Legal

Business Associate Addendum

This Business Associate Addendum (“Addendum”) is entered into as of (DATE) by MEDSENDER, INC., a Delaware corporation and (BUSINESS NAME) a (BUSINESS TYPE) (“Covered Entity”), on behalf of itself and Business Associate) (each a “Party” and collectively the “Parties “). 1. BACKGROUND AND PURPOSE. 1.1 The parties have entered into one or more agreements for the provision of services/ products (the “Underlying contracts”). The Underlying Contracts require Business Associate to be provided with, to have access to, and/or to create Protected Health Information (as defined in 45 C.F.R. § 160.103) on behalf of Covered Entity that is subject to the federal privacy regulations (the “Privacy Rule“) and the federal security regulations (the “Security rule”) issued pursuant to the Health Insurance Portability and Accountability Act (“HIPAA”) and codified at 45 C.F.R. parts 160 and 164, as may be amended from time to time, including those modifications contained in the American Recovery and Reinvestment Act of 2009 (Pub. L. 111-5), pursuant to Title XIII of Division A and Title IV of Division B, called the Health Information Technology for Economic and Clinical Health” (HITECH Act). This Addendum shall govern Business Associate’s receipt, use and creation of Protected Health information (PHI) (as defined below) under Underlying Contract for duration of each Underlying Contract and shall be effective for all Underlying Contracts between the Parties in the future. It supplements and/or amends each Underlying contract, in part, to allow Covered Entity to comply with the Privacy Rule and the Security Rule. Any provision in the Underlying Contract regarding the limitation or exclusion of liability or damages shall not apply to Business Associate’s breach of its obligations hereunder with respect to PHI. 2. DEFINITIONS. 2.1 Unless otherwise defined in the Addendum, all capitalized terms used in this Addendum have the meanings ascribed to them in the Privacy Rule and the Security Rule. 2.2 “Electronic PHI” shall mean Electronic Protected Health Information, as defined in 45 C.F. R.§ 160.103, limited to the information received from or created or received by Business Associate on behalf of Covered Entity. 2.3 “PHI shall mean Protected Health Information, as defined in 45 C.F. R. § 160.103, limited to the information received or created or received by Business Associate on behalf of Covered Entity. 3. OBLIGATIONS OF THE PARTIES WITH RESPECT TO PHI 3.1 Obligations of the Business Associate. Business Associate agrees to: a. Not use or disclose the PHI other than permitted or required by this Addendum or as Required by Law. b. Access only the PHI of patients who are assigned by COVERED ENTITY to Business Associate. c. Use appropriate safeguards to prevent use or disclosure of PHI other than as provided by this Addendum. Business Associate acknowledges that the HITECH Act requires Business Associate to comply with the Security Rule as well as all additional security provisions of the HITECH Act as if Business Associate were a covered entity. d. Implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the Electronic PHI that it creates, receives, maintains, or transmits on behalf of COVERED ENTITY; and (ii) make its policies and procedures, and documentation required by the Security Rule relating to such safeguards, available to the Secretary of the Department of Health and Human Services (“HHS”) for the purposes of determining Covered Entity’s compliance with the Security Rule. e. Mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Addendum. f. Report to COVERED ENTITY any use or disclosure of PHI not provided for by this Addendum of which Business Associate becomes aware, as more fully detailed in Section 3.3 below. g. Report to COVERED ENTITY any Security Incident with respect to Electronic PHI of which it becomes aware, as fully detailed in section 3.3 below. h. Ensure that all of its subcontractors and agents that receive, use or have access to PHI agree, in writing, to essentially the same restrictions and conditions on the use and/ or disclosure of PHI that apply through this Addendum to Business Associate with respect to such information. i. Ensure that all of its subcontractors and agents to whom it provides Electronic PHI agree to implement reasonable and appropriate safeguards to protect such Electronic PHI. j. At the request of COVERED ENTITY, and in the time and manner specified by COVERED ENTITY, provide access to PHI in a Designated Record Set to Covered Entity or, as directed by COVERED ENTITY, to an Individual in order to meet applicable access requirements of the Privacy Rule. k. At the request of COVERED ENTITY and in the time and manner specified