HomeMy WebLinkAboutRESOLUTION NO. 2013-68 SOLUTION NO. 20 3-68
A RESOLUTION TO ENTER INTO A BUSINESS ASSOICATE AGREEMENT
WHEREAS, the City of Fairfax uses Jim Schiltz, of Group Benefits Design a division of
PDCM Insurance, as its health insurance agent; and
WHEREAS, a Business Associate Agreement between the City of Fairfax and Group
Benefits Design a division of PDCM Insurance is required to comply with the privacy and
security regulations issued by the United. States Department of Health and Human Services under
the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the security
provisions of the American.Recovery and.Reinvestment Act of 21109 ("ARRA"), as amended.
NOW, THEREFORE,BE IT RESOLVED,that the City of Fairfax agrees to enter into
the attached Business Associate Agreement with Group Benefits Design a division of PDCM
Insurance.
BE IT FURTHER RESOLVED, by the City Council of the City of Fairfax, Iowa, that
the Mayor and City Clerk are hereby directed to certify this resolution of approval and the Mayor
and City Clerk are authorized to sign the attached Business Associate Agreement with Group
Benefits Design a division of PDCM Insurance.
i
Passed and approved this Bit'day of October, 2013.
AYES: Beer, Frieden, Otto, Magers, and Wainwright
NAYS: None
1,0
Jasgari Labe, Mayor
I
i
dM / if r`{ '•7/ +pr,`4�
C is Stimson, City Clerk/Treasurer
• r' o CJ
BUSINESS ASSOCIATE NGREEMENT
This Business Associate Agreement ("Agreement") by and between City of Fairfax ("Covered
Entity") and Group Benefits Design a division of PDCM Insurance ("Business Associate"), is
entered into on this 8th day of October, 2013 ("Effective Date"), for the purposes of complying,
with the privacy and security regulations issued by the United States Department of Health and
Human Services under the Health Insurance Portability and Accountability Act of 1996
("HIPAA") and the security provisions of the American Recovery and Reinvestment Act of 2009
('ARRA"), as amended. Covered Entity and Business Associate are collectively referred to as
the"Parties."
WITNESSET11
WHEREAS, Covered Entity is a covered entity as such terin is defined under HIPAA and
as such is required to comply with the requirements thereof regarding the confidentiality and
privacy of Protected Health Information; and
WHEREAS, Business Associate performs functions or activities on behalf of, or provides
certain services to, Covered Entity that may involve access by Business Associate to Protected
Health Information;
WHEREAS, by providing the services and representation, Business Associate may
become a business associate of Covered Entity as such term is defined under HIPAA at 45 CFR
Section 160,103; and
WHEREAS, Business Associate acknowledges that Business Associate is directly subject
to the requirements of 45 C.F.,R §§ 164.308, 164.310, 164.312, arid 164,316 of the HIPAA
regulations, as amended;
NOW THEREFORE, in consideration of the mutual covenants, promises and agreements
contained herein, the,Parties hereto agree as follows:
I. Definitions.
A. Catch-all definition:
I The following terms used in this Agreement shall have the same meaning
as those terms in the HIPAA Rules: Breach, Data Aggregation,Designated
Record Set, Disclosure, Health Care Operations, Individual, Minimum
Necessary, Notice of Privacy Practices, Protected Health Information
("PI-11"), Required By Law, Secretary, Security Incident, Subcontractor,
Unsecured Protected Health Information, and Use.
B. Specific definitions:
I. "Business Associate" shall generally have the same meaning as the term
"business associate" at 45 CFR 160.103.
1
2. "Covered Entity" shall generally have the same meaning as the term
"covered entity" at 45 CFR 1,60.103.
3. "HIPAA Rules" shall mean the Privacy, Security, Breach Notification,
and Enforcement Rules at 45 CFR Part 16O and Part 164.
Obligations and Activities of Business Associate.
Business Associate agrees to:
A. Not use or disclose PHI other than as permitted or required by the Agreement or
as required by law;
B. Use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 to
prevent use or disclosure of PHI other than as provided for by the Agreement, In
doing so, Business Associate shall implement administrative, physical and
technical safeguards that reasonably and appropriately protect the confidentiality,
integrity, and availability of the PHI that it creates, receives, maintains or
transmits on behalf of Covered Entity. Business Associate covenants that such
safeguards shall include, without limitation, implementing written policies and
procedures in compliance with HIPAA and ARRA, conducting a security risk
assessment, and training Business Associate employees who will have access to
PHI with respect to the policies and procedures required by HIPAA and ARRA;
C. Report to Covered Entity any use or disclosure of PHI not provided for by the
Agreement of which it becomes aware, including breaches of'unsecured PHI as
required by 45 CFR 164.410, and any security incident of which it becomes
aware;
D. In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable,
ensure that any subcontractors that create, receive, maintain, or transmit PHI on
behalf of Business Associate agree to the same restrictions, conditions, and
requirements that apply to the business associate with respect to such information;
E. Abide by the following with regard to access of individuals to PHI:
I. In order to allow Covered Entity to respond to a request by an Individual
for access pursuant to 45 C.F.R. Section 164.524, Business Associate,
within five (5) business days of a written request by Covered Entity for
access to PHI about an Individual contained in a Designated Record Set,
shall make available to Covered Entity such PHI for so long as such
information is maintained in the Designated Record Set. If PHI is stored
offsite, PHI shall be made available to Covered Entity within twenty (20)
days of Business Associate's receipt of written request.
