Laserfiche WebLink
1.8 "Protected Health Information" or "PHI" shall have the same meaning as the term "protected health information" in <br />45 C.F.R. § 160.103, limited to the information created, received, maintained, or transmitted by BA from or on behalf of <br />CE pursuant to this Agreement. <br />1.9 "Required by Law" shall have the same meaning found in 45 C.F.R. § 164.103. <br />1.10 "Secretary" shall mean the Secretary of the Department of Health and Human Services or his or her designee. <br />1.11 "Unsecured PHI" shall have the same meaning as the term "unsecured protected health information" in 45 C.F.R. § <br />164.402 . <br />1.12 "Use" or "Uses" shall mean, with respect to Protected Health Information, the sharing, employment, application, <br />utilization, examination, or analysis of such information within BA's internal operations . <br />2. Authorized Uses and Disclosures by Business Associate. <br />2.1 General Use and Disclosure <br />Except as otherwise limited in this Agreement, BA may Use or Disclose PHI on behalf of CE as necessary to provide <br />services as set forth in the Services Agreement , if such Use or Disclosure of PHI would not violate the Privacy Rule if . <br />done by CE . <br />2.2 Business Activities of Business Associate <br />2.2.1 Unless otherwise limited herein, BA may Use PHI: <br />(a) As necessary for the proper management and administration of BA or to carry out the legal <br />responsibilities of BA; <br />(b) To provide Data Aggregation services as permitted by 42 CFR § 164.504(e)(2)(i)(B); <br />(c) To De-identify any and all PHI created, received, maintained , or transmitted by BA on behalf of CE <br />provided that the De-identification conforms to the requirements of the HIPAA Rules . Such <br />resulting De-identified information is not PHI and is not subject to the terms of this Agreement; and <br />(d) As Required by Law. <br />2.2.2 Unless otherwise limited herein, BA may Disclose PHI for the proper management and administration of BA <br />or to carry out the legal responsibilities of BA provided that: <br />(a) The Disclosure is Required by Law; or <br />(b) BA obtains reasonable assurances from the person to whom the PHI is Disclosed that ii will be <br />held confidentially and Used or further Disclosed only as Required by Law or for the purposes for which ii <br />was Disclosed to the person, and the person notifies BA of any instances of which ii is aware in which the <br />confidentiality of the PHI has been breached , <br />3. Business Associate Obligations. <br />3.1 Use of PHI <br />BA shall not Use or further Disclose PHI other than as permitted or required by the Services Agreement, this <br />Agreement, or as Required by Law. In Using, Disclosing, or requesting PHI from CE, BA agrees to limit PHI to the <br />minimum necessary to accomplish the intended purpose of such Use, Disclosure, or request. "Minimum necessary" <br />shall be interpreted in accordance with the HITECH Act and the HIPAA Rules , and implementing regulation or guidance <br />on the definition . <br />3.2 Appropriate Safeguards; Compliance with Security Rule <br />FCHN-PRO-042016 18