Common use of Breach Notification Requirements Clause in Contracts

Breach Notification Requirements. i. In addition to requirements in 5.a above, in the event of a breach or other impermissible use or disclosure by Business Associate of PHI or unsecured PHI, the Business Associate shall be required to notify in writing all affected individuals to include, a) a brief description of what happened, including the date of the breach and the date the Business Associate discovered the breach; b) a description of the types of unsecured PHI that were involved in the breach; c) any steps the individuals should take to protect themselves from potential harm resulting from the breach; d) a brief description of what Business Associate is doing to investigate the breach, mitigate harm to individuals, and protect against any future breaches, and, if necessary, e) Establishing and staffing a toll-free telephone line to respond to questions. ii. Business Associate shall be responsible for all costs associated with breach notifications requirements in 5b, above. iii. Written notices to all individuals and entities shall comply with 45 CFR 164.404(c)(2), 164.404(d)(1), 164.406, 164.408 and 164.412.

Appears in 4 contracts

Samples: Business Associate Agreement, Business Associate Agreement, Business Associate Agreement

AutoNDA by SimpleDocs
Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!