2. In the event any Individual requests access to PHI directly from Business
Associate, Business Associate shall forward such request to Covered
Entity within -five (5) business days. Before forwarding any PHI to
Covered Entity, Business Associate shall indicate in the Designated
2
Record Set any material it deems unavailable to the Individual, pursuant to
45 C.F.R. Section 164.524.
3. Any denial of access to PHI determined by Covered Entity pursuant to 45
C.F.R. Section 164,524, and conveyed to Business Associate by Covered
Entity, shall be the responsibility of Covered Entity, including resolution
or reporting of all appeals and/or complaints arising from denials.
F. Abide by the following with regard to amendment of information:
1. In order to allow Covered Entity to respond to a request by an Individual
for an amendment pursuant to 45 C.F.R. Section 164.526, Business
Associate shall, within live (5) business days of a written request by
Covered Entity for an amendment to PHI about an Individual contained in
a Designated Record Set, make available to Covered Entity such PHI for
so long as such information is maintained in the Designated Record Set.
2. In the event any Individual requests amendment of PHI directly from
Business Associate, Business Associate shall forward such request to
Covered Entity within five (5) business days of the receipt of the request.
Before forwarding any PHI to Covered Entity, Business Associate shall
indicate in the Designated Record Set any material it deems unavailable to
the Individual pursuant to 45 C.F.R. Section 164.526.
3. Any denial of amendment to PHI determined by Covered Entity pursuant
to 45 C.F.R. Section 164.526 (arid conveyed to Business Associate by
Covered Entity) shall be the responsibility of Covered Entity, including
resolution or reporting of all appeals and/or complaints arising from
denials.
4. Within ten(10) business days of receipt of a request from Covered Entity
to amend an Individual's PHI in the Designated Record Set, Business
Associate shall incorporate any approved amendments, statements of
disagreement, and/or rebuttals into its Designated Record Set as required
by 45 C.F.R. Section, 1,64.526.
G. Abide by,the following with regard,to accounting of disclosures:
I In order to allow Covered Entity to respond to a request by an Individual
for an accounting pursuant to 45 C.F.R. Section 164.528, Business
Associate shall, within five (5) business days of a written request by
Covered Entity for an accounting of disclosures of PHI about an
Individual,make available to Covered Entity such PHI.
2. At a minimum, Business Associate shall provide Covered Entity with the
following information: (i) the date of the disclosure; (ii) the name of the:
entity or person who received the PHI, and if known, the address of such
entity or person; (iii) a brief description of the PHI disclosed; and (iv) a
brief statement of the purpose of such disclosure.
3
3. In the event any Individual, requests an accounting of disclosure of PHI
directly from Business Associate, Business Associate shall forward such
request to Covered Entity within five (5) business days.
4. Business Associate shall implement an appropriate recordkeeping process
to enable it to comply with the requirements of this Agreement.
5. Business Associate shall support Covered Entity in a manner that enables
Covered Entity to meet its obligations under 45 C.F.R. Section 164.528.
H. To the extent the Business Associate is to carry out one or more of Covered
Entity's obligatio,n(s) under Subpart E of 45 CFR Part 164 ("Subpart E"), comply
with the requirement-, of Subpart E that apply to the Covered Entity in the
performance of such obligation(s); and
I. Permit the Secretary and other regulatory and accreditation authorities to audit
Business Associate's internal practices, books and records at reasonable times as
they pertain to the use and disclosure of PHI received from, or created or received
by Business Associate on behalf of, Covered Entity in order to ensure that
Covered Entity is in compliance with the requirements of the Privacy Rule.
Permitted Uses and Disclosures by Business Associate.
A. Business Associate warrants that Business Associate, its agents, and any
subcontractors shall not use or disclose PHI other than as permitted.or required by
this Agreement or required by law and shall not use or disclose PHI in any
manner that violates applicable federal and state laws or would violate such laws
if used or disclosed in such manner by Covered Entity.
1. Subject to the restrictions set forth in the previous paragraph and
throughout this Agreement, Business Associate may use the information
received from Covered Entity as required by law.
