricopa
County Department of Public Health. DME coordination includes, but is not limited to, interfacing
collaboratively with the State, case managers, and Clients; facilitating the scheduling of the
DME; ensuring clinic staff and providers are trained on working with refugees, the DME program,
and the CDC DME guidance; reviewing overseas medical records; regularly reporting DME
outcomes to the State; and documenting services in an online portal. Actual DME services
include physical health assessments and preventative screening, counseling, initial laboratory
tests, behavioral health screening, immunizations, and referrals for treatment. All DME services
shall be provided by the same organization that provides for coordination of these services.
4.1.1
Under the DME Program, DME activities reimbursable by health insurance (e.g.,
physical exams, diagnostic procedures, immunizations, and lab testing) will be billed
to clients’ insurance or Refugee Medical Assistance and are therefore not considered
billable under this Agreement.
5.0
PROGRAM ELIGIBILITY
5.1
Eligibility for the DME Program includes individuals who have been authorized by the RRP to
receive services. Proof of authorization is provided through validation in the RRP online
database or Contractor verification of immigration documentation.
5.1.1
Eligible Clients include:
5.1.1.1
Refugees admitted under INA § 207.
5.1.1.2
Asylees granted asylum under INS § 208.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 4 of 19
5.1.1.3
Cuban and Haitian Entrants as defined under 45 CFR § 401.2.
5.1.1.4
Certain Amerasians.
5.1.1.5
Adult Foreign Victims of Trafficking certified by the U.S. Department of
Health and Human Services (DHHS) and Minor Victims of Trafficking.
5.1.1.6
Permanent Residents who had held one of the above statuses in the past.
5.1.1.7
Special Immigrant Juvenile Status Cases.
5.1.1.8
Special Immigrant Visa holders.
5.1.1.9
Others as indicated by RRP.
6.0
RESPONSIBILITIES
6.1
The Contractor shall:
6.1.1
Provide all services in a Linguistically Appropriate and Culturally Responsive manner
for the population to be served.
6.1.2
Provide interpretation and translation services that are Linguistically Appropriate and
Culturally Responsive to the eligible population to be served. Services must be provided
in compliance with the National Origin Discrimination, Limited English Proficiency (LEP)
Equal Access provisions of Title VI of the Civil Rights Act of 1964, including but not
limited to the use of interpreters, bilingual forms, and diversity in staffing.
6.1.3
Coordinate the scheduling of the DME. Schedule the DME visits within two (2) business
days from the date of referral for the next available time interval.
6.1.3.1
Coordinate completion of the DME within twenty-one (21) calendar days
of referral, unless another mutually agreed upon timeframe is approved by
RRP in writing.
6.1.3.1.1
When coordinating DMEs, be cognizant of Clients’
schedules and time restrictions.
6.1.3.1.2
When coordinating DMEs for Clients arriving with
Class A Health Conditions, as documented by the
U.S.
Department
of
Health
and
Human
Services/Centers
for
Disease
Control
and
Prevention (CDC), Division of Global Migration
and Quarantine, ensure the completion of the
DME within five (5) business days of referral in
ARRPODS.
6.1.4
Coordinate the DME in conjunction with the Local Resettlement Agencies (LRA) and
Private Sponsor Groups (PSG) that sponsor Clients to ensure that the LRA or PSG can
assist Clients with attending their DME appointments and to minimize the time and
disruption to Clients. Coordinate directly with Clients when they are not affiliated with
an LRA or PSG.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 5 of 19
6.1.4.1
Confer with designated staff at the Client’s LRA or PSG when they must
help coordinate Client health care. This process shall only take place if the
Client has signed a release of information form stating that their LRA or
PSG is eligible to receive their medical information and coordinate follow-
up medical appointments.
6.1.5
Coordinate for a physician, physician assistant, and/or nurse to conduct the
recommended health assessment activities found in ORR’s Domestic Medical
Screening Guidelines Checklist (available at
https://www.google.com/url?q=https://www.acf.hhs.gov/sites/default/files/documents/o
rr/revised_refugee_medical_screening_document_final_7_24_2012.docx&sa=D&sour
ce=docs&ust=1706290330894371&usg=AOvVaw3FOPkP6DmnpIqR6eqfp7JR), as
may be amended in writing by RRP. For best practices and recommendations on how
to provide these services, the CDC has created Guidance for the U.S. Domestic
Medical Examination for Newly Arriving Refugees (available at
https://www.cdc.gov/immigrantrefugeehealth/guidelines/domestic-guidelines.html).
6.1.6
Maintain the ability to directly bill the Arizona Health Care Cost Containment System
(AHCCCS) through the AHCCCS health plans for payment of any services provided
during the DME such as, initial health assessments, immunizations, and referrals for
treatment. The medical assessment procedures are supported by the state Medicaid
according
to
the
current
AHCCCS
fee
for
service
rates
(available
at
https://www.azahcccs.gov/PlansProviders/RatesAndBilling/FFS/).
6.1.7
Bill AHCCCS Health Plans for the cost of all medical assessment procedures for Clients
who are enrolled in AHCCCS on DME dates of service.
6.1.8
Bill RMA for the services provided during the DME for those Clients who were not
enrolled in AHCCCS on the DME dates of service.
6.1.9
Ensure AHCCCS is first payee for all AHCCCS enrolled Clients. Clients shall not be
billed for DME services.
6.1.9.1
Wait thirty (30) calendar days after administering the DME to charge RMA
for DME services if the Client is not found within the AHCCCS system at
the time of the screening, due to the occasional delay in Clients appearing
within the AHCCCS system. If RMA receives a claim for services for a
Client who is found to have had AHCCCS at the time of the screening,
RMA will deny the claim.
6.1.9.2
Ensure that Clients are not billed for any part of the DME at any time.
Should a Client be found not to be enrolled in any AHCCCS Health Plan
thirty (30) calendar days after the DME is completed, RMA may be billed
for DME services. An Explanation of Benefits from AHCCCS billing must
be included with any claims sent to RMA, except where a Client was not
found to be enrolled in AHCCCS on the dates of service at the time of
billing. RMA may not be billed where a Client is enrolled in an AHCCCS
Plan on the DME dates of service.
6.1.9.3
Do not delay the DME screening regardless of the Client’s AHCCCS
coverage. After thirty (30) calendar days, all Clients who did not have
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 6 of 19
AHCCCS at the time of the DME will have their DME services paid for
under RMA per 45 CFR § 400.107.
6.1.9.4
Do not bill the Client for any DME services.
6.1.10 For those Clients deemed eligible for RMA reimbursement, RMA shall reimburse the
Contractor for DME services utilizing the AHCCCS fee for service rates (available at
https://www.azahcccs.gov/PlansProviders/RatesAndBilling/FFS/).
RMA
shall
not
reimburse the Contractor for any services provided outside of the ORR’s Domestic
Medical Screening Guidelines Checklist, including additional services recommended by
CDC-issued guidance, unless indicated by ADES in writing.
6.1.11 Ensure that all DME services are documented accurately in ARRPODS with correct
dates of service. RRP shall only reimburse DME medical assessment bills for Clients
with DME services documented in ARRPODS by the Contractor. Applicable service
options in ARRPODS are “Screening Completed” for the appointment where a provider
performs a physical, medical history, and reviews lab results, and “Lab Completed” for
the appointment where labs are drawn and are to be documented in ARRPODS within
fourteen (14) calendar days from the date of the respective appointment.
6.1.12 Ensure that the DME services provided are reimbursable by the AHCCCS Health Plan
and that all medical providers employed by the Contractor and performing DME medical
services are eligible for reimbursement by the plans for the activities performed during
the DME. RMA shall not reimburse DME providers or the Contractor for any DME
services billed to RMA due to a provider not being properly registered, certified, or
contracted with an AHCCCS Health Plan. ADES is not responsible for the Contractor’s
contract with the AHCCCS Health Plan or negotiations with AHCCCS or the Health
Plans regarding reimbursement and reimbursement rates for DME services.
