Laserfiche WebLink
1 *A:11_ -j_1_" �]�I <br />HIPAA Compliance <br />Preamble: This section of the Contract is the Business Associate Agreement as required <br />by H I PAA. <br />2. Definitions. <br />a. "Business Associate," as used in this Contract, means the "Contractor" and generally <br />has the same meaning as the term "business associate" at 45 CFR 160.103. Any <br />reference to Business Associate in this Contract includes Business Associate's <br />employees, agents, officers, Subcontractors, third party contractors, volunteers, or <br />directors. <br />b. "Business Associate Agreement" means this HIPAA Compliance section of the <br />Contract and includes the Business Associate provisions required by the U.S. <br />Department of Health and Human Services, Office for Civil Rights. <br />c. "Breach" means the acquisition, access, use, or disclosure of Protected Health <br />Information in a manner not permitted under the HIPAA Privacy Rule which <br />compromises the security or privacy of the Protected Health Information, with the <br />exclusions and exceptions listed in 45 CFR 164.402. <br />d. "Covered Entity" means DSHS, a Covered Entity as defined at 45 CFR 160.103, in <br />its conduct of covered functions by its health care components. <br />e. "Designated Record Set" means a group of records maintained by or for a Covered <br />Entity, that is: the medical and billing records about Individuals maintained by or for a <br />covered health care provider; the enrollment, payment, claims adjudication, and case <br />or medical management record systems maintained by or for a health plan; or Used <br />in whole or part by or for the Covered Entity to make decisions about Individuals. <br />f. "Electronic Protected Health Information (EPHI)" means Protected Health Information <br />that is transmitted by electronic media or maintained in any medium described in the <br />definition of electronic media at 45 CFR 160.103. <br />g. "HIPAX means the Health Insurance Portability and Accountability Act of 1996, Pub. <br />L. 104-191, as modified by the American Recovery and Reinvestment Act of 2009 <br />("ARRA"), Sec. 13400 — 13424, H.R. 1 (2009) (HITECH Act). <br />h. "HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement <br />Rules at 45 CFR Parts 160 and Part 164. <br />i. "Individual(s)" means the person(s) who is the subject of PHI and includes a person <br />who qualifies as a personal representative in accordance with 45 CFR 164.502(g). <br />j. "Minimum Necessary" means the least amount of PHI necessary to accomplish the <br />Professional Services Agreement <br />Page 22 <br />