B. Business Associate agrees to make uses and disclosures and requests for PHI
consistent with Covered Entity's minimum necessary policies and procedures.
Covered Entity further understands and acknowledges that, to the extent Business
Associate requests that Covered Entity disclose PHI to Business Associate, such
request is only for the minimum necessary PHI for the accomplishment of the
Business Associate's purpose.
C, Business Associate may not use or disclose PHI in a manner that would violate
Subpart E if done by Covered Entity, except for the specific uses and disclosures
set forth below.,
D. Business Associate may use PHI for the proper management and administration
of the Business,Associate or to carry out its legal responsibilities,
E. Covered Entity shall not request Business Associate to use or disclose PHI in any
manner that would not be permissible tinder Subpart E if done by Covered Entity.
4
IV. Obligations of Covered Entity.
A. Covered Entity warrants that Covered Entity, its directors, officers,
subcontractors, employees, affiliates, agents, and representatives; (i) shall comply
with the Privacy Rule in its use or disclosure of PHI; (ii) shall not use or disclose
PHI in any manner that violates applicable federal and state laws; (iii) shall not
request Business Associate to use or disclose PHI in any manner that violates
applicable federal and state laws if such use or disclosure were done by Covered
Entity; and (iv) may request Business Associate to disclose PHI directly to
another party only for the purposes allowed by the Privacy Rule.
B. Covered Entity shall notify Business Associate of any limitation(s) in its notice of
privacy practices of Covered Entity in accordance with 45 CFR Section 164.520,
to the extent that such limitation may affect Business Associate's use or
disclosure of PHI,
C. Covered Entity shall notify Business Associate of any changes in, or revocation
of, permission by an Individual to use or disclose PHI, to the extent that such
changes may affect Business Associate's use or disclosure of PHI.
D. Covered Entity shall notify Business Associate of any restriction to the use or
disclosure of PHI that Covered entity has agreed to in accordance with 45 CFR
Section 164.522, to the extent that such restriction may affect Business
Associate's use or disclosure of PHI.
V. Disclosure to Third Parties.
A. Business Associate shall obtain and maintain an agreement with each
subcontractor and agent that has or will have access to PHI, which is received
from or created or received by Business Associate on behalf of Covered Entity,
pursuant to which agreement such subcontractor, and agent agrees to be bound by
the same restrictions, terms, and conditions that apply to Business Associate
pursuant to the Agreement with respect to such PHI.
B. Business Associate shall also (i) obtain reasonable assurances from the person to
whom the PHI is disclosed that it will be held confidentially and used or further
disclosed only as Required by Law or :for the purpose for which it was disclosed
and (ii) obligate such person to notify Business Associate of any instances of
which it is aware in which the confidentiality of the PHI has been breached,
I. Reporting of Breaches and Improper Disclosures.
A. The term "breach" means the acquisition, access, use, or disclosure of PHI in a
manner not permitted under Subpart E which compromises the security or privacy
of such information. The following situations are excluded from the definition of
"breach:"
1. Any unintentional acquisition, access, or use of PRI by a workforce
member or person acting under the authority of Covered Entity or
5
Business Associate, if such, acquisition, access, or use was made in good
11dth and within the scope of authority and does not result in,further use or
disclosure in a manner not permitted under Subpart E.
2. Any inadvertent disclosure by a person who is authorized to access PHI at
either Covered Entity or Business Associate to another person authorized
to access PHI at the same Covered Entity or Business Associate (or
organized health care arrangement in which the Covered Entity
participates), and the information received as a result of such disclosure is
not further used or disclosed in a manner not permitted under Subpart E.
3. A disclosure of PHI where a Covered Entity or Business Associate has a
good faith belief that an -unauthorized person to whom the disclosure was
made would not reasonably have been able to retain such information.
B. Except as provided in paragraph IV(A), an acquisition, access, use, or disclosure
of PHI in a manner not permitted under Subpart E is presumed to be a breach
unless the Covered Entity or Business Associate, as applicable, can demonstrate
that there is a low probability that the PHI has been compromised based on a risk
assessment of at least the following factors:
1. The nature and extent of the PHI involved, including the types of
identifiers and the likelihood of re-identification;
2. The unauthorized person who used the PI11 or to whom the disclosure was
made;
3. Whether the PHI was actually acquired or viewed; and
4. The extent to which the risk to the PHI has been mitigated.
C. The term "unsecured" shall mean PHI that is not rendered unusable, unreadable,
or indecipherable to unauthorized individuals through the use of a technology or
methodology specified by the Secretary from time to time.
D. In the event of a Breach of any Unsecured PHI that Business Associate accesses,
maintains, retains, modifies, records, stores, destroys, or otherwise holds or uses
on behalf of Covered Entity, Business Associate shall report such Breach to
Covered Entity within ten (10) days.