6.1.13 Not bill RMA for services paid by other funding sources; i.e., the Contractor may not bill
RMA for vaccines paid by the Vaccines for Children's Program, testing paid for by
AHCCCS Health Plans, etc.
6.1.14 Record the Client’s alien number in each Client’s medical record.
6.1.15 Document DME results, immunizations, and referrals for treatment in each Client’s
medical record.
6.1.16 Refer Clients with adverse health conditions to appropriate health care providers for
treatment and document referral in the Client's medical records.
6.1.17 Provide coordination of care for Clients requiring Tuberculosis (TB) testing and refer
those testing positive for treatment. Document coordination and referrals in Client
medical records.
6.1.18 Collect all necessary laboratory samples at their primary location. All required clinical
facilities, including laboratory facilities, should be located in one (1) medical campus.
Alternatively, the Contractor may send laboratory samples out for testing.
6.1.19 Prepare and provide copies of all Client medical records as requested by RRP within
five (5) business days.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 7 of 19
6.1.20 Attend all RRP meetings, as scheduled by RRP, and present on numbers of Clients
screened, Client’s screening timelines, trends, challenges, and DME program
successes.
6.1.21 Develop a procedural manual and document training that details the coordination of the
DME and the billing process. This manual and training process will be routinely reviewed
during programmatic monitoring.
6.1.22 Ensure that access to RRP systems and databases are restricted to health care
professionals who either coordinate or provide assessment procedures required to
complete the DME.
6.1.23 Ensure that coordination of DME services is not interrupted (ie., scheduling DMEs is
delayed or unavailable).
6.1.24 Identify and train staff to assume the responsibilities of the DME, thus ensuring
uninterrupted DME coordination, should primary staff responsible for DME coordination
become unavailable.
6.1.25 Notify RRP within twenty-four (24) hours should there be a coordination or medical
staffing vacancy or change that impedes or could potentially impede the delivery of
services.
6.1.26 Comply with Arizona Administrative Code (A.A.C. R-9-6-202) Communicable Disease
and
Infestation
Reporting
as
may
be
amended.
(Available
at
https://apps.azsos.gov/public_services/title_09/9-06.pdf.)
6.1.27 Gain access to the CDC’s Electronic Disease Notification (EDN) system and review
Clients’ overseas medical examination results before performing the DME. Most Clients
receive a limited overseas health screening before departure for the United States. The
EDN is an online portal and accessible through an internet browser.
6.1.28 Ensure that all staff providing direct services (i.e. front office staff, support staff, and
health care providers) attend a Refugee 101 training (1 hour and 30-minute session)
provided by RRP annually.
6.1.29 Ensure all staff providing direct services have applicable accreditations, licenses or
certifications related to their profession. Ensure licenses are without sanctions,
according to Arizona State laws.
6.1.30 Ensure compliance with the Business Associates Agreement.
7.0
MANNER OF FINANCING
7.1
Reimbursement to the Contractor is in accordance with actual allowable costs incurred, not to
exceed the service reimbursement ceiling as stated in the Itemized Service Budget (Exhibit A,
as may be amended).
7.1.1
If the subrecipient elects to use a federally negotiated indirect cost rate, they must
provide a copy of the rate agreement with the Itemized Service Budget. If the federally
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 8 of 19
approved indirect cost rate changes, or is allowed to expire within the contract period,
the subrecipient must notify ADES of the changes.
7.2
Costs for DME medical screenings and diagnostic services shall be billed at current AHCCCS
rates as specified in Section 6.1.6.
7.3
In addition to the amount specified in the Itemized Service Budget, as part of the reimbursement
for coordination of the DME, RRP shall pay the Contractor an amount of $150.00 per Client with
both a “Screening Completed” and “Lab Completed” service documented in ARRPODS by the
15th calendar day after the end of the month of service. The Contractor shall be reimbursed
$150.00 only once per Client.
8.0
REPORTING REQUIREMENTS
The Contractor shall:
8.1
Submit all notices/correspondence relevant to this contract electronically to the assigned
DAAS Contract Specialist, or as directed by ADES.
8.2
Submit the following items electronically to: DAAS-RRP-Reports@azdes.gov:
8.2.1
Complete the Refugee Health Screening Monthly Report (Exhibit C as may be
amended), which is due the 15th day following the end of each calendar month.
Indicate in the email subject line the Contractor name, service month, and year. (e.g.,
ABC Agency-April 2022).
8.3
Reporting requirements may change during the Contract term. The Contractor will be notified
in writing about any change in reporting forms.
8.3.1
ADES reserves the right to request that the Contractor submit additional or revised
reports related to the service provision and contract performance
8.4
Submit financial billing information every month directly to the Division of Aging and Adult
Reporting System (DAARS), which is due the 25th day following the end of each calendar
month.
8.5
Submit the Contractor's Equipment List with instructions, Form FES-1000AFORFF (available
at https://des.az.gov/sites/default/files/FES-1000aforff.doc) quarterly, for all equipment
purchases costing $5,000 or more purchased by the Contractor and Subcontractor{s), in
whole or in part with ADES funds.
9.0
PAYMENT REQUIREMENTS
9.1
Invoices shall be submitted by the 15th day of the month following the month services were
provided.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 9 of 19
9.2
Directly enter financial billing information monthly into the DAARS in accordance with the system
Guide, as may be amended. DAARS web address: https://azdaars.getcare.com/
10.0
NOTICES
10.1
All notices to the Contractor regarding this Agreement shall be sent to the following address:
Maricopa County Department of Public Health
ATTN: Grants and Contracts
4041 N. Central Ave, Suite 1400
Phoenix, AZ 85012
10.2
All notices, reporting, funding, and correspondence to ADES regarding this agreement shall be
sent to the following address:
Department of Economic Security
Division of Aging and Adult Services
ATTN: Contract Unit – Mail Drop 6271
P.O. Box 6123
Phoenix, AZ 85005
11.0
DISPOSITION OF PROPERTY
11.1
None
12.0
OTHER MATTERS
12.1
None
13.0
ATTACHMENTS
13.1
The following list of attachments constitutes an integral part of subject Agreement:
13.1.1
Attachment 1 - Direct Service Central Registry Clearance Form (Attached
separately)
13.1.2
Attachment 2 – Business Associate Agreement
14.0
EXHIBITS
14.1
The following list of exhibits constitutes an integral part of subject Agreement:
14.1.1
Exhibit A - Itemized Service Budget (ISB)
14.1.2
Exhibit B - Refugee Health Screening Monthly Report
15.0
EXTENSION
15.1
This Agreement may be extended through a mutual written amendment. The term of this
Agreement should not exceed five (5) years.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 10 of 19
16.0
TERMINATION
16.1
This Agreement may be terminated by mutual agreement of the parties at any time during the
term of this Agreement.
16.2
Each Party shall have the right to terminate this Agreement by written request to the other Party.
Written notice of termination shall be received by either party at least thirty (30) days prior to the
effective date of said termination.
17.0
AMENDMENTS
17.1
This Agreement may be amended only by mutual written amendment. No agent, employee, or
other representative of either Party is empowered to alter any of the terms of the Agreement
unless amended in writing and signed by the authorized representative of the respective Parties.
17.2
Either Party shall give written notice to the other Party of any non-material alteration that affects
the provisions of this Agreement. Non-material alterations that do not require a written
amendment are as follows:
17.2.1 Change of telephone number;
17.2.2 Change in authorized signatory; and/or
17.2.3 Change in the name and/or address of the person to whom notices are to be sent.
18.0
APPLICABLE LAW
18.1
This Agreement shall be governed and interpreted by the laws of the State of Arizona. The
materials and services supplied under this Agreement shall comply with all applicable Federal,
State, and local laws, and the Contractor shall maintain all applicable licenses and permit
requirements.
