HomeMy WebLinkAboutPlanning - Franklin County
AGREEMENT BETWEEN
Emergency Solutions Grant (ESG)
Sub-recipient Agreement
BETWEEN
County of Franklin
AND
Waynesboro Community and Human Services
116 Walnut Street
Waynesboro, PA 17268
AGREEMENT
THIS AGREEMENT is made by and between COUNTY OF FRANKLIN, HEREAFTER
REFERRED TO AS THE “COUNTY” AND WAYNESBORO COMMUNITY AND
HUMAN SERVICES, HEREINAFTER REFERRED TO AS THE “ORGANIZATION”.
WHEREAS, the Stewart B. McKinney Homeless Assistance Act (passed July 1987) authorized
the use of the Emergency Solutions Grant (ESG) Program; and
WHEREAS, the County has applied to the Commonwealth of Pennsylvania for funds from the
ESG Program, and the Commonwealth has awarded ESG Program funds to the County; and
WHEREAS, The County may finance certain activities and projects as part of the ESG Program
for non-profit organizations within the County; and
WHEREAS, the Organization desires the County to finance certain services and activities with
ESG Program funds; and
WHEREAS, the Organization has the legal power to implement said services and activities;
I. TERM:
The effective date is the date the fully executed contract is sent to the Organization and
ends on June 30, 2027, subject to the other provisions herein, unless terminated earlier by
either party in accordance with the termination provisions of this agreement.
II. TERMINATION:
Either party may terminate this agreement by providing the other party sixty (60) days
advance written notice at the address set forth below:
THE COUNTY:
County of Franklin
272 North Second Street
Chambersburg, PA 17201
WITH COPY TO:
Franklin County Solicitor
272 North Second Street
Chambersburg, PA 17201
ORGANIZATION:
Waynesboro Community and Human Services
116 Walnut Street
Waynesboro, PA 17268
Attention: Morgan Hovermale
III. CONTRACTOR/SUBRECIPIENT DETERMINATION:
In accordance with Uniform Guidance 2 CFR Part 200, Waynesboro Community and
Human Services is determined to be a Subrecipient.
Subrecipient acknowledges that payments for Services under this Agreement are federal
funds and as such Subrecipient shall be bound by the requirements for Subrecipients as
outlined in Uniform Guidance. If Subrecipient is contributing toward the general
contract cost, Subrecipient certifies that the federal funds to be used under this
Agreement do not replace or supplant in any way state, local, or private funds used for
already existing services.
IV. INVOICING PROCEDURES:
The County will allocate a maximum of $43,452.60 for Rapid Rehousing, Homelessness
Prevention, HMIS reporting and administrative funds from the state ESG Program as
described in the budget Appendix A. Administration expenses are restricted to 3.75% of
the total invoice per month. If administrative reimbursement is requested, the staff’s
name, title and a brief explanation of the duties performed that were included during the
said time frame. No funds can be incurred until the COUNTY’s environmental review is
completed and approved by DCED.
The Organization shall match the ESG Program funds with an equal amount of funds
from sources other than the ESG Program. Funds used for the matching requirement must
be provided with each invoice submitted and cannot be the same funds used to match
other ESG Program funds received by the Organization from any other entity.
Upon submission of MONTHLY invoices by the Organization for cost incurred and
directly related to services and activities provided by the Agreement, the County shall
reimburse the Organization to the maximum approved ESG budget. Submitted invoices
for reimbursement shall be limited to the following:
A. Should the County find services, activities, or expenses to be unacceptable,
reimbursement shall be withheld and reasons for each withholding shall be sent to the
Organization. Satisfactory resolution of the County’s objections may result in the
processing of the request for reimbursement.
B. All ESG Program funds shall be released to the Organization only as a reimbursement
for actual costs incurred for services and activities provided during the time frame of
the submitted invoice.
C. The Organization certifies that it will not accumulate ESG Program funds in reserve.
Any interest earned on reimbursements that exceed actual costs incurred during the
time of the agreement shall be governed by the ESG Program.
D. The Organization must be able to certify its compliance with provisions of this
Agreement at all times by maintaining appropriate supporting financial
documentation and making said documentation available to the County at reasonable
times.
E. The Organization must submit supporting documentation of matching funds that
equal or exceed the amount of funds requested.
V. INVOICING INSTRUCTIONS:
A. Payments to be made MONTHLY upon submission of itemized invoices for services
rendered pursuant to this agreement. The Organization’s invoices must be received
within fifteen (15) days of the close of each calendar month.
B. All invoices shall to be sent electronically to Lin Xu, Franklin County Senior
Accountant at lxu@franklincountypa.gov. Invoices shall be itemized in accordance
with the date submitted.
VI. WORK STATEMENT:
ORGANIZATION shall provide the work, services, and activities as set forth and
described in Appendix A and Appendix B, and in accordance with the applicable ESG
requirements.
VII. APPENDICES:
The following attached Appendices are incorporated into and made a part of this contract:
Appendix A - ESG Budget
Appendix B - Work Statement / Program Specific Tasks
Appendix C - Audit Requirements
Appendix C - Attachment 1 / Federal Awards
Appendix D - Business Associate Agreement
VIII. CONTRACT CONDITIONS:
A. STANDARD GENERAL TERMS AND CONDITIONS
ORGANIZATION agrees to abide by and comply with the service requirements, all
reporting requirements, and contract conditions as provided herein.
1. Modification: The COUNTY reserves the right to amend this Agreement at any
time pursuant to amendments in the ESG Grant Agreement with the Department
of Community and Economic Development (DCED). The ORGANIZATION will
be notified in advance of any such Contract language amendments. Any
alteration, variation, modification, or waiver of a provision of this Agreement
shall be valid only when reduced to writing, duly signed by the parties of this
Agreement and attached to the original of the Agreement.
2. Contract Construction: The provisions of this Agreement shall be construed in
accordance with the Laws of the Commonwealth of Pennsylvania.
ORGANIZATION shall include all of the performance and regulatory provisions
of this Agreement in every sub-contract under this Agreement so that the
contractual provisions also bind each sub-ORGANIZATION.
ORGANIZATION agrees to comply with all applicable requirements of the ESG
Grant Agreement with DCED. ORGANIZATION shall comply with all
applicable state and federal regulations and laws. All documents referenced in this
paragraph are incorporated herein by reference. Each provision enumerated
herein or incorporated by reference hereto shall be deemed to be material and any
breach thereof may be considered a material breach of this Agreement.
3. Independent ORGANIZATION: The parties hereto agree that the
ORGANIZATION, and any agents and employees of the ORGANIZATION, in
the performance of this Contract, shall act in an independent contractor capacity
and not as officers, employees, or agents of the COUNTY or the Commonwealth
of Pennsylvania. The ORGANIZATION shall be responsible for the payment of
all payroll taxes and shall provide and be responsible for all premiums for public
liability, property damage, and workers’ compensation insurance, insuring as they
may appear, the interests of the COUNTY and ORGANIZATION against any and
all claims which may arise out of ORGANIZATION’s operations pursuant to this
Agreement.
4. Sub-Contracts: Except for those sub-contracts specifically authorized by this
Agreement, ORGANIZATION shall not enter into sub-contracts for any work
contemplated under this Agreement without obtaining prior written approval of
the COUNTY. Provided, however, notwithstanding the foregoing, unless
otherwise provided herein, such prior written approval shall not be required for
the purchase by ORGANIZATION of articles, supplies, equipment and services
which are both necessary for and merely incidental to the performance of the
work required under this Agreement. No provision of this clause and no approval
by the COUNTY of any sub-contract shall be deemed in any event in any manner
to provide for the incurrence of any obligation of the COUNTY in addition to the
total agreed upon contract amount.
5. Availability of Information: ORGANIZATION agrees that all information
obtained during the period of this Agreement by ORGANIZATION through work
governed by this Agreement shall be made available to the COUNTY and DCED
immediately upon demand.
6. Program Records: ORGANIZATION agrees to maintain program records and
program statistical records required by the COUNTY and DCED and agrees to a
program and facilities review, including meetings with consumers, review of
service records, review of service policy and procedural issuances, review of
staffing ratios and job descriptions, and meetings with any staff directly or
indirectly involved in the provision of services.
ORGANIZATION agrees to maintain books, records, documents and other
evidence in accordance with accounting procedures and practices which meet
generally accepted accounting principles.
7. Record Retention Requirements:
A. ORGANIZATION agrees to maintain books, records, documents and other
evidence pertaining to the costs and expense incurred pursuant to this
Agreement (hereinafter collectively referred to as “the records”) in such detail
as will properly reflect all costs, direct and indirect, of labor, materials,
equipment, supplies and services and other costs, and expenses of whatever
nature for which reimbursement is claimed under the provisions of the
Agreement. ORGANIZATION agrees to maintain books, records, documents
and other evidence and accounting procedures and practices that comply with
generally accepted accounting principles (GAAP) and all applicable State and
Federal regulations.
B. ORGANIZATION agrees to make available at the office of the
ORGANIZATION at all reasonable times during the term of this Agreement,
any of the records for inspection, audit or reproduction by any authorized
representative of the Federal, State or County governments.
C. ORGANIZATION shall preserve and make available its records for a period
of seven (7) years from the date of final payment by the COUNTY to
ORGANIZATION, and for such period, if any, as is required by applicable
statute, by any other paragraph of this Agreement, or by sub-paragraphs (1) or
(2) below.
1) If this Agreement is completely or partially terminated, the records
relating to the work terminated shall be preserved and made available for a
period of seven (7) years from the date of any resulting final payment.
2) Records which relate to litigation or the settlement of claims arising out of
the performance of this Agreement, or costs and expenses of this
Agreement as to which exception has been taken by the auditors, shall be
retained by the ORGANIZATION until such litigation, claims, or
exceptions have been disposed of.
8. Confidentiality, Sensitive Documents and Information:
A. ORGANIZATION shall maintain the confidentiality of medical records of
individuals served by ORGANIZATION under this Agreement except to
disclose such confidential information to DCED and/or the COUNTY for
purposes of consultation or DCED’s and/or the COUNTY’s monitoring of this
Agreement. The parties shall execute a Business Associate Agreement, as
required by law and requested by COUNTY.
B. ORGANIZATION shall not publish or otherwise disclose, except to DCED
and/or the COUNTY, and except matters of public record, any information or
data obtained hereunder from private individuals, organizations, or public
agencies, in a publication whereby the information or data furnished by or
about any particular person or establishment can be identified, except with the
informed consent of such person or establishment.
