CONFIDENTIALITYANDDATAACCESSAGREEMENT.PDF

Maricopa County — Formal (2023-10-18)

View PDF Item 89 Meeting page

Extracted text (via ocr_local) 40710 characters
DocuSign Envelope ID: £6355837-010D-48EF-A8A5-625EC09B48314

CONFIDENTIALITY AND DATA ACCESS AGREEMENT

This CONFIDENTIALITY AND DATA ACCESS AGREEMENT (“Agreement”) is made and
entered into as of the last date of signature (the “Effective Date”) by and between Banner Health, an
Arizona nonprofit corporation (“BH”) and Maricopa County Department of Public Health (“User”)
(individually, the “party” and collectively, the “parties”).

I. RECITALS

WHEREAS, BH is a covered entity as defined by 45 CFR § 160,103 and therefore is the custodian
of certain electronically-available Protected Health Information, as defined by 45 CFR § 160.103
(hereinafter "PHI"); and

WHEREAS, User desires to access, use, and retain, and to permit its authorized agents, identified
more fully below ("User Agents"), to access, use, and retain PHI via BH's web-based application ("Patient
Information Application") to perform disease investigations mandated under the AZ Administrative Code
Title 9, Chapter 6 and to review all records related to suicide per Arizona Revised Statutes (A.R.S.) § 36-
199.01 and opioid fatalities per A.R.S. Title 36, Chapter 1, Article 6 as part of its responsibility for leading
the Suicide Mortality Review Board and a county requirement to continue to lead the opioid fatality review
board; and

and

NOW, THEREFORE, in consideration of the mutual promises herein contained, BH and User agree
to the terms as defined in this Agreement.

IL. AGREEMENT

1, Access, BH will permit User and User Agents to request IDs and passwords as set forth
herein and User agrees to transmit electronically or permit electronic access to PHI in accordance with this
Agreement for the following HIPAA compliant activities:

Activities related to Arizona’s Communicable Disease Program, Suicide Mortality Review
Program, and Drug Overdose Fatality Review Program

Access will be granted to the User Agents listed on Exhibit A.

2. Compliance with Law. User agrees to comply with, and to ensure that all User Agents,
including but not limited to, cinployees, owners, partners, subcontractors or vendors, comply with this
Agreement and all state and federal law.

3, Administrator and Notice, User will identify, to BH, an Administrator (User's designated
representative authorized to assign passwords or IDs to User Agents, and responsible for the enforcement
of this Agreement) and User Agents accessing the Patient Information Application. User will use best
efforls (o notify BH within 14 days, but no later than 30 days, after any change in the Administrator or
User Agent, provided, however, User will immediately terminate Administrator or User Agent access when
access is not required. User agrees to accept responsibility for the activities of the Administrator and all
User Agents and to keep current the written identification of User Agents in Exhibit A.

4, Access. If User desires any User Agent to have access to the Patient Information
Application, Administrator may request a user ID and a password, both of which are necessary to access

Page | of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID; E6355837-010D-48EF-A8A5-625EC09B4831

the Patient Information Application, The Administrator will authorize User Agent's access to different
portions of the Patient Information Application based upon User Agent’s need for PHI to perform the
activities identified in Section | above, and may delete or limit User Agent’s access. User will review the
terms of this Agreement with User Agent. User will be responsible for User Agent’s compliance, and
acknowledges and agrees that, in the event of any violation of this Agreement, BH may terminate User
Agent’s or User’s electronic access to the PHI immediately.

5, Requirements, In order to ensure the confidentiality of PHI, User agrees that:

5.1

5.2

5.3

3.4

5.5

5.6

3.7

5.8

5.9

User will ensure that User Agents will only use the PHI when needed, and to the
extent necessary as authorized by this Agreement and in compliance with HIPAA,

BH has implemented a corporate compliance program to ensure compliance with
federal, state, and local laws and regulations. User will either (i) train the User
Agents through User’s own compliance and privacy program, or (ii) require User’s
Agents to attend BH’s Corporate Compliance Training.

User will protect the PHI from distribution, disclosure, reproduction, or
dissemination in any manner to any person not authorized or entitled by law to
have access to the PHIL

User will be responsible for ensuring that User Agents will not disclose, distribute,
reproduce or disseminate the PHI in any manner to any person not authorized or
entitled by law to have access to the PHI.

