HomeMy WebLinkAboutRFP 2026131-02 Professional Audit Services - FINAL
REQUEST FOR PROPOSAL for
PROFESSIONAL AUDIT SERVICES
FOR THE COUNTY OF FRANKLIN, PA
COUNTY OF FRANKLIN, PENNSYLVANIA
RFP# 2026131-02
County of Franklin, PA
272 North Second Street
Chambersburg, PA 17201
Contents
SECTION I – INTRODUCTION & INSTRUCTIONS......................................................................... 2
1.01 PURPOSE ...................................................................................................................... 2
1.02 RFP SCHEDULE ............................................................................................................. 2
1.03 REQUIRED REVIEW ........................................................................................................ 2
1.04 AMENDMENTS TO PROPOSALS ..................................................................................... 3
1.05 AMENDMENTS TO THE RFP ............................................................................................ 3
1.06 QUESTION & ANSWER PERIOD ...................................................................................... 3
1.07 PRE-PROPOSAL CONFERENCE ..................................................................................... 3
1.08 RETURN INSTRUCTIONS ................................................................................................ 3
1.09 RIGHT TO REJECT PROPOSALS ...................................................................................... 4
1.10 TERM ............................................................................................................................. 4
1.11 NONDISCRIMINATION CLAUSE ..................................................................................... 4
SECTION II - BACKGROUND & INFORMATION ........................................................................... 5
SECTION III - SCOPE OF WORK TO BE PERFORMED .................................................................. 6
3.01 FINANCIAL STATEMENT AUDIT ....................................................................................... 6
3.02 SINGLE AUDIT................................................................................................................ 6
3.03 AUDIT SCHEDULE AND REPORTING EXPECTATIONS ...................................................... 7
3.04 ADDITIONAL SERVICES .................................................................................................. 7
3.05 SPECIAL CONSIDERATION............................................................................................. 8
3.06 AUDITING STANDARDS TO BE FOLLOWED ..................................................................... 9
3.07 ASSISTANCE TO BE PROVIDED BY COUNTY STAFF ........................................................ 10
3.08 AUDITOR RESPONSIBILITIES ......................................................................................... 11
3.09 WORKING PAPER RETENTION AND ACCESS TO WORKING PAPERS .............................. 12
3.10 CONTINUITY OF ASSIGNED PERSONNEL ...................................................................... 13
SECTION IV - RESPONSE FORMAT ........................................................................................... 13
SECTION V - EVALUATION OF THE PROPOSALS & GENERAL SELECTION PROCESS ................. 17
SECTION VI - CONTRACT PROVISIONS & INSURANCE REQUIREMENTS ................................... 18
6.01 CONTRACT PROVISIONS .............................................................................................. 18
6.02 INSURANCE ................................................................................................................. 20
SECTION VII - GENERAL LEGAL INFORMATION ........................................................................ 21
7.01 RIGHT OF REJECTION ................................................................................................... 21
7.02 VENDOR CLEARANCE .................................................................................................. 21
7.03 COUNTY NOT RESPONSIBLE FOR PREPARATION COSTS .............................................. 21
7.04 DISCLOSURE OF PROPOSAL CONTENTS ..................................................................... 21
ATTACHMENT A 2026 BUDGET IN BRIEF
ATTACHMENT B BASIC FINANCIAL STATEMENT FOR THE YEAR ENDED DECEMBER 31, 2025
ATTACHMENT C SINGLE AUDIT REPORTS FOR THE YEAR ENDED DECEMBER 31, 2025
ATTACHMENT D PROPOSED CONTRACT
ATTACHMENT E BUSINESS ASSOCIATE AGREEMENT
ATTACHMENT F SCHEDULE OF PROFESSIONAL FEES
SECTION I – INTRODUCTION & INSTRUCTIONS
1.01 PURPOSE
The County of Franklin is requesting proposals from qualified independent certified public
accounting firms to perform annual financial and compliance (Single) audits for the
County.
The selected firm shall conduct audits of the County's financial statements in accordance
with generally accepted auditing standards (GAAS), Government Auditing Standards
issued by the Comptroller General of the United States, and, when applicable, the Uniform
Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards
(Uniform Guidance).
1.02 RFP SCHEDULE
The RFP schedule set out herein represents Franklin County’s best estimate of the
schedule that will be followed. If a component of this schedule, such as the deadline for
the receipt of proposals, is delayed, the rest of the schedule may be shifted accordingly.
All times are Franklin County, Pennsylvania time.
RFP Released…………………………………………………………. Friday September 11, 2026
Proposer Questions due by …………………… Monday September 28, 2026, at 4:00 PM
Responses to Questions to be posted by .………………………… Friday October 2, 2026
RFP Submission Deadline ……………………..……… Friday October 9, 2026, at 4:00 PM
Anticipated Selection Date ………………………………………………… December 30, 2026
1.03 REQUIRED REVIEW
Offerors should carefully review this solicitation for defects and erroneous material.
Submit comments concerning defects and erroneous material in writing to the
procurement office at procurement@franklincountypa.gov a minimum of ten days before
the deadline for receipt of proposals. This will allow time for the issuance of any necessary
amendments. It will also help prevent the opening of a defective proposal and exposure of
the offeror’s proposals upon which award could not be made.
1.04 AMENDMENTS TO PROPOSALS
Amendments to or withdrawals of proposals will only be allowed if an acceptable request
is received prior to the deadline that is set for the receipt of proposals. No amendments or
withdrawals will be accepted after the deadline.
1.05 AMENDMENTS TO THE RFP
If an amendment is issued, it will be posted on the Franklin County, PA website at
https://www.franklincountypa.gov/current-solicitation-opportunities/.
1.06 QUESTION & ANSWER PERIOD
All questions must be submitted in writing to procurement@franklincountypa.gov.
Questions may be submitted until Monday September 28, 2026, at 4:00 PM, prevailing
Franklin County, Pennsylvania time.
1.07 PRE-PROPOSAL CONFERENCE
There is no pre-proposal conference for this RFP.
1.08 RETURN INSTRUCTIONS
Proposals shall be submitted to the Procurement Office as electronic PDF files at the
following address:
Franklin County, Pennsylvania
Procurement Department RFP #2026131-02
272 North Second Street
Chambersburg, PA 17201
The electronic files may alternatively be submitted via email to
procurement@franklincountypa.gov or via a USB flash drive.
The technical proposal shall be titled in the format of “VENDOR A – AUDIT SERVICES
PROPOSAL – TECHNICAL” where VENDOR A is the name of your firm.
The cost proposal shall be saved in a separate PDF file from the main proposal and clearly
named in a format such as “VENDOR A – AUDIT SERVICES – COST PROPOSAL”.
Any confidential information submitted by the vendor must be submitted in a separate PDF
Document from the main proposal and labeled similarly as described above including the
word “Confidential” at the end of the file name.
The County is not responsible for deliveries that do not reach the Procurement Department
by the required due date and time.
1.09 RIGHT TO REJECT PROPOSALS
The County reserves the right, at its discretion, to reject any or all Proposals and to waive
irregularities or information in any proposal and to award contracts based on the proposal
deemed the greatest overall value and benefit to the County. The County shall be the sole
judge as to what constitutes the greatest overall value.
1.10 TERM
The initial term of the contract shall begin upon execution and end December 31, 2029 or
upon completion of the 2028 audit, whichever comes later. There shall be an option to
extend the contract term for up to two (2) additional one (1) year periods. The County shall
exercise this option by notifying the Contractor in writing within thirty (30) days of the
expiration of the then-current term.
1.11 NONDISCRIMINATION CLAUSE
Franklin County assures that no person shall be excluded from participating in, be denied
the benefits of, or be otherwise subjected to discrimination on the grounds of race, gender,
creed, color, sexual orientation, gender identity or expression, or in violation of the
Pennsylvania Human Relations Act, which prohibits discrimination on the basis of race,
color, religious creed, ancestry, age, sex, national origin, handicap or disability, or in
violation of any applicable local, state, or federal laws. With advance notification,
accommodations may be provided for those with special needs for language, speech, sight
or hearing. If you have a request for a special need, wish to file a complaint, or desire
additional information please contact the Risk Management Department at (717) 261-3819
or riskmgt@franklincountypa.gov.
SECTION II - BACKGROUND & INFORMATION
The County of Franklin is a fourth-class county located in south-central Pennsylvania,
operating under an elected three-person Board of Commissioners organized under the
laws of the Commonwealth of Pennsylvania and governed under the County Code of 1955,
as amended.
The County maintains multiple governmental, proprietary, fiduciary, and component
activities and annually expends federal financial assistance requiring a Single Audit.
The County provides services to its residents in many areas, including various general
government services, a court system, public safety, corrections, health and welfare, public
works (bridge program), conservation and development, and community enrichment
programs.
General Information:
• Annual operating budget - approximately $140 million
• Number of active funds – 38
• Number of employees – approximately 700 full-time, part-time, and casual
• Enterprise Resource Planning software – Tyler Enterprise ERP
• Annual federal expenditures – approximately $12 million
More information on the County of Franklin, its operations and finances can be found at
www.franklincountypa.gov. The County’s 2026 Budget in Brief (Attachment A), Basic
Financial Statement for the year ended December 31, 2025 (Attachment B) and the Single
Audit Reports for the year ended December 31, 2025 (Attachment C) are included in this
Request for Proposal.
SECTION III - SCOPE OF WORK TO BE PERFORMED
3.01 FINANCIAL STATEMENT AUDIT
The County of Franklin seeks the services of an independent certified public accounting
firm to perform an annual audit of the County's financial statements. The audit shall be
conducted in accordance with generally accepted auditing standards (GAAS), Government
Auditing Standards issued by the Comptroller General of the United States, and all other
applicable professional standards.
