Laserfiche WebLink
for any purpose other than the performance of this Contract, to release it only to <br />authorized employees or Subcontractors requiring such information for the purposes <br />of carrying out this Contract, and not to release, divulge, publish, transfer, sell, <br />disclose, or otherwise make the information known to any other party without HCA's <br />express written consent or as provided by law. <br />Contractor agrees to implement physical, electronic, and managerial safeguards to <br />prevent unauthorized access to Confidential Information. <br />4.7.2 Contractors that come into contact with Protected Health Information may be <br />required to enter into a Business Associate Agreement with HCA in compliance with <br />the requirements of the Health Insurance Portability and Accountability Act of 1996, <br />Pub. L. 104-191, as modified by the American Recovery and Reinvestment Act of <br />2009 ("ARRA"), Sec. 13400-13424, H.R. 1 (2009) (HITECH Act) (HIPAA). <br />4.7.3 HCA reserves the right to monitor, audit, or investigate the use of Confidential <br />Information collected, used, or acquired by Contractor through this Contract. <br />Violation of this section by Contractor or its Subcontractors may result in termination <br />of this Contract and demand for return of all Confidential Information, monetary <br />damages, or penalties. <br />4.7.4 The obligations set forth in this Section will survive completion, cancellation, <br />expiration, or termination of this Contract. <br />4.8 CONFIDENTIAL INFORMATION SECURITY <br />The federal government, including the Centers for Medicare and Medicaid Services <br />(CMS), and the State of Washington all maintain security requirements regarding privacy, <br />data access, and other areas. Contractor is required to comply with the Confidential <br />Information Security Requirements set out in this Contract and appropriate portions of the <br />Washington OCIO Security Standard, 141.1 O (https://ocio. wa .gov/pollcies/141 -securing- <br />informatlon-technology-assets/14110-securinq-iriformation-technology-assets). <br />4.9 CONFIDENTIAL INFORMATION BREACH -REQUIRED NOTIFICATION <br />4.9.1 Contractor must notify the HCA Privacy Officer (HCAPrlvacyOfficer@hca .wa .gov) <br />within five Business days of discovery of any Breach or suspected Breach of <br />Confidential Information. <br />4.9.2 Contractor will take steps necessary to mitigate any known harmful effects of such <br />unauthorized access including, but not limited to, sanctioning employees and taking <br />steps necessary to stop further unauthorized access. Contractor agrees to <br />indemnify and hold HCA harmless for any damages related to unauthorized use or <br />disclosure of Confidential Information by Contractor, its officers, directors, and <br />employees, Subcontractors or agents. <br />Washington State <br />Health Care Authority Page 15 of 53 Contract# 2747