Laserfiche WebLink
colllplinllce rvitir the privacy pror''isions ollaw that appty to the Business Assgciate ttl tlresatlte extcr.lr a.s the covered Entity. <br />B' Securiry: Intplentcnt aclntinistrative. physical, ancl technical safbguar-ds that reasonably <br />and appropriately protr:ct the confidentiality, integrity, ancl availability of the pHI thar it <br />creates. receil'es, nraintains, or transnrits on behalf of the Coveretl Entily as recluircd bylarv' The Business Associate is clirectly responsible for conrpliance rvirh the securityprovisions of HIPAA and IIITECII to the sane extent as rhe Covered Er:rity. <br />Cl' Illproper DisclosLtres.: Repoft all unaLrthorizccl or otherwisc inrproper disclosures of pljl, <br />o[ security incidcnt, to thc covered Entity within tr,vo (2) clays of tlre Business <br />Associate's hrorvledge of sLrch evetlt. <br />D Notice of-Brcacli: wilhin two (2) business clays ol-tlre cliscover-y of a breach as clefinerl at45 cFR $ 164'402 notilv the covered Entity o[any breach ol'unsecured pFII. Notillcatio' <br />shnll by tlte nrost rapid nreans reasonably possible, such as tclephonic notice nracledi|ectly to all appropriate person rr,'ithiu the correreclentity ancllot inclucling a voice mailor similar nressOge. written notification shall follorv within that trvo 12) periocl by fax n'cl <br />be con{irnedby direcL contact with the intenclecl recipient, ancl inclucle the iclentillcutio'of eat-lt individual whose unsecurect PHI has been, o,lis reasonlbly believetl by the <br />Business Associale to have been, accessecl. acquired, or disclosccl cluring such breaclr: abrief'descripfion of what happcnccl, inclucling the date of t6e breach ancltlre date of t6ecliscovery of the breach" if krrowrr; a clescription ol'the types of unsecured pHl rhat wereinvolved in tire breach (such as whcther fi.rllnarne, socialsecurity uunber, clate olbirL6, <br />horne address, account number, cliagnosis, clisability code, or other types ol.information <br />$'ere involved); any steps inclividuals should take to protect thenrselves fi.om potential <br />harm resulting frum thc breach; a brief clescriptiol oiwlrat the Business Associate isdoing to investigate the breach, to mitigate hamr to individr-rals, ancl to protect against anyfi'rrther breaches; the contact pt'oceclures of the Business Associate for individuals to askclueslions or leam additional inlbmratiorr. rvhich shall inclucle a tolI fi-ee number. an e-mail address, Web site, or postal adclress; ancl any other infonnation retluired to beprovidcd to the individual by rhe covered Entity pur.suant to 45 cFR 5\ 164.404, as <br />amended' A breach shall be treatecl as discoverecl in accordance rvitir the tems ot45 CFR <br />$164'410' The informatiou shall be upclatectplornptly and proviclecl to the covered E'tiry <br />as requested by the Covered Entity, <br />E' Nlitieiltion; Mitigate, to the extent pructicable, any hannful effbct that is linorvn to <br />Business Associate of a use or disclosure of PFII by Br.rsiness Associatc in violation of thcrequirements of this Addendrun or the law. <br />F' Ag*e$l; Ensttte that any agent, inclucling allof its enployees, repr.esentatives, anrJ <br />subcontractors, to whom it provides PHI receivecl flrom, or created or received by <br />Business Associate on belralf of Covered Entity agrees to the same resgictions and <br />B. A. A. Aflachrnenr page I of 5