Permitted and Required Uses and Disclosures of Phi By Business Associate Sample Clauses

Permitted and Required Uses and Disclosures of Phi By Business Associate. (a) Except as expressly permitted in this Agreement or in writing by Covered Entity, Business Associate shall not divulge, disclose, or communicate PHI to any third party in violation of this Agreement without prior written approval from Covered Entity. (b) Except as otherwise limited in this Agreement, Business Associate may use PHI to provide data aggregation services to Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). (c) Business Associate must comply with 45 C.F.R. § 164, subpart E, and may not use or disclose PHI in violation of 45 C.F.R. § 164, subpart E. (d) Business Associate may use and disclose PHI to report violations of law to appropriate federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1). (e) Business Associate may use and/or disclose PHI for Business Associate’s proper management and administration, provided that: (1) Business Associate obtains reasonable assurances from the person to whom PHI is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the person; and (2) the person notifies Business Associate of any instances of the Breach of PHI for which it is aware. Business Associate also may make disclosures that are required by law. Business Associate’s use of PHI as described in this paragraph is subject to and limited as described in 45 C.F.R. § 164.504(e)(2) and (4). (f) Business Associate may create a Limited Data Set only as necessary and required for the purpose of performing its obligations and services for Covered Entity, provided that Business Associate complies with the provisions of this Agreement. (g) Business Associate shall disclose PHI when required by the Secretary to investigate or determine Covered Entity or Business Associate’s compliance with 45 C.F.R. § 164, subpart E. (h) Business Associate shall provide access to PHI in a designated record set as required under 45 C.F.R. § 164.524. (i) Business Associate shall, upon request by Covered Entity or Individual, disclose PHI to Covered Entity, Individual, or Individual’s designee, as necessary to satisfy Covered Entity’s obligations under 45 C.F.R. §§ 164.502(a)(4)(ii), 164.524(c)(2)(ii), and 164.524(c)(3)(ii) with respect to an Individual’s request.
Permitted and Required Uses and Disclosures of Phi By Business Associate. Business Associate may use or disclose PHI solely (a) as necessary to provide the Services to Covered Entity and in compliance with each applicable requirement of 45 CFR §164.504(e), (b) as Required by Law, or (c) as expressly otherwise authorized under this Agreement or by Covered Entity, in writing and prior to any such use. Business Associate shall not use or disclose PHI for any other purpose or in any other manner.
Permitted and Required Uses and Disclosures of Phi By Business Associate 

Related to Permitted and Required Uses and Disclosures of Phi By Business Associate

  • Permitted Uses and Disclosures of Phi by Business Associate Except as otherwise indicated in this Agreement, Business Associate may use or disclose PHI, inclusive of de-identified data derived from such PHI, only to perform functions, activities or services specified in this Agreement on behalf of DHCS, provided that such use or disclosure would not violate HIPAA or other applicable laws if done by DHCS.

  • Permitted Uses and Disclosures by Business Associate Except as otherwise limited by this Agreement, Business Associate may make any uses and disclosures of Protected Health Information necessary to perform its services to Covered Entity and otherwise meet its obligations under this Agreement, if such use or disclosure would not violate the Privacy Rule if done by Covered Entity. All other uses or disclosures by Business Associate not authorized by this Agreement or by specific instruction of Covered Entity are prohibited.

  • Permitted Uses and Disclosure by Business Associate (1) General Use and Disclosure Provisions Except as otherwise limited in this Section of the Contract, Business Associate may use or disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in this Contract, provided that such use or disclosure would not violate the HIPAA Standards if done by Covered Entity or the minimum necessary policies and procedures of the Covered Entity.

  • Permitted Uses and Disclosures of PHI and the third party notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

  • PERMITTED USES AND DISCLOSURES BY CONTRACTOR Except as otherwise limited in this Schedule, Contractor may use or disclose Protected Health Information to perform functions, activities, or services for, or on behalf of, County as specified in the Agreement; provided that such use or disclosure would not violate the Privacy Rule if done by County.

  • Permitted Uses and Disclosures i. Business Associate shall use and disclose PHI only to accomplish Business Associate’s obligations under the Contract. i. To the extent Business Associate carries out one or more of Covered Entity’s obligations under Subpart E of 45 C.F.R. Part 164, Business Associate shall comply with any and all requirements of Subpart E that apply to Covered Entity in the performance of such obligation. ii. Business Associate may disclose PHI to carry out the legal responsibilities of Business Associate, provided, that the disclosure is Required by Law or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that: A. the information will remain confidential and will be used or disclosed only as Required by Law or for the purpose for which Business Associate originally disclosed the information to that person, and; B. the person notifies Business Associate of any Breach involving PHI of which it is aware. iii. Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity. Business Associate may de-identify any or all PHI created or received by Business Associate under this Agreement, provided the de-identification conforms to the requirements of the HIPAA Rules.

  • Permitted and Required Uses/Disclosures of PHI 3.1 Except as limited in this Agreement, Business Associate may use or disclose PHI to perform Services, as specified in the underlying grant or contract with Covered Entity. The uses and disclosures of Business Associate are limited to the minimum necessary, to complete the tasks or to provide the services associated with the terms of the underlying agreement. Business Associate shall not use or disclose PHI in any manner that would constitute a violation of the Privacy Rule if used or disclosed by Covered Entity in that manner. Business Associate may not use or disclose PHI other than as permitted or required by this Agreement or as Required by Law. 3.2 Business Associate may make PHI available to its employees who need access to perform Services provided that Business Associate makes such employees aware of the use and disclosure restrictions in this Agreement and binds them to comply with such restrictions. Business Associate may only disclose PHI for the purposes authorized by this Agreement: (a) to its agents and Subcontractors in accordance with Sections 9 and 17 or, (b) as otherwise permitted by Section 3. 3.3 Business Associate shall be directly liable under HIPAA for impermissible uses and disclosures of the PHI it handles on behalf of Covered Entity, and for impermissible uses and disclosures, by Business Associate’s Subcontractor(s), of the PHI that Business Associate handles on behalf of Covered Entity and that it passes on to Subcontractors.

  • Prohibited Uses and Disclosures BA shall not use or disclose PHI other than as permitted or required by the Contract and Addendum, or as required by law. BA shall not use or disclose Protected Information for fundraising or marketing purposes. BA shall not disclose Protected Information to a health plan for payment or health care operation purposes if the patient has requested this special restriction, and has paid out of pocket in full for the health care item or service to which the PHI solely relates [42 U.S.C. Section 17935(a) and 45 C.F.R. Section 164.522(a)(vi)]. BA shall not directly or indirectly receive remuneration in exchange for Protected Information, except with the prior written consent of CE and as permitted by the HITECH Act, 42 U.S.C. Section 17935(d)(2), and the HIPAA regulations, 45 C.F.R. Section 164.502(a)(5)(ii); however, this prohibition shall not affect payment by CE to BA for services provided pursuant to the Contract.

  • Permitted Use and Disclosures Each Party hereto may use or disclose Information disclosed to it by the other Party to the extent such use or disclosure: (i) is reasonably necessary in complying with Applicable Laws or otherwise submitting information to tax or other governmental authorities, (ii) is provided by the receiving Party to Third Parties, on a strictly as-needed basis, for consulting services, conducting Preclinical or Clinical Development, CMC/Process Development, Manufacturing, external testing, market research, or otherwise exercising its rights or performing its obligations hereunder; provided, that such Third Parties are obligated to maintain the confidentiality of such other Party’s Information as set forth herein for the benefit of such other Party for a period of at least the term of the agreement with such Third Party and for a period of *** thereafter; (iii) is included in submissions by the receiving Party to Governmental Authorities to facilitate the issuance of approvals for NDAs and NDA Equivalents for the Product, provided that reasonable measures shall be taken to assure confidential treatment of such Information; or (iv) is to Third Parties in connection with a receiving Party’s efforts to secure financing or enter into strategic partnerships, provided such Information is disclosed only on a need-to-know basis and under confidentiality provisions at least as stringent as those in this Agreement. Additionally, Bayer may disclose to Mitsui any Information received from Licensee hereunder; provided, that such disclosure is reasonably considered by Bayer to be necessary to comply with the terms and conditions of the Patent License Agreement; and further provided, that Mitsui is obligated to maintain the confidentiality of Licensee’s Information as set forth herein for the benefit of Licensee. Notwithstanding the foregoing, if a receiving Party is required to make any such disclosure of the disclosing Party’s confidential Information, other than pursuant to a confidentiality agreement, the receiving Party will give reasonable advance notice to the disclosing Party of such disclosure and, save to the extent inappropriate in the case of patent applications, will use its reasonable efforts to secure confidential treatment of such Information prior to its disclosure (whether through protective orders or otherwise).

  • OBLIGATIONS AND ACTIVITIES OF CONTRACTOR AS BUSINESS ASSOCIATE 1. CONTRACTOR agrees not to use or further disclose PHI COUNTY discloses to CONTRACTOR other than as permitted or required by this Business Associate Contract or as required by law. 2. XXXXXXXXXX agrees to use appropriate safeguards, as provided for in this Business Associate Contract and the Agreement, to prevent use or disclosure of PHI COUNTY discloses to CONTRACTOR or CONTRACTOR creates, receives, maintains, or transmits on behalf of COUNTY other than as provided for by this Business Associate Contract. 3. XXXXXXXXXX agrees to comply with the HIPAA Security Rule at Subpart C of 45 CFR Part 164 with respect to electronic PHI COUNTY discloses to CONTRACTOR or CONTRACTOR creates, receives, maintains, or transmits on behalf of COUNTY. 4. CONTRACTOR agrees to mitigate, to the extent practicable, any harmful effect that is known to CONTRACTOR of a Use or Disclosure of PHI by CONTRACTOR in violation of the requirements of this Business Associate Contract. 5. XXXXXXXXXX agrees to report to COUNTY immediately any Use or Disclosure of PHI not provided for by this Business Associate Contract of which CONTRACTOR becomes aware. CONTRACTOR must report Breaches of Unsecured PHI in accordance with Paragraph E below and as required by 45 CFR § 164.410. 6. CONTRACTOR agrees to ensure that any Subcontractors that create, receive, maintain, or transmit PHI on behalf of CONTRACTOR agree to the same restrictions and conditions that apply through this Business Associate Contract to CONTRACTOR with respect to such information. 7. CONTRACTOR agrees to provide access, within fifteen (15) calendar days of receipt of a written request by COUNTY, to PHI in a Designated Record Set, to COUNTY or, as directed by COUNTY, to an Individual in order to meet the requirements under 45 CFR § 164.524. If CONTRACTOR maintains an Electronic Health Record with PHI, and an individual requests a copy of such information in an electronic format, CONTRACTOR shall provide such information in an electronic format. 8. CONTRACTOR agrees to make any amendment(s) to PHI in a Designated Record Set that COUNTY directs or agrees to pursuant to 45 CFR § 164.526 at the request of COUNTY or an Individual, within thirty (30) calendar days of receipt of said request by COUNTY. XXXXXXXXXX agrees to notify COUNTY in writing no later than ten (10) calendar days after said amendment is completed. 9. CONTRACTOR agrees to make internal practices, books, and records, including policies and procedures, relating to the use and disclosure of PHI received from, or created or received by CONTRACTOR on behalf of, COUNTY available to COUNTY and the Secretary in a time and manner as determined by COUNTY or as designated by the Secretary for purposes of the Secretary determining COUNTY’S compliance with the HIPAA Privacy Rule. 10. CONTRACTOR agrees to document any Disclosures of PHI COUNTY discloses to CONTRACTOR or CONTRACTOR creates, receives, maintains, or transmits on behalf of COUNTY, and to make information related to such Disclosures available as would be required for COUNTY to respond to a request by an Individual for an accounting of Disclosures of PHI in accordance with 45 CFR § 164.528. 11. CONTRACTOR agrees to provide COUNTY or an Individual, as directed by COUNTY, in a time and manner to be determined by COUNTY, that information collected in accordance with the Agreement, in order to permit COUNTY to respond to a request by an Individual for an accounting of Disclosures of PHI in accordance with 45 CFR § 164.528. 12. XXXXXXXXXX agrees that to the extent CONTRACTOR carries out COUNTY’s obligation under the HIPAA Privacy and/or Security rules CONTRACTOR will comply with the requirements of 45 CFR Part 164 that apply to COUNTY in the performance of such obligation. 13. If CONTRACTOR receives Social Security data from COUNTY provided to COUNTY by a state agency, upon request by COUNTY, CONTRACTOR shall provide COUNTY with a list of all employees, subcontractors and agents who have access to the Social Security data, including employees, agents, subcontractors and agents of its subcontractors. 14. CONTRACTOR will notify COUNTY if CONTRACTOR is named as a defendant in a criminal proceeding for a violation of HIPAA. COUNTY may terminate the Agreement, if CONTRACTOR is found guilty of a criminal violation in connection with HIPAA. COUNTY may terminate the Agreement, if a finding or stipulation that CONTRACTOR has violated any standard or requirement of the privacy or security provisions of HIPAA, or other security or privacy laws are made in any administrative or civil proceeding in which CONTRACTOR is a party or has been joined. COUNTY will consider the nature and seriousness of the violation in deciding whether or not to terminate the Agreement.