Town CrierWest Orange, New Jersey
← Back to search

Supporting Documentation · Jan 6, 2015

24-15 emsCharts Agreement.pdf

Preserved file SHA-256ba25f776dcc84c7d29203870879448b6ef0a92a8009236c1726aa848134dba0a

Indexed text · page 16

Show all pages
Page 16

vii. Protected Health Information. "Protected Health Information" shall have the same meaning as the term "protected health information" in 45 CFR 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity. viii. Required By Law. "Required by Law" shall have the same meaning as the term "required by law" in 45 CFR 164.103. ix. Secretary, "Secretary" shall mean the Secretary of the Department of Health and Human Services or his designee. x. Security Rule. "Security Rule" shali mean the Security Standards at 45 CFR part 160 and part 164. xi Services Agreement. "Services Agreement" shail mean any present or future agreements, either written or oral, between Covered Entity and Business Associate under which Business Associate provides services to Covered Entity which involve the use or disclosure of Protected Health Information, The Services Agreement is amended by and incorporates the terms of this Addendum. xii, Unsecured Protected Health Information, "Unsecured Protected Health Information" shall have the same meaning as the term "unsecured protected health information" in the HITECH Act, Section 13402(h)(1). 2. Obligations and Activities of Business Associate. a. Use and Disclosure. Business Associate agrees to not use or disclose Protected Health Information other than as permitted or required by the Services Agreement, this Addendum or as Required By Law. Business Associate shall comply with the provisions of this Addendum relating to privacy and security of Protected Health Information and all present and future provisions of HIPAA, the HITECH Act and HIPAA Regulations that relate to the privacy and security of Protected Health Information and that are applicable to Covered Entity and/or Business Associate. b Appropriate Safeguards. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of the Protected Health Information other than as provided for by the Services Agreement. Without limiting the generality of the foregoing, Business Associate will: i Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of Electronic Protected Health Information as required by the Security Rule; ii. Ensure that any agent, including a subcontractor, to whom Business Associate

Page 16

fidentiality, integrity, and availability of Electronic Protected Health Information as required by the Security Rule; ii. Ensure that any agent, including a subcontractor, to whom Business Associate provides Electronic Protected Health Information agrees to implement reasonable and appropriate safeguards to protect Electronic Protected Health Information; iti. Promptly report to Covered Entity any Security Incident of which Business Associate becomes aware. In addition, Business Associate agrees to promptly notify Covered Entity following the discovery of a Breach of Unsecured Protected Health Information. A Breach is considered "discovered" as of the first day on which the Breach is known, or reasonably should have been known, to Business Associate or any employee, officer or agent of Business Associate, other than the individual committing the Breach. Any notice of a Security Incident or Breach of Unsecured Protected Health Information shall include the identification of each Individual whose Protected Health Information has been, or is reasonably believed by Business Associate to have been, accessed, acquired, or disclosed during such Security Incident or Breach as well as any other relevant information regarding the Security Incident or Breach. emsCharts Service Agreement, v12.3 Page 15 of 19

File revisions (1)