Obligations of AACVPR as Business Associate. (a) AACVPR agrees not to Use or Disclose PHI other than as permitted or required by this Agreement or as Required By Law. (b) AACVPR agrees to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to EPHI to prevent Use or Disclosure of PHI by AACVPR or its Subcontractors other than as provided for by this Agreement, including Administrative, Physical, and Technical Safeguards that reasonably and appropriately protect the Confidentiality, Integrity, and Availability of the EPHI that AACVPR creates, receives, maintains or transmits on behalf of Participant. Without limiting the foregoing, AACVPR and/or its Subcontractors will, at its own expense, provide the equipment and software services necessary to reasonably protect and safeguard the PHI consistent with industry standards of similarly situated business associates. (c) AACVPR agrees to promptly report to Participant any Use or Disclosure of PHI not authorized by this Agreement of which it becomes aware and any Security Incident of which it becomes aware. (d) In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), AACVPR agrees to ensure that any Subcontractors that create, receive, maintain, or transmit PHI or EPHI on behalf of AACVPR agree to comply with the same restrictions and conditions that apply to AACVPR through this Agreement, including the implementation of reasonable and appropriate safeguards to protect EPHI and the provisions of Section 7.6 below. (e) AACVPR agrees to make its internal practices, books and records relating to the Use and Disclosure of PHI and EPHI received from, or created or received by AACVPR on behalf of Participant and AACVPR’s Administrative, Physical and Technical Safeguards for EPHI, available to the Secretary of the U.S. Department of Health and Human Services (“Secretary”), during reasonable business hours, for purposes of the Secretary determining Participant’s compliance with the HIPAA Regulations. (f) If PHI provided to AACVPR constitutes a Designated Record Set, AACVPR agrees to provide Participant with timely access to such PHI, upon reasonable advance notice and during regular business hours, or, at Participant’s request, to provide an Individual with access to his or her PHI in order to meet the requirements under 45 CFR 164.524 concerning access of Individuals to Protected Health Information. In the event an Individual contacts AACVPR or its Subcontractor directly about gaining access to his or her PHI, AACVPR will not provide such access but rather will promptly forward such request to Participant. (g) If PHI provided to AACVPR, or to which AACVPR otherwise has access, constitutes a Designated Record Set, AACVPR agrees to make timely amendment(s) to such PHI as Participant may reasonably direct or agree to pursuant to 45 CFR 164.526. In the event an Individual contacts AACVPR or its Subcontractor directly about making amendments to his or her PHI, AACVPR will not make such amendments, but rather will promptly forward such request to Participant. (h) AACVPR agrees to document Disclosures of PHI and information related to such Disclosures as would be required for Participant to respond to a request by an Individual for an accounting of Disclosures of PHI in accordance with 45 CFR 164.528. In addition, AACVPR agrees to provide promptly to Participant or an Individual, upon Participant’s reasonable request, information collected in accordance with this subsection in order to permit Participant to respond to a request by an Individual for an accounting of Disclosures of PHI in accordance with 45 CFR 164.528. Notwithstanding the foregoing, this subsection will not apply with respect to Disclosures made to carry out Participant’s Health Care Operations or the Disclosure of Limited Data Set Information, in accordance with the exceptions to 45 CFR 164.528 as set forth in the HIPAA Regulations. (i) In the event of an unauthorized Use or Disclosure that constitutes a Breach of Unsecured PHI, AACVPR will notify Participant without unreasonable delay but in no event later than sixty (60) calendar days following the Discovery of such Breach. Such notice shall include, to the extent possible, the identification of each individual whose Unsecured PHI has been, or is reasonably believed by AACVPR to have been, accessed, acquired, used, or disclosed during the Breach, and such other available information as is required to be included in the notification to the individual under 45 CFR 164.404(c). (j) To the extent that AACVPR is to carry out one or more of Participant’s obligation(s) under Subpart E of 45 CFR Part 164, AACVPR agrees to comply with the requirements of Subpart E that apply to Participant in the performance of such obligation(s).
Appears in 9 contracts
Samples: Participation Agreement, Participation Agreement, Participation Agreement