Security

Business Associate Agreement

This is the agreement we sign with every practice, in full and unedited. The copy you download from Practice Settings is this document with your practice name and start date filled in where the brackets are.

This Business Associate Agreement (the "Agreement") is entered into by [Practice name] ("Covered Entity") and Valence Behavioral Health ("Business Associate"), and is effective as of [the date the practice's account was created].

Covered Entity is a health care provider subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164 (together, "HIPAA"). Business Associate provides a practice management and clinical documentation service to Covered Entity, and in doing so creates, receives, maintains, or transmits Protected Health Information on Covered Entity's behalf. The parties agree as follows.

1. Definitions

Terms used but not otherwise defined in this Agreement have the meaning given to them in 45 CFR 160.103 and 45 CFR 164.501, including Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

"PHI" means Protected Health Information that Business Associate creates, receives, maintains, or transmits for or on behalf of Covered Entity under this Agreement. "ePHI" means PHI held or transmitted in electronic form.

2. Permitted uses and disclosures

Business Associate may use and disclose PHI only as necessary to perform the services it provides to Covered Entity, as permitted or required by this Agreement, or as Required By Law. Business Associate will not use or disclose PHI in a way that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity itself.

Business Associate may use PHI for the proper management and administration of its own business and to carry out its legal responsibilities. Business Associate may disclose PHI for those purposes only if the disclosure is Required By Law, or if Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially, used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate of any breach of confidentiality.

Business Associate may provide Data Aggregation services relating to Covered Entity's Health Care Operations, and may de-identify PHI in accordance with 45 CFR 164.514(a)-(c).

Business Associate will not sell PHI, and will not use or disclose PHI for marketing or for its own product development or model training purposes.

Business Associate will limit its uses, disclosures, and requests of PHI to the Minimum Necessary to accomplish the intended purpose, consistent with 45 CFR 164.502(b).

3. Safeguards

Business Associate will use appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement, and will comply with Subpart C of 45 CFR Part 164 (the Security Rule) with respect to ePHI.

Business Associate will encrypt ePHI in transit and at rest, restrict access to PHI to workforce members who need it to perform the services, and maintain records of access to and changes made to PHI held in the service.

4. Reporting

Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this Agreement of which it becomes aware, including any Security Incident and any Breach of Unsecured PHI, without unreasonable delay and in no case later than sixty (60) calendar days after Discovery, as that term is used in 45 CFR 164.410.

The report will include, to the extent known at the time and as it becomes known thereafter, the identification of each Individual whose Unsecured PHI was or is reasonably believed to have been accessed, acquired, used, or disclosed; a description of what happened and when; the types of information involved; and what Business Associate is doing to investigate, mitigate, and prevent recurrence.

Unsuccessful Security Incidents that result in no unauthorized access to, or use, disclosure, modification, or destruction of PHI (for example, blocked scans, pings, and failed login attempts) are reported on Covered Entity's request rather than individually, and this paragraph serves as notice that they occur.

Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of this Agreement.

5. Subcontractors

In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement.

Business Associate maintains a current list of the subcontractors that may handle PHI, together with the purpose of each, and will make that list available to Covered Entity on request.

6. Individual rights

Access. Business Associate will make PHI held in a Designated Record Set available to Covered Entity, or to the Individual where directed by Covered Entity, so that Covered Entity can meet its obligations under 45 CFR 164.524, within fifteen (15) business days of a written request.

Amendment. Business Associate will make PHI held in a Designated Record Set available for amendment, and will incorporate amendments Covered Entity directs, as required by 45 CFR 164.526, within fifteen (15) business days of a written request.

Accounting of disclosures. Business Associate will document disclosures of PHI and information related to those disclosures as would be required for Covered Entity to respond to a request for an accounting under 45 CFR 164.528, and will provide that documentation to Covered Entity on request.

Obligations of Covered Entity. To the extent Business Associate carries out an obligation of Covered Entity under Subpart E of 45 CFR Part 164, Business Associate will comply with the requirements of that Subpart that apply to Covered Entity in the performance of that obligation.

7. Access by the Secretary

Business Associate will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA.

8. Term and termination

This Agreement takes effect on the effective date stated above and continues until all PHI is returned or destroyed under Section 9, or until terminated as provided below.

Covered Entity may terminate this Agreement and the underlying service if it determines that Business Associate has materially breached this Agreement and the breach is not cured within thirty (30) days of written notice, or immediately if cure is not possible.

Termination of the underlying service agreement terminates this Agreement, except for the obligations in Section 9, which survive.

9. Return or destruction of PHI

On termination, Business Associate will return to Covered Entity or destroy all PHI it holds, and will require the same of its Subcontractors. Covered Entity may export its records from the service before termination, and Business Associate will provide a machine-readable export on request.

If return or destruction is infeasible, Business Associate will notify Covered Entity of the conditions that make it infeasible, will extend the protections of this Agreement to the retained PHI, and will limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it retains the PHI.

10. Miscellaneous

Amendment. The parties will amend this Agreement as necessary for each to comply with HIPAA and the Health Information Technology for Economic and Clinical Health Act as they change.

Interpretation. Any ambiguity in this Agreement is resolved in favor of a meaning that permits the parties to comply with HIPAA. In the event of a conflict with the underlying service agreement, this Agreement controls as to PHI.

Regulatory references. A reference to a section of the HIPAA regulations means that section as in effect or as amended.

No third party beneficiaries. Nothing in this Agreement confers rights on any person other than the parties, their successors, and their permitted assigns.

Survival. Sections 4, 7, and 9 survive termination of this Agreement.

11. Signatures

Covered Entity: ______________________________ Name / Title: ______________________________ Date: ____________

Business Associate (Valence Behavioral Health): ______________________________ Name / Title: ______________________________ Date: ____________

This template is provided for the practice's convenience and is not legal advice. Review it with your own counsel before relying on it. A signed agreement between the parties, not this download, is what takes effect.

Questions about this agreement go to [email protected]. For how the product actually handles PHI, read the security page.