Egnyte Hipaa Business Associate Agreement Page 2

ADVERTISEMENT

HIPAA Business Associate Agreement
“Protected Health Information” or “PHI” has the same meaning as the term “protected health
information” as defined in 45 CFR 164.103, and any amendments thereto, limited to the
information Business Associate has access to, receives from, and maintains for or on behalf of
Covered Entity. PHI includes Electronic Protected Health Information.
“Electronic Protected Health Information” or “EPHI” means the subset of PHI that is
transmitted by electronic media or maintained in electronic media.
Business Associate acknowledges and agrees that all Protected Health Information is subject to
this BAA.
2. CONFIDENTIALITY REQUIREMENTS.
a. Business Associate agrees:
i.
to use or disclose any Protected Health Information solely: (A) for meeting its
obligations as set forth in the Services Agreement, or (B) as Required By Law.
ii.
upon termination of this BAA, the Services Agreement, or upon request of Covered
Entity, whichever occurs first, if feasible, to return or destroy all Protected Health Information
received from Covered Entity that Business Associate still maintains in any form and retain no
copies of such information, or if such return or destruction is not feasible, to extend the
protections of this BAA to the information and limit further uses and disclosures to those
purposes that make the return or destruction of the information not feasible; and
iii.
to ensure that its agents (including subcontractors) to whom it provides Protected
Health Information agree to the same restrictions and conditions that apply to Business
Associate with respect to such Information. In addition, Business Associate agrees to take
reasonable steps to ensure that its employees’ actions or omissions do not cause Business
Associate to breach the terms of this BAA.
b. Notwithstanding the prohibitions set forth in this BAA, Business Associate may use and
disclose Protected Health Information if necessary, for the proper management and
administration of Business Associate or to carry out the legal responsibilities of Business
Associate, provided that as to any such disclosure, the following requirements are met:
i.
the disclosure is Required By Law; or
ii.
Business Associate obtains reasonable assurances from the person to whom the
Information is disclosed that it will be held confidentially and used or further disclosed only as
Required by Law or for the purpose for which it was disclosed to the person, and the person
notifies Business Associate of any instances of which it is aware in which the confidentiality of
the Information has been breached.
2

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Business
Go
Page of 6