C. ORGANIZATION shall not release any sensitive documents or information
without the prior written approval of DCED and/or the COUNTY. The term
“sensitive documents or information” shall mean a document or information
that contains the description, design, operational plan, or other vital
information about a critical facility or infrastructure located in Pennsylvania
and bordering states (e.g., nuclear power plants, hazardous chemical plant, oil
refinery, bridge, dam, tunnel, etc.), or contains information about the
operational protocols or emergency response capabilities of state and local
agency personnel, the content of which could be used by a terrorist or enemy
of the United states to plan an attack upon a critical facility located in
Pennsylvania and bordering states or engages in other activities that could
cause death or injury to fire, police, medical, military, or other emergency
response personnel, public officials, or the general public.
9. Default and Termination:
A. The COUNTY may, by written notice of default to ORGANIZATION,
immediately terminate upon such terms as said notice shall set forth, the
whole or any part of this Agreement in any one of the following
circumstances:
1) If ORGANIZATION fails to perform the contracted services within the
time specified herein or any extension thereof; or
2) If ORGANIZATION fails to perform any of the other provisions of this
Agreement, and does not cure such failure within the period of time as
determined by the COUNTY and authorized in writing to
ORGANIZATION after receipt of notice from the COUNTY specifying
such failure.
B. In the event the COUNTY terminates this Agreement as provided herein,
ORGANIZATION shall transfer and deliver to the COUNTY all partially
completed reports or other documentation as ORGANIZATION has produced
under this Agreement.
C. Should ORGANIZATION become insolvent, or if proceedings in bankruptcy
be instituted by or against ORGANIZATION, the remaining or unexpired
portion of this Agreement may be terminated.
D. It is further agreed that in the event funding to the COUNTY from state or
federal funding sources is not obtained and continued at the anticipated level,
the COUNTY may exercise one of the following options:
1) Issue a written Notice of Termination of this Agreement to
ORGANIZATION effective upon a specified date.
E. After receipt of Notice of Termination, unless otherwise directed in writing by
the COUNTY, ORGANIZATION shall:
1) Stop work under this Agreement on the date and to the extent specified in
the Notice of termination.
2) Terminate all orders, contracts, and subcontracts to the extent that they
relate to the performance of work terminated by the Notice of
Termination.
3) Settle all outstanding liabilities and all claims arising out of such
termination. Notwithstanding the above, ORGANIZATION shall not be
relieved of liability to the COUNTY for damages sustained by the
COUNTY by virtue of the performance of ORGANIZATION.
F. The rights and remedies of the COUNTY provided in this Paragraph shall not
be exclusive and are in addition to any other rights and remedies provided by
law or under this Agreement.
10. Equal Employment Opportunity:
A. ORGANIZATION shall not discriminate against any employee, applicant for
employment, independent ORGANIZATION or any other person because of
race, color, religious creed, ancestry, national origin, age, or sex.
ORGANIZATION shall take affirmative action to ensure that applicants are
employed, and that employees or agents are treated during employment,
without regard to their race, color, religious creed, ancestry, national origin,
age, or sex. Such affirmative action shall include, but is not limited to:
employment, upgrading, demotion or transfer, recruitment or recruitment
advertising; layoff or termination; rates of pay or other forms of
compensation; and selection for training. ORGANIZATION shall post in
conspicuous places, available to employees, agents, applicants for
employment, and other persons.
B. ORGANIZATION shall, in advertisements or requests for employment placed
by it or on its behalf; state that all qualified applicants will receive
consideration for employment without regard to race, color, religious creed,
ancestry, national origin, age, or sex.
C. ORGANIZATION shall send each labor union or workers’ representative
with which it has a collective bargaining agreement or other contract or
understanding, a notice advising said labor union or workers’ representative of
its commitment to this nondiscrimination clause. Similar notice shall be sent
to every other source of recruitment regularly utilized by ORGANIZATION.
D. It shall be no defense to a finding of noncompliance with this
nondiscrimination clause that ORGANIZATION had delegated some of its
employment practices to any union, training program, or other source of
recruitment, which prevents it from meeting its obligations. However, if the
evidence indicates that the ORGANIZATION was not on notice of the third-
party discrimination or made a good faith effort to correct it; such factor shall
be considered in mitigation in determining appropriate sanction.
E. Where the practices of a union or training program or other source of
recruitment will result in the exclusion of minority group persons, so that
ORGANIZATION will be unable to meet its obligations under this
nondiscrimination clause, ORGANIZATION shall then employ and fill
vacancies through other nondiscriminatory employment procedures.
F. ORGANIZATION shall comply with all state and federal laws prohibiting
discrimination in hiring or employment opportunities. In the event of
ORGANIZATION’s noncompliance with the nondiscrimination clause of this
Agreement or with any such laws, this Agreement may be terminated or
suspended, in whole or in part, and ORGANIZATION may be declared
temporarily ineligible for further Commonwealth contracts, and other
sanctions may be imposed and remedies invoked.
G. ORGANIZATION shall furnish all necessary employment documents and
records to, and permit access to its books, records, and accounts by, the
Department and the Office of Administration, Bureau of Affirmative Action,
for purposes of investigation to ascertain compliance with the provisions of
this clause. If ORGANIZATION does not possess documents or records
reflecting the necessary information requested, it shall furnish such
information on reporting forms supplied by DCED.
H. ORGANIZATION shall actively recruit minority sub-ORGANIZATIONs or
sub-ORGANIZATIONs with minority representation among their employees.
I. ORGANIZATION shall include the provisions of this nondiscrimination
clause in every sub-contract, so that such provisions will be binding on each
sub-ORGANIZATION.
J. ORGANIZATION obligations under this clause are limited to the
ORGANIZATION’s facilities within Pennsylvania, or where the contract is
for purchase of goods manufactured outside of Pennsylvania, the facilities at
which such goods are actually produced.
11. Equal Opportunity for the Handicapped: ORGANIZATION agrees to abide by
Section 504 of the Rehabilitation Act of 1973, as amended (Public Law 93-112,
29 U.S.C. Section 794, as amended) and implementing Federal regulations.
ORGANIZATION assures that any benefits, services, or employment, available
through ORGANIZATION to the public by way of this Agreement’s funds, shall
not be denied persons with handicaps who are otherwise qualified or eligible for
the benefits, services, or employment available as a result of this Agreement.
ORGANIZATION agrees to indemnify and hold harmless the Commonwealth of
Pennsylvania and THE COUNTY from all losses, damages, expenses, claims,
demands, suits, and actions, including reasonable attorneys’ fees and court costs,
brought by any party against the Commonwealth of Pennsylvania and/or the
COUNTY as a result of ORGANIZATION’s failure to comply with the
provisions of the above paragraph.
12. Provisions Concerning the Americans with Disabilities Act: During the term
of this Agreement, ORGANIZATION agrees as follows: Pursuant to federal
regulations promulgated under the authority of the Americans With Disabilities
Act, 28 C.F.R. Section 35.101 et seq., ORGANIZATION understands and agrees
that no individual with a disability shall, on the basis of the disability, be excluded
from participation in this Agreement or from activities provided for under this
Agreement. As a condition of accepting and executing this Agreement,
ORGANIZATION agrees to comply with the “General Prohibitions Against
Discrimination,” 28 C.F.R. Section 35.130, and all other regulations promulgated
under Title II of The Americans With Disabilities Act which are applicable to the
benefits, services, programs, and activities provided by the Commonwealth of
Pennsylvania through contracts with outside ORGANIZATIONs.
ORGANIZATION agrees to indemnify and hold harmless the Commonwealth of
Pennsylvania and THE COUNTY from all losses, damages, expenses, claims,
demands, suits, and actions, including reasonable attorneys’ fees and court costs,
brought by any party against the Commonwealth of Pennsylvania and/or the
COUNTY as a result of ORGANIZATION’s failure to comply with the
provisions of the above paragraph.
13. Nondiscrimination/Sexual Harassment Clause: During the term of this
Agreement, ORGANIZATION agrees as follows:
A. ORGANIZATION and any sub-ORGANIZATIONs shall comply with any
federal, state, or local law, and the provisions of this Paragraph, as applicable,
pertaining to nondiscrimination and equal opportunity in regard to its
employees, applicants for employment, independent ORGANIZATIONs, or
any other person. ORGANIZATION represents that it is presently in
compliance with and will maintain compliance with all applicable federal,
state, and local laws and regulations relating to nondiscrimination and sexual
harassment. ORGANIZATION further represents that it has filed a Standard
Form 100 Employer Information Report (“EEO-1”) with the U.S. Equal
Employment Opportunity Commission (“EEOC”) and shall file an annual
EEO-1 report with the EEOC as required for employers subject to Title VII of
the Civil Rights Act of 1964, as amended, that have 100 or more employees
and employers that have federal government contracts or first-tier
subcontracts and have 50 or more employees. ORGANIZATION shall, upon
request and within the time periods requested by the Commonwealth, furnish
all necessary employment documents and records, including EEO-1 reports,
and permit access to their books, records and accounts by the granting agency
and the Bureau of Small Business Opportunities (BSBO), for the purpose of
ascertaining compliance with the provisions of this Nondiscrimination/Sexual
Harassment Clause.
B. In the hiring of any employees for the manufacture of supplies, performance
of work, or any other activity required under this Agreement,
ORGANIZATION or any person acting on behalf of ORGANIZATION shall
not by reason of gender, race, creed, color, religion, age, sexual preference,
handicap, or national origin discriminate against any citizen of this
Commonwealth who is qualified and available to perform the work to which
the employment relates.
In the hiring of any employees for the manufacture of supplies, performance
of work, or any other activity required under this Agreement,
ORGANIZATION or any person acting on behalf of ORGANIZATION shall
not discriminate in violation of the Pennsylvania Human Relations Act
(PHRA) and applicable Federal Law against any citizen of this
Commonwealth who is qualified and available to perform the work to which
the employment relates.
C. Neither ORGANIZATION nor any person on ORGANIZATION’s behalf
shall in any manner discriminate against or intimidate any employee involved
in the manufacture of supplies, the performance of work or any other activity
required under this Agreement on account of gender, race, creed, color,
religion, age, sexual preference, handicap, or national origin.
Neither ORGANIZATION nor any person on ORGANIZATION’s behalf
shall in any manner discriminate in violation of the Pennsylvania Human
Relations Act (PHRA) and applicable Federal Law against or intimidate any
employee.
D. ORGANIZATION shall not discriminate by reason of gender, race, creed,
color, religion, age, sexual preference, handicap, or national origin against any
sub ORGANIZATION or supplier who is qualified to perform the work to
which this Agreement relates.