19.0
ARBITRATION
19.1
The Parties to this Agreement agree to resolve all disputes arising out of or relating to this
Agreement through arbitration, after exhausting applicable administrative review, to the extent
required by A.R.S. §§ 12-1518(B) and 12-133, except as may be required by other applicable
statutes.
20.0
AUDIT
20.1
In accordance with A.R.S. § 35-214, the Contractor shall retain and shall contractually require
each subcontractor to retain all data, books, and other records (“records”) relating to this
Agreement for a period of five (5) years after the completion of the Agreement except if subject
to Health Insurance Portability & Accountability Act which is six (6) years from the date of final
payment. All records shall be subject to inspection and audit at reasonable times. Upon request,
ADES shall produce the original of any or all such records.
21.0
CONFIDENTIALITY
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 11 of 19
21.1
The Contractor shall observe and abide by all applicable State and federal statutes, rules and
regulations regarding the use or disclosure of information including, but not limited to,
information concerning applicants for and recipients of contract services. To the extent
permitted by law, the Contractor shall release information to ADES and to the Attorney General's
Office as required by the terms of this Agreement, by law or upon their request.
21.2
The Contractor shall comply with the requirements of Arizona Address Confidentiality Program,
A.R.S. § 41-161 et. seq. ADES will advise the Contractor as to applicable policies and
procedures ADES has adopted for such compliance.
22.0
CONFLICT OF INTEREST
22.1
In accordance with A.R.S. § 38-511, the State may within three years after execution terminate
the Agreement, without penalty or further obligation, if any person significantly involved in
initiating, negotiating, securing, drafting, or creating this Agreement on behalf of either party, at
any time while this Agreement is in effect, becomes an employee or agent of any other party to
this Agreement in any capacity or a consultant to any other party to the Agreement with respect
to the matter of this Agreement.
23.0
E-VERIFY
23.1
In accordance with A.R.S. § 41-4401, the Contractor warrants compliance with all Federal
immigration laws and regulations relating to employees and warrants its compliance with A.R.S.
§ 23-214, Subsection A.
24.0
HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (P. L. 104-191)
24.1
The Contractor warrants that it is familiar with the requirements of HIPAA, as amended and
accompanying regulations and will comply with all applicable HIPAA requirements in the
course of this Agreement. Contractor warrants that it will cooperate with the State in the
course of performance of this Agreement so that both the State and Contractor will be in
compliance with HIPAA, including cooperation and coordination with the offices of the
Department’s Chief Information Security Officer and Chief Privacy Officer, and other
compliance officials required by HIPAA and its regulations.
24.2
The Contractor agrees to sign the Department’s Business Associates Agreement and to
abide by the statements addressing the creation, use and disclosure of confidential
information, including information designated as protected health information and all other
confidential or sensitive information as defined in policy. In addition, if requested,
Contractor agrees to either:
24.2.1
Complete the Department’s HIPAA training that is intended to
make the Contractor proficient in HIPAA for purposes of
performing the services required, or
24.2.2
Provide the Department with materials that will be utilized for
Contractor’s own training. The Department reserves the right to
review the independent training materials and either approve or
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 12 of 19
reject them. If the training materials are rejected, the Contractor
shall complete the Department’s HIPAA training.
25.0
FEDERAL IMMIGRATION AND NATIONALITY ACT
25.1
By entering into this Agreement, the Contractor warrants compliance with the Federal
Immigration and Nationality Act. (FINA) and all other Federal immigration laws and regulations
related to the immigration status of its employees. The Contractor shall obtain statements from
its subcontractors certifying compliance and shall furnish the statements to the Procurement
Officer upon request. These warranties shall remain in effect through the term of this
Agreement. The Contractor and its subcontractors shall also maintain Employment Eligibility
Verification forms (I-9) as required by the U.S. Department of Labor’s Immigration and Control
Act, for all employees performing work under this Agreement. I-9 forms are available for
download at USCIS.GOV.
25.2
The State may request verification of compliance for any Contractor or subcontractor performing
work under this Agreement. Should the State suspect or find that the Contractor or any of its
subcontractors are not in compliance, the State may pursue any and all remedies allowed by
law, including, but not limited to suspension of work, termination of the Agreement for default,
and suspension and/or debarment of the Contractor. All costs necessary to verify compliance
are the responsibility of the Contractor.
26.0
INDEMNIFICATION AND INSURANCE REQUIREMENTS
26.1
INDEMNIFICATION:
26.1.1 Each party (as "Indemnitor") agrees to defend, indemnify, and hold harmless the other
party (as "Indemnitee") from and against any and all claims, losses, liability, costs, or
expenses (including reasonable attorney's fees) (hereinafter collectively referred to as
"Claims") arising out of bodily injury of any person (including death) or property damage,
but only to the extent that such Claims which result in vicarious/derivative liability to the
Indemnitee are caused by the act, omission, negligence, misconduct, or other fault of
the Indemnitor, its officers, officials, agents, employees, or volunteers. The State of
Arizona, Department of Economic Security is self-insured per A.R.S. 41-621.
26.1.2 In addition, should (insert name of other governmental entity) utilize a contractor(s) and
subcontractor(s) the indemnification clause between (insert name of other
governmental entity) and its contractor(s) and subcontractor(s) shall include the
following:
a.
To the fullest extent permitted by law, Contractor shall defend, indemnify, and hold
harmless the (insert name of other government entity) and the State of Arizona, and
any jurisdiction or agency issuing any permits for any work arising out of this agreement,
and its departments, agencies, boards, commissions, universities, , officers, officials,
agents, and employees (hereinafter referred to as “Indemnitee”) from and against any
and all claims, actions, liabilities, damages, losses, or expenses (including court costs,
attorneys’ fees, and costs of claim processing, investigation and litigation) (hereinafter
referred to as “Claims”) for bodily injury or personal injury (including death), or loss or
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 13 of 19
damage to tangible or intangible property caused, or alleged to be caused, in whole or
in part, by the negligent or willful acts or omissions of the contractor or any of the
directors, officers, agents, or employees or subcontractors of such contractor. This
indemnity includes any claim or amount arising out of or recovered under the Workers’
Compensation Law or arising out of the failure of such contractor to conform to any
federal, state, or local law, statute, ordinance, rule, regulation, or court decree. It is the
specific intention of the parties that the Indemnitee shall, in all instances, except for
Claims arising solely from the negligent or willful acts or omissions of the Indemnitee,
be indemnified by such contractor from and against all claims. It is agreed that such a
contractor will be responsible for primary loss investigation, defense, and judgment
costs where this indemnification is applicable. Additionally, on all applicable insurance
policies, the contractor and its subcontractors shall name the State of Arizona, and its
departments, agencies, boards, commissions, universities, officers, officials, agents,
and employees as additional insured and also include a waiver of subrogation in favor
of the State.
26.2
INSURANCE REQUIREMENTS FOR GOVERNMENTAL PARTIES TO AN IGA
26.2.1 None
26.3
INSURANCE REQUIREMENTS FOR ANY CONTRACTORS USED BY A PARTY TO THE
INTERGOVERNMENTAL AGREEMENT
(Note: this applies only to Contractors used by a governmental entity, not to the governmental
entity itself.) The insurance requirements herein are minimum requirements and in no way limit
the indemnity covenants contained in the Intergovernmental Agreement. The State of Arizona
in no way warrants that the minimum limits contained herein are sufficient to protect the
governmental entity or Contractor from liabilities that might arise out of the performance of the
work under this Contract by the Contractor, his agents, representatives, employees or
subcontractors, and Contractor and the governmental entity are free to purchase additional
insurance.
