Laserfiche WebLink
(2) When the request is made by the Individual to the Business Associate or if DSHS <br />asks the Business Associate to respond to a request, the Business Associate shall <br />comply with requirements in 45 CFR 164.524 (Access of Individuals to Protected <br />Health Information) on form, time and manner of access. When the request is <br />made by DSHS, the Business Associate shall provide the records to DSHS within <br />ten (10) business days. <br />c. Amendment. <br />(1) If DSHS amends, in whole or in part, a record or PHI contained in an Individual's <br />Designated Record Set and DSHS has previously provided the PHI or record that is <br />the subject of the amendment to Business Associate, then DSHS will inform <br />Business Associate of the amendment pursuant to 45 CFR 164.526(c)(3) <br />(Amendment of Protected Health Information). <br />(2) Business Associate shall make any amendments to PHI in a Designated Record <br />Set as directed by DSHS or as necessary to satisfy DSHS's obligations under 45 <br />CFR 164.526 (Amendment of Protected Health Information). <br />5. Subcontracts and other Third Party Agreements. In accordance with 45 CFR <br />164.502(e)(1 )(ii), 164.504(e)(1 )(i), and 164.308(b)(2), Business Associate shall ensure that <br />any agents, Subcontractors, independent contractors or other third parties that create, <br />receive, maintain, or transmit PHI on Business Associate's behalf, enter into a written <br />contract that contains the same terms, restrictions, requirements, and conditions as the <br />HIPAA compliance provisions in this Contract with respect to such PHI. The same <br />provisions must also be included in any contracts by a Business Associate's Subcontractor <br />with its own business associates as required by 45 CFR 164.314(a)(2)(b) and <br />164.504(e)(5). <br />6. Obligations. To the extent the Business Associate is to carry out one or more of DSHS's <br />obligation(s) under Subpart E of 45 CFR Part 164 (Privacy of Individually Identifiable Health <br />Information), Business Associate shall comply with all requirements that would apply to <br />DSHS in the performance of such obligation(s). <br />7. Liability. Within ten (10) business days, Business Associate must notify DSHS of any <br />complaint, enforcement or compliance action initiated by the Office for Civil Rights based <br />on an allegation of violation of the HIPAA Rules and must inform DSHS of the outcome of <br />that action. Business Associate bears all responsibility for any penalties, fines or sanctions <br />imposed against the Business Associate for violations of the HI PAA Rules and for any <br />imposed against its Subcontractors or agents for which it is found liable. <br />8. Breach Notification. <br />a. In the event of a Breach of unsecured PHI or disclosure that compromises the privacy <br />or security of PHI obtained from DSHS or involving DSHS clients, Business Associate <br />will take all measures required by state or federal law. <br />b. Business Associate will notify DSHS within one (1) business day by telephone and in <br />writing of any acquisition, access, Use or disclosure of PHI not allowed by the <br />provisions of this Contract or not authorized by HIPAA Rules or required by law of <br />Washington State <br />Health Care Authority Page 57 of90 HCA Contract No. K3924