Town CrierWest Orange, New Jersey
← Back to search

Supporting Documentation · Jan 6, 2015

36-15 Resolution authorizing Execution of BSA with ImageTrend and Attachment.pdf

Preserved file SHA-25639178d580988e8c1209d849168f3cf7006c6e58cd5eb10fc1cad543f4bf3a8ad

Indexed text

Page 6

individuais unauthorized to acquire or otherwise have access to such PHI in accordance with HHS Guidance published at 74 Federal Register 19006 (April 17, 2009}, or such later reguiations or guidance promulgated by HHS or issued by the National Institute for Standards and Technology (‘NIST’) concerning the protection of identifiable data such as PHI. Lastly, Business Associate will promptly report to Covered Entity any successful Security Incident of which it becomes aware. At the request of Covered Entity, Business Associate shall identify: the date of the Security incident, the Covered Entity Version (10/23/2009) Page 3 of 8

Page 7

9. scope of the Security Incident, the Business Associate's response to the Security Incident and the identification of the party responsible for causing the Security Incident, if known. Business Associate and Covered Entity shall take reasonable measures to ensure the availability of all affirmative defenses under the HITECH Act, HIPAA, and other state and federal laws and regulations governing PHI and EPHI. Data Breach Notification and Mitigation. a. HIPAA Data Breach Notification and Mitigation. Business Associate agrees to implement reasonable systems for the discovery and prompt reporting of any “breach” of “unsecured PHI’ as those terms are defined by 45 C.F.R. §164.402 (hereinafter a “HIPAA Breach”). The parties acknowledge and agree that 45 C.F.R. §164.404, as described below in this Section 9.1, governs the determination of the date of a HIPAA Breach. In the event of any conflict between this Section 9.1 and the Confidentiality Requirements, the more stringent requirements shall govern. Business Associate will, following the discovery of a HIPAA Breach, notify Covered Entity immediately and in no event later than three (3) business days after Business Associate discovers such HIPAA Breach, unless Business Associate is prevented from doing so by 45 C.F.R. §164.412 concerning law enforcement investigations. For purposes of reporting a HIPAA Breach to Covered Entity, the discovery of a HIPAA Breach shall occur as of the first day on which such HIPAA Breach is known to the Business Associate or, by exercising reasonable diligence, would have been known to the Business Associate. Business Associate will be considered to have had knowledge of a HIPAA Breach if the HIPAA Breach is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing the HIPAA Breach) who is an employee, officer or other agent of the Business Associate. No later than seven (7) business days following a HIPAA Breach, Business Associate shall provide Covered Entity with sufficient information to permit Covered Entity to comply with the HIPAA Breach notification requirements set forth at 45 C.F.R. §164.400 ef seq. Specifically, if the following information is known to (or can be reasonably obtained by) the Business Associate, Business Associate will provide Covered Entity with: (i) contact information for individuals who were or

Page 7

he following information is known to (or can be reasonably obtained by) the Business Associate, Business Associate will provide Covered Entity with: (i) contact information for individuals who were or who may have been impacted by the HIPAA Breach (e.g., first and last name, mailing address, street address, phone number, email address); (ii) a brief description of the circumstances of the HIPAA Breach, including the date of the HIPAA Breach and date of discovery; (ili) a description of the types of unsecured PHI involved in the HIPAA Breach (e.g., names, social security number, date of birth, address(es), account numbers of any type, disability codes. diagnostic and/or billing codes and similar information); (iv) a brief description of what the Business Associate has done or is doing to investigate the HIPAA Breach, mitigate harm to the individual impacted by the HIPAA Breach, and protect against future HIPAA Breaches: and (v) appoint a liaison and provide contact information for same so that the Covered Entity may ask questions or learn additional information conceming the HIPAA Breach. Following a HIPAA Breach, Business Associate will have a continuing duty to inform Covered Entity of new information learned by Business Associate regarding the HIPAA Breach, including but not limited to the information described in items (i) through (v), above. b. Data Breach Notification and Mitigation Under Other Laws. In addition to the requirements of Section 9.1, Business Associate agrees to implement reasonable systems for the discovery and prompt reporting of any breach of individually identifiable information (including but not limited to PHI, and referred to hereinafter as “Individually identifiable Information”) that, if misused, disclosed, lost or stolen, Covered Entity believes would trigger an obligation under one or more State data breach notification laws (each a “State Breach’) to notify the individuals who are the subject of the information. Business Associate agrees that in the event any Individuaily Identifiable Information is lost, stolen, used or disclosed in violation of one or more State data breach notification laws, Business Associate shail promptly: (i) cooperate and assist Covered Entity with any investigation into any State Breach or alleged State Breach; (ii) cooperate and assist Covered Entity with any investigation into any State Breach or

Page 7

: (i) cooperate and assist Covered Entity with any investigation into any State Breach or alleged State Breach; (ii) cooperate and assist Covered Entity with any investigation into any State Breach or alleged State Breach conducted by any State Attorney Genera! or State Consumer Covered Entity Version (10/23/2009) Page 4 of 8

