Loading...
HomeMy WebLinkAboutPlanning - Franklin County AGREEMENT BETWEEN Emergency Solutions Grant (ESG) Sub-recipient Agreement BETWEEN County of Franklin AND Waynesboro Community and Human Services 116 Walnut Street Waynesboro, PA 17268 AGREEMENT THIS AGREEMENT is made by and between COUNTY OF FRANKLIN, HEREAFTER REFERRED TO AS THE “COUNTY” AND WAYNESBORO COMMUNITY AND HUMAN SERVICES, HEREINAFTER REFERRED TO AS THE “ORGANIZATION”. WHEREAS, the Stewart B. McKinney Homeless Assistance Act (passed July 1987) authorized the use of the Emergency Solutions Grant (ESG) Program; and WHEREAS, the County has applied to the Commonwealth of Pennsylvania for funds from the ESG Program, and the Commonwealth has awarded ESG Program funds to the County; and WHEREAS, The County may finance certain activities and projects as part of the ESG Program for non-profit organizations within the County; and WHEREAS, the Organization desires the County to finance certain services and activities with ESG Program funds; and WHEREAS, the Organization has the legal power to implement said services and activities; I. TERM: The effective date is the date the fully executed contract is sent to the Organization and ends on June 30, 2027, subject to the other provisions herein, unless terminated earlier by either party in accordance with the termination provisions of this agreement. II. TERMINATION: Either party may terminate this agreement by providing the other party sixty (60) days advance written notice at the address set forth below: THE COUNTY: County of Franklin 272 North Second Street Chambersburg, PA 17201 WITH COPY TO: Franklin County Solicitor 272 North Second Street Chambersburg, PA 17201 ORGANIZATION: Waynesboro Community and Human Services 116 Walnut Street Waynesboro, PA 17268 Attention: Morgan Hovermale III. CONTRACTOR/SUBRECIPIENT DETERMINATION: In accordance with Uniform Guidance 2 CFR Part 200, Waynesboro Community and Human Services is determined to be a Subrecipient. Subrecipient acknowledges that payments for Services under this Agreement are federal funds and as such Subrecipient shall be bound by the requirements for Subrecipients as outlined in Uniform Guidance. If Subrecipient is contributing toward the general contract cost, Subrecipient certifies that the federal funds to be used under this Agreement do not replace or supplant in any way state, local, or private funds used for already existing services. IV. INVOICING PROCEDURES: The County will allocate a maximum of $43,452.60 for Rapid Rehousing, Homelessness Prevention, HMIS reporting and administrative funds from the state ESG Program as described in the budget Appendix A. Administration expenses are restricted to 3.75% of the total invoice per month. If administrative reimbursement is requested, the staff’s name, title and a brief explanation of the duties performed that were included during the said time frame. No funds can be incurred until the COUNTY’s environmental review is completed and approved by DCED. The Organization shall match the ESG Program funds with an equal amount of funds from sources other than the ESG Program. Funds used for the matching requirement must be provided with each invoice submitted and cannot be the same funds used to match other ESG Program funds received by the Organization from any other entity. Upon submission of MONTHLY invoices by the Organization for cost incurred and directly related to services and activities provided by the Agreement, the County shall reimburse the Organization to the maximum approved ESG budget. Submitted invoices for reimbursement shall be limited to the following: A. Should the County find services, activities, or expenses to be unacceptable, reimbursement shall be withheld and reasons for each withholding shall be sent to the Organization. Satisfactory resolution of the County’s objections may result in the processing of the request for reimbursement. B. All ESG Program funds shall be released to the Organization only as a reimbursement for actual costs incurred for services and activities provided during the time frame of the submitted invoice. C. The Organization certifies that it will not accumulate ESG Program funds in reserve. Any interest earned on reimbursements that exceed actual costs incurred during the time of the agreement shall be governed by the ESG Program. D. The Organization must be able to certify its compliance with provisions of this Agreement at all times by maintaining appropriate supporting financial documentation and making said documentation available to the County at reasonable times. E. The Organization must submit supporting documentation of matching funds that equal or exceed the amount of funds requested. V. INVOICING INSTRUCTIONS: A. Payments to be made MONTHLY upon submission of itemized invoices for services rendered pursuant to this agreement. The Organization’s invoices must be received within fifteen (15) days of the close of each calendar month. B. All invoices shall to be sent electronically to Lin Xu, Franklin County Senior Accountant at lxu@franklincountypa.gov. Invoices shall be itemized in accordance with the date submitted. VI. WORK STATEMENT: ORGANIZATION shall provide the work, services, and activities as set forth and described in Appendix A and Appendix B, and in accordance with the applicable ESG requirements. VII. APPENDICES: The following attached Appendices are incorporated into and made a part of this contract: Appendix A - ESG Budget Appendix B - Work Statement / Program Specific Tasks Appendix C - Audit Requirements Appendix C - Attachment 1 / Federal Awards Appendix D - Business Associate Agreement VIII. CONTRACT CONDITIONS: A. STANDARD GENERAL TERMS AND CONDITIONS ORGANIZATION agrees to abide by and comply with the service requirements, all reporting requirements, and contract conditions as provided herein. 