Upon completion of the audit, the selected firm shall issue an Independent Auditor's
Report expressing an opinion on the County's financial statements. In addition, the auditor
shall issue a Report on Internal Control over Financial Reporting and on Compliance and
Other Matters based on an audit of the financial statements performed in accordance with
Government Auditing Standards. The auditor shall also provide all communications
required by professional auditing standards to those charged with governance, including
any significant audit findings, accounting policies, estimates, difficulties encountered
during the audit, and uncorrected misstatements.
Should deficiencies in internal control or other matters warrant communication to
management, the auditor shall issue a management letter containing recommendations
for operational, financial reporting, or internal control improvements.
The County expects that the audit to be performed utilizing a combination of on-site and
remote procedures. The County also encourages firms to maximize the use of secure
electronic document exchange as opposed to other communication methods.
3.02 SINGLE AUDIT
The County annually expends federal financial assistance and, therefore, requires the
auditor to conduct a Single Audit in accordance with the Single Audit Act Amendments and
the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for
Federal Awards (Uniform Guidance).
The auditor shall perform all procedures necessary to satisfy federal Single Audit
requirements, including identification of major programs, testing of compliance
requirements applicable to those programs, and evaluation of internal controls over
compliance. The auditor shall prepare and issue all reports required under Uniform
Guidance, including the Schedule of Findings and Questioned Costs and related
auditor reports.
The auditor shall review the County-prepared Schedule of Expenditures of Federal Awards
(SEFA), evaluate the completeness and accuracy of federal expenditures reported, and
perform all procedures necessary to support the issuance of the required audit opinions.
The auditor shall also assist the County with matters related to the completion and
submission of the Data Collection Form and filing requirements of the Federal Audit
Clearinghouse.
3.03 AUDIT SCHEDULE AND REPORTING EXPECTATIONS
The County anticipates that the annual audit will be performed in accordance with a
schedule generally consistent with the timeline outlined below. The purpose of this
schedule is to facilitate timely completion of the audit, compliance with applicable federal
and state reporting requirements, and presentation of final audit reports to County
management and the Board of Commissioners.
Milestone Anticipated Timing
The County expects the selected auditor to work cooperatively with County personnel
throughout the engagement to establish detailed planning, fieldwork, review, and reporting
schedules. Proposers should describe their anticipated audit timeline and identify any
scheduling considerations that may affect completion of the engagement.
The County recognizes that firms may employ differing audit methodologies and
scheduling approaches. Accordingly, proposers may recommend alternative timelines or
milestone dates, provided that all applicable reporting deadlines are met and final audit
reports are issued in a timely manner.
3.04 ADDITIONAL SERVICES
The County expects the selected firm to serve as a professional resource throughout the
term of the engagement. The purpose of this is to allow The County to be proactive in
aligning with the audit requirements. Accordingly, the firm shall be available to provide
technical accounting and auditing guidance to County management and Fiscal
Department staff as questions arise during the year for this purpose. Examples of such
services may include consultation regarding the implementation of new Governmental
Accounting Standards Board (GASB) pronouncements, interpretation of emerging
accounting and auditing standards, assistance with federal compliance matters, and
discussion of industry best practices affecting county governments.
Representatives of the firm may be requested to attend meetings of the Board of
Commissioners, management, or other County officials to discuss audit results,
accounting matters, compliance issues, or significant developments affecting the County.
In addition, the selected firm shall provide annual training to County personnel, of a
minimum of eight (8) hours per year. Training topics may include updates to Uniform
Guidance requirements, changes to the annual Compliance Supplement, new GASB
standards, governmental accounting developments, internal control practices, and other
matters relevant to County financial management and federal program administration.
3.05 SPECIAL CONSIDERATION
The County's reporting entity includes several discretely presented component units
whose financial information is incorporated into the County's annual financial reporting.
Separate audit engagements for these component units are administered independently of
this Request for Proposals and are not included within the scope of services to be provided
under this engagement.
The County's component units currently include the Franklin County Conservation District,
Letterkenny Industrial Development Authority, Franklin County Industrial Development
Authority, Tuscarora Managed Care Alliance, and the Franklin County Redevelopment
Authority.
County Fiscal Department personnel have historically served as the primary point of
contact with component unit management and their respective auditors and will continue
to coordinate the collection of audited financial statements, audit reports, management
representations, and other necessary information for the County's financial reporting
process. The selected auditor shall evaluate component unit financial information and
perform such procedures as are required by applicable professional auditing standards;
however, proposers should assume that the County will coordinate the collection of
component unit financial reporting information and that the selected auditor will not be
responsible for managing communications with component unit auditors except as
necessary to address specific audit matters arising during the engagement.
The County reserves the right to add or remove component units from its reporting entity
during the term of the engagement should circumstances require.
3.06 AUDITING STANDARDS TO BE FOLLOWED
The audit shall be conducted in accordance with generally accepted auditing standards
(GAAS) as promulgated by the American Institute of Certified Public Accountants; the
standards applicable to financial audits contained in Government Auditing Standards
issued by the Comptroller General of the United States; the provisions of the federal Single
Audit Act of 1984, as amended; and the Uniform Administrative Requirements, Cost
Principles, and Audit Requirements for Federal Awards (Uniform Guidance), as amended.
The auditor shall perform all audit procedures necessary to express an opinion on the
County's financial statements and to satisfy all applicable reporting requirements
associated with a Single Audit. The auditor shall also consider and apply all relevant
Governmental Accounting Standards Board (GASB) pronouncements, the Pennsylvania
Department of Human Services Single Audit Supplement (formerly Department of Public
Welfare), and any additional federal, state, local, or programmatic compliance
requirements applicable to the County.
The auditor shall issue all reports required under the applicable professional standards,
including reports on financial statements, internal control over financial reporting,
compliance, and federal awards programs. The auditor shall communicate audit findings,
recommendations, and other matters required by professional standards to management
and those charged with governance.
In submitting a proposal, firms should recognize that Franklin County maintains significant
internal financial reporting capabilities and has historically assumed responsibility for the
preparation of its financial statements, note disclosures, Management's Discussion and
Analysis (MD&A), Schedule of Expenditures of Federal Awards (SEFA), and related
supporting schedules. Accordingly, the County seeks an independent auditor to perform
audit and attestation services rather than a firm to provide extensive financial statement
preparation services.
3.07 ASSISTANCE TO BE PROVIDED BY COUNTY STAFF
Franklin County maintains an experienced financial management team consisting of Fiscal
Department personnel, the Controller's Office, and departmental management staff who
actively participate in the annual audit process. County personnel are committed to
providing timely access to records, schedules, supporting documentation, and
explanations necessary for the completion of the audit.
The Fiscal Department serves as the County's primary financial reporting function and is
responsible for the preparation of the County's financial statements, note disclosures,
Management's Discussion and Analysis (MD&A), Schedule of Expenditures of Federal
Awards (SEFA), and related supporting schedules. The Controller's Office and other
County personnel provide support through the maintenance of accounting records,
processing of accounting transactions, and assistance with information and
documentation requests necessary to facilitate the audit process.
For purposes of audit planning, fieldwork coordination, financial reporting matters,
implementation of new accounting standards, federal compliance reporting, and
preparation of audit schedules, the auditor should anticipate working primarily with the
Fiscal Department, with support provided by the Controller's Office and other County
departments as necessary.
County personnel will prepare the financial statements, SEFA, supporting grant
expenditure schedules, Assistance Listing ID (formerly CFDA, the Catalog of Federal
Domestic Assistance, number), reconciliations of federal expenditures to the County's
accounting records, and other schedules necessary for the audit. The auditor will be
expected to review, test, and opine on these schedules as required by applicable auditing
standards and Uniform Guidance.
To facilitate the audit, County staff will prepare and provide a comprehensive package of
audit workpapers and supporting schedules, including trial balances, general ledger detail,
bank reconciliations, capital asset records, debt schedules, lease and subscription-based
information technology arrangement (SBITA) schedules, pension and OPEB information,
grant documentation, accounts receivable and payable analyses, revenue and expenditure
schedules, and other documentation customarily requested during governmental financial
and compliance audits.
County personnel will serve as the primary liaison with the County's discretely presented
component units and their respective auditors and will coordinate the collection of audited
financial statements, supporting schedules, and other information required for the
County's financial reporting and audit processes. The County will make such information
available to the selected auditor as necessary to facilitate the performance of procedures
required by applicable professional auditing standards.
The County will provide designated audit liaison personnel throughout the engagement to
coordinate requests and facilitate communication between the audit team and County
departments. The County will also provide reasonable workspace for on-site fieldwork,
internet access, and secure electronic access to records and supporting documentation.
The County encourages the use of electronic workpapers, secure file-sharing
technologies, and remote auditing techniques whenever practical and consistent with
professional auditing standards.
3.08 AUDITOR RESPONSIBILITIES
The selected auditor shall be responsible for planning and performing the audit in
accordance with the auditing standards and requirements identified in this Request for
Proposals. The auditor shall develop an audit plan and engagement timeline designed to
facilitate the timely completion of all audit and reporting requirements.
The auditor shall perform appropriate risk assessment procedures, obtain an
understanding of internal controls relevant to the audit, and conduct such testing and
other procedures as are necessary to express an opinion on the County's financial
statements. The auditor shall also perform all procedures required under Government
Auditing Standards and Uniform Guidance, including testing of internal controls and
compliance requirements applicable to federal programs selected for Single Audit testing.
Throughout the engagement, the auditor shall maintain open and timely communication
with County management regarding audit progress, information requests, emerging
issues, potential findings, and other matters that may affect the audit. The auditor shall
promptly communicate any significant deficiencies, material weaknesses, instances of
noncompliance, questioned costs, or other reportable conditions identified during the
course of the engagement.
The auditor shall provide draft audit reports and related communications to management
for review prior to issuance of final reports. Final audit reports shall be issued in
accordance with the mutually agreed-upon audit schedule and any reporting deadlines
established by applicable federal, state, or local requirements.
The auditor shall designate an engagement partner and audit manager who will serve as
primary contacts for the County throughout the term of the engagement and who will be
responsible for ensuring continuity, responsiveness, and quality of service.
