Loading...
HomeMy WebLinkAboutRFP 2026131-02 Professional Audit Services - FINAL REQUEST FOR PROPOSAL for PROFESSIONAL AUDIT SERVICES FOR THE COUNTY OF FRANKLIN, PA COUNTY OF FRANKLIN, PENNSYLVANIA RFP# 2026131-02 County of Franklin, PA 272 North Second Street Chambersburg, PA 17201 Contents SECTION I – INTRODUCTION & INSTRUCTIONS......................................................................... 2 1.01 PURPOSE ...................................................................................................................... 2 1.02 RFP SCHEDULE ............................................................................................................. 2 1.03 REQUIRED REVIEW ........................................................................................................ 2 1.04 AMENDMENTS TO PROPOSALS ..................................................................................... 3 1.05 AMENDMENTS TO THE RFP ............................................................................................ 3 1.06 QUESTION & ANSWER PERIOD ...................................................................................... 3 1.07 PRE-PROPOSAL CONFERENCE ..................................................................................... 3 1.08 RETURN INSTRUCTIONS ................................................................................................ 3 1.09 RIGHT TO REJECT PROPOSALS ...................................................................................... 4 1.10 TERM ............................................................................................................................. 4 1.11 NONDISCRIMINATION CLAUSE ..................................................................................... 4 SECTION II - BACKGROUND & INFORMATION ........................................................................... 5 SECTION III - SCOPE OF WORK TO BE PERFORMED .................................................................. 6 3.01 FINANCIAL STATEMENT AUDIT ....................................................................................... 6 3.02 SINGLE AUDIT................................................................................................................ 6 3.03 AUDIT SCHEDULE AND REPORTING EXPECTATIONS ...................................................... 7 3.04 ADDITIONAL SERVICES .................................................................................................. 7 3.05 SPECIAL CONSIDERATION............................................................................................. 8 3.06 AUDITING STANDARDS TO BE FOLLOWED ..................................................................... 9 3.07 ASSISTANCE TO BE PROVIDED BY COUNTY STAFF ........................................................ 10 3.08 AUDITOR RESPONSIBILITIES ......................................................................................... 11 3.09 WORKING PAPER RETENTION AND ACCESS TO WORKING PAPERS .............................. 12 3.10 CONTINUITY OF ASSIGNED PERSONNEL ...................................................................... 13 SECTION IV - RESPONSE FORMAT ........................................................................................... 13 SECTION V - EVALUATION OF THE PROPOSALS & GENERAL SELECTION PROCESS ................. 17 SECTION VI - CONTRACT PROVISIONS & INSURANCE REQUIREMENTS ................................... 18 6.01 CONTRACT PROVISIONS .............................................................................................. 18 6.02 INSURANCE ................................................................................................................. 20 SECTION VII - GENERAL LEGAL INFORMATION ........................................................................ 21 7.01 RIGHT OF REJECTION ................................................................................................... 21 7.02 VENDOR CLEARANCE .................................................................................................. 21 7.03 COUNTY NOT RESPONSIBLE FOR PREPARATION COSTS .............................................. 21 7.04 DISCLOSURE OF PROPOSAL CONTENTS ..................................................................... 21 ATTACHMENT A 2026 BUDGET IN BRIEF ATTACHMENT B BASIC FINANCIAL STATEMENT FOR THE YEAR ENDED DECEMBER 31, 2025 ATTACHMENT C SINGLE AUDIT REPORTS FOR THE YEAR ENDED DECEMBER 31, 2025 ATTACHMENT D PROPOSED CONTRACT ATTACHMENT E BUSINESS ASSOCIATE AGREEMENT ATTACHMENT F SCHEDULE OF PROFESSIONAL FEES SECTION I – INTRODUCTION & INSTRUCTIONS 1.01 PURPOSE The County of Franklin is requesting proposals from qualified independent certified public accounting firms to perform annual financial and compliance (Single) audits for the County. The selected firm shall conduct audits of the County's financial statements in accordance with generally accepted auditing standards (GAAS), Government Auditing Standards issued by the Comptroller General of the United States, and, when applicable, the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). 1.02 RFP SCHEDULE The RFP schedule set out herein represents Franklin County’s best estimate of the schedule that will be followed. If a component of this schedule, such as the deadline for the receipt of proposals, is delayed, the rest of the schedule may be shifted accordingly. All times are Franklin County, Pennsylvania time. RFP Released…………………………………………………………. Friday September 11, 2026 Proposer Questions due by …………………… Monday September 28, 2026, at 4:00 PM Responses to Questions to be posted by .………………………… Friday October 2, 2026 RFP Submission Deadline ……………………..……… Friday October 9, 2026, at 4:00 PM Anticipated Selection Date ………………………………………………… December 30, 2026 1.03 REQUIRED REVIEW Offerors should carefully review this solicitation for defects and erroneous material. Submit comments concerning defects and erroneous material in writing to the procurement office at procurement@franklincountypa.gov a minimum of ten days before the deadline for receipt of proposals. This will allow time for the issuance of any necessary amendments. It will also help prevent the opening of a defective proposal and exposure of the offeror’s proposals upon which award could not be made. 1.04 AMENDMENTS TO PROPOSALS Amendments to or withdrawals of proposals will only be allowed if an acceptable request is received prior to the deadline that is set for the receipt of proposals. No amendments or withdrawals will be accepted after the deadline. 1.05 AMENDMENTS TO THE RFP If an amendment is issued, it will be posted on the Franklin County, PA website at https://www.franklincountypa.gov/current-solicitation-opportunities/. 1.06 QUESTION & ANSWER PERIOD All questions must be submitted in writing to procurement@franklincountypa.gov. Questions may be submitted until Monday September 28, 2026, at 4:00 PM, prevailing Franklin County, Pennsylvania time. 1.07 PRE-PROPOSAL CONFERENCE There is no pre-proposal conference for this RFP. 1.08 RETURN INSTRUCTIONS Proposals shall be submitted to the Procurement Office as electronic PDF files at the following address: Franklin County, Pennsylvania Procurement Department RFP #2026131-02 272 North Second Street Chambersburg, PA 17201 The electronic files may alternatively be submitted via email to procurement@franklincountypa.gov or via a USB flash drive. The technical proposal shall be titled in the format of “VENDOR A – AUDIT SERVICES PROPOSAL – TECHNICAL” where VENDOR A is the name of your firm. The cost proposal shall be saved in a separate PDF file from the main proposal and clearly named in a format such as “VENDOR A – AUDIT SERVICES – COST PROPOSAL”. Any confidential information submitted by the vendor must be submitted in a separate PDF Document from the main proposal and labeled similarly as described above including the word “Confidential” at the end of the file name. The County is not responsible for deliveries that do not reach the Procurement Department by the required due date and time. 1.09 RIGHT TO REJECT PROPOSALS The County reserves the right, at its discretion, to reject any or all Proposals and to waive irregularities or information in any proposal and to award contracts based on the proposal deemed the greatest overall value and benefit to the County. The County shall be the sole judge as to what constitutes the greatest overall value. 1.10 TERM The initial term of the contract shall begin upon execution and end December 31, 2029 or upon completion of the 2028 audit, whichever comes later. There shall be an option to extend the contract term for up to two (2) additional one (1) year periods. The County shall exercise this option by notifying the Contractor in writing within thirty (30) days of the expiration of the then-current term. 1.11 NONDISCRIMINATION CLAUSE Franklin County assures that no person shall be excluded from participating in, be denied the benefits of, or be otherwise subjected to discrimination on the grounds of race, gender, creed, color, sexual orientation, gender identity or expression, or in violation of the Pennsylvania Human Relations Act, which prohibits discrimination on the basis of race, color, religious creed, ancestry, age, sex, national origin, handicap or disability, or in violation of any applicable local, state, or federal laws. With advance notification, accommodations may be provided for those with special needs for language, speech, sight or hearing. If you have a request for a special need, wish to file a complaint, or desire additional information please contact the Risk Management Department at (717) 261-3819 or riskmgt@franklincountypa.gov. SECTION II - BACKGROUND & INFORMATION The County of Franklin is a fourth-class county located in south-central Pennsylvania, operating under an elected three-person Board of Commissioners organized under the laws of the Commonwealth of Pennsylvania and governed under the County Code of 1955, as amended. The County maintains multiple governmental, proprietary, fiduciary, and component activities and annually expends federal financial assistance requiring a Single Audit. The County provides services to its residents in many areas, including various general government services, a court system, public safety, corrections, health and welfare, public works (bridge program), conservation and development, and community enrichment programs. General Information: • Annual operating budget - approximately $140 million • Number of active funds – 38 • Number of employees – approximately 700 full-time, part-time, and casual • Enterprise Resource Planning software – Tyler Enterprise ERP • Annual federal expenditures – approximately $12 million More information on the County of Franklin, its operations and finances can be found at www.franklincountypa.gov. The County’s 2026 Budget in Brief (Attachment A), Basic Financial Statement for the year ended December 31, 2025 (Attachment B) and the Single Audit Reports for the year ended December 31, 2025 (Attachment C) are included in this Request for Proposal. SECTION III - SCOPE OF WORK TO BE PERFORMED 3.01 FINANCIAL STATEMENT AUDIT The County of Franklin seeks the services of an independent certified public accounting firm to perform an annual audit of the County's financial statements. The audit shall be conducted in accordance with generally accepted auditing standards (GAAS), Government Auditing Standards issued by the Comptroller General of the United States, and all other applicable professional standards. Upon completion of the audit, the selected firm shall issue an Independent Auditor's Report expressing an opinion on the County's financial statements. In addition, the auditor shall issue a Report on Internal Control over Financial Reporting and on Compliance and Other Matters based on an audit of the financial statements performed in accordance with Government Auditing Standards. The auditor shall also provide all communications required by professional auditing standards to those charged with governance, including any significant audit findings, accounting policies, estimates, difficulties encountered during the audit, and uncorrected misstatements. Should deficiencies in internal control or other matters warrant communication to management, the auditor shall issue a management letter containing recommendations for operational, financial reporting, or internal control improvements. The County expects that the audit to be performed utilizing a combination of on-site and remote procedures. The County also encourages firms to maximize the use of secure electronic document exchange as opposed to other communication methods. 3.02 SINGLE AUDIT The County annually expends federal financial assistance and, therefore, requires the auditor to conduct a Single Audit in accordance with the Single Audit Act Amendments and the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). The auditor shall perform all procedures necessary to satisfy federal Single Audit requirements, including identification of major programs, testing of compliance requirements applicable to those programs, and evaluation of internal controls over compliance. The auditor shall prepare and issue all reports required under Uniform Guidance, including the Schedule of Findings and Questioned Costs and related auditor reports. The auditor shall review the County-prepared Schedule of Expenditures of Federal Awards (SEFA), evaluate the completeness and accuracy of federal expenditures reported, and perform all procedures necessary to support the issuance of the required audit opinions. The auditor shall also assist the County with matters related to the completion and submission of the Data Collection Form and filing requirements of the Federal Audit Clearinghouse. 3.03 AUDIT SCHEDULE AND REPORTING EXPECTATIONS The County anticipates that the annual audit will be performed in accordance with a schedule generally consistent with the timeline outlined below. The purpose of this schedule is to facilitate timely completion of the audit, compliance with applicable federal and state reporting requirements, and presentation of final audit reports to County management and the Board of Commissioners. Milestone Anticipated Timing The County expects the selected auditor to work cooperatively with County personnel throughout the engagement to establish detailed planning, fieldwork, review, and reporting schedules. Proposers should describe their anticipated audit timeline and identify any scheduling considerations that may affect completion of the engagement. The County recognizes that firms may employ differing audit methodologies and scheduling approaches. Accordingly, proposers may recommend alternative timelines or milestone dates, provided that all applicable reporting deadlines are met and final audit reports are issued in a timely manner. 3.04 ADDITIONAL SERVICES The County expects the selected firm to serve as a professional resource throughout the term of the engagement. The purpose of this is to allow The County to be proactive in aligning with the audit requirements. Accordingly, the firm shall be available to provide technical accounting and auditing guidance to County management and Fiscal Department staff as questions arise during the year for this purpose. Examples of such services may include consultation regarding the implementation of new Governmental Accounting Standards Board (GASB) pronouncements, interpretation of emerging accounting and auditing standards, assistance with federal compliance matters, and discussion of industry best practices affecting county governments. Representatives of the firm may be requested to attend meetings of the Board of Commissioners, management, or other County officials to discuss audit results, accounting matters, compliance issues, or significant developments affecting the County. In addition, the selected firm shall provide annual training to County personnel, of a minimum of eight (8) hours per year. Training topics may include updates to Uniform Guidance requirements, changes to the annual Compliance Supplement, new GASB standards, governmental accounting developments, internal control practices, and other matters relevant to County financial management and federal program administration. 3.05 SPECIAL CONSIDERATION The County's reporting entity includes several discretely presented component units whose financial information is incorporated into the County's annual financial reporting. Separate audit engagements for these component units are administered independently of this Request for Proposals and are not included within the scope of services to be provided under this engagement. The County's component units currently include the Franklin County Conservation District, Letterkenny Industrial Development Authority, Franklin County Industrial Development Authority, Tuscarora Managed Care Alliance, and the Franklin County Redevelopment Authority. County Fiscal Department personnel have historically served as the primary point of contact with component unit management and their respective auditors and will continue to coordinate the collection of audited financial statements, audit reports, management representations, and other necessary information for the County's financial reporting process. The selected auditor shall evaluate component unit financial information and perform such procedures as are required by applicable professional auditing standards; however, proposers should assume that the County will coordinate the collection of component unit financial reporting information and that the selected auditor will not be responsible for managing communications with component unit auditors except as necessary to address specific audit matters arising during the engagement. The County reserves the right to add or remove component units from its reporting entity during the term of the engagement should circumstances require. 3.06 AUDITING STANDARDS TO BE FOLLOWED The audit shall be conducted in accordance with generally accepted auditing standards (GAAS) as promulgated by the American Institute of Certified Public Accountants; the standards applicable to financial audits contained in Government Auditing Standards issued by the Comptroller General of the United States; the provisions of the federal Single Audit Act of 1984, as amended; and the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), as amended. The auditor shall perform all audit procedures necessary to express an opinion on the County's financial statements and to satisfy all applicable reporting requirements associated with a Single Audit. The auditor shall also consider and apply all relevant Governmental Accounting Standards Board (GASB) pronouncements, the Pennsylvania Department of Human Services Single Audit Supplement (formerly Department of Public Welfare), and any additional federal, state, local, or programmatic compliance requirements applicable to the County. The auditor shall issue all reports required under the applicable professional standards, including reports on financial statements, internal control over financial reporting, compliance, and federal awards programs. The auditor shall communicate audit findings, recommendations, and other matters required by professional standards to management and those charged with governance. In submitting a proposal, firms should recognize that Franklin County maintains significant internal financial reporting capabilities and has historically assumed responsibility for the preparation of its financial statements, note disclosures, Management's Discussion and Analysis (MD&A), Schedule of Expenditures of Federal Awards (SEFA), and related supporting schedules. Accordingly, the County seeks an independent auditor to perform audit and attestation services rather than a firm to provide extensive financial statement preparation services. 3.07 ASSISTANCE TO BE PROVIDED BY COUNTY STAFF Franklin County maintains an experienced financial management team consisting of Fiscal Department personnel, the Controller's Office, and departmental management staff who actively participate in the annual audit process. County personnel are committed to providing timely access to records, schedules, supporting documentation, and explanations necessary for the completion of the audit. The Fiscal Department serves as the County's primary financial reporting function and is responsible for the preparation of the County's financial statements, note disclosures, Management's Discussion and Analysis (MD&A), Schedule of Expenditures of Federal Awards (SEFA), and related supporting schedules. The Controller's Office and other County personnel provide support through the maintenance of accounting records, processing of accounting transactions, and assistance with information and documentation requests necessary to facilitate the audit process. For purposes of audit planning, fieldwork coordination, financial reporting matters, implementation of new accounting standards, federal compliance reporting, and preparation of audit schedules, the auditor should anticipate working primarily with the Fiscal Department, with support provided by the Controller's Office and other County departments as necessary. County personnel will prepare the financial statements, SEFA, supporting grant expenditure schedules, Assistance Listing ID (formerly CFDA, the Catalog of Federal Domestic Assistance, number), reconciliations of federal expenditures to the County's accounting records, and other schedules necessary for the audit. The auditor will be expected to review, test, and opine on these schedules as required by applicable auditing standards and Uniform Guidance. To facilitate the audit, County staff will prepare and provide a comprehensive package of audit workpapers and supporting schedules, including trial balances, general ledger detail, bank reconciliations, capital asset records, debt schedules, lease and subscription-based information technology arrangement (SBITA) schedules, pension and OPEB information, grant documentation, accounts receivable and payable analyses, revenue and expenditure schedules, and other documentation customarily requested during governmental financial and compliance audits. County personnel will serve as the primary liaison with the County's discretely presented component units and their respective auditors and will coordinate the collection of audited financial statements, supporting schedules, and other information required for the County's financial reporting and audit processes. The County will make such information available to the selected auditor as necessary to facilitate the performance of procedures required by applicable professional auditing standards. The County will provide designated audit liaison personnel throughout the engagement to coordinate requests and facilitate communication between the audit team and County departments. The County will also provide reasonable workspace for on-site fieldwork, internet access, and secure electronic access to records and supporting documentation. The County encourages the use of electronic workpapers, secure file-sharing technologies, and remote auditing techniques whenever practical and consistent with professional auditing standards. 