ORGANIZATION shall not discriminate in violation of the Pennsylvania
Human Relations Act (PHRA) and applicable Federal Law against any sub
ORGANIZATION or supplier who is qualified to perform the work to which
this Agreement relates.
E. ORGANIZATION shall establish and maintain a written sexual harassment
policy and shall inform employees of the policy. The policy must contain a
notice that sexual harassment will not be tolerated and employees who
practice it will be disciplined.
F. ORGANIZATION shall ensure that any services or benefits available to the
public or other third parties by way of this Agreement shall not be denied or
restricted for such persons due to race, creed, color, religion, sex, sexual
preference, age, handicap, or national origin (national origin protections
include persons who are limited English proficient) consistent with the
provisions of Title VI of the Civil Rights Act of 1964, Section 504 of the
Rehabilitation Act of 1973, Title II of the Americans with Disabilities Act and
The Age Discrimination Act of 1975 as well as applicable provisions of the
Omnibus Reconciliation Act of 1981.
G. ORGANIZATION shall furnish all necessary employment documents and
records and permit access to its books, records, and accounts by THE
COUNTY and the Department of General Services’ Bureau of Contract
Administration and Business Development for purposes of investigation to
ascertain compliance with the provisions of this Nondiscrimination/Sexual
Harassment Clause. If ORGANIZATION or any sub ORGANIZATION does
not possess documents or records reflecting the necessary information
requested, it shall furnish such information on reporting forms supplied by the
Department or the Bureau of Contract Administration and Business
Development.
H. The Commonwealth may direct the COUNTY to cancel or terminate this
Agreement, and all money due or to become due under this Agreement may
be forfeited for a violation of the terms and conditions of this
Nondiscrimination/Sexual Harassment Clause. In addition, the agency may
proceed with debarment or suspension and may place ORGANIZATION in
the ORGANIZATION Responsibility File.
I. ORGANIZATION shall include the provisions of this
Nondiscrimination/Sexual Harassment Clause in every subcontract so that
such provisions will be binding upon each sub ORGANIZATION.
J. ORGANIZATION’S and all sub-ORGANIZATION’S obligations pursuant to
these provisions are ongoing from and after the effective date of this
Agreement through the termination date thereof. Accordingly,
ORGANIZATION shall have an obligation to inform the COUNTY if, at any
time during the term of this Agreement, it becomes aware of any actions or
occurrences that would result in violation of these provisions.
14. Drug Free Workplace Act of 1988 (P.L. 100-690):
By signing this Agreement, the ORGANIZATION, certifies to THE COUNTY,
as a condition precedent, that ORGANIZATION is in compliance with the Drug-
Free Workplace Act, 41 U.S.C. § 701, et. seq. ORGANIZATION agrees and
certifies that it shall provide a drug-free workplace in accordance with the Act.
15. ORGANIZATION Responsibility Provisions:
A. ORGANIZATION must certify, in writing, for itself and all its sub
ORGANIZATION, that as of the date of its execution of this Agreement, that
ORGANIZATION is not under suspension or debarment by the
Commonwealth or any governmental entity, instrumentality, or authority and,
if ORGANIZATION cannot so certify, then it agrees to submit, a written
explanation of why such certification cannot be made.
B. ORGANIZATION must also certify, in writing, that as of the date of the
execution of this Agreement it has no tax liabilities or other Commonwealth
obligations.
C. ORGANIZATION’s obligations pursuant to these provisions are ongoing
from and after the effective date of this Agreement through the termination
date thereof. Accordingly, the ORGANIZATION shall have an obligation to
inform the COUNTY if, at any time during the term of this Agreement, it
becomes delinquent in the payment of taxes, or other Commonwealth
obligations, or if it is suspended or debarred by the Commonwealth, the
federal government, or any other state or governmental entity. Such notice
shall be made within 15 days of the date of suspension or debarment.
D. The failure of ORGANIZATION to notify the COUNTY of its suspension or
debarment by the Commonwealth, any other state, or the federal government
shall constitute an event of default under this Agreement.
E. ORGANIZATION agrees to reimburse the COUNTY and DCED for the
reasonable costs of investigation incurred by the Office of State Inspector
General for investigations of ORGANIZATION’s compliance with the terms
of this Agreement, which results in the suspension or debarment of
ORGANIZATION. Such costs shall include, but shall not be limited to,
salaries of investigators, including overtime; travel and lodging expenses; and
expert witness and documentary fees. ORGANIZATION shall not be
responsible for investigative costs for investigations that do not result in
ORGANIZATION’s suspension or debarment.
F. ORGANIZATION may obtain a current list of suspended and debarred
Commonwealth ORGANIZATIONs by either searching the Internet at
www.dgs.state.pa.us/ or by contacting the:
Department of General Services
Office of Chief Counsel
603 North Office Building
Harrisburg, Pennsylvania 17125
Telephone No: (717) 783-6472
16. Reporting Requirements Under The Federal Funding Accountability and
Transparency Act (FFATA):
A. Registration and Identification Information
ORGANIZATION must maintain current registration in the Central
ORGANIZATION Registration (www.ccr.gov) at all times during which they
have active Federal awards funded pursuant to this Agreement. A Dun and
Bradstreet Data Universal Numbering System (DUNS) Number
(www.dnb.com) is one of the requirements for registration in the Central
ORGANIZATION Registration.
ORGANIZATION must provide its assigned DUNS number, and DUNS + 4
numbers if applicable, to the COUNTY along with ORGANIZATION’s
return of the signed Agreement. The COUNTY will not process this
Agreement until such time that the ORGANIZATION provides this
information.
B. Primary Location
ORGANIZATION must provide to the COUNTY the primary location of
performance under this Agreement, including the City, State, and Zip+4. If
performance is to occur in multiple locations, then ORGANIZATION must
list the location where the greatest amount of the funding is to be expended
pursuant to this Agreement.
ORGANIZATION must provide this information to the COUNTY along with
the ORGANIZATION’s return of the signed Agreement. The COUNTY will
not process this Agreement until such time that ORGANIZATION provides
this information.
C. Compensation of Officers
ORGANIZATION must provide to THE COUNTY the names and total
compensation of the 5 most highly compensated officers of the entity if—
1) the entity in the preceding fiscal year received:
(a) 80 percent or more of its annual gross revenues in Federal awards;
and,
(b) $25,000,000 or more in annual gross revenues from Federal awards;
and,
2) the public does not have access to information about the compensation of
the senior executives of the entity through periodic reports filed under
Section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C.
Sections 78m(a), 78o(d)) or Section 6104 of the Internal Revenue Code of
1986 (26 U.S.C. Section 6104).
If ORGANIZATION does not meet the conditions listed above, then it must
specifically affirm to the COUNTY that the requirements of this clause are
inapplicable to ORGANIZATION.
ORGANIZATION must provide information responding to this question
along with the ORGANIZATION’s return of the signed Agreement. The
COUNTY will not process this Agreement until such time that
ORGANIZATION provides such information in response to this question.
17. MONITORING:
ORGANIZATION agrees to permit on-site monitoring by the DCED-assigned
COUNTY for administrative and program performance. The ORGANIZATION
will allow the COUNTY staff to access any information requested in order to
verify adherence to this Agreement. The ORGANIZATION will allow the
COUNTY to monitor for all services provided on behalf of all the COUNTYs
who contract with the provider. The ORGANIZATION will allow the COUNTY
to monitor all documentation required based on the tool provided by the
COUNTY.
18. INDEMNIFICATION:
ORGANIZATION and its subcontractors shall release, hold harmless, and
indemnify the COUNTY, its officers, elected officials, agents, representatives,
and employees from and against any and all claims, liabilities, demands, or causes
of action, including reasonable attorneys’ fees and court costs, arising out of the
actions of the ORGANIZATION, its subcontractors, agents, servants, and/or
anyone acting under the ORGANZIATION’S control and/or the
ORGANIZATION’S direction, and employees as it relates to the provision of
services provided by the ORGANIZATION pursuant to this agreement and with
respect to the performance of the requirements of the AGREEMENT.
ORGANIZATION and its subcontractors assume full responsibility for all of their
acts or omissions which violate the ORGANIZATION’S or subcontractors’
obligations and duties under this AGREEMENT. The ORGANIZATION shall
defend any lawsuit commenced against the COUNTY and shall pay any
judgments and costs connected with such proceeding which are based upon the
acts or omissions of the ORGANIZATION or its subcontractors as it relates to the
provision of services provided by the ORGANIZATION pursuant to this
agreement and with respect to the performance of the requirements of this
AGREEMENT. The COUNTY does not in any manner waive its rights and
immunities provided by applicable law and/or regulation by entering into this
AGREEMENT.
19. INSURANCE:
ORGANIZATION will maintain a minimum, the following insurance coverage’s
and provide evidence of such insurance in the form of a Certificate of Insurance,
which names the COUNTY as the certificate holder and provides a 30 day notice
of cancellation or non-renewal;
$1,000,000 General Liability, per occurrence/aggregate, and naming the County
as an Additional Insured.
$1,000,000 Professional Liability, per occurrence.
$1,000,000 Automobile Liability Combined Single Limit
$25,000 Employee Dishonesty Bond
Statutory Limits, Workers’ Compensation and Employers’ Liability
This Agreement is a binding contract between the COUNTY and ORGANIZATION.
COUNTY INFORMATION
Name: Franklin County
Business Address: 272 North Second Street
Chambersburg, PA 17201
Phone: (717) 709-7218
Contact Person: Melodie Hoff
Email: mshoff@franklincountypa.gov
BILLING INFORMATION
Billing Information: Franklin County Administration Building
272 North Second Street,
Chambersburg, PA 17201
Phone: (717) 261-3101
Contact Person: Lin Xu
Email: lxu@franklincountypa.gov
ORGANIZATION INFORMATION
Name: Waynesboro Community and Human Services
Address: 116 Walnut Street
Waynesboro, PA 17268
Phone: (717) 762-6941
Contact Person: Morgan Hovermale
Email: mhovermale@wchs-pa.org
See signatures on next page
September 16
APPENDIX A
EMERGENCY SOLUTIONS BUDGET
This ESG Payment Agreement shall be effective from the date executed agreement is sent to the
Organization through June 30, 2027.
RAPID REHOUSING
HOMELESSNESS PREVENTION
HMIS
ADMIN
TOTAL BUDGET $43,452.60
APPENDIX B
WORK STATEMENT
PROGRAM SPECIFIC TASKS
1. The ORGANIZATION will use ESG Program funds to support the administrative costs for
supporting the Emergency Solutions Grant, as well as rapid rehousing and HMIS data entry.
