Laserfiche WebLink
MUTUAL BAA AND DATA PROTECTION AGREEMENT <br />MUTUAL HIPAA BUSINESS ASSOCIATE <br />AND DATA PROTECTION AGREEMENT <br />Kittitas County / Kittitas County Jail and Contractor I August 2026 <br />1. PARTIES AND PURPOSE <br />This Mutual HIPAA Business Associate and Data Protection Agreement (BAA) is between Kittitas County, acting <br />through Kittitas County Jail (County), and Apple Valley Counseling Services, LLC, a Washington limited liability <br />company doing business as Valley Health and Counseling (Contractor). This BAA governs protected information <br />exchanged or created in connection with mental health, substance use disorder, behavioral -health practitioner, and <br />medication -management services at the Jail. <br />Role follows the transaction. A party is a Business Associate only to the extent it creates, receives, maintains, or <br />transmits Protected Health Information (PHI) on behalf of the other party as a Covered Entity or Business Associate. <br />Nothing in this BAA concedes that either party has a status not otherwise imposed by law. <br />2. DEFINITIONS AND CONTROLLING LAW <br />Terms not defined here have the meanings assigned by HIPAA and its implementing regulations at 45 C.F.R. Parts <br />160 and 164. Part 2 Record means a record protected by 42 C.F.R. Part 2. Washington Health Care Information has <br />the meaning and protections supplied by chapter 70.02 RCW and other applicable Washington law. <br />The most protective applicable requirement controls. The parties will apply HIPAA, 42 C.F.R. Part 2, chapter 70.02 <br />RCW, professional privilege, correctional -health rules, and valid patient authorizations or court orders as applicable. <br />3. PERMITTED USES AND DISCLOSURES <br />• Use or disclose PHI only to perform the service agreement, administer this BAA, or as required by law. <br />• Limit access, use, and disclosure to the minimum necessary and to personnel with a legitimate role. <br />• Do not use PHI for marketing, sale, unrelated analytics, employment decisions, custody classification, <br />punishment, or law -enforcement purposes unless separately authorized,required by law, or necessary to ensure <br />care and safety of those incarcerated. <br />• Do not use or disclose psychotherapy notes except with the authorization or legal basis specifically required for <br />those notes. <br />• Use de -identified or aggregate information whenever it will satisfy the operational purpose. <br />4.SAFEGUARDS <br />• Maintain reasonable and appropriate administrative, physical, and technical safeguards, including unique <br />accounts, least privilege, access review, encryption in transit and at rest where reasonable, secure disposal, audit <br />logging, workforce training, and incident response. <br />• Access County systems only through County -approved methods and access Contractor systems only through <br />Contractor -approved methods. <br />• Do not place PHI in ordinary email, personal cloud storage, personal messaging, or unapproved Al systems. Any <br />cloud or Al service receiving PHI must be authorized in writing and covered by required contractual protections. <br />• Ensure subcontractors that create, receive, maintain, or transmit PHI accept materially equivalent restrictions in <br />writing before access. <br />5. INCIDENT AND BREACH RESPONSE <br />A party discovering an unauthorized use or disclosure, Security Incident, breach of Unsecured PHI, or compromise of <br />a Part 2 Record will notify the other party without unreasonable delay and no later than ten (10) calendar days after <br />discovery. Routine unsuccessful security events that do not compromise data need not be individually reported <br />unless requested. <br />The initial notice will identify, to the extent known: discovery date; occurrence date; systems and records involved; <br />individuals and data elements affected; containment; mitigation; evidence preserved; and a response contact. The <br />parties will cooperate on risk assessment, mitigation, legally required notices, regulator communications, and <br />documentation. Neither party will notify affected individuals or regulators on the other party's behalf without <br />coordination, unless law requires immediate independent action. <br />Page 1 <br />