3.08 AUDITOR RESPONSIBILITIES The selected auditor shall be responsible for planning and performing the audit in accordance with the auditing standards and requirements identified in this Request for Proposals. The auditor shall develop an audit plan and engagement timeline designed to facilitate the timely completion of all audit and reporting requirements. The auditor shall perform appropriate risk assessment procedures, obtain an understanding of internal controls relevant to the audit, and conduct such testing and other procedures as are necessary to express an opinion on the County's financial statements. The auditor shall also perform all procedures required under Government Auditing Standards and Uniform Guidance, including testing of internal controls and compliance requirements applicable to federal programs selected for Single Audit testing. Throughout the engagement, the auditor shall maintain open and timely communication with County management regarding audit progress, information requests, emerging issues, potential findings, and other matters that may affect the audit. The auditor shall promptly communicate any significant deficiencies, material weaknesses, instances of noncompliance, questioned costs, or other reportable conditions identified during the course of the engagement. The auditor shall provide draft audit reports and related communications to management for review prior to issuance of final reports. Final audit reports shall be issued in accordance with the mutually agreed-upon audit schedule and any reporting deadlines established by applicable federal, state, or local requirements. The auditor shall designate an engagement partner and audit manager who will serve as primary contacts for the County throughout the term of the engagement and who will be responsible for ensuring continuity, responsiveness, and quality of service. The County utilizes audit cost allocations for indirect cost and grant reimbursement purposes. Accordingly, the auditor shall provide a reasonable estimate of the distribution of audit effort among the County's major programs, operations, and reporting units. The County recognizes that such allocations are estimates and are not intended to represent precise measurements of actual audit costs incurred by program or activity. The allocation may be based upon anticipated audit hours, level of audit effort, relative risk, transaction volume, or another reasonable methodology consistently applied by the proposer. The proposed allocation shall include, at a minimum, the General Fund, each of the Human Services programs, Domestic Relations, Liquid Fuels, 911, Community Development Block Grant programs, and other major County operations as applicable. 3.09 WORKING PAPER RETENTION AND ACCESS TO WORKING PAPERS The auditor shall retain all working papers, reports, correspondence, and other records relating to the audit for a period of not less than three (3) years following acceptance of the audit report by the County and final resolution of all audit findings, whichever is later, or for such longer period as may be required by applicable professional standards, federal regulations, state requirements, or pending audit matters. If notified by the County, federal agencies, state agencies, or other authorized oversight bodies of the need to extend the retention period, the auditor shall retain such records for the additional period specified. Upon reasonable notice, the auditor shall make audit documentation available for inspection by authorized representatives of the County, federal and state oversight agencies, or other parties entitled to access under applicable law, regulation, or professional standards. The auditor shall respond in a timely and professional manner to reasonable inquiries from successor auditors and shall provide access to working papers and other audit documentation relating to matters of continuing accounting significance in accordance with applicable professional standards. Such access shall be provided at no additional cost to the County, except for reasonable reproduction expenses, if any. In the event the County engages a successor auditor, the incumbent auditor shall cooperate fully in facilitating an orderly transition, including participation in transition meetings and timely responses to reasonable requests for information. Nothing contained herein shall be construed to require the disclosure of proprietary audit methodologies, proprietary software, or other materials protected from disclosure under applicable professional standards or law. 3.10 CONTINUITY OF ASSIGNED PERSONNEL The County places significant value on continuity and retention of engagement personnel throughout the term of the contract. Proposers should recognize that the County's evaluation will consider not only the qualifications of the proposed engagement team, but also the firm's ability to maintain staffing continuity and preserve institutional knowledge throughout the engagement period. The County expects the engagement partner, audit manager and in-charge auditor identified in the proposal to remain actively involved throughout the engagement unless circumstances beyond the firm's reasonable control require reassignment. The County’s award is based in part upon the qualifications and experiences of these individuals, and the contractor shall not remove, replace or reassign these personnel without providing advance written notice to the County. If replacement of key personnel becomes necessary, the firm shall provide personnel possessing qualifications and governmental auditing experience substantially equivalent to or greater than those of the individual being replaced, subject to County approval. SECTION IV - RESPONSE FORMAT The County discourages overly lengthy and costly proposals. In order for the County to evaluate proposals fairly and completely, offerors must follow the format set out in this RFP and provide all requested information. If your firm has prior experience working with the County, DO NOT assume this prior work is known to the evaluation committee. All firms are evaluated solely by the information contained in their proposal, information obtained from references, and interviews or presentations, if requested. All submittals must be prepared as if the evaluation committee has no knowledge of the firm, their qualifications or past projects. Any submission that does not follow this format or does not include all the information requested may be deemed unresponsive by the County and not evaluated. TECHNICAL PROPOSAL 1. Title Page – List the RFP subject, the name of the firm, the local address, telephone number, name of the contact person and date. 2. Table of Contents – Include a clear identification of the material included in the proposal by page number. 3. Introduction/Transmittal Letter (1 page max) A transmittal letter must accompany the RFP submission. The purposes of this letter are to transmit the proposal, acknowledge receipt of any addenda and to allow the firm an opportunity to indicate their ability to provide the services requested. The letter must contain the following information about the primary firm and any subconsultants or partner firms: • Primary Point-of-Contact Name • Primary Project Lead Name (if different from above) • Primary Contact Address • Primary Contact Phone, Fax and Email • Company Internet Address • Name(s) of the person(s) who will be authorized to make representation for your firm, their title, phone number and email address. • Authorized signature confirming the proposal will remain open and valid for at least 180 days from the date set as the deadline for receipt of proposals. 4. Profile of Proposer (2 pages max) Provide information on firm history, office location(s), and years providing governmental audit services. State whether your firm is local, national or international in size. Give the location of the office from which the work is to be done, and the number of partners, managers, supervisors, seniors, and other professional staff employed at the office. Briefly describe the range of activities performed by the local office such as auditing, accounting, tax services, and management advisory services. 5. Summary of the Firm’s Qualifications (5 pages max plus reports) Provide details as to the capability of your firm to provide governmental accounting and auditing services. The firm shall provide a list of the most significant audits of counties or other governmental agencies of similar size to the County of Franklin that they have performed, with special emphasis on experience with other Pennsylvania counties. Provide at least three (3) references, including organization name, principal client contact person along with the telephone number and email address of that person. The firm shall indicate whether or not it is a member of AICPA’s Governmental Audit Quality Center and the extent of its involvement. The firm is also required to submit a copy of the most recent peer review report, with a statement whether that quality control review included a review of specific government engagements. The firm must also include, if applicable, any letter of comment as well as a description of corrective actions taken. The firm shall provide information on the circumstances and status of any disciplinary action taken or pending against the firm during the past three (3) years with state regulatory bodies or professional organizations and information regarding any adverse litigation. The firm shall indicate if it has been suspended or debarred by the Commonwealth of Pennsylvania or state affirmatively that it has not. The firm shall provide an affirmative statement that it is independent of the County of Franklin and the County’s component units as defined by generally accepted auditing standards. 6. Engagement Team Qualifications and Experience (2 pages max) Identify the principal supervisory and management staff, including engagement and review partners, managers, other supervisors and specialists, who would be assigned to the engagement. Identify the percentage of governmental audit hours anticipated to be performed by personnel located in the office identified as the lead office for this engagement. Provide resumes and relevant governmental experience of each person, including CPA licensure, and information on relevant continuing professional education for the past three (3) years and membership in professional organizations relevant to the performance of this audit. 7. Continuity of Assigned Personnel (2 pages max) Identify the engagement partner, audit manager and in-charge auditor that would be assigned to this contract and describe the anticipated tenure of each, as well as the firm's approach to maintaining continuity of key personnel. The proposal should discuss the circumstances under which key personnel may be replaced, the procedures for notifying the County of staffing changes, the firm's historical turnover rates for governmental audit personnel, and the extent to which the proposed engagement team has previously worked together on governmental audit engagements. 8. Methodology and Approach (3 pages max) Describe your approach and methodology to the audit process. Include your communication approach and proposed schedule (if different than in Section 3.03). Identify any scheduling considerations that may affect the completion of the engagement. Describe the breakdown of work that will be completed on site in Franklin County versus remotely. Provide information on how your firm will meet the requirements listed in 3.04, Additional Services. 