BUSINESS ASSOCIATE ACKNOWLEDGEMENTS, OBLIGATIONS, PERMITTED USES AND DISCLOSURES Sample Clauses

BUSINESS ASSOCIATE ACKNOWLEDGEMENTS, OBLIGATIONS, PERMITTED USES AND DISCLOSURES a. Business Associate acknowledges it is subject to the requirements of the HIPAA Privacy and Security Rules to the extent required by HITECH and will comply with those rules and any other requirements applicable to Business Associate relating to the confidentiality of PHI under any federal or state law, including but not limited to the regulations pertaining to the confidentiality of substance use disorder patient records found at 42 CFR Part 2. b. Except as otherwise expressly limited in the Agreement, Business Associate may use or disclose PHI: i. To perform functions, activities, or services for, or on behalf of, Covered Entity in connection with the Administrative Services Agreement and any other agreements in effect between Covered Entity and Business Associate. ii. For the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate, provided that if Business Associate further discloses PHI: 1. The disclosure is Required by Law; or 2. The Business Associate obtains reasonable assurances from the third-party to whom the information is disclosed that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the third-party and the third-party agrees to notify the Business Associate of any instances of which the third-party is aware in which the confidentiality of the information has been Breached. iii. To provide Data Aggregation services to Covered Entity as permitted by 45 CFR §164.504(e)(2)(i)(B). iv. To report violations of law to appropriate Federal and State authorities, consistent with 45 CFR §164.502(j) (1), Business Associate agrees to not use or further disclose PHI other than as permitted or required by the Agreement or as Required by Law. c. Except as permitted by 45 C.F.R. §164.502(b)(2), Business Associate agrees to limit its use, disclosure and requests of PHI under the Agreement to the Minimum Necessary. d. Business Associate agrees to use appropriate safeguards to prevent use or disclosure of the PHI other than as provided for by this Agreement and will implement administrative, physical and technical safeguards (including written policies and procedures) that reasonably and appropriately protect the confidentiality, integrity and availability of Electronic PHI that it creates, receives, maintains or transmits on behalf of Covered Entity as required by the HIPAA Privacy and Security Ru...
AutoNDA by SimpleDocs

Related to BUSINESS ASSOCIATE ACKNOWLEDGEMENTS, OBLIGATIONS, PERMITTED USES AND DISCLOSURES

  • Permitted Uses and Disclosure by Business Associate (1) General Use and Disclosure Provisions Except as otherwise limited in this Section of the Contract, Business Associate may use or disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in this Contract, provided that such use or disclosure would not violate the HIPAA Standards if done by Covered Entity or the minimum necessary policies and procedures of the Covered Entity.

  • Permitted Uses and Disclosures by Business Associate Except as otherwise limited by this Agreement, Business Associate may make any uses and disclosures of Protected Health Information necessary to perform its services to Covered Entity and otherwise meet its obligations under this Agreement, if such use or disclosure would not violate the Privacy Rule if done by Covered Entity. All other uses or disclosures by Business Associate not authorized by this Agreement or by specific instruction of Covered Entity are prohibited.

  • PERMITTED USES AND DISCLOSURES BY CONTRACTOR Except as otherwise limited in this Schedule, Contractor may use or disclose Protected Health Information to perform functions, activities, or services for, or on behalf of, County as specified in the Agreement; provided that such use or disclosure would not violate the Privacy Rule if done by County.

  • Permitted Uses and Disclosures of Phi by Business Associate Except as otherwise indicated in this Agreement, Business Associate may use or disclose PHI, inclusive of de-identified data derived from such PHI, only to perform functions, activities or services specified in this Agreement on behalf of DHCS, provided that such use or disclosure would not violate HIPAA or other applicable laws if done by DHCS.

  • Permitted Uses and Disclosures i. Business Associate shall use and disclose PHI only to accomplish Business Associate’s obligations under the Contract. i. To the extent Business Associate carries out one or more of Covered Entity’s obligations under Subpart E of 45 C.F.R. Part 164, Business Associate shall comply with any and all requirements of Subpart E that apply to Covered Entity in the performance of such obligation. ii. Business Associate may disclose PHI to carry out the legal responsibilities of Business Associate, provided, that the disclosure is Required by Law or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that: A. the information will remain confidential and will be used or disclosed only as Required by Law or for the purpose for which Business Associate originally disclosed the information to that person, and; B. the person notifies Business Associate of any Breach involving PHI of which it is aware. iii. Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity. Business Associate may de-identify any or all PHI created or received by Business Associate under this Agreement, provided the de-identification conforms to the requirements of the HIPAA Rules.