The ORGANIZATION is required to enter all data into HMIS. Administrative costs are
restricted to 3.75% of the total invoiced amount per month. If administrative reimbursement
is requested, the staff’s name, title and a brief explanation of the duties performed that was
included during the said time frame.
2. The ORGANIZATION will follow the PA CoC Written Standards and any addendums
moving forward.
3. The ORGANIZATION shall develop a formal process for the termination of ESG Program
assistance to any individual or family who violates any requirements of the ESG Program.
The process shall recognize the right of the individuals affected and may include a hearing.
4. The ORGANIZATION shall provide all information necessary for the COUNTY to submit
required reports to the Department of Community and Economic Development.
5. The ORGANIZATION’S Executive Director and/or Director shall attend the Connect to
Home Coordinated Entry by name monthly meeting every month either in person or via
phone conference.
6. The ORGANIZATION will notify the Grants Director of Franklin County of any and all
changes in status of grant-funded elements including, but not limited to: assets such as land,
building, improvements, equipment, furnishings and vehicles; program services,
requirements, objectives; individuals such as staff and participants; and subcontractors or
sub-recipient agencies. Incidents that may lead to media publicity of any kind, involve law
enforcement, pose risk of becoming a liability and/or may affect funding in any way must be
reported immediately.
APPENDIX C
AUDIT REQUIREMENTS
This Appendix is intended to provide general audit requirement instruction to ORGANIZATION
as a recipient of funds issued by the COUNTY, from funds initiated by DCED.
ORGANIZATION must comply with all applicable federal and state grant requirements
including The Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other
applicable law or regulation, and any amendment to such other applicable law or regulation
which may be enacted or promulgated by the federal government.
Audit requirements may be either a Federal mandate or a DCED mandate. The audit require-
ments that are applicable to this Agreement are determined by the source(s) of the funding as
described in the following Sections of this document:
• Section II – Contracts/grants funded 100 percent by federal funds
• Section III – Contracts/grants funded 100 percent by state funds
• Section IV – Contracts/grants funded by federal and state funds
Audit exemption conditions are described in Section V of this document. Additionally, general
audit provisions that are applicable to ALL Agreements are described in Section VI.
II. CONTRACTS/GRANTS FUNDED 100 PERCENT BY FEDERAL FUNDS - (Federally
Mandated Audits)
A. General Requirements
If ORGANIZATION is a local government or non-profit organization and expends total
federal awards of $1,000,000 or more during its fiscal year, received either directly from
the Federal government or indirectly from a recipient of Federal funds,
ORGANIZATION is required to provide the appropriate single or program-specific audit
in accordance with the provisions outlined in 2 CFR Part 200.501.
If ORGANIZATION expends total Federal awards of less than the threshold established
by 2 CFR 200.501, it is exempt from Federal audit requirements for that year, but records
must be available for review or audit by appropriate officials (or designees) of the Federal
agency, pass-through entity, and Government Accountability Office (GAO).
If ORGANIZATION is a for-profit entity, it is not subject to the auditing and reporting
requirements of 2 CFR Part 200, Subpart F – Audit Requirements (Subpart F).
However, DCED is responsible for establishing requirements, as necessary, to ensure
compliance by for-profit ORGANIZATIONs/grantees. To accomplish this, THE
COUNTY reserves the right to perform monitoring during the Agreement and require the
following at its discretion:
1) Pre-award audits; and
2) Post-award audits. The post-award audits may be in the form of a financial audit
conducted in accordance with Government Auditing Standards, or a single audit
report or a program-specific audit report in accordance with Subpart F. However, if a
post-award audit is required by DCED, it must be directly submitted to THE
COUNTY. Only single audit reports for local governmental and non-profit
ORGANIZATIONs/grantees are electronically submitted to the Federal Audit
Clearinghouse.
In instances where a federal program-specific audit guide is available, the audit report package
for a program-specific audit should be prepared in accordance with the appropriate audit guide,
Government Auditing Standards, and Subpart F.
B. Additional Components of the Single Audit Reporting Package
In addition to the requirements of Subpart F, DCED requires that the single audit report
packages include the following additional components in the Schedule of Expenditures of
Federal Awards (SEFA), or supplemental schedules:
1) A breakdown of federal funds passed through DCED by federal grantor, Catalog of
Federal Domestic Assistance (CFDA) number, CFDA name and state program name
(if different from CFDA name), state program year, and state contract/grant number
(if applicable);
2) Contract/grant period beginning and ending dates for federal funds passed through
DCED, by contract/grant;
3) Program or award amount for each DCED contract/grant;
4) Total received during the year for each DCED contract/grant;
5) Accrued or deferred revenue at the beginning of the year for each DCED
contract/grant;
6) Revenue recognized during the year for each DCED contract/grant;
7) Accrued or deferred revenue at the end of the year for each DCED contract/grant.
C. Submission of the Audit Report
All recipients of funds required to complete a federally mandated audit must submit an
electronic copy of the data collection form and the audit reporting package to the Federal
Audit Clearinghouse, which shall include the elements outlined in Subpart F.
D. Submission of the Federal Audit Clearinghouse Confirmation
The ORGANIZATION must electronically send a copy of the confirmation from the
Federal Audit Clearinghouse to the resource account established by the Office of the
Budget, Bureau of Audits at RA-BOASingleAudit@pa.gov. Note that this is only
applicable to recipients directly funded by the Commonwealth through a contract or grant
agreement with an agency of the Commonwealth; or any administrative agent utilized by
the ORGANIZATION/grantee to manage the disbursement and contracting of funds for
the ORGANIZATION/grantee. Instructions for confirmation of audit material submission
to the Federal Audit Clearinghouse by sub-ORGANIZATIONs or sub-grantees would be
provided by the entity contractually engaged with that sub-ORGANIZATION or sub-
grantee.
III. CONTRACTS/GRANTS FUNDED 100 PERCENT BY STATE FUNDS -
(Department Mandated Audits)
A. General Requirements
The ORGANIZATION shall have a program-specific audit performed when it expends
$1,000,000 or more of state funds under this contract/grant during the state fiscal year
(i.e., July 1 through June 30), or unless notified in writing by DCED prior to the
termination of the applicable audit period that the audit requirement has been waived. If
the ORGANIZATION/grantee’s contract/grant or any successive period is for a period
shorter than the state fiscal year, but the contract/grant amount expended by the
ORGANIZATION/grantee during said period includes $1,000,000 or more of state funds,
the ORGANIZATION/grantee is also required to have a program-specific audit
performed for the entire contract/grant or successive period, unless notified in writing by
DCED prior to the termination of the applicable audit period that the program-specific
audit requirement has been waived.
If the body of the ORGANIZATION’s Agreement with THE COUNTY contains
language superseding the dollar threshold for Department mandated audits identified in
this document, the superseding language takes precedence and must be used by the
ORGANIZATION/grantee when determining whether the ORGANIZATION/grantee is
required to have an audit performed.
When the ORGANIZATION is required to have a program-specific audit performed, it
must be a financial audit conducted in accordance with auditing standards generally
accepted in the United States of America and Government Auditing Standards, issued by
the Government Accountability Office (GAO). The audit shall meet the audit require-
ments of the laws and regulations governing the program(s) in which the
ORGANIZATION participates, and the terms of this Agreement. With the written
consent of DCED, the ORGANIZATION may be permitted to vary the audit period for
these audits.
The costs of program-specific audits performed in accordance with the provisions of
Section III of this document shall be reimbursed by DCED when said costs are
specifically budgeted in the agreement budget as audit expenses.
B. Minimum Audit Reporting Requirements
When a program-specific audit is performed, the audit report must include the following
at a minimum:
1. A Statement of Financial Position (balance sheet) for each contract/grant the
ORGANIZATION includes in the program-specific audit. Said statement of financial
position shall identify any unexpended/unused funds at the end of the audit period.
2. A separate Statement of Contractual Performance, which shall reflect the contract/grant
budget and reporting period and include a comparison of budgeted to actual
expenditures/services, must be prepared for each contract/grant the ORGANIZATION
includes in the program-specific audit. Said schedule(s) must reconcile to the state
fiscal year(s) affected.
3. Notes to the financial statements. The following must be included:
(a) Definition of the reporting entity
(b) Summary of significant accounting policies used in preparing the statements
(c) Other informative disclosures (as necessary)
4. Auditor's report on the financial statements and any additional statements required in
the terms of this contract/grant. The report must identify each contract/grant included
in the program–specific audit by its Department contract/grant number.
5. Auditor's report on internal control, including (where applicable) references to
contract/grant requirements and Department audit guidance. The report must identify
each contract/grant included in the program–specific audit by its Department
contract/grant number. This report shall describe the scope of testing of internal control
and the results of the tests, and, where applicable, refer to the separate Schedule of
Findings and Questioned Costs described below.
6. Auditor's report on compliance with laws, regulations, and the provisions of this
contract/grant, noncompliance with which could have a material effect on the financial
statements. The report must identify each contract/grant included in the program–
specific audit by its Department contract/grant number. This report shall include
(where applicable) references to contract/grant requirements and Department audit
guidance.
7. Schedule of Findings and Questioned Costs (if applicable). This schedule shall include
the views of responsible officials of the ORGANIZATION concerning the auditors’
findings, conclusions, and recommendations. This schedule shall contain all findings
and questioned costs for the financial statements which are required to be reported
under Government Auditing Standards. Specifically, the auditor shall report the
following as audit findings in this schedule:
(a) Reportable conditions in internal control over the program(s) (state and/or federal)
that provide funding under this contract/grant. The auditor shall identify reportable
conditions which are individually or cumulatively material weaknesses.
(b) Material noncompliance with the provision of laws, regulations, and the provisions
of this contract/grant.
(c) Questioned costs specifically identified by the auditor (known questioned costs). In
evaluating the effect of the questioned costs, the auditor shall consider the best
estimate of total costs questioned (likely questioned costs), not just the known
questioned costs. In reporting questioned costs, the auditor shall include
information to provide proper perspective for judging the prevalence and
consequences of the questioned costs.
(d) Known fraud that has a material effect on the financial statements.
8. Corrective Action Plan (if applicable). At the completion of the audit, the
ORGANIZATION shall prepare a corrective action plan (CAP) to address each audit
finding included in the audit report. The CAP shall provide the name(s) of the contact
person(s) responsible for corrective action(s), the corrective action(s) planned, and the
anticipated completion date(s) for the corrective action(s) planned. Further, if the
ORGANIZATION does not agree with an audit finding, it must clearly and completely
explain the nature of its disagreement with the finding in the CAP. Finally, if the
ORGANIZATION believes that corrective action is not required, it must provide the
specific reason(s) in the CAP.
