Laserfiche WebLink
v. Unsecured Protected Health Information. "Unsecured Protected Health Information" <br />shall have the same meaning as the term "unsecured protected health information" in 45 CFR <br />§164.402. <br />w. Use. "Use" shall have the same meaning as the term "Use" in 45 CFR §164.103. <br />2. Obligations and Activities of Business Associate. <br />a. Business Associate agrees to not Use or Disclose Protected Health Information other than <br />as permitted or required by this Agreement or as Required By Law. <br />b. Business Associate agrees to use appropriate safeguards to prevent Use or Disclosure of <br />Protected Health Information other than as provided for by this Agreement. Business <br />Associate further agrees to implement administrative, physical and technical safeguards that <br />reasonably and appropriately protect the confidentiality, integrity and availability of any <br />electronic Protected Health Information, as provided for in the Security Rule and as <br />mandated by Section 13401 of the HITECH Act. <br />c. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is <br />known to Business Associate of a Use or Disclosure of Protected Health Information by <br />Business Associate in violation of the requirements of this Agreement. Business Associate <br />further agrees to report to Covered Entity any Use or Disclosure of Protected Health <br />Information not provided for by this Agreement of which it becomes aware, and in a manner <br />as prescribed herein. <br />d. Business Associate agrees to report to Covered Entity any Security Incident, including all <br />data Breaches or compromises, whether internal or external, related to Protected Health <br />Information, whether the Protected Health Information is secured or unsecured, of which <br />Business Associate becomes aware. <br />e. If the Breach, as discussed in paragraph 2(d), pertains to Unsecured Protected Health <br />Information, then Business Associate agrees to report any such data Breach to Covered <br />Entity within ten (10) business days of discovery of said Breach; all other compromises, or <br />attempted compromises, of Protected Health Information shall be reported to Covered Entity <br />within twenty (20) business days of discovery. Business Associate further agrees, consistent <br />with Section 13402 of the HITECH Act, to provide Covered Entity with information <br />necessary for Covered Entity to meet the requirements of said section, and in a manner and <br />format to be specified by Covered Entity. <br />f. If Business Associate is an Agent of Covered Entity, then Business Associate agrees that <br />any Breach of Unsecured Protected Health Information shall be reported to Covered Entity <br />immediately after the Business Associate becomes aware of said Breach, and under no <br />circumstances later than one (1) business day thereafter. Business Associate further agrees <br />that any compromise, or attempted compromise, of Protected Health Information, other than <br />a Breach of Unsecured Protected Health Information as specified in 2(e) of this Agreement, <br />3