Laserfiche WebLink
collllrliallce with the privacy provisirlns of lar.v that apply to thc Business Associirte to the <br />same cxteul as the Covcred Entity. <br />B. Securitv: Ittrplement aclministrative, physical, ancl teclrnical sal'eguarcls that reasouably <br />and appropriately protect the confidentialit-v, integrity. anci availability of the PHI that it <br />creates, receivcs. triailttiiirts, or transurits on behall'o1'the Covered Entity as requirecl by <br />lau'' The Busiticss Associate is directly i'esponsible liir corrpliance r.vith the security <br />provisiotrs of I-lIPAA ancl FIITECH to the same extent as the Coverccl Entity. <br />C. Ilrlproper Disclostttes: Repofi all unairthorized or otherlvise improper ciisclosures of pHI. <br />or security inciclent, to the Coverccl Entity r,vithin trvo (2) clays of the Busiuess <br />Associate's knorvlcclge of such cvent. <br />D. Noticc of Bleaclt: Within two (2) business clays of the cliscovcry oi'a bre ach as clefined at <br />45 CFR s\164.402 notify the Covci'ed Entity of any breach of unsecured PHL Notification <br />shall by the most rapicl means reasonably possible. such as telephonic notice macle <br />cli|cctly to arr appt'opriate persou r,vithin the covelecl entity nncl not including a voice mail <br />or similar rllessilgc. Written notification shall lbllor.v within that tr.vo (2) periocl by lax ancl <br />be coufinrrcclby direct contact rvith tlie intentled rccipienl, ancl inclucle the iclentificatiol <br />of each indivich-ral i.vltosc uuseci-rrecl PHI has been, or is reasonably believeclby the <br />Busiucss Associate to have beerr, acccssecl, acquirecl, or clisclosecl duriug such breach; a <br />bricf dcsclilltiolt of r,vhat happened, inclucling tlie clate of the bleach ancl the clate of the <br />discovery of tltc bleach, if kuown; a clescription of tl-rc types of uusecurecl Pl-ll thiitlvere <br />involvecl in tlie breaclr (such as lvhethcr flll name, social security number', clate oflbirth, <br />houre adclress, account uuutber, diagnosis, disability cocle, or other types of infbmratiou <br />rvere involvecl); any steps indivirir"rals shoulcl take to protcct tirernselves f}om potential <br />harrn resultittg fi'otn tlre breach; a brief clescription ollvliat the Busincss Associate is <br />cloing to investigate the breaclt, to uritigate hamr to individuals, ancl to protect against any <br />futther breacltes;the contact procedures of the Business Associate for inciiviciuals to ask <br />clttcstiotls or leartr aclditional infbmration, rvhich shall inclutle a toll ti'ee rrurnber, an e- <br />mail adtlress, Web site, or postal acldress; ancl any other infonlation requirecl tg bc <br />proviclecl to thc indivicluiil by the covered Entity pursuant to 45 cFR s\164.404, as <br />at]ieuclecl. A breach shallbe lreated as cliscovereclin accorclance rvith the tenns of 45 CFR <br />s\16'1.'+10. The inibrrttation shall be upclated promptly anclplovideclto the Coverecl Entity <br />as reqr-rcsted by the Covered Entity. <br />E' Mitisation: Mitigate, to the extent practicable, any hanlfirl effcct thaf is knowp to <br />Business Associate of a use or disclosure of PHI by Business Associate in violation of the <br />requirements of this Addendurn or the law. <br />F. Aqeuts: Ettsttt'e that any agent, iuch"rdurg all of its enrployecs, representatives, aucl <br />subcontractors, to wltom it provicles PHI received t}om, or createcior receivecl by <br />Br:siness Associate on behalf of Covcrecl Entity agrees to the same restrictions aucl <br />Il. A. A. Attachnicnt Page 2 of 5