26.4
MINIMUM SCOPE AND LIMITS OF INSURANCE
Contractor shall provide coverage with limits of liability not less than those stated below.
26.4.1 Commercial General Liability – Occurrence Form
Policy shall include bodily injury, property damage, and broad form contractual liability
coverage.
●
General Aggregate
$2,000,000
●
Products – Completed Operations Aggregate
$1,000,000
●
Personal and Advertising Injury
$1,000,000
●
Damage to Rented Premises
$ 50,000
●
Each Occurrence
$1,000,000
a. The policy shall be endorsed, as required by this written Agreement, to include the
State of Arizona, and its departments, agencies, boards, commissions, universities,
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 14 of 19
officers, officials, agents, and employees as additional insureds with respect to
liability arising out of the activities performed by or on behalf of the Contractor.
b. Policy shall contain a waiver of subrogation endorsement, as required by this written
Agreement, in favor of the State of Arizona, and its departments, agencies, boards,
commissions, universities, officers, officials, agents, and employees for losses
arising from work performed by or on behalf of the Contractor.
26.4.2 Business Automobile Liability
Bodily Injury and Property Damage for any owned, hired and/or non-owned automobiles
used in the performance of this Contract.
●
Combined Single Limit (CSL) $1,000,000
a. Policy shall contain a waiver of subrogation endorsement, as required by this written
Agreement, in favor of the State of Arizona, and its departments, agencies, boards,
commissions, universities, officers, officials, agents, and employees for losses
arising from work performed by or on behalf of the Contractor.
b. This requirement shall not apply to each Contractor or subcontractor that is exempt
under A.R.S. § 23-901, and when such Contractor or subcontractor executes the
appropriate waiver form (Sole Proprietor or Independent Contractor)
26.5
ADDITIONAL INSURANCE REQUIREMENTS
The policies shall include, or be endorsed to include, as required by this written Agreement, the
following provisions:
26.5.1 The Contractor's policies, as applicable, shall stipulate that the insurance afforded the
Contractor shall be primary and that any insurance carried by the Department, its
agents, officials, employees or the State of Arizona shall be excess and not contributory
insurance, as provided by A.R.S. § 41-621 (E).
26.5.2 Insurance provided by the Contractor shall not limit the Contractor’s liability assumed
under the indemnification provisions of this Contract.
26.6
NOTICE OF CANCELLATION
Applicable to all insurance policies required within the Insurance Requirements of this Contract,
Contractor’s insurance shall not be permitted to expire, be suspended, be canceled, or be
materially changed for any reason without thirty (30) days prior written notice to the State of
Arizona. Within two (2) business days of receipt, Contractor must provide notice to the State of
Arizona if they receive notice of a policy that has been or will be suspended, canceled, materially
changed for any reason, has expired, or will be expiring. Such notice shall be sent directly to the
Department and shall be mailed or emailed to Arizona Department of Economic Security C/O:
myCOI
1075
Broad
Ripple
Ave,
Suite
313,
Indianapolis,
IN
46220
or
support@myCOItracking.com.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 15 of 19
26.7
ACCEPTABILITY OF INSURERS
Contractor’s insurance shall be placed with companies licensed in the State of Arizona or hold
approved non-admitted status on the Arizona Department of Insurance List of Qualified
Unauthorized Insurers. Insurers shall have an “A.M. Best” rating of not less than A- VII. The
State of Arizona in no way warrants that the above-required minimum insurer rating is sufficient
to protect the Contractor from potential insurer insolvency.
26.8
VERIFICATION OF COVERAGE
Contractor shall furnish the State of Arizona with certificates of insurance (valid ACORD form or
equivalent approved by the State of Arizona) evidencing that Contractor has the insurance as
required by this Contract. An authorized representative of the insurer shall sign the certificates.
26.8.1 All such certificates of insurance and policy endorsements must be received by the
State before work commences. The State’s receipt of any certificates of insurance or
policy endorsements that do not comply with this written Agreement shall not waive or
otherwise affect the requirements of this Agreement.
26.8.2 Each insurance policy required by this Contract must be in effect at, or prior to,
commencement of work under this Contract. Failure to maintain the insurance policies
as required by this Contract, or to provide evidence of renewal, is a material breach of
contract.
26.8.3 All certificates required by this Contract shall be sent as instructed by the requesting
Department. The State of Arizona project/contract number and project description shall
be noted on the certificate of insurance. The State of Arizona reserves the right to
require complete copies of all insurance policies required by this Contract at any time.
26.9
SUBCONTRACTORS
Contractor’s certificate(s) shall include all subcontractors as insureds under its policies or
Contractor shall be responsible for ensuring and/or verifying that all subcontractors have valid
and collectable insurance as evidenced by the certificates of insurance and endorsements for
each subcontractor. All coverages for subcontractors shall be subject to the minimum Insurance
Requirements identified above. The Department reserves the right to require, at any time
throughout the life of the Contract, proof from the Contractor that its subcontractors have the
required coverage.
26.10
APPROVAL AND MODIFICATIONS
The Contracting Agency, in consultation with State Risk, reserves the right to review or make
modifications to the insurance limits, required coverages, or endorsements throughout the life
of this contract, as deemed necessary. Such action will not require a formal Contract
amendment but may be made by administrative action.
26.11
EXCEPTIONS
In the event the Contractor or subcontractor(s) is/are a public entity, then the Insurance
Requirements shall not apply. Such public entity shall provide a certificate of self-insurance. If
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 16 of 19
the Contractor or subcontractor(s) is/are a State of Arizona agency, board, commission, or
university, none of the above shall apply.
27.0
IT 508 COMPLIANCE
Unless specifically authorized in this Agreement, any electronic or information technology offered to the
State of Arizona under this Agreement shall comply with A.R.S. §§ 18-131 and §§ 18-132 and Section
508 of the Rehabilitation Act of 1973, which requires that employees and members of the public shall
have access to and use of information technology that is comparable to the access and use by
employees and members of the public who are not individuals with disabilities.
28.0
NON-AVAILABILITY OF FUNDS
In accordance with A.R.S. § 35-154, every payment obligation of the State under this Agreement is
conditioned upon the availability of funds appropriated or allocated for payment of such obligation. If
funds are not allocated and available for the continuance of this Agreement, this Agreement may be
terminated by the State at the end of the period for which funds are available. No liability shall accrue
to the State in the event this provision is exercised, and the State shall not be obligated or liable for any
future payments or for any damages as a result of termination under this paragraph.
29.0
NON-DISCRIMINATION
The Contractor shall comply with State Executive Orders Nos. 2023-09, 2023-01 and 2009-09 and all
other applicable Federal and State laws, rules, and regulations, including the Americans with Disabilities
Act. Contractor shall include these provisions in contracts with Subcontractors when required by Federal
or State law.
30.0
OFFSHORE PERFORMANCE OF WORK PROHIBITED
Due to security and identity protection concerns, direct services under this Agreement shall be performed
within the borders of the United States. Any services that are described in the specifications or scope of
work that directly serve the State of Arizona or its clients and may involve access to secure or sensitive
data or personal client data or development or modification of software for the State shall be performed
within the borders of the United States. Unless specifically stated otherwise in the specifications, this
definition does not apply to indirect or 'overhead' services, redundant back-up services, or services that
are incidental to the performance of the Agreement. This provision applies to work performed by
subcontractors at all tiers.
31.0
PRIOR SERVICES
31.1
The Parties agree that if services were performed before the start date of this Agreement in
compliance with the terms of the expired Agreement that started 10/1/2017, then they will be
compensated as if performed under this Agreement.
