Loading...
HomeMy WebLinkAboutRESOLUTION NO. 2013-68 SOLUTION NO. 20 3-68 A RESOLUTION TO ENTER INTO A BUSINESS ASSOICATE AGREEMENT WHEREAS, the City of Fairfax uses Jim Schiltz, of Group Benefits Design a division of PDCM Insurance, as its health insurance agent; and WHEREAS, a Business Associate Agreement between the City of Fairfax and Group Benefits Design a division of PDCM Insurance is required to comply with the privacy and security regulations issued by the United. States Department of Health and Human Services under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the security provisions of the American.Recovery and.Reinvestment Act of 21109 ("ARRA"), as amended. NOW, THEREFORE,BE IT RESOLVED,that the City of Fairfax agrees to enter into the attached Business Associate Agreement with Group Benefits Design a division of PDCM Insurance. BE IT FURTHER RESOLVED, by the City Council of the City of Fairfax, Iowa, that the Mayor and City Clerk are hereby directed to certify this resolution of approval and the Mayor and City Clerk are authorized to sign the attached Business Associate Agreement with Group Benefits Design a division of PDCM Insurance. i Passed and approved this Bit'day of October, 2013. AYES: Beer, Frieden, Otto, Magers, and Wainwright NAYS: None 1,0 Jasgari Labe, Mayor I i dM / if r`{ '•7/ +pr,`4� C is Stimson, City Clerk/Treasurer • r' o CJ BUSINESS ASSOCIATE NGREEMENT This Business Associate Agreement ("Agreement") by and between City of Fairfax ("Covered Entity") and Group Benefits Design a division of PDCM Insurance ("Business Associate"), is entered into on this 8th day of October, 2013 ("Effective Date"), for the purposes of complying, with the privacy and security regulations issued by the United States Department of Health and Human Services under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the security provisions of the American Recovery and Reinvestment Act of 2009 ('ARRA"), as amended. Covered Entity and Business Associate are collectively referred to as the"Parties." WITNESSET11 WHEREAS, Covered Entity is a covered entity as such terin is defined under HIPAA and as such is required to comply with the requirements thereof regarding the confidentiality and privacy of Protected Health Information; and WHEREAS, Business Associate performs functions or activities on behalf of, or provides certain services to, Covered Entity that may involve access by Business Associate to Protected Health Information; WHEREAS, by providing the services and representation, Business Associate may become a business associate of Covered Entity as such term is defined under HIPAA at 45 CFR Section 160,103; and WHEREAS, Business Associate acknowledges that Business Associate is directly subject to the requirements of 45 C.F.,R §§ 164.308, 164.310, 164.312, arid 164,316 of the HIPAA regulations, as amended; NOW THEREFORE, in consideration of the mutual covenants, promises and agreements contained herein, the,Parties hereto agree as follows: I. Definitions. A. Catch-all definition: I The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation,Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information ("PI-11"), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use. B. Specific definitions: I. "Business Associate" shall generally have the same meaning as the term "business associate" at 45 CFR 160.103. 1 2. "Covered Entity" shall generally have the same meaning as the term "covered entity" at 45 CFR 1,60.103. 3. "HIPAA Rules" shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 16O and Part 164. Obligations and Activities of Business Associate. Business Associate agrees to: A. Not use or disclose PHI other than as permitted or required by the Agreement or as required by law; B. Use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 to prevent use or disclosure of PHI other than as provided for by the Agreement, In doing so, Business Associate shall implement administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the PHI that it creates, receives, maintains or transmits on behalf of Covered Entity. Business Associate covenants that such safeguards shall include, without limitation, implementing written policies and procedures in compliance with HIPAA and ARRA, conducting a security risk assessment, and training Business Associate employees who will have access to PHI with respect to the policies and procedures required by HIPAA and ARRA; C. Report to Covered Entity any use or disclosure of PHI not provided for by the Agreement of which it becomes aware, including breaches of'unsecured PHI as required by 45 CFR 164.410, and any security incident of which it becomes aware; D. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to the business associate with respect to such information; E. Abide by the following with regard to access of individuals to PHI: I. In order to allow Covered Entity to respond to a request by an Individual for access pursuant to 45 C.F.R. Section 164.524, Business Associate, within five (5) business days of a written request by Covered Entity for access to PHI about an Individual contained in a Designated Record Set, shall make available to Covered Entity such PHI for so long as such information is maintained in the Designated Record Set. If PHI is stored offsite, PHI shall be made available to Covered Entity within twenty (20) days of Business Associate's receipt of written request. 2. In the event any Individual requests access to PHI directly from Business Associate, Business Associate shall forward such request to Covered Entity within -five (5) business days. Before forwarding any PHI to Covered Entity, Business Associate shall indicate in the Designated 2 Record Set any material it deems unavailable to the Individual, pursuant to 45 C.F.R. Section 164.524. 3. Any denial of access to PHI determined by Covered Entity pursuant to 45 C.F.R. Section 164,524, and conveyed to Business Associate by Covered Entity, shall be the responsibility of Covered Entity, including resolution or reporting of all appeals and/or complaints arising from denials. F. Abide by the following with regard to amendment of information: 1. In order to allow Covered Entity to respond to a request by an Individual for an amendment pursuant to 45 C.F.R. Section 164.526, Business Associate shall, within live (5) business days of a written request by Covered Entity for an amendment to PHI about an Individual contained in a Designated Record Set, make available to Covered Entity such PHI for so long as such information is maintained in the Designated Record Set. 2. In the event any Individual requests amendment of PHI directly from Business Associate, Business Associate shall forward such request to Covered Entity within five (5) business days of the receipt of the request. Before forwarding any PHI to Covered Entity, Business Associate shall indicate in the Designated Record Set any material it deems unavailable to the Individual pursuant to 45 C.F.R. Section 164.526. 3. Any denial of amendment to PHI determined by Covered Entity pursuant to 45 C.F.R. Section 164.526 (arid conveyed to Business Associate by Covered Entity) shall be the responsibility of Covered Entity, including resolution or reporting of all appeals and/or complaints arising from denials. 4. Within ten(10) business days of receipt of a request from Covered Entity to amend an Individual's PHI in the Designated Record Set, Business Associate shall incorporate any approved amendments, statements of disagreement, and/or rebuttals into its Designated Record Set as required by 45 C.F.R. Section, 1,64.526. G. Abide by,the following with regard,to accounting of disclosures: I In order to allow Covered Entity to respond to a request by an Individual for an accounting pursuant to 45 C.F.R. Section 164.528, Business Associate shall, within five (5) business days of a written request by Covered Entity for an accounting of disclosures of PHI about an Individual,make available to Covered Entity such PHI. 2. At a minimum, Business Associate shall provide Covered Entity with the following information: (i) the date of the disclosure; (ii) the name of the: entity or person who received the PHI, and if known, the address of such entity or person; (iii) a brief description of the PHI disclosed; and (iv) a brief statement of the purpose of such disclosure. 3 3. In the event any Individual, requests an accounting of disclosure of PHI directly from Business Associate, Business Associate shall forward such request to Covered Entity within five (5) business days. 4. Business Associate shall implement an appropriate recordkeeping process to enable it to comply with the requirements of this Agreement. 5. Business Associate shall support Covered Entity in a manner that enables Covered Entity to meet its obligations under 45 C.F.R. Section 164.528. H. To the extent the Business Associate is to carry out one or more of Covered Entity's obligatio,n(s) under Subpart E of 45 CFR Part 164 ("Subpart E"), comply with the requirement-, of Subpart E that apply to the Covered Entity in the performance of such obligation(s); and I. Permit the Secretary and other regulatory and accreditation authorities to audit Business Associate's internal practices, books and records at reasonable times as they pertain to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity in order to ensure that Covered Entity is in compliance with the requirements of the Privacy Rule. Permitted Uses and Disclosures by Business Associate. A. Business Associate warrants that Business Associate, its agents, and any subcontractors shall not use or disclose PHI other than as permitted.or required by this Agreement or required by law and shall not use or disclose PHI in any manner that violates applicable federal and state laws or would violate such laws if used or disclosed in such manner by Covered Entity. 