9. Status of Prior Audit Findings and Recommendations (if applicable). The auditor shall
report the status of uncorrected material findings and recommendations from prior
audits that affect the current audit.
10. Management Letter (if applicable). If a letter is issued to management disclosing non-
reportable conditions or other matters that warrant the attention of management, it must
be furnished to THE COUNTY with the audit report.
11. Subcontractor/Sub-grantee Audit Requirements: As applicable, the ORGANIZATION
shall have subcontractors/subgrantees obtain audits of their contracts/grants in
accordance with Section III of this document. The ORGANIZATION shall make the
requirements of Section III applicable to any subcontractor/subgrantee expending
$1,000,000 or more of state funds under this contract/grant during the state fiscal year
(i.e., July 1 through June 30),or expending $1,000,000 or more of state funds under this
contract/grant within any successive state fiscal year. If the subcontract/subgrant or any
successive period is for a period shorter than the state fiscal year, but the
subcontractor/subgrantee expends $1,000,000 or more of state funds under this
contract/grant during said period, the ORGANIZATION is also required to make the
requirements of Section III of this document applicable to the subcontractor/subgrantee.
The COUNTY NOT DCED, is responsible for the receipt, review, and resolution
of such audits. The ORGANIZATION shall follow up on all findings disclosed in the
audit report(s). The ORGANIZATION shall retain such audits for a period of time
which is the greater of four years after termination of the ORGANIZATION's
contract/grant with the subcontractor/subgrantee or until resolution of any audit
exceptions or other claims or actions involving a subcontract/subgrant.
If the body of the ORGANIZATION’s Agreement with THE COUNTY contains
language superseding the dollar threshold for Department mandated audits identified in
this document, the superseding language takes precedence and must be used by the
ORGANIZATION when determining whether the subcontractors/subgrantees are
required to have an audit performed of their contracts/grants.
C. Submission of Audit Reports
When the ORGANIZATION is responsible for obtaining a program-specific audit in
accordance with Section III of this document, the audit report must be completed and
submitted within 120 days of the end of the state fiscal year (i.e., June 30) or 120 days
following the end of each state fiscal year in case of a contract/grant lasting more than
twelve months. DCED will accept electronic submission of program-specific audit
reporting packages. Electronic submission is required for the state fiscal year ending
June 30, 2021 and subsequent reporting periods. The reporting package must be
submitted electronically in single Portable Document Format (PDF) file to the e-mail
resource account RA-BOASingleAudit@pa.gov.
Steps for electronic submission:
1) Complete the Program-Specific Audit Reporting Package Checklist to ensure your
package contains all required elements.
2) Upload the completed Program-Specific Audit Reporting Package along with the
checklist in a single PDF file to the e-mail resource account RA-
BOASingleAudit@pa.gov. In the subject line of the e-mail you must identify the
exact name on the Program-Specific Audit Reporting Package and the period end date
to which the package applies.
3) You will receive an e-mail to confirm the receipt of your Program-Specific Audit
Reporting Package, including the completed checklist.
Technical assistance with respect to program-specific audits performed in accordance
with Section III of these Audit Requirements will be provided by DCED’S Division of
Budget and Grants Management at RA-BOASingleAudit@pa.gov.
IV. CONTRACTS FUNDED BY FEDERAL AND STATE FUNDS
A. Conditions Requiring an Audit
1) The ORGANIZATION is required to have a federally mandated audit made in
accordance with the requirements of Section II when the ORGANIZATION expends
more than $1,000,000 of total federal awards received from ALL sources during its
fiscal year, regardless of the amount of state funds received under this contract/grant
during the state fiscal year.
2) The ORGANIZATION is required to have a program-specific audit made in
accordance with the requirements of Section III if the ORGANIZATION expends
$1,000,000 or more of state funds received under this contract/grant during the state
fiscal year and the ORGANIZATION is not required to have a federally mandated
audit(s) in accordance with this document that covers the entire state fiscal year.
If the body of the ORGANIZATION’s contract/grant with DCED contains language
superseding the dollar threshold for Department mandated audits identified in this
document, the superseding language takes precedence and must be used by the
ORGANIZATION when determining whether the ORGANIZATION is required to have
an audit performed in accordance with the condition described above.
V. AUDIT EXEMPTION CONDITIONS
A. Unless stated otherwise in the terms of this Agreement, the ORGANIZATION is not
required to have an audit performed when EITHER of the following conditions is
applicable:
1) The ORGANIZATION expends less than $1,000,000 of state funds received under
this contract/grant during the state fiscal year (i.e., July 1 through June 30) (for
Department mandated audits) AND it expends less than $1,000,000 of total federal
awards received from ALL sources during its fiscal year.
B. If the body of the ORGANIZATION’s Agreement with THE COUNTY contains
language superseding the dollar threshold for Department mandated audits identified in
this document, the superseding language takes precedence and must be used by the
ORGANIZATION when determining whether the ORGANIZATION is required to have
an audit performed.
1) The contract/grant is funded by either state or federal funds, and all contract/grant
monies expended during either the ORGANIZATION’s fiscal year (for federally
mandated audits) or during the state fiscal year (i.e., July 1 through June 30) (for
Department mandated audits) are received on a strictly fee for service basis.
However, even if the ORGANIZATION is not required to have an audit performed, the
ORGANIZATION is required to maintain auditable records of federal awards and any
state funds which supplement such awards, and to provide access to such records by
federal and state agencies or their designees.
VI. GENERAL AUDIT PROVISIONS
A. Auditor Selection
The ORGANIZATION is responsible for obtaining the necessary audit and securing the
services of a certified public accountant or independent governmental auditor.
The Office of the Budget, Office of Comptroller Operations, Bureau of Audits (Bureau of
Audits) may decide to perform program-specific audits that are required under Section III
of these Audit Requirements. The ORGANIZATION will be given written notification if
the Bureau of Audits makes this decision. In the event that the Bureau of Audits does
perform the program-specific audit, any audit costs included in the Agreement will revert
to DCED. However, unless notified as provided above, the ORGANIZATION is
required to arrange for the audit as described above.
B. Questioned Costs
Any questioned costs identified as such in audit reports of either the ORGANIZATION
or its subcontractors/subgrantees shall be returned to the cognizant federal and/or state
agencies providing the financial assistance, unless resolved to the satisfaction of said
entities.
C. Sanctions (Remedies for Noncompliance with Audit Requirements)
The ORGANIZATION's failure to provide an acceptable audit in accordance with the
requirements of this document may result in THE COUNTY initiating sanctions against
the ORGANIZATION including, but not limited to, the following actions:
1) Disallowance of the cost of the audit.
2) Withholding a percentage of the contract/grant funding.
3) Withholding or disallowance of administrative/overhead costs.
4) Suspension of subsequent contract/grant funding.
D. Additional Audits
The Commonwealth reserves the right for federal and state agencies or their authorized
representatives to perform additional audits of a financial or performance nature, if
deemed necessary by commonwealth or federal agencies. Any such additional audit
work will rely on work already performed by the ORGANIZATION's auditor and the
costs for any additional work performed by the federal or state agencies will be borne by
those agencies at no additional expense to the ORGANIZATION.
E. Audit Working Papers and Reports
Audit documentation and audit reports must be retained by the ORGANIZATION’s
auditor for a minimum of five years from the date of issuance of the audit report, unless
the ORGANIZATION’s auditor is notified in writing by the commonwealth, the
cognizant federal agency for audit, or the oversight federal agency for audit to extend the
retention period. Audit documentation will be made available upon request to authorized
representatives of the commonwealth, the cognizant federal agency for audit, the
oversight federal agency for audit, the federal funding agency, or the Government
Accountability Office (GAO).
F. Records Retention
The ORGANIZATION is required to maintain records of state funds and federal awards.
The ORGANIZATION shall preserve all books, records and documents related to this
contract/grant for a minimum of four years from the date of final payment under this
contract/grant; or until all findings, questioned costs or activities have been resolved to
the satisfaction of the commonwealth; or as required by applicable federal laws and
regulations, whichever is longer, unless this contract/grant elsewhere provides for a
shorter period; or unless THE COUNTY otherwise separately agrees in writing to a
shorter period. The ORGANIZATION shall provide federal and state agencies or their
designees access to such books, records and documents for inspection, audit or
reproduction.
G. Funding Source(s)
The audit report must identify the amounts of federal and state funding that is included in
the report. This identification must include the breakdown of federal and state dollars
provided and the related federal and state financial assistance program name and number.
This identifying information is provided in Attachment 1 to this Appendix F, entitled
FEDERAL AWARDS, of this Agreement.
28
APPENDIX C
ATTACHMENT 1
FEDERAL AWARDS
The following information is provided pursuant to the requirements of 2 C.F.R. Section 200 as
Uniform Guidance:
Subrecipient Name: Waynesboro Community and Human Services
Subrecipient's DUNS Number: 17-154-9652
Subrecipient's Unique Entity Identifier: EKLDWBG47535
Federal Award Identification Number (FAIN): 23-DC-42-0001
Date of Federal Award: the date executed agreement is sent to the Organization through June
30, 2027.
Subaward Period of Performance Start and End Date: August 1, 2026, through June 30, 2027
Federal Funds Obligated (this action): $43,452.60
Total Federal Funds Obligated to the Subrecipient (including current obligation): $230,176.69
(Active Contracts FY 2024, and 2025)
Total Amount of Federal Award To Franklin County: $43,452.60
Project Description: The ESG program provides funding to engage homeless individuals and families living
on the street and improves the number and quality of emergency shelter for homeless individuals and families;
helps operate these shelters; provides essential services to shelter residents; rapidly re-houses homeless
individuals and families and prevents families and individuals from becoming homeless.
Federal awarding agency: Assistant Secretary for Community Planning and Development
Pass-Through Entity: Franklin County, Pennsylvania
Pass-Through Entity Contact Information: Melodie Hoff, 272 North Second Street,
Chambersburg, PA 17201, mshoff@franklincountypa.gov (717) 709-7218
Catalog of Federal Domestic Assistance (CFDA) name and number: 14.231
Is this award for research and development? YES NO X
“Research” is defined as a systematic study directed toward fuller scientific knowledge or understanding of the subject studied.