E. Notice of a Breach shall include the identification of each individual whose PHI
has been, or is reasonably believed to have been, accessed, acquired, or disclosed
during the Breach. At the request of Covered Entity, Business Associate shall
identify: the date of the Breach, the scope of the Breach, the Business Associate's
response to the Breach and the identification of the party responsible for causing
the Breach, if known.
F. In the event of any use or disclosure that does not constitute a Breach, but that is
an unauthorized or improper use or disclosure of any PHI under this Agreement
6
or applicable laws, Business Associate shall report to Covered Entity such
unauthorized or improper use or disclosure as soon as practicable, but in no event
later than five (5) business days of the date on which Business Associate becomes
aware of such use or disclosure. In such event, Business Associate shall, in
consultation with Covered Entity, mitigate, to the extent practicable, any harmful
effect that is known to Business Associate of such unauthorized or improper use
disclosure.
VII, Term and Termination.
A. This Agreement shall become effective on the Effective Date set forth above and
shall terminate upon the termination or expiration of the Service Agreement and
when. all PHI provided by either party to the other, or created or received by
Business Associate on behalf of Covered Entity is, in accordance with Section
VIII below, destroyed or returned to Covered Entity or, if it is not feasible to
return or destroy PHI, protections are extended to such information, in accordance
with the terms of this Agreement.
B. Where either Party has knowledge of a material breach by the other Party and
cure is possible,the non-breaching Party shall provide the breaching Party with an
opportunity to cure. Where said breach is not cured within ten (10) business days,
of the breaching Party's receipt of notice from the non-breaching Party of said
breach, the non-breaching Party shall terminate this Agreement. When neither
cure not termination is feasible, the non-breaching Party shall report the violation.
to the Secretary.
VIII. Return/Destruction of PHI Upon Termination.
A. Upon termination of this Agreement for any reason, Business Associate, with
respect to PHI received from Covered Entity, or created, maintained, or received
by Business Associate on behalf of Covered Entity, shall:
1. Retain only that PHI which is necessary for Business Associate to
continue its proper management and administration or to carry out its legal
responsibilities;
2. Return to Covered Entity (or, if agreed to by Covered Entity, destroy) the
remaining PHI that the Business Associate still maintains in any form;
3. Continue to use appropriate safeguards and comply with Subpart C of 45
CFR Part 164 with respect to ePHI to prevent use or disclosure of the PHI,
other than as provided for in this Section, for as long as Business
Associate retains the PHI;
4. Not use or disclose the PHI retained by Business Associate other than for
the purposes for which such PHI was retained and subject to the same
conditions set out in this Agreement related to "Permitted Uses and
Disclosures By Business Associate" which applied prior to termination;
and
7
5. Return to Covered Entity (or, if agreed to by Covered Entity, destroy) the
PHI retained by Business Associate when it is no longer needed by
Business Associate for its proper management and administration or to
carry out its legal responsibilities.
B. The obligations of Business Associate under this Section shall survive the
termination of this Agreement.
C. If any of the regulations promulgated under HTPAA or ARRA are amended or
interpreted in a manner that renders this Agreement inconsistent therewith, the
Parties shall amend this Agreement to the extent necessary to comply with such
amendments or interpretations.
IX. Miscellaneous.
A. This Agreement shall be governed by and construed in accordance with the laws,
of the State of Iowa.
B. A reference in this Agreement to a section in the HIPAA Rules means the section
as in effect or as amended.
C. The Parties agree-to take such action as is necessary to amend this Agreement
from time to time as is necessary for compliance with the requirements of the
HIPAA Rules and any other applicable law,
D. Any ambiguity in this Agreement shall be interpreted to permit compliance with
HIPAA,
X. Notices.
A. All notices, requests, approvals, demands and other communications required or
permitted to be: given under this Agreement shall be in writing and delivered
either personally, or by certified mail with postage prepaid and return receipt
requested, or by overnight courier to the party to be notified. All communications
will be deemed�given when received. The addresses of the parties shall be as
follows; or as otherwise designated by any party through notice to the other party:
If to Covered Entity:
City of Fairfax
525 Vanderbilt St. Box 337
Fairfax, IA 52228
Attn: Cynthia Stimson
8
If to Business Associate:
Group Benefits Design a division of PDCM Insurance
PO Box 2597
Waterloo, IA50704
Attn: Jim Schiltz and Janet Henderson
IN WITNESS WHEREOF, each of the undersigned has duty executed this Agreement on
behalf of the party and on the date set forth below.
Covered Entity: City,of Fairfax Business Associate: Group Benefits Design a
division of PDCM Insurance
By:
By:
Print: Print:
Title: Title:
Date: Date:
382113
9