The County utilizes audit cost allocations for indirect cost and grant reimbursement
purposes. Accordingly, the auditor shall provide a reasonable estimate of the distribution
of audit effort among the County's major programs, operations, and reporting units. The
County recognizes that such allocations are estimates and are not intended to represent
precise measurements of actual audit costs incurred by program or activity. The allocation
may be based upon anticipated audit hours, level of audit effort, relative risk, transaction
volume, or another reasonable methodology consistently applied by the proposer. The
proposed allocation shall include, at a minimum, the General Fund, each of the Human
Services programs, Domestic Relations, Liquid Fuels, 911, Community Development Block
Grant programs, and other major County operations as applicable.
3.09 WORKING PAPER RETENTION AND ACCESS TO WORKING PAPERS
The auditor shall retain all working papers, reports, correspondence, and other records
relating to the audit for a period of not less than three (3) years following acceptance of the
audit report by the County and final resolution of all audit findings, whichever is later, or for
such longer period as may be required by applicable professional standards, federal
regulations, state requirements, or pending audit matters.
If notified by the County, federal agencies, state agencies, or other authorized oversight
bodies of the need to extend the retention period, the auditor shall retain such records for
the additional period specified.
Upon reasonable notice, the auditor shall make audit documentation available for
inspection by authorized representatives of the County, federal and state oversight
agencies, or other parties entitled to access under applicable law, regulation, or
professional standards.
The auditor shall respond in a timely and professional manner to reasonable inquiries from
successor auditors and shall provide access to working papers and other audit
documentation relating to matters of continuing accounting significance in accordance
with applicable professional standards. Such access shall be provided at no additional
cost to the County, except for reasonable reproduction expenses, if any. In the event the
County engages a successor auditor, the incumbent auditor shall cooperate fully in
facilitating an orderly transition, including participation in transition meetings and timely
responses to reasonable requests for information.
Nothing contained herein shall be construed to require the disclosure of proprietary audit
methodologies, proprietary software, or other materials protected from disclosure under
applicable professional standards or law.
3.10 CONTINUITY OF ASSIGNED PERSONNEL
The County places significant value on continuity and retention of engagement personnel
throughout the term of the contract. Proposers should recognize that the County's
evaluation will consider not only the qualifications of the proposed engagement team, but
also the firm's ability to maintain staffing continuity and preserve institutional knowledge
throughout the engagement period.
The County expects the engagement partner, audit manager and in-charge auditor
identified in the proposal to remain actively involved throughout the engagement unless
circumstances beyond the firm's reasonable control require reassignment. The County’s
award is based in part upon the qualifications and experiences of these individuals, and
the contractor shall not remove, replace or reassign these personnel without providing
advance written notice to the County. If replacement of key personnel becomes
necessary, the firm shall provide personnel possessing qualifications and governmental
auditing experience substantially equivalent to or greater than those of the individual being
replaced, subject to County approval.
SECTION IV - RESPONSE FORMAT
The County discourages overly lengthy and costly proposals. In order for the County to
evaluate proposals fairly and completely, offerors must follow the format set out in this
RFP and provide all requested information.
If your firm has prior experience working with the County, DO NOT assume this prior work
is known to the evaluation committee. All firms are evaluated solely by the information
contained in their proposal, information obtained from references, and interviews or
presentations, if requested. All submittals must be prepared as if the evaluation
committee has no knowledge of the firm, their qualifications or past projects.
Any submission that does not follow this format or does not include all the information
requested may be deemed unresponsive by the County and not evaluated.
TECHNICAL PROPOSAL
1. Title Page – List the RFP subject, the name of the firm, the local address, telephone
number, name of the contact person and date.
2. Table of Contents – Include a clear identification of the material included in the
proposal by page number.
3. Introduction/Transmittal Letter (1 page max)
A transmittal letter must accompany the RFP submission. The purposes of this letter
are to transmit the proposal, acknowledge receipt of any addenda and to allow the firm
an opportunity to indicate their ability to provide the services requested. The letter
must contain the following information about the primary firm and any subconsultants
or partner firms:
• Primary Point-of-Contact Name
• Primary Project Lead Name (if different from above)
• Primary Contact Address
• Primary Contact Phone, Fax and Email
• Company Internet Address
• Name(s) of the person(s) who will be authorized to make representation for your
firm, their title, phone number and email address.
• Authorized signature confirming the proposal will remain open and valid for at least
180 days from the date set as the deadline for receipt of proposals.
4. Profile of Proposer (2 pages max)
Provide information on firm history, office location(s), and years providing
governmental audit services. State whether your firm is local, national or international
in size. Give the location of the office from which the work is to be done, and the
number of partners, managers, supervisors, seniors, and other professional staff
employed at the office. Briefly describe the range of activities performed by the local
office such as auditing, accounting, tax services, and management advisory services.
5. Summary of the Firm’s Qualifications (5 pages max plus reports)
Provide details as to the capability of your firm to provide governmental accounting and
auditing services.
The firm shall provide a list of the most significant audits of counties or other
governmental agencies of similar size to the County of Franklin that they have
performed, with special emphasis on experience with other Pennsylvania counties.
Provide at least three (3) references, including organization name, principal client
contact person along with the telephone number and email address of that person.
The firm shall indicate whether or not it is a member of AICPA’s Governmental Audit
Quality Center and the extent of its involvement.
The firm is also required to submit a copy of the most recent peer review report, with a
statement whether that quality control review included a review of specific government
engagements. The firm must also include, if applicable, any letter of comment as well
as a description of corrective actions taken.
The firm shall provide information on the circumstances and status of any disciplinary
action taken or pending against the firm during the past three (3) years with state
regulatory bodies or professional organizations and information regarding any adverse
litigation.
The firm shall indicate if it has been suspended or debarred by the Commonwealth of
Pennsylvania or state affirmatively that it has not.
The firm shall provide an affirmative statement that it is independent of the County of
Franklin and the County’s component units as defined by generally accepted auditing
standards.
6. Engagement Team Qualifications and Experience (2 pages max)
Identify the principal supervisory and management staff, including engagement and
review partners, managers, other supervisors and specialists, who would be assigned
to the engagement. Identify the percentage of governmental audit hours anticipated to
be performed by personnel located in the office identified as the lead office for this
engagement.
Provide resumes and relevant governmental experience of each person, including CPA
licensure, and information on relevant continuing professional education for the past
three (3) years and membership in professional organizations relevant to the
performance of this audit.
7. Continuity of Assigned Personnel (2 pages max)
Identify the engagement partner, audit manager and in-charge auditor that would be
assigned to this contract and describe the anticipated tenure of each, as well as the
firm's approach to maintaining continuity of key personnel. The proposal should
discuss the circumstances under which key personnel may be replaced, the
procedures for notifying the County of staffing changes, the firm's historical turnover
rates for governmental audit personnel, and the extent to which the proposed
engagement team has previously worked together on governmental audit
engagements.
8. Methodology and Approach (3 pages max)
Describe your approach and methodology to the audit process. Include your
communication approach and proposed schedule (if different than in Section 3.03).
Identify any scheduling considerations that may affect the completion of the
engagement. Describe the breakdown of work that will be completed on site in Franklin
County versus remotely.
Provide information on how your firm will meet the requirements listed in 3.04,
Additional Services.
9. Proposed Engagement Letter and Contractual Exceptions
The County intends to utilize its standard professional services agreement for this
engagement. A copy of the County's proposed contract is included in Attachment D. A
Business Associate Agreement is also required and included in Attachment E.
Proposers shall identify any provisions of the County's proposed contract to which they
object or for which they anticipate requesting modification. Any exceptions, revisions,
or additions requested shall be clearly identified and explained within the proposal.
In addition, proposers shall provide a sample engagement letter and any standard
contract terms, conditions, or supplemental agreements that the firm customarily
utilizes for governmental audit engagements.
Submission of a sample engagement letter or standard contract documents shall not
be construed as acceptance by the County of such terms. The County reserves the
right to negotiate final contract and engagement letter provisions with the selected
firm.
Failure to identify requested exceptions during the proposal process may be
considered by the County during contract negotiations.
COST PROPOSAL
The cost proposal shall be presented using Attachment F – Schedule of Professional Fees
and Expenses and shall include:
1. Total All-Inclusive Fixed Price –
The dollar cost proposal shall contain all pricing information related to performing the
audit engagement as described in this Request for Proposal. The total all-inclusive
fixed price to be proposed will contain all direct and indirect costs including all out-of-
pocket expenses.
2. Rates by Partner, Specialist, Supervisory, and Staff Level Times Hours Anticipated for
Each
For the 2026 audit only, include a schedule of professional fees and expenses that
supports the total all-inclusive fixed price. Provide the estimated number of hours and
hourly rates by staff classification necessary to complete the engagement. Include the
estimated out-of-pocket costs and the resulting all-inclusive fixed fee for requested
work.
SECTION V - EVALUATION OF THE PROPOSALS & GENERAL SELECTION
PROCESS
Professional audit services are of significant importance to Franklin County, and relying
exclusively on price is not in the best interest of the County. Award of a contract shall be at
the sole discretion of Franklin County. Franklin County reserves the right to accept or reject
any or all submissions in whole or in part and to waive any irregularities in the proposal
process. Further, Franklin County reserves the right to enter into any contract deemed in
its best interest. The County reserves the right to reject any and all proposals and to waive
any and all irregularities.
All proposals will be evaluated for the completion of the required elements. If one of the
required elements is not submitted in the required format, the County may deem the
proposal nonresponsive.
Proposals will be evaluated by a committee consisting of representatives of Franklin
County and such other individuals as the County may designate. The evaluation committee
will review and score proposals based upon the criteria set forth below.
Criteria Weight
After scoring is complete, the evaluation committee will meet to discuss next steps in the
evaluation process and select proposals that they desire to continue to consider based on
the scoring as well as the discussions of the evaluation committee members. The County
reserves the right to conduct interviews and/or request additional information of all, some
or none of the offerors, as part of the evaluation and selection process.
