Town CrierWest Orange, New Jersey
← Back to search

Supporting Documentation · Jan 6, 2015

36-15 Resolution authorizing Execution of BSA with ImageTrend and Attachment.pdf

Preserved file SHA-25639178d580988e8c1209d849168f3cf7006c6e58cd5eb10fc1cad543f4bf3a8ad

Indexed text

Page 1

RESOLUTION WHEREAS, the Township of West Orange (the “Township”), through the Township's Fire Department, provides emergency ambulance transport services to residents and visitors of the Township; and WHEREAS, provision of the foregoing services entails substantial annual cost, the cost of which can be offset by charging medical insurance companies a user fee for ambulance transport services; and WHEREAS, following competitive bidding, by adoption of Resolution 160-13 on August 20, 2013, the Township authorized the award of a third-party billing contract to Revenue Guard, a New Jersey corporation with a principal business address of 50 U.S. Highway 9, Morganville, New Jersey, 07751 (“RevGuard”); and WHEREAS, pursuant to the Township's agreement with RevGuard, RevGuard is responsible for all costs related to software utilized in connection with the third-party billing services provided to the Township by RevGuard; and WHEREAS, it is anticipated that in the coming year, the Township will begin to utilize software owned by ImageTrend, Inc. (“ImageTrend”) in connection with the third-party billing services provided to the Township by RevGuard; and WHEREAS, ImageTrend has requested that the Township execute a Business Associate Agreement (“BSA”), which shall govern the transmission of health information protected by state and/or federal law, in the form annexed hereto as Attachment “A”; and NOW, BE IT HEREBY RESOLVED BY THE TOWNSHIP COUNCIL OF THE TOWNSHIP OF WEST ORANGE, that the Township shall and hereby does authorize execution of the BSA, to be executed in the form annexed hereto as Attachment “A”; and be it further RESOLVED, that the Mayor be and is hereby authorized to execute all documents necessary to effectuate such agreement between the Township and ImageTrend, and the

Page 2

Municipai Clerk shall be and is hereby authorized to attest to the Mayor’s signature; and be it further RESOLVED, that this Resolution shall be published and made available in the Clerk’s Office for reasonable inspection in accordance with applicable law. Karen Carnevale Honorable Jerry Guarino Township Clerk Council President Dated: Adopted:

Page 3

ATTACHMENT “A”

Page 4

BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (“Agreement”) is effective upon execution of the Agreement between Client's authorized user </nsert Service or Agency Name> Address. City, State Zip referred to as the (“Covered Entity’) and State of New Jersey, Department of the Treasury, Division of Purchase and Property at 33 West State Street, 8 Floor, PO Box 230, Trenton, New Jersey 08625 referred to as the (“Client”) who has established a Business Associate Agreement (‘Agreement’) with ImageTrend, Inc., a Minnesota corporation and Client's Vendor located at 20855 Kensington Blvd., Lakeville, MN 55044, ("ImageTrenc”) or the (“Business Associate”). WHEREAS, Covered Entity and Business Associate have entered into, or are entering into, or may subsequently enter into, agreements or other documented arrangements (collectively, the “Business. Arrangements”) pursuant to which Business Associate may provide products and/or services for Covered Entity that require Business Associate to access, create and use health information that is protected by state and/or federal law; and WHEREAS, pursuant to the Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the U.S, Department of Health & Human Services (“HHS”) promulgated the Standards for Privacy of Individually Identifiable Health Information (the “Privacy Standards’), at 45 C.F.R. Parts 160 and 164, requiring certain individuals and entities subject to the Privacy Standards (each a “Covered Entity”, or collectively, “Covered Entities”) to protect the privacy of certain individually identifiable health information (“Protected Health Information’, or PHI"); and WHEREAS, pursuant to HIPAA, HHS has issued the Security Standards (the “Security Standards’), at 45 C.F.R. Parts 160, 162 and 164, for the protection of electronic protected health information (“EPHI"); and WHEREAS, in order to protect the privacy and security of PHI, including EPHI, created or maintained by or on behaif of the Covered Entity, the Privacy Standards and Security Standards require a Covered Entity to enter into a “business associate agreement” with certain individuals and entities providing services for or on behalf of the Covered Entity if such services require the use or disclosure of PHI or EPHI; and WHEREAS, on February 17, 2009, the federal Health