9. Proposed Engagement Letter and Contractual Exceptions The County intends to utilize its standard professional services agreement for this engagement. A copy of the County's proposed contract is included in Attachment D. A Business Associate Agreement is also required and included in Attachment E. Proposers shall identify any provisions of the County's proposed contract to which they object or for which they anticipate requesting modification. Any exceptions, revisions, or additions requested shall be clearly identified and explained within the proposal. In addition, proposers shall provide a sample engagement letter and any standard contract terms, conditions, or supplemental agreements that the firm customarily utilizes for governmental audit engagements. Submission of a sample engagement letter or standard contract documents shall not be construed as acceptance by the County of such terms. The County reserves the right to negotiate final contract and engagement letter provisions with the selected firm. Failure to identify requested exceptions during the proposal process may be considered by the County during contract negotiations. COST PROPOSAL The cost proposal shall be presented using Attachment F – Schedule of Professional Fees and Expenses and shall include: 1. Total All-Inclusive Fixed Price – The dollar cost proposal shall contain all pricing information related to performing the audit engagement as described in this Request for Proposal. The total all-inclusive fixed price to be proposed will contain all direct and indirect costs including all out-of- pocket expenses. 2. Rates by Partner, Specialist, Supervisory, and Staff Level Times Hours Anticipated for Each For the 2026 audit only, include a schedule of professional fees and expenses that supports the total all-inclusive fixed price. Provide the estimated number of hours and hourly rates by staff classification necessary to complete the engagement. Include the estimated out-of-pocket costs and the resulting all-inclusive fixed fee for requested work. SECTION V - EVALUATION OF THE PROPOSALS & GENERAL SELECTION PROCESS Professional audit services are of significant importance to Franklin County, and relying exclusively on price is not in the best interest of the County. Award of a contract shall be at the sole discretion of Franklin County. Franklin County reserves the right to accept or reject any or all submissions in whole or in part and to waive any irregularities in the proposal process. Further, Franklin County reserves the right to enter into any contract deemed in its best interest. The County reserves the right to reject any and all proposals and to waive any and all irregularities. All proposals will be evaluated for the completion of the required elements. If one of the required elements is not submitted in the required format, the County may deem the proposal nonresponsive. Proposals will be evaluated by a committee consisting of representatives of Franklin County and such other individuals as the County may designate. The evaluation committee will review and score proposals based upon the criteria set forth below. Criteria Weight After scoring is complete, the evaluation committee will meet to discuss next steps in the evaluation process and select proposals that they desire to continue to consider based on the scoring as well as the discussions of the evaluation committee members. The County reserves the right to conduct interviews and/or request additional information of all, some or none of the offerors, as part of the evaluation and selection process. The County reserves the right to contact any references provided or other organizations to assess the quality of work performed and use this information as part of the evaluation and scoring of the proposal. After the completion of the evaluation process, a recommendation for award of the contract will be made to the Board of Commissioners of the County Franklin based on the proposal deemed to offer the best value to the County. Proposers are advised to submit their best technical and cost proposals initially, as the County reserves the right to make an award based solely upon the proposals received. SECTION VI - CONTRACT PROVISIONS & INSURANCE REQUIREMENTS 6.01 CONTRACT PROVISIONS After the County of Franklin makes its selection, it shall proceed to negotiate a contract at a mutually agreeable price based upon a Scope of Work for the project. If the County is unable to negotiate a satisfactory contract with the most highly qualified person or firm, the County shall formally end negotiations with that person or firm and begin to negotiate with the second most highly qualified person or firm. Negotiations shall continue in this sequence until a contract is agreed upon. The performance of this contract shall be in accordance with all Federal, State and local laws as may be applicable. Any contract between the County of Franklin and the consultant shall be subject to the rules and regulations of any agencies where funding is being requested. The contract between the County and the selected firm will include the following non- negotiable contract provisions: 1. Indemnification of the County. 2. Non-Indemnification of the Contractor. 3. Forum Selection (Franklin County, PA Court of Common Pleas). 4. Choice of law (Commonwealth of Pennsylvania). 5. Prevailing party attorneys’ fees. 6. Termination for convenience/termination for cause by the County. 7. County ownership of the instruments of service/deliverables. 8. Work-for-Hire Transfer of Copyrights/Intellectual Property. 9. All data is the property of the County of Franklin. The contract must include express provisions guaranteeing County ownership of all data and guaranteeing that the data may be accessed post-contract using non- proprietary means. No mining, analytics, or duplication is allowed without the County’s express written permission. 10. Data security, confidentiality, and use of County data and information. 11. Nondiscrimination. 12. Suspension and debarment. 13. Release of liability in favor of the County. 14. Non-release of liability of the contractor. 15. Insurance coverage and County’s status as additional insured as set forth in Section 6.02. 16. Terms of payment and invoicing, including 45-day payment period. 17. Any and all federal and state provisions required as a result of grant funding. A separate “Data Sharing Agreement” will be signed by the selected consultant and Franklin County during the Scope of Work process. Any work proposed and undertaken by this RFP that requires the use, access, and sharing of County data shall be addressed via the “Data Sharing Agreement” as compliant with current County of Franklin processes and procedures. The County reserves the right to request additional contract provisions as it deems necessary in order to protect the best interest of the County. 6.02 INSURANCE Prior to and during the performance of any services covered by this RFP, vendor shall provide the County, upon execution of an agreement, in a form and manner reasonably acceptable to the County Solicitor or Risk Manager, a certificate of insurance as evidence that it has obtained and maintains in full force and effect during the term of this Agreement the following types of insurance in the amounts described as follows: i. General Liability insurance covering liability for death and bodily injury and liabilities for loss of or damage to property with a combined single limit of not less than One Million Dollars ($1,000,000) per occurrence and One Million Dollars ($1,000,000) in the aggregate; ii. Automobile Liability insurance combined single limit of not less than one million dollars and zero cents ($1,000,000.00) for any automobile. iii. Worker’s Compensation and Employer’s Liability insurance as required by the laws of the Commonwealth of Pennsylvania; iv. Employee Dishonesty coverage at a minimum limit of $25,000; v. Professional Liability insurance of not less than One Million Dollars ($1,000,000) per occurrence; and vi. Cyber Liability insurance of not less than One Million Dollars ($1,000,000) per occurrence and Two Million Dollars ($2,000,000) aggregate. The County shall be endorsed as additional insured on General Liability Insurance for services and activities provided by the vendor under this agreement. Vendor shall provide proof of insurance and the requirements of this section upon execution of this agreement as requested after that. Should the vendor have any changes to their current insurance coverage, they shall notify the County within five business days. SECTION VII - GENERAL LEGAL INFORMATION 7.01 RIGHT OF REJECTION Franklin County reserves the right to cancel this request for proposals at any time for any reason. Any proposal received may be rejected in whole or in part when in the best interest of the County. 7.02 VENDOR CLEARANCE All vendors will be required to submit a W-9 and pass clearance checks including a debarment check and other background checks as deemed necessary by Franklin County. 7.03 COUNTY NOT RESPONSIBLE FOR PREPARATION COSTS The County will not pay any cost associated with the preparation, submittal, presentation, or evaluation of any proposal. 7.04 DISCLOSURE OF PROPOSAL CONTENTS All responses are subject to the Pennsylvania Right to Know Law, 65 P.S. §§ 67.101-3104, (“RTKL” or Right to Know Law”), which may mandate the release of any and all information and documents submitted by the proposer. By submitting a proposal, all proposers acknowledge the County’s non-waivable duties under the Right to Know Law and agree to cooperate therewith. Any confidential or proprietary information should be marked accordingly. Additionally, any confidential information submitted by the vendor must be easily separable from the non-confidential sections of the proposal and as such must be submitted in a separate PDF document from the main proposal and labeled similarly to as described above including the word “Confidential” in the file name. Notwithstanding the foregoing, all proposals, documents, submissions and data are subject to the Pennsylvania Right to Know Law. Any exceptions taken to such mandatory terms may result in rejection of the proposal. Any exceptions to the terms and conditions must be set forth in writing, with reasons for such objection, and alternate language suggested, or is otherwise waived. ATTACHMENT D COUNTY OF FRANKLIN SERVICE AGREEMENT THIS AGREEMENT made and entered into this day of , 20__, by and between the COUNTY OF FRANKLIN, a fourth class county organized and existing under the laws of the Commonwealth of Pennsylvania, with a principal address of 272 North Second Street, Chambersburg, Pennsylvania, 17201(hereinafter the “COUNTY”) and ., a corporation organized and existing under the laws of the Commonwealth of Pennsylvania (hereinafter “CONTRACTOR”) with a principal address of . WHEREAS, the COUNTY requires annual financial and compliance audit services (hereinafter “SERVICES”); and WHEREAS, CONTRACTOR has presented an acceptable proposal to COUNTY and is desirous of providing the services to the COUNTY in accordance with the terms and conditions of this SERVICE AGREEMENT (hereinafter “AGREEMENT”); and WHEREAS, the Board of Commissioners of Franklin County by majority vote at a regularly scheduled meeting, approved CONTRACTOR to provide the SERVICES. NOW THEREFORE, in consideration of the foregoing, the Parties hereto agree as follows: 1. RECITALS The above recitals are incorporated herein by reference thereto and made a part of this AGREEMENT. 2. TERM The term of this AGREEMENT shall commence upon execution on and shall remain in effect until completion of the 2028 financial statement and compliance audit services or December 31, 2029, whichever comes later. There shall be an option to extend the contract term for up to two (2) additional one (1) year periods. The COUNTY shall exercise this option by notifying the Contractor in writing within thirty (30) days of the expiration of the then-current term. 3. INCORPORATION OF PROPOSAL The CONTRACTOR shall supply all work and comply with all requirements of its Proposal RFP 2026131-02 dated (“the PROPOSAL”) marked as Exhibit A and incorporated as though set forth fully herein. To the extent that any terms of the PROPOSAL conflict with the terms of the AGREEMENT, the AGREEMENT shall bind the Parties, unless otherwise mutually agreed in writing. 