Page 8

Affairs Department (or their respective agents); (iii) comply with Covered Entity’s determinations regarding Covered Entity's and Business Associate's obligations to mitigate to the extent practicable any potential harm to the individuals impacted by the State Breach; and {iv) assist with the implementation of any decision by Covered Entity or any State agency, including any State Attorney General or State Consumer Affairs Department (or their respective agents), to notify individuals impacted or potentially impacted by a State Breach. c. Breach Indemnification. Business Associate shall indemnify, defend and hold Covered Entity and its officers, directors, employees, agents, successors and assigns harmiess, from and against all reasonable losses, claims, actions, demands, liabilities, damages, costs and expenses (including costs of judgments, settlements, court costs and reasonable attorneys’ fees actually incurred) (collectively, “Information Disclosure Claims”) arising from or related to: (}) the use or disclosure of Individually Identifiable Information (including PHI) by Business Associate in violation of the terms of this Agreement or applicable law, and (ii) whether in oral, paper or electronic media, any HIPAA Breach of unsecured PHI and/or State Breach of Individually Identifiable Information by Business Associate. if Business Associate assumes the defense of an Information Disclosure Claim, Covered Entity shall have the right, at its expense and without indemnification notwithstanding the previous sentence, to participate in the defense of such Information Disclosure Claim. Business Associate shall not take any final action with respect to any Information Disclosure Claim without the prior written consent of Covered Entity. Covered Entity likewise shall not take any final action with respect to any Information Disclosure Ciaim without the prior written consent of Business Associate. To the extent permitted by law and except when caused by an act of Covered Entity or resulting from a disclosure to a Recipient required or directed by Covered Entity to receive the information, Business Associate shail be fully liable to Covered Entity for any acts, failures or omissions of Recipients in furnishing the services as if they were the Business Associate’s own acts, failures or omissions. i, Covered Entity shail indemnify, defend and hold Business

Page 8

, failures or omissions of Recipients in furnishing the services as if they were the Business Associate’s own acts, failures or omissions. i, Covered Entity shail indemnify, defend and hold Business Associate and its officers, directors, employees, agents, successors and assigns harmless, from and against ail reasonable losses, claims, actions, demands, liabilities, damages, costs and expenses (including costs of judgments, settlements, court costs and reasonable attorneys’ fees actually incurred) (collectively, “Information Disclosure Claims”) arising from or related to: (i) the use or disclosure of Individually identifiable information (including PHI) by Covered Entity, its subcontractors, agents, or employees in violation of the terms of this Agreement or applicable law, and (ii) whether in oral, paper or electronic media, any HIPAA Breach of unsecured PHI and/or State Breach of Individually Identifiable Information by Covered Entity, its subcontractors, agents, or employees. ii. Covered Entity and Business Associate shall seek to keep costs or expenses that the other may be liable for under this Section 9, including information Disclosure Claims, to the minimum reasonably required to comply with the HITECH Act and HIPAA. Covered Entity and Business Associate shall timely raise all applicable affirmative defenses in the event a violation of this Agreement, or a use or disclosure of PHI or EPHI in violation of the terms of this Agreement or applicable law occurs. 10. Ter Termination. a. This Agreement shall commence on the Effective Date and shail remain in effect until terminated in accordance with the terms of this Section 10, provided, however, that termination shall not affect the respective obligations or rights of the parties arising under this Agreement prior to the effective date of termination, all of which shall continue in accordance with their terms. b. Covered Entity shall have the right to terminate this Agreement for any reason upon thirty (30) days written notice to Business Associate. Covered Entity Version (10/23/2009) Page 5 of 8

Page 9

¢. Covered Entity, at its sole discretion, may immediately terminate this Agreement and shall have no further obligations to Business Associate if any of the following events shall have occurred and be continuing: i. Business Associate fails to observe or perform any material covenant or obligation contained in this Agreement for ten (10) days after written notice thereof has been given to the Business Associate by Covered Entity; or ii. A violation by the Business Associate of any provision of the Confidentiality Requirements or other applicable federal or state privacy law relating to the obligations of the Business Associate under this Agreement. d. Termination of this Agreement for either of the two reasons set forth in Section 10.c above shall be cause for Covered Entity to immediately terminate for cause any Business Arrangement pursuant to which Business Associate is entitled to receive PHI from Covered Entity. e, Upon the termination of ail Business Arrangements, either Party may terminate this Agreement by providing written notice to the other Party. f. Upon termination of this Agreement for any reason, Business Associate agrees either to return to Covered Entity or to destroy all PHI received from Covered Entity or otherwise through the performance of services for Covered Entity, that is in the possession or control of Business Associate or its agents. In the case of PHI which is not feasible to “return or destroy,” Business Associate shall extend the protections of this Agreement to such PHI and jimit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI, Business Associate further agrees to comply with other applicable state or federal law, which may require a specific period of retention, redaction, or other treatment of such PHI. 11. No Warranty. PHI IS PROVIDED TO BUSINESS ASSOCIATE SOLELY ON AN “AS IS” BASIS, COVERED ENTITY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY, AND FITNESS FOR A PARTICULAR PURPOSE. 12. Ineligible Persons. Business Associate represents and warrants to Covered Entity that Business Associate (i) is not currently excluded, debarred, or otherwise ineligible to participate in any federal health care program as defined in 42 U.S.C.