User will limit access to the PHI by User Agents to the PHI necessary for the User
Agents to perform their responsibilities.

User will promptly terminate access to those individuals who are no longer User
Agents or who no longer have a need to access the Patient Information Application,

User will ensure that User Agents do not use any other person’s user ID or
password to gain access (o the Patient Information Application, and User Agents
do not share user IDs or passwords with any other user,

User will conduct a comprehensive review on an annual basis of all User Agents
to ensure that each User Agent requires access to the Patient Information
Application.

User acknowledges that none of the PHI will be accessed by, or provided to, any
individual or company that is not physically located within one of the fifty United
States or United States Territories. This provision applies to work performed by
User or any subcontractor utilized by User with any access to the PHI provided
under this Agreement at all tiers.

6. Insurance and Indemnification.

6.1

User agrees to indemnify, defend, and hold harmless BH for, from, and against any
and all third party liabilities, damages, claims, or losses incurred by BH to the
extent arising from any violation by User or User Agents of any of the provisions
of this Agreement.

Page 2 of 13

0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID: £6355837-010D-48EF-ABA5-625EC09B4831

6.2

6.3

User is a self-insured government entity, pursuant to A.R.S. § 11-981 and the
Revised Restated Declaration of Trust for Maricopa County, Arizona Self-Insured
Risk Trust Fund.

User will indemnify and hold harmless BH from and against third party claims
brought against BH to the extent resulting from, or arising out of, a breach of this
Agreement by User or any subcontractors, including, but not limited to, any breach
of a provision dealing with security or unauthorized use or disclosure of PHI,

7, Unauthorized Activities.

VA

7.2

73

If User suspects or has reason to know that a User Agent is accessing PHI by using
another User Agent's ID or Password, User will promptly request suspension of
that ID or Password, report the suspected, or known, misuse to BH’s Information
Technology Help Desk at (602) 747-4444, and make a written report of the misuse
to the BH Privacy Officer within 10 days of the occurrence as provided below.

If User suspects or has reason to know that a User Agent is accessing PHI that the
User Agent does not reasonably need to perform the activities identified in Section
L above, User will promptly request suspension of the User Agent's ID or
Password, report the suspected or known misuse to BH’s Information Technology
Help Desk at (602) 747-4444, and make a written report of the misuse to the BY
Privacy Officer within 24 hours of the occurrence.

Any written report required will be addressed to the BH Privacy Officer, 2901 N.
Central Ave., Suite 160, Phoenix, AZ 85012, will be made via U.S. mail, first class,
postage prepaid or express courier and will, at a minimum;

7.3.1 Identify the PHI that was subject to the unauthorized access and the date
the unauthorized access occurred;

73.2 Identify the date the unauthorized access was discovered and what, if any,
additional disclosure of PHI may have occurred.

7.3.3 Identify what User did or will do to mitigate any harmful effect of the non-
permitted access and how User will prevent the non-permitted access from
occurring in the future.

8, Term and Termination, This Agreement will be effective on the Effective Date and will
remain in effect unless terminated by either party for any reason by giving 10 days advance written notice
to the other party, BH retains the right to terminate this Agreement immediately if it suspects a violation
of patient confidentially or violation of any other term of use.

9. Rules, Regulations and HIPAA policies. User hereby agrees to comply, and to ensure that

User Agents comply, with any User rules, regulations, and policies implementing HIPAA requirements
whether now or hereafter existing. Should BH determine that modifications to this Agreement are
necessary in order to comply with HIPAA regulations or cither party’s obligations thereunder, then the
parties agree to negotiate in good faith an amendment to this Agreement and to execute the amendment in
order to achieve compliance.

Page 3 of 13

0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID; £6356837-010D-48EF-A8A5-625EC09B4831

10, Patient Information Application. User acknowledges and agrees that BH maintains the

right to modify the features of the platform used to provide the PHI to User at any time, BH will use best
efforts to communicate to User any changes in a timely manner.

li. Limited Technical Support. BH agrees to provide limited technical support to User to

troubleshoot problems or research data errors related to the Patient Information Application. BH also agrees
to train a designated User trainer so that this person can train other User staff on the use of the Patient
Information Application. BH will not provide training or technical support on the use of PCs, internet
browsers, or assist with site-specific technical issue that may be unique to User's information systems.