  • Permitted Use and Disclosures Each Party hereto may use or disclose Information disclosed to it by the other Party to the extent such use or disclosure: (i) is reasonably necessary in complying with Applicable Laws or otherwise submitting information to tax or other governmental authorities, (ii) is provided by the receiving Party to Third Parties, on a strictly as-needed basis, for consulting services, conducting Preclinical or Clinical Development, CMC/Process Development, Manufacturing, external testing, market research, or otherwise exercising its rights or performing its obligations hereunder; provided, that such Third Parties are obligated to maintain the confidentiality of such other Party’s Information as set forth herein for the benefit of such other Party for a period of at least the term of the agreement with such Third Party and for a period of *** thereafter; (iii) is included in submissions by the receiving Party to Governmental Authorities to facilitate the issuance of approvals for NDAs and NDA Equivalents for the Product, provided that reasonable measures shall be taken to assure confidential treatment of such Information; or (iv) is to Third Parties in connection with a receiving Party’s efforts to secure financing or enter into strategic partnerships, provided such Information is disclosed only on a need-to-know basis and under confidentiality provisions at least as stringent as those in this Agreement. Additionally, Bayer may disclose to Mitsui any Information received from Licensee hereunder; provided, that such disclosure is reasonably considered by Bayer to be necessary to comply with the terms and conditions of the Patent License Agreement; and further provided, that Mitsui is obligated to maintain the confidentiality of Licensee’s Information as set forth herein for the benefit of Licensee. Notwithstanding the foregoing, if a receiving Party is required to make any such disclosure of the disclosing Party’s confidential Information, other than pursuant to a confidentiality agreement, the receiving Party will give reasonable advance notice to the disclosing Party of such disclosure and, save to the extent inappropriate in the case of patent applications, will use its reasonable efforts to secure confidential treatment of such Information prior to its disclosure (whether through protective orders or otherwise).

  • Permitted Uses and Disclosures of PHI and the third party notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

  • Prohibited Uses and Disclosures BA shall not use or disclose PHI other than as permitted or required by the Contract and Addendum, or as required by law. BA shall not use or disclose Protected Information for fundraising or marketing purposes. BA shall not disclose Protected Information to a health plan for payment or health care operation purposes if the patient has requested this special restriction, and has paid out of pocket in full for the health care item or service to which the PHI solely relates [42 U.S.C. Section 17935(a) and 45 C.F.R. Section 164.522(a)(vi)]. BA shall not directly or indirectly receive remuneration in exchange for Protected Information, except with the prior written consent of CE and as permitted by the HITECH Act, 42 U.S.C. Section 17935(d)(2), and the HIPAA regulations, 45 C.F.R. Section 164.502(a)(5)(ii); however, this prohibition shall not affect payment by CE to BA for services provided pursuant to the Contract.

  • Customer Information and Release Authorization Throughout this Agreement, you authorize Clearview Energy or its agents to obtain and review information from credit-reporting agencies regarding your credit history and information from the Utility relating to you and your account that includes, but is not limited to: account name and number; billing history; payment history; rate classification; historical and future electricity usage; meter readings; and characteristics of electricity service. Clearview Energy will not provide or sell such information to any other party without your consent unless required to do so by law, or it is necessary to enforce the terms of this Agreement. Clearview Energy reserves the right to reject your enrollment, or terminate this Agreement, in the event you rescind these authorizations.

