HIPAA Compliance
Business Associate Agreement
Required for covered entities under HIPAA. Please read the full agreement, then complete the form below to execute it.
OFFICE GUARD, LLC — BUSINESS ASSOCIATE AGREEMENT
Effective upon execution · Pursuant to 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.314
This Business Associate Agreement ("BAA" or "Agreement") is entered into between the Covered Entity identified in the execution form below ("Covered Entity") and Office Guard, LLC, a Georgia limited liability company ("Business Associate"), and is incorporated into and made a part of the services agreement between the parties. This Agreement is intended to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and their implementing regulations, as amended from time to time.
1. Definitions
Capitalized terms used but not defined in this Agreement have the meanings ascribed to them in HIPAA and its implementing regulations. Key terms include:
- "Protected Health Information" or "PHI" means individually identifiable health information transmitted or maintained in any form or medium, as defined in 45 C.F.R. § 160.103, excluding education records covered by FERPA and employment records held by a covered entity in its role as employer.
- "Electronic Protected Health Information" or "ePHI" means PHI that is created, received, maintained, or transmitted in electronic form.
- "Breach" has the meaning set forth in 45 C.F.R. § 164.402.
- "Security Incident" means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
2. Obligations of Business Associate
Business Associate agrees to:
- Not use or disclose PHI other than as permitted or required by this Agreement or as required by law;
- Use appropriate safeguards, and comply with Subpart C of 45 C.F.R. Part 164 with respect to ePHI, to prevent use or disclosure of PHI other than as provided for by this Agreement;
- Report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including Breaches of Unsecured PHI as required by 45 C.F.R. § 164.410, and any Security Incidents of which it becomes aware;
- In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information;
- Make available PHI in a Designated Record Set to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.524;
- Make any amendment(s) to PHI in a Designated Record Set as directed or agreed to by Covered Entity pursuant to 45 C.F.R. § 164.526, or take other measures as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.526;
- Maintain and make available the information required to provide an accounting of disclosures to Covered Entity as necessary to satisfy Covered Entity's obligations under 45 C.F.R. § 164.528;
- To the extent Business Associate is to carry out one or more of Covered Entity's obligation(s) under Subpart E of 45 C.F.R. Part 164, comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s);
- Make its internal practices, books, and records available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
3. Permitted Uses and Disclosures by Business Associate
Business Associate may only use or disclose PHI as follows:
- As necessary to perform the services set forth in the underlying services agreement between the parties, including email security filtering, phishing simulation, and security awareness training;
- As required by law;
- For the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that disclosures are required by law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached;
- To provide Data Aggregation services relating to the Health Care Operations of Covered Entity.
Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(b). De-identified information is not subject to the terms of this Agreement.
4. Obligations of Covered Entity
Covered Entity agrees to:
- Notify Business Associate of any limitation(s) in the notice of privacy practices of Covered Entity under 45 C.F.R. § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI;
- Notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent that such changes may affect Business Associate's permitted or required uses and disclosures;
- Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 C.F.R. § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI;
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.
5. Breach Notification
Business Associate shall notify Covered Entity without unreasonable delay, and in no case later than sixty (60) calendar days after discovery of a Breach of Unsecured PHI. Such notification shall include, to the extent possible: (i) the identification of each individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the Breach; (ii) a brief description of what happened, including the date of the Breach and the date of discovery; (iii) a description of the types of Unsecured PHI involved; (iv) any steps individuals should take to protect themselves from potential harm; (v) a brief description of what Business Associate is doing to investigate the Breach, mitigate harm, and protect against further Breaches; and (vi) contact information for Business Associate.
6. Security of Electronic PHI
With respect to ePHI, Business Associate shall: (a) implement Administrative Safeguards as required by 45 C.F.R. § 164.308; (b) implement Physical Safeguards as required by 45 C.F.R. § 164.310; (c) implement Technical Safeguards as required by 45 C.F.R. § 164.312; (d) implement policies and procedures as required by 45 C.F.R. § 164.316; and (e) ensure that any agent or subcontractor to whom it provides ePHI agrees to implement reasonable and appropriate safeguards.
7. Term and Termination
This Agreement shall be effective as of the date of execution and shall terminate when all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information, in accordance with the termination provisions in this Section.
Termination for Cause. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall either: (a) provide an opportunity for Business Associate to cure the breach or end the violation and terminate this Agreement if Business Associate does not cure the breach or end the violation within the time specified by Covered Entity; (b) immediately terminate this Agreement if Business Associate has breached a material term of this Agreement and cure is not possible; or (c) if neither termination nor cure is feasible, report the violation to the Secretary.
Effect of Termination. Except as provided in the following paragraph, upon termination of this Agreement, for any reason, Business Associate shall return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity. This provision shall apply to PHI that is in the possession of subcontractors or agents of Business Associate. Business Associate shall retain no copies of the PHI. If return or destruction is not feasible, Business Associate shall extend the protections of this Agreement to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.
8. Miscellaneous
- Regulatory References. A reference in this Agreement to a section in HIPAA means the section as in effect or as amended.
- Amendment. The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of HIPAA and the HITECH Act.
- Survival. The respective rights and obligations of Business Associate under Section 7 of this Agreement shall survive the termination of this Agreement.
- Interpretation. Any ambiguity in this Agreement shall be resolved to permit Covered Entity to comply with HIPAA.
- Governing Law. This Agreement shall be governed by the laws of the State of Georgia, without regard to its conflict of law provisions.
- Entire Agreement. This Agreement, together with the underlying services agreement between the parties, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements, understandings, negotiations, and discussions, whether oral or written, relating to such subject matter.
9. Contact
Office Guard, LLC
1522 Alcovy Mountain Rd, Monroe GA 30655
[email protected]
Scroll to the bottom of the agreement to enable execution.