4. SCOPE OF SERVICES The CONTRACTOR’s responsibility under this AGREEMENT is to provide SERVICES as set forth in the PROPOSAL. See Exhibit A. 5. COUNTY RESPONSIBILITIES COUNTY shall provide all information and approvals required by CONTRACTOR in a manner that is timely and that will not unnecessarily delay the approval process. 6. GENERAL STANDARDS The CONTRACTOR shall perform all SERVICES in accordance with the generally accepted standards and practices used in the profession. The CONTRACTOR shall render diligently and competently all SERVICES, with due consideration given to applicable laws and regulations. The enumeration of specific duties and obligations to be performed by the CONTRACTOR hereunder shall not be construed to limit the general ethical requirements in the undertakings of the CONTRACTOR. 7. INFORMATION / ASSISTANCE PROVIDED BY COUNTY COUNTY will provide the following information and assistance to the CONTRACTOR: A. The COUNTY will designate a person to act as its representative with respect to the SERVICES to be rendered under this AGREEMENT. Such person shall have complete authority to transmit instructions and receive information pertaining to CONTRACTOR’s SERVICES. 8. SCHEDULE / TIME FOR PERFORMANCE OF SERVICES CONTRACTOR and the COUNTY shall mutually establish the schedule of SERVICES to meet the requirements of RFP 2026131-02. 9. TERMS OF PAYMENT TO CONTRACTOR A. The COUNTY shall pay the CONTRACTOR as set forth in Exhibit A, which is attached and incorporated by reference as through set forth fully herein. B. Invoices are due upon presentation and shall be considered past-due if not paid within forty-five (45) days of the invoice date. C. If the COUNTY objects to any portion of an invoice, the COUNTY shall so notify the CONTRACTOR in writing within twenty (20) days of receipt of the invoice. The COUNTY shall identify the specific cause of the disagreement and shall pay when due that portion of the invoice not in dispute. Interest as stated above shall be paid by the COUNTY on all disputed invoiced amounts resolved in the CONTRACTOR’s favor and unpaid for more than forty-five (45) days after date of the notice of the dispute. D. COUNTY reserves the right to withhold payments for costs determined not eligible for reimbursement. 10. INDEPENDENT CONTRACTORS Any SERVICES provided by the CONTRACTOR or its consultants under this AGREEMENT are provided as independent contractors. Nothing in this AGREEMENT shall be considered to create the relationship of employer and employee between the Parties. All persons engaged in any of the SERVICES performed pursuant to this AGREEMENT shall at all times and places be subject to the CONTRACTOR’s sole direction, supervision, and control. The CONTRACTOR shall exercise control over the means and manner in which it, its employees, and consultants perform the SERVICES. The CONTRACTOR does not have the power or authority to bind the COUNTY in any promise, agreement, or representation unless expressly provided written agreement to do so. 11. AUTHORITY TO PRACTICE / LICENSES The CONTRACTOR hereby represents and warrants that it has and will continue to maintain all licenses and approvals required to conduct its business and to provide the SERVICES as required pursuant to this AGREEMENT. 12. TERMINATION A. The COUNTY shall have the right to terminate this AGREEMENT at any time and for any reason, which termination shall be effective upon the COUNTY providing written notice to the CONTRACTOR. In the event that the COUNTY elects to terminate this AGREEMENT prior to CONTRACTOR’s performance of the SERVICES required hereunder the CONTRACTOR shall be compensated for all SERVICES satisfactorily completed in an amount proportionate to services actually provided by CONTRACTOR. B. The CONTRACTOR shall have the right to terminate this AGREEMENT in the event of substantial failure of COUNTY to perform in accordance with the terms hereof through no fault of the CONTRACTOR. As a condition precedent to the CONTRACTOR’s ability to terminate the AGREEMENT, the CONTRACTOR shall have provided the COUNTY with written notice of the delinquency and provided the COUNTY with sixty (60) days in which to cure the delinquency. If the CONTRACTOR terminates the AGREEMENT after meeting all conditions precedent, the CONTRACTOR shall be compensated for all SERVICES satisfactorily completed in an amount proportionate to the SERVICES actually provided by CONTRACTOR. 13. INDEMNIFICATION A. The CONTRACTOR and its consultants shall release, hold harmless, and indemnify the COUNTY, if officers, elected officials, agents, representatives, and employees acting within the scope of their official duties from and against damages, costs, and expenses (including reasonable attorneys’ fees) to the extent caused by the negligent acts, errors, or omissions of the CONTRACTOR, its employees, consultants, agents, servants, and/or anyone acting under the CONTRACTOR’s control and/or the CONTRACTOR’s direction, in the performance of the requirements of this AGREEMENT. The CONTRACTOR shall defend any lawsuit commenced against the COUNTY and shall pay any judgments and costs connected with such proceedings which are based upon the negligent acts or omissions of the CONTRACTOR or its consultants. 14. INSURANCE Prior to and during the performance of any SERVICES covered by this AGREEMENT, CONTRACTOR shall provide the COUNTY in a form reasonably acceptable to the Risk Manager and County Solicitor, evidence that it has obtained and maintains in full force and effect during the term of this AGREEMENT the types of insurance and amounts described as follows: i. General Liability insurance covering liability for death and bodily injury and liabilities for loss of or damage to property with a combined single limit of not less than One Million Dollars ($1,000,000) per occurrence and One Million Dollars ($1,000,000) in the aggregate; ii. Automobile Liability insurance combined single limit of not less than one million dollars and zero cents ($1,000,000.00) for any automobile. iii. Worker’s Compensation and Employer’s Liability insurance as required by the laws of the Commonwealth of Pennsylvania; iv. Employee Dishonesty coverage at a minimum limit of $25,000; v. Professional Liability insurance of not less than One Million Dollars ($1,000,000) per occurrence; and vi. Cyber Liability insurance of not less than One Million Dollars ($1,000,000) per occurrence and Two Million Dollars ($2,000,000) aggregate. The COUNTY shall be provided thirty (30) days advance written notice of any cancellation of the required insurances. 15. FORCE MAJEURE The COUNTY, and the CONTRACTOR shall not be held responsible for any delay, default, or nonperformance directly caused by an act of God, unforeseen adverse weather events, accident, labor strike, fire, explosion, riot, war, rebellion, terrorist activity, sabotage, flood, epidemic, act of federal or state government, labor, material, equipment, or supply shortage. 16. REMEDIES No remedy herein conferred upon any party is exclusive of any other remedy, and each and every remedy shall be cumulative and shall be in addition to every other remedy given hereunder or provided by law, equity, statute, or otherwise. No single or partial exercise by any party of any right, power, or remedy hereunder shall preclude any other exercise or further exercise thereof. 17. ENFORCEMENT COSTS, CHOICE OF LAW AND FORUM SELECTION If an action at law or in equity is necessary to enforce or interpret the terms of this Agreement, the prevailing party shall be entitled to recover, in addition to any other relief, reasonable attorney's fees, costs and disbursements. The parties agree that this Agreement shall be governed by the laws of the Commonwealth of Pennsylvania. All claims shall be filed in and heard by the Court of Common Pleas for the Thirty-Ninth Judicial District of Pennsylvania Franklin County Branch, which shall have exclusive jurisdiction thereunder. 18. NOTICES Any notices required to be given in accordance with this AGREEMENT shall be in writing and delivered to the Parties by certified mail or personal delivery or acceptable overnight courier service. Notice that is mailed shall be sent to the following addresses: If to the COUNTY: With Copy to: Franklin County Solicitor Administration Building 272 N. Second St. Chambersburg, PA 17201 If to the CONTRACTOR: 19. NON-DISCRIMINATION The CONTRACTOR shall not discriminate against any employee, applicant for employment, or any person seeking the SERVICES of the CONTRACTOR to be provided under this AGREEMENT on the basis of race, color, religion, creed, sex, age, national origin, marital status, or presence of any sensory, mental, or physical handicap. 20. ASSIGNMENT This AGREEMENT (including, without limitation, any rights under or interest in this AGREEMENT) shall not be assigned by either party without the express written consent of the other party hereto. The provisions of this Section shall survive the completion or termination of this AGREEMENT for any reason and shall remain enforceable between the Parties. 21. ENTIRE AGREEMENT / AMENDMENTS This AGREEMENT contains the entire AGREEMENT between the Parties and no other agreements, oral or otherwise, regarding the subject matter of this AGREEMENT, shall be deemed to exist or bind any of the Parties. This AGREEMENT cannot be modified, except by a written document signed by the Parties hereto. Board of Commissioners’ approval at a public meeting shall be required to amend this AGREEMENT unless otherwise delegated to its designees. 22. SEVERABILITY If any term, provision, covenant, or condition of this AGREEMENT is held by a court of competitive jurisdiction to be invalid, void or unenforceable, the remainder of the provisions hereof shall remain in full force and effect and shall in no way be affected, impaired, or invalidated as a result of such decision. 23. CAPTIONS The captions used herein are for convenience only and are not a part of this AGREEMENT and do not in any way limit or amplify the terms and provisions hereof. 24. NO OFFER This AGREEMENT does not constitute an offer and shall not be binding on the Parties unless and until executed by both Parties. 25. USE OF HEADINGS The use of headings within this AGREEMENT are for ease of reference and convenience only and shall not be used or construed to limit or enlarge the interpretation of the language hereof or the enforcement of this AGREEMENT. 