1. Subject to the restrictions set forth in the previous paragraph and throughout this Agreement, Business Associate may use the information received from Covered Entity as required by law. B. Business Associate agrees to make uses and disclosures and requests for PHI consistent with Covered Entity's minimum necessary policies and procedures. Covered Entity further understands and acknowledges that, to the extent Business Associate requests that Covered Entity disclose PHI to Business Associate, such request is only for the minimum necessary PHI for the accomplishment of the Business Associate's purpose. C, Business Associate may not use or disclose PHI in a manner that would violate Subpart E if done by Covered Entity, except for the specific uses and disclosures set forth below., D. Business Associate may use PHI for the proper management and administration of the Business,Associate or to carry out its legal responsibilities, E. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible tinder Subpart E if done by Covered Entity. 4 IV. Obligations of Covered Entity. A. Covered Entity warrants that Covered Entity, its directors, officers, subcontractors, employees, affiliates, agents, and representatives; (i) shall comply with the Privacy Rule in its use or disclosure of PHI; (ii) shall not use or disclose PHI in any manner that violates applicable federal and state laws; (iii) shall not request Business Associate to use or disclose PHI in any manner that violates applicable federal and state laws if such use or disclosure were done by Covered Entity; and (iv) may request Business Associate to disclose PHI directly to another party only for the purposes allowed by the Privacy Rule. B. Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices of Covered Entity in accordance with 45 CFR Section 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI, C. Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI. D. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered entity has agreed to in accordance with 45 CFR Section 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI. V. Disclosure to Third Parties. A. Business Associate shall obtain and maintain an agreement with each subcontractor and agent that has or will have access to PHI, which is received from or created or received by Business Associate on behalf of Covered Entity, pursuant to which agreement such subcontractor, and agent agrees to be bound by the same restrictions, terms, and conditions that apply to Business Associate pursuant to the Agreement with respect to such PHI. B. Business Associate shall also (i) obtain reasonable assurances from the person to whom the PHI is disclosed that it will be held confidentially and used or further disclosed only as Required by Law or :for the purpose for which it was disclosed and (ii) obligate such person to notify Business Associate of any instances of which it is aware in which the confidentiality of the PHI has been breached, I. Reporting of Breaches and Improper Disclosures. A. The term "breach" means the acquisition, access, use, or disclosure of PHI in a manner not permitted under Subpart E which compromises the security or privacy of such information. The following situations are excluded from the definition of "breach:" 1. Any unintentional acquisition, access, or use of PRI by a workforce member or person acting under the authority of Covered Entity or 5 Business Associate, if such, acquisition, access, or use was made in good 11dth and within the scope of authority and does not result in,further use or disclosure in a manner not permitted under Subpart E. 2. Any inadvertent disclosure by a person who is authorized to access PHI at either Covered Entity or Business Associate to another person authorized to access PHI at the same Covered Entity or Business Associate (or organized health care arrangement in which the Covered Entity participates), and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted under Subpart E. 3. A disclosure of PHI where a Covered Entity or Business Associate has a good faith belief that an -unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information. B. Except as provided in paragraph IV(A), an acquisition, access, use, or disclosure of PHI in a manner not permitted under Subpart E is presumed to be a breach unless the Covered Entity or Business Associate, as applicable, can demonstrate that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors: 1. The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; 2. The unauthorized person who used the PI11 or to whom the disclosure was made; 3. Whether the PHI was actually acquired or viewed; and 4. The extent to which the risk to the PHI has been mitigated. C. The term "unsecured" shall mean PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary from time to time. D. In the event of a Breach of any Unsecured PHI that Business Associate accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds or uses on behalf of Covered Entity, Business Associate shall report such Breach to Covered Entity within ten (10) days. E. Notice of a Breach shall include the identification of each individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, or disclosed during the Breach. At