Laserfiche WebLink
ATTACHMENT "A" <br />Business Associate Agreement -HIPAA Compliance <br />1. DEFINITIONS <br />(a) The following terms used in this Agreement shall have the same meaning as <br />those terms in the HIPAA Rules: Breach, Data Aggregation, DeSignated <br />Record Set, Disclosure, Health Care Operations, Individual, Minimum <br />Necessary, Notice of Privacy Practices, Protected Health Information, Required <br />By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected <br />Health Information, and Use. <br />(b) Business Associate. "Business Associate" shall generally have the same <br />meaning as the term "business associate" at 45 CFR 160.103, and in reference <br />to the party to this agreement, shall mean EVERGREEN FINANCIAL <br />SERVICES, INC. ("EFS"). <br />(c) Covered Entity. ·Covered Entity" shall generally have the same meaning as <br />the term "covered entity" at 45 CFR 160.103, and in reference to the party to <br />this agreement, shall mean Kittitas County Public Health Department, a <br />department of Kittitas County. <br />(d) HIPAA Rules. "HIPAA Rules" shall mean the Privacy, Security, Breach <br />Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164. <br />2. Obligations and Activities of Business Associate <br />Business Associate agrees to: <br />(a) Not use or disclose protected health information other than as permitted or <br />required by the Agreement or as required by law; <br />(b) Use appropriate safeguards, and comply with Subpart C of 45 CFR Part 164 <br />with respect to electronic protected health information, to prevent use or <br />disclosure of protected health information other than as provided for by the <br />Agreement; <br />(c) Report to covered entity any use or disclosure of protected health information <br />not provided for by the Agreement of which it becomes aware, including <br />breaches of unsecured protected health information as required at 45 CFR <br />164.410, and any security incident of which it becomes aware; <br />(d) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, <br />ensure that any subcontractors that create, receive, maintain, or transmit <br />protected health information on behalf of the business associate agree to the <br />same restrictions, conditions, and requirements that apply to the business <br />associate with respect to such information; <br />Page 16