“Development” is the systematic use of knowledge and understanding gained from research directed toward the production of useful
materials, devices, systems, or methods, including design and development of prototypes and processes. Indirect cost rate: 10%
For nonprofit organizations, the costs of activities performed by the non-Federal entity primarily as a service to members, clients, or the general
public when significant and necessary to the non-Federal entity's mission must be treated as direct costs wh ether or not allowable, and be
allocated an equitable share of indirect (F&A) costs. Indirect (F&A) costs mean those costs incurred for a common or joint purpose benefitting
more than one cost objective.
De Minimis Indirect cost rate applied? YES X NO
APPENDIX D
Business Associate Agreement
This Business Associate Agreement (this “Agreement”) is entered into by Waynesboro
Community and Human Services. (“Business Associate” and County of Franklin,
Pennsylvania (“Covered Entity”), individually referred to as “Party” and collectively as the
“Parties.” This Agreement is effective as of DATE EXECUTED AGREEMENT IS SENT
TO THE BUSINESS ASSOCIATE (“Effective Date”).
RECITALS
WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and
Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative
Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in
Article 1 of this Agreement, and with the applicable provisions of the Health Information
Technology for Economic and Clinical Health Act of 2009 (“HITECH”).
WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to
Covered Entity pursuant to the Services Agreement, as defined below.
WHEREAS, Business Associate is a business associate under HIPAA. Business Associate must
comply with the provisions of the Privacy Rule and Security Rule made applicable to business
associates pursuant to HITECH and with all other applicable provisions of HITECH.
WHEREAS, Covered Entity is not permitted to allow Business Associate to create, receive,
maintain, or transmit Protected Health Information on behalf of Covered Entity without
satisfactory assurances that Business Associate will appropriately safeguard the information.
Therefore, Covered Entity will only disclose Protected Health Information to Business Associate
or allow Business Associate to create or receive Protected Health Information on behalf of
Covered Entity in accordance with the requirements of HIPAA, HITECH, and provisions of this
Agreement.
NOW, THEREFORE, in consideration of the mutual promises below and for other good and
valuable consideration, the receipt and adequacy of which are hereby acknowledged, the Parties
agree as follows:
WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and
Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative
Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in
Article 1 of this Agreement, and with the applicable provisions of the Health Information
Technology for Economic and Clinical Health Act of 2009 (“HITECH”).
WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to
Covered Entity pursuant to the Services Agreement, as defined below.
WHEREAS, Business Associate is a business associate under HIPAA. Business Associate must
comply with the provisions of the Privacy Rule and Security Rule made applicable to business
associates pursuant to HITECH and with all other applicable provisions of HITECH.
WHEREAS, Covered Entity is not permitted to allow Business Associate to create, receive,
maintain, or transmit Protected Health Information on behalf of Covered Entity without
satisfactory assurances that Business Associate will appropriately safeguard the information.
Therefore, Covered Entity will only disclose Protected Health Information to Business Associate
or allow Business Associate to create or receive Protected Health Information on behalf of
Covered Entity in accordance with the requirements of HIPAA, HITECH, and provisions of this
Agreement.
NOW, THEREFORE, in consideration of the mutual promises below and for other good and
valuable consideration, the receipt and adequacy of which are hereby acknowledged, the Parties
agree as follows:
ARTICLE I
DEFINITIONS
Terms used in this Agreement that are specifically defined in HIPAA shall have the same
meaning as set forth in HIPAA. A change to HIPAA which modifies any defined HIPAA term,
or which alters the regulatory citation for the definition shall be deemed incorporated into this
Agreement.
1. Breach means the unauthorized acquisition, access, use, or disclosure of Protected Health
Information which compromises the security or privacy of such information, except
where an unauthorized person to whom such information is disclosed would not
reasonably have been able to retain such information. The term “breach” does not
include the exceptions described in 42 U.S.C. § 17921(1)(B) summarized below.
(a) Certain uses or disclosures by a Covered Entity’s work-force members (defined as
persons acting under the authority of the Covered Entity or Business Associate), if the
use or disclosure was made in good faith, was within the scope of the disclosing
individual’s authority, and does not result in a further violation of the Privacy Rule.
(b) Inadvertent disclosures from one person who is authorized to access PHI to another
person who is also authorized to access PHI within the same Covered Entity,
Business Associate, or organized health care arrangement when the disclosed PHI is
not further used or disclosed in a manner not permitted under the Privacy Rule.
(c) A disclosure of PHI when a Covered Entity or Business Associate has a good faith
belief that an unauthorized person to whom the disclosure was made would not
reasonably have been able to retain such information.
2. Designated Record Set, as defined under the Privacy Rule at 45 C.F.R. § 164.501, means
a group of records maintained by or for a Covered Entity that are:
(a) the medical records and billing records about individuals maintained by or for a
covered health care provider;
(b) the enrollment, payment, claims adjudication, and case or medical management
record systems maintained by or for a health care plan; or
(c) used, in whole or in part, by or for the Covered Entity to make decisions about
individuals.
For purposes of this section, a “Record” is any item, collection, or grouping of information that
includes PHI and is maintained, collected, used, or disseminated by or for a Covered Entity.
3. Electronic Health Record has the same meaning that applies under Section 13400(5) of
ARRA and currently means an electronic record of health-related information on an
individual that is created, gathered, managed, and consulted by authorized staff.
4. Electronic Protected Health Information (EPHI), as defined by 45 C.F.R. § 160.103,
means individually identifiable health information that is transmitted by electronic media,
or maintained in electronic media, but not certain education and employment records
described in 45 C.F.R. § 160.103, the definition of Protected Health Information. EPHI
also includes any EPHI provided by Covered Entity or created or received by Business
Associate on behalf of Covered Entity.
5. HHS means the U.S. Department of Health and Human Services.
6. Individual, as defined by 45 C.F.R § 160.103, means the person who is the subject of
PHI. It also includes a person who qualifies as a Personal Representative in accordance
with 45 C.F.R. § 164.502(g).
7. Limited Date Set, as defined by 45 C.F.R. §164.514(e) is partially de-identified data that
may be used or disclosed for research, public health and health care operation purposes,
such as quality assurance, as long as a recipient signs a data use agreement that complies
with HIPAA requirements.
8. Privacy Rule means the Standards for Privacy of individually Identifiable Health
Information codified at 45 C.F.R. §§ 160 and 164, Subpart E, any other applicable
provision of HIPAA, and any amendments to HIPAA, including HITECH.
9. Protected Health Information (PHI) as defined by 45 C.F.R. § 164.103, mean
individually identifiable health information that is:
(a) transmitted by electronic media;
(b) maintained in electronic media; or
(c) transmitted or maintained in any other form or medium;
PHI does not include certain education and employment records described in 45 C.F.R.
§ 160.103, the definition of PHI. PHI includes, without limitation, any PHI provided by
Covered Entity or created or received by Business Associate on behalf of Covered Entity.
Unless otherwise stated in this Agreement, any provision, restriction, or obligation in this
Agreement related to the use of PHI shall apply equally to EPHI.
10. Required By Law, as defined by 45 C.F.R. § 164.103, means a mandate contained in law
that compels an entity to make a use or disclosure of PHI and that is enforceable in a
court of law; and any additional requirements created under HITECH.
11. Secretary means the Secretary of the Department of Health and Human Services or
his/her designee.
12. Security Incident, as defined by 45 C.F.R. § 164.304, means the attempted or successful
unauthorized access, use, disclosure, modification, or destruction of information or
interference with system operations in an information system.
13. Security Rule means the Security Standards for the Protection of Electronic Protected
Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart C, any other applicable
provision of HIPAA, and any amendments to HIPAA, including HITECH.
14. Services Agreement means the underlying agreement(s) that outline the terms of the
services that Business Associate agrees to provide to Covered Entity and that fall within
the functions, activities or services described in the definition of Business Associate at
45 C.F.R. § 160.103.
15. Unsecured PHI shall mean PHI that is not rendered unusable, unreadable, or
indecipherable to unauthorized individuals through the use of a technology or
methodology specified by the Secretary of HHS, such as encryption in compliance with
the National Institute of Standards and Technology standards or destruction.
ARTICLE II
BUSINESS ASSOCIATE OBLIGATIONS
1. Request, Use and Disclosure of PHI. Business Associate agrees that it will only request,
use and disclose PHI in accordance with the terms of this Agreement, and as is Required
by Law. Business Associate acknowledges that it may only request, use and disclose PHI
obtained or created pursuant to this Agreement with Covered Entity if the request, use or
disclosure is in compliance with each applicable requirement of the Privacy Rule found
in 45 C.F.R. § 164.504(e).
2. Permitted Requests, Uses and Disclosures. Business Associate will not request, use or
disclose PHI except for the purpose of performing Business Associate’s obligations to
Covered Entity as described in the Services Agreement, consistent with the requirements
of HIPAA and this Agreement, and for other uses and disclosures permitted under this
Agreement. Business Associate may request, use or disclose PHI only if such request,
use or disclosure does not violate the Privacy Rule or this Agreement. To the extent
Business Associate is to carry out any of Covered Entity’s obligations under the Privacy
Rule, Business Associate will comply with the requirements of the Privacy Rule that
apply to Covered Entity in the performance of the applicable obligations.
In accordance with the provisions of 45 C.F.R. § 164.504(e)(4), Business Associate also
may request, use or disclose PHI, if necessary:
(a) for the proper management and administration of Business Associate’s organization,
or
(b) to carry out the legal responsibilities of Business Associate.
Business Associate may only disclose PHI for these purposes, in accordance with the
provisions of 45 C.F.R. § 164.504(e)(4)(ii), if either
(a) the disclosure is Required By Law, or
(b) Business Associate obtains reasonable written assurances from the person to whom
Business Associate discloses the PHI that the PHI will be held confidentially and
used or further disclosed only as Required By Law or for the purposes for which it
was disclosed to the person and that the person agrees to notify Business Associate of
any instances of which it is aware in which the confidentiality of the information has
been breached.
3. Prohibited Requests, Use and Disclosures. Business Associate will not request, use or
disclose PHI in any manner that constitutes a violation of the Privacy Rule, this
Agreement, or the Services Agreement.
4. Minimum Requirements. Business Associate will only request, use and disclose the
minimum amount of PHI necessary for Business Associate to perform the services for
which it has been retained by Covered Entity, in accordance with 42 U.S.C. § 17935(b).
Business Associate agrees to comply with the Secretary’s guidance on what constitutes
minimum necessary.