32.0
RIGHT OF OFFSET
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 17 of 19
ADES shall be entitled to offset against any sums due the Contractor, any expenses or costs incurred
by ADES, or damages assessed by ADES concerning the Contractor's non-conforming performance or
failure to perform this Agreement. The right to offset may include but is not limited to, a deduction from
an unpaid balance and a collection against the bid and/or performance bonds. Any offset taken for
damages assessed by the ADES shall represent a fair and reasonable amount for the actual damages
and shall not be a penalty for non-performance.
33.0
SIGNATURES IN COUNTERPART
This Agreement may be executed in any number of counterparts, each of which when executed and
delivered shall constitute a duplicate original, but all counterparts together shall constitute a single
agreement.
34.0
THIRD-PARTY ANTITRUST VIOLATIONS
The Contractor assigns to ADES any claim for overcharges resulting from antitrust violations concerning
materials or services supplied by third parties to the Contractor, toward fulfillment of this Agreement.
35.0
FINGERPRINTING
35.1
Contractor shall comply with, and shall ensure that all of Contractor’s employees, independent
contractors, subcontractors, volunteers and other agents comply with, all applicable (current and
future) legal requirements relating to fingerprinting, fingerprint clearance cards, certifications
regarding pending or past criminal matters, and criminal records checks that relate to contract
performance.
35.2
Applicable legal requirements relating to fingerprinting, certification, and criminal background
checks may include, but are not limited, to the following: A.R.S. §§ 36-594.01, 36-3008, 41-
1964, and 46-141. All applicable legal requirements relating to fingerprinting, fingerprint
clearance cards, certifications regarding pending or past criminal matters, and criminal records
checks are hereby incorporated in their entirety as provisions of this Agreement. The Contractor
is responsible for knowing which legal requirements relating to fingerprinting, fingerprint
clearance cards, certifications regarding pending or past criminal matters, and criminal records
checks relate to contract performance.
35.3
To the extent A.R.S. § 46-141 is applicable to contract performance or the services provided
under this Agreement, the following provisions apply:
35.3.1 Personnel who are employed by the Contractor, whether paid or not, and who are
required or allowed to provide services directly to juveniles or vulnerable adults shall
have a valid fingerprint clearance card or shall apply for a fingerprint clearance card
within seven working days of employment.
35.3.2 Except as provided in A.R.S. § 46-141, this Agreement may be cancelled or terminated
immediately if a person employed by the Contractor and who has contact with juveniles
certifies pursuant to the provisions of A.R.S. § 46-141 (as may be amended) that the
person is awaiting trial or has been convicted of any of the offenses listed therein in this
State, or of acts committed in another state that would be offenses in this State, or if the
person does not possess or is denied issuance of a valid fingerprint clearance card.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 18 of 19
35.4
Federally recognized Indian tribes may submit and ADES will accept certifications that state that
no personnel who are employed or who will be employed during the term of this Agreement
have been convicted of, have admitted committing or are awaiting trial on any offense as
described in A.R.S. § 41-1758.03 (as may be amended).
36.0
BACKGROUND CHECKS FOR EMPLOYMENT THROUGH THE CENTRAL REGISTRY
If providing direct services to children or vulnerable adults, the following shall apply:
36.1
The provisions of A.R.S. § 8-804 (as may be amended) are hereby incorporated in its entirety
as provisions of this Agreement.
36.2
ADES will conduct Central Registry Background Checks and will use the information contained
in the Central Registry as a factor to determine qualifications for positions that provide direct
service to children or vulnerable adults for:
36.2.1 Any person who applies for a contract with this State and that person’s employees;
36.2.2 All employees of a contractor;
36.2.3 A subcontractor of a contractor and the subcontractor’s employees; and
36.2.4 Prospective employees of the contractor or subcontractor at the request of the
prospective employer.
36.3
Volunteers who provide direct services to children or vulnerable adults shall have a Central
Registry Background Check which is to be used as a factor to determine qualifications for
volunteer positions.
36.4
A person who is disqualified because of a Central Registry Background Check may apply to the
Board of Fingerprinting for a Central Registry exception pursuant to A.R.S. § 41-619.57. A
person who is granted a Central Registry exception pursuant to A.R.S. § 41-619.57 is not
entitled to a contract, employment, licensure, certification or other benefit because the person
has been granted a Central Registry exception.
36.5
Before being employed or volunteering in a position that provides direct services to children or
vulnerable adults, persons shall certify on forms that are provided by ADES whether an
allegation of abuse or neglect was made against them and was substantiated. The completed
forms are to be maintained as confidential.
36.6
A person awaiting receipt of the Central Registry Background Check may provide direct services
to ADES clients after completion and submittal of the Direct Service Position certification form if
the certification states:
36.6.1 The person is not currently the subject of an investigation of child abuse or neglect in
Arizona or another state or jurisdiction; and
36.6.2 The person has not been the subject of an investigation of child abuse or neglect in
Arizona, or another state or jurisdiction, which resulted in a substantiated finding.
Intergovernmental Agreement (IGA)
Agreement No.: DI24-002411
Description: Coordination - Health Assessment
12/05/2023 Intergovernmental Agreement Page 19 of 19
36.7
If the Central Registry Background Check specifies any disqualifying act and the person does
not have a Central Registry exception, the person shall be prohibited from providing direct
services to ADES clients.
36.8
The Contractor shall maintain the Central Registry Background Check results and any related
forms or documents in a confidential file for five (5) years after termination of this Agreement.
37.0
DATA SHARING AGREEMENT
37.1
When determined by ADES that sharing of confidential data will occur with the Contractor, the
Contractor shall complete ADES Data Sharing Request Agreement and submit the completed
Agreement to ADES Program Designated Staff prior to any work commencing or data shared.
A separate Data Sharing Request Agreement shall be required between the Contractor and
each ADES Program sharing confidential data.
37.2
The Data Sharing Request Agreement is located at: http://des.az.gov/documents-center. In
the “Search” field type “Data Sharing” and click “Apply”. The search will produce the following
results:
37.2.1 Document Number J-119-Single (For requests involving a single division or program).
IN WITNESS WHEREOF, the parties agree to enter into this Agreement
FOR AND ON BEHALF OF
MARICOPA COUNTY
BY:
CHAIRMAN, BOARD OF SUPERVISORS
DATE
______________________________________________________
ATTEST:
______________________________________________________
CLERK OF THE BOARD
DATE
______________________________________________________
APPROVED AS TO FORM
DATE
PPP-1136A FORENG (2-23)
ARIZONA DEPARTMENT OF ECONOMIC SECURITY
Office of the Director
Page 1 of 7
HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT OF 1996 – HIPAA
AND HEALTH INFORMATION TECHNOLOGY FOR ECONOMIC AND CLINICAL
HEALTH ACT OF 2009 - HITECH
BUSINESS ASSOCIATE AGREEMENT
The Arizona Department of Economic Security (DES) or on behalf of a DES Division or Program (“DES Covered
Component”), and undersigned Business Associate hereby enter into this Business Associate Agreement (“BAA” or
“Agreement”).
This BAA has the same effective date as the Contract, Intergovernmental Agreement, Memorandum of Understanding
or Interagency Service Agreement to which it is appended (“Related Contract” or “Contract”), or the date of the last
signature, whichever is later. If there is no Related Contract, the effective date of this BAA is the date of the last signature
to this Agreement. This Agreement supplements any Contract between a DES Covered Component and the Business
Associate which involves the disclosure of Protected Health Information (“PHI”) as defined in HIPAA. In the event of
conflicting terms or conditions, this Agreement’s terms shall supersede the provisions of the Related Contract to which it is
appended.
The DES Covered Component and the Business Associate agree to comply with applicable Privacy and Security
Standards of HIPAA and HITECH, and with other applicable federal and state laws, in order to protect the privacy of PHI
in any form and to safeguard the confidentiality, integrity, and availability of any Electronic PHI (“ePHI’) related to this
Agreement.