by COVERED ENTITY, make amendment(s) to PHI in a Designated Record Set. l. Make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of HHS, in the time and manner specified by the Secretary, for purposes of the Secretary determining COVERED ENTITY’s compliance with the Privacy Rule and Section 13405(c)(3) of the HITECH Act. m. Document any disclosures of PHI and Information related to such disclosures as would be required for COVERED ENTITY to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with the requirements of the Privacy Rule. n. Provide to COVERED ENTITY, in the time and manner specified by COVERED ENTITY, information collected in accordance with Section 3.1.1 of this Addendum, to permit COVERED ENTITY to respond to a request by an Individual for an accounting of disclosures of PHI. o. Return to COVERED ENTITY or destroy, within thirty (30) days of the termination of this Addendum or any underlying Contract, all PHI obtained from COVERED ENTITY or created or obtained by Business Associate on behalf of COVERED ENTITY with respect to the affected Underlying Contract(s), including such PHI that is in possession of Business Associate’s subcontractors and agents, and retain no copies if it is feasible to do so. If return or destruction of the PHI is infeasible, Business Associate shall notify COVERED ENTITY of the conditions that make return or destruction infeasible, extend all protections contained in this Addendum to any retained PHI, and limit any further uses and/or disclosures of the PHI to the purposes that make return or destruction of the PHI infeasible. This Section 3.1 shall survive any termination or expiration of this Addendum. 3.2 Permitted uses and Disclosures of PHI by Business Associate. Except as otherwise specified in this Addendum, Business Associate may use and disclose the PHI as reasonably necessary to perform its obligations under the Underlying Contracts. Unless otherwise limited herein, Business Associate may (a) use the PHI in its possession for its proper management and administration and to carry out the legal responsibilities of Business Associate; (b) disclose the PHI in its possession to a third party for the purpose of the Business Associate’s proper management and administration or to carry out the legal responsibilities of Business Associate, provided that the disclosures are Required By Law or Business Associate obtains reasonable assurances from the third party that (i) the information will be held confidentially and used or further disclosed only as required by law for the purpose for which it was disclosed to the third party, and (ii) the third party will notify the Business Associate of any instances of which it becomes aware in which the confidentiality of the information has been breached; and (c) provide Data Aggregation services to COVERED ENTITY. 3.3 Business Associate shall, following the discovery of a breach of unsecured PHI, as defined in the HITECH Act or accompanying regulations, notify COVERED ENTITY of such breach pursuant to the terms of 45 C.F.R. §164.410 and cooperate in COVERED ENTITY’s breach analysis procedures, including risk assessment, if requested. A breach shall be treated as discovered by Business Associate as of the first day on which such breach is known to Business Associate, or by exercising reasonable diligence, would have known to Business Associate. Business Associate will provide such notification to COVERED ENTITY without unreasonable delay and in no event later than ten (10) calendar days after discovery of the breach. Such notification will contain the elements required in 45 C.F.R. § 164.410 as well as Section 13402 of the HITECH Act. 3.4 Prohibited Access and Use of Certain PHI By Business Associate. Business Associate understands and agrees that it will not access or use any PHI of any patient except for those patients whose accounts have been assigned to Business Associate, and it will further limit access to that PHI as that which is necessary to the activities undertaken by Business Associate on behalf of COVERED ENTITY. 3.5 Additional Compliance by Business Associate. Business Associate will, pursuant to the HITECH Act and its implementing regulations, comply with all additional applicable requirements of the Privacy Rule, including those contained in 45 CFR. §§ 164.502(e) and 164.50(1)(ii), at such time as the requirements are applicable to the Business Associate. Business Associate will not directly or indirectly receive remuneration in exchange for any PHI, subject to the exceptions contained in the HITECH Act, without a valid authorization from the applicable individual. Business Associate will not engage in any communication which might be deemed “Marketing” under the HITECH Act. In addition, Business Associate will, pursuant to the HITECH Act and its implementing regulations, comply with all applicable requirements of the Security Rule contained in CFR §§ 164.308, 164.310, 164.312 and 164.316, at such time as the requirements are applicable to Business Associate. 