12, Confidentiality and Nondisclosure,

12.1

12.2

12.3

The parties agree that the PHI and other information accessed, used, and retained
as a result of this Agreement will remain confidential pursuant to the applicable
Arizona Revised Statutes, including A.R.S. § 36-198.01 and § 36-199.01,

User acknowledges that User may have access to confidential and proprictary
information of BH (the “Proprietary Material”) through this Agreement. User will
keep confidential all Proprietary Material by exercising the same degree of care
toward such material as User does with respect to its own confidential and
proprietary information of like importance, but, in any case, using no less than a
reasonable degree of care, User will not disclose, distribute, publish, transmit,
transfer or disassemble the Proprietary Material or use the Proprietary Material for
its own or any other party’s benefit, except in furtherance of its obligations under
this Agreement. User will limit access to the Proprietary Material to only those
individuals who need {o know such information for carrying out User’s obligations
hereunder. User will ensure that its personnel, agents, consultants and
representatives who are given access lo the Proprietary Material will be bound by
and comply with the terms of this Agreement. The nondisclosure provisions of
this Agreement will be in effect during the term of this Agreement and will survive
termination, and User’s duty to hold the Proprietary Material in confidence will
remain in effect until the Proprietary Material no longer qualifics as confidential
information or a trade secret under applicable law. For purposes hereof, the
Proprietary Material includes, but is not limited to, documents, records, reports,
data, patient health information, demographic information, plans, concepts, ideas,
processes, procedures, policies, designs, discoveries, inventions, marketing plans,
methodologies, specifications, and other business information relating to BH’s
business, assets, operations or contracts, regardless of whether such information
has been expressly designated as confidential or proprietary. The Proprietary
Material may be provided in written, oral, electronic or other form, The Proprietary
Material will not include any information that (a) is now or becomes generally
known or available to the public through no fault of User; (b) was known by User
before receipt from BH without any obligation of confidentiality; (¢) is rightfully
obtained by User from a third party without breach of any obligation to the
disclosing party; or (d) is independently developed by User without use of or
reference to any of the Proprietary Material.

The parties understand and agree that this Agreement is subject to all state and

federal laws protecting client confidentiality of medical, behavioral health, and
drug treatment information. User is a government entity subject to public records

Page 4 of 13

0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope [D: E6355837-010D-48EF-A8A5-625EC09B4831

laws. Accordingly, notwithstanding any other provision of this Agreement, any
provision regarding confidentiality is limited to the extent necessary to comply
with federal and Arizona law. Should User receive any request for disclosure of
confidential information related to this Agreement, User will promptly notify BH
in writing prior to the disclosure date.

13. Information Technology Security. Where User is required to (a) access, process, receive,
transmit or store any confidential information, personal information, or protected health information of BH,
or (b) have access to computer(s), computer network(s), computer application(s), storage device(s), mobile
computing device(s) or software owned or leased by BH, or any BH facility, the Banner Security
Addendum, a copy of which is attached hereto as Exhibit B and incorporated herein by reference, will

apply.

14, No Referral. This Agreement is limited solely to BH’s contractual arrangement with User
to provide access to PHI in accordance with the terms of this Agreement. User acknowledges and agrees
that there is no intent, agreement, understanding or requirement pursuant to which User or any other person
or entity affiliated with User has any obligation to admil, refer or recommend patients to any hospital or
facility owned or operated by BH.

15, Governing Law. This Agreement will be governed by the internal substantive law of the
State of Arizona, without regard for the conflict of law principles thereof,

16. No Federal Exclusion or Preclusion. User represents and warrants that it and all personnel
with access to PHI pursuant to this Agreement are not excluded from participation, and are not otherwise
ineligible to participate, in a “Federal health care program” as defined in 42 U.S.C. § 1320a-7b(f) or in any
other government payment program. User will use commercially reasonable efforts to disclose in writing
within three working days any debarment, exclusion, suspension or other event that makes User (i)
ineligible to participate in the Federal health care programs or in Federal procurement or non-procurement
programs; or (ii) if User has been convicted of a criminal offense that falls within the ambit of 42 U.S.C. §
1320a-7(a), but has not yet been excluded, debarred, suspended or otherwise declared ineligible.

