Supporting Documentation · Jan 6, 2015
36-15 Resolution authorizing Execution of BSA with ImageTrend and Attachment.pdf
39178d580988e8c1209d849168f3cf7006c6e58cd5eb10fc1cad543f4bf3a8adIndexed text · page 6
Show all pagesa deniai is appropriate or an exception applies. Business Associate shall notify Covered Entity within five (5) days of receipt of any request for access or amendment by an individual. Covered Entity shall determine whether to grant or deny any access or amendment requested by the individual. Business Associate shall have a process in place for requests for amendments and for appending such requests to the Designated Record Set, as requested by Covered Entity. Accounting of Disclosures. Business Associate shall make available to Covered Entity in response to a request from an individual, information required for an accounting of disclosures of PHI with respect to the individual in accordance with 45 CFR §164.528, as amended by Section 13408(c) of the HITECH Act and any related regulations or guidance issued by HHS in accordance with such provision. Business Associate shall provide to Covered Entity such information necessary to provide an accounting within thirty (30) days of Covered Entity’s request or such shorter time as may be required by state or federal law. Such accounting must be provided without cost to the individual or to Covered Entity if it is the first accounting requested by an individual within any twelve (12) month period. For subsequent accountings within a twelve (12) month period, Business Associate may charge a reasonable fee based upon the Business Associate's labor costs in responding to a request for electronic information (or a cost-based fee for the production of non-electronic media copies) so long as Business Associate informs the Covered Entity and the Covered Entity informs the individual in advance of the fee, and the individual is afforded an opportunity to withdraw or modify the request. Such accounting obligations shal! survive termination of this Agreement and shall continue as long as Business Associate maintains PHI. ithdrawal of Authorization. If the use or disclosure of PHI in this Agreement is based upon an individual’s specific authorization for the use of his or her PHI, and (i) the individual revokes such authorization in writing, (ji) the effective date of such authorization has expired, or (iii) the consent or authorization is found to be defective in any manner that renders it invalid, Business Associate agrees, if it has notice of such revocation or invalidity, to cease the use and disclosure of any
nt or authorization is found to be defective in any manner that renders it invalid, Business Associate agrees, if it has notice of such revocation or invalidity, to cease the use and disclosure of any such individual's PHI except to the extent it has relied on such use or disclosure, or where an exception under the Confidentiality Requirements expressly applies. Records and Audit. Business Associate shail make available to the U.S. Department of Health and Human Services or its agents, its internal practices, books, and records relating to the use and disclosure of PHI received from, created, or received by Business Associate on behalf of Covered Entity for the purpose of determining Covered Entity’s compliance with the Confidentiality Requirements or any other heaith oversight agency, in a time and manner designated by the Secretary. Except to the extent prohibited by law, Business Associate agrees to notify Covered Entity immediately upon receipt by Business Associate of any and all requests by or on behaif of any and all federal, state and local government authorities served upon Business Associate for PHI. Implementation of Security Standards: Notice of Security Incidents. Business Associate will use appropriate safeguards to prevent the use or disclosure of PHI other than as expressly permitted under this Agreement. Business Associate will implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of the PHI that it creates, receives, maintains or transmits on behalf of Covered Entity. Business Associate acknowledges that the HITECH Act requires Business Associate to comply with 45 C.F.R. §§ 164.308, 164.310, 164.312 and 164.316 as if Business Associate were a Covered Entity, and Business Associate agrees to comply with these provisions of the Security Standards and ali additiona! security provisions of the HITECH Act. Furthermore, to the extent feasible, Business Associate will use commercially reasonable efforts to ensure that the technology safeguards used by Business Associate to secure PHI will render such PHI unusable, unreadable and indecipherable to individuais unauthorized to acquire or otherwise have access to such PHI in accordance with HHS Guidance published at 74 Federal Register 19006 (April 17, 2009}, or such later reguiations or guidance
individuais unauthorized to acquire or otherwise have access to such PHI in accordance with HHS Guidance published at 74 Federal Register 19006 (April 17, 2009}, or such later reguiations or guidance promulgated by HHS or issued by the National Institute for Standards and Technology (‘NIST’) concerning the protection of identifiable data such as PHI. Lastly, Business Associate will promptly report to Covered Entity any successful Security Incident of which it becomes aware. At the request of Covered Entity, Business Associate shall identify: the date of the Security incident, the Covered Entity Version (10/23/2009) Page 3 of 8
File revisions (1)
- Sep 29, 2026
39178d580988506,763 bytes