5. Administrative, Physical and Technical Safeguards. Business Associate will develop,
implement, maintain, and use appropriate safeguards to prevent any use or disclosure of
the PHI other than as provided by this Agreement. Business Associate will implement
administrative, physical, and technical safeguards that reasonably and appropriately
protect the confidentiality, integrity and availability of EPHI. Business Associate
acknowledges that the Security Rule provisions regarding administrative, physical, and
technical safeguards, policies and procedures and documentation requirements found in
45 C.F.R. §§ 164.308, 164.310, 164.312 and 164.316 apply to Business Associate in the
same manner as to Covered Entity and Business Associate will fully comply with such
Security Rule provisions.
6. Unusable, Unreadable or Indecipherable Technology. Business Associate will, to the
extent feasible, adopt a technology or methodology specified by the Secretary pursuant to
42 U.S.C. § 17932(h) that renders PHI unusable, unreadable, or indecipherable to
unauthorized individuals.
7. Agents and Sub-contractors. Prior to making any permitted disclosures, Business
Associate will ensure that any of its agents, including subcontractors, to whom it provides
PHI received from, or created or received by, Business Associate on behalf of Covered
Entity agree in writing to be bound by the same privacy and security restrictions and
conditions that apply to Business Associate under this Agreement, including but not
limited to those conditions relating to termination of the contract for improper disclosure.
Further, Business Associate shall implement and maintain sanctions against agents and
subcontractors, if any, that violate such restrictions and conditions. Business Associate
shall terminate any agreement with an agent or subcontractor, if any, who fails to abide
by such restrictions and obligations. Business Associate shall not provide any PHI to any
third party or subcontract any services described in the Services Agreement without
Covered Entity’s express written permission.
8. Reporting Obligations. Business Associate will report, in writing, to Covered Entity any
use or disclosure of PHI that is not authorized by this Agreement, including Breaches of
Unsecured PHI. In addition, Business Associate will report in writing, to Covered Entity
any Security Incident of which it becomes aware that it, its employees, or its agents or
subcontractors experience involving or potentially involving Covered Entity EPHI. The
written notice shall be provided to Covered Entity within five (5) business days of
becoming aware of the non-authorized use or disclosure or Security Incident.
9. Notification to Covered Entity of Breach of Unsecured PHI. Business Associate will
provide written notification to Covered Entity within seventy-two (72) hours of
discovering a Breach of Unsecured PHI. Such notification will identify, to the extent
possible, (1) each individual whose Unsecured Protected Health Information has been, or
is reasonably believed by Business Associate to have been, accessed, acquired or
disclosed during the Breach, (2) the nature of the non-permitted access, use or disclosure,
including the date of the Breach and the date of discovery of the Breach; (3) Protected
Health Information accessed, used or disclosed as part of the Breach (e.g., full name,
social security number, date of birth, etc.); (4) who or what area of Business Associate’s
operation made the non-permitted access, use or disclosure and who received the non-
permitted disclosure; (5) identify what corrective action the Business Associate took or
will take to prevent further non-permitted accesses, uses or disclosures; (6) identify what
Business Associate did or will do to mitigate any deleterious effect of the non-permitted
access, use or disclosure; and (7) provide such other information that is reasonably
available to Business Associate that Covered Entity may request. For purposes of the
preceding sentence, Business Associate will be treated as discovering the Breach on the
first day on which the Breach is known (or by exercising reasonable diligence should
have been known) to Business Associate (including any employee, officer or other agent
of Business Associate other than the person committing the Breach). Whether a Breach
has occurred will be determined in accordance with applicable regulations or other
authoritative guidance issued pursuant to the HITECH Act. A delay in notification of a
Breach that qualifies as a “law enforcement delay” under 45 CFR Section 164.412 will
not be treated as a violation of this Agreement. Business Associate will supplement its
initial notification to Covered Entity with additional information as any additional
information becomes available. Business Associate will implement a reasonable system
for discovery of Breaches.
10. Breach Notification Expenses. Business Associate agrees to indemnify, defend, and hold
harmless Covered Entity and its employees, agents, and representatives from any and all
direct, reasonable and actual costs, settlements, judgments, and expenses incurred by
Covered Entity caused by a Breach of Unsecured Protected Health Information while in
the possession of Business Associate, or its employees, subcontractors or agents. Such
costs will include those related to Breach notifications sent to the affected individuals and
the media, as required by Section 13402(e) of ARRA and 45 CFR Part 164, and any costs
incurred by Covered Entity or its employees, agents or representatives to mitigate
potential harm to individuals from the Breach.
11. Notification to Covered Entity of Use or Disclosure Data. Business Associate will notify
Covered Entity in writing of any actual or suspected use or disclosure of data in violation
of any applicable federal or state laws or regulations or any legal action against Business
Associate arising from an alleged HIPAA violation. Business Associate shall take:
(a) prompt action to correct any such deficiencies; and
(b) any action pertaining to such unauthorized disclosure required by applicable federal
and state laws and regulations.
Business Associate will provide the written notice to Covered Entity within five (5)
business days of becoming aware of the violation or legal action.
12. Mitigation of Harmful Effect. Business Associate agrees to mitigate, to the extent
practicable, any harmful effect that is known to Business Associate of a use or disclosure
of PHI by Business Associate in violation of the requirements of this Agreement
13. Designated Record Sets. Business Associate will make PHI in Designated Record Sets
that are maintained by Business Associate or its agents or subcontractors, if any,
available to Covered Entity or to an individual for inspection and copying within ten (10)
business days of a request by Covered Entity to enable Covered Entity to fulfill its
obligations under the Privacy Rule, including, but not limited to the requirements
concerning access to individuals to PHI found at 45 C.F.R. § 164.524. If Business
Associate maintains Protected Health information in the form of an Electronic Health
Record for any individual, Business Associate agrees to provide, at the request of
Covered Entity or an individual, and in the time and manner designated by Covered
Entity, a copy of such information in an electronic format to that individual or, if clearly,
conspicuously and specifically directed by the individual (or by Covered Entity based on
a clear, conspicuous and specific request of the individual) to transmit an electronic copy
of that information directly to an entity or person designated by the individual. Any fee
charged to the individual for providing such information (or a summary or explanation of
such information) may not exceed Business Associate’s labor costs incurred in
responding to the individual’s request.
14. Amendments to PHI and EPHI. Within ten (10) business days of receipt of a request
from Covered Entity for an amendment of PHI or a record about an individual contained
in a Designated Record Set, Business Associate or its agents or subcontractors, if any,
shall make such PHI available to Covered Entity for amendment and shall incorporate
any such amendment to enable Covered Entity to fulfill its obligations under the Privacy
Rule, including, but not limited to, 45 C.F.R. § 164.526. If an individual requests an
amendment of PHI directly from Business Associate or its agents or subcontractors, if
any, Business Associate must notify Covered Entity in writing within five (5) business
days of the request. Any denial of amendment of PHI maintained by Business Associate
or its agents or subcontractors, if any, shall be the responsibility of Covered Entity. Upon
the approval of Covered Entity, Business Associate shall appropriately amend the PHI
maintained by it, or any agents or subcontractors.
15. Accounting of PHI and EPHI. Within ten (10) business days of notice by Covered Entity
of a request for an accounting of disclosures of PHI, Business Associate and any agents
or subcontractors shall make available to Covered Entity the information required to
provide an accounting of disclosures to enable Covered Entity to fulfill its obligations
under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.528 and any
additional information required under the HITECH Act, including Section 13405(c) if
Business Associate maintains information in the form of an Electronic Health Record,
and any implementing regulations.
(a) If a request for an accounting is made directly to Business Associate or its agents or
subcontractors, Business Associate will notify Covered Entity of the request within
five (5) business days of having received the request. Covered Entity shall either
inform Business Associate to provide the requested information directly to the
individual or request Business Associate to immediately forward the information to
the Covered Entity for compilation and distribution to the individual.
(b) In the case of a direct request for an accounting from an individual related to
treatment, payment or health care operations disclosures through Electronic Health
Records, Business Associate will provide the accounting to the individual in
accordance with 42 U.S.C. § 17935(c) and any regulations adopted subsequent to this
Agreement. Business Associate will confirm with Covered Entity that Covered
Entity provided Business Associate’s name to the individual in response to a request
for an accounting before providing the requested accounting to the individual.
16. Retention of Accounting Documentation. Notwithstanding termination of this
Agreement, Business Associate and any of its agents or subcontractors shall continue to
maintain the information required for purposes of complying with this Section 2.14 for a
period of six (6) years after termination of the Agreement.
17. Business Associate’s Compliance with HHS. Business Associate will make its internal
practices, books and records relating to the use and disclosure of PHI available to the
Secretary of HHS in the time and manner designated by the Covered Entity or the
Secretary of HHS for purposes of determining Covered Entity’s compliance with the
Privacy Rule. Business Associate will notify Covered Entity regarding any PHI that
Business Associate provides to the Secretary of HHS concurrently with providing the
requested PHI to the Secretary of HHS. Upon request by Covered Entity, Business
Associate will provide Covered Entity with a duplicate copy of the requested PHI.
18. Inspection by Covered Entity. Within five (5) business days of a written request by
Covered Entity, Business Associate and its agents or subcontractors, if any, shall allow
Covered Entity to conduct a reasonable inspection of the facilities, systems, books,
records, agreements, policies and procedures relating to the use or disclosure of PHI
pursuant to this Agreement for the purpose of determining whether Business Associate
has complied with this Agreement, the Security Rule and provisions of the Privacy Rule
directly applicable to Business Associate or as deemed necessary by Covered Entity to
determine whether a Breach has occurred. Both Parties agree to the following:
(a) Business Associate will cooperate with Covered Entity’s risk assessment without
unreasonable delay;
(b) Business Associate and Covered Entity will mutually agree in advance upon the
scope, location and timing of such an inspection; and
(c) Covered Entity will protect the confidentiality of all confidential and proprietary
information of Business Associate to which Covered Entity has access during the
course of such inspection.
19. Damages. Business Associate shall be responsible to compensate the affected individual
for any reasonable damages as a result of a Breach caused by Business Associate.
20. No Ownership Rights. Business Associate agrees that Business Associate does not and
will not have any ownership rights in any of the PHI.
21. Additional HITECH Requirements. The additional requirements of Title XIII of
HITECH that relate to privacy and security and that are made applicable with respect to
covered entities are also applicable to Business Associate and by this reference these
requirements are hereby incorporated into this Agreement.
22. Standard Transactions. In conducting any standard transaction that is subject to the
Standard Transaction Regulations (set forth in 45 C.F.R. Part 162) on behalf of Covered
Entity, Business Associate agrees to comply with all requirements of the Standard
Transaction Regulations that would apply to Covered Entity if Covered Entity were
conducting the transaction itself and shall require the same of any subcontractor or agent
involved with the conducts of such Standard Transactions.