3.6 Obligations of Covered Entity. COVERED ENTITY agrees to timely notify Business Associate of any arrangements between COVERED ENTITY and the Individual that is the subject of PHI that may reasonably affect the use and/or disclosure of that PHI by Business Associate under this Addendum. 3.7 Effect of Changes to the Law. The parties agree to take such action as is necessary to amend this Addendum from time to time as is necessary for COVERED ENTITY to comply with the Privacy Rule, the Security Rule, HIPAA, and applicable state privacy and security laws and regulations. 4. EFFECTIVE DATE: TERMINATION. 4.1 Effective Date. Each term and condition of this Addendum shall be effective on the compliance date applicable to COVERED ENTITY under the Privacy Rule, unless such term or condition relates to Electronic PHI only, in which event such term or condition shall be effective on the later of (a) the date set forth in the first paragraph of this Addendum, or (b) the compliance date applicable to COVERED ENTITY under the Security Rule (“B.A. Effective Date”). This Addendum shall continue in effect unless terminated as provided in sections 4.1 or 4.2. 4.2 Termination without Cause. This Addendum shall terminate when (a) all of the PHI obtained from COVERED ENTITY or created or obtained by Business Associate on behalf of COVERED ENTITY, is destroyed or returned to COVERED ENTITY, or (b) each Underlying Contract has terminated or expired, provided that if it is infeasible to return or destroy the PHI, protections shall be extended to such information in accordance with Section 3.1.n of this Addendum. 4.3 Termination for Cause. Upon COVERED ENTITY’s determination that there has been a material breach by Business Associate of this Addendum, COVERED ENTITY may either: a. Provide an opportunity for Business Associate to cure the breach or end the violation, and terminate this Addendum and, at its option, one or more Underlying contracts, if Business Associate does not cure the breach or end the violation within the time specified by COVERED ENTITY; or b. Immediately terminate this Addendum and at its option, one or more Underlying Contracts, if Business Associate has breached a material term of this Addendum. 5. MISCELLANEOUS. 5.1 INTERPRETATION. As of the B.A. Effective Date, the terms of this Addendum shall prevail in the case of any conflict with the terms of the Underlying Contract to the extent and only to the extent of the conflict and only to the extent that it is reasonably impossible to comply with both the terms of the Underlying Contract and the terms of this Addendum. 5.2 No Third Party Beneficiaries. Nothing in this Addendum shall confer upon any person other than the Parties and their respective successors or assigns, any rights, remedies, obligations, or liabilities whatsoever. 5.3 Indemnification. Business Associate shall indemnify, hold harmless and defend COVERED ENTITY from and against any and all claims, losses, liabilities, costs and any other expenses incurred as a result of, or arising in connection with, any breach by Business Associate of the terms of this Addendum. 5.4 Right to Audit. Business Associate understands and agrees that its access to PHI stored in databases and information systems at COVERED ENTITY is subject to review and audit by COVERED ENTITY at any time, that remote audits of such access may occur at any time, that on-site audits of such access will be conducted during regular business hours, and that any audit may occur with or without prior notice by COVERED ENTITY. 5.5 Limitation on Subcontracting. Business Associate understands and agrees that it will not assign, delegate, or subcontract any of its rights or obligations under this Addendum to individuals or entities residing outside the United States. Business Associate further understands and agrees that it will not assign, delegate or subcontract any of its rights or obligations under this Addendum to individuals or entities residing within the United States without the prior written consent of Covered Entity’s Privacy Officer. 5.6 Governing Law; Jurisdiction. This Addendum shall be governed by the laws of the State of Delaware and shall be enforceable in the courts of the State of Delaware or in the United States District Court for the district of Delaware. The Parties irrevocably submit to exclusive jurisdiction of such courts.
IN WITNESS WHEREFORE, the Parties have agreed and executed this Agreement. Print This Page