17. Assignment, This Agreement may not be assigned by either party without the prior written
consent of the other party. If consent to an assignment is obtained, this Agreement is binding on the assigns
of the parlies to this Agreement. Notwithstanding anything to the contrary in this Agreement, BH may
assign or otherwise transfer its interest under this Agreement to any “related entity” without the consent of
the other party. For the purposes of this Section, a related entity will be deemed to include a parent, a
subsidiary, any entity that acquires all or substantially all of BH’s assets or operations relating to this
Agreement, and the surviving entity of any merger or consolidation involving BH,

18. Waiver and Breach. No waiver of the enforcement or breach of any agreement or provision
herein will be deemed a waiver of any preceding or succeeding breach thereof or of the enforcement of any
other agreement or provision herein. No extension of time for performing any obligation or act will be
deemed an extension of time for performing any other obligation or act. All rights and remedies provided
herein are cumulative and not exclusive of any rights or remedies otherwise provided by law.

19, Supersede and Replace. This Agreement is intended to supersede and replace any existing
agreements between the parties with regard to the subject matter contained herein, including the Electronic
Transmission Agreement dated October 9, 2013,

20. Notices. Any notice required to be given under this Agreement will be in writing, and will
be deemed delivered to the party to whom the notice is sent (a) when personally delivered, (b) one business

Page 5 of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID: £6355837-010D-48EF-ABA5-625EC08B4831

day after the same is sent by overnight delivery service, or (c) three days after the same is sent by certified
mail, postage prepaid, addressed to such party at the address that follows or to such other address as such
party may hereinafter designate in writing:

For BH: Banner Health
Attn: Senior VP, Care Management & CMIO
2901 N. Central Ave, Ste, 160
Phoenix, AZ 85012

With a copy to: Banner Health
Legal Department
2901 N. Central Ave, Ste, 160
Phoenix, AZ 85012
Attn: General Counsel

If to User: Administrator, Public Health Epidemiology and Informatics Division
4041 N. Central Avenue, Suite 600
Phoenix, AZ 85012
‘Attn: Dr. Jessica White

21, Survival. Any covenant or provision herein that requires or might require performance
after the termination or expiration of this Agreement, including, but not limited to, indemnities,
confidentiality, and insurance requirements, will survive any termination or expiration of this Agreement.

22, Entire Agreement. This Agreement and any attachments/exhibits/schedules contains the
entire agreement between the parties with respect to the subject matter hereof. AIL prior negotiations
between the parties are merged in this Agreement, and there are no understandings or agreements other
than those incorporated herein. This Agreement may not be modified except by a written instrument signed
by both parties to this Agreement,

23, Statutory Termination. Pursuant to A.R.S. § 38-511, User may cancel this Agreement
without penalty or further obligation within three years after execution of the contract if any person
significantly involved in initiating, negotiating, securing, drafting or creating the Agreement on behalf of
User is at any time while the Agreement or any extension of the Agreement is in effect, an employee or
agent of any other party to the Agreement in any capacity or consultant to any other party of the contract
with respect to the subject matter of the Agreement. Additionally, User may recoup any fee or commission
paid or due to any person significantly involved in initiating, negotiating, securing, drafting or creating the
contract on behalf of User 1 from any other party to the Agreement arising as the result of the Agreement.

Banner Health: FOR AND ON BEHALF OF MARICOPA COUNTY:
py; William Halland By:
. William Holland Chairman, Board of Supervisors Date
Typed Name:

ATTEST
Title: SVP_ Care Management, CMIO

Clerk of the Board Date
DateSePtember 22, 2023 | 2:20 PM MST APPROVED AS TO FORM

Attorney for Maricopa County Date

Page 6 of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope !D: £6355837-010D-48EF-A8A5-625EC09B4831

EXHIBIT A
USER AGENTS

Name of Group Admin —

Mailing Address —

Phone number —

Email address —

TITLE EMPLOYEE NAME EMAIL ADDRESS PHONE EMPLOYEE ID
NUMBER
Page 7 of 13

0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID: £6355837-010D-48EF-A8A5-625EC09B4831

EXHIBIT B
BANNER SECURITY ADDENDUM

The terms and conditions of this Banner Security Addendum (“Addendum”) apply to vendors and
business partners (“Contractor”) providing services thal include Processing Banner Content under an
underlying agreement (“Agreement”). By signing the Agreement, Contractor agrees to the terms and
conditions of this Addendum as may be amended as described below, This Addendum establishes the
minimum standards to protect the Banner Systems and Banner Content and to minimize security risks and
costly data breaches.