the request of Covered Entity, Business Associate shall identify: the date of the Breach, the scope of the Breach, the Business Associate's response to the Breach and the identification of the party responsible for causing the Breach, if known. F. In the event of any use or disclosure that does not constitute a Breach, but that is an unauthorized or improper use or disclosure of any PHI under this Agreement 6 or applicable laws, Business Associate shall report to Covered Entity such unauthorized or improper use or disclosure as soon as practicable, but in no event later than five (5) business days of the date on which Business Associate becomes aware of such use or disclosure. In such event, Business Associate shall, in consultation with Covered Entity, mitigate, to the extent practicable, any harmful effect that is known to Business Associate of such unauthorized or improper use disclosure. VII, Term and Termination. A. This Agreement shall become effective on the Effective Date set forth above and shall terminate upon the termination or expiration of the Service Agreement and when. all PHI provided by either party to the other, or created or received by Business Associate on behalf of Covered Entity is, in accordance with Section VIII below, destroyed or returned to Covered Entity or, if it is not feasible to return or destroy PHI, protections are extended to such information, in accordance with the terms of this Agreement. B. Where either Party has knowledge of a material breach by the other Party and cure is possible,the non-breaching Party shall provide the breaching Party with an opportunity to cure. Where said breach is not cured within ten (10) business days, of the breaching Party's receipt of notice from the non-breaching Party of said breach, the non-breaching Party shall terminate this Agreement. When neither cure not termination is feasible, the non-breaching Party shall report the violation. to the Secretary. VIII. Return/Destruction of PHI Upon Termination. A. Upon termination of this Agreement for any reason, Business Associate, with respect to PHI received from Covered Entity, or created, maintained, or received by Business Associate on behalf of Covered Entity, shall: 1. Retain only that PHI which is necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities; 2. Return to Covered Entity (or, if agreed to by Covered Entity, destroy) the remaining PHI that the Business Associate still maintains in any form; 3. Continue to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to ePHI to prevent use or disclosure of the PHI, other than as provided for in this Section, for as long as Business Associate retains the PHI; 4. Not use or disclose the PHI retained by Business Associate other than for the purposes for which such PHI was retained and subject to the same conditions set out in this Agreement related to "Permitted Uses and Disclosures By Business Associate" which applied prior to termination; and 7 5. Return to Covered Entity (or, if agreed to by Covered Entity, destroy) the PHI retained by Business Associate when it is no longer needed by Business Associate for its proper management and administration or to carry out its legal responsibilities. B. The obligations of Business Associate under this Section shall survive the termination of this Agreement. C. If any of the regulations promulgated under HTPAA or ARRA are amended or interpreted in a manner that renders this Agreement inconsistent therewith, the Parties shall amend this Agreement to the extent necessary to comply with such amendments or interpretations. IX. Miscellaneous. A. This Agreement shall be governed by and construed in accordance with the laws, of the State of Iowa. B. A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended. C. The Parties agree-to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the requirements of the HIPAA Rules and any other applicable law, D. Any ambiguity in this Agreement shall be interpreted to permit compliance with HIPAA, X. Notices. A. All notices, requests, approvals, demands and other communications required or permitted to be: given under this Agreement shall be in writing and delivered either personally, or by certified mail with postage prepaid and return receipt requested, or by overnight courier to the party to be notified. All communications will be deemed�given when received. The addresses of the parties shall be as follows; or as otherwise designated by any party through notice to the other party: If to Covered Entity: City of Fairfax 525 Vanderbilt St. Box 337 Fairfax, IA 52228 Attn: Cynthia Stimson 8 If to Business Associate: Group Benefits Design a division of PDCM Insurance PO Box 2597 Waterloo, IA50704 Attn: Jim Schiltz and Janet Henderson IN WITNESS WHEREOF, each of the undersigned has duty executed this Agreement on behalf of the party and on the date set forth below. Covered Entity: City,of Fairfax Business Associate: Group Benefits Design a division of PDCM Insurance By: By: Print: Print: Title: Title: Date: Date: 382113 9