Page 4

individuals and entities providing services for or on behalf of the Covered Entity if such services require the use or disclosure of PHI or EPHI; and WHEREAS, on February 17, 2009, the federal Health Information Technology for Economic and Clinical Health Act was signed into law (the "HITECH Act’), and the HITECH Act imposes certain privacy and security obligations on Covered Entities in addition to the obligations created by the Privacy Standards and Security Standards; and WHEREAS, the HITECH Act revises many of the requirements of the Privacy Standards and Security Standards concerning the confidentiality of PHI and EPHI, including extending certain HIPAA and HITECH Act requirements directly to business associates; and WHEREAS, Business Associate and Covered Entity desire to enter into this Business Associate Agreement; NOW THEREFORE, in consideration of the mutual promises set forth in this Agreement and the Business Arrangements, and other good and valuable consideration, the sufficiency and receipt of which are hereby severally acknowledged, the parties agree as follows: 1. Business Associate Obligations. Business Associate may receive from Covered Entity, or create or receive on behalf of Covered Entity, health information that is protected under applicable state and/or federal law, including without limitation, PHI and EPHI. All capitalized terms not otherwise Covered Entity Version (10/23/2009) Page 1 of 8

Page 5

defined in this Agreement shall have the meanings set forth in the Privacy Standards, Security Standards or the HITECH Act, as applicable (collectively referred to hereinafter as the “Confidentiality Requirements’). All references to PHI herein shall be construed to include EPHI. Business Associate agrees not to use or disclose (or permit the use or disclosure of) PHI in a manner that would violate the Confidentiality Requirements if the PHi were used or disclosed by Covered Entity in the same manner. Use of PHI. Except as otherwise required by law, Business Associate shail use PH! in compliance with 45 C.F.R. § 164.504(e). Furthermore, Business Associate shall use PHI (i) solely for Covered Entity’s benefit and only for the purpose of performing services for Covered Entity as such services are defined in Business Arrangements, and (ii} as necessary for the proper management and administration of the Business Associate or to carry out its legal responsibilities, provided that such uses are permitted under federal and state law. Covered Entity shall retain all rights in the PHI not granted herein. Use, creation and disclosure of de-identified health information by Business Associate are not permitted unless expressly authorized in writing by Covered Entity. Disciosure of PHI. Subject to any limitations in this Agreement, Business Associate may disclose PHI to any third party persons or entities as necessary to perform its obligations under the Business Arrangement and as permitted or required by applicable federal or state law. Further, Business Associate may disclose PHI for the proper management and administration of the Business Associate, provided that (i) such disclosures are required by law, or (ii) Business Associate: (a) obtains reasonable assurances from any third party to whom the information is disclosed that it will be held confidential and further used and disclosed only as required by law or for the purpose for which it was disclosed to the third party; (b) requires the third party to agree to immediately notify Business Associate of any instances of which it is aware that PHI is being used or disclosed for a purpose that is not otherwise provided for in this Agreement or for a purpose not expressly permitted by the Confidentiality Requirements. Additionally, Business Associate shall ensure that all disclosures of PHI by Business Associate and

Page 5

for in this Agreement or for a purpose not expressly permitted by the Confidentiality Requirements. Additionally, Business Associate shall ensure that all disclosures of PHI by Business Associate and the third party comply with the principle of “minimum necessary use and disclosure,” i.e., only the minimum PHI that is necessary to accomplish the intended purpose may be disclosed; provided further, Business Associate shall comply with Section 13405(b) of the HITECH Act, and any regulations or guidance issued by HHS concerning such provision, regarding the minimum necessary standard and the use and disclosure (if applicable) of Limited Data Sets. If Business Associate discloses PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity, to agents, including a subcontractor (collectively, “Recipients”), Business Associate shall require Recipients to agree in writing to the same restrictions and conditions that apply to the Business Associate under this Agreement. Business Associate shall report to Covered Entity any use or disclosure of PHI not permitted by this Agreement, of which it becomes aware, such report to be made within three (3) business days of the Business Associate becoming aware of such use or disclosure. In addition to Business Associate's obligations under Section 9, Business Associate agrees to mitigate, to the extent practical and unless otherwise requested by Covered Entity in writing or as directed by or as a result of a request by Covered Entity to disclose to Recipients, any harmful effect that is known to Business Associate and is the result of a use or disclosure of PHI by Business Associate or Recipients in violation of this Agreement. Individual Rights Regarding Designated Record Sets. If Business Associate maintains a Designated Record Set on behalf of Covered Entity, Business Associate shall (i) provide access to, and permit inspection and copying of, PHI by Covered Entity or, as directed by Covered Entity, an individual who is the subject of the PHI under conditions and limitations required under 45 CFR §164.524, as it may be amended from time to time, and (ii) amend PHI maintained by Business Associate as requested by Covered Entity. Business Associate shall respond to any request from Covered Entity for access by an individual within five (5) days of such request and shall make