The County reserves the right to contact any references provided or other organizations to
assess the quality of work performed and use this information as part of the evaluation and
scoring of the proposal.
After the completion of the evaluation process, a recommendation for award of the
contract will be made to the Board of Commissioners of the County Franklin based on the
proposal deemed to offer the best value to the County.
Proposers are advised to submit their best technical and cost proposals initially, as the
County reserves the right to make an award based solely upon the proposals received.
SECTION VI - CONTRACT PROVISIONS & INSURANCE REQUIREMENTS
6.01 CONTRACT PROVISIONS
After the County of Franklin makes its selection, it shall proceed to negotiate a contract at
a mutually agreeable price based upon a Scope of Work for the project. If the County is
unable to negotiate a satisfactory contract with the most highly qualified person or firm,
the County shall formally end negotiations with that person or firm and begin to negotiate
with the second most highly qualified person or firm. Negotiations shall continue in this
sequence until a contract is agreed upon.
The performance of this contract shall be in accordance with all Federal, State and local
laws as may be applicable. Any contract between the County of Franklin and the
consultant shall be subject to the rules and regulations of any agencies where funding is
being requested.
The contract between the County and the selected firm will include the following non-
negotiable contract provisions:
1. Indemnification of the County.
2. Non-Indemnification of the Contractor.
3. Forum Selection (Franklin County, PA Court of Common Pleas).
4. Choice of law (Commonwealth of Pennsylvania).
5. Prevailing party attorneys’ fees.
6. Termination for convenience/termination for cause by the County.
7. County ownership of the instruments of service/deliverables.
8. Work-for-Hire Transfer of Copyrights/Intellectual Property.
9. All data is the property of the County of Franklin. The contract must
include express provisions guaranteeing County ownership of all data and
guaranteeing that the data may be accessed post-contract using non-
proprietary means. No mining, analytics, or duplication is allowed without
the County’s express written permission.
10. Data security, confidentiality, and use of County data and information.
11. Nondiscrimination.
12. Suspension and debarment.
13. Release of liability in favor of the County.
14. Non-release of liability of the contractor.
15. Insurance coverage and County’s status as additional insured as set forth in
Section 6.02.
16. Terms of payment and invoicing, including 45-day payment period.
17. Any and all federal and state provisions required as a result of grant funding.
A separate “Data Sharing Agreement” will be signed by the selected consultant and
Franklin County during the Scope of Work process. Any work proposed and undertaken by
this RFP that requires the use, access, and sharing of County data shall be addressed via
the “Data Sharing Agreement” as compliant with current County of Franklin processes and
procedures.
The County reserves the right to request additional contract provisions as it deems
necessary in order to protect the best interest of the County.
6.02 INSURANCE
Prior to and during the performance of any services covered by this RFP, vendor shall
provide the County, upon execution of an agreement, in a form and manner reasonably
acceptable to the County Solicitor or Risk Manager, a certificate of insurance as evidence
that it has obtained and maintains in full force and effect during the term of this Agreement
the following types of insurance in the amounts described as follows:
i. General Liability insurance covering liability for death and bodily injury and
liabilities for loss of or damage to property with a combined single limit of not
less than One Million Dollars ($1,000,000) per occurrence and One Million
Dollars ($1,000,000) in the aggregate;
ii. Automobile Liability insurance combined single limit of not less than one
million dollars and zero cents ($1,000,000.00) for any automobile.
iii. Worker’s Compensation and Employer’s Liability insurance as required by
the laws of the Commonwealth of Pennsylvania;
iv. Employee Dishonesty coverage at a minimum limit of $25,000;
v. Professional Liability insurance of not less than One Million Dollars
($1,000,000) per occurrence; and
vi. Cyber Liability insurance of not less than One Million Dollars ($1,000,000)
per occurrence and Two Million Dollars ($2,000,000) aggregate.
The County shall be endorsed as additional insured on General Liability Insurance for
services and activities provided by the vendor under this agreement. Vendor shall provide
proof of insurance and the requirements of this section upon execution of this agreement
as requested after that. Should the vendor have any changes to their current insurance
coverage, they shall notify the County within five business days.
SECTION VII - GENERAL LEGAL INFORMATION
7.01 RIGHT OF REJECTION
Franklin County reserves the right to cancel this request for proposals at any time for any
reason. Any proposal received may be rejected in whole or in part when in the best interest
of the County.
7.02 VENDOR CLEARANCE
All vendors will be required to submit a W-9 and pass clearance checks including a
debarment check and other background checks as deemed necessary by Franklin County.
7.03 COUNTY NOT RESPONSIBLE FOR PREPARATION COSTS
The County will not pay any cost associated with the preparation, submittal, presentation,
or evaluation of any proposal.
7.04 DISCLOSURE OF PROPOSAL CONTENTS
All responses are subject to the Pennsylvania Right to Know Law, 65 P.S. §§ 67.101-3104,
(“RTKL” or Right to Know Law”), which may mandate the release of any and all information
and documents submitted by the proposer. By submitting a proposal, all proposers
acknowledge the County’s non-waivable duties under the Right to Know Law and agree to
cooperate therewith.
Any confidential or proprietary information should be marked accordingly. Additionally,
any confidential information submitted by the vendor must be easily separable from the
non-confidential sections of the proposal and as such must be submitted in a separate
PDF document from the main proposal and labeled similarly to as described above
including the word “Confidential” in the file name. Notwithstanding the foregoing, all
proposals, documents, submissions and data are subject to the Pennsylvania Right to
Know Law.
Any exceptions taken to such mandatory terms may result in rejection of the proposal. Any
exceptions to the terms and conditions must be set forth in writing, with reasons for such
objection, and alternate language suggested, or is otherwise waived.
ATTACHMENT D
COUNTY OF FRANKLIN SERVICE AGREEMENT
THIS AGREEMENT made and entered into this day of , 20__, by and between the COUNTY OF FRANKLIN, a fourth class county organized and existing under the laws of the Commonwealth of Pennsylvania, with a principal address of 272 North Second Street, Chambersburg, Pennsylvania,
17201(hereinafter the “COUNTY”) and
., a corporation organized and existing under the laws of
the Commonwealth of Pennsylvania (hereinafter “CONTRACTOR”) with a principal address of .
WHEREAS, the COUNTY requires annual financial and compliance audit services (hereinafter “SERVICES”); and
WHEREAS, CONTRACTOR has presented an acceptable proposal to COUNTY and is
desirous of providing the services to the COUNTY in accordance with the terms and conditions of this SERVICE AGREEMENT (hereinafter “AGREEMENT”); and
WHEREAS, the Board of Commissioners of Franklin County by majority vote
at a regularly scheduled meeting, approved CONTRACTOR to provide the
SERVICES.
NOW THEREFORE, in consideration of the foregoing, the Parties hereto agree as follows:
1. RECITALS
The above recitals are incorporated herein by reference thereto and made a
part of this AGREEMENT.
2. TERM
The term of this AGREEMENT shall commence upon execution on and shall remain in effect until completion of the 2028 financial statement and compliance
audit services or December 31, 2029, whichever comes later. There shall be an
option to extend the contract term for up to two (2) additional one (1) year periods. The COUNTY shall exercise this option by notifying the Contractor in writing within thirty (30) days of the expiration of the then-current term.
3. INCORPORATION OF PROPOSAL
The CONTRACTOR shall supply all work and comply with all requirements of its Proposal RFP 2026131-02 dated (“the PROPOSAL”) marked as Exhibit A and incorporated as though set forth fully herein. To the extent that any terms of
the PROPOSAL conflict with the terms of the AGREEMENT, the AGREEMENT shall bind the Parties, unless otherwise mutually agreed in writing.
4. SCOPE OF SERVICES
The CONTRACTOR’s responsibility under this AGREEMENT is to provide SERVICES as set forth in the PROPOSAL. See Exhibit A.
5. COUNTY RESPONSIBILITIES
COUNTY shall provide all information and approvals required by CONTRACTOR
in a manner that is timely and that will not unnecessarily delay the approval process.
6. GENERAL STANDARDS
The CONTRACTOR shall perform all SERVICES in accordance with the
generally accepted standards and practices used in the profession. The
CONTRACTOR shall render diligently and competently all SERVICES, with due consideration given to applicable laws and regulations. The enumeration of specific duties and obligations to be performed by the CONTRACTOR hereunder shall not be construed to limit the general ethical requirements in the
undertakings of the CONTRACTOR.
7. INFORMATION / ASSISTANCE PROVIDED BY COUNTY
COUNTY will provide the following information and assistance to the CONTRACTOR:
A. The COUNTY will designate a person to act as its representative with
respect to the SERVICES to be rendered under this AGREEMENT. Such
person shall have complete authority to transmit instructions and receive information pertaining to CONTRACTOR’s SERVICES.
8. SCHEDULE / TIME FOR PERFORMANCE OF SERVICES
CONTRACTOR and the COUNTY shall mutually establish the schedule of
SERVICES to meet the requirements of RFP 2026131-02.
9. TERMS OF PAYMENT TO CONTRACTOR
A. The COUNTY shall pay the CONTRACTOR as set forth in Exhibit A, which is attached and incorporated by reference as through set forth fully herein.
B. Invoices are due upon presentation and shall be considered past-due if not paid within forty-five (45) days of the invoice date.
C. If the COUNTY objects to any portion of an invoice, the COUNTY shall so
notify the CONTRACTOR in writing within twenty (20) days of receipt of the invoice. The COUNTY shall identify the specific cause of the disagreement and shall pay when due that portion of the invoice not in dispute. Interest as stated above shall be paid by the COUNTY on all disputed invoiced
amounts resolved in the CONTRACTOR’s favor and unpaid for more than
forty-five (45) days after date of the notice of the dispute.
D. COUNTY reserves the right to withhold payments for costs determined not eligible for reimbursement.
10. INDEPENDENT CONTRACTORS
Any SERVICES provided by the CONTRACTOR or its consultants under this
AGREEMENT are provided as independent contractors. Nothing in this
AGREEMENT shall be considered to create the relationship of employer and employee between the Parties. All persons engaged in any of the SERVICES performed pursuant to this AGREEMENT shall at all times and places be subject to the CONTRACTOR’s sole direction, supervision, and control. The
CONTRACTOR shall exercise control over the means and manner in which it, its employees, and consultants perform the SERVICES. The CONTRACTOR does not have the power or authority to bind the COUNTY in any promise, agreement, or representation unless expressly provided written agreement to do so.
11. AUTHORITY TO PRACTICE / LICENSES
The CONTRACTOR hereby represents and warrants that it has and will continue
to maintain all licenses and approvals required to conduct its business and to provide the SERVICES as required pursuant to this AGREEMENT.
12. TERMINATION
A. The COUNTY shall have the right to terminate this AGREEMENT at any
time and for any reason, which termination shall be effective upon the
COUNTY providing written notice to the CONTRACTOR. In the event that the COUNTY elects to terminate this AGREEMENT prior to CONTRACTOR’s performance of the SERVICES required hereunder the CONTRACTOR shall be compensated for all SERVICES satisfactorily
completed in an amount proportionate to services actually provided by
CONTRACTOR.
B. The CONTRACTOR shall have the right to terminate this AGREEMENT in the event of substantial failure of COUNTY to perform in accordance with the
terms hereof through no fault of the CONTRACTOR. As a condition precedent to the CONTRACTOR’s ability to terminate the AGREEMENT, the CONTRACTOR shall have provided the COUNTY with written notice of the
delinquency and provided the COUNTY with sixty (60) days in which to cure the delinquency. If the CONTRACTOR terminates the AGREEMENT after meeting all conditions precedent, the CONTRACTOR shall be compensated for all SERVICES satisfactorily completed in an amount proportionate to the
SERVICES actually provided by CONTRACTOR.
13. INDEMNIFICATION
A. The CONTRACTOR and its consultants shall release, hold harmless, and indemnify the COUNTY, if officers, elected officials, agents, representatives, and employees acting within the scope of their official duties from and against damages, costs, and expenses (including reasonable attorneys’ fees) to the
extent caused by the negligent acts, errors, or omissions of the CONTRACTOR, its employees, consultants, agents, servants, and/or anyone acting under the CONTRACTOR’s control and/or the CONTRACTOR’s direction, in the performance of the requirements of this AGREEMENT. The
CONTRACTOR shall defend any lawsuit commenced against the COUNTY
and shall pay any judgments and costs connected with such proceedings which are based upon the negligent acts or omissions of the CONTRACTOR or its consultants.
14. INSURANCE
Prior to and during the performance of any SERVICES covered by this
AGREEMENT, CONTRACTOR shall provide the COUNTY in a form reasonably
acceptable to the Risk Manager and County Solicitor, evidence that it has obtained and maintains in full force and effect during the term of this AGREEMENT the types of insurance and amounts described as follows:
i. General Liability insurance covering liability for death and bodily injury and
liabilities for loss of or damage to property with a combined single limit of
not less than One Million Dollars ($1,000,000) per occurrence and One
Million Dollars ($1,000,000) in the aggregate;
ii. Automobile Liability insurance combined single limit of not less than one
million dollars and zero cents ($1,000,000.00) for any automobile.
iii. Worker’s Compensation and Employer’s Liability insurance as required by
the laws of the Commonwealth of Pennsylvania;
iv. Employee Dishonesty coverage at a minimum limit of $25,000;
v. Professional Liability insurance of not less than One Million Dollars
($1,000,000) per occurrence; and
vi. Cyber Liability insurance of not less than One Million Dollars ($1,000,000)
per occurrence and Two Million Dollars ($2,000,000) aggregate.
The COUNTY shall be provided thirty (30) days advance written notice of any cancellation of the required insurances.
15. FORCE MAJEURE
The COUNTY, and the CONTRACTOR shall not be held responsible for any
delay, default, or nonperformance directly caused by an act of God, unforeseen
adverse weather events, accident, labor strike, fire, explosion, riot, war, rebellion, terrorist activity, sabotage, flood, epidemic, act of federal or state government, labor, material, equipment, or supply shortage.
16. REMEDIES
No remedy herein conferred upon any party is exclusive of any other remedy,
and each and every remedy shall be cumulative and shall be in addition to every
other remedy given hereunder or provided by law, equity, statute, or otherwise. No single or partial exercise by any party of any right, power, or remedy hereunder shall preclude any other exercise or further exercise thereof.
17. ENFORCEMENT COSTS, CHOICE OF LAW AND FORUM SELECTION
If an action at law or in equity is necessary to enforce or interpret the terms of
this Agreement, the prevailing party shall be entitled to recover, in addition to any other relief, reasonable attorney's fees, costs and disbursements.
The parties agree that this Agreement shall be governed by the laws of the Commonwealth of Pennsylvania. All claims shall be filed in and heard by the
Court of Common Pleas for the Thirty-Ninth Judicial District of Pennsylvania Franklin County Branch, which shall have exclusive jurisdiction thereunder.
18. NOTICES
Any notices required to be given in accordance with this AGREEMENT shall be in writing and delivered to the Parties by certified mail or personal delivery or
acceptable overnight courier service. Notice that is mailed shall be sent to the following addresses:
If to the COUNTY:
With Copy to:
Franklin County Solicitor Administration Building
272 N. Second St. Chambersburg, PA 17201
If to the CONTRACTOR:
19. NON-DISCRIMINATION
The CONTRACTOR shall not discriminate against any employee, applicant for
employment, or any person seeking the SERVICES of the CONTRACTOR to be
provided under this AGREEMENT on the basis of race, color, religion, creed, sex, age, national origin, marital status, or presence of any sensory, mental, or physical handicap.
20. ASSIGNMENT
This AGREEMENT (including, without limitation, any rights under or interest in
this AGREEMENT) shall not be assigned by either party without the express
written consent of the other party hereto. The provisions of this Section shall survive the completion or termination of this AGREEMENT for any reason and shall remain enforceable between the Parties.
21. ENTIRE AGREEMENT / AMENDMENTS
This AGREEMENT contains the entire AGREEMENT between the Parties and
no other agreements, oral or otherwise, regarding the subject matter of this AGREEMENT, shall be deemed to exist or bind any of the Parties. This AGREEMENT cannot be modified, except by a written document signed by the Parties hereto. Board of Commissioners’ approval at a public meeting shall be
required to amend this AGREEMENT unless otherwise delegated to its designees.
22. SEVERABILITY
If any term, provision, covenant, or condition of this AGREEMENT is held by a court of competitive jurisdiction to be invalid, void or unenforceable, the
remainder of the provisions hereof shall remain in full force and effect and shall in no way be affected, impaired, or invalidated as a result of such decision.
23. CAPTIONS
The captions used herein are for convenience only and are not a part of this
AGREEMENT and do not in any way limit or amplify the terms and provisions hereof.
24. NO OFFER
This AGREEMENT does not constitute an offer and shall not be binding on the
Parties unless and until executed by both Parties.
25. USE OF HEADINGS
The use of headings within this AGREEMENT are for ease of reference and convenience only and shall not be used or construed to limit or enlarge the interpretation of the language hereof or the enforcement of this AGREEMENT.
26. EFFECTIVE DATE
As used herein, the “Effective Date” shall mean the later of the COUNTY
execution date and the CONTRACTOR execution date, each of which is set forth on the signature page hereof. OR As used herein, the "Effective Date" shall mean _____________, 20___.
IN WITNESS WHEREOF, the Parties have caused this AGREEMENT to be executed on the dates written below. OR IN WITNESS WHEREOF, the
County of Franklin, Pennsylvania have caused these presents to be executed, and its corporate seal affixed thereto and the Contractor has caused these presents to be executed in a like manner the days and year above written.
ATTEST: CONTRACTOR
_________________________________ ___________________________
(SEAL) BY: _________________
TITLE: _____________________
ATTEST: COUNTY OF FRANKLIN
(SEAL),
Carrie E. Gray Dean A. Horst County Administrator/ Chief Clerk Chairperson, Board of Commissioners
John T. Flannery, Commissioner
Robert G. Ziobrowski, Commissioner
ATTACHMENT E
Page 1 of 16 Revised: November 4, 2022
Business Associate Agreement
This Business Associate Agreement (this “Agreement”) is entered into by [BUSINESS
ASSOCIATE] (“Business Associate” and Franklin County, Pennsylvania (“Covered Entity”),
individually referred to as “Party” and collectively as the “Parties.” This Agreement is effective
as of [DATE] (“Effective Date”).
RECITALS
WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and
Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative
Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in
Article 1 of this Agreement, and with the applicable provisions of the Health Information
Technology for Economic and Clinical Health Act of 2009 (“HITECH”).
WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to
Covered Entity pursuant to the Services Agreement, as defined below.
WHEREAS, Business Associate is a business associate under HIPAA. Business Associate
must comply with the provisions of the Privacy Rule and Security Rule made applicable to
business associates pursuant to HITECH and with all other applicable provisions of HITECH.
WHEREAS, Covered Entity is not permitted to allow Business Associate to create,
receive, maintain, or transmit Protected Health Information on behalf of Covered Entity
without satisfactory assurances that Business Associate will appropriately safeguard the
information. Therefore, Covered Entity will only disclose Protected Health Information to
Business Associate or allow Business Associate to create or receive Protected Health
Information on behalf of Covered Entity in accordance with the requirements of HIPAA,
HITECH, and provisions of this Agreement.
NOW, THEREFORE, in consideration of the mutual promises below and for other good
and valuable consideration, the receipt and adequacy of which are hereby acknowledged, the
Parties agree as follows:
ARTICLE I
DEFINITIONS
Terms used in this Agreement that are specifically defined in HIPAA shall have the same
meaning as set forth in HIPAA. A change to HIPAA which modifies any defined
Page 2 of 16 Revised: November 4, 2022
HIPAA term, or which alters the regulatory citation for the definition shall be deemed
incorporated into this Agreement.
1.1 Breach means the unauthorized acquisition, access, use, or disclosure of
Protected Health Information which compromises the security or privacy of such
information, except where an unauthorized person to whom such information is
disclosed would not reasonably have been able to retain such information. The term
“breach” does not include the exceptions described in 42 U.S.C. § 17921(1)(B)
summarized below.
(a) Certain uses or disclosures by a Covered Entity’s work-force
members (defined as persons acting under the authority of the
Covered Entity or Business Associate), if the use or disclosure was
made in good faith, was within the scope of the disclosing individual’s
authority, and does not result in a further violation of the Privacy Rule.
(b) Inadvertent disclosures from one person who is authorized to access
PHI to another person who is also authorized to access PHI within the
same Covered Entity, Business Associate, or organized health care
arrangement when the disclosed PHI is not further used or disclosed
in a manner not permitted under the Privacy Rule.
(c) A disclosure of PHI when a Covered Entity or Business Associate
has a good faith belief that an unauthorized person to whom the
disclosure was made would not reasonably have been able to
retain such information.
1.2 Designated Record Set, as defined under the Privacy Rule at 45 C.F.R.
§ 164.501, means a group of records maintained by or for a Covered Entity that are:
(a) the medical records and billing records about individuals
maintained by or for a covered health care provider;
(b) the enrollment, payment, claims adjudication, and case or medical
management record systems maintained by or for a health care
plan; or
(c) used, in whole or in part, by or for the Covered Entity to make
decisions about individuals.
For purposes of this section, a “Record” is any item, collection, or grouping of information that
includes PHI and is maintained, collected, used, or disseminated by or for a Covered Entity.
Page 3 of 16 Revised: November 4, 2022
1.3 Electronic Health Record has the same meaning that applies under
Section 13400(5) of ARRA and currently means an electronic record of health-related
information on an individual that is created, gathered, managed, and consulted by
authorized staff.
1.4 Electronic Protected Health Information (EPHI), as defined by 45 C.F.R.
§ 160.103, means individually identifiable health information that is transmitted by electronic
media, or maintained in electronic media, but not certain education and employment records
described in 45 C.F.R. § 160.103, the definition of Protected Health Information. EPHI also
includes any EPHI provided by Covered Entity or created or received by Business Associate on
behalf of Covered Entity.
1.5 HHS means the U.S. Department of Health and Human Services.
1.6 Individual, as defined by 45 C.F.R § 160.103, means the person who is the
subject of PHI. It also includes a person who qualifies as a Personal Representative in
accordance with 45 C.F.R. § 164.502(g).
1.7 Limited Data Set, as defined by 45 C.F.R. §164.514(e) is partially de-
identified data that may be used or disclosed for research, public health and health care
operation purposes, such as quality assurance, as long as a recipient signs a data use
agreement that complies with HIPAA requirements.
1.8 Privacy Rule means the Standards for Privacy of individually Identifiable
Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart E, any other applicable
provision of HIPAA, and any amendments to HIPAA, including HITECH.
1.9 Protected Health Information (PHI) as defined by 45 C.F.R. § 164.103,
mean individually identifiable health information that is:
(a) transmitted by electronic media;
(b) maintained in electronic media; or
(c) transmitted or maintained in any other form or medium;
PHI does not include certain education and employment records described in 45 C.F.R.
§ 160.103, the definition of PHI. PHI includes, without limitation, any PHI provided by Covered
Entity or created or received by Business Associate on behalf of Covered Entity. Unless
otherwise stated in this Agreement, any provision, restriction, or obligation in this Agreement
related to the use of PHI shall apply equally to EPHI.
Page 4 of 16 Revised: November 4, 2022
1.10 Required By Law, as defined by 45 C.F.R. § 164.103, means a mandate
contained in law that compels an entity to make a use or disclosure of PHI and that is
enforceable in a court of law; and any additional requirements created under HITECH.
1.11 Secretary means the Secretary of the Department of Health and Human
Services or his/her designee.
1.12 Security Incident, as defined by 45 C.F.R. § 164.304, means the
attempted or successful unauthorized access, use, disclosure, modification, or
destruction of information or interference with system operations in an information
system.
1.13 Security Rule means the Security Standards for the Protection of
Electronic Protected Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart C,
any other applicable provision of HIPAA, and any amendments to HIPAA, including
HITECH.
1.14 Services Agreement means the underlying agreement(s) that outline the
terms of the services that Business Associate agrees to provide to Covered Entity and that
fall within the functions, activities or services described in the definition of Business
Associate at 45 C.F.R. § 160.103.
1.15 Unsecured PHI shall mean PHI that is not rendered unusable, unreadable, or
indecipherable to unauthorized individuals through the use of a technology or
methodology specified by the Secretary of HHS, such as encryption in compliance with the
National Institute of Standards and Technology standards or destruction.
ARTICLE II
BUSINESS ASSOCIATE OBLIGATIONS
2.1 Request, Use and Disclosure of PHI. Business Associate agrees that it will
only request, use and disclose PHI in accordance with the terms of this Agreement, and as
is Required by Law. Business Associate acknowledges that it may only request, use and
disclose PHI obtained or created pursuant to this Agreement with Covered Entity if the
request, use or disclosure is in compliance with each applicable requirement of the Privacy
Rule found in 45 C.F.R. § 164.504(e).
2.2 Permitted Requests, Uses and Disclosures. Business Associate will not
request, use or disclose PHI except for the purpose of performing Business Associate’s
obligations to Covered Entity as described in the Services Agreement, consistent with the
requirements of HIPAA and this Agreement, and for other uses and disclosures permitted
under this Agreement. Business Associate may request, use or disclose PHI only if such
request, use or disclosure does not violate the Privacy Rule or this
Page 5 of 16 Revised: November 4, 2022
Agreement. To the extent Business Associate is to carry out any of Covered Entity’s obligations
under the Privacy Rule, Business Associate will comply with the requirements of the Privacy
Rule that apply to Covered Entity in the performance of the applicable obligations.
In accordance with the provisions of 45 C.F.R. § 164.504(e)(4), Business Associate
also may request, use or disclose PHI, if necessary:
(a) for the proper management and administration of Business
Associate’s organization, or
(b) to carry out the legal responsibilities of Business Associate.
Business Associate may only disclose PHI for these purposes, in accordance with
the provisions of 45 C.F.R. § 164.504(e)(4)(ii), if either
(i) the disclosure is Required By Law, or
(ii) Business Associate obtains reasonable written assurances
from the person to whom Business Associate discloses the
PHI that the PHI will be held confidentially and used or
further disclosed only as Required By Law or for the
purposes for which it was disclosed to the person and that
the person agrees to notify Business Associate of any
instances of which it is aware in which the confidentiality of
the information has been breached.
2.3 Prohibited Requests, Use and Disclosures. Business Associate will not
request, use or disclose PHI in any manner that constitutes a violation of the Privacy
Rule, this Agreement, or the Services Agreement.
2.4 Minimum Requirements. Business Associate will only request, use and
disclose the minimum amount of PHI necessary for Business Associate to perform the
services for which it has been retained by Covered Entity, in accordance with 42 U.S.C.
§ 17935(b). Business Associate agrees to comply with the Secretary’s guidance on what
constitutes minimum necessary.
2.5 Administrative, Physical and Technical Safeguards. Business Associate will
develop, implement, maintain, and use appropriate safeguards to prevent any use or
disclosure of the PHI other than as provided by this Agreement. Business Associate will
implement administrative, physical, and technical safeguards that reasonably and
appropriately protect the confidentiality, integrity and availability of EPHI. Business
Associate acknowledges that the Security Rule provisions regarding administrative,
physical, and technical safeguards, policies and procedures and documentation
Page 6 of 16 Revised: November 4, 2022
requirements found in 45 C.F.R. §§ 164.308, 164.310, 164.312 and 164.316 apply to Business
Associate in the same manner as to Covered Entity and Business Associate will fully comply with
such Security Rule provisions.
2.6 Unusable, Unreadable or Indecipherable Technology. Business Associate
will, to the extent feasible, adopt a technology or methodology specified by the Secretary
pursuant to 42 U.S.C. § 17932(h) that renders PHI unusable, unreadable, or indecipherable
to unauthorized individuals.
2.7 Agents and Sub-contractors. Prior to making any permitted disclosures,
Business Associate will ensure that any of its agents, including subcontractors, to whom it
provides PHI received from, or created or received by, Business Associate on behalf of
Covered Entity agree in writing to be bound by the same privacy and security restrictions
and conditions that apply to Business Associate under this Agreement, including but not
limited to those conditions relating to termination of the contract for improper disclosure.
Further, Business Associate shall implement and maintain sanctions against agents and
subcontractors, if any, that violate such restrictions and conditions. Business Associate
shall terminate any agreement with an agent or subcontractor, if any, who fails to abide by
such restrictions and obligations. Business Associate shall not provide any PHI to any
third party or subcontract any services described in the Services Agreement without
Covered Entity’s express written permission.
2.8 Reporting Obligations. Business Associate will report, in writing, to Covered
Entity any use or disclosure of PHI that is not authorized by this Agreement, including
Breaches of Unsecured PHI. In addition, Business Associate will report in writing, to
Covered Entity any Security Incident of which it becomes aware that it, its employees, or
its agents or subcontractors experience involving or potentially involving Covered Entity
EPHI. The written notice shall be provided to Covered Entity within five (5) business days
of becoming aware of the non-authorized use or disclosure or Security Incident.
2.9 Notification to Covered Entity of Breach of Unsecured PHI. Business
Associate will provide written notification to Covered Entity within seventy-two (72) hours
of discovering a Breach of Unsecured PHI. Such notification will identify, to the extent
possible, (1) each individual whose Unsecured Protected Health Information has been, or
is reasonably believed by Business Associate to have been, accessed, acquired or
disclosed during the Breach, (2) the nature of the non-permitted access, use or disclosure,
including the date of the Breach and the date of discovery of the Breach; (3) Protected
Health Information accessed, used or disclosed as part of the Breach (e.g., full name,
social security number, date of birth, etc.); (4) who or what area of Business Associate’s
operation made the non-permitted access, use or disclosure and who received the non-
permitted disclosure; (5) identify what corrective action the Business Associate took or
will take to prevent further non-permitted accesses, uses or
Page 7 of 16 Revised: November 4, 2022
disclosures; (6) identify what Business Associate did or will do to mitigate any deleterious effect
of the non-permitted access, use or disclosure; and (7) provide such other information that is
reasonably available to Business Associate that Covered Entity may request. For purposes of
the preceding sentence, Business Associate will be treated as discovering the Breach on the first
day on which the Breach is known (or by exercising reasonable diligence should have been
known) to Business Associate (including any employee, officer or other agent of Business
Associate other than the person committing the Breach). Whether a Breach has occurred will
be determined in accordance with applicable regulations or other authoritative guidance issued
pursuant to the HITECH Act. A delay in notification of a Breach that qualifies as a “law
enforcement delay” under 45 CFR Section 164.412 will not be treated as a violation of this
Agreement. Business Associate will supplement its initial notification to Covered Entity with
additional information as any additional information becomes available. Business Associate will
implement a reasonable system for discovery of Breaches.
2.10 Breach Notification Expenses. Business Associate agrees to indemnify,
defend, and hold harmless Covered Entity and its employees, agents, and representatives
from any and all direct, reasonable and actual costs, settlements, judgments, and
expenses incurred by Covered Entity caused by a Breach of Unsecured Protected Health
Information while in the possession of Business Associate, or its employees,
subcontractors or agents. Such costs will include those related to Breach notifications
sent to the affected individuals and the media, as required by Section 13402(e) of ARRA
and 45 CFR Part 164, and any costs incurred by Covered Entity or its employees, agents or
representatives to mitigate potential harm to individuals from the Breach.
2.11 Notification to Covered Entity of Use or Disclosure Data. Business
Associate will notify Covered Entity in writing of any actual or suspected use or
disclosure of data in violation of any applicable federal or state laws or regulations or
any legal action against Business Associate arising from an alleged HIPAA violation.
Business Associate shall take:
(i) prompt action to correct any such deficiencies; and
(ii) any action pertaining to such unauthorized disclosure
required by applicable federal and state laws and
regulations.
Business Associate will provide the written notice to Covered Entity within five
(5) business days of becoming aware of the violation or legal action.
2.12 Mitigation of Harmful Effect. Business Associate agrees to mitigate, to the
extent practicable, any harmful effect that is known to Business Associate of a use or
Page 8 of 16 Revised: November 4, 2022
disclosure of PHI by Business Associate in violation of the requirements of this Agreement.
2.13 Designated Record Sets. Business Associate will make PHI in Designated
Record Sets that are maintained by Business Associate or its agents or subcontractors, if
any, available to Covered Entity or to an individual for inspection and copying within ten
(10) business days of a request by Covered Entity to enable Covered Entity to fulfill its
obligations under the Privacy Rule, including, but not limited to the requirements
concerning access to individuals to PHI found at 45 C.F.R. § 164.524. If Business
Associate maintains Protected Health information in the form of an Electronic Health
Record for any individual, Business Associate agrees to provide, at the request of Covered
Entity or an individual, and in the time and manner designated by Covered Entity, a copy of
such information in an electronic format to that individual or, if clearly, conspicuously and
specifically directed by the individual (or by Covered Entity based on a clear, conspicuous
and specific request of the individual) to transmit an electronic copy of that information
directly to an entity or person designated by the individual. Any fee charged to the
individual for providing such information (or a summary or explanation of such
information) may not exceed Business Associate’s labor costs incurred in responding to
the individual’s request.
2.14 Amendments to PHI and EPHI. Within ten (10) business days of receipt of a
request from Covered Entity for an amendment of PHI or a record about an individual
contained in a Designated Record Set, Business Associate or its agents or subcontractors,
if any, shall make such PHI available to Covered Entity for amendment and shall
incorporate any such amendment to enable Covered Entity to fulfill its obligations under
the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.526. If an individual requests
an amendment of PHI directly from Business Associate or its agents or subcontractors, if
any, Business Associate must notify Covered Entity in writing within five (5) business days
of the request. Any denial of amendment of PHI maintained by Business Associate or its
agents or subcontractors, if any, shall be the responsibility of Covered Entity. Upon the
approval of Covered Entity, Business Associate shall appropriately amend the PHI
maintained by it, or any agents or subcontractors.
2.15 Accounting of PHI and EPHI. Within ten (10) business days of notice by
Covered Entity of a request for an accounting of disclosures of PHI, Business Associate
and any agents or subcontractors shall make available to Covered Entity the information
required to provide an accounting of disclosures to enable Covered Entity to fulfill its
obligations under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.528 and
any additional information required under the HITECH Act, including Section 13405(c) if
Business Associate maintains information in the form of an Electronic Health Record, and
any implementing regulations.
Page 9 of 16 Revised: November 4, 2022
(a) If a request for an accounting is made directly to Business Associate
or its agents or subcontractors, Business Associate will notify
Covered Entity of the request within five (5) business days of having
received the request. Covered Entity shall either inform Business
Associate to provide the requested information directly to the
individual or request Business Associate to immediately forward the
information to the Covered Entity for compilation and distribution to
the individual.
(b) In the case of a direct request for an accounting from an individual
related to treatment, payment or health care operations disclosures
through Electronic Health Records, Business Associate will provide
the accounting to the individual in accordance with 42 U.S.C.
§ 17935(c) and any regulations adopted subsequent to this Agreement.
Business Associate will confirm with Covered Entity that Covered Entity
provided Business Associate’s name to the individual in response to a
request for an accounting before providing the requested accounting to
the individual.
2.16 Retention of Accounting Documentation. Notwithstanding termination of
this Agreement, Business Associate and any of its agents or subcontractors shall
continue to maintain the information required for purposes of complying with this
Section 2.14 for a period of six (6) years after termination of the Agreement.
2.17 Business Associate’s Compliance with HHS. Business Associate will make
its internal practices, books and records relating to the use and disclosure of PHI available
to the Secretary of HHS in the time and manner designated by the Covered Entity or the
Secretary of HHS for purposes of determining Covered Entity’s compliance with the
Privacy Rule. Business Associate will notify Covered Entity regarding any PHI that
Business Associate provides to the Secretary of HHS concurrently with providing the
requested PHI to the Secretary of HHS. Upon request by Covered Entity, Business
Associate will provide Covered Entity with a duplicate copy of the requested PHI.
2.18 Inspection by Covered Entity. Within five (5) business days of a written
request by Covered Entity, Business Associate and its agents or subcontractors, if any,
shall allow Covered Entity to conduct a reasonable inspection of the facilities, systems,
books, records, agreements, policies and procedures relating to the use or disclosure of
PHI pursuant to this Agreement for the purpose of determining whether Business
Associate has complied with this Agreement, the Security Rule and provisions of the
Privacy Rule directly applicable to Business Associate or as deemed necessary by
Covered Entity to determine whether a Breach has occurred. Both Parties agree to the
following:
Page 10 of 16 Revised: November 4, 2022
(a) Business Associate will cooperate with Covered Entity’s risk
assessment without unreasonable delay;
(b) Business Associate and Covered Entity will mutually agree in
advance upon the scope, location and timing of such an inspection;
and
(c) Covered Entity will protect the confidentiality of all confidential and
proprietary information of Business Associate to which Covered
Entity has access during the course of such inspection.
2.19 Damages. Business Associate shall be responsible to compensate the
affected individual for any reasonable damages as a result of a Breach caused by
Business Associate.
2.20 No Ownership Rights. Business Associate agrees that Business
Associate does not and will not have any ownership rights in any of the PHI.
2.21 Additional HITECH Requirements. The additional requirements of Title
XIII of HITECH that relate to privacy and security and that are made applicable with
respect to covered entities are also applicable to Business Associate and by this
reference these requirements are hereby incorporated into this Agreement.
2.22 Standard Transactions. In conducting any standard transaction that is
subject to the Standard Transaction Regulations (set forth in 45 C.F.R. Part 162) on behalf
of Covered Entity, Business Associate agrees to comply with all requirements of the
Standard Transaction Regulations that would apply to Covered Entity if Covered Entity
were conducting the transaction itself and shall require the same of any subcontractor or
agent involved with the conducts of such Standard Transactions.
2.23 Limitations on Marketing. Business Associate may not use and disclose PHI
for “marketing,” as defined in 45 C.F.R. § 164.501, unless expressly permitted to do so in
the Services Agreement.
2.24 Sale of PHI. Except for compensation set forth in the Services Agreement
between Business Associate and Covered Entity, Business Associate shall not receive any
direct or indirect remuneration in exchange for the provision of Protected Health
Information.
ARTICLE III
COVERED ENTITY OBLIGATIONS
Page 11 of 16 Revised: November 4, 2022
3.1 Risk Assessment of Breach by Covered Entity. Covered Entity shall make the
final determination of whether for a Breach of PHI occurred.
3.2 Restrictions. Covered Entity shall notify Business Associate of any
restriction to the use or disclosure of PHI that Covered Entity has agreed to or must
comply with in accordance with 45 C.F.R. § 164.522 and 42 U.S.C. § 17935(a).
3.3 Notification of Changes or Revocations of Permission. Covered Entity
shall provide Business Associate with notice of any changes to, revocation of, or
permission by individual to use or disclose PHI, if such changes affect Business
Associate’s permitted uses or disclosures, within a reasonable period of time after
Covered Entity becomes aware of such changes to or revocation of permission.