1. Modification: The COUNTY reserves the right to amend this Agreement at any time pursuant to amendments in the ESG Grant Agreement with the Department of Community and Economic Development (DCED). The ORGANIZATION will be notified in advance of any such Contract language amendments. Any alteration, variation, modification, or waiver of a provision of this Agreement shall be valid only when reduced to writing, duly signed by the parties of this Agreement and attached to the original of the Agreement. 2. Contract Construction: The provisions of this Agreement shall be construed in accordance with the Laws of the Commonwealth of Pennsylvania. ORGANIZATION shall include all of the performance and regulatory provisions of this Agreement in every sub-contract under this Agreement so that the contractual provisions also bind each sub-ORGANIZATION. ORGANIZATION agrees to comply with all applicable requirements of the ESG Grant Agreement with DCED. ORGANIZATION shall comply with all applicable state and federal regulations and laws. All documents referenced in this paragraph are incorporated herein by reference. Each provision enumerated herein or incorporated by reference hereto shall be deemed to be material and any breach thereof may be considered a material breach of this Agreement. 3. Independent ORGANIZATION: The parties hereto agree that the ORGANIZATION, and any agents and employees of the ORGANIZATION, in the performance of this Contract, shall act in an independent contractor capacity and not as officers, employees, or agents of the COUNTY or the Commonwealth of Pennsylvania. The ORGANIZATION shall be responsible for the payment of all payroll taxes and shall provide and be responsible for all premiums for public liability, property damage, and workers’ compensation insurance, insuring as they may appear, the interests of the COUNTY and ORGANIZATION against any and all claims which may arise out of ORGANIZATION’s operations pursuant to this Agreement. 4. Sub-Contracts: Except for those sub-contracts specifically authorized by this Agreement, ORGANIZATION shall not enter into sub-contracts for any work contemplated under this Agreement without obtaining prior written approval of the COUNTY. Provided, however, notwithstanding the foregoing, unless otherwise provided herein, such prior written approval shall not be required for the purchase by ORGANIZATION of articles, supplies, equipment and services which are both necessary for and merely incidental to the performance of the work required under this Agreement. No provision of this clause and no approval by the COUNTY of any sub-contract shall be deemed in any event in any manner to provide for the incurrence of any obligation of the COUNTY in addition to the total agreed upon contract amount. 5. Availability of Information: ORGANIZATION agrees that all information obtained during the period of this Agreement by ORGANIZATION through work governed by this Agreement shall be made available to the COUNTY and DCED immediately upon demand. 6. Program Records: ORGANIZATION agrees to maintain program records and program statistical records required by the COUNTY and DCED and agrees to a program and facilities review, including meetings with consumers, review of service records, review of service policy and procedural issuances, review of staffing ratios and job descriptions, and meetings with any staff directly or indirectly involved in the provision of services. ORGANIZATION agrees to maintain books, records, documents and other evidence in accordance with accounting procedures and practices which meet generally accepted accounting principles. 7. Record Retention Requirements: A. ORGANIZATION agrees to maintain books, records, documents and other evidence pertaining to the costs and expense incurred pursuant to this Agreement (hereinafter collectively referred to as “the records”) in such detail as will properly reflect all costs, direct and indirect, of labor, materials, equipment, supplies and services and other costs, and expenses of whatever nature for which reimbursement is claimed under the provisions of the Agreement. ORGANIZATION agrees to maintain books, records, documents and other evidence and accounting procedures and practices that comply with generally accepted accounting principles (GAAP) and all applicable State and Federal regulations. B. ORGANIZATION agrees to make available at the office of the ORGANIZATION at all reasonable times during the term of this Agreement, any of the records for inspection, audit or reproduction by any authorized representative of the Federal, State or County governments. C. ORGANIZATION shall preserve and make available its records for a period of seven (7) years from the date of final payment by the COUNTY to ORGANIZATION, and for such period, if any, as is required by applicable statute, by any other paragraph of this Agreement, or by sub-paragraphs (1) or (2) below. 1) If this Agreement is completely or partially terminated, the records relating to the work terminated shall be preserved and made available for a period of seven (7) years from the date of any resulting final payment. 