1. PROTECTION OF BANNER CONTENT. Contractor will establish and maintain practices,
procedures and other safeguards to prevent the unauthorized access, destruction, loss, alteration or
disclosure of Banner Content in the possession of the Contractor or Contractor personnel. These practices
will conform to the terms of this Addendum, the Agreement and Applicable Laws.

Ll Contractor’s Obligations, Contractor will hold, maintain, and manage Banner Content in
strictest confidence and use reasonable care to prevent any unauthorized use or disclosure. Contractor will
not use, assign, sell, rent, lease, license, transfer, convey, distribute, or otherwise disclose or make
available Banner Content for Contractor’s own purposes or for the benefit of any party other than Banner
without Banner’s prior express written consent. Contractor represents that during the term of the
Agreement it will maintain and implement a comprehensive written information security program that
complies with Applicable Laws and relevant Standards. Contractor’s information security program will
include appropriate administrative, technical, physical, organizational, and operational safeguards and
other security measures that will: (a) establish minimum controls and requirements consistent with
Standards to be met in connection with the safeguarding of Banner Content in any form; (b) ensure the
security, integrity, confidentiality, and availability of Banner Content, the Banner Systems managed by
Contractor, and the Contractor Systems Accessing or Processing Banner Content in a manner consistent
with Standards; (c) protect against anticipated threats or hazards to the security and integrity of Banner
Content and the Contractor Systems; (d) identify, report, and notify Banner of an Incident; (e) investigate
and remediate an Incident; and (f) provide Banner with satisfactory assurance that such Incident will not
recur,

12 Data Management Obligations, Untess otherwise provided in a Business Associate
Agreement between the parties, if Contractor stores Banner Content, (a) Contractor will implement and
maintain information management requirements and policies and establish procedures to ensure
compliance with the terms of this Addendum; and (b) promptly upon the expiration or termination of the
Agreement or upon reasonable written request, and at no additional cost to Banner, Contractor will, at
Banner’s election, cither (i) securely destroy or render unreadable, or (ii) return to Banner all Banner
Content received by the Contractor. If Banner Content is returned {o Banner, Contractor will deliver a
complete and secure file of Banner Content in a file format agreed upon by the parties. If complete data
destruction or return is not technically feasible or retention is required by Applicable Laws or Standards
(excluding instances when Banner Content is retained as part of Contractor’s automatic, secured back-up
or similar archival system), Contractor will notify Banner in writing of Contractor’s inability to destroy or

Page 8 of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID: E6355837-010D-48EF-A8A5-625EC09B4831

return Banner Content, and will continue to protect Banner Content according to the requirements set
forth in this Addendum.

1.3 Contractor Personnel Requirements, Contractor will limit Access to Banner Content to
those who have a need to know and ensure that Contractor personnel receive appropriate training
regarding the security requirements set forth in this Addendum and comply with provisions that are no
less restrictive than those required by this Addendum.

14 Third Party Requirements, Contractor will not assign all its rights or obligations under
this Addendum to a third party(ies) without the prior written consent of Banner. If Contractor
subcontracts any rights or obligations, Contractor will enter into a written agreement with each third party

that imposes obligations that are no less restrictive than those imposed on Contractor under this
Addendum. Contractor will only retain third parties that Contractor reasonably expects are suitable and
capable of securing Banner Content in accordance with this Addendum, the Agreement, and Banner’s
written instructions,

LS Subpoena, Judicial, and Administrative Disclosure Orders, To the extent not prohibited
by law, rule or order, Contractor will notify Banner promptly in writing of any subpoena or other judicial
or administrative order by a government authority or proceeding seeking access to or disclosure of Banner
Content prior to responding to such request, Banner will have the right to defend such action in lieu of
and on behalf of Contractor at Banner’s expense, Banner may seck a protective order and Contractor will
reasonably cooperate with Banner in such efforts.