  • OBLIGATIONS AND ACTIVITIES OF CONTRACTOR AS BUSINESS ASSOCIATE 1. CONTRACTOR agrees not to use or further disclose PHI COUNTY discloses to CONTRACTOR other than as permitted or required by this Business Associate Contract or as required by law. 2. XXXXXXXXXX agrees to use appropriate safeguards, as provided for in this Business Associate Contract and the Agreement, to prevent use or disclosure of PHI COUNTY discloses to CONTRACTOR or CONTRACTOR creates, receives, maintains, or transmits on behalf of COUNTY other than as provided for by this Business Associate Contract. 3. XXXXXXXXXX agrees to comply with the HIPAA Security Rule at Subpart C of 45 CFR Part 164 with respect to electronic PHI COUNTY discloses to CONTRACTOR or CONTRACTOR creates, receives, maintains, or transmits on behalf of COUNTY. 4. CONTRACTOR agrees to mitigate, to the extent practicable, any harmful effect that is known to CONTRACTOR of a Use or Disclosure of PHI by CONTRACTOR in violation of the requirements of this Business Associate Contract. 5. XXXXXXXXXX agrees to report to COUNTY immediately any Use or Disclosure of PHI not provided for by this Business Associate Contract of which CONTRACTOR becomes aware. CONTRACTOR must report Breaches of Unsecured PHI in accordance with Paragraph E below and as required by 45 CFR § 164.410. 6. CONTRACTOR agrees to ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of CONTRACTOR agree to the same restrictions and conditions that apply through this Business Associate Contract to CONTRACTOR with respect to such information. 7. CONTRACTOR agrees to provide access, within fifteen (15) calendar days of receipt of a written request by COUNTY, to PHI in a Designated Record Set, to COUNTY or, as directed by COUNTY, to an Individual in order to meet the requirements under 45 CFR § 164.524. If CONTRACTOR maintains an Electronic Health Record with PHI, and an individual requests a copy of such information in an electronic format, CONTRACTOR shall provide such information in an electronic format. 8. CONTRACTOR agrees to make any amendment(s) to PHI in a Designated Record Set that COUNTY directs or agrees to pursuant to 45 CFR § 164.526 at the request of COUNTY or an Individual, within thirty (30) calendar days of receipt of said request by COUNTY. XXXXXXXXXX agrees to notify COUNTY in writing no later than ten (10) calendar days after said amendment is completed. 9. CONTRACTOR agrees to make internal practices, books, and records, including policies and procedures, relating to the use and disclosure of PHI received from, or created or received by CONTRACTOR on behalf of, COUNTY available to COUNTY and the Secretary in a time and manner as determined by COUNTY or as designated by the Secretary for purposes of the Secretary determining COUNTY’S compliance with the HIPAA Privacy Rule. 10. CONTRACTOR agrees to document any Disclosures of PHI COUNTY discloses to CONTRACTOR or CONTRACTOR creates, receives, maintains, or transmits on behalf of COUNTY, and to make information related to such Disclosures available as would be required for COUNTY to respond to a request by an Individual for an accounting of Disclosures of PHI in accordance with 45 CFR § 164.528. 11. CONTRACTOR agrees to provide COUNTY or an Individual, as directed by COUNTY, in a time and manner to be determined by COUNTY, that information collected in accordance with the Agreement, in order to permit COUNTY to respond to a request by an Individual for an accounting of Disclosures of PHI in accordance with 45 CFR § 164.528. 12. XXXXXXXXXX agrees that to the extent CONTRACTOR carries out COUNTY’s obligation under the HIPAA Privacy and/or Security rules CONTRACTOR will comply with the requirements of 45 CFR Part 164 that apply to COUNTY in the performance of such obligation. 13. If CONTRACTOR receives Social Security data from COUNTY provided to COUNTY by a state agency, upon request by COUNTY, CONTRACTOR shall provide COUNTY with a list of all employees, subcontractors and agents who have access to the Social Security data, including employees, agents, subcontractors and agents of its subcontractors. 14. CONTRACTOR will notify COUNTY if CONTRACTOR is named as a defendant in a criminal proceeding for a violation of HIPAA. COUNTY may terminate the Agreement, if CONTRACTOR is found guilty of a criminal violation in connection with HIPAA. COUNTY may terminate the Agreement, if a finding or stipulation that CONTRACTOR has violated any standard or requirement of the privacy or security provisions of HIPAA, or other security or privacy laws are made in any administrative or civil proceeding in which CONTRACTOR is a party or has been joined. COUNTY will consider the nature and seriousness of the violation in deciding whether or not to terminate the Agreement.

Draft better contracts in just 5 minutes Get the weekly Law Insider newsletter packed with expert videos, webinars, ebooks, and more!