26. EFFECTIVE DATE As used herein, the “Effective Date” shall mean the later of the COUNTY execution date and the CONTRACTOR execution date, each of which is set forth on the signature page hereof. OR As used herein, the "Effective Date" shall mean _____________, 20___. IN WITNESS WHEREOF, the Parties have caused this AGREEMENT to be executed on the dates written below. OR IN WITNESS WHEREOF, the County of Franklin, Pennsylvania have caused these presents to be executed, and its corporate seal affixed thereto and the Contractor has caused these presents to be executed in a like manner the days and year above written. ATTEST: CONTRACTOR _________________________________ ___________________________ (SEAL) BY: _________________ TITLE: _____________________ ATTEST: COUNTY OF FRANKLIN (SEAL), Carrie E. Gray Dean A. Horst County Administrator/ Chief Clerk Chairperson, Board of Commissioners John T. Flannery, Commissioner Robert G. Ziobrowski, Commissioner ATTACHMENT E Page 1 of 16 Revised: November 4, 2022 Business Associate Agreement This Business Associate Agreement (this “Agreement”) is entered into by [BUSINESS ASSOCIATE] (“Business Associate” and Franklin County, Pennsylvania (“Covered Entity”), individually referred to as “Party” and collectively as the “Parties.” This Agreement is effective as of [DATE] (“Effective Date”). RECITALS WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in Article 1 of this Agreement, and with the applicable provisions of the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”). WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to Covered Entity pursuant to the Services Agreement, as defined below. WHEREAS, Business Associate is a business associate under HIPAA. Business Associate must comply with the provisions of the Privacy Rule and Security Rule made applicable to business associates pursuant to HITECH and with all other applicable provisions of HITECH. WHEREAS, Covered Entity is not permitted to allow Business Associate to create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity without satisfactory assurances that Business Associate will appropriately safeguard the information. Therefore, Covered Entity will only disclose Protected Health Information to Business Associate or allow Business Associate to create or receive Protected Health Information on behalf of Covered Entity in accordance with the requirements of HIPAA, HITECH, and provisions of this Agreement. NOW, THEREFORE, in consideration of the mutual promises below and for other good and valuable consideration, the receipt and adequacy of which are hereby acknowledged, the Parties agree as follows: ARTICLE I DEFINITIONS Terms used in this Agreement that are specifically defined in HIPAA shall have the same meaning as set forth in HIPAA. A change to HIPAA which modifies any defined Page 2 of 16 Revised: November 4, 2022 HIPAA term, or which alters the regulatory citation for the definition shall be deemed incorporated into this Agreement. 1.1 Breach means the unauthorized acquisition, access, use, or disclosure of Protected Health Information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information. The term “breach” does not include the exceptions described in 42 U.S.C. § 17921(1)(B) summarized below. (a) Certain uses or disclosures by a Covered Entity’s work-force members (defined as persons acting under the authority of the Covered Entity or Business Associate), if the use or disclosure was made in good faith, was within the scope of the disclosing individual’s authority, and does not result in a further violation of the Privacy Rule. (b) Inadvertent disclosures from one person who is authorized to access PHI to another person who is also authorized to access PHI within the same Covered Entity, Business Associate, or organized health care arrangement when the disclosed PHI is not further used or disclosed in a manner not permitted under the Privacy Rule. (c) A disclosure of PHI when a Covered Entity or Business Associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information. 1.2 Designated Record Set, as defined under the Privacy Rule at 45 C.F.R. § 164.501, means a group of records maintained by or for a Covered Entity that are: (a) the medical records and billing records about individuals maintained by or for a covered health care provider; (b) the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health care plan; or (c) used, in whole or in part, by or for the Covered Entity to make decisions about individuals. For purposes of this section, a “Record” is any item, collection, or grouping of information that includes PHI and is maintained, collected, used, or disseminated by or for a Covered Entity. Page 3 of 16 Revised: November 4, 2022 1.3 Electronic Health Record has the same meaning that applies under Section 13400(5) of ARRA and currently means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized staff. 1.4 Electronic Protected Health Information (EPHI), as defined by 45 C.F.R. § 160.103, means individually identifiable health information that is transmitted by electronic media, or maintained in electronic media, but not certain education and employment records described in 45 C.F.R. § 160.103, the definition of Protected Health Information. EPHI also includes any EPHI provided by Covered Entity or created or received by Business Associate on behalf of Covered Entity. 1.5 HHS means the U.S. Department of Health and Human Services. 1.6 Individual, as defined by 45 C.F.R § 160.103, means the person who is the subject of PHI. It also includes a person who qualifies as a Personal Representative in accordance with 45 C.F.R. § 164.502(g). 1.7 Limited Data Set, as defined by 45 C.F.R. §164.514(e) is partially de- identified data that may be used or disclosed for research, public health and health care operation purposes, such as quality assurance, as long as a recipient signs a data use agreement that complies with HIPAA requirements. 1.8 Privacy Rule means the Standards for Privacy of individually Identifiable Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart E, any other applicable provision of HIPAA, and any amendments to HIPAA, including HITECH. 1.9 Protected Health Information (PHI) as defined by 45 C.F.R. § 164.103, mean individually identifiable health information that is: (a) transmitted by electronic media; (b) maintained in electronic media; or (c) transmitted or maintained in any other form or medium; PHI does not include certain education and employment records described in 45 C.F.R. § 160.103, the definition of PHI. PHI includes, without limitation, any PHI provided by Covered Entity or created or received by Business Associate on behalf of Covered Entity. Unless otherwise stated in this Agreement, any provision, restriction, or obligation in this Agreement related to the use of PHI shall apply equally to EPHI. Page 4 of 16 Revised: November 4, 2022 1.10 Required By Law, as defined by 45 C.F.R. § 164.103, means a mandate contained in law that compels an entity to make a use or disclosure of PHI and that is enforceable in a court of law; and any additional requirements created under HITECH. 1.11 Secretary means the Secretary of the Department of Health and Human Services or his/her designee. 1.12 Security Incident, as defined by 45 C.F.R. § 164.304, means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. 1.13 Security Rule means the Security Standards for the Protection of Electronic Protected Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart C, any other applicable provision of HIPAA, and any amendments to HIPAA, including HITECH. 1.14 Services Agreement means the underlying agreement(s) that outline the terms of the services that Business Associate agrees to provide to Covered Entity and that fall within the functions, activities or services described in the definition of Business Associate at 45 C.F.R. § 160.103. 1.15 Unsecured PHI shall mean PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary of HHS, such as encryption in compliance with the National Institute of Standards and Technology standards or destruction. ARTICLE II BUSINESS ASSOCIATE OBLIGATIONS 2.1 Request, Use and Disclosure of PHI. Business Associate agrees that it will only request, use and disclose PHI in accordance with the terms of this Agreement, and as is Required by Law. Business Associate acknowledges that it may only request, use and disclose PHI obtained or created pursuant to this Agreement with Covered Entity if the request, use or disclosure is in compliance with each applicable requirement of the Privacy Rule found in 45 C.F.R. § 164.504(e). 2.2 Permitted Requests, Uses and Disclosures. Business Associate will not request, use or disclose PHI except for the purpose of performing Business Associate’s obligations to Covered Entity as described in the Services Agreement, consistent with the requirements of HIPAA and this Agreement, and for other uses and disclosures permitted under this Agreement. Business Associate may request, use or disclose PHI only if such request, use or disclosure does not violate the Privacy Rule or this Page 5 of 16 Revised: November 4, 2022 Agreement. To the extent Business Associate is to carry out any of Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of the applicable obligations. In accordance with the provisions of 45 C.F.R. § 164.504(e)(4), Business Associate also may request, use or disclose PHI, if necessary: (a) for the proper management and administration of Business Associate’s organization, or (b) to carry out the legal responsibilities of Business Associate. Business Associate may only disclose PHI for these purposes, in accordance with the provisions of 45 C.F.R. § 164.504(e)(4)(ii), if either (i) the disclosure is Required By Law, or (ii) Business Associate obtains reasonable written assurances from the person to whom Business Associate discloses the PHI that the PHI will be held confidentially and used or further disclosed only as Required By Law or for the purposes for which it was disclosed to the person and that the person agrees to notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached. 2.3 Prohibited Requests, Use and Disclosures. Business Associate will not request, use or disclose PHI in any manner that constitutes a violation of the Privacy Rule, this Agreement, or the Services Agreement. 2.4 Minimum Requirements. Business Associate will only request, use and disclose the minimum amount of PHI necessary for Business Associate to perform the services for which it has been retained by Covered Entity, in accordance with 42 U.S.C. § 17935(b). Business Associate agrees to comply with the Secretary’s guidance on what constitutes minimum necessary. 2.5 Administrative, Physical and Technical Safeguards. Business Associate will develop, implement, maintain, and use appropriate safeguards to prevent any use or disclosure of the PHI other than as provided by this Agreement. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of EPHI. Business Associate acknowledges that the Security Rule provisions regarding administrative, physical, and technical safeguards, policies and procedures and documentation Page 6 of 16 Revised: November 4, 2022 requirements found in 45 C.F.R. §§ 164.308, 164.310, 164.312 and 164.316 apply to Business Associate in the same manner as to Covered Entity and Business Associate will fully comply with such Security Rule provisions. 2.6 Unusable, Unreadable or Indecipherable Technology. Business Associate will, to the extent feasible, adopt a technology or methodology specified by the Secretary pursuant to 42 U.S.C. § 17932(h) that renders PHI unusable, unreadable, or indecipherable to unauthorized individuals. 2.7 Agents and Sub-contractors. Prior to making any permitted disclosures, Business Associate will ensure that any of its agents, including subcontractors, to whom it provides PHI received from, or created or received by, Business Associate on behalf of Covered Entity agree in writing to be bound by the same privacy and security restrictions and conditions that apply to Business Associate under this Agreement, including but not limited to those conditions relating to termination of the contract for improper disclosure. Further, Business Associate shall implement and maintain sanctions against agents and subcontractors, if any, that violate such restrictions and conditions. Business Associate shall terminate any agreement with an agent or subcontractor, if any, who fails to abide by such restrictions and obligations. Business Associate shall not provide any PHI to any third party or subcontract any services described in the Services Agreement without Covered Entity’s express written permission. 2.8 Reporting Obligations. Business Associate will report, in writing, to Covered Entity any use or disclosure of PHI that is not authorized by this Agreement, including Breaches of Unsecured PHI. In addition, Business Associate will report in writing, to Covered Entity any Security Incident of which it becomes aware that it, its employees, or its agents or subcontractors experience involving or potentially involving Covered Entity EPHI. The written notice shall be provided to Covered Entity within five (5) business days of becoming aware of the non-authorized use or disclosure or Security Incident. 