Laserfiche WebLink
Attachment 1 <br />Data Use, Security, and Confidentiality <br />1. Definitions <br />In addition to the definitions set out in section 2, Definitions, of the Contract, the definitions below apply to this <br />Schedule: <br />"Authorized User" means an individual or individuals with an authorized business need to access HCA's <br />Confidential Information under this Contract. <br />"Breach" means the acquisition, access, use, or disclosure of Data in a manner not permitted under law, <br />including but not limited to the HIPAA Privacy Rule which compromises the security or privacy of the <br />Protected Health Information, with the exclusions and exceptions listed in 45 C.F.R. 164.402. <br />"Client" means an individual who is eligible for or receiving services through HCA program(s). <br />"Confidential Information" means information that is exempt from disclosure to the public or other <br />unauthorized persons under Chapter 42.56 RCW or other federal or state laws. Confidential Information <br />comprises both Category 3 and Category 4 Data as described in Section 4, Data Classification, which <br />includes, but is not limited to, Personal Information and Protected Health Information. For purposes of this <br />Contract, Confidential Information means the same as "Data." <br />"Contract Administrator" means the HCA individual designated to receive legal notices and to administer, <br />amend, or terminate this Contract. <br />"Contract Manager" means the individual identified on the cover page of this Contract who will provide <br />oversight of the activities conducted under this Contract. <br />"Covered Entity" means HCA, which is a Covered Entity as defined in 45 C.F.R. § 160.103, in its conduct of <br />covered functions by its health care components. <br />"Designated Record Set" means a group of records maintained by or for a Covered Entity, that is: the <br />medical and billing records about individuals maintained by or for a covered health care provider; the <br />enrollment, payment, claims adjudication, and case or medical management record systems maintained by or <br />for a health plan; or used in whole or part by or for the Covered Entity to make decisions about individuals. <br />"Disclosure" means the release, transfer, provision of, access to, or divulging in any other manner of <br />information outside the entity holding the information. <br />"Electronic Protected Health Information" or "ePHI" means Protected Health Information that is <br />transmitted by electronic media or maintained in any medium described in the definition of electronic media at <br />45 C.F.R. § 160.103. <br />"HIPAA" means the Health Insurance Portability and Accountability Act of 1996, Pub. L. 104-191, as <br />amended by the American Recovery and Reinvestment Act of 2009 ("ARRA"), Sec. 13400 — 13424, H.R. <br />(2009) (HITECH Act). <br />"HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts <br />160 and Part 164. <br />"Individual(s)" means the person(s) who is the subject of PHI and includes a person who qualifies as a <br />personal representative in accordance with 45 C.F.R. § 164.502(g). <br />"Limited Data Set(s)" means a data set that meets the requirements of 45 C.F.R. §§ 164.514(e)(2) and <br />164.514(e)(3). <br />Washington State <br />Health Care Authority Page 7 HCA Contract No. K5885-1 <br />