Laserfiche WebLink
BA shall use appropriate administrative, technical, and physical safeguards to prevent Use or Disclosure of PHI other <br />than as provided for by this Agreement. BA shall comply with the Security Rule and shall implement administrative, <br />physical, and technical safeguards (including written policies and procedures) that will reasonably and appropriately <br />protect the confidentiality, integrity, and availability of the EPHI it creates, receives, maintains, or transmits on behalf of <br />CE. <br />3.3 Disclosure to Subcontractors <br />BA agrees to ensure that any subcontractor that creates , receives , maintains, or transmits PHI on behalf of BA agrees <br />to comply with the applicable HIPAA Rules and the same restrictions and conditions that apply through this Agreement <br />to BA with respect to such PHI by entering into a Business Associate Agreement with the subcontractor consistent with <br />45 C.F.R. 164.502(e). <br />3,4 Delegation of Covered Entity's Duties <br />To the extent BA is to carry out one or more of GE's obligations under the Privacy Rule, BA shall comply with the <br />requirements of the Privacy Rule that apply to CE in the performance of such obligations . <br />3.5 Disclosure Accounting <br />BA agrees to document all Disclosures of PHI and information related to such Disclosures as would be required for CE <br />to respond to a request by an Individual for an accounting of Disclosures in accordance with 45 C.F.R. § 164.528 <br />("Disclosure Information") and to retain such documentation for six (6) years from the date of Disclosure . <br />Within thirty (30) calendar days after receipt of a written notice from CE of a request by an Individual for an accounting <br />of Disclosures of PHI, BA shall provide to CE the Disclosure Information to enable CE to meet the Disclosure <br />accounting obligations under 45 C.F.R. § 164.528. In the event a request for an accounting regarding PHI is delivered <br />directly to BA or it subcontractors, BA shall within ten (10) calendar days after receipt forward such request to CE. <br />Within twenty (20) calendar days after forwarding the request to CE, BA shall provide its Disclosure Information to CE. <br />It shall be GE's responsibility to prepare and deliver any accounting of disclosures to the Individual. BA will include, in <br />any Disclosure Information, the information listed in 45 C.F.R. § 164.528(b). <br />3.6 Access to PHI <br />Within fifteen (15) calendar days following GE's request , BA shall make available to CE or , at the written direction of <br />CE, to an Individual, for inspection and copying PHI about the Individual that is in a Designated Record Set maintained <br />by the BA, so that CE may meet its access obligations under 45 C.F.R. §164.524 . If CE requests an electronic copy of <br />PHI that is maintained by BA electronically in a Designated Record Set, BA will provide an electronic copy in the form <br />and format specified by CE in accordance with 45 C.F.R . § 164.524(c)(2). Any denial of access to the PHI requested <br />shall be the responsibility of the CE. <br />3. 7 Amendment of PHI <br />Upon receipt of a request from CE, BA shall promptly amend or make available to CE for amendment, an Individual's <br />PHI maintained by BA in a Designated Record Set to enable CE to meet its obligations under 45 C.F .R. § 164.526. <br />Any denial of a request by an Individual for amendment of PHI maintained by BA pursuant to the Agreement shall be <br />the responsibility of CE . <br />3.8 Government Access to Books and Records <br />3.9 <br />FCHN-PRO-042016 <br />BA shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or <br />created or received by BA on behalf of CE, available to the Secretary for purposes of determining GE's compliance <br />with the HIPAA Rules. Unless prohibited by law or court or order, BA shall provide to CE, (i) prompt written notice of <br />BA's receipt of any such request from the Secretary, and (ii) a copy of any documentation, books, and records <br />provided by BA to the Secretary pursuant to the Secretary's request. <br />Reporting and Mitigation of Unauthorized Use and Disclosure of PHI or Breach of Unsecured PHI <br />3.9.1 Reporting of Unauthorized Use and Disclosure of PHI. BA shall provide a written report to CE of any Uses or <br />Disclosures of PHI not authorized by the Services Agreement or this Agreement of which it becomes aware not more <br />than thirty (30) calendar days after the unauthorized Use or Disclosure is discovered. <br />19