1.0. DEFINITIONS.
Capitalized terms not otherwise defined in this Agreement shall have the same meanings as those
terms in the Privacy Rule and HITECH.
1.1 Breach shall have the meaning given to such term under the HITECH Act (42 U.S.C. § 17921).
1.2 Business Associate shall have the meaning given to such term under the Privacy Rule, the Security Rule, and the
HITECH Act (45 C.F.R. § 160.103 and 42 U.S.C. §17938).
1.3 Covered Component shall have the meaning given to such term under the Privacy Rule and the Security Rule (45
C.F.R §160.103).
1.4 Data Aggregation shall have the meaning given to such term under the Privacy Rule (45 C.F.R. §164.501).
1.5 Designated Record Set shall have the meaning given to such term under the Privacy Rule (45 C.F.R. §164.501).
1.6 Electronic Health Record shall have the meaning given to such term in the HITECH Act (42 C.F.R. § 17921).
1.7 Electronic Protected Health Information shall have the meaning given to such term under the Privacy Rule (45 CFR
§164.501and §106.103)
1.8 Health Care Operations shall have the meaning given to such term under the Privacy Rule (45 C.F.R. §164.501).
1.9 Individual shall have the meaning given to such term under the Privacy Rule (45 C.F.R. §160.103) and shall include a
person who qualifies as a personal representative (45 C.F.R. §164.502(g)).
1.10 Privacy Rule shall mean the Standards for Privacy of Individually Identifiable Health Information codified at 45 C.F.R.
Parts 160 and 164, Subparts A and E.
1.11 Protected Health Information shall have the meaning given to such term under the Privacy Rule (45 C.F.R.
§164.501). Protected Health Information includes Electronic Protected Health Information (C.F.R. §160.103 and
§164.501).
1.12 Protected Information shall have the meaning given to such term under the Privacy Rule (45 C.F.R. §164.501).
Protected Information includes Electronic Protected Information (C.F.R. §160.103 and §164.501).
See page 7 for EOE/ADA disclosures
PPP-1136A FORENG (2-23)
Page 2 of 7
1.13 Required By Law shall have the meaning given to such term under the Privacy Rule (45 C.F.R. §164.512).
1.14 Secretary shall mean the Secretary of the U.S. Department of Health and Human Services or his designee.
1.15 Security Rule shall mean the HIPAA Regulation that is codified at 45 C.F.R. Parts 160 and 164, Subparts A and C.
1.16 Unsecured PHI shall have the meaning given to such term under the HITECH Act and any guidance issued pursuant
to such Act ( 42 U.S.C. §17932(h)).
2.0 PERMITTED USES AND DISCLOSURES OF PHI. The Business Associate will use and disclose PHI only for
those purposes necessary to perform functions, activities, or services for, or on behalf of, the DES Covered
Component as specified in the underlying Contract, this BAA , or as Required By Law. Any use or disclosure by the
Business Associate shall not violate applicable Privacy Rule provisions, the terms of this BAA, or the DES Covered
Component policies and procedures for using or disclosing only the Minimum Necessary PHI.
2.1 Prohibited Use and Disclosures. The Business Associate shall not use or disclose Protected Information for
fundraising or marketing purposes. The Business Associate shall not disclose Protected Information to a health plan
for payment or health care operations purposes if the patient has requested a restriction and has paid out of pocket
in full for health care items or services to which the PHI solely related as described in 42 U.S.C. §17935(a). The
Business Associate shall not directly or indirectly receive remuneration in exchange for Protected Information, except
with the prior written consent of the Covered Component and as permitted by the HITECH Act, 42 U.S.C. §17935(d)
(2); however, this prohibition shall not affect payment by the Covered Component to the Business Associate for
services provided pursuant to the Contract. Disclosure for research is prohibited without the Covered Component’s
permission prior to such disclosure.
2.2 Business Activities of Business Associate. The Business Associate may use PHI for the necessary management
and administration of the Business Associate, or to carry out the legal responsibilities of the Business Associate if:
1. The disclosure is Required By Law; or
2. The Business Associate obtains reasonable written assurances from a third party receiving the PHI that the third
party will:
i. Maintain the confidentiality of the PHI;
ii. Use or disclose the PHI only as Required By Law or for the purpose for which the PHI was disclosed to the
person;
iii. Notify the Business Associate within 1 business day of any discovered breach of confidentiality of the Protected
Information (42 U.S.C. §17932; 45 C.F.R. §164.504(e)(2)(ii)(D)) and comply in writing with paragraphs 3.1, 3.2,
3.3, 3.4, 3.5 and 3.6; and
iv. Ensure that any third party to whom it provides Protected Information receives from, or created or received by
the Business Associate on behalf of the Covered Component, agrees to the same restrictions and conditions
that apply to the Business Associate with respect to such information (45 C.F.R. §164.504 (e)(2)(ii)(D)).
2.3. Aggregation of PHI. The Business Associate shall provide data aggregation services with regard to PHI created or
received from or on behalf of the DES Covered Component, if requested to do so by the DES Covered Component.
(45 C.F.R. §164.504(e)(2)(i)(B)).
2.4 De-Identification of PHI. Under 45 C.F.R. §164.502(d) (2), de-identified information does not constitute PHI and is
not subject to the terms of this Agreement. The Business Associate may de-identify any and all PHI, provided
1. The de-identification conforms to the requirements of 45 C.F.R. §164.514(b),
2. The Business Associate maintains the documentation required by 45 C.F.R. §164.514(b), and
3. The Business Associate gives written assurance to the DES Covered Component that the Business Associate
appropriately maintains the documentation required by 45 C.F.R. §164.514(b).
3.0. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE.
3.1. Safeguards. The Business Associate shall implement appropriate safeguards as are necessary to prevent the
use or disclosure of Protected information otherwise that as permitted by the Contract and the Business Associate
Agreement, including, but not limited to, administrative, physical, and technical safeguards that reasonably and
appropriately protect the confidentiality, integrity and availability of the Protected Information, in accordance with 45
C.F.R §164.308, §164.310, and §164.312. The Business Associate shall comply with the policies, procedures, and
documentation requirements of the HIPAA Security Rule, including but not limited to 42 U.S.C. §17931 and 45 C.F.R.
§164.316.
PPP-1136A FORENG (2-23)
Page 3 of 7
3.2 Reporting Impermissible Use or Disclosure and Security Incidents. The Business Associate agrees to report to
the DES Covered Component in writing of any access, use or disclosure of Protected Information not permitted by
the contract or the Business Associate Agreement, and any breach of Unsecured PHI of which it becomes aware of
as described in 42 U.S.C. §17921 and 45 C.F.R. §164.308(b) and §164.504(e)(2)(ii)(C), within 1 business day after
discovery. The Business Associate shall:
1. Promptly take corrective action to secure any such deficiencies; and
2. Grant prompt and immediate access to DES Covered Component and other individuals from DES or the State of
Arizona authorized by DES to participate in the incident investigation, mitigation, resolution, or breach notification;
and
3. Contact the DES Chief Privacy Officer if DES Covered Component cannot be notified within 1 business day after
discovery of incident; and
4. Secure and preserve all records pertinent to the incident; and
5. Promptly require within 1 business day of incident discovery applicable subcontractors and agents to secure and
preserve all records pertinent to the incident; and
6. Any action pertaining to such unauthorized disclosure required by applicable federal and state statutes and
regulations.
3.3. Mitigation. The Business Associate agrees to mitigate, to the extent practicable, any harmful effects that are known
to the Business Associate of a use or disclosure of PHI by the Business Associate or its agents or subcontractors in
violation of the requirements of this Agreement ( 45 C.F.R §164.530(f)).