2.9 Notification to Covered Entity of Breach of Unsecured PHI. Business Associate will provide written notification to Covered Entity within seventy-two (72) hours of discovering a Breach of Unsecured PHI. Such notification will identify, to the extent possible, (1) each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been, accessed, acquired or disclosed during the Breach, (2) the nature of the non-permitted access, use or disclosure, including the date of the Breach and the date of discovery of the Breach; (3) Protected Health Information accessed, used or disclosed as part of the Breach (e.g., full name, social security number, date of birth, etc.); (4) who or what area of Business Associate’s operation made the non-permitted access, use or disclosure and who received the non- permitted disclosure; (5) identify what corrective action the Business Associate took or will take to prevent further non-permitted accesses, uses or Page 7 of 16 Revised: November 4, 2022 disclosures; (6) identify what Business Associate did or will do to mitigate any deleterious effect of the non-permitted access, use or disclosure; and (7) provide such other information that is reasonably available to Business Associate that Covered Entity may request. For purposes of the preceding sentence, Business Associate will be treated as discovering the Breach on the first day on which the Breach is known (or by exercising reasonable diligence should have been known) to Business Associate (including any employee, officer or other agent of Business Associate other than the person committing the Breach). Whether a Breach has occurred will be determined in accordance with applicable regulations or other authoritative guidance issued pursuant to the HITECH Act. A delay in notification of a Breach that qualifies as a “law enforcement delay” under 45 CFR Section 164.412 will not be treated as a violation of this Agreement. Business Associate will supplement its initial notification to Covered Entity with additional information as any additional information becomes available. Business Associate will implement a reasonable system for discovery of Breaches. 2.10 Breach Notification Expenses. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity and its employees, agents, and representatives from any and all direct, reasonable and actual costs, settlements, judgments, and expenses incurred by Covered Entity caused by a Breach of Unsecured Protected Health Information while in the possession of Business Associate, or its employees, subcontractors or agents. Such costs will include those related to Breach notifications sent to the affected individuals and the media, as required by Section 13402(e) of ARRA and 45 CFR Part 164, and any costs incurred by Covered Entity or its employees, agents or representatives to mitigate potential harm to individuals from the Breach. 2.11 Notification to Covered Entity of Use or Disclosure Data. Business Associate will notify Covered Entity in writing of any actual or suspected use or disclosure of data in violation of any applicable federal or state laws or regulations or any legal action against Business Associate arising from an alleged HIPAA violation. Business Associate shall take: (i) prompt action to correct any such deficiencies; and (ii) any action pertaining to such unauthorized disclosure required by applicable federal and state laws and regulations. Business Associate will provide the written notice to Covered Entity within five (5) business days of becoming aware of the violation or legal action. 2.12 Mitigation of Harmful Effect. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or Page 8 of 16 Revised: November 4, 2022 disclosure of PHI by Business Associate in violation of the requirements of this Agreement. 2.13 Designated Record Sets. Business Associate will make PHI in Designated Record Sets that are maintained by Business Associate or its agents or subcontractors, if any, available to Covered Entity or to an individual for inspection and copying within ten (10) business days of a request by Covered Entity to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to the requirements concerning access to individuals to PHI found at 45 C.F.R. § 164.524. If Business Associate maintains Protected Health information in the form of an Electronic Health Record for any individual, Business Associate agrees to provide, at the request of Covered Entity or an individual, and in the time and manner designated by Covered Entity, a copy of such information in an electronic format to that individual or, if clearly, conspicuously and specifically directed by the individual (or by Covered Entity based on a clear, conspicuous and specific request of the individual) to transmit an electronic copy of that information directly to an entity or person designated by the individual. Any fee charged to the individual for providing such information (or a summary or explanation of such information) may not exceed Business Associate’s labor costs incurred in responding to the individual’s request. 2.14 Amendments to PHI and EPHI. Within ten (10) business days of receipt of a request from Covered Entity for an amendment of PHI or a record about an individual contained in a Designated Record Set, Business Associate or its agents or subcontractors, if any, shall make such PHI available to Covered Entity for amendment and shall incorporate any such amendment to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.526. If an individual requests an amendment of PHI directly from Business Associate or its agents or subcontractors, if any, Business Associate must notify Covered Entity in writing within five (5) business days of the request. Any denial of amendment of PHI maintained by Business Associate or its agents or subcontractors, if any, shall be the responsibility of Covered Entity. Upon the approval of Covered Entity, Business Associate shall appropriately amend the PHI maintained by it, or any agents or subcontractors. 2.15 Accounting of PHI and EPHI. Within ten (10) business days of notice by Covered Entity of a request for an accounting of disclosures of PHI, Business Associate and any agents or subcontractors shall make available to Covered Entity the information required to provide an accounting of disclosures to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.528 and any additional information required under the HITECH Act, including Section 13405(c) if Business Associate maintains information in the form of an Electronic Health Record, and any implementing regulations. Page 9 of 16 Revised: November 4, 2022 (a) If a request for an accounting is made directly to Business Associate or its agents or subcontractors, Business Associate will notify Covered Entity of the request within five (5) business days of having received the request. Covered Entity shall either inform Business Associate to provide the requested information directly to the individual or request Business Associate to immediately forward the information to the Covered Entity for compilation and distribution to the individual. (b) In the case of a direct request for an accounting from an individual related to treatment, payment or health care operations disclosures through Electronic Health Records, Business Associate will provide the accounting to the individual in accordance with 42 U.S.C. § 17935(c) and any regulations adopted subsequent to this Agreement. Business Associate will confirm with Covered Entity that Covered Entity provided Business Associate’s name to the individual in response to a request for an accounting before providing the requested accounting to the individual. 2.16 Retention of Accounting Documentation. Notwithstanding termination of this Agreement, Business Associate and any of its agents or subcontractors shall continue to maintain the information required for purposes of complying with this Section 2.14 for a period of six (6) years after termination of the Agreement. 2.17 Business Associate’s Compliance with HHS. Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of HHS in the time and manner designated by the Covered Entity or the Secretary of HHS for purposes of determining Covered Entity’s compliance with the Privacy Rule. Business Associate will notify Covered Entity regarding any PHI that Business Associate provides to the Secretary of HHS concurrently with providing the requested PHI to the Secretary of HHS. Upon request by Covered Entity, Business Associate will provide Covered Entity with a duplicate copy of the requested PHI. 2.18 Inspection by Covered Entity. Within five (5) business days of a written request by Covered Entity, Business Associate and its agents or subcontractors, if any, shall allow Covered Entity to conduct a reasonable inspection of the facilities, systems, books, records, agreements, policies and procedures relating to the use or disclosure of PHI pursuant to this Agreement for the purpose of determining whether Business Associate has complied with this Agreement, the Security Rule and provisions of the Privacy Rule directly applicable to Business Associate or as deemed necessary by Covered Entity to determine whether a Breach has occurred. Both Parties agree to the following: Page 10 of 16 Revised: November 4, 2022 (a) Business Associate will cooperate with Covered Entity’s risk assessment without unreasonable delay; (b) Business Associate and Covered Entity will mutually agree in advance upon the scope, location and timing of such an inspection; and (c) Covered Entity will protect the confidentiality of all confidential and proprietary information of Business Associate to which Covered Entity has access during the course of such inspection. 2.19 Damages. Business Associate shall be responsible to compensate the affected individual for any reasonable damages as a result of a Breach caused by Business Associate. 2.20 No Ownership Rights. Business Associate agrees that Business Associate does not and will not have any ownership rights in any of the PHI. 2.21 Additional HITECH Requirements. The additional requirements of Title XIII of HITECH that relate to privacy and security and that are made applicable with respect to covered entities are also applicable to Business Associate and by this reference these requirements are hereby incorporated into this Agreement. 2.22 Standard Transactions. In conducting any standard transaction that is subject to the Standard Transaction Regulations (set forth in 45 C.F.R. Part 162) on behalf of Covered Entity, Business Associate agrees to comply with all requirements of the Standard Transaction Regulations that would apply to Covered Entity if Covered Entity were conducting the transaction itself and shall require the same of any subcontractor or agent involved with the conducts of such Standard Transactions. 2.23 Limitations on Marketing. Business Associate may not use and disclose PHI for “marketing,” as defined in 45 C.F.R. § 164.501, unless expressly permitted to do so in the Services Agreement. 2.24 Sale of PHI. Except for compensation set forth in the Services Agreement between Business Associate and Covered Entity, Business Associate shall not receive any direct or indirect remuneration in exchange for the provision of Protected Health Information. ARTICLE III COVERED ENTITY OBLIGATIONS Page 11 of 16 Revised: November 4, 2022 3.1 Risk Assessment of Breach by Covered Entity. Covered Entity shall make the final determination of whether for a Breach of PHI occurred. 3.2 Restrictions. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to or must comply with in accordance with 45 C.F.R. § 164.522 and 42 U.S.C. § 17935(a). 3.3 Notification of Changes or Revocations of Permission. Covered Entity shall provide Business Associate with notice of any changes to, revocation of, or permission by individual to use or disclose PHI, if such changes affect Business Associate’s permitted uses or disclosures, within a reasonable period of time after Covered Entity becomes aware of such changes to or revocation of permission. 