Page 9

esents and warrants to Covered Entity that Business Associate (i) is not currently excluded, debarred, or otherwise ineligible to participate in any federal health care program as defined in 42 U.S.C. Section 1320a-7b(f) (‘the Federal Healthcare Programs’); (ji) has not been convicted of a criminal offense related to the provision of heaith care items or services and not yet been excluded, debarred, or otherwise declared ineligible to participate in the Federal Healthcare Programs, and (iii) is not under investigation or otherwise aware of any circumstances which may result in Business Associate being excluded from participation in the Federal Healthcare Programs. This shall be an ongoing representation and warranty during the term of this Agreement, and Business Associate shall immediately notify Covered Entity of any change in the status of the representations and warranty set forth in this section. Any breach of this section shall give Covered Entity the right to terminate this Agreement immediately for cause. 13. Miscellaneous. a, Notice. All notices, requests, demands and other communications required or permitted to be given or made under this Agreement shall be in writing, shall be effective upon receipt or attempted delivery, and shall be sent by (i) personal delivery; (ii) certified or registered United States mail, retum receipt requested; or (iii) overnight delivery service with proof of delivery. Notices shail be sent to the addresses below. Neither party shall refuse delivery of any notice hereunder. If to Covered Entity: Covered Entity Version (10/23/2009) Page 6 of &

Page 10

Compliance Office If to Business Associate: ImageTrend, Inc. Attn: Michael J. McBrady 20855 Kensington Blvd. Lakeville, MN 55044 14. Waiver. No provision of this Agreement or any breach thereof shal! be deemed waived unless such waiver is in writing and signed by the Party claimed to have waived such provision or breach, No waiver of a breach shail constitute a waiver of or excuse any different or subsequent breach. 15. Assignment. Neither Party may assign (whether by operation or law or otherwise) any of its rights or delegate or subcontract any of its obligations under this Agreement without the prior written consent of the other Party. Notwithstanding the foregoing, Covered Entity shall have the right to assign its tights and obligations hereunder to any entity that is an affiliate or successor of Covered Entity, without the prior approval of Business Associate. 16. Severability. Any provision of this Agreement that is determined to be invalid or unenforceable will be ineffective to the extent of such determination without invalidating the remaining provisions of this Agreement or affecting the validity or enforceability of such remaining provisions. 17. Entire Agreement. This Agreement constitutes the complete agreement between Business Associate and Covered Entity relating to the matters specified in this Agreement, and supersedes all prior representations or agreements, whether oral or written, with respect to such matters. In the event of any conflict between the terms of this Agreement and the terms of the Business Arrangements or any such later agreement(s), the terms of this Agreement shall control unless the terms of such Business Arrangements are more strict with respect to PHI and comply with the Confidentiality Requirements, or the parties specifically otherwise agree in writing. No oral modification or waiver of any of the provisions of this Agreement shall be binding on either Party; provided, however, that upon the enactment of any law, regulation, court decision or relevant government publication and/or interpretive guidance or policy that the Covered Entity believes in good faith will adversely impact the use or disclosure of PHI under this Agreement, Covered Entity may amend the Agreement to comply with such law, regulation, court decision or government publication, guidance or policy by delivering a written amendment to Business

Page 10

r this Agreement, Covered Entity may amend the Agreement to comply with such law, regulation, court decision or government publication, guidance or policy by delivering a written amendment to Business Associate which shall be effective thirty (30) days after receipt. No obligation on either Party to enter into any transaction is to be implied from the execution or delivery of this Agreement. This Agreement is for the benefit of, and shall be binding upon the parties, their affiliates and respective successors and assigns. No third party shall be considered a third-party beneficiary under this Agreement, nor shall any third party have any rights as a result of this Agreement. 18. Governing Law. This Agreement shall be governed by and interpreted in accordance with the laws of the state in which the Covered Entity is located, excluding its conflicts of iaws provisions. Jurisdiction and venue for any dispute relating to this Agreement shall exclusively rest with the state and federal courts in the county in which the Covered Entity is located. 19. Equitable Relief. The parties understand and acknowledge that any disclosure or misappropriation of any PHI in violation of this Agreement will cause the other irreparable harm, the amount of which may be difficult to ascertain, and therefore agrees that the injured party shall have the right to apply to Covered Entity Version (10/23/2009) Page 7 of 8

File revisions (1)