3.4 Agents and Subcontractors. The Business Associate agrees to the following:
1. Ensure that any agent, including a subcontractor, to whom it provides PHI received from, or created or received by
the Business Associate on behalf of the DES Covered Component, agrees in writing to the same restrictions and
conditions that apply to the Business Associate through this Agreement with respect to such PHI and implementing
the safeguards required by paragraph 2.1 above with respect to Protected Information (45 C.F.R. §164.308(b) and
§164.504(e)(2)(ii)(D)).
2. It shall implement and maintain sanctions against agents and subcontractors that violate such restrictions and
conditions and shall mitigate the effects of any such violations as described in 45 C.F.R. §164.530(e)(l) and
164.530(f).
3.5 Personnel. The Business Associate shall appropriately inform all of its employees, agents, representatives, and
members of its workforce (“Personnel”), whose services may be used to satisfy the Business Associate’s obligations
under this Agreement and the Related Contract, of the terms of this Agreement. The Business Associate represents
and warrants that the Personnel are under sufficient legal obligations to the Business Associate for the Business
Associate to fully comply with the provisions of this Agreement. The Business Associate agrees to train its workforce
on the HIPAA Rule and keep appropriate records of the training as prescribed in 45 C.F.R. §164.530(b)(1)(2).
3.6. Access to Protected Information. The Business Associate shall make Protected Information maintained by
the Business Associate or its agents or subcontractors in Designated Record Sets available to the DES Covered
Component for inspection and copying within 10 business days of a request by the DES Covered Component to
enable the DES Covered Component to fulfill its obligations under the Privacy Rule, including, but not limited to, 45
C.F.R. §164.524. If the Business Associate maintains an Electronic Health Record, the Business Associate shall
provide such information in electronic format to enable the DES Covered Component to fulfill its obligations under
the HITECH Act, including, but not limited to, 42 U.S.C. §17935(e).
3.7 Individual Access to PHI. If an Individual requests direct access to PHI in possession of the Business Associate
which is maintained under its contract with DES, prior to disclosure of any PHI the Business Associate shall first
consult in writing with the DES Covered Component’s Privacy Officer or the DES Chief Privacy Officer. The
Business Associate shall grant or deny access pursuant to written instructions from the DES Covered Component
which are consistent with 45 C.F.R. §164.524 or other applicable law. Within 5 business days, the Business
Associate shall notify the DES Covered Component’s Privacy Officer or the DES Chief Privacy Officer in writing of
the actions it has taken pursuant to the request for access and DES Covered Component’s authorization.
PPP-1136A FORENG (2-23)
Page 4 of 7
3.8. Amendment of PHI. The Business Associate agrees to make any amendment(s) to PHI in a Designated Record
Set within 5 business days after the Business Associate receives from the DES Covered Component instructions
to amend PHI. Such instructions generally follow an Individual’s request to the DES Covered Component to amend
the Individual’s PHI held by the DES Covered Component or its Business Associates in a Designated Record Set.
If the DES Covered Component declines an Individual’s request to amend that Individual’s PHI, the DES Covered
Component shall provide to its Business Associate, who shall promptly incorporate into the Individual’s Designated
Record Set, any statements of disagreement and/or rebuttals supplied by the Individual, as required by 45 C.F.R. §
164.526.
3.9 Individual Amendment of PHI. If an individual requests an amendment of PHI directly from the Business Associate
or its agents or subcontractors on behalf of the DES Covered Component, the Business Associate must notify the
DES Covered Component in writing within 5 business days of the request. Any approval or denial of amendment
to Protected Information maintained by the Business Associate or its agents or subcontractors shall be the
responsibility of the DES Covered Component, which shall notify the Business Associate of its decision in writing.
3.10 Documentation of Disclosure. The Business Associate agrees to document all disclosures of PHI made by
the Business Associate and information related to such disclosures as would be required by the DES Covered
Component to respond to a request by an Individual for an accounting of disclosures of PHI according to 45 C.F.R.
§164.528. At a minimum, the documentation related to the Business Associate’s disclosure of PHI shall include:
1. The date of disclosure;
2. The name of the PHI recipient and, if known, the address of the PHI recipient;
3. A brief description of the PHI disclosed; and
4. A brief statement of the purpose of the disclosure that reasonably informs the Individual of the basis for the
disclosure, or instead of such statement, a copy of the written request for disclosure by the Secretary or under 45
C.F.R. §164.512.
3.11. Accounting of Disclosures. Within 10 business days after receipt of notice from the DES Covered Component to
the Business Associate that the DES Covered Component has received a request for an accounting of disclosures
of an Individual’s PHI, the Business Associate agrees to provide the DES Covered Component with the disclosure
information requested by the Individual and as required in paragraph 3.10 above. If an individual requests an
accounting of disclosures directly from the Business Associate, the Business Associate shall, within sixty (60)
business days, provide or deny an accounting according to 45 C.F.R §164.528. Unless otherwise directed by the
DES Covered Component, the Business Associate shall notify the DES Covered Component of the action it has
taken and shall do so in writing within five (5) business days after the action. The accounting of disclosure shall
include all PHI disclosures for the time period the Individual requested, but not for a date earlier than six years
prior to the date of creation or last entry, which ever occurred last. If the Business Associate is unable to provide
the accounting of disclosure within the allowed time frame, the Business Associate shall provide the DES Covered
Component with a written statement of the reason for delay and the date the Business Associate will provide the
accounting.
3.12 Government Access to Records. For the purpose of determining the DES Covered Component compliance with
the Privacy Rule, as well as the Business Associate’s compliance with this BAA, the Business Associate agrees to
make available to the DES Covered Component or its authorized agent, or to the Secretary, in the time and manner
designated:
1. The Business Associate’s internal practices, books, and records, including policies and procedures, relating to the
use and disclosure of PHI received from, or created or received by the Business Associate on behalf of the DES
Covered Component; and
2. All PHI received by the Business Associate from the DES Covered Component or created or received by the
Business Associate on behalf of the DES Covered Component.
3.13 Minimum Necessary. The Business Associate and its agents and subcontractors shall request, use, and disclose
only the minimum amount of Protected Information necessary to accomplish the purpose of the request, use or
disclosure as described in 42 U.S.C. § 17935(b); 45 C. F. R. § 164.502(b)(1) and 164.514(d).
3.14 Data Ownership. The Business Associate acknowledges that the Business Associate has no ownership rights with
respect to the Protected Information.
PPP-1136A FORENG (2-23)
Page 5 of 7
3.15 Transaction Standards Regulation. If the Business Associate conducts in whole or part Standard Transactions
for or on behalf of the DES Covered Component, the Business Associate agrees to comply with the Electronic
Data Transaction Standards and Code Sets, 45 C.F.R. Part 162 (I – R). The Business Associate agrees to
require any subcontractor or agent involved in conducting Standard Transactions for or on behalf of the DES
Covered Component, to comply with the Transaction Standards and Code Sets. The Business Associate and its
subcontractors or agents shall not engage in any practice or enter into any agreement related to conducting in whole
or in part Standard Transactions for or on behalf of the DES Covered Component that:
1. Changes the definition, Data Condition, or use of a Data Element or Segment in a Standard Transaction;
2. Adds a Data Element or Segments to the maximum defined Data Set;
3. Uses any code or Data Element that is marked “not used” in the Standard Transaction’s implementation
specification or that is not in the Standard Transaction’s implementation specification; or
4. Changes the meaning or intent of the Standard transaction implementation specification.
3.16 Retention of Records. All records containing PHI created or received by the Business Associate from or on behalf
of the DES Covered Component will be retained for six years from the date of creation (e.g., PHI) or the date when it
last was in effect (e.g., a policy or form), whichever is later.
3.17 Violations of Law. The Business Associate may use PHI to report violations of law to appropriate Federal and State
authorities, consistent with 45 C.F.R. §164.502(j).