2) Records which relate to litigation or the settlement of claims arising out of the performance of this Agreement, or costs and expenses of this Agreement as to which exception has been taken by the auditors, shall be retained by the ORGANIZATION until such litigation, claims, or exceptions have been disposed of. 8. Confidentiality, Sensitive Documents and Information: A. ORGANIZATION shall maintain the confidentiality of medical records of individuals served by ORGANIZATION under this Agreement except to disclose such confidential information to DCED and/or the COUNTY for purposes of consultation or DCED’s and/or the COUNTY’s monitoring of this Agreement. The parties shall execute a Business Associate Agreement, as required by law and requested by COUNTY. B. ORGANIZATION shall not publish or otherwise disclose, except to DCED and/or the COUNTY, and except matters of public record, any information or data obtained hereunder from private individuals, organizations, or public agencies, in a publication whereby the information or data furnished by or about any particular person or establishment can be identified, except with the informed consent of such person or establishment. C. ORGANIZATION shall not release any sensitive documents or information without the prior written approval of DCED and/or the COUNTY. The term “sensitive documents or information” shall mean a document or information that contains the description, design, operational plan, or other vital information about a critical facility or infrastructure located in Pennsylvania and bordering states (e.g., nuclear power plants, hazardous chemical plant, oil refinery, bridge, dam, tunnel, etc.), or contains information about the operational protocols or emergency response capabilities of state and local agency personnel, the content of which could be used by a terrorist or enemy of the United states to plan an attack upon a critical facility located in Pennsylvania and bordering states or engages in other activities that could cause death or injury to fire, police, medical, military, or other emergency response personnel, public officials, or the general public. 9. Default and Termination: A. The COUNTY may, by written notice of default to ORGANIZATION, immediately terminate upon such terms as said notice shall set forth, the whole or any part of this Agreement in any one of the following circumstances: 1) If ORGANIZATION fails to perform the contracted services within the time specified herein or any extension thereof; or 2) If ORGANIZATION fails to perform any of the other provisions of this Agreement, and does not cure such failure within the period of time as determined by the COUNTY and authorized in writing to ORGANIZATION after receipt of notice from the COUNTY specifying such failure. B. In the event the COUNTY terminates this Agreement as provided herein, ORGANIZATION shall transfer and deliver to the COUNTY all partially completed reports or other documentation as ORGANIZATION has produced under this Agreement. C. Should ORGANIZATION become insolvent, or if proceedings in bankruptcy be instituted by or against ORGANIZATION, the remaining or unexpired portion of this Agreement may be terminated. D. It is further agreed that in the event funding to the COUNTY from state or federal funding sources is not obtained and continued at the anticipated level, the COUNTY may exercise one of the following options: 1) Issue a written Notice of Termination of this Agreement to ORGANIZATION effective upon a specified date. E. After receipt of Notice of Termination, unless otherwise directed in writing by the COUNTY, ORGANIZATION shall: 1) Stop work under this Agreement on the date and to the extent specified in the Notice of termination. 2) Terminate all orders, contracts, and subcontracts to the extent that they relate to the performance of work terminated by the Notice of Termination. 3) Settle all outstanding liabilities and all claims arising out of such termination. Notwithstanding the above, ORGANIZATION shall not be relieved of liability to the COUNTY for damages sustained by the COUNTY by virtue of the performance of ORGANIZATION. F. The rights and remedies of the COUNTY provided in this Paragraph shall not be exclusive and are in addition to any other rights and remedies provided by law or under this Agreement. 10. Equal Employment Opportunity: A. ORGANIZATION shall not discriminate against any employee, applicant for employment, independent ORGANIZATION or any other person because of race, color, religious creed, ancestry, national origin, age, or sex. ORGANIZATION shall take affirmative action to ensure that applicants are employed, and that employees or agents are treated during employment, without regard to their race, color, religious creed, ancestry, national origin, age, or sex. Such affirmative action shall include, but is not limited to: employment, upgrading, demotion or transfer, recruitment or recruitment advertising; layoff or termination; rates of pay or other forms of compensation; and selection for training. ORGANIZATION shall post in conspicuous places, available to employees, agents, applicants for employment, and other persons. B. ORGANIZATION shall, in advertisements or requests for employment placed by it or on its behalf; state that all qualified applicants will receive consideration for employment without regard to race, color, religious creed, ancestry, national origin, age, or sex. C. ORGANIZATION shall send each labor union or workers’ representative with which it has a collective bargaining agreement or other contract or understanding, a notice advising said labor union or workers’ representative of its commitment to this nondiscrimination clause. Similar notice shall be sent to every other source of recruitment regularly utilized by ORGANIZATION. D. It shall be no defense to a finding of noncompliance with this nondiscrimination clause that ORGANIZATION had delegated some of its employment practices to any union, training program, or other source of recruitment, which prevents it from meeting its obligations. However, if the evidence indicates that the ORGANIZATION was not on notice of the third- party discrimination or made a good faith effort to correct it; such factor shall be considered in mitigation in determining appropriate sanction. E. Where the practices of a union or training program or other source of recruitment will result in the exclusion of minority group persons, so that ORGANIZATION will be unable to meet its obligations under this nondiscrimination clause, ORGANIZATION shall then employ and fill vacancies through other nondiscriminatory employment procedures. F. ORGANIZATION shall comply with all state and federal laws prohibiting discrimination in hiring or employment opportunities. In the event of ORGANIZATION’s noncompliance with the nondiscrimination clause of this Agreement or with any such laws, this Agreement may be terminated or suspended, in whole or in part, and ORGANIZATION may be declared temporarily ineligible for further Commonwealth contracts, and other sanctions may be imposed and remedies invoked. G. ORGANIZATION shall furnish all necessary employment documents and records to, and permit access to its books, records, and accounts by, the Department and the Office of Administration, Bureau of Affirmative Action, for purposes of investigation to ascertain compliance with the provisions of this clause. If ORGANIZATION does not possess documents or records reflecting the necessary information requested, it shall furnish such information on reporting forms supplied by DCED. H. ORGANIZATION shall actively recruit minority sub-ORGANIZATIONs or sub-ORGANIZATIONs with minority representation among their employees. I. ORGANIZATION shall include the provisions of this nondiscrimination clause in every sub-contract, so that such provisions will be binding on each sub-ORGANIZATION. J. ORGANIZATION obligations under this clause are limited to the ORGANIZATION’s facilities within Pennsylvania, or where the contract is for purchase of goods manufactured outside of Pennsylvania, the facilities at which such goods are actually produced. 11. Equal Opportunity for the Handicapped: ORGANIZATION agrees to abide by Section 504 of the Rehabilitation Act of 1973, as amended (Public Law 93-112, 29 U.S.C. Section 794, as amended) and implementing Federal regulations. ORGANIZATION assures that any benefits, services, or employment, available through ORGANIZATION to the public by way of this Agreement’s funds, shall not be denied persons with handicaps who are otherwise qualified or eligible for the benefits, services, or employment available as a result of this Agreement. ORGANIZATION agrees to indemnify and hold harmless the Commonwealth of Pennsylvania and THE COUNTY from all losses, damages, expenses, claims, demands, suits, and actions, including reasonable attorneys’ fees and court costs, brought by any party against the Commonwealth of Pennsylvania and/or the COUNTY as a result of ORGANIZATION’s failure to comply with the provisions of the above paragraph. 12. Provisions Concerning the Americans with Disabilities Act: During the term of this Agreement, ORGANIZATION agrees as follows: Pursuant to federal regulations promulgated under the authority of the Americans With Disabilities Act, 28 C.F.R. Section 35.101 et seq., ORGANIZATION understands and agrees that no individual with a disability shall, on the basis of the disability, be excluded from participation in this Agreement or from activities provided for under this Agreement. As a condition of accepting and executing this Agreement, ORGANIZATION agrees to comply with the “General Prohibitions Against Discrimination,” 28 C.F.R. Section 35.130, and all other regulations promulgated under Title II of The Americans With Disabilities Act which are applicable to the benefits, services, programs, and activities provided by the Commonwealth of Pennsylvania through contracts with outside ORGANIZATIONs. ORGANIZATION agrees to indemnify and hold harmless the Commonwealth of Pennsylvania and THE COUNTY from all losses, damages, expenses, claims, demands, suits, and actions, including reasonable attorneys’ fees and court costs, brought by any party against the Commonwealth of Pennsylvania and/or the COUNTY as a result of ORGANIZATION’s failure to comply with the provisions of the above paragraph. 13. Nondiscrimination/Sexual Harassment Clause: During the term of this Agreement, ORGANIZATION agrees as follows: A. ORGANIZATION and any sub-ORGANIZATIONs shall comply with any federal, state, or local law, and the provisions of this Paragraph, as applicable, pertaining to nondiscrimination and equal opportunity in regard to its employees, applicants for employment, independent ORGANIZATIONs, or any other person. ORGANIZATION represents that it is presently in compliance with and will maintain compliance with all applicable federal, state, and local laws and regulations relating to nondiscrimination and sexual harