Loading...
HomeMy WebLinkAboutChildren & Youth - Zullinger-Davis-Trinh, P.C. 1 AGREEMENT BETWEEN The County of Franklin, Pennsylvania Franklin County Children and Youth Service 425 Franklin Farm Lane Chambersburg, PA 17202 And Zullinger-Davis-Trinh, P.C. July 1, 2026 – June 30, 2027 This AGREEMENT (“Agreement”) is made on ________________________, by and between the County of Franklin, Pennsylvania, hereinafter referred to as the “County” whose principal place of business is 272 North Second Street, Chambersburg, Pennsylvania 17201, and Zullinger- Davis-Trinh, P.C., whose principal place of business is located at 74 North Second Street, Chambersburg, Pennsylvania 17201, hereinafter referred to as the “Provider” and shall be in force and effect from July 1, 2026 through June 30, 2027, inclusive, or until either party gives thirty (30) business days’ written notice that this agreement should be terminated. WHEREAS, the COUNTY is in need of interim Solicitor services for the Franklin County Children & Youth Service; and WHEREAS, the PROVIDER has the necessary qualifications and any required licensure to provide said services for COUNTY; and WHEREAS, the Board of Commissioners of Franklin County has approved this Agreement during a duly advertised meeting. NOW, THEREFORE, in consideration of the mutual promises contained herein, the parties, intending to be legally bound, hereby agree as follows: 1. Recitals The above recitals are incorporated herein by reference thereto and made a part of this AGREEMENT. 2. Services Provided The PROVIDER shall provide Solicitor services (hereinafter referred to as “Services”, as outlined and described in the Provider Program Description(s), Attachment “B”) as requested by the COUNTY for individuals with the Franklin County Children & Youth Service. There is no guarantee of any specified minimum number of hours that the COUNTY shall request services. PROVIDER agrees to comply with the rules, regulations, policies and procedures of CYS; and, to meet her responsibility faithfully and industriously in the provision of legal services, all as directed by CYS. 3. Description of Services 2 A. PROVIDER agrees to perform the services as outlined and described in the Provider Program Description(s) attached hereto and incorporated herein by reference as Attachment “B”, with said Provider Program Description(s) including PROVIDER’S location and hours of operation. B. PROVIDER shall submit to the COUNTY all documents required by Attachment “A”,(Provider Program Description(s) - Attachment “B”, Payment Schedule/Rates – Attachment “C”, HIPAA Business Associate Agreement, - Attachment “D”). C. As is applicable, PROVIDER agrees to complete, submit, and where appropriate, maintain such data and/or data logs as requested by Franklin County Children and Youth Service, and will submit this data in a format as directed by Franklin County Children and Youth Service in a timely manner. 4. Licensure The PROVIDER certifies that all staff performing legal services pursuant to this agreement are currently licensed to practice in the Commonwealth of Pennsylvania and are attorneys in good standing. Should any suspension or revocation of license occur during the term of this agreement, the PROVIDER shall immediately notify COUNTY. 5. Term of Agreement The PROVIDER shall provide Services as requested by the COUNTY during the period beginning July 1, 2026 through June 30, 2027. In the event that the parties are desirous of continuing the relationship set forth in this Agreement but, as of the expiration of the term set forth herein, have not executed a new Agreement, this Agreement shall continue on a month-to-month basis under the same terms and conditions until such time as either party shall give thirty (30) days’ notice of termination. If the COUNTY continues to purchase services under this Agreement beyond the term specified herein but has not executed a new contract pending finalization of the State or Federal funding allocations, or should the parties fail to agree to rates applicable to the next Agreement year, all terms and conditions of this Agreement shall continue to apply and be binding on the parties for the services described herein until a new Agreement has been executed. With respect to the provision of interim Solicitor services, the COUNTY may terminate this Agreement with or without cause for any reason. 6. Payments A. The COUNTY, in consideration of the services performed by the PROVIDER under this Agreement and other costs as specified, shall pay the costs of the services rendered on an hourly or unit-of-service basis, as set forth herein. The fee schedule and/or rates for services as agreed upon by the COUNTY and PROVIDER are listed on Attachment “C”. 3 B. The PROVIDER will render billing statements to the appropriate COUNTY department on said PROVIDER’S Invoice/Letterhead on or before the fifteenth (15th) calendar day of the month immediately following the provision of services. The COUNTY shall issue payment no later than thirty (30) days from receipt of a complete and accurate invoice. Work performed during the time period outlined in Paragraph Three (3) herein but prior to the execution of this Agreement shall be submitted as timely as possible by PROVIDER and the COUNTY will issue payment within forty-five (45) days from receipt of a complete and accurate invoice. The first full month following the execution of this Agreement, the parties shall follow the deadlines set forth in the first sentence of this Paragraph. C. The COUNTY, in its sole judgment, reserves the right to withhold payment if a discrepancy exists that warrants a new billing statement. The COUNTY may only withhold payment for that portion of the statement which is in dispute. It is the responsibility of the COUNTY to notify the PROVIDER of any discrepancy in the billing statement as soon as possible in writing. D. The PROVIDER fully understands that the reimbursement rate is a specific fee-for- service arrangement and, as such, agrees to exempt the COUNTY from any and all additional financial and legal obligations such as social security, federal income tax withholding, and any taxes imposed by any taxing authority. These are regarded as the sole reporting responsibility of the PROVIDER as an independent contractor. 7. Program Records and Retention Requirements: All records shall be retained pursuant to the provisions of this paragraph. A. PROVIDER must maintain records regarding the units of service being provided and billed for, i.e. timesheets, at all times, and the COUNTY shall have access to those records upon request. B. PROVIDER must maintain auditable records at all times and the COUNTY shall have access to those records upon request. C. Audit and Inspection Rights: PROVIDER shall retain records to substantiate all invoices for a period of five (5) years, and the COUNTY shall have the right for review said records, without delay, upon request. D. Records which relate to litigation or the settlement of claims arising out of the performance of this Agreement, or costs and expenses of this Agreement as to which exception has been taken by the auditors, shall be retained by the PROVIDER until such litigation, claims, or exceptions have been disposed of. E. Except for the records described in sub-paragraph D above, the PROVIDER may, in fulfillment of its obligation to retain its records as required by this paragraph, substitute photographs, microphotographs, or other authentic reproductions of such records, after the expiration of two (2) years following the last day of the month of reimbursement to the Provider of the invoice or voucher to which such records 4 relate, unless a shorter period is authorized by DHS, with the concurrence of the auditors. F. Additionally, other regulations may supersede the aforementioned retention requirements, such as the Health Insurance Portability and Accountability Act (HIPAA). At a minimum, HIPAA requires all client-identifying information to be retained for a period of six (6) years after final service payment. The Provider should consult HIPAA regulations for complete compliance requirements. 