1.6 Incident Notification. Contractor shall notify Banner within three business days of
discovery of any Incident. In addition to providing notice, Contractor will: (a) inform Banner in writing of
any Incident; (b) summarize in reasonable detail the impact on Banner; (c) identify and take reasonable
and necessary corrective action(s); and (d) cooperate fully with Banner in all reasonable and lawful
efforts to prevent, investigate, mitigale, report, or rectify such Incident. Contractor will not distribute any
filings, communications, notices, press releases, or reports related to any Incident that materially impacts
Banner, Banner Content, or the Banner Systems without prior written approval from Banner, which will
not be unreasonably withheld or delayed.

1.7 Notification Costs. Upon the occurrence of an Incident for which Contractor is
responsible, Contractor will reimburse Banner for reasonable expenses incurred by Banner, including,
without limitation, expenses in notifying individuals affected by the breach, providing protective services,
and undertaking other actions that may be required under Applicable Law. Notification costs will be at
Banner’s discretion and are subject to any limitation of liability provisions agreed to by the parties to the
Agreement.

1.8 Compliance, Contractor agrees to comply with Applicable Laws and Standards.
Contractor covenants and agrees that no Applicable Law, legal requirement, or privacy or information
security enforcement action, investigation, litigation, claim, or any other circumstance (collectively,
“Action”) prohibits Contractor from: (a) fulfilling its obligations under this Addendum or (b) complying

Page 9 of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID: £6355837-010D-4 8EF-A8A5-625EC09B4831

with written instructions it receives from Banner concerning the Processing of Banner Content. If any
Action is reasonably likely to adversely affect Contractor’s ability to fulfill or comply with its obligations
under this Addendum, Contractor will, within five business days, notify Banner in writing, If Contractor
fails to remedy any curable Action pursuant to any cure provision provided in the Agreement or as
reasonably directed by Banner, Banner may, without penalty: (i) suspend Access or Processing, (ii)
terminate Access or Processing, and/or (iii) terminate the Agreement,

2, ACCESS TO THE BANNER SYSTEM AND BANNER CONTENT.

2.1 Restrictions. Except as specifically contemplated in the Agreement, Contractor will not,
and will not allow any Contractor personnel to: (a) Process Banner Content or Personal Information from
outside the United States; (b) attempt unauthorized Access to Banner Content; (c) input, delete, or
otherwise modify Banner Content or make any changes to the Banner Systems; or (d) Access, or attempt
to Access, any third party networks or systems from the Banner Systems except as necessary to perform
the Services and agreed to in writing by the parties,

2.2 Portable Storage Media, Unless expressly authorized in writing by Banner, Contractor
will not allow any Personal Information to be Processed using laptops, USB drives, external hard drives,
mobile devices, or any other portable storage media (collectively, “Portable Storage Media”), except as
required to perform the Services and only for the duration necessary. Where Portable Storage Media is
used, Contractor will use industry-standard encryption.

2.3 Credentials, Banner may issue Contractor personnel: (a) a login ID, password, or other
authentication credentials; or (b) a Banner facility identification card or other physical security access or
permission (collectively, “Credentials”), as necessary to perform the Services. Contractor personnel will
treat Credentials with due care and confidentiality to prevent unauthorized disclosure or misuse.
Contractor acknowledges that any Credentials issued to Contractor personnel are Banner’s confidential
information subject to the protections set forth in this Addendum, and will not be shared, disclosed, or
used in any unauthorized manner. Contractor will be responsible for the actions of any individuals using
Credentials issued to Contractor personnel. Upon termination of the Services or the underlying
Agreement, Contractor will promptly return physical Credentials. Contractor will notify Banner, where
possible, in advance or as soon as reasonably possible if any Contractor personnel no longer require their
Credentials.

24 Security Design Information, Any information related to the design or security topology
of the Banner Systems acquired by Contractor or that may be gained through Contractor’s Access will
constitute Banner Content. Contractor will not share, disclose, or use such information in any manner,
unless expressly authorized by Banner in writing.

