Laserfiche WebLink
Attachment 1 <br />Data Use, Security, and Confidentiality <br />1. Definitions <br />ln addition to the definitions set out in section 2, Definitions, of the Contract, the definitions below apply to this <br />Schedule: <br />"Authorized User" means an individual or individuals with an authorized business need to access HCA's <br />Confidential lnformation under this Contract. <br />"Breach" means the acquisition, access, use, or disclosure of Data in a manner not permitted under law, <br />including but not limited to the HIPAA Privacy Rule which compromises the security or privacy of the <br />Protected Health lnformation, with the exclusions and exceptions listed in 45 C.F.R. 164.402. <br />"Client" means an individual who is eligible for or receiving services through HCA program(s). <br />"Confidential lnformation" means information that is exempt from disclosure to the public or other <br />unauthorized persons under Chapter 42.56 RCW or other federal or state laws. Confidential lnformation <br />comprises both Category 3 and Category 4 Data as described in Section 4, Data Ctassification, which <br />includes, but is not limited to, Personal lnformation and Protected Health lnformation. For purposes of this <br />Contract, Confidential lnformation means the same as "Data." <br />"Contract Administrator" means the HCA individual designated to receive legal notices and to administer, <br />amend, or terminate this Contract. <br />"Gontract Manager" means the individual identified on the cover page of this Contract who will provide <br />oversight of the activities conducted under this Contract. <br />"Govered Entity" means HCA, which is a Covered Entity as defined in 45 C.F.R. S 160.103, in its conduct of <br />covered functions by its health care components. <br />"Designated Record Set" means a group of records maintained by or for a Covered Entity, that is: the <br />medical and billing records about individuals mainlained by or for a covered health care provider; the <br />enrollment, payment, claims adjudication, and case or medical management record systems maintained by or <br />for a health plan; or used in whole or part by or for the Covered Entity to make decisions about individuals. <br />"Disclosure" means the release, transfer, provision of, access to, or divulging in any other manner of <br />information outside the entity holding the information. <br />"Electronic Protected Health lnformation" or "ePHl" means Protected Health lnformation that is <br />transmitted by electronic media or maintained in any medium described in lhe definition of electronic media at <br />45 C.F.R. S 160.103. <br />"HIPAA" means the Health lnsurance Portability and Accountability Act of 1996, Pub. L. 104-191, as <br />amended by the American Recovery and Reinvestment Act of 2009 ('ARRA"), Sec. 13400 - 13424, H.R. 1 <br />(200e) (HITECH Acg. <br />"HIPAA Rules" means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts <br />160 and Part 164. <br />"lndividual(s)" means the person(s) who is the subject of PHI and includes a person who qualifies as a <br />personal representative in accordance with 45 C.F.R. g 164.502(9). <br />"Limited Data Set(s)" means a data set that meets the requirements of 45 C.F.R. SS 164.514(eX2) and <br />164.51a(e)(3). <br />Washington Stale <br />Haalth Carc Authotry Page 7 HCA Contract No. K5885-1