Laserfiche WebLink
assets/14110-securing-information-technology-assets.) The Securitv Standard 141.10 is hereby <br />incorporated by reference into this Contract. <br />6.3. Data Disposition and Retention <br />a. Contractor will dispose of HCA Data in accordance with this section. <br />b. Upon request by HCA, or at the end of the Contract term, or when no longer needed, <br />Confidential Information/Data must be disposed of as set out in Attachment 1, Section 5 Data <br />Disposition, except as required to be maintained for compliance or accounting purposes. <br />Contractor will provide written certification to HCA of disposition using Attachment 4, <br />Certification of Destruction/Disposition of Confidential Information. <br />7. Data Confidentiality and Non -Disclosure <br />7.1. Data Confidentiality. <br />The Contractor will not use, publish, transfer, sell, or otherwise disclose any Confidential Information <br />gained by reason of this Contract for any purpose that is not directly connected with the purpose, <br />justification, and Permissible Use of this Contract, as set out in the attached Data Licensing Statement(s) <br />except: (a) as provided by law; or (b) with the prior written consent of the person or personal <br />representative of the person who is the subject of the Data. <br />7.2. Non -Disclosure of Data <br />The Contractor must ensure that all employees or Subcontractors who will have access to the Data <br />described in this Contract (including both employees who will use the Data and IT support staff) are <br />instructed and made aware of the use restrictions and protection requirements of this Contract before <br />gaining access to the Data identified herein. The Contractor will also instruct and make any new employe <br />aware of the use restrictions and protection requirements of this Contract before they gain access to the <br />Data. <br />The Contractor will ensure that each employee or Subcontractor who will access the Data signs the User <br />Agreement on Non -Disclosure of Confidential Information, Attachment 3 hereto. The Contractor will retair <br />the signed copy of the User Agreement on Non -Disclosure of Confidential Information in each employee': <br />personnel file for a minimum of six years from the date the employee's access to the Data ends. The <br />documentation must be available to HCA upon request. <br />7.3. Penalties for Unauthorized Disclosure of Data <br />State laws (including RCW 74.04.060 and RCW 70.02.020) and federal regulations (including HIPAA <br />Privacy and Security Rules, 45 C.F.R. Part 160 and Part 164; Confidentiality of Alcohol and Drug Abuse <br />Patient Records, 42 C.F.R., Part 2; and Safeguarding Information on Applicants and Beneficiaries, 42 <br />C.F.R. Part 431, Subpart F) prohibit unauthorized access, use, or disclosure of Confidential Information. <br />Violation of these laws may result in criminal or civil penalties or fines. <br />The Contractor accepts full responsibility and liability for any noncompliance by itself, its employees, and <br />its Subcontractors with these laws and any violations of the Contract. <br />8. Data Shared with Subcontractors <br />The Contractor will not enter into any Subcontract without the express, written permission of HCA, which will <br />approve or deny the proposed subcontract in its sole discretion. If Data access is to be provided to a <br />Subcontractor under this Contract it will only be for the Permissible Use authorized by HCA and the <br />Washington State <br />Health Care Authority Page 11 HCA Contract No. K5885-1 <br />