8. Insurance All insurance provided for in this section shall be obtained under valid and enforceable policies issued by insurers of recognized responsibility that are licensed to do business in the Commonwealth of Pennsylvania. Certificates of insurance evidencing the existence of such insurance shall be submitted to the COUNTY at least ten (10) calendar days before work is begun. If the term of this Agreement coincides with the term of the PROVIDER’S insurance coverage, a certificate of insurance from the expiring policy will be acceptable, but a certificate evidencing renewed coverage, or a new policy must be presented to the COUNTY no later than thirty (30) calendar days after effective date of the policy. Each policy and certificate of insurance shall contain an endorsement naming the COUNTY as an additional insured party there under and a provision requiring that at least thirty (30) calendar days prior written notice be given to the COUNTY in the event the policy is canceled, not renewed or the limits of coverage are reduced. If the PROVIDER desires to self-insure any, or all, of the coverages listed in this section, it shall provide to the COUNTY documentation that such self-insurance has received all the approvals required by law or regulation, as well as the most recent audited financial statement of the PROVIDER’S insurance. Any coverage that is self-insured shall provide the same coverage, limits, and benefits as the coverage listed in this section and shall be approved by COUNTY. If the PROVIDER fails to obtain or maintain the required insurance, the COUNTY shall have the right to treat such failure as a material breach of the Agreement and to exercise all appropriate rights and remedies, including, but not limited to, the right to immediately terminate this Agreement. The PROVIDER shall procure and maintain insurance in full force and effect covering the scope of the services rendered under this Agreement in the types and limits specified below. In addition to the insurance coverage and limits specified herein, the PROVIDER shall obtain any other insurance coverage as may be required by law. A. General Liability Insurance: 1. Limits of Liability: $1,000,000 per occurrence; $1,000,000 in the aggregate. 2. Coverage: Premises operations, contractual liability, personal injury, 5 products liability, and completed operations, vicarious liability for independent contractors, employees and volunteers as additional insured’s, and completed operations coverage. B. Workers’ Compensation and Employers’ Liability Insurance: 1. Limits of Liability: Workmen’s Compensation – Statutory Limits. Employers’ Liability - Statutory Limits. 2. Other States’ coverage and Pennsylvania endorsement. C. Automobile Liability: 1. Limit of Liability: $1,000,000 per occurrence combined single limit for bodily injury and property damage liability. 2. Coverage: Owned, non-owned, and hired vehicles. Coverage limits apply. D. Professional Liability Insurance: 1. Limit of Liability: $1,000,000 per occurrence; $3,000,000 in the aggregate. 2. Coverage for occurrences happening during the performance of services required under this Agreement shall be maintained in full force and effect under the policy. If coverage is on a claims-made basis, the policy shall include “tail coverage” for up to a two-year period of exposure. The PROVIDER will not be covered under the COUNTY’S Professional Liability Policy. PROVIDER certifies they maintain professional liability insurance on all PROVIDER staff performing services pursuant to this agreement and proof of said insurance shall be provided upon request. E. Subcontractors for Direct Client Services: The PROVIDER shall include all subcontractors as insured’s under its policies or shall furnish separate certificates, endorsements or other proof of coverage for each subcontractor. All coverage’s for subcontractors shall be subject to all of the requirements stated in this Agreement. 9. Service Provider Responsibility Provisions A. The PROVIDER certifies that it is not currently under suspension or debarment by the COUNTY, Commonwealth, any other state, or the federal government, and if the PROVIDER cannot so certify, then it agrees to submit a written explanation of why such certification cannot be made. B. If the PROVIDER enters into subcontracts or employs under this Agreement any subcontractors/individuals who are currently suspended or debarred by the COUNTY, Commonwealth or federal government, or who become suspended, or 6 debarred, by the Commonwealth or federal government during the term of this Agreement, or any extension or renewals thereof, the COUNTY or Commonwealth shall have the right to require the PROVIDER to terminate such subcontracts or employment. C. The PROVIDER agrees to reimburse the COUNTY or Commonwealth for the reasonable costs of investigating the PROVIDER’S compliance with terms of this or any other Agreement between the PROVIDER and the COUNTY or Commonwealth which result in the suspension or debarment of the PROVIDER or its subcontractor. Such costs shall include, but are not limited to, salaries of the investigators, including overtime, travel and lodging expenses, and expert witness and documentary fees. The SERVCE PROVIDER shall not be responsible for investigative costs that do not result in the SERVICE PROVIDER’S or subcontractor’s suspension or debarment. D. The PROVIDER may obtain the current list of suspended and debarred contractors by contacting the: Department of General Services Office of Chief Counsel 603 North Office Building Harrisburg, PA 17125 Phone: (717) 763-6472 FAX: (717) 787-9138 10. Non-discrimination The PROVIDER assures that, in compliance with Title VI of the Civil Rights Act of 1964, Section 504 of the Federal Rehabilitation Act of 1973, and the Pennsylvania Human Relations Act of 1955, as amended: A. The PROVIDER agrees to comply with the provisions of the Federal Civil Rights Act of 1964 Title VI, the Pennsylvania Human Relations Act of 1955, as amended, the Age Discrimination Act of 1974 as amended, Section 504 of the Rehabilitation Act of 1973 and Executive Orders #II246 and #II375, and all requirements imposed pursuant thereto, to the end that no person shall, on the grounds of race, color, national origin, religious creed, ancestry, age, sex or handicap or disability be excluded from participation in, be denied benefits of, or otherwise be subjected to discrimination in the pro-vision of any care or service. B. The PROVIDER will comply with all regulations promulgated to enforce the statutory provisions against discrimination. 11. Americans with Disabilities Act (ADA) Pursuant to the federal regulations promulgated under the authority of The Americans with Disabilities Act, 28 C.F.R. § 35.101, et. seq., PROVIDER understands and agrees that it shall not cause any individual with a disability to be excluded from participation in this Agreement or from 7 activities provided for under this Agreement on the basis of a disability as defined by the Act. As a condition of accepting this Agreement, PROVIDER agrees to comply with the “General Prohibitions Against Discrimination,” 28 C.F.R. § 35.130, and all other regulations promulgated under Title 11 of The Americans with Disabilities Act which are applicable to all benefits, services, programs, and activities provided by COUNTY or the Commonwealth of Pennsylvania through contracts with outside PROVIDERS. PROVIDER shall be responsible for and agrees to indemnify and hold the COUNTY harmless from all losses, damages, expenses, claims, demands, suits and actions brought by any party against COUNTY as a result of PROVIDER’S failure to comply with this provision. 