Page 5

y Business Associate as requested by Covered Entity. Business Associate shall respond to any request from Covered Entity for access by an individual within five (5) days of such request and shall make any amendment requested by Covered Entity within ten (10) days of such request. Any information requested under this Section 4 shail be provided in the form or format requested, if it is readily producible in such form or format. Business Associate may charge a reasonable fee based upon the Business Associate's labor costs in responding to a request for electronic information (or a cost- based fee for the production of non-electronic media copies). Covered Entity shall determine whether Covered Entity Version (10/23/2009) Page 2 of 8

Page 6

a deniai is appropriate or an exception applies. Business Associate shall notify Covered Entity within five (5) days of receipt of any request for access or amendment by an individual. Covered Entity shall determine whether to grant or deny any access or amendment requested by the individual. Business Associate shall have a process in place for requests for amendments and for appending such requests to the Designated Record Set, as requested by Covered Entity. Accounting of Disclosures. Business Associate shall make available to Covered Entity in response to a request from an individual, information required for an accounting of disclosures of PHI with respect to the individual in accordance with 45 CFR §164.528, as amended by Section 13408(c) of the HITECH Act and any related regulations or guidance issued by HHS in accordance with such provision. Business Associate shall provide to Covered Entity such information necessary to provide an accounting within thirty (30) days of Covered Entity’s request or such shorter time as may be required by state or federal law. Such accounting must be provided without cost to the individual or to Covered Entity if it is the first accounting requested by an individual within any twelve (12) month period. For subsequent accountings within a twelve (12) month period, Business Associate may charge a reasonable fee based upon the Business Associate's labor costs in responding to a request for electronic information (or a cost-based fee for the production of non-electronic media copies) so long as Business Associate informs the Covered Entity and the Covered Entity informs the individual in advance of the fee, and the individual is afforded an opportunity to withdraw or modify the request. Such accounting obligations shal! survive termination of this Agreement and shall continue as long as Business Associate maintains PHI. ithdrawal of Authorization. If the use or disclosure of PHI in this Agreement is based upon an individual’s specific authorization for the use of his or her PHI, and (i) the individual revokes such authorization in writing, (ji) the effective date of such authorization has expired, or (iii) the consent or authorization is found to be defective in any manner that renders it invalid, Business Associate agrees, if it has notice of such revocation or invalidity, to cease the use and disclosure of any

Page 6

nt or authorization is found to be defective in any manner that renders it invalid, Business Associate agrees, if it has notice of such revocation or invalidity, to cease the use and disclosure of any such individual's PHI except to the extent it has relied on such use or disclosure, or where an exception under the Confidentiality Requirements expressly applies. Records and Audit. Business Associate shail make available to the U.S. Department of Health and Human Services or its agents, its internal practices, books, and records relating to the use and disclosure of PHI received from, created, or received by Business Associate on behalf of Covered Entity for the purpose of determining Covered Entity’s compliance with the Confidentiality Requirements or any other heaith oversight agency, in a time and manner designated by the Secretary. Except to the extent prohibited by law, Business Associate agrees to notify Covered Entity immediately upon receipt by Business Associate of any and all requests by or on behaif of any and all federal, state and local government authorities served upon Business Associate for PHI. Implementation of Security Standards: Notice of Security Incidents. Business Associate will use appropriate safeguards to prevent the use or disclosure of PHI other than as expressly permitted under this Agreement. Business Associate will implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of the PHI that it creates, receives, maintains or transmits on behalf of Covered Entity. Business Associate acknowledges that the HITECH Act requires Business Associate to comply with 45 C.F.R. §§ 164.308, 164.310, 164.312 and 164.316 as if Business Associate were a Covered Entity, and Business Associate agrees to comply with these provisions of the Security Standards and ali additiona! security provisions of the HITECH Act. Furthermore, to the extent feasible, Business Associate will use commercially reasonable efforts to ensure that the technology safeguards used by Business Associate to secure PHI will render such PHI unusable, unreadable and indecipherable to individuais unauthorized to acquire or otherwise have access to such PHI in accordance with HHS Guidance published at 74 Federal Register 19006 (April 17, 2009}, or such later reguiations or guidance

File revisions (1)