2.5 Remote Access. If the Services require or provide remote Access to the Banner
Systems or the Contractor Systems Processing Banner Content, Contractor will secure transmissions of
Banner Content using industry-standard encryption technology. Contractor wil! implement and enable
two-factor authentication to remotely access the Contractor Systems that Process Banner Content, If the
Contractor Systems provide Banner Consumers with remote Access to the Contractor Systems Processing

Page 10 of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DecuSign Envelope ID: £6355837-010D-48EF-A8A5-625EC09B4831

Banner Content, Contractor will implement two-factor authentication and provide Banner Consumers the
option to opt-in to two-factor authentication.

2.6 Malware. Contractor will take reasonable precautions to prevent transmission of a
computer virus, malware, trojan, worm, ransomware, or other malicious code (collectively, “Malware”
to the Banner Systems, Banner personnel, or Banner Consumers. Contractor will maintain current
industry standard endpoint protection and detection tools on the Contractor Systems and will ensure
Contractor Systems are maintained with up-to-date securily patches, hotfixes, and other similar software
or firmware changes. Contractor personnel using the Contractor Systems to deliver the Services will
comply with this Addendum. Contractor will notify Banner promptly if Malware is detected ina file or
transmission sent to or received from Banner. If Malware is transmitted by Contractor in the delivery of
the Services to Banner, Contractor will make reasonable efforts to restore and/or reconstruct Banner
Content in Contractor’s possession lost due to such Malware at no additional cost to Banner.

2.7 Background Investigations, Contractor will conduct adequate screening of Contractor
Personnel, as may be agreed to in the Agreement, Banner reserves the right to restrict or deny Access to
Banner facilities, Banner Content and the Banner Systems by any individual for any reason.

3. AUDIT RIGHTS,

3.1. Banner Systems. Contractor and Contractor personnel may be subject to monitoring and
their activity recorded with no advance warning while using the Banner Systems. Contractor consents to
such monitoring and recording for itself and Contractor personnel.

3.2. Audit Rights / Reports. If Contractor Processes Banner Content using Contractor
Systems, Banner will have the right to perform an assessment, audit, examination, or review of
Contractor’s physical and/or technical environment, and/or request Reports to confirm compliance with
this Addendum no more than once per calendar year, unless Banner becomes aware of an Incident or
raises a reasonable concern regarding Contractor’s privacy and/or security practices. Any audit will be:
(a) conducted upon reasonable notice; (b) performed during Contractor’s normal business hours; and (c)
conducted in a manner that minimizes disruption to Contractor’s operations. Such audit may be conducted
by Banner or its designated representatives who have entered into appropriate confidentiality agreements
with Contractor, Contractor will provide reasonable cooperation and reasonable access to Contractor
facilities, Contractor Systems and Contractor personnel. Contractor will respond promptly to reasonable
inquiries from Banner or its designated representatives. If Banner requests Reports, such Reports will be
treated as Contractor’s confidential information and will be provided at no cost to Banner.

3.3, Third-Party Data Center. If Contractor uses a third-party hosted data center (e.g., Amazon
Web Services, Microsoft Azure, Rackspace) to deliver the Services, Contractor will provide Banner with
or access to an independent security certification (e.g., SOC 2 or SOC 3) confirming the third-party
hosted data center meets or exceeds industry-recognized data center security and availability standards.

3.4. Security Questionnaire, Upon Banner’s request to confirm compliance with this

Page 11 of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope ID: E6355837-010D-48EF-A8A5-625EC09B4831

Addendum, Applicable Laws, and Standards, Contractor will promptly cooperate and accurately complete
a written information security questionnaire provided by Banner or its designated representative regarding
Contractor’s business practices and information technology environment relating to the Services provided
hereunder.

4. AMENDMENT. Banner may modify the terms and conditions of this Addendum at any time
and will use reasonable efforls to provide notice if Contractor has provided a current contact and email
address, The latest version of the Addendum will be posted on Banner’s website.

5. TERMINATION, The following will be considered a material breach giving risc to Banner’s
right to terminate the Agreement for cause, without penalty: (a) a successful Incident, or (b) Contractor’s
failure fo comply with the material obligations set forth in this Addendum.

6. CONFLICT. In the event of a conflict between the terms of this Addendum and the terms of the
Agreement, the order of precedence will be: this Addendum and then the Agreement. If the conflict
relates to Personal Information subject to HIPAA and the parties have entered into a Business Associate
Agreement (“BAA”), the order of precedence will be: (1) the BAA, (2) this Addendum, and (3) the
Agreement.