12. Drug Free Workplace Provision Agreement and Certification Regarding Drug-Free Workplace Requirements By signing this Agreement, the SERVICE PROVIDER, in accordance with 45 CFR Part 76 and Part 82, agrees and certifies that it shall provide a drug-free workplace by: A. Establishing and maintaining a drug-free awareness program to inform employees about: 1. The dangers of drug abuse in the Workplace; and 2. The policy of the COUNTY of maintaining a drug-free workplace; and 3. Any available drug counseling, rehabilitation, and employee assistance programs; and 4. The penalties that may be imposed upon employees for drug abuse violations occurring in the workplace. B. Publishing a statement notifying employees that the unlawful manufacture, distribution, dispensing, possession, or use of a controlled substance, or being under the influence of a controlled substance, is prohibited in the SERVICE PROVIDER’S workplace and specifying the actions that shall be taken against employees for violations of such prohibitions. C. Require that each employee, as a condition of employment, shall: 1. Abide by the terms of the policy noted in (A), above and the COUNTY Drug Free Policy incorporated into this contract as Attachment I; and 2. Notify the employer of any criminal drug statute conviction for a violation occurring in the workplace not later than three (3) days after such a conviction. D. Notify FRANKLIN COUNTY within five (5) days after receiving notice under subparagraph (C)(2), above, from an employee or otherwise receiving actual or constructive notice. E. Taking one of the following actions, within thirty (30) days of receiving notice under subparagraph (C)(2), above, with respect to any employee who is so convicted: 8 1. Taking appropriate personnel action against such an employee, up to and including termination; or 2. Requiring such an employee to participate satisfactorily in a drug abuse assistance or rehabilitation program approved for such purposes by a federal, state, or local health, law enforcement, or other appropriate agency. 13. Applicable Laws The PROVIDER and any other staff performing services pursuant to this contract, shall comply at all times relative hereto with all applicable laws and regulations in its business and activities that pertain to the performance or funding of this Agreement. PROVIDER shall perform all Services in accordance with the general accepted standards and practices used in the profession. The PROVIDER shall render diligently and competently all Services, with due consideration given to applicable laws and regulations. The enumeration of specific duties and obligations to be performed by the PROVIDER hereunder shall not be construed to limit the general ethical requirements in the undertakings of the PROVIDER. 14. Approval to Operate . The PROVIDER shall ensure that it and all staff working in connection with the services supplied under the Purchase of Service Agreement possess all necessary licenses, credentials, certifications and clearances (PA Child Abuse, Criminal Background/Clearance and Federal Bureau of Investigation Background/Clearance) as required by applicable law ( Act 147 Child Protective Services Law) and contract. These shall include, without limitation, all licenses required to be reimbursable for Medical Assistance, Title IV-E, Temporary Assistance for Needy Families or other third party reimbursements. The PROVIDER shall provide copies of said documentation to the COUNTY, including, without limitation, all licenses and clearances The PROVIDER shall notify the COUNTY in writing within three (3) working days of notification of any loss/change in status of its license/certificate of compliance/approval to operate for any of the services being provided to the COUNTY. 15. Liability or Expense PROVIDER and its employees, consultants and subcontractors shall release, hold harmless, and indemnify the COUNTY, its officers, elected officials, agents, representatives, and employees acting within the scope of their official duties from and against damages, costs, and expenses (including reasonable attorneys’ fees and court costs) to the extent caused by the negligent acts, errors, or omissions of the PROVIDER, its employees, consultants, agents, servants, and/or anyone acting under the PROVIDER’S control and/or the PROVIDER’S direction, in the performance of the requirements of this Agreement. The PROVIDER shall defend any lawsuit commenced against the COUNTY and shall pay any judgments and costs connected with such proceeding which are based upon the negligent acts or omissions of the PROVIDER or its employees. By 9 entering into this Agreement, the COUNTY does not waive any rights or protections of governmental immunity in accordance with the Political Subdivision Tort Claims Act, 42 Pa.C.S.A. § 8541 et. seq. and in accordance with such limits of liability set forth in the Act. 16. Assignment The PROVIDER shall not assign any obligations or benefits of this Agreement without prior written approval of the COUNTY, which may be withheld for any reason. 17. Independent Contractor Any Services provided by the PROVIDER or its employees or subcontractors under this Agreement are provided as independent contractors. Nothing in this Agreement shall be considered to create the relationship of employer and employee between the parties. The PROVIDER does not have the power or authority to bind the COUNTY in any promise, agreement, or representation unless expressly provided written agreement to do so. 18. Notices Any notices required to be given in accordance with this Agreement shall be in writing and delivered to the parties by certified mail or personal delivery or acceptable overnight courier service. Notice that is mailed shall be sent to the following addresses: If to the COUNTY: Franklin County Commissioners 272 North Second Street Chambersburg, PA 17201 If to the PROVIDER: Zullinger-Davis-Trinh, P.C. 74 North Second Street Chambersburg, PA 17201 19. Applicable Law and Venue This Agreement shall be construed and interpreted in accordance with the laws of the Commonwealth of Pennsylvania, and in the event of dispute, the venue of any action brought hereunder, shall be in Court of Common Pleas for the Thirty-Ninth Judicial District, Franklin County Branch. 20. Complete Agreement This Agreement, and all attachments which are incorporated by reference, contain all the terms, provisions, and conditions of this Agreement. Any alteration, variation, modification, or waiver of a provision of this Agreement shall be valid only when reduced to writing, duly signed by the parties of this Agreement, and attached to the original of the Agreement. Should any part of this agreement be determined by a Court of Law to be invalid or unenforceable, all other provisions 10 shall remain binding and enforceable on all parties. If either party waives or fails to enforce any term of this contract, all other provisions shall remain binding and enforceable on all parties. In the event COUNTY updates its Drug-Free Workplace Policy or COUNTY, in its sole discretion, revises its Business Associate Agreement during the term of the herein Agreement, PROVIDER agrees to cooperate in the execution of the revised documents. IN WITNESS WHEREOF, the parties hereto have caused this contract to be executed on their behalf. ___________________________ __________________________ Dean A. Horst, Chairman PROVIDER ___________________________ John T. Flannery, Commissioner ___________________________ Robert G. Ziobrowski, Commissioner 11 ATTACHMENT A LISTING OF ATTACHMENTS ATTACHMENT B – DESCRIPTION OF SERVICES ATTACHMENT C - PAYMENT SCHEDULE/RATES ATTACHMENT D – HIPAA BUSINESS ASSOCIATE AGREEMENT 12 ATTACHMENT B DESCRIPTION OF SERVICES APPENDIX A- PROVIDER DESCRIPTION OF SERVICES 1. Agency name, address, and hours of operation: Zullinger-Davis-Trinh, P.C. 74 N Second Street, Chambersburg, PA 17201 Monday – Friday 8:30 a.m. to 4:30 p.m. 2. Program services - Describe services to be provided: Zullinger-Davis-Trinh, P.C. will provide conflict solicitor services to Franklin County Children and Youth Services as requested by the Agency. Services include legal advice, counsel, and representation at Juvenile Court hearings and Orphans Court matters during the contracted period. 13 ATTACHMENT C PAYMENT SCHEDULE/RATES Service Description Rate Interim Solicitor-billed hourly 75.00$ Franklin County Children & Youth Services Contract Period: July 01, 2026-June 30, 2027 Contract Rate Sheet Provider: Zullinger-Davis-Trinh, P.C. 14 ATTACHMENT D Business Associate Agreement This Business Associate Agreement (this “Agreement”) is entered into by Zullinger-Davis- Trinh, P.C. (“Business Associate”) and Franklin County, Pennsylvania (“Covered Entity”), individually referred to as “Party” and collectively as the “Parties.” This Agreement is effective as of July 1, 2026 (“Effective Date”). RECITALS WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in Article 1 of this Agreement, and with the applicable provisions of the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”). WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to Covered Entity pursuant to the Services Agreement, as defined below. WHEREAS, Business Associate is a business associate under HIPAA. Business Associate must comply with the provisions of the Privacy Rule and Security Rule made applicable to business associates pursuant to HITECH and with all other applicable provisions of HITECH. WHEREAS, Covered Entity is not permitted to allow Business Associate to create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity without satisfactory assurances that Business Associate will appropriately safeguard the information. Therefore, Covered Entity will only disclose Protected Health Information to Business Associate or allow Business Associate to create or receive Protected Health Information on behalf of Covered Entity in accordance with the requirements of HIPAA, HITECH, and provisions of this Agreement. NOW, THEREFORE, in consideration of the mutual promises below and for other good and valuable consideration, the receipt and adequacy of which are hereby acknowledged, the Parties agree as follows: WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in Article 1 of this Agreement, and with the applicable provisions of the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”). 15 WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to Covered Entity pursuant to the Services Agreement, as defined below. WHEREAS, Business Associate is a business associate under HIPAA. Business Associate must comply with the provisions of the Privacy Rule and Security Rule made applicable to business associates pursuant to HITECH and with all other applicable provisions of HITECH. WHEREAS, Covered Entity is not permitted to allow Business Associate to create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity without satisfactory assurances that Business Associate will appropriately safeguard the information. Therefore, Covered Entity will only disclose Protected Health Information to Business Associate or allow Business Associate to create or receive Protected Health Information on behalf of Covered Entity in accordance with the requirements of HIPAA, HITECH, and provisions of this Agreement. NOW, THEREFORE, in consideration of the mutual promises below and for other good and valuable consideration, the receipt and adequacy of which are hereby acknowledged, the Parties agree as follows: ARTICLE I DEFINITIONS Terms used in this Agreement that are specifically defined in HIPAA shall have the same meaning as set forth in HIPAA. A change to HIPAA which modifies any defined HIPAA term, or which alters the regulatory citation for the definition shall be deemed incorporated into this Agreement. 1.1 Breach means the unauthorized acquisition, access, use, or disclosure of Protected Health Information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information. The term “breach” does not include the exceptions described in 42 U.S.C. § 17921(1)(B) summarized below. (a) Certain uses or disclosures by a Covered Entity’s work-force members (defined as persons acting under the authority of the Covered Entity or Business Associate), if the use or disclosure was made in good faith, was within the scope of the disclosing individual’s authority, and does not result in a further violation of the Privacy Rule. (b) Inadvertent disclosures from one person who is authorized to access PHI to another person who is also authorized to access PHI within the same 16 Covered Entity, Business Associate, or organized health care arrangement when the disclosed PHI is not further used or disclosed in a manner not permitted under the Privacy Rule. (c) A disclosure of PHI when a Covered Entity or Business Associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information. 1.2 Designated Record Set, as defined under the Privacy Rule at 45 C.F.R. § 164.501, means a group of records maintained by or for a Covered Entity that are: (a) the medical records and billing records about individuals maintained by or for a covered health care Contractor; (b) the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health care plan; or (c) used, in whole or in part, by or for the Covered Entity to make decisions about individuals. For purposes of this section, a “Record” is any item, collection, or grouping of information that includes PHI and is maintained, collected, used, or disseminated by or for a Covered Entity. 1.3 Electronic Health Record has the same meaning that applies under Section 13400(5) of ARRA and currently means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized staff. 1.4 Electronic Protected Health Information (EPHI), as defined by 45 C.F.R. § 160.103, means individually identifiable health information that is transmitted by electronic media, or maintained in electronic media, but not certain education and employment records described in 45 C.F.R. § 160.103, the definition of Protected Health Information. EPHI also includes any EPHI provided by Covered Entity or created or received by Business Associate on behalf of Covered Entity. 1.5 HHS means the U.S. Department of Health and Human Services. 1.6 Individual, as defined by 45 C.F.R § 160.103, means the person who is the subject of PHI. It also includes a person who qualifies as a Personal Representative in accordance with 45 C.F.R. § 164.502(g). 1.7 Limited Date Set, as defined by 45 C.F.R. §164.514(e) is partially de-identified data that may be used or disclosed for research, public health and health care 17 operation purposes, such as quality assurance, as long as a recipient signs a data use agreement that complies with HIPAA requirements. 1.8 Privacy Rule means the Standards for Privacy of individually Identifiable Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart E, any other applicable provision of HIPAA, and any amendments to HIPAA, including HITECH. 1.9 Protected Health Information (PHI) as defined by 45 C.F.R. § 164.103, mean individually identifiable health information that is: (a) transmitted by electronic media; (b) maintained in electronic media; or (c) transmitted or maintained in any other form or medium; PHI does not include certain education and employment records described in 45 C.F.R. § 160.103, the definition of PHI. PHI includes, without limitation, any PHI provided by Covered Entity or created or received by Business Associate on behalf of Covered Entity. Unless otherwise stated in this Agreement, any provision, restriction, or obligation in this Agreement related to the use of PHI shall apply equally to EPHI. 1.10 Required By Law, as defined by 45 C.F.R. § 164.103, means a mandate contained in law that compels an entity to make a use or disclosure of PHI and that is enforceable in a court of law; and any additional requirements created under HITECH. 1.11 Secretary means the Secretary of the Department of Health and Human Services or his/her designee. 1.12 Security Incident, as defined by 45 C.F.R. § 164.304, means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. 1.13 Security Rule means the Security Standards for the Protection of Electronic Protected Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart C, any other applicable provision of HIPAA, and any amendments to HIPAA, including HITECH. 1.14 Services Agreement means the underlying agreement(s) that outline the terms of the services that Business Associate agrees to provide to Covered Entity and that fall within the functions, activities or services described in the definition of Business Associate at 45 C.F.R. § 160.103. 18 1.15 Unsecured PHI shall mean PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary of HHS, such as encryption in compliance with the National Institute of Standards and Technology standards or destruction. ARTICLE II BUSINESS ASSOCIATE OBLIGATIONS 2.1 Request, Use and Disclosure of PHI. Business Associate agrees that it will only request, use and disclose PHI in accordance with the terms of this Agreement, and as is Required by Law. Business Associate acknowledges that it may only request, use and disclose PHI obtained or created pursuant to this Agreement with Covered Entity if the request, use or disclosure is in compliance with each applicable requirement of the Privacy Rule found in 45 C.F.R. § 164.504(e). 2.2 Permitted Requests, Uses and Disclosures. Business Associate will not request, use or disclose PHI except for the purpose of performing Business Associate’s obligations to Covered Entity as described in the Services Agreement, consistent with the requirements of HIPAA and this Agreement, and for other uses and disclosures permitted under this Agreement. Business Associate may request, use or disclose PHI only if such request, use or disclosure does not violate the Privacy Rule or this Agreement. To the extent Business Associate is to carry out any of Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of the applicable obligations. In accordance with the provisions of 45 C.F.R. § 164.504(e)(4), Business Associate also may request, use or disclose PHI, if necessary: (a) for the proper management and administration of Business Associate’s organization, or (b) to carry out the legal responsibilities of Business Associate. Business Associate may only disclose PHI for these purposes, in accordance with the provisions of 45 C.F.R. § 164.504(e)(4)(ii), if either (i) the disclosure is Required By Law, or (ii) Business Associate obtains reasonable written assurances from the person to whom Business Associate discloses the PHI that the PHI will be held confidentially and used or further disclosed only as Required By Law or for the purposes for which it was disclosed to 19 the person and that the person agrees to notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached. 2.3 Prohibited Requests, Use and Disclosures. Business Associate will not request, use or disclose PHI in any manner that constitutes a violation of the Privacy Rule, this Agreement, or the Services Agreement. 2.4 Minimum Requirements. Business Associate will only request, use and disclose the minimum amount of PHI necessary for Business Associate to perform the services for which it has been retained by Covered Entity, in accordance with 42 U.S.C. § 17935(b). Business Associate agrees to comply with the Secretary’s guidance on what constitutes minimum necessary. 2.5 Administrative, Physical and Technical Safeguards. Business Associate will develop, implement, maintain, and use appropriate safeguards to prevent any use or disclosure of the PHI other than as provided by this Agreement. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of EPHI. Business Associate acknowledges that the Security Rule provisions regarding administrative, physical, and technical safeguards, policies and procedures and documentation requirements found in 45 C.F.R. §§ 164.308, 164.310, 164.312 and 164.316 apply to Business Associate in the same manner as to Covered Entity and Business Associate will fully comply with such Security Rule provisions. 2.6 Unusable, Unreadable or Indecipherable Technology. Business Associate will, to the extent feasible, adopt a technology or methodology specified by the Secretary pursuant to 42 U.S.C. § 17932(h) that renders PHI unusable, unreadable, or indecipherable to unauthorized individuals. 2.7 Agents and Sub-contractors. Prior to making any permitted disclosures, Business Associate will ensure that any of its agents, including subcontractors, to whom it provides PHI received from, or created or received by, Business Associate on behalf of Covered Entity agree in writing to be bound by the same privacy and security restrictions and conditions that apply to Business Associate under this Agreement, including but not limited to those conditions relating to termination of the contract for improper disclosure. Further, Business Associate shall implement and maintain sanctions against agents and subcontractors, if any, that violate such restrictions and conditions. Business Associate shall terminate any agreement with an agent or subcontractor, if any, who fails to abide by such restrictions and obligations. Business Associate shall not provide any PHI to any third party or subcontract any services described in the Services Agreement without Covered Entity’s express written permission. 20 2.8 Reporting Obligations. Business Associate will report, in writing, to Covered Entity any use or disclosure of PHI that is not authorized by this Agreement, including Breaches of Unsecured PHI. In addition, Business Associate will report in writing, to Covered Entity any Security Incident of which it becomes aware that it, its employees, or its agents or subcontractors experience involving or potentially involving Covered Entity EPHI. The written notice shall be provided to Covered Entity within five (5) business days of becoming aware of the non- authorized use or disclosure or Security Incident. 2.9 Notification to Covered Entity of Breach of Unsecured PHI. Business Associate will provide written notification to Covered Entity within seventy-two (72) hours of discovering a Breach of Unsecured PHI. Such notification will identify, to the extent possible, (1) each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been, accessed, acquired or disclosed during the Breach, (2) the nature of the non- permitted access, use or disclosure, including the date of the Breach and the date of discovery of the Breach; (3) Protected Health Information accessed, used or disclosed as part of the Breach (e.g., full name, social security number, date of birth, etc.); (4) who or what area of Business Associate’s operation made the non- permitted access, use or disclosure and who received the non-permitted disclosure; (5) identify what corrective action the Business Associate took or will take to prevent further non-permitted accesses, uses or disclosures; (6) identify what Business Associate did or will do to mitigate any deleterious effect of the non-permitted access, use or disclosure; and (7) provide such other information that is reasonably available to Business Associate that Covered Entity may request. For purposes of the preceding sentence, Business Associate will be treated as discovering the Breach on the first day on which the Breach is known (or by exercising reasonable diligence should have been known) to Business Associate (including any employee, officer or other agent of Business Associate other than the person committing the Breach). Whether a Breach has occurred will be determined in accordance with applicable regulations or other authoritative guidance issued pursuant to the HITECH Act. A delay in notification of a Breach that qualifies as a “law enforcement delay” under 45 CFR Section 164.412 will not be treated as a violation of this Agreement. Business Associate will supplement its initial notification to Covered Entity with additional information as any additional information becomes available. Business Associate will implement a reasonable system for discovery of Breaches. 2.10 Breach Notification Expenses. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity and its employees, agents, and representatives from any and all direct, reasonable and actual costs, settlements, judgments, and expenses incurred by Covered Entity caused by a Breach of Unsecured Protected Health Information while in the possession of Business Associate, or its employees, subcontractors or agents. Such costs will include those related to Breach notifications sent to the affected individuals and the media, as required by Section 13402(e) of ARRA and 45 CFR Part 164, and any costs incurred by Covered Entity or its employees, agents or representatives to mitigate potential harm to individuals from the Breach. 21 2.11 Notification to Covered Entity of Use or Disclosure Data. Business Associate will notify Covered Entity in writing of any actual or suspected use or disclosure of data in violation of any applicable federal or state laws or regulations or any legal action against Business Associate arising from an alleged HIPAA violation. Business Associate shall take: (i) prompt action to correct any such deficiencies; and (ii) any action pertaining to such unauthorized disclosure required by applicable federal and state laws and regulations. Business Associate will provide the written notice to Covered Entity within five (5) business days of becoming aware of the violation or legal action. 2.12 Mitigation of Harmful Effect. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Agreement 2.13 Designated Record Sets. Business Associate will make PHI in Designated Record Sets that are maintained by Business Associate or its agents or subcontractors, if any, available to Covered Entity or to an individual for inspection and copying within ten (10) business days of a request by Covered Entity to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to the requirements concerning access to individuals to PHI found at 45 C.F.R. § 164.524. If Business Associate maintains Protected Health information in the form of an Electronic Health Record for any individual, Business Associate agrees to provide, at the request of Covered Entity or an individual, and in the time and manner designated by Covered Entity, a copy of such information in an electronic format to that individual or, if clearly, conspicuously and specifically directed by the individual (or by Covered Entity based on a clear, conspicuous and specific request of the individual) to transmit an electronic copy of that information directly to an entity or person designated by the individual. Any fee charged to the individual for providing such information (or a summary or explanation of such information) may not exceed Business Associate’s labor costs incurred in responding to the individual’s request. 2.14 Amendments to PHI and EPHI. Within ten (10) business days of receipt of a request from Covered Entity for an amendment of PHI or a record about an individual contained in a Designated Record Set, Business Associate or its agents or subcontractors, if any, shall make such PHI available to Covered Entity for amendment and shall incorporate any such amendment to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.526. If an individual requests an amendment of PHI directly from Business Associate or its agents or subcontractors, if any, Business Associate must notify Covered Entity in writing within five (5) business days of the request. Any denial of amendment of PHI maintained by Business Associate 22 or its agents or subcontractors, if any, shall be the responsibility of Covered Entity. Upon the approval of Covered Entity, Business Associate shall appropriately amend the PHI maintained by it, or any agents or subcontractors. 2.15 Accounting of PHI and EPHI. Within ten (10) business days of notice by Covered Entity of a request for an accounting of disclosures of PHI, Business Associate and any agents or subcontractors shall make available to Covered Entity the information required to provide an accounting of disclosures to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.528 and any additional information required under the HITECH Act, including Section 13405(c) if Business Associate maintains information in the form of an Electronic Health Record, and any implementing regulations. (a) If a request for an accounting is made directly to Business Associate or its agents or subcontractors, Business Associate will notify Covered Entity of the request within five (5) business days of having received the request. Covered Entity shall either inform Business Associate to provide the requested information directly to the individual or request Business Associate to immediately forward the information to the Covered Entity for compilation and distribution to the individual. (b) In the case of a direct request for an accounting from an individual related to treatment, payment or health care operations disclosures through Electronic Health Records, Business Associate will provide the accounting to the individual in accordance with 42 U.S.C. § 17935(c) and any regulations adopted subsequent to this Agreement. Business Associate will confirm with Covered Entity that Covered Entity provided Business Associate’s name to the individual in response to a request for an accounting before providing the requested accounting to the individual. 2.16 Retention of Accounting Documentation. Notwithstanding termination of this Agreement, Business Associate and any of its agents or subcontractors shall continue to maintain the information required for purposes of complying with this Section 2.14 for a period of six (6) years after termination of the Agreement. 2.17 Business Associate’s Compliance with HHS. Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of HHS in the time and manner designated by the Covered Entity or the Secretary of HHS for purposes of determining Covered Entity’s compliance with the Privacy Rule. Business Associate will notify Covered Entity regarding any PHI that Business Associate provides to the Secretary of HHS concurrently with providing the requested PHI to the Secretary of HHS. Upon request by Covered Entity, Business Associate will provide Covered Entity with a duplicate copy of the requested PHI. 23 2.18 Inspection by Covered Entity. Within five (5) business days of a written request by Covered Entity, Business Associate and its agents or subcontractors, if any, shall allow Covered Entity to conduct a reasonable inspection of the facilities, systems, books, records, agreements, policies and procedures relating to the use or disclosure of PHI pursuant to this Agreement for the purpose of determining whether Business Associate has complied with this Agreement, the Security Rule and provisions of the Privacy Rule directly applicable to Business Associate or as deemed necessary by Covered Entity to determine whether a Breach has occurred. Both Parties agree to the following: (a) Business Associate will cooperate with Covered Entity’s risk assessment without unreasonable delay; (b) Business Associate and Covered Entity will mutually agree in advance upon the scope, location and timing of such an inspection; and (c) Covered Entity will protect the confidentiality of all confidential and proprietary information of Business Associate to which Covered Entity has access during the course of such inspection. 2.19 Damages. Business Associate shall be responsible to compensate the affected individual for any reasonable damages as a result of a Breach caused by Business Associate. 2.20 No Ownership Rights. Business Associate agrees that Business Associate does not and will not have any ownership rights in any of the PHI. 2.21 Additional HITECH Requirements. The additional requirements of Title XIII of HITECH that relate to privacy and security and that are made applicable with respect to covered entities are also applicable to Business Associate and by this reference these requirements are hereby incorporated into this Agreement. 2.22 Standard Transactions. In conducting any standard transaction that is subject to the Standard Transaction Regulations (set forth in 45 C.F.R. Part 162) on behalf of Covered Entity, Business Associate agrees to comply with all requirements of the Standard Transaction Regulations that would apply to Covered Entity if Covered Entity were conducting the transaction itself and shall require the same of any subcontractor or agent involved with the conducts of such Standard Transactions. 2.23 Limitations on Marketing. Business Associate may not use and disclose PHI for “marketing,” as defined in 45 C.F.R. § 164.501, unless expressly permitted to do so in the Services Agreement. 24 2.24 Sale of PHI. Except for compensation set forth in the Services Agreement between Business Associate and Covered Entity, Business Associate shall not receive any direct or indirect remuneration in exchange for the provision of Protected Health Information. ARTICLE III COVERED ENTITY OBLIGATIONS 3.1 Risk Assessment of Breach by Covered Entity. Covered Entity shall make the final determination of whether for a Breach of PHI occurred. 3.2 Restrictions. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to or must comply with in accordance with 45 C.F.R. § 164.522 and 42 U.S.C. § 17935(a). 3.3 Notification of Changes or Revocations of Permission. Covered Entity shall provide Business Associate with notice of any changes to, revocation of, or permission by individual to use or disclose PHI, if such changes affect Business Associate’s permitted uses or disclosures, within a reasonable period of time after Covered Entity becomes aware of such changes to or revocation of permission. 3.4 Permissible Requests by Covered Entity. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy and Security Rules if done by Covered Entity. ARTICLE IV TERMINATION 4.1 Term and Survival. The term of this Agreement shall be effective as of the Effective Date of this Agreement and continue until terminated by Covered Entity or any underlying Services Agreement expires or is terminated. Any provision related to the use, disclosure, access, or protection of PHI or EPHI or that by its terms shall survive termination of this Agreement shall survive termination. 4.2 Termination for Breach. A material breach by Business Associate, or its agents or subcontractors, if any, of this Agreement, as determined by Covered Entity, shall constitute a material breach of the Services Agreement. As provided for under 45 C.F.R. §§ 164.314(a)(2)(i)(D) and 164.504(e)(2)(iii), the Covered Entity may immediately terminate this Agreement and the Services Agreement or, alternatively, the Covered Entity may choose to provide Business Associate with written notice of the material breach and an opportunity to cure the material breach or end the violation within thirty (30) calendar days. If Business Associate becomes aware of a material breach of this Agreement by Covered Entity, 25 Business Associate shall (1) provide an opportunity for Covered Entity to cure the breach or end the violation and terminate this Agreement (and any applicable portion of the Services Agreement between the parties) if Covered Entity does not cure the breach or end the violation within thirty (30) calendar days, or (2) immediately terminate this Agreement (and any applicable portion of the Services Agreement ) if Covered Entity has breached a material term of this Agreement and cure is not possible. 4.3 Termination for Violation by Business Associate. Covered Entity may terminate this Agreement and the Services Agreement effective immediately, if (i) Business Associate is named as a defendant in a criminal proceeding for a violation of HIPAA, HITECH, or other security or privacy laws or (ii) there is a finding or stipulation that Business Associate has violated any standard or requirement of HIPAA, HITECH, or other security or privacy laws in any administrative or civil proceeding in which Business Associate is involved. 4.4 Return or Destruction of PHI. (a) Upon termination of this Agreement for any reason, Business Associate shall return or, at Covered Entity’s request, destroy all PHI received from Covered Entity or created or received by Business Associate on behalf of Covered Entity that Business Associate still maintains in any form. If Business Associate destroys the PHI, Business Associate shall certify in writing to Covered Entity that such PHI has been destroyed. This provision applies to PHI that is in the possession of agents or subcontractors of Business Associate. Business Associate will retain no copies of the PHI. (b) If Business Associate determines that returning or destroying the PHI is not feasible, Business Associate shall explain to Covered Entity why conditions make the return or destruction of the PHI not feasible. If Covered Entity agrees that the return or destruction of PHI is not feasible, Business Associate will retain the PHI, subject to all of the protections of this Agreement, and limit further uses and disclosures of the PHI to those purposes that make the return or destruction of the PHI infeasible for so long as Business Associate maintains the PHI. (c) If Business Associate determines that it is infeasible to obtain from an agent or subcontractor any PHI in the possession of the agent or subcontractor or to destroy the PHI, Business Associate will provide Covered Entity written notification explaining why obtaining the PHI is infeasible. If Covered Entity agrees that the return or destruction of PHI is not feasible, Business Associate will require the agent or subcontractor to extend the protections of this Agreement to the PHI and limit further uses and disclosures of the PHI to those purposes that make the return or 26 destruction of the PHI infeasible for so long as the agent or subcontractor maintains the PHI. 4.5 Termination of Services Agreement. If this Agreement is terminated for any reason, Covered Entity will also terminate the Services Agreement between the Parties. This provision shall supersede any termination provision to the contrary which may be set forth in the Services Agreement. ARTICLE V MISCELLANEOUS 5.1 Acknowledgement. By affixing their respective signatures below, the Parties certify that they have read and understand each and every provision in this Agreement. Each Party certifies that it possesses the authority to enter into the Agreement. The execution and performance of this Agreement by each Party has been duly authorized by all necessary laws, resolutions or corporate actions, and the Agreement constitutes valid and enforceable obligations of each Party in accordance with its terms. 5.2 Amendment. This Agreement shall not be amended, altered, or modified, except by an instrument in writing duly executed by the Parties to the Agreement. 5.3 Assignment. This Agreement may not be assigned by Business Associate without the prior written consent of Covered Entity. 5.4 Binding Effect. Subject to provisions hereof restricting assignment, this Agreement shall be binding upon and shall inure to the benefit of the Parties and their respective successors and permitted assigns. 5.5 Change in Law. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity and Business Associate to comply with the requirements of HIPAA and the HITECH Act, and of the regulations issued pursuant to those laws. If Covered Entity reasonably concludes that an amendment to this Agreement is needed because of change in federal or state law or changing industry standards, Covered Entity shall notify Business Associate of such proposed modification(s), “Legally-Required Modifications”. Such Legally Required Modifications shall be deemed accepted by Business Associate and this Agreement so amended, if Business Associate does not, within thirty (30) calendar days following the date of notice, or within such other time period as may be mandated by applicable state or federal law, deliver to Covered Entity its written rejection of such Legally-Required Modifications. 27 5.6 Compliance with Laws. Business Associate will comply with all applicable federal and state security and privacy laws, to the extent that such laws apply to Business Associate or are more protective of individual privacy than HIPAA. 5.7 Entire Agreement. This Agreement, including attachments, constitutes the entire Agreement between the Parties with respect to the subject matter hereof, and it supersedes all prior oral or written agreements, commitments, or understandings with respect to the matters provided for herein. 5.8 Execution. This Agreement and any amendments thereto shall be executed in duplicate copies on behalf of the Parties by an official of each, specifically authorized by its respective Party to perform such executions. Each duplicate copy shall be deemed an original, but both duplicate originals together constitute one and the same instrument. 5.9 Indemnification by Business Associate. Business Associate and any of its subcontractors and agents shall indemnify, hold harmless and defend Covered Entity and its employees, officers, directors, agents, and contractors from and against any and all claims, losses, liabilities, costs, attorneys’ fees, and other expenses incurred as a result of or arising directly or indirectly out of or in connection with Business Associate’s or its subcontractors’ or agents’ breach of this Agreement, violation of HIPAA, HITECH or other applicable law, or otherwise related to the acts or omissions of Business Associate or its subcontractors or agents. 5.10 Independent Contractors. This Agreement establishes an independent contractor relationship between Covered Entity and Business Associate. Nothing in this Agreement is intended, nor may anything be construed, to create a partner, joint venture employer/employee, or agent relationship. 5.11 Limitations on Benefits of this Agreement. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than Covered Entity, Business Associate, or their respective successors or assigns, any rights, remedies, obligations or liabilities whatsoever. It is the express intent of the Parties that no person or entity other than the Parties shall be entitled to bring any action to enforce any provision of this Agreement against either of the Parties, and that the Agreement set forth shall be solely for the benefit of, and shall be enforceable only by, the Parties to this Agreement or their respective successors and assigns as permitted hereunder. 5.12 Notices. All notices which are required or permitted to be given pursuant to this Agreement shall be in writing and shall be sufficient in all respects if delivered personally, by electronic facsimile (with a confirmation by registered or certified mail placed in the mail no later than the following day), or by registered or certified mail, postage prepaid, addressed to a Party as indicated below: 28 If to Business Associate: If to Covered Entity, to: Zullinger-Davis-Trinh, P.C. Franklin County Human Services 74 North Second Street 272 North Second Street Chambersburg, PA 17201 Chambersburg, PA 17201 Notice shall be deemed to have been given upon transmittal thereof as to communications which are personally delivered or transmitted by electronic facsimile and, as to communications made by United States mail, on the third (3rd) day after mailing. The above addresses may be changed by giving notice of such change in the manner provided above for giving notice. 5.13 References. A reference in this Agreement to a section in the Privacy Rule or Security Rule means the section as in effect or as amended at the time of reference and as interpreted pursuant to any applicable guidance provided by the Secretary or other responsible regulatory authority and any applicable case law. 5.14 Severability. If any part of any provision of this Agreement, or any other agreement, document or writing given pursuant to or in connection with this Agreement, shall be held invalid or unenforceable, the holding of invalidity or unenforceability will apply to the invalid or unenforceable part of the provision only, without in any way affecting the remaining parts of said provision or the remaining provisions of said Agreement. 5.15 Sub-Contract. Business Associate may not sub-contract any services under the Services Agreement without the express written consent of Covered Entity. 5.16 Waiver. Neither the waiver by either Party of a breach of or a default under any of the provisions of this Agreement, nor the failure of either of the Parties, on one or more occasions, to enforce any of the provisions of this Agreement or to exercise any rights or privilege hereunder shall thereafter be construed as a waiver of any subsequent breach or default of a similar nature, or as a waiver of any such provisions, rights or privileges hereunder. 5.17 Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with applicable requirements of HIPAA HITECH Act, the Privacy Rule and the Security Rule. Any conflict between a provision of the Services Agreement and this Agreement regarding the subject matter of this Agreement, shall be resolved in favor of this Agreement 29 IN WITNESS WHEREOF, the parties have caused this Agreement to be executed by their respective duly authorized representatives as of the dates set forth below. BUSINESS ASSOCIATE COVERED ENTITY By: By: Name: Name: Title: Title: Suzanne Trinh Managing Shareholder 30 EXHIBIT A PERMITTED USES AND DISCLOSURES This Exhibit sets forth the permitted uses and disclosures of Information by Associate. This Exhibit may be amended from time to time if applicable. Purpose(s) of Disclosure. The purpose(s) for which County shall disclose Information to Associate are as follows: To ensure Associate has all necessary information available to provide appropriate care/treatment that the Associate is contracted to perform. Information to be disclosed. County shall disclose the following Information to Associate in accordance with the terms of the Agreement: Any and all information that may be necessary to ensure proper care/treatment is provided to the identified client. Permitted Uses and Disclosures of Information. Associate shall be limited to the following uses and/or disclosures of County’s PHI: Associate may use or disclose information, as it deems necessary in order to ensure client receives appropriate care/treatment. Subcontractor(s). If Associate intends to utilize any subcontractor(s) in performing Associate's obligations under the Agreement, such subcontractor(s) shall be identified as follows: An individual or agency that the Service Provider may contract with to provide direct provider services. 5. Disclosure and Use for Management and Administration. Associate may use or disclose PHI received by Associate in its capacity as a Business Associate of County for the proper management and administration of Associate, if such use and disclosure is necessary (i) for the proper management and administration of Associate or (ii) to carry out the legal responsibilities of Associate. 6. Data Aggregation Services. For purposes of this Section, "Data Aggregation" means, with respect to County’s PHI, the combining of such PHI by Associate with the PHI received by Associate in its capacity as a Business Associate of another Covered Entity to permit data analyses that relate to the health care operations of the respective Covered Entities. Associate shall provide the following Data Aggregation services relating to the health care operations of County: Any and all data prepared by the Associate in connection with services contemplated under the Agreement shall become the exclusive property of the County. 7. Additional Restrictions on Use of Data. County is a Business Associate of certain other Covered Entities and, pursuant to such obligations of County, Associate shall comply with the following restrictions on the use and disclosure of PHI: The County shall have the right to use such data for any official purpose in whatever manner deemed appropriate. Associate shall not include in the data it provides to the County any data copyrighted by another entity without the written approval of the County, unless the Service Provider provides the County with written permission of the copyright owner for the County to us such copyrighted matter. 31 | P a g e EXHIBIT B Pennsylvania Law If this agreement authorizes the release of Mental Health Records, HIV – related information, or Substance Abuse treatment information, the following statement must be included with the information being released: This information has been disclosed to you from records whose confidentiality is protected by Pennsylvania Law. Pennsylvania Law prohibits you from making any further disclosure of this information unless further disclosure is expressly permitted by the written authorization of the person to whom it pertains or is otherwise permitted by law. A general authorization for release of medical or other information is not sufficient for this purpose.