HomeMy WebLinkAboutChildren & Youth - Zullinger-Davis-Trinh, P.C. 1
AGREEMENT BETWEEN
The County of Franklin, Pennsylvania
Franklin County Children and Youth Service
425 Franklin Farm Lane
Chambersburg, PA 17202
And
Zullinger-Davis-Trinh, P.C.
July 1, 2026 – June 30, 2027
This AGREEMENT (“Agreement”) is made on ________________________, by and between the
County of Franklin, Pennsylvania, hereinafter referred to as the “County” whose principal place
of business is 272 North Second Street, Chambersburg, Pennsylvania 17201, and Zullinger-
Davis-Trinh, P.C., whose principal place of business is located at 74 North Second Street,
Chambersburg, Pennsylvania 17201, hereinafter referred to as the “Provider” and shall be in
force and effect from July 1, 2026 through June 30, 2027, inclusive, or until either party gives
thirty (30) business days’ written notice that this agreement should be terminated.
WHEREAS, the COUNTY is in need of interim Solicitor services for the Franklin County
Children & Youth Service; and
WHEREAS, the PROVIDER has the necessary qualifications and any required licensure to
provide said services for COUNTY; and
WHEREAS, the Board of Commissioners of Franklin County has approved this Agreement during
a duly advertised meeting.
NOW, THEREFORE, in consideration of the mutual promises contained herein, the parties,
intending to be legally bound, hereby agree as follows:
1. Recitals
The above recitals are incorporated herein by reference thereto and made a part of this
AGREEMENT.
2. Services Provided
The PROVIDER shall provide Solicitor services (hereinafter referred to as “Services”, as outlined
and described in the Provider Program Description(s), Attachment “B”) as requested by the
COUNTY for individuals with the Franklin County Children & Youth Service. There is no
guarantee of any specified minimum number of hours that the COUNTY shall request services.
PROVIDER agrees to comply with the rules, regulations, policies and procedures of CYS; and, to
meet her responsibility faithfully and industriously in the provision of legal services, all as directed
by CYS.
3. Description of Services
2
A. PROVIDER agrees to perform the services as outlined and described in the Provider
Program Description(s) attached hereto and incorporated herein by reference as
Attachment “B”, with said Provider Program Description(s) including PROVIDER’S
location and hours of operation.
B. PROVIDER shall submit to the COUNTY all documents required by Attachment
“A”,(Provider Program Description(s) - Attachment “B”, Payment Schedule/Rates –
Attachment “C”, HIPAA Business Associate Agreement, - Attachment “D”).
C. As is applicable, PROVIDER agrees to complete, submit, and where appropriate,
maintain such data and/or data logs as requested by Franklin County Children and
Youth Service, and will submit this data in a format as directed by Franklin County
Children and Youth Service in a timely manner.
4. Licensure
The PROVIDER certifies that all staff performing legal services pursuant to this agreement are
currently licensed to practice in the Commonwealth of Pennsylvania and are attorneys in good
standing. Should any suspension or revocation of license occur during the term of this agreement,
the PROVIDER shall immediately notify COUNTY.
5. Term of Agreement
The PROVIDER shall provide Services as requested by the COUNTY during the period beginning
July 1, 2026 through June 30, 2027.
In the event that the parties are desirous of continuing the relationship set forth in this Agreement
but, as of the expiration of the term set forth herein, have not executed a new Agreement, this
Agreement shall continue on a month-to-month basis under the same terms and conditions until
such time as either party shall give thirty (30) days’ notice of termination.
If the COUNTY continues to purchase services under this Agreement beyond the term specified
herein but has not executed a new contract pending finalization of the State or Federal funding
allocations, or should the parties fail to agree to rates applicable to the next Agreement year, all
terms and conditions of this Agreement shall continue to apply and be binding on the parties for
the services described herein until a new Agreement has been executed.
With respect to the provision of interim Solicitor services, the COUNTY may terminate this
Agreement with or without cause for any reason.
6. Payments
A. The COUNTY, in consideration of the services performed by the PROVIDER
under this Agreement and other costs as specified, shall pay the costs of the services
rendered on an hourly or unit-of-service basis, as set forth herein. The fee schedule
and/or rates for services as agreed upon by the COUNTY and PROVIDER are listed
on Attachment “C”.
3
B. The PROVIDER will render billing statements to the appropriate COUNTY department
on said PROVIDER’S Invoice/Letterhead on or before the fifteenth (15th) calendar day
of the month immediately following the provision of services. The COUNTY shall
issue payment no later than thirty (30) days from receipt of a complete and accurate
invoice. Work performed during the time period outlined in Paragraph Three (3) herein
but prior to the execution of this Agreement shall be submitted as timely as possible by
PROVIDER and the COUNTY will issue payment within forty-five (45) days from
receipt of a complete and accurate invoice. The first full month following the execution
of this Agreement, the parties shall follow the deadlines set forth in the first sentence
of this Paragraph.
C. The COUNTY, in its sole judgment, reserves the right to withhold payment if a
discrepancy exists that warrants a new billing statement. The COUNTY may only
withhold payment for that portion of the statement which is in dispute. It is the
responsibility of the COUNTY to notify the PROVIDER of any discrepancy in the
billing statement as soon as possible in writing.
D. The PROVIDER fully understands that the reimbursement rate is a specific fee-for-
service arrangement and, as such, agrees to exempt the COUNTY from any and all
additional financial and legal obligations such as social security, federal income tax
withholding, and any taxes imposed by any taxing authority. These are regarded as the
sole reporting responsibility of the PROVIDER as an independent contractor.
7. Program Records and Retention Requirements:
All records shall be retained pursuant to the provisions of this paragraph.
A. PROVIDER must maintain records regarding the units of service being
provided and billed for, i.e. timesheets, at all times, and the COUNTY shall have
access to those records upon request.
B. PROVIDER must maintain auditable records at all times and the COUNTY shall
have access to those records upon request.
C. Audit and Inspection Rights: PROVIDER shall retain records to substantiate all
invoices for a period of five (5) years, and the COUNTY shall have the right for
review said records, without delay, upon request.
D. Records which relate to litigation or the settlement of claims arising out of the
performance of this Agreement, or costs and expenses of this Agreement as to
which exception has been taken by the auditors, shall be retained by the
PROVIDER until such litigation, claims, or exceptions have been disposed of.
E. Except for the records described in sub-paragraph D above, the PROVIDER may,
in fulfillment of its obligation to retain its records as required by this paragraph,
substitute photographs, microphotographs, or other authentic reproductions of such
records, after the expiration of two (2) years following the last day of the month of
reimbursement to the Provider of the invoice or voucher to which such records
4
relate, unless a shorter period is authorized by DHS, with the concurrence of the
auditors.
F. Additionally, other regulations may supersede the aforementioned retention
requirements, such as the Health Insurance Portability and Accountability Act
(HIPAA). At a minimum, HIPAA requires all client-identifying information to be
retained for a period of six (6) years after final service payment. The Provider
should consult HIPAA regulations for complete compliance requirements.
8. Insurance
All insurance provided for in this section shall be obtained under valid and enforceable policies
issued by insurers of recognized responsibility that are licensed to do business in the
Commonwealth of Pennsylvania. Certificates of insurance evidencing the existence of such
insurance shall be submitted to the COUNTY at least ten (10) calendar days before work is begun.
If the term of this Agreement coincides with the term of the PROVIDER’S insurance coverage, a
certificate of insurance from the expiring policy will be acceptable, but a certificate evidencing
renewed coverage, or a new policy must be presented to the COUNTY no later than thirty (30)
calendar days after effective date of the policy.
Each policy and certificate of insurance shall contain an endorsement naming the COUNTY as an
additional insured party there under and a provision requiring that at least thirty (30) calendar days
prior written notice be given to the COUNTY in the event the policy is canceled, not renewed or
the limits of coverage are reduced.
If the PROVIDER desires to self-insure any, or all, of the coverages listed in this section, it shall
provide to the COUNTY documentation that such self-insurance has received all the approvals
required by law or regulation, as well as the most recent audited financial statement of the
PROVIDER’S insurance. Any coverage that is self-insured shall provide the same coverage,
limits, and benefits as the coverage listed in this section and shall be approved by COUNTY.
If the PROVIDER fails to obtain or maintain the required insurance, the COUNTY shall have the
right to treat such failure as a material breach of the Agreement and to exercise all appropriate
rights and remedies, including, but not limited to, the right to immediately terminate this
Agreement.
The PROVIDER shall procure and maintain insurance in full force and effect covering the scope
of the services rendered under this Agreement in the types and limits specified below. In addition
to the insurance coverage and limits specified herein, the PROVIDER shall obtain any other
insurance coverage as may be required by law.
A. General Liability Insurance:
1. Limits of Liability: $1,000,000 per occurrence; $1,000,000 in the
aggregate.
2. Coverage: Premises operations, contractual liability, personal injury,
5
products liability, and completed operations, vicarious liability for independent
contractors, employees and volunteers as additional insured’s, and completed
operations coverage.
B. Workers’ Compensation and Employers’ Liability Insurance:
1. Limits of Liability: Workmen’s Compensation – Statutory Limits.
Employers’ Liability - Statutory Limits.
2. Other States’ coverage and Pennsylvania endorsement.
C. Automobile Liability:
1. Limit of Liability: $1,000,000 per occurrence combined single limit for
bodily injury and property damage liability.
2. Coverage: Owned, non-owned, and hired vehicles. Coverage limits apply.
D. Professional Liability Insurance:
1. Limit of Liability: $1,000,000 per occurrence; $3,000,000 in the aggregate.
2. Coverage for occurrences happening during the performance of services required
under this Agreement shall be maintained in full force and effect under the policy.
If coverage is on a claims-made basis, the policy shall include “tail coverage” for
up to a two-year period of exposure.
The PROVIDER will not be covered under the COUNTY’S Professional Liability Policy.
PROVIDER certifies they maintain professional liability insurance on all PROVIDER staff
performing services pursuant to this agreement and proof of said insurance shall be provided upon
request.
E. Subcontractors for Direct Client Services:
The PROVIDER shall include all subcontractors as insured’s under its policies or shall
furnish separate certificates, endorsements or other proof of coverage for each
subcontractor. All coverage’s for subcontractors shall be subject to all of the requirements
stated in this Agreement.
9. Service Provider Responsibility Provisions
A. The PROVIDER certifies that it is not currently under suspension or debarment by
the COUNTY, Commonwealth, any other state, or the federal government, and if the
PROVIDER cannot so certify, then it agrees to submit a written explanation of why
such certification cannot be made.
B. If the PROVIDER enters into subcontracts or employs under this Agreement any
subcontractors/individuals who are currently suspended or debarred by the
COUNTY, Commonwealth or federal government, or who become suspended, or
6
debarred, by the Commonwealth or federal government during the term of this
Agreement, or any extension or renewals thereof, the COUNTY or Commonwealth
shall have the right to require the PROVIDER to terminate such subcontracts or
employment.
C. The PROVIDER agrees to reimburse the COUNTY or Commonwealth for the
reasonable costs of investigating the PROVIDER’S compliance with terms of this or
any other Agreement between the PROVIDER and the COUNTY or Commonwealth
which result in the suspension or debarment of the PROVIDER or its subcontractor.
Such costs shall include, but are not limited to, salaries of the investigators, including
overtime, travel and lodging expenses, and expert witness and documentary fees.
The SERVCE PROVIDER shall not be responsible for investigative costs that do
not result in the SERVICE PROVIDER’S or subcontractor’s suspension or
debarment.
D. The PROVIDER may obtain the current list of suspended and debarred
contractors by contacting the:
Department of General Services
Office of Chief Counsel
603 North Office Building
Harrisburg, PA 17125
Phone: (717) 763-6472
FAX: (717) 787-9138
10. Non-discrimination
The PROVIDER assures that, in compliance with Title VI of the Civil Rights Act of 1964, Section
504 of the Federal Rehabilitation Act of 1973, and the Pennsylvania Human Relations Act of 1955,
as amended:
A. The PROVIDER agrees to comply with the provisions of the Federal Civil Rights
Act of 1964 Title VI, the Pennsylvania Human Relations Act of 1955, as amended,
the Age Discrimination Act of 1974 as amended, Section 504 of the Rehabilitation
Act of 1973 and Executive Orders #II246 and #II375, and all requirements imposed
pursuant thereto, to the end that no person shall, on the grounds of race, color,
national origin, religious creed, ancestry, age, sex or handicap or disability be
excluded from participation in, be denied benefits of, or otherwise be subjected to
discrimination in the pro-vision of any care or service.
B. The PROVIDER will comply with all regulations promulgated to enforce the
statutory provisions against discrimination.
11. Americans with Disabilities Act (ADA)
Pursuant to the federal regulations promulgated under the authority of The Americans with
Disabilities Act, 28 C.F.R. § 35.101, et. seq., PROVIDER understands and agrees that it shall not
cause any individual with a disability to be excluded from participation in this Agreement or from
7
activities provided for under this Agreement on the basis of a disability as defined by the Act. As
a condition of accepting this Agreement, PROVIDER agrees to comply with the “General
Prohibitions Against Discrimination,” 28 C.F.R. § 35.130, and all other regulations promulgated
under Title 11 of The Americans with Disabilities Act which are applicable to all benefits, services,
programs, and activities provided by COUNTY or the Commonwealth of Pennsylvania through
contracts with outside PROVIDERS. PROVIDER shall be responsible for and agrees to indemnify
and hold the COUNTY harmless from all losses, damages, expenses, claims, demands, suits and
actions brought by any party against COUNTY as a result of PROVIDER’S failure to comply with
this provision.
12. Drug Free Workplace Provision
Agreement and Certification Regarding Drug-Free Workplace Requirements
By signing this Agreement, the SERVICE PROVIDER, in accordance with 45 CFR Part 76 and
Part 82, agrees and certifies that it shall provide a drug-free workplace by:
A. Establishing and maintaining a drug-free awareness program to inform employees
about:
1. The dangers of drug abuse in the Workplace; and
2. The policy of the COUNTY of maintaining a drug-free workplace; and
3. Any available drug counseling, rehabilitation, and employee assistance
programs; and
4. The penalties that may be imposed upon employees for drug abuse
violations occurring in the workplace.
B. Publishing a statement notifying employees that the unlawful manufacture,
distribution, dispensing, possession, or use of a controlled substance, or being under
the influence of a controlled substance, is prohibited in the SERVICE
PROVIDER’S workplace and specifying the actions that shall be taken against
employees for violations of such prohibitions.
C. Require that each employee, as a condition of employment, shall:
1. Abide by the terms of the policy noted in (A), above and the COUNTY
Drug Free Policy incorporated into this contract as Attachment I; and
2. Notify the employer of any criminal drug statute conviction for a violation
occurring in the workplace not later than three (3) days after such a
conviction.
D. Notify FRANKLIN COUNTY within five (5) days after receiving notice under
subparagraph (C)(2), above, from an employee or otherwise receiving actual or
constructive notice.
E. Taking one of the following actions, within thirty (30) days of receiving notice
under subparagraph (C)(2), above, with respect to any employee who is so
convicted:
8
1. Taking appropriate personnel action against such an employee, up to and
including termination; or
2. Requiring such an employee to participate satisfactorily in a drug abuse
assistance or rehabilitation program approved for such purposes by a
federal, state, or local health, law enforcement, or other appropriate agency.
13. Applicable Laws
The PROVIDER and any other staff performing services pursuant to this contract, shall comply at
all times relative hereto with all applicable laws and regulations in its business
and activities that pertain to the performance or funding of this Agreement.
PROVIDER shall perform all Services in accordance with the general accepted standards and
practices used in the profession. The PROVIDER shall render diligently and competently all
Services, with due consideration given to applicable laws and regulations. The enumeration of
specific duties and obligations to be performed by the PROVIDER hereunder shall not be
construed to limit the general ethical requirements in the undertakings of the PROVIDER.
14. Approval to Operate
.
The PROVIDER shall ensure that it and all staff working in connection with the services supplied
under the Purchase of Service Agreement possess all necessary licenses, credentials, certifications
and clearances (PA Child Abuse, Criminal Background/Clearance and Federal Bureau of
Investigation Background/Clearance) as required by applicable law ( Act 147 Child Protective
Services Law) and contract. These shall include, without limitation, all licenses required to be
reimbursable for Medical Assistance, Title IV-E, Temporary Assistance for Needy Families or
other third party reimbursements.
The PROVIDER shall provide copies of said documentation to the COUNTY, including, without
limitation, all licenses and clearances
The PROVIDER shall notify the COUNTY in writing within three (3) working days of notification
of any loss/change in status of its license/certificate of compliance/approval to operate for any of
the services being provided to the COUNTY.
15. Liability or Expense
PROVIDER and its employees, consultants and subcontractors shall release, hold harmless, and
indemnify the COUNTY, its officers, elected officials, agents, representatives, and employees
acting within the scope of their official duties from and against damages, costs, and expenses
(including reasonable attorneys’ fees and court costs) to the extent caused by the negligent acts,
errors, or omissions of the PROVIDER, its employees, consultants, agents, servants, and/or anyone
acting under the PROVIDER’S control and/or the PROVIDER’S direction, in the performance of
the requirements of this Agreement. The PROVIDER shall defend any lawsuit commenced
against the COUNTY and shall pay any judgments and costs connected with such proceeding
which are based upon the negligent acts or omissions of the PROVIDER or its employees. By
9
entering into this Agreement, the COUNTY does not waive any rights or protections of
governmental immunity in accordance with the Political Subdivision Tort Claims Act, 42
Pa.C.S.A. § 8541 et. seq. and in accordance with such limits of liability set forth in the Act.
16. Assignment
The PROVIDER shall not assign any obligations or benefits of this Agreement without prior
written approval of the COUNTY, which may be withheld for any reason.
17. Independent Contractor
Any Services provided by the PROVIDER or its employees or subcontractors under this
Agreement are provided as independent contractors. Nothing in this Agreement shall be
considered to create the relationship of employer and employee between the parties. The
PROVIDER does not have the power or authority to bind the COUNTY in any promise,
agreement, or representation unless expressly provided written agreement to do so.
18. Notices
Any notices required to be given in accordance with this Agreement shall be in writing and
delivered to the parties by certified mail or personal delivery or acceptable overnight courier
service. Notice that is mailed shall be sent to the following addresses:
If to the COUNTY: Franklin County Commissioners
272 North Second Street
Chambersburg, PA 17201
If to the PROVIDER: Zullinger-Davis-Trinh, P.C.
74 North Second Street
Chambersburg, PA 17201
19. Applicable Law and Venue
This Agreement shall be construed and interpreted in accordance with the laws of the
Commonwealth of Pennsylvania, and in the event of dispute, the venue of any action brought
hereunder, shall be in Court of Common Pleas for the Thirty-Ninth Judicial District, Franklin
County Branch.
20. Complete Agreement
This Agreement, and all attachments which are incorporated by reference, contain all the terms,
provisions, and conditions of this Agreement. Any alteration, variation, modification, or waiver
of a provision of this Agreement shall be valid only when reduced to writing, duly signed by the
parties of this Agreement, and attached to the original of the Agreement. Should any part of this
agreement be determined by a Court of Law to be invalid or unenforceable, all other provisions
10
shall remain binding and enforceable on all parties. If either party waives or fails to enforce any
term of this contract, all other provisions shall remain binding and enforceable on all parties. In
the event COUNTY updates its Drug-Free Workplace Policy or COUNTY, in its sole discretion,
revises its Business Associate Agreement during the term of the herein Agreement, PROVIDER
agrees to cooperate in the execution of the revised documents.
IN WITNESS WHEREOF, the parties hereto have caused this contract to be executed on their
behalf.
___________________________ __________________________
Dean A. Horst, Chairman PROVIDER
___________________________
John T. Flannery, Commissioner
___________________________
Robert G. Ziobrowski, Commissioner
11
ATTACHMENT A
LISTING OF ATTACHMENTS
ATTACHMENT B – DESCRIPTION OF SERVICES
ATTACHMENT C - PAYMENT SCHEDULE/RATES
ATTACHMENT D – HIPAA BUSINESS ASSOCIATE AGREEMENT
12
ATTACHMENT B
DESCRIPTION OF SERVICES
APPENDIX A- PROVIDER DESCRIPTION OF SERVICES
1. Agency name, address, and hours of operation:
Zullinger-Davis-Trinh, P.C.
74 N Second Street, Chambersburg, PA 17201
Monday – Friday 8:30 a.m. to 4:30 p.m.
2. Program services - Describe services to be provided:
Zullinger-Davis-Trinh, P.C. will provide conflict solicitor services to
Franklin County Children and Youth Services as requested by the Agency.
Services include legal advice, counsel, and representation at Juvenile
Court hearings and Orphans Court matters during the contracted period.
13
ATTACHMENT C
PAYMENT SCHEDULE/RATES
Service Description Rate
Interim Solicitor-billed hourly 75.00$
Franklin County Children & Youth Services
Contract Period: July 01, 2026-June 30, 2027
Contract Rate Sheet
Provider: Zullinger-Davis-Trinh, P.C.
14
ATTACHMENT D
Business Associate Agreement
This Business Associate Agreement (this “Agreement”) is entered into by Zullinger-Davis-
Trinh, P.C. (“Business Associate”) and Franklin County, Pennsylvania (“Covered Entity”),
individually referred to as “Party” and collectively as the “Parties.” This Agreement is effective
as of July 1, 2026 (“Effective Date”).
RECITALS
WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability
and Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the
Administrative Simplification Provisions of HIPAA, including the Privacy Rule and
Security Rule, as defined in Article 1 of this Agreement, and with the applicable
provisions of the Health Information Technology for Economic and Clinical Health Act
of 2009 (“HITECH”).
WHEREAS, Covered Entity has engaged Business Associate to furnish certain services
to Covered Entity pursuant to the Services Agreement, as defined below.
WHEREAS, Business Associate is a business associate under HIPAA. Business
Associate must comply with the provisions of the Privacy Rule and Security Rule made
applicable to business associates pursuant to HITECH and with all other applicable
provisions of HITECH.
WHEREAS, Covered Entity is not permitted to allow Business Associate to create,
receive, maintain, or transmit Protected Health Information on behalf of Covered Entity
without satisfactory assurances that Business Associate will appropriately safeguard the
information. Therefore, Covered Entity will only disclose Protected Health Information
to Business Associate or allow Business Associate to create or receive Protected Health
Information on behalf of Covered Entity in accordance with the requirements of HIPAA,
HITECH, and provisions of this Agreement.
NOW, THEREFORE, in consideration of the mutual promises below and for other good
and valuable consideration, the receipt and adequacy of which are hereby acknowledged,
the Parties agree as follows:
WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability
and Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the
Administrative Simplification Provisions of HIPAA, including the Privacy Rule and
Security Rule, as defined in Article 1 of this Agreement, and with the applicable
provisions of the Health Information Technology for Economic and Clinical Health Act
of 2009 (“HITECH”).
15
WHEREAS, Covered Entity has engaged Business Associate to furnish certain services
to Covered Entity pursuant to the Services Agreement, as defined below.
WHEREAS, Business Associate is a business associate under HIPAA. Business
Associate must comply with the provisions of the Privacy Rule and Security Rule made
applicable to business associates pursuant to HITECH and with all other applicable
provisions of HITECH.
WHEREAS, Covered Entity is not permitted to allow Business Associate to create,
receive, maintain, or transmit Protected Health Information on behalf of Covered Entity
without satisfactory assurances that Business Associate will appropriately safeguard the
information. Therefore, Covered Entity will only disclose Protected Health Information
to Business Associate or allow Business Associate to create or receive Protected Health
Information on behalf of Covered Entity in accordance with the requirements of HIPAA,
HITECH, and provisions of this Agreement.
NOW, THEREFORE, in consideration of the mutual promises below and for other good
and valuable consideration, the receipt and adequacy of which are hereby acknowledged,
the Parties agree as follows:
ARTICLE I
DEFINITIONS
Terms used in this Agreement that are specifically defined in HIPAA shall have the same
meaning as set forth in HIPAA. A change to HIPAA which modifies any defined HIPAA term,
or which alters the regulatory citation for the definition shall be deemed incorporated into this
Agreement.
1.1 Breach means the unauthorized acquisition, access, use, or disclosure of Protected
Health Information which compromises the security or privacy of such
information, except where an unauthorized person to whom such information is
disclosed would not reasonably have been able to retain such information. The
term “breach” does not include the exceptions described in 42 U.S.C.
§ 17921(1)(B) summarized below.
(a) Certain uses or disclosures by a Covered Entity’s work-force members
(defined as persons acting under the authority of the Covered Entity or
Business Associate), if the use or disclosure was made in good faith, was
within the scope of the disclosing individual’s authority, and does not
result in a further violation of the Privacy Rule.
(b) Inadvertent disclosures from one person who is authorized to access PHI
to another person who is also authorized to access PHI within the same
16
Covered Entity, Business Associate, or organized health care arrangement
when the disclosed PHI is not further used or disclosed in a manner not
permitted under the Privacy Rule.
(c) A disclosure of PHI when a Covered Entity or Business Associate has a
good faith belief that an unauthorized person to whom the disclosure was
made would not reasonably have been able to retain such information.
1.2 Designated Record Set, as defined under the Privacy Rule at 45 C.F.R. § 164.501,
means a group of records maintained by or for a Covered Entity that are:
(a) the medical records and billing records about individuals maintained by or
for a covered health care Contractor;
(b) the enrollment, payment, claims adjudication, and case or medical
management record systems maintained by or for a health care plan; or
(c) used, in whole or in part, by or for the Covered Entity to make decisions
about individuals.
For purposes of this section, a “Record” is any item, collection, or grouping of information that
includes PHI and is maintained, collected, used, or disseminated by or for a Covered Entity.
1.3 Electronic Health Record has the same meaning that applies under Section
13400(5) of ARRA and currently means an electronic record of health-related
information on an individual that is created, gathered, managed, and consulted by
authorized staff.
1.4 Electronic Protected Health Information (EPHI), as defined by 45 C.F.R.
§ 160.103, means individually identifiable health information that is transmitted
by electronic media, or maintained in electronic media, but not certain education
and employment records described in 45 C.F.R. § 160.103, the definition of
Protected Health Information. EPHI also includes any EPHI provided by Covered
Entity or created or received by Business Associate on behalf of Covered Entity.
1.5 HHS means the U.S. Department of Health and Human Services.
1.6 Individual, as defined by 45 C.F.R § 160.103, means the person who is the subject
of PHI. It also includes a person who qualifies as a Personal Representative in
accordance with 45 C.F.R. § 164.502(g).
1.7 Limited Date Set, as defined by 45 C.F.R. §164.514(e) is partially de-identified
data that may be used or disclosed for research, public health and health care
17
operation purposes, such as quality assurance, as long as a recipient signs a data
use agreement that complies with HIPAA requirements.
1.8 Privacy Rule means the Standards for Privacy of individually Identifiable Health
Information codified at 45 C.F.R. §§ 160 and 164, Subpart E, any other applicable
provision of HIPAA, and any amendments to HIPAA, including HITECH.
1.9 Protected Health Information (PHI) as defined by 45 C.F.R. § 164.103, mean
individually identifiable health information that is:
(a) transmitted by electronic media;
(b) maintained in electronic media; or
(c) transmitted or maintained in any other form or medium;
PHI does not include certain education and employment records described in 45 C.F.R.
§ 160.103, the definition of PHI. PHI includes, without limitation, any PHI provided by Covered
Entity or created or received by Business Associate on behalf of Covered Entity. Unless
otherwise stated in this Agreement, any provision, restriction, or obligation in this Agreement
related to the use of PHI shall apply equally to EPHI.
1.10 Required By Law, as defined by 45 C.F.R. § 164.103, means a mandate contained
in law that compels an entity to make a use or disclosure of PHI and that is
enforceable in a court of law; and any additional requirements created under
HITECH.
1.11 Secretary means the Secretary of the Department of Health and Human Services
or his/her designee.
1.12 Security Incident, as defined by 45 C.F.R. § 164.304, means the attempted or
successful unauthorized access, use, disclosure, modification, or destruction of
information or interference with system operations in an information system.
1.13 Security Rule means the Security Standards for the Protection of Electronic
Protected Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart C,
any other applicable provision of HIPAA, and any amendments to HIPAA,
including HITECH.
1.14 Services Agreement means the underlying agreement(s) that outline the terms of
the services that Business Associate agrees to provide to Covered Entity and that
fall within the functions, activities or services described in the definition of
Business Associate at 45 C.F.R. § 160.103.
18
1.15 Unsecured PHI shall mean PHI that is not rendered unusable, unreadable, or
indecipherable to unauthorized individuals through the use of a technology or
methodology specified by the Secretary of HHS, such as encryption in
compliance with the National Institute of Standards and Technology standards or
destruction.
ARTICLE II
BUSINESS ASSOCIATE OBLIGATIONS
2.1 Request, Use and Disclosure of PHI. Business Associate agrees that it will only
request, use and disclose PHI in accordance with the terms of this Agreement, and
as is Required by Law. Business Associate acknowledges that it may only
request, use and disclose PHI obtained or created pursuant to this Agreement with
Covered Entity if the request, use or disclosure is in compliance with each
applicable requirement of the Privacy Rule found in 45 C.F.R. § 164.504(e).
2.2 Permitted Requests, Uses and Disclosures. Business Associate will not request,
use or disclose PHI except for the purpose of performing Business Associate’s
obligations to Covered Entity as described in the Services Agreement, consistent
with the requirements of HIPAA and this Agreement, and for other uses and
disclosures permitted under this Agreement. Business Associate may request, use
or disclose PHI only if such request, use or disclosure does not violate the Privacy
Rule or this Agreement. To the extent Business Associate is to carry out any of
Covered Entity’s obligations under the Privacy Rule, Business Associate will
comply with the requirements of the Privacy Rule that apply to Covered Entity in
the performance of the applicable obligations.
In accordance with the provisions of 45 C.F.R. § 164.504(e)(4), Business Associate also may
request, use or disclose PHI, if necessary:
(a) for the proper management and administration of Business Associate’s
organization, or
(b) to carry out the legal responsibilities of Business Associate.
Business Associate may only disclose PHI for these purposes, in accordance with the provisions
of 45 C.F.R. § 164.504(e)(4)(ii), if either
(i) the disclosure is Required By Law, or
(ii) Business Associate obtains reasonable written assurances from the
person to whom Business Associate discloses the PHI that the PHI
will be held confidentially and used or further disclosed only as
Required By Law or for the purposes for which it was disclosed to
19
the person and that the person agrees to notify Business Associate
of any instances of which it is aware in which the confidentiality of
the information has been breached.
2.3 Prohibited Requests, Use and Disclosures. Business Associate will not request,
use or disclose PHI in any manner that constitutes a violation of the Privacy Rule,
this Agreement, or the Services Agreement.
2.4 Minimum Requirements. Business Associate will only request, use and disclose
the minimum amount of PHI necessary for Business Associate to perform the
services for which it has been retained by Covered Entity, in accordance with 42
U.S.C. § 17935(b). Business Associate agrees to comply with the Secretary’s
guidance on what constitutes minimum necessary.
2.5 Administrative, Physical and Technical Safeguards. Business Associate will
develop, implement, maintain, and use appropriate safeguards to prevent any use
or disclosure of the PHI other than as provided by this Agreement. Business
Associate will implement administrative, physical, and technical safeguards that
reasonably and appropriately protect the confidentiality, integrity and availability
of EPHI. Business Associate acknowledges that the Security Rule provisions
regarding administrative, physical, and technical safeguards, policies and
procedures and documentation requirements found in 45 C.F.R. §§ 164.308,
164.310, 164.312 and 164.316 apply to Business Associate in the same manner as
to Covered Entity and Business Associate will fully comply with such Security
Rule provisions.
2.6 Unusable, Unreadable or Indecipherable Technology. Business Associate will, to
the extent feasible, adopt a technology or methodology specified by the Secretary
pursuant to 42 U.S.C. § 17932(h) that renders PHI unusable, unreadable, or
indecipherable to unauthorized individuals.
2.7 Agents and Sub-contractors. Prior to making any permitted disclosures, Business
Associate will ensure that any of its agents, including subcontractors, to whom it
provides PHI received from, or created or received by, Business Associate on
behalf of Covered Entity agree in writing to be bound by the same privacy and
security restrictions and conditions that apply to Business Associate under this
Agreement, including but not limited to those conditions relating to termination of
the contract for improper disclosure. Further, Business Associate shall implement
and maintain sanctions against agents and subcontractors, if any, that violate such
restrictions and conditions. Business Associate shall terminate any agreement
with an agent or subcontractor, if any, who fails to abide by such restrictions and
obligations. Business Associate shall not provide any PHI to any third party or
subcontract any services described in the Services Agreement without Covered
Entity’s express written permission.
20
2.8 Reporting Obligations. Business Associate will report, in writing, to Covered
Entity any use or disclosure of PHI that is not authorized by this Agreement,
including Breaches of Unsecured PHI. In addition, Business Associate will report
in writing, to Covered Entity any Security Incident of which it becomes aware
that it, its employees, or its agents or subcontractors experience involving or
potentially involving Covered Entity EPHI. The written notice shall be provided
to Covered Entity within five (5) business days of becoming aware of the non-
authorized use or disclosure or Security Incident.
2.9 Notification to Covered Entity of Breach of Unsecured PHI. Business Associate
will provide written notification to Covered Entity within seventy-two (72) hours
of discovering a Breach of Unsecured PHI. Such notification will identify, to the
extent possible, (1) each individual whose Unsecured Protected Health
Information has been, or is reasonably believed by Business Associate to have
been, accessed, acquired or disclosed during the Breach, (2) the nature of the non-
permitted access, use or disclosure, including the date of the Breach and the date
of discovery of the Breach; (3) Protected Health Information accessed, used or
disclosed as part of the Breach (e.g., full name, social security number, date of
birth, etc.); (4) who or what area of Business Associate’s operation made the non-
permitted access, use or disclosure and who received the non-permitted
disclosure; (5) identify what corrective action the Business Associate took or will
take to prevent further non-permitted accesses, uses or disclosures; (6) identify
what Business Associate did or will do to mitigate any deleterious effect of the
non-permitted access, use or disclosure; and (7) provide such other information
that is reasonably available to Business Associate that Covered Entity may
request. For purposes of the preceding sentence, Business Associate will be
treated as discovering the Breach on the first day on which the Breach is known
(or by exercising reasonable diligence should have been known) to Business
Associate (including any employee, officer or other agent of Business Associate
other than the person committing the Breach). Whether a Breach has occurred
will be determined in accordance with applicable regulations or other
authoritative guidance issued pursuant to the HITECH Act. A delay in
notification of a Breach that qualifies as a “law enforcement delay” under 45 CFR
Section 164.412 will not be treated as a violation of this Agreement. Business
Associate will supplement its initial notification to Covered Entity with additional
information as any additional information becomes available. Business Associate
will implement a reasonable system for discovery of Breaches.
2.10 Breach Notification Expenses. Business Associate agrees to indemnify, defend,
and hold harmless Covered Entity and its employees, agents, and representatives
from any and all direct, reasonable and actual costs, settlements, judgments, and
expenses incurred by Covered Entity caused by a Breach of Unsecured Protected
Health Information while in the possession of Business Associate, or its
employees, subcontractors or agents. Such costs will include those related to
Breach notifications sent to the affected individuals and the media, as required by
Section 13402(e) of ARRA and 45 CFR Part 164, and any costs incurred by
Covered Entity or its employees, agents or representatives to mitigate potential
harm to individuals from the Breach.
21
2.11 Notification to Covered Entity of Use or Disclosure Data. Business Associate
will notify Covered Entity in writing of any actual or suspected use or disclosure
of data in violation of any applicable federal or state laws or regulations or any
legal action against Business Associate arising from an alleged HIPAA violation.
Business Associate shall take:
(i) prompt action to correct any such deficiencies; and
(ii) any action pertaining to such unauthorized disclosure required by
applicable federal and state laws and regulations.
Business Associate will provide the written notice to Covered Entity within five (5) business
days of becoming aware of the violation or legal action.
2.12 Mitigation of Harmful Effect. Business Associate agrees to mitigate, to the extent
practicable, any harmful effect that is known to Business Associate of a use or
disclosure of PHI by Business Associate in violation of the requirements of this
Agreement
2.13 Designated Record Sets. Business Associate will make PHI in Designated Record
Sets that are maintained by Business Associate or its agents or subcontractors, if
any, available to Covered Entity or to an individual for inspection and copying
within ten (10) business days of a request by Covered Entity to enable Covered
Entity to fulfill its obligations under the Privacy Rule, including, but not limited
to the requirements concerning access to individuals to PHI found at 45 C.F.R.
§ 164.524. If Business Associate maintains Protected Health information in the
form of an Electronic Health Record for any individual, Business Associate
agrees to provide, at the request of Covered Entity or an individual, and in the
time and manner designated by Covered Entity, a copy of such information in an
electronic format to that individual or, if clearly, conspicuously and specifically
directed by the individual (or by Covered Entity based on a clear, conspicuous
and specific request of the individual) to transmit an electronic copy of that
information directly to an entity or person designated by the individual. Any fee
charged to the individual for providing such information (or a summary or
explanation of such information) may not exceed Business Associate’s labor costs
incurred in responding to the individual’s request.
2.14 Amendments to PHI and EPHI. Within ten (10) business days of receipt of a
request from Covered Entity for an amendment of PHI or a record about an
individual contained in a Designated Record Set, Business Associate or its agents
or subcontractors, if any, shall make such PHI available to Covered Entity for
amendment and shall incorporate any such amendment to enable Covered Entity
to fulfill its obligations under the Privacy Rule, including, but not limited to,
45 C.F.R. § 164.526. If an individual requests an amendment of PHI directly
from Business Associate or its agents or subcontractors, if any, Business
Associate must notify Covered Entity in writing within five (5) business days of
the request. Any denial of amendment of PHI maintained by Business Associate
22
or its agents or subcontractors, if any, shall be the responsibility of Covered
Entity. Upon the approval of Covered Entity, Business Associate shall
appropriately amend the PHI maintained by it, or any agents or subcontractors.
2.15 Accounting of PHI and EPHI. Within ten (10) business days of notice by
Covered Entity of a request for an accounting of disclosures of PHI, Business
Associate and any agents or subcontractors shall make available to Covered
Entity the information required to provide an accounting of disclosures to enable
Covered Entity to fulfill its obligations under the Privacy Rule, including, but not
limited to, 45 C.F.R. § 164.528 and any additional information required under the
HITECH Act, including Section 13405(c) if Business Associate maintains
information in the form of an Electronic Health Record, and any implementing
regulations.
(a) If a request for an accounting is made directly to Business Associate or its
agents or subcontractors, Business Associate will notify Covered Entity of
the request within five (5) business days of having received the request.
Covered Entity shall either inform Business Associate to provide the
requested information directly to the individual or request Business
Associate to immediately forward the information to the Covered Entity
for compilation and distribution to the individual.
(b) In the case of a direct request for an accounting from an individual related
to treatment, payment or health care operations disclosures through
Electronic Health Records, Business Associate will provide the accounting
to the individual in accordance with 42 U.S.C. § 17935(c) and any
regulations adopted subsequent to this Agreement. Business Associate
will confirm with Covered Entity that Covered Entity provided Business
Associate’s name to the individual in response to a request for an
accounting before providing the requested accounting to the individual.
2.16 Retention of Accounting Documentation. Notwithstanding termination of this
Agreement, Business Associate and any of its agents or subcontractors shall
continue to maintain the information required for purposes of complying with this
Section 2.14 for a period of six (6) years after termination of the Agreement.
2.17 Business Associate’s Compliance with HHS. Business Associate will make its
internal practices, books and records relating to the use and disclosure of PHI
available to the Secretary of HHS in the time and manner designated by the
Covered Entity or the Secretary of HHS for purposes of determining Covered
Entity’s compliance with the Privacy Rule. Business Associate will notify
Covered Entity regarding any PHI that Business Associate provides to the
Secretary of HHS concurrently with providing the requested PHI to the Secretary
of HHS. Upon request by Covered Entity, Business Associate will provide
Covered Entity with a duplicate copy of the requested PHI.
23
2.18 Inspection by Covered Entity. Within five (5) business days of a written request
by Covered Entity, Business Associate and its agents or subcontractors, if any,
shall allow Covered Entity to conduct a reasonable inspection of the facilities,
systems, books, records, agreements, policies and procedures relating to the use or
disclosure of PHI pursuant to this Agreement for the purpose of determining
whether Business Associate has complied with this Agreement, the Security Rule
and provisions of the Privacy Rule directly applicable to Business Associate or as
deemed necessary by Covered Entity to determine whether a Breach has occurred.
Both Parties agree to the following:
(a) Business Associate will cooperate with Covered Entity’s risk assessment
without unreasonable delay;
(b) Business Associate and Covered Entity will mutually agree in advance
upon the scope, location and timing of such an inspection; and
(c) Covered Entity will protect the confidentiality of all confidential and
proprietary information of Business Associate to which Covered Entity
has access during the course of such inspection.
2.19 Damages. Business Associate shall be responsible to compensate the affected
individual for any reasonable damages as a result of a Breach caused by Business
Associate.
2.20 No Ownership Rights. Business Associate agrees that Business Associate does
not and will not have any ownership rights in any of the PHI.
2.21 Additional HITECH Requirements. The additional requirements of Title XIII of
HITECH that relate to privacy and security and that are made applicable with
respect to covered entities are also applicable to Business Associate and by this
reference these requirements are hereby incorporated into this Agreement.
2.22 Standard Transactions. In conducting any standard transaction that is subject to
the Standard Transaction Regulations (set forth in 45 C.F.R. Part 162) on behalf
of Covered Entity, Business Associate agrees to comply with all requirements of
the Standard Transaction Regulations that would apply to Covered Entity if
Covered Entity were conducting the transaction itself and shall require the same
of any subcontractor or agent involved with the conducts of such Standard
Transactions.
2.23 Limitations on Marketing. Business Associate may not use and disclose PHI for
“marketing,” as defined in 45 C.F.R. § 164.501, unless expressly permitted to do
so in the Services Agreement.
24
2.24 Sale of PHI. Except for compensation set forth in the Services Agreement
between Business Associate and Covered Entity, Business Associate shall not
receive any direct or indirect remuneration in exchange for the provision of
Protected Health Information.
ARTICLE III
COVERED ENTITY OBLIGATIONS
3.1 Risk Assessment of Breach by Covered Entity. Covered Entity shall make the
final determination of whether for a Breach of PHI occurred.
3.2 Restrictions. Covered Entity shall notify Business Associate of any restriction to
the use or disclosure of PHI that Covered Entity has agreed to or must comply
with in accordance with 45 C.F.R. § 164.522 and 42 U.S.C. § 17935(a).
3.3 Notification of Changes or Revocations of Permission. Covered Entity shall
provide Business Associate with notice of any changes to, revocation of, or
permission by individual to use or disclose PHI, if such changes affect Business
Associate’s permitted uses or disclosures, within a reasonable period of time after
Covered Entity becomes aware of such changes to or revocation of permission.
3.4 Permissible Requests by Covered Entity. Covered Entity shall not request
Business Associate to use or disclose PHI in any manner that would not be
permissible under the Privacy and Security Rules if done by Covered Entity.
ARTICLE IV
TERMINATION
4.1 Term and Survival. The term of this Agreement shall be effective as of the
Effective Date of this Agreement and continue until terminated by Covered Entity
or any underlying Services Agreement expires or is terminated. Any provision
related to the use, disclosure, access, or protection of PHI or EPHI or that by its
terms shall survive termination of this Agreement shall survive termination.
4.2 Termination for Breach. A material breach by Business Associate, or its agents or
subcontractors, if any, of this Agreement, as determined by Covered Entity, shall
constitute a material breach of the Services Agreement. As provided for under 45
C.F.R. §§ 164.314(a)(2)(i)(D) and 164.504(e)(2)(iii), the Covered Entity may
immediately terminate this Agreement and the Services Agreement or,
alternatively, the Covered Entity may choose to provide Business Associate with
written notice of the material breach and an opportunity to cure the material
breach or end the violation within thirty (30) calendar days. If Business Associate
becomes aware of a material breach of this Agreement by Covered Entity,
25
Business Associate shall (1) provide an opportunity for Covered Entity to cure the
breach or end the violation and terminate this Agreement (and any applicable
portion of the Services Agreement between the parties) if Covered Entity does not
cure the breach or end the violation within thirty (30) calendar days, or (2)
immediately terminate this Agreement (and any applicable portion of the Services
Agreement ) if Covered Entity has breached a material term of this Agreement
and cure is not possible.
4.3 Termination for Violation by Business Associate. Covered Entity may terminate
this Agreement and the Services Agreement effective immediately, if (i) Business
Associate is named as a defendant in a criminal proceeding for a violation of
HIPAA, HITECH, or other security or privacy laws or (ii) there is a finding or
stipulation that Business Associate has violated any standard or requirement of
HIPAA, HITECH, or other security or privacy laws in any administrative or civil
proceeding in which Business Associate is involved.
4.4 Return or Destruction of PHI.
(a) Upon termination of this Agreement for any reason, Business Associate
shall return or, at Covered Entity’s request, destroy all PHI received from
Covered Entity or created or received by Business Associate on behalf of
Covered Entity that Business Associate still maintains in any form. If
Business Associate destroys the PHI, Business Associate shall certify in
writing to Covered Entity that such PHI has been destroyed. This
provision applies to PHI that is in the possession of agents or
subcontractors of Business Associate. Business Associate will retain no
copies of the PHI.
(b) If Business Associate determines that returning or destroying the PHI is
not feasible, Business Associate shall explain to Covered Entity why
conditions make the return or destruction of the PHI not feasible. If
Covered Entity agrees that the return or destruction of PHI is not feasible,
Business Associate will retain the PHI, subject to all of the protections of
this Agreement, and limit further uses and disclosures of the PHI to those
purposes that make the return or destruction of the PHI infeasible for so
long as Business Associate maintains the PHI.
(c) If Business Associate determines that it is infeasible to obtain from an
agent or subcontractor any PHI in the possession of the agent or
subcontractor or to destroy the PHI, Business Associate will provide
Covered Entity written notification explaining why obtaining the PHI is
infeasible. If Covered Entity agrees that the return or destruction of PHI is
not feasible, Business Associate will require the agent or subcontractor to
extend the protections of this Agreement to the PHI and limit further uses
and disclosures of the PHI to those purposes that make the return or
26
destruction of the PHI infeasible for so long as the agent or subcontractor
maintains the PHI.
4.5 Termination of Services Agreement. If this Agreement is terminated for any
reason, Covered Entity will also terminate the Services Agreement between the
Parties. This provision shall supersede any termination provision to the contrary
which may be set forth in the Services Agreement.
ARTICLE V
MISCELLANEOUS
5.1 Acknowledgement. By affixing their respective signatures below, the Parties
certify that they have read and understand each and every provision in this
Agreement. Each Party certifies that it possesses the authority to enter into the
Agreement. The execution and performance of this Agreement by each Party has
been duly authorized by all necessary laws, resolutions or corporate actions, and
the Agreement constitutes valid and enforceable obligations of each Party in
accordance with its terms.
5.2 Amendment. This Agreement shall not be amended, altered, or modified, except
by an instrument in writing duly executed by the Parties to the Agreement.
5.3 Assignment. This Agreement may not be assigned by Business Associate without
the prior written consent of Covered Entity.
5.4 Binding Effect. Subject to provisions hereof restricting assignment, this
Agreement shall be binding upon and shall inure to the benefit of the Parties and
their respective successors and permitted assigns.
5.5 Change in Law. The Parties agree to take such action as is necessary to amend
this Agreement from time to time as is necessary for Covered Entity and Business
Associate to comply with the requirements of HIPAA and the HITECH Act, and
of the regulations issued pursuant to those laws. If Covered Entity reasonably
concludes that an amendment to this Agreement is needed because of change in
federal or state law or changing industry standards, Covered Entity shall notify
Business Associate of such proposed modification(s), “Legally-Required
Modifications”. Such Legally Required Modifications shall be deemed accepted
by Business Associate and this Agreement so amended, if Business Associate
does not, within thirty (30) calendar days following the date of notice, or within
such other time period as may be mandated by applicable state or federal law,
deliver to Covered Entity its written rejection of such Legally-Required
Modifications.
27
5.6 Compliance with Laws. Business Associate will comply with all applicable
federal and state security and privacy laws, to the extent that such laws apply to
Business Associate or are more protective of individual privacy than HIPAA.
5.7 Entire Agreement. This Agreement, including attachments, constitutes the entire
Agreement between the Parties with respect to the subject matter hereof, and it
supersedes all prior oral or written agreements, commitments, or understandings
with respect to the matters provided for herein.
5.8 Execution. This Agreement and any amendments thereto shall be executed in
duplicate copies on behalf of the Parties by an official of each, specifically
authorized by its respective Party to perform such executions. Each duplicate
copy shall be deemed an original, but both duplicate originals together constitute
one and the same instrument.
5.9 Indemnification by Business Associate. Business Associate and any of its
subcontractors and agents shall indemnify, hold harmless and defend Covered
Entity and its employees, officers, directors, agents, and contractors from and
against any and all claims, losses, liabilities, costs, attorneys’ fees, and other
expenses incurred as a result of or arising directly or indirectly out of or in
connection with Business Associate’s or its subcontractors’ or agents’ breach of
this Agreement, violation of HIPAA, HITECH or other applicable law, or
otherwise related to the acts or omissions of Business Associate or its
subcontractors or agents.
5.10 Independent Contractors. This Agreement establishes an independent contractor
relationship between Covered Entity and Business Associate. Nothing in this
Agreement is intended, nor may anything be construed, to create a partner, joint
venture employer/employee, or agent relationship.
5.11 Limitations on Benefits of this Agreement. Nothing express or implied in this
Agreement is intended to confer, nor shall anything herein confer, upon any
person other than Covered Entity, Business Associate, or their respective
successors or assigns, any rights, remedies, obligations or liabilities whatsoever.
It is the express intent of the Parties that no person or entity other than the Parties
shall be entitled to bring any action to enforce any provision of this Agreement
against either of the Parties, and that the Agreement set forth shall be solely for
the benefit of, and shall be enforceable only by, the Parties to this Agreement or
their respective successors and assigns as permitted hereunder.
5.12 Notices. All notices which are required or permitted to be given pursuant to this
Agreement shall be in writing and shall be sufficient in all respects if delivered
personally, by electronic facsimile (with a confirmation by registered or certified
mail placed in the mail no later than the following day), or by registered or
certified mail, postage prepaid, addressed to a Party as indicated below:
28
If to Business Associate: If to Covered Entity, to:
Zullinger-Davis-Trinh, P.C. Franklin County Human Services
74 North Second Street 272 North Second Street
Chambersburg, PA 17201 Chambersburg, PA 17201
Notice shall be deemed to have been given upon transmittal thereof as to communications which
are personally delivered or transmitted by electronic facsimile and, as to communications made
by United States mail, on the third (3rd) day after mailing. The above addresses may be changed
by giving notice of such change in the manner provided above for giving notice.
5.13 References. A reference in this Agreement to a section in the Privacy Rule or
Security Rule means the section as in effect or as amended at the time of
reference and as interpreted pursuant to any applicable guidance provided by the
Secretary or other responsible regulatory authority and any applicable case law.
5.14 Severability. If any part of any provision of this Agreement, or any other
agreement, document or writing given pursuant to or in connection with this
Agreement, shall be held invalid or unenforceable, the holding of invalidity or
unenforceability will apply to the invalid or unenforceable part of the provision
only, without in any way affecting the remaining parts of said provision or the
remaining provisions of said Agreement.
5.15 Sub-Contract. Business Associate may not sub-contract any services under the
Services Agreement without the express written consent of Covered Entity.
5.16 Waiver. Neither the waiver by either Party of a breach of or a default under any
of the provisions of this Agreement, nor the failure of either of the Parties, on one
or more occasions, to enforce any of the provisions of this Agreement or to
exercise any rights or privilege hereunder shall thereafter be construed as a waiver
of any subsequent breach or default of a similar nature, or as a waiver of any such
provisions, rights or privileges hereunder.
5.17 Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a
meaning that permits Covered Entity to comply with applicable requirements of
HIPAA HITECH Act, the Privacy Rule and the Security Rule. Any conflict
between a provision of the Services Agreement and this Agreement regarding the
subject matter of this Agreement, shall be resolved in favor of this Agreement
29
IN WITNESS WHEREOF, the parties have caused this Agreement to be executed by their
respective duly authorized representatives as of the dates set forth below.
BUSINESS ASSOCIATE COVERED ENTITY
By: By:
Name: Name:
Title: Title:
Suzanne Trinh
Managing Shareholder
30
EXHIBIT A
PERMITTED USES AND DISCLOSURES
This Exhibit sets forth the permitted uses and disclosures of Information by Associate. This
Exhibit may be amended from time to time if applicable.
Purpose(s) of Disclosure. The purpose(s) for which County shall disclose Information to Associate
are as follows: To ensure Associate has all necessary information available to provide appropriate
care/treatment that the Associate is contracted to perform.
Information to be disclosed. County shall disclose the following Information to Associate in
accordance with the terms of the Agreement: Any and all information that may be necessary to
ensure proper care/treatment is provided to the identified client.
Permitted Uses and Disclosures of Information. Associate shall be limited to the following uses
and/or disclosures of County’s PHI: Associate may use or disclose information, as it deems
necessary in order to ensure client receives appropriate care/treatment.
Subcontractor(s). If Associate intends to utilize any subcontractor(s) in performing Associate's
obligations under the Agreement, such subcontractor(s) shall be identified as follows: An individual
or agency that the Service Provider may contract with to provide direct provider services.
5. Disclosure and Use for Management and Administration. Associate may use or disclose
PHI received by Associate in its capacity as a Business Associate of County for the proper
management and administration of Associate, if such use and disclosure is necessary (i) for the
proper management and administration of Associate or (ii) to carry out the legal responsibilities of
Associate.
6. Data Aggregation Services. For purposes of this Section, "Data Aggregation" means, with
respect to County’s PHI, the combining of such PHI by Associate with the PHI received by
Associate in its capacity as a Business Associate of another Covered Entity to permit data analyses
that relate to the health care operations of the respective Covered Entities. Associate shall provide
the following Data Aggregation services relating to the health care operations of County: Any and
all data prepared by the Associate in connection with services contemplated under the Agreement
shall become the exclusive property of the County.
7. Additional Restrictions on Use of Data. County is a Business Associate of certain other
Covered Entities and, pursuant to such obligations of County, Associate shall comply with the
following restrictions on the use and disclosure of PHI: The County shall have the right to use
such data for any official purpose in whatever manner deemed appropriate. Associate shall not
include in the data it provides to the County any data copyrighted by another entity without the
written approval of the County, unless the Service Provider provides the County with written
permission of the copyright owner for the County to us such copyrighted matter.
31 | P a g e
EXHIBIT B
Pennsylvania Law
If this agreement authorizes the release of Mental Health Records, HIV – related information, or
Substance Abuse treatment information, the following statement must be included with the
information being released:
This information has been disclosed to you from records whose confidentiality is protected
by Pennsylvania Law. Pennsylvania Law prohibits you from making any further disclosure
of this information unless further disclosure is expressly permitted by the written
authorization of the person to whom it pertains or is otherwise permitted by law. A general
authorization for release of medical or other information is not sufficient for this purpose.