|
MUTUAL BAA AND DATA PROTECTION AGREEMENT
<br />MUTUAL HIPAA BUSINESS ASSOCIATE
<br />AND DATA PROTECTION AGREEMENT
<br />Kittitas County / Kittitas County Jail and Contractor I August 2026
<br />1. PARTIES AND PURPOSE
<br />This Mutual HIPAA Business Associate and Data Protection Agreement (BAA) is between Kittitas County, acting
<br />through Kittitas County Jail (County), and Apple Valley Counseling Services, LLC, a Washington limited liability
<br />company doing business as Valley Health and Counseling (Contractor). This BAA governs protected information
<br />exchanged or created in connection with mental health, substance use disorder, behavioral -health practitioner, and
<br />medication -management services at the Jail.
<br />Role follows the transaction. A party is a Business Associate only to the extent it creates, receives, maintains, or
<br />transmits Protected Health Information (PHI) on behalf of the other party as a Covered Entity or Business Associate.
<br />Nothing in this BAA concedes that either party has a status not otherwise imposed by law.
<br />2. DEFINITIONS AND CONTROLLING LAW
<br />Terms not defined here have the meanings assigned by HIPAA and its implementing regulations at 45 C.F.R. Parts
<br />160 and 164. Part 2 Record means a record protected by 42 C.F.R. Part 2. Washington Health Care Information has
<br />the meaning and protections supplied by chapter 70.02 RCW and other applicable Washington law.
<br />The most protective applicable requirement controls. The parties will apply HIPAA, 42 C.F.R. Part 2, chapter 70.02
<br />RCW, professional privilege, correctional -health rules, and valid patient authorizations or court orders as applicable.
<br />3. PERMITTED USES AND DISCLOSURES
<br />• Use or disclose PHI only to perform the service agreement, administer this BAA, or as required by law.
<br />• Limit access, use, and disclosure to the minimum necessary and to personnel with a legitimate role.
<br />• Do not use PHI for marketing, sale, unrelated analytics, employment decisions, custody classification,
<br />punishment, or law -enforcement purposes unless separately authorized,required by law, or necessary to ensure
<br />care and safety of those incarcerated.
<br />• Do not use or disclose psychotherapy notes except with the authorization or legal basis specifically required for
<br />those notes.
<br />• Use de -identified or aggregate information whenever it will satisfy the operational purpose.
<br />4.SAFEGUARDS
<br />• Maintain reasonable and appropriate administrative, physical, and technical safeguards, including unique
<br />accounts, least privilege, access review, encryption in transit and at rest where reasonable, secure disposal, audit
<br />logging, workforce training, and incident response.
<br />• Access County systems only through County -approved methods and access Contractor systems only through
<br />Contractor -approved methods.
<br />• Do not place PHI in ordinary email, personal cloud storage, personal messaging, or unapproved Al systems. Any
<br />cloud or Al service receiving PHI must be authorized in writing and covered by required contractual protections.
<br />• Ensure subcontractors that create, receive, maintain, or transmit PHI accept materially equivalent restrictions in
<br />writing before access.
<br />5. INCIDENT AND BREACH RESPONSE
<br />A party discovering an unauthorized use or disclosure, Security Incident, breach of Unsecured PHI, or compromise of
<br />a Part 2 Record will notify the other party without unreasonable delay and no later than ten (10) calendar days after
<br />discovery. Routine unsuccessful security events that do not compromise data need not be individually reported
<br />unless requested.
<br />The initial notice will identify, to the extent known: discovery date; occurrence date; systems and records involved;
<br />individuals and data elements affected; containment; mitigation; evidence preserved; and a response contact. The
<br />parties will cooperate on risk assessment, mitigation, legally required notices, regulator communications, and
<br />documentation. Neither party will notify affected individuals or regulators on the other party's behalf without
<br />coordination, unless law requires immediate independent action.
<br />Page 1
<br />
|