7. NOTICE, Notification of an Incident will be made promptly (and no later than three business
days after discovery) by email to privacy@bannerhealth.com and by courier service with one copy each
to Banner’s Chief Privacy Officer, Chief Information Security Officer, and General Counsel at 2901 N.
Central Avenue, Suite 160, Phoenix, AZ 85012,

8 DEFINITIONS. All capitalized terms used in this Addendum but not defined herein will have the
same meaning ascribed to such terms in the Agreement as supplemented by this Addendum.

8.1. “Access” or “Accessing” means any access to the: (a) Banner Content, (b) the Banner
Systems that Process Banner Content, or (c) Banner facilities where Banner Content is Processed.

8.2, “Applicable Law” means all federal and state security, confidentiality, and/or privacy
and data protection laws, including the Health Insurance Portability and Accountability Act of 1996, the
Health Information Technology for Economic and Clinical Health Act, and regulations promulgated
thereunder (“HIPAA”), and other applicable standards, guidelines, policies, regulations and procedures,
as the same may be amended or supplemented from time to time, that are applicable to Contractor, the
Services, and/or any other programs or products provided pursuant to the Agreement.

8.3, “Banner Consumer” means Banner patients and/or customers.

8.4. “Banner Content” means any Personal Information and other Banner confidential
information (whether in electronic or non-electronic form) in the care, custody, or control of Contractor or
a third party on Contractor’s behalf that was (a) provided fo Contractor in connection with the Services, or
(b) Processed in the course of Contractor’s performance of the Services.

Page 12 of 13
0101-03-182637/Maricopa DPH Data Access Agreement

DocuSign Envelope iD: E6355837-010D-48EF-A8A5-625EC09B4831

8.5. “Banner Systems” means any computer, computer network, computer application,
storage device, mobile computing device, or sofiware owned or leased by Banner or operated by a third
party (excluding Contractor) on Banner’s behalf,

8.6. “Contractor Systems” means any computer, computer network, computer application,
storage device, mobile computing device, or software owned, leased, or controlled by Contractor or
operated by a third party on behalf of Contractor.

8.7, “Tneident” means any actual or reasonably suspected unauthorized Access to or
acquisition, alteration, destruction, disclosure, interception, loss, transmission, or use of Banner Content,
the Banner Systems, or Banner’s confidential information, or delivery of Malware from Contractor to
Banner, An Incident does not include minor incidents that regularly occur, such as third-party scans,
pings, or unsuccessful attempts (o penetrate computer networks or servers maintained by Contractor.

8.8. “Personal Information” means any information relating to an identified or identifiable
individual (including, but not limited to, name, postal or email address, telephone number, Social Security
nuinber, driver’s license number, date of birth, demographic information, health or medical information
(including Protected Health Information as defined under HIPAA), and financial account information), in
whatever format, incliding that contained in communications, documents, databases, records or materials
of any kind whether in individual or aggregate form, and regardless of the media in which it is contained,
that may be: (a) disclosed at any time to Contractor or Contractor personnel by Banner or Banner
Personnel in anticipation of, in connection with or incidental to the performance of the Services for or on
behalf of Banner; (b) Processed at any time by Contractor or Contractor personnel in connection with or
incidental to the performance of this Addendum or the Agreement; or (c) derived by Contractor or
Contractor personnel from the information described in (a) or (b) above.

8.9, “Process,” “Processed,” or “Processing” means any operation or set of operations
performed upon Banner Content, whether or not by automatic means, such as Accessing, adapting,
altering, collecting, consulting, creating, disclosing, destroying, maintaining, obtaining, organizing,
procuring, receiving, recording, retrieving, storing, transmitting, transferring, or using the data.

8.10. “Reports” means a description of the Contractor Systems used to deliver the Services,
including the contro! objectives and related controls applicable to such systems, and an executed copy of
one or more opinions or attestations from independent auditors compensated by Contractor that opines on
the design and operating effectiveness of information security controls and Contractor’s information
security program (i.e, SOC 2 Type I, PCI DSS AOC reports (if applicable), etc.).

8.11. “Standard(s)” means generally-accepted, industry good practice information security
requirements relevant to Contractor’s industry and Services.

Page 13 of 13
0101-03-182637/Maricopa DPH Data Access Agreement