Business Associate Agreement
Version v1
1. Parties and purpose
This Business Associate Agreement ("Agreement") is entered into between the practice identified in the accompanying application ("Covered Entity") and PreferNP ("Business Associate").
Covered Entity is a health care provider and a covered entity as defined at 45 CFR §160.103. Business Associate provides the practice platform, clinical record, scheduling, telehealth, billing, and related services through which Covered Entity creates, receives, maintains, and transmits Protected Health Information.
This Agreement sets out the terms on which Business Associate may handle that information, as required by the HIPAA Privacy, Security, and Breach Notification Rules at 45 CFR Parts 160 and 164. It takes effect when Covered Entity signs it and remains in force for as long as Business Associate holds any Protected Health Information of Covered Entity.
2. Definitions
Terms used but not otherwise defined in this Agreement have the meaning given to them in 45 CFR Parts 160 and 164.
"Protected Health Information" ("PHI") means individually identifiable health information, as defined at 45 CFR §160.103, that Business Associate creates, receives, maintains, or transmits on behalf of Covered Entity. "Electronic Protected Health Information" ("ePHI") means PHI held or transmitted in electronic form.
"Breach", "Disclosure", "Individual", "Required by Law", "Secretary", "Security Incident", "Subcontractor", "Unsecured Protected Health Information", and "Use" have the meanings given in 45 CFR Parts 160 and 164.
3. Permitted uses and disclosures
Business Associate may use and disclose PHI only as necessary to perform the services it provides to Covered Entity, as permitted or required by this Agreement, or as Required by Law.
Business Associate may use PHI for its own proper management and administration, and to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only where the disclosure is Required by Law, or where Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.
Business Associate may de-identify PHI in accordance with 45 CFR §164.514(a)-(c), and may use and disclose the resulting de-identified information, which is not PHI.
Business Associate will not use or disclose PHI in any manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted for its own management and administration above. Business Associate will not sell PHI, and will not use or disclose PHI for marketing or fundraising, except as expressly permitted by this Agreement and by law.
Business Associate will limit its uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 CFR §164.502(b) and §164.514(d).
4. Safeguards
Business Associate will use appropriate safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement.
With respect to ePHI, Business Associate will comply with Subpart C of 45 CFR Part 164 — the HIPAA Security Rule — and will implement the administrative, physical, and technical safeguards it requires, including encryption of ePHI in transit and at rest, access controls limiting access to those with a need for it, and audit controls recording access to clinical records.
Business Associate will document its safeguards and will make that documentation available to Covered Entity on reasonable request.
5. Subcontractors
In accordance with 45 CFR §164.502(e)(1)(ii) and §164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement.
Business Associate remains responsible to Covered Entity for the performance of its Subcontractors with respect to PHI, and will maintain a current register of Subcontractors with access to PHI, available to Covered Entity on request.
6. Reporting of breaches, security incidents, and improper use
Business Associate will report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware, including any Breach of Unsecured Protected Health Information as required by 45 CFR §164.410, and any Security Incident of which it becomes aware.
Business Associate will make that report without unreasonable delay and in no case later than thirty (30) calendar days after discovery. A Breach is treated as discovered on the first day it is known to Business Associate, or by exercising reasonable diligence would have been known.
The report will identify, to the extent known at the time and supplemented as further information becomes available: the nature of the incident; the Individuals whose PHI was involved and the types of information concerned; what Business Associate has done to investigate, mitigate, and prevent recurrence; and any other information Covered Entity reasonably requires to meet its own notification obligations under 45 CFR §164.404 through §164.408.
Unsuccessful Security Incidents that result in no unauthorized access to, or use, disclosure, modification, or destruction of, PHI — such as routinely blocked network scans, failed log-in attempts, and denied connection requests — are reported to Covered Entity in aggregate on request, rather than individually.
Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement.
7. Individual rights
Business Associate will make PHI held in a Designated Record Set available to Covered Entity, or at Covered Entity’s direction to the Individual, as necessary for Covered Entity to meet its obligations under 45 CFR §164.524, within fifteen (15) calendar days of a request.
Business Associate will make amendments to PHI in a Designated Record Set as directed or agreed by Covered Entity in accordance with 45 CFR §164.526, within fifteen (15) calendar days of a request.
Business Associate will maintain and make available the information required to provide an accounting of disclosures in accordance with 45 CFR §164.528, within fifteen (15) calendar days of a request.
To the extent Business Associate carries out any obligation of Covered Entity under Subpart E of 45 CFR Part 164, it will comply with the requirements of that Subpart that apply to Covered Entity in performing that obligation.
If an Individual makes a request under §164.524, §164.526, or §164.528 directly to Business Associate, Business Associate will forward it to Covered Entity within five (5) business days and will not respond to it directly except at Covered Entity’s direction.
8. Access by the Secretary
Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Covered Entity available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity’s compliance with Subpart E of 45 CFR Part 164.
Business Associate will notify Covered Entity of any such request, unless prohibited from doing so by law.
9. Obligations of Covered Entity
Covered Entity will notify Business Associate of any limitation in its notice of privacy practices, of any change to or revocation of an Individual’s permission to use or disclose PHI, and of any restriction on use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR §164.522, to the extent any of these affects Business Associate’s use or disclosure of PHI.
Covered Entity will not ask Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted under Section 3 of this Agreement for Business Associate’s own management and administration.
Covered Entity is responsible for the accuracy of the clinical information it records, for the clinical decisions it makes, and for the professional licensure and conduct of the clinicians who practise under it.
10. Term and termination
This Agreement takes effect on the date Covered Entity signs it, and terminates when all PHI held by Business Associate has been returned or destroyed in accordance with this Section, or when the parties agree in writing.
If Covered Entity becomes aware of a material breach of this Agreement by Business Associate, Covered Entity may provide an opportunity to cure within thirty (30) calendar days, and may terminate this Agreement and the underlying services if the breach is not cured within that period or if cure is not practicable.
On termination, Business Associate will return or destroy all PHI it holds on behalf of Covered Entity, and will require the same of its Subcontractors. Covered Entity may export its complete record before or at termination, in a machine-readable format.
Where return or destruction is not feasible — including where retention is Required by Law — Business Associate will extend the protections of this Agreement to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it is retained.
Business Associate retains the executed copy of this Agreement, and the record of its signature, for a minimum of six (6) years as required by 45 CFR §164.530(j). That obligation survives termination.
11. General
The parties will take such action to amend this Agreement as is necessary for Covered Entity to comply with the requirements of HIPAA, the HITECH Act, and their implementing regulations as they are amended from time to time.
Any ambiguity in this Agreement will be resolved in favour of a meaning that permits Covered Entity and Business Associate to comply with those requirements.
Nothing in this Agreement is intended to confer, nor may be construed as conferring, any rights or remedies on any person other than Covered Entity, Business Associate, and their respective successors and assigns.
Section headings are for convenience and do not affect interpretation. If any provision of this Agreement is held unenforceable, the remainder continues in force.
12. Signature
Covered Entity signs this Agreement by typing its authorized signatory’s full legal name and affirming agreement. Under the E-SIGN Act, 15 U.S.C. §7001, that act constitutes a legally binding electronic signature with the same effect as a handwritten one.
The name entered, the version of this Agreement shown, and the date and time of signing are recorded together as the executed record.