3.4 Permissible Requests by Covered Entity. Covered Entity shall not request
Business Associate to use or disclose PHI in any manner that would not be permissible
under the Privacy and Security Rules if done by Covered Entity.
ARTICLE IV
TERMINATION
4.1 Term and Survival. The term of this Agreement shall be effective as of the
Effective Date of this Agreement and continue until terminated by Covered Entity or any
underlying Services Agreement expires or is terminated. Any provision related to the use,
disclosure, access, or protection of PHI or EPHI or that by its terms shall survive
termination of this Agreement shall survive termination.
4.2 Termination for Breach. A material breach by Business Associate, or its
agents or subcontractors, if any, of this Agreement, as determined by Covered Entity,
shall constitute a material breach of the Services Agreement. As provided for under 45
C.F.R. §§ 164.314(a)(2)(i)(D) and 164.504(e)(2)(iii), the Covered Entity may immediately
terminate this Agreement and the Services Agreement or, alternatively, the Covered Entity may
choose to provide Business Associate with written notice of the material breach and an
opportunity to cure the material breach or end the violation within thirty (30) calendar days. If
Business Associate becomes aware of a material breach of this Agreement by Covered Entity,
Business Associate shall (1) provide an opportunity for Covered Entity to cure the breach or
end the violation and terminate this Agreement (and any applicable portion of the Services
Agreement between the parties) if Covered Entity does not cure the breach or end the violation
within thirty (30) calendar days, or (2) immediately terminate this Agreement (and any
applicable portion of the Services Agreement ) if Covered Entity has breached a material term
of this Agreement and cure is not possible.
Page 12 of 16 Revised: November 4, 2022
4.3 Termination for Violation by Business Associate. Covered Entity may terminate
this Agreement and the Services Agreement effective immediately, if (i) Business Associate is
named as a defendant in a criminal proceeding for a violation of HIPAA, HITECH, or other
security or privacy laws or (ii) there is a finding or stipulation that Business Associate has
violated any standard or requirement of HIPAA, HITECH, or other security or privacy laws in
any administrative or civil proceeding in which Business Associate is involved.
4.4 Return or Destruction of PHI.
(a) Upon termination of this Agreement for any reason, Business Associate
shall return or, at Covered Entity’s request, destroy all PHI received from
Covered Entity or created or received by Business Associate on behalf of
Covered Entity that Business Associate still maintains in any form. If
Business Associate destroys the PHI, Business Associate shall certify in
writing to Covered Entity that such PHI has been destroyed. This
provision applies to PHI that is in the possession of agents or
subcontractors of Business Associate. Business Associate will retain no
copies of the PHI.
(b) If Business Associate determines that returning or destroying the PHI is
not feasible, Business Associate shall explain to Covered Entity why
conditions make the return or destruction of the PHI not feasible. If
Covered Entity agrees that the return or destruction of PHI is not feasible,
Business Associate will retain the PHI, subject to all of the protections of
this Agreement, and limit further uses and disclosures of the PHI to those
purposes that make the return or destruction of the PHI infeasible for so
long as Business Associate maintains the PHI.
(c) If Business Associate determines that it is infeasible to obtain from an
agent or subcontractor any PHI in the possession of the agent or
subcontractor or to destroy the PHI, Business Associate will provide
Covered Entity written notification explaining why obtaining the PHI is
infeasible. If Covered Entity agrees that the return or destruction of PHI
is not feasible, Business Associate will require the agent or subcontractor
to extend the protections of this Agreement to the PHI and limit further
uses and disclosures of the PHI to those purposes that make the return or
destruction of the PHI infeasible for so long as the agent or subcontractor
maintains the PHI.
4.5 Termination of Services Agreement. If this Agreement is terminated for any
reason, Covered Entity will also terminate the Services Agreement between the
Page 13 of 16 Revised: November 4, 2022
Parties. This provision shall supersede any termination provision to the contrary which may be
set forth in the Services Agreement.
ARTICLE V
MISCELLANEOUS
5.1 Acknowledgement. By affixing their respective signatures below, the Parties
certify that they have read and understand each and every provision in this Agreement.
Each Party certifies that it possesses the authority to enter into the Agreement. The
execution and performance of this Agreement by each Party has been duly authorized by
all necessary laws, resolutions or corporate actions, and the Agreement constitutes valid
and enforceable obligations of each Party in accordance with its terms.
5.2 Amendment. This Agreement shall not be amended, altered, or modified,
except by an instrument in writing duly executed by the Parties to the Agreement.
5.3 Assignment. This Agreement may not be assigned by Business Associate
without the prior written consent of Covered Entity.
5.4 Binding Effect. Subject to provisions hereof restricting assignment, this
Agreement shall be binding upon and shall inure to the benefit of the Parties and their
respective successors and permitted assigns.
5.5 Change in Law. The Parties agree to take such action as is necessary to
amend this Agreement from time to time as is necessary for Covered Entity and Business
Associate to comply with the requirements of HIPAA and the HITECH Act, and of the
regulations issued pursuant to those laws. If Covered Entity reasonably concludes that an
amendment to this Agreement is needed because of change in federal or state law or
changing industry standards, Covered Entity shall notify Business Associate of such
proposed modification(s), “Legally-Required Modifications”. Such Legally Required
Modifications shall be deemed accepted by Business Associate and this Agreement so
amended, if Business Associate does not, within thirty (30) calendar days following the
date of notice, or within such other time period as may be mandated by applicable state or
federal law, deliver to Covered Entity its written rejection of such Legally-Required
Modifications.
5.6 Compliance with Laws. Business Associate will comply with all applicable
federal and state security and privacy laws, to the extent that such laws apply to Business
Associate or are more protective of individual privacy than HIPAA.
5.7 Entire Agreement. This Agreement, including attachments, constitutes the
entire Agreement between the Parties with respect to the subject matter hereof, and it
Page 14 of 16 Revised: November 4, 2022
supersedes all prior oral or written agreements, commitments, or understandings with respect
to the matters provided for herein.
5.8 Execution. This Agreement and any amendments thereto shall be executed
in duplicate copies on behalf of the Parties by an official of each, specifically authorized by
its respective Party to perform such executions. Each duplicate copy shall be deemed an
original, but both duplicate originals together constitute one and the same instrument.
5.9 Indemnification by Business Associate. Business Associate and any of its
subcontractors and agents shall indemnify, hold harmless and defend Covered Entity and
its employees, officers, directors, agents, and contractors from and against any and all
claims, losses, liabilities, costs, attorneys’ fees, and other expenses incurred as a result of
or arising directly or indirectly out of or in connection with Business Associate’s or its
subcontractors’ or agents’ breach of this Agreement, violation of HIPAA, HITECH or other
applicable law, or otherwise related to the acts or omissions of Business Associate or its
subcontractors or agents.
5.10 Independent Contractors. This Agreement establishes an independent
contractor relationship between Covered Entity and Business Associate. Nothing in this
Agreement is intended, nor may anything be construed, to create a partner, joint venture
employer/employee, or agent relationship.
5.11 Limitations on Benefits of this Agreement. Nothing express or implied in this
Agreement is intended to confer, nor shall anything herein confer, upon any person other
than Covered Entity, Business Associate, or their respective successors or assigns, any
rights, remedies, obligations or liabilities whatsoever. It is the express intent of the Parties
that no person or entity other than the Parties shall be entitled to bring any action to
enforce any provision of this Agreement against either of the Parties, and that the
Agreement set forth shall be solely for the benefit of, and shall be enforceable only by, the
Parties to this Agreement or their respective successors and assigns as permitted
hereunder.
5.12 Notices. All notices which are required or permitted to be given pursuant to
this Agreement shall be in writing and shall be sufficient in all respects if delivered
personally, by electronic facsimile (with a confirmation by registered or certified mail
placed in the mail no later than the following day), or by registered or certified mail,
postage prepaid, addressed to a Party as indicated below:
If to Business Associate: If to Covered Entity, to:
[INSERT APPROPRIATE CONTACT
INFORMATION]
Page 15 of 16 Revised: November 4, 2022
Notice shall be deemed to have been given upon transmittal thereof as to communications
which are personally delivered or transmitted by electronic facsimile and, as to communications
made by United States mail, on the third (3rd) day after mailing. The above addresses may be
changed by giving notice of such change in the manner provided above for giving notice.
5.13 References. A reference in this Agreement to a section in the Privacy
Rule or Security Rule means the section as in effect or as amended at the time of
reference and as interpreted pursuant to any applicable guidance provided by the
Secretary or other responsible regulatory authority and any applicable case law.
5.14 Severability. If any part of any provision of this Agreement, or any other
agreement, document or writing given pursuant to or in connection with this Agreement,
shall be held invalid or unenforceable, the holding of invalidity or unenforceability will
apply to the invalid or unenforceable part of the provision only, without in any way
affecting the remaining parts of said provision or the remaining provisions of said
Agreement.
5.15 Sub-Contract. Business Associate may not sub-contract any services
under the Services Agreement without the express written consent of Covered Entity.
5.16 Waiver. Neither the waiver by either Party of a breach of or a default under
any of the provisions of this Agreement, nor the failure of either of the Parties, on one or
more occasions, to enforce any of the provisions of this Agreement or to exercise any rights
or privilege hereunder shall thereafter be construed as a waiver of any subsequent breach
or default of a similar nature, or as a waiver of any such provisions, rights or privileges
hereunder.
5.17 Interpretation. Any ambiguity in this Agreement shall be resolved in favor of
a meaning that permits Covered Entity to comply with applicable requirements of HIPAA
HITECH Act, the Privacy Rule and the Security Rule. Any conflict between a provision of
the Services Agreement and this Agreement regarding the subject matter of this
Agreement, shall be resolved in favor of this Agreement
IN WITNESS WHEREOF, the parties have caused this Agreement to be executed by their
respective duly authorized representatives as of the dates set forth below.
BUSINESS ASSOCIATE COVERED ENTITY
By: By:
Name: Name:
Title: Title: