Reporting Obligations - Breach Notification Sample Clauses

Reporting Obligations - Breach Notification. Sub-Business Associate shall report to Business Associate in writing any use or disclosure of PHI of which it becomes aware that is not in accordance with this Agreement or the Privacy Rule, including Breaches of Unsecured PHI, as required by 45 C.F.R. § 164.410, and any Security Incidents, without unreasonable delay and in no case later than thirty (30) calendar days after the discovery of any such use, disclosure, Breach, or Security Incident. Upon discovery of a Breach or Security Incident, Sub-Business Associate will undertake a documented risk assessment in accordance with the Breach Response Rule to determine whether the acquisition, access, use or disclosure of the PHI at issue is likely to compromise the affected PHI. Sub-Business Associate shall make this determination in coordination and consultation with Business Associate. Sub-Business Associate shall make and retain records of such determinations, including the basis for any determination that an unauthorized use or disclosure of PHI is not a Breach that requires notification of affected individuals, regulators and others, and shall provide the documents supporting such determination to Business Associate if requested. Sub-Business Associate’s determination that the Breach is likely to result in low probability of compromise of the affected PHI is subject to review and approval by Business Associate. If Business Associate disagrees with Sub-Business Associate’s determination of low probability of compromise, Sub-Business Associate shall comply with Business Associate’s determination and comply with the requirements of this Agreement consistent with such determination. Sub-Business Associate shall mitigate, to the extent commercially practicable, any harmful effect known to Sub-Business Associate arising from a use or disclosure of PHI by Sub-Business Associate in violation of the requirements of this Agreement (including a Breach of Unsecured PHI) a Security Incident; however, nothing in this Section will impose an obligation on Sub-Business Associate to notify the Covered Entity or Individual in question directly of such Breach, Security Incident, or other disclosure, and the Business Associate undertakes to provide such notice to that Covered Entity or Individual as required by law.
AutoNDA by SimpleDocs

Related to Reporting Obligations - Breach Notification

  • Data Breach Notification Seller will promptly notify Buyer of any actual or potential exposure or misappropriation of Buyer data ("breach") that comes to Seller's attention. Seller will cooperate with Xxxxx and in investigating any such breach, at Xxxxxx's expense. Seller will likewise cooperate with Buyer and, as applicable, with law enforcement agencies in any effort to notify injured or potentially injured parties, and such cooperation will be at Seller's expense, except to the extent that the breach was caused by Xxxxx. The remedies and obligations set forth in this subsection are in addition to any others Buyer may have, including, but not limited to, any requirements in the “Privacy, Confidentiality, and Security” provisions of this Agreement.

  • Security Breach Notification In addition to the information enumerated in Article V, Section 4(1) of the DPA Standard Clauses, any Security Breach notification provided by the Provider to the LEA shall include:

  • Breach Notification a. In the event of a Breach of unsecured PHI or disclosure that compromises the privacy or security of PHI obtained from DSHS or involving DSHS clients, Business Associate will take all measures required by state or federal law.

  • Security Breach Notifications Notice must be given by the Subrecipient to anyone whose PSCI could have been breached in accordance with HIPAA, the Information Practices Act of 1977, and State policy.

  • COMPLIANCE WITH BREACH NOTIFICATION AND DATA SECURITY LAWS Contractor shall comply with the provisions of the New York State Information Security Breach and Notification Act (General Business Law § 899-aa and State Technology Law § 208) and commencing March 21, 2020 shall also comply with General Business Law § 899-bb.

  • Personal Data Breach Notification SAP will notify Customer without undue delay after becoming aware of any Personal Data Breach and provide reasonable information in its possession to assist Customer to meet Customer’s obligations to report a Personal Data Breach as required under Data Protection Law. SAP may provide such information in phases as it becomes available. Such notification shall not be interpreted or construed as an admission of fault or liability by SAP.

  • Security Breach Notice and Reporting The Contractor shall have policies and procedures in place for the effective management of Security Breaches, as defined below, which shall be made available to the State upon request. In addition to the requirements set forth in any applicable Business Associate Agreement as may be attached to this Contract, in the event of any actual security breach or reasonable belief of an actual security breach the Contractor either suffers or learns of that either compromises or could compromise State Data (a “Security Breach”), the Contractor shall notify the State within 24 hours of its discovery. Contractor shall immediately determine the nature and extent of the Security Breach, contain the incident by stopping the unauthorized practice, recover records, shut down the system that was breached, revoke access and/or correct weaknesses in physical security. Contractor shall report to the State: (i) the nature of the Security Breach; (ii) the State Data used or disclosed; (iii) who made the unauthorized use or received the unauthorized disclosure; (iv) what the Contractor has done or shall do to mitigate any deleterious effect of the unauthorized use or disclosure; and (v) what corrective action the Contractor has taken or shall take to prevent future similar unauthorized use or disclosure. The Contractor shall provide such other information, including a written report, as reasonably requested by the State. Contractor shall analyze and document the incident and provide all notices required by applicable law. In accordance with Section 9 V.S.A. §2435(b)(3), the Contractor shall notify the Office of the Attorney General, or, if applicable, Vermont Department of Financial Regulation (“DFR”), within fourteen (14) business days of the Contractor’s discovery of the Security Breach. The notice shall provide a preliminary description of the breach. The foregoing notice requirement shall be included in the subcontracts of any of Contractor’s subcontractors, affiliates or agents which may be “data collectors” hereunder. The Contractor agrees to fully cooperate with the State and assume responsibility at its own expense for the following, to be determined in the sole discretion of the State: (i) notice to affected consumers if the State determines it to be appropriate under the circumstances of any particular Security Breach, in a form recommended by the AGO; and (ii) investigation and remediation associated with a Security Breach, including but not limited to, outside investigation, forensics, counsel, crisis management and credit monitoring, in the sole determination of the State. The Contractor agrees to comply with all applicable laws, as such laws may be amended from time to time (including, but not limited to, Chapter 62 of Title 9 of the Vermont Statutes and all applicable State and federal laws, rules or regulations) that require notification in the event of unauthorized release of personally-identifiable information or other event requiring notification. In addition to any other indemnification obligations in this Contract, the Contractor shall fully indemnify and save harmless the State from any costs, loss or damage to the State resulting from a Security Breach or the unauthorized disclosure of State Data by the Contractor, its officers, agents, employees, and subcontractors.

  • FAILURE TO MEET REPORTING OBLIGATIONS 14.1 Should the Licensee fail to furnish the Licence Parameter Return referred to in clause 13.1 above within the required time period, SAMRO will be entitled to invoice the Licensee based on the licence parameters upon which the preceding invoice was based.

  • Reporting Obligations As long as any Holder shall own Registrable Securities, the Company, at all times while it shall be a reporting company under the Exchange Act, covenants to file timely (or obtain extensions in respect thereof and file within the applicable grace period) all reports required to be filed by the Company after the date hereof pursuant to Sections 13(a) or 15(d) of the Exchange Act and to promptly furnish the Holders with true and complete copies of all such filings. The Company further covenants that it shall take such further action as any Holder may reasonably request, all to the extent required from time to time to enable such Holder to sell shares of Common Stock held by such Holder without registration under the Securities Act within the limitation of the exemptions provided by Rule 144 promulgated under the Securities Act (or any successor rule promulgated thereafter by the Commission), including providing any legal opinions. Upon the request of any Holder, the Company shall deliver to such Holder a written certification of a duly authorized officer as to whether it has complied with such requirements.

  • Termination of Reporting Obligation The Servicer’s obligation to deliver or cause the delivery of reports under this Section 3.5 will terminate on payment in full of the Notes.

Time is Money Join Law Insider Premium to draft better contracts faster.