3.18 Audits, Inspection and Enforcement.
1. Within 10 business days of a written request by the DES Covered Component, the Business Associate and its
agents or subcontractors shall allow the DES Covered Component to conduct a reasonable inspection of the
facilities, systems, books, records, agreements, and policies and procedures relating to the use, acquisition,
or disclosure of Protected Information pursuant to this Agreement for the purpose of determining whether the
Business Associate has complied with this Agreement; provided, however that:
i. The Business Associate and the DES Covered Component shall mutually agree in advance upon the scope,
timing and location of such inspection. If an agreement can not be concluded, then DES will decide; and
ii. To the extent allowed by law, the DES Covered Component shall safeguard all trade secret information of the
Business Associate to which the DES Covered Component has access during the course of such inspection; and
2. The fact that the DES Covered Component inspects, fails to inspect, or has the right to inspect the Business
Associate’s facilities, systems, books, records, agreements, and polices and procedures does not relieve the
Business Associate of its responsibilities to comply with this Agreement. The following acts by the DES Covered
Component do not constitute acceptance of such practices or waive the DES Covered Entity’s enforcement rights
under the contract or Agreement.
i. Failure to detect; or
ii. Detection, but failure to notify the Business Associate; or
iii. Requiring the Business Associate to correct any unsatisfactory practices.
3. The Business Associate shall notify the DES Covered Component in writing within 1 business day of learning that
the Business Associate has become the subject of an audit, compliance review, or complaint investigation by the
Office for Civil Rights.
4. Notwithstanding paragraph 3.18.1, pursuant to paragraphs 3.1 through 3.4 and in compliance with 42 U.S.C.
§17921 and 45 C.F.R. §164.308(b) and §164.504(e)(2)(ii)(C), Business Associate, its subcontractors and agents
shall permit prompt and immediate access to the Covered Component to all physical locations and business
records, including electronic records and all relevant data files, under the control or maintained by the Business
Associate, its subcontractors and agents on behalf of Covered Component, for the purpose of mitigating a data
breach, conducting a risk analysis and obtaining information which will identify individuals affected.
4.0 OBLIGATIONS OF DES COVERED COMPONENT
4.1. Notice of Privacy Practices. The DES Covered Component shall notify the Business Associate of any changes or
limitation(s) in the DES Covered Component’s Notice of Privacy Practices according to 45 C.F.R. §164.520, to the
extent that such changes or limitation(s) may effect the Business Associate’s use or disclosure of PHI.
4.2 Changes in Permission by Individual. The DES Covered Component shall notify the Business Associate of any
changes in, or revocation of, an Individual’s permission to use or disclose PHI, to the extent that such changes may
affect the Business Associate’s use or disclosure of PHI.
PPP-1136A FORENG (2-23)
Page 6 of 7
4.3 Restriction on PHI. The DES Covered Component shall notify the Business Associate of any restriction on PHI uses
and disclosures that the DES Covered Component has agreed to in accordance with 45 C.F.R. §164.522, to the
extent that such restriction may affect the Business Associate’s use or disclosure of PHI.
4.4 Permissible Requests by DES Covered Component. The DES Covered Component shall not request the Business
Associate to use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by the
DES Covered Component.
5.0 TERM AND TERMINATION
5.1 Term. The term of this Agreement is specified on page one (1) of this Agreement or in the Contract to which it is
appended and shall terminate when all PHI provided by the DES Covered Component to the Business Associate, or
created or received by the Business Associate on behalf of the DES Covered Component, is destroyed or returned
to the DES Covered Component. If it is not feasible for the Business Associate to return to the DES Covered
Component or destroy all PHI when this Agreement terminates under the Contract or is terminated early, protections
agreed to by the Business Associate are extended to such information, whether PHI is held or controlled by the
Business Associate or its agents or subcontractors.
5.2 Effect of Termination.
1. Except as provided in subparagraph 3 of this paragraph, upon termination of this Agreement for any reason, the
Business Associate shall return or destroy all PHI received from the DES Covered Component, or created or
received by the Business Associate on behalf of the DES Covered Component. No copies or data repositories can
be retained as to this information.
2. This provision shall apply to PHI in the possession or under the control of subcontractors or agents of the
Business Associate. The Business Associate and its subcontractors and agents shall retain no copies or data
repositories of any type of returned or destroyed PHI unless ordered to do so by a court of law.
3. If the Business Associate determines that returning or destroying PHI is not feasible, the Business Associate shall
provide to the DES Covered Component notification of the conditions making the return or destruction not feasible.
The Business Associate shall extend the protections of this Agreement to the PHI and shall limit further uses and
disclosures of the PHI to the purpose that make the return or destruction not feasible, for so long as the Business
Associate maintains the PHI. If it is not feasible for the Business Associate to recover from a subcontractor or
agent any PHI, the Business Associate shall provide a written explanation to the DES Covered Component. The
Business Associate shall require the subcontractor or agent to agree:
i. To extend the protections of this Agreement to the PHI in subcontractor or agent; and
ii. To limit further uses or disclosures of the PHI to the purpose that makes the return or destruction not feasible, for
so long as the subcontractor or agent maintains the PHI.
5.3 Termination for Cause.
1. Breach. Upon the DES Covered Component’s knowledge of a material breach by the Business Associate of the
terms of this Agreement, the DES Covered Component shall take one or more of the following actions:
i. Provide an opportunity for the Business Associate to cure the breach within a specified timeframe;
ii. Terminate this Agreement and the underlying Contract if the Business Associate does not cure the breach or end
the violation within the time specified by the DES Covered Component, or if a cure of the breach is not possible;
iii. Immediately terminate this Agreement and the underlying contract; or
iv. Report the violation to the Secretary, if neither termination nor cure is feasible.
2. Judicial or Administrative Proceedings. The DES Covered Component may terminate the Agreement if;
i. The Business Associate is named as a defendant in a criminal proceeding for a violation of HIPAA, the HITECH
Act, the HIPAA Regulations or other security or privacy laws; or
ii. There is a governmental agency or tribunal finding or stipulation that the Business Associate has violated any
standard or requirement of HIPAA, the HITECH Act, the HIPAA regulations or other security or privacy laws.
6.0 MISCELLANEOUS
6.1 HIPAA Reference. A reference in this Agreement to HIPAA or the Privacy Rule means the regulation including the
HITECH Act of 2009, as in effect on the effective date or as subsequently amended, and for which compliance is
required. (45 C.F.R. § 160, §162, and §164 and 42 U.S.C. §17938).
PPP-1136A FORENG (2-23)
Page 7 of 7
day of
20
by the
Department of Economic Security.
DES Senior Records and Privacy Officer
Printed Name
The above referenced HIPAA Business
Associate Agreement is hereby executed this
Contractor hereby acknowledges receipt and acceptance of
this HIPAA Business Associate Agreement and that a signed
copy must be filed with the DES Procurement Office.
Signature
Date
Printed Name
Title
Name of Contractor
6.2. Amendment. The parties agree to take the action necessary to amend this Agreement from time to time so that the
DES Covered Component may comply with the requirements of HIPAA, HITECH, court decisions and any regulatory
changes.
6.3 Interpretation. Any ambiguity in this Agreement shall be resolved to permit the DES Covered Component to comply
with the HIPAA and HITECH Rules.
Pursuant to Title VI of the Civil Rights Act of 1964, the Americans with Disabilities Act (ADA) and other nondiscrimination
laws and authorities, ADES does not discriminate on the basis of race, color, national origin, sex, age, or disability. To
request this document in alternative format or for further information about this policy, contact your local office; TTY/TDD
Services: 7-1-1.
IN WITNESS WHEREOF, the parties agree to enter into this Agreement
FOR AND ON BEHALF OF
MARICOPA COUNTY
ATTEST:
_____________________________________________________
CLERK OF THE BOARD
DATE
_____________________________________________________
APPROVED AS TO FORM
DATE