3.4 Permissible Requests by Covered Entity. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy and Security Rules if done by Covered Entity. ARTICLE IV TERMINATION 4.1 Term and Survival. The term of this Agreement shall be effective as of the Effective Date of this Agreement and continue until terminated by Covered Entity or any underlying Services Agreement expires or is terminated. Any provision related to the use, disclosure, access, or protection of PHI or EPHI or that by its terms shall survive termination of this Agreement shall survive termination. 4.2 Termination for Breach. A material breach by Business Associate, or its agents or subcontractors, if any, of this Agreement, as determined by Covered Entity, shall constitute a material breach of the Services Agreement. As provided for under 45 C.F.R. §§ 164.314(a)(2)(i)(D) and 164.504(e)(2)(iii), the Covered Entity may immediately terminate this Agreement and the Services Agreement or, alternatively, the Covered Entity may choose to provide Business Associate with written notice of the material breach and an opportunity to cure the material breach or end the violation within thirty (30) calendar days. If Business Associate becomes aware of a material breach of this Agreement by Covered Entity, Business Associate shall (1) provide an opportunity for Covered Entity to cure the breach or end the violation and terminate this Agreement (and any applicable portion of the Services Agreement between the parties) if Covered Entity does not cure the breach or end the violation within thirty (30) calendar days, or (2) immediately terminate this Agreement (and any applicable portion of the Services Agreement ) if Covered Entity has breached a material term of this Agreement and cure is not possible. Page 12 of 16 Revised: November 4, 2022 4.3 Termination for Violation by Business Associate. Covered Entity may terminate this Agreement and the Services Agreement effective immediately, if (i) Business Associate is named as a defendant in a criminal proceeding for a violation of HIPAA, HITECH, or other security or privacy laws or (ii) there is a finding or stipulation that Business Associate has violated any standard or requirement of HIPAA, HITECH, or other security or privacy laws in any administrative or civil proceeding in which Business Associate is involved. 4.4 Return or Destruction of PHI. (a) Upon termination of this Agreement for any reason, Business Associate shall return or, at Covered Entity’s request, destroy all PHI received from Covered Entity or created or received by Business Associate on behalf of Covered Entity that Business Associate still maintains in any form. If Business Associate destroys the PHI, Business Associate shall certify in writing to Covered Entity that such PHI has been destroyed. This provision applies to PHI that is in the possession of agents or subcontractors of Business Associate. Business Associate will retain no copies of the PHI. (b) If Business Associate determines that returning or destroying the PHI is not feasible, Business Associate shall explain to Covered Entity why conditions make the return or destruction of the PHI not feasible. If Covered Entity agrees that the return or destruction of PHI is not feasible, Business Associate will retain the PHI, subject to all of the protections of this Agreement, and limit further uses and disclosures of the PHI to those purposes that make the return or destruction of the PHI infeasible for so long as Business Associate maintains the PHI. (c) If Business Associate determines that it is infeasible to obtain from an agent or subcontractor any PHI in the possession of the agent or subcontractor or to destroy the PHI, Business Associate will provide Covered Entity written notification explaining why obtaining the PHI is infeasible. If Covered Entity agrees that the return or destruction of PHI is not feasible, Business Associate will require the agent or subcontractor to extend the protections of this Agreement to the PHI and limit further uses and disclosures of the PHI to those purposes that make the return or destruction of the PHI infeasible for so long as the agent or subcontractor maintains the PHI. 4.5 Termination of Services Agreement. If this Agreement is terminated for any reason, Covered Entity will also terminate the Services Agreement between the Page 13 of 16 Revised: November 4, 2022 Parties. This provision shall supersede any termination provision to the contrary which may be set forth in the Services Agreement. ARTICLE V MISCELLANEOUS 5.1 Acknowledgement. By affixing their respective signatures below, the Parties certify that they have read and understand each and every provision in this Agreement. Each Party certifies that it possesses the authority to enter into the Agreement. The execution and performance of this Agreement by each Party has been duly authorized by all necessary laws, resolutions or corporate actions, and the Agreement constitutes valid and enforceable obligations of each Party in accordance with its terms. 5.2 Amendment. This Agreement shall not be amended, altered, or modified, except by an instrument in writing duly executed by the Parties to the Agreement. 5.3 Assignment. This Agreement may not be assigned by Business Associate without the prior written consent of Covered Entity. 5.4 Binding Effect. Subject to provisions hereof restricting assignment, this Agreement shall be binding upon and shall inure to the benefit of the Parties and their respective successors and permitted assigns. 5.5 Change in Law. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity and Business Associate to comply with the requirements of HIPAA and the HITECH Act, and of the regulations issued pursuant to those laws. If Covered Entity reasonably concludes that an amendment to this Agreement is needed because of change in federal or state law or changing industry standards, Covered Entity shall notify Business Associate of such proposed modification(s), “Legally-Required Modifications”. Such Legally Required Modifications shall be deemed accepted by Business Associate and this Agreement so amended, if Business Associate does not, within thirty (30) calendar days following the date of notice, or within such other time period as may be mandated by applicable state or federal law, deliver to Covered Entity its written rejection of such Legally-Required Modifications. 5.6 Compliance with Laws. Business Associate will comply with all applicable federal and state security and privacy laws, to the extent that such laws apply to Business Associate or are more protective of individual privacy than HIPAA. 5.7 Entire Agreement. This Agreement, including attachments, constitutes the entire Agreement between the Parties with respect to the subject matter hereof, and it Page 14 of 16 Revised: November 4, 2022 supersedes all prior oral or written agreements, commitments, or understandings with respect to the matters provided for herein. 5.8 Execution. This Agreement and any amendments thereto shall be executed in duplicate copies on behalf of the Parties by an official of each, specifically authorized by its respective Party to perform such executions. Each duplicate copy shall be deemed an original, but both duplicate originals together constitute one and the same instrument. 5.9 Indemnification by Business Associate. Business Associate and any of its subcontractors and agents shall indemnify, hold harmless and defend Covered Entity and its employees, officers, directors, agents, and contractors from and against any and all claims, losses, liabilities, costs, attorneys’ fees, and other expenses incurred as a result of or arising directly or indirectly out of or in connection with Business Associate’s or its subcontractors’ or agents’ breach of this Agreement, violation of HIPAA, HITECH or other applicable law, or otherwise related to the acts or omissions of Business Associate or its subcontractors or agents. 5.10 Independent Contractors. This Agreement establishes an independent contractor relationship between Covered Entity and Business Associate. Nothing in this Agreement is intended, nor may anything be construed, to create a partner, joint venture employer/employee, or agent relationship. 5.11 Limitations on Benefits of this Agreement. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than Covered Entity, Business Associate, or their respective successors or assigns, any rights, remedies, obligations or liabilities whatsoever. It is the express intent of the Parties that no person or entity other than the Parties shall be entitled to bring any action to enforce any provision of this Agreement against either of the Parties, and that the Agreement set forth shall be solely for the benefit of, and shall be enforceable only by, the Parties to this Agreement or their respective successors and assigns as permitted hereunder. 5.12 Notices. All notices which are required or permitted to be given pursuant to this Agreement shall be in writing and shall be sufficient in all respects if delivered personally, by electronic facsimile (with a confirmation by registered or certified mail placed in the mail no later than the following day), or by registered or certified mail, postage prepaid, addressed to a Party as indicated below: If to Business Associate: If to Covered Entity, to: [INSERT APPROPRIATE CONTACT INFORMATION] Page 15 of 16 Revised: November 4, 2022 Notice shall be deemed to have been given upon transmittal thereof as to communications which are personally delivered or transmitted by electronic facsimile and, as to communications made by United States mail, on the third (3rd) day after mailing. The above addresses may be changed by giving notice of such change in the manner provided above for giving notice. 5.13 References. A reference in this Agreement to a section in the Privacy Rule or Security Rule means the section as in effect or as amended at the time of reference and as interpreted pursuant to any applicable guidance provided by the Secretary or other responsible regulatory authority and any applicable case law. 5.14 Severability. If any part of any provision of this Agreement, or any other agreement, document or writing given pursuant to or in connection with this Agreement, shall be held invalid or unenforceable, the holding of invalidity or unenforceability will apply to the invalid or unenforceable part of the provision only, without in any way affecting the remaining parts of said provision or the remaining provisions of said Agreement. 5.15 Sub-Contract. Business Associate may not sub-contract any services under the Services Agreement without the express written consent of Covered Entity. 5.16 Waiver. Neither the waiver by either Party of a breach of or a default under any of the provisions of this Agreement, nor the failure of either of the Parties, on one or more occasions, to enforce any of the provisions of this Agreement or to exercise any rights or privilege hereunder shall thereafter be construed as a waiver of any subsequent breach or default of a similar nature, or as a waiver of any such provisions, rights or privileges hereunder. 5.17 Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with applicable requirements of HIPAA HITECH Act, the Privacy Rule and the Security Rule. Any conflict between a provision of the Services Agreement and this Agreement regarding the subject matter of this Agreement, shall be resolved in favor of this Agreement IN WITNESS WHEREOF, the parties have caused this Agreement to be executed by their respective duly authorized representatives as of the dates set forth below. BUSINESS ASSOCIATE COVERED ENTITY By: By: Name: Name: Title: Title: