Hipaa Business Associate Agreement Page 3

ADVERTISEMENT

that it will remain confidential and be used or further disclosed only as Required by Law
or for the purpose for which it was disclosed to the person, and the person notifies
Business Associate of any instances of which it is aware in which the confidentiality of
the information has been breached.
3.
Obligations of Business Associate.
a.
Use and Disclosure. Business Associate agrees to not use or further disclose PHI other than as
permitted or required by this Agreement or as Required by Law.
b.
Appropriate Safeguards. Business Associate shall use appropriate safeguards to prevent use or
disclosure of PHI other than as provided for by this Agreement.
c.
Reporting of Improper Use or Disclosure. Business Associate shall report to CompBenefits any
use or disclosure of PHI not provided for by this Agreement.
d.
Mitigation. Business Associate shall mitigate, to the extent practicable, any harmful effect that is
known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of
this Agreement.
e.
Business Associate’s Agents.
Business Associate shall ensure that any agent, including a
subcontractor, to whom it provides PHI received from, or created or received by Business Associate on behalf of
CompBenefits, agrees to the same restrictions and conditions that apply through this Agreement to Business
Associate with respect to such PHI.
f.
Access to PHI. Business Associate shall provide access, at the request of CompBenefits, and in
the time and manner designated by CompBenefits, to PHI in a Designated Record Set, to CompBenefits or, as
directed by CompBenefits, to an Individual in order to meet the requirements under 45 CFR Section 164.524, if
applicable.
g.
Amendment of PHI. Business Associate shall make any amendment(s) to PHI in a Designated
Record Set that the CompBenefits directs or agrees to pursuant to 45 CFR Section 164.526 at the request of
CompBenefits or an Individual, and in the time and manner designated by the CompBenefits, if applicable.
h.
Documentation of Disclosures. Business Associate agrees to document such disclosures of PHI
and information related to such disclosures as would be required for CompBenefits to respond to a request by an
Individual for an accounting of disclosures of PHI in accordance with 45 CFR Section 164.528.
i.
Accounting of Disclosures.
Business Associate agrees to provide to CompBenefits or an
Individual, in time and manner designated by CompBenefits, information collected in accordance with Section 3(e)
of this Agreement, to permit CompBenefits to respond to a request by an Individual for an accounting of disclosures
of PHI in accordance with 45 CFR Section 164.528.
j.
Governmental Access to Records. Business Associate shall make its internal practices, books and
records relating to the use and disclosure of PHI received from, or created or received by Business Associate on
behalf of, CompBenefits available to CompBenefits or, at the request of CompBenefits, to the Secretary for purposes
of the Secretary determining CompBenefits’ compliance with the Privacy Rule.
k.
Minimum Necessary Standard. In the performance of functions and activities on CompBenefits’
behalf, Business Associate agrees to use, disclose or request only the minimum amount of PHI necessary to
accomplish the purpose of the use, disclosure or request.
l.
Chain of Trust. To the extent PHI is electronically exchanged between CompBenefits and
Business Associate, Business Associate shall provide and maintain the equipment, software, services and testing
necessary to effectively, reliably and confidentially transmit, process, convert, receive and interchange PHI in
accordance with this Agreement and HIPAA Regulations.
Further, Business Associate shall ensure that all
electronic transmissions of PHI shall be protected from improper disclosure. In the event that such transmissions
travel across lines of communication where both ends are not under the control of CompBenefits, Business
Associate agrees to use appropriate authentication and encryption systems designed to protect PHI from improper
disclosures.
4.
Obligations of CompBenefits.
BizAssoc.HIPAA-Agreement
3

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Business
Go
Page of 5