23. Limitations on Marketing. Business Associate may not use and disclose PHI for
“marketing,” as defined in 45 C.F.R. § 164.501, unless expressly permitted to do so in the
Services Agreement.
24. Sale of PHI. Except for compensation set forth in the Services Agreement between
Business Associate and Covered Entity, Business Associate shall not receive any direct
or indirect remuneration in exchange for the provision of Protected Health Information.
ARTICLE III
COVERED ENTITY OBLIGATIONS
1. Risk Assessment of Breach by Covered Entity. Covered Entity shall make the final
determination of whether for a Breach of PHI occurred.
2. Restrictions. Covered Entity shall notify Business Associate of any restriction to the use
or disclosure of PHI that Covered Entity has agreed to or must comply with in
accordance with 45 C.F.R. § 164.522 and 42 U.S.C. § 17935(a).
3. Notification of Changes or Revocations of Permission. Covered Entity shall provide
Business Associate with notice of any changes to, revocation of, or permission by
individual to use or disclose PHI, if such changes affect Business Associate’s permitted
uses or disclosures, within a reasonable period of time after Covered Entity becomes
aware of such changes to or revocation of permission.
3.4 Permissible Requests by Covered Entity. Covered Entity shall not request Business
Associate to use or disclose PHI in any manner that would not be permissible under
the Privacy and Security Rules if done by Covered Entity.
ARTICLE IV
TERMINATION
1. Term and Survival. The term of this Agreement shall be effective as of the Effective
Date of this Agreement and continue until terminated by Covered Entity or any
underlying Services Agreement expires or is terminated. Any provision related to the
use, disclosure, access, or protection of PHI or EPHI or that by its terms shall survive
termination of this Agreement shall survive termination.
2. Termination for Breach. A material breach by Business Associate, or its agents or
subcontractors, if any, of this Agreement, as determined by Covered Entity, shall
constitute a material breach of the Services Agreement. As provided for under 45 C.F.R.
§§ 164.314(a)(2)(i)(D) and 164.504(e)(2)(iii), the Covered Entity may immediately
terminate this Agreement and the Services Agreement or, alternatively, the Covered
Entity may choose to provide Business Associate with written notice of the material
breach and an opportunity to cure the material breach or end the violation within thirty
(30) calendar days. If Business Associate becomes aware of a material breach of this
Agreement by Covered Entity, Business Associate shall (1) provide an opportunity for
Covered Entity to cure the breach or end the violation and terminate this Agreement (and
any applicable portion of the Services Agreement between the parties) if Covered Entity
does not cure the breach or end the violation within thirty (30) calendar days, or (2)
immediately terminate this Agreement (and any applicable portion of the Services
Agreement ) if Covered Entity has breached a material term of this Agreement and cure
is not possible.
3. Termination for Violation by Business Associate. Covered Entity may terminate this
Agreement and the Services Agreement effective immediately, if (i) Business Associate
is named as a defendant in a criminal proceeding for a violation of HIPAA, HITECH, or
other security or privacy laws or (ii) there is a finding or stipulation that Business
Associate has violated any standard or requirement of HIPAA, HITECH, or other
security or privacy laws in any administrative or civil proceeding in which Business
Associate is involved.
4. Return or Destruction of PHI.
(a) Upon termination of this Agreement for any reason, Business Associate shall return
or, at Covered Entity’s request, destroy all PHI received from Covered Entity or
created or received by Business Associate on behalf of Covered Entity that Business
Associate still maintains in any form. If Business Associate destroys the PHI,
Business Associate shall certify in writing to Covered Entity that such PHI has been
destroyed. This provision applies to PHI that is in the possession of agents or
subcontractors of Business Associate. Business Associate will retain no copies of the
PHI.
(b) If Business Associate determines that returning or destroying the PHI is not feasible,
Business Associate shall explain to Covered Entity why conditions make the return or
destruction of the PHI not feasible. If Covered Entity agrees that the return or
destruction of PHI is not feasible, Business Associate will retain the PHI, subject to
all of the protections of this Agreement, and limit further uses and disclosures of the
PHI to those purposes that make the return or destruction of the PHI infeasible for so
long as Business Associate maintains the PHI.
(c) If Business Associate determines that it is infeasible to obtain from an agent or
subcontractor any PHI in the possession of the agent or subcontractor or to destroy
the PHI, Business Associate will provide Covered Entity written notification
explaining why obtaining the PHI is infeasible. If Covered Entity agrees that the
return or destruction of PHI is not feasible, Business Associate will require the agent
or subcontractor to extend the protections of this Agreement to the PHI and limit
further uses and disclosures of the PHI to those purposes that make the return or
destruction of the PHI infeasible for so long as the agent or subcontractor maintains
the PHI.
5. Termination of Services Agreement. If this Agreement is terminated for any reason,
Covered Entity will also terminate the Services Agreement between the Parties. This
provision shall supersede any termination provision to the contrary which may be set
forth in the Services Agreement.
ARTICLE V
MISCELLANEOUS
1. Acknowledgement. By affixing their respective signatures below, the Parties certify that
they have read and understand each and every provision in this Agreement. Each Party
certifies that it possesses the authority to enter into the Agreement. The execution and
performance of this Agreement by each Party has been duly authorized by all necessary
laws, resolutions or corporate actions, and the Agreement constitutes valid and
enforceable obligations of each Party in accordance with its terms.
2. Amendment. This Agreement shall not be amended, altered, or modified, except by an
instrument in writing duly executed by the Parties to the Agreement.
3. Assignment. This Agreement may not be assigned by Business Associate without the
prior written consent of Covered Entity.
4. Binding Effect. Subject to provisions hereof restricting assignment, this Agreement shall
be binding upon and shall inure to the benefit of the Parties and their respective
successors and permitted assigns.
5. Change in Law. The Parties agree to take such action as is necessary to amend this
Agreement from time to time as is necessary for Covered Entity and Business Associate
to comply with the requirements of HIPAA and the HITECH Act, and of the regulations
issued pursuant to those laws. If Covered Entity reasonably concludes that an
amendment to this Agreement is needed because of change in federal or state law or
changing industry standards, Covered Entity shall notify Business Associate of such
proposed modification(s), “Legally-Required Modifications”. Such Legally Required
Modifications shall be deemed accepted by Business Associate and this Agreement so
amended, if Business Associate does not, within thirty (30) calendar days following the
date of notice, or within such other time period as may be mandated by applicable state or
federal law, deliver to Covered Entity its written rejection of such Legally-Required
Modifications.
41
6.Compliance with Laws. Business Associate will comply with all applicable federal and
state security and privacy laws, to the extent that such laws apply to Business Associate
or are more protective of individual privacy than HIPAA.
7.Entire Agreement. This Agreement, including attachments, constitutes the entire
Agreement between the Parties with respect to the subject matter hereof, and it
supersedes all prior oral or written agreements, commitments, or understandings with
respect to the matters provided for herein.
8.Execution. This Agreement and any amendments thereto shall be executed in duplicate
copies on behalf of the Parties by an official of each, specifically authorized by its
respective Party to perform such executions. Each duplicate copy shall be deemed an
original, but both duplicate originals together constitute one and the same instrument.
9.Indemnification by Business Associate. Business Associate and any of its subcontractors
and agents shall indemnify, hold harmless and defend Covered Entity and its employees,
officers, directors, agents, and contractors from and against any and all claims, losses,
liabilities, costs, attorneys’ fees, and other expenses incurred as a result of or arising
directly or indirectly out of or in connection with Business Associate’s or its
subcontractors’ or agents’ breach of this Agreement, violation of HIPAA, HITECH or
other applicable law, or otherwise related to the acts or omissions of Business Associate
or its subcontractors or agents.
10.Independent Contractors. This Agreement establishes an independent contractor
relationship between Covered Entity and Business Associate. Nothing in this Agreement
is intended, nor may anything be construed, to create a partner, joint venture
employer/employee, or agent relationship.
11.Limitations on Benefits of this Agreement. Nothing express or implied in this Agreement
is intended to confer, nor shall anything herein confer, upon any person other than
Covered Entity, Business Associate, or their respective successors or assigns, any rights,
remedies, obligations or liabilities whatsoever. It is the express intent of the Parties that
no person or entity other than the Parties shall be entitled to bring any action to enforce
any provision of this Agreement against either of the Parties, and that the Agreement set
forth shall be solely for the benefit of, and shall be enforceable only by, the Parties to this
Agreement or their respective successors and assigns as permitted hereunder.
12.Notices. All notices which are required or permitted to be given pursuant to this
Agreement shall be in writing and shall be sufficient in all respects if delivered
personally, by electronic facsimile (with a confirmation by registered or certified mail
placed in the mail no later than the following day), or by registered or certified mail,
postage prepaid, addressed to a Party as indicated below:
42
If to Business Associate: If to Covered Entity, to:
Waynesboro Community County of Franklin
And Human Services 272 North Second Street
Waynesboro, PA 17268 Chambersburg, PA 17201
Notice shall be deemed to have been given upon transmittal thereof as to communications
which are personally delivered or transmitted by electronic facsimile and, as to
communications made by United States mail, on the third (3rd) day after mailing. The
above addresses may be changed by giving notice of such change in the manner provided
above for giving notice.
13.References. A reference in this Agreement to a section in the Privacy Rule or Security
Rule means the section as in effect or as amended at the time of reference and as
interpreted pursuant to any applicable guidance provided by the Secretary or other
responsible regulatory authority and any applicable case law.
14.Severability. If any part of any provision of this Agreement, or any other agreement,
document or writing given pursuant to or in connection with this Agreement, shall be
held invalid or unenforceable, the holding of invalidity or unenforceability will apply to
the invalid or unenforceable part of the provision only, without in any way affecting the
remaining parts of said provision or the remaining provisions of said Agreement.
15.Sub-Contract. Business Associate may not sub-contract any services under the Services
Agreement without the express written consent of Covered Entity.
16.Waiver. Neither the waiver by either Party of a breach of or a default under any of the
provisions of this Agreement, nor the failure of either of the Parties, on one or more
occasions, to enforce any of the provisions of this Agreement or to exercise any rights or
privilege hereunder shall thereafter be construed as a waiver of any subsequent breach or
default of a similar nature, or as a waiver of any such provisions, rights or privileges
hereunder.
17.Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning
that permits Covered Entity to comply with applicable requirements of HIPAA HITECH
Act, the Privacy Rule and the Security Rule. Any conflict between a provision of the
Services Agreement and this Agreement regarding the subject matter of this Agreement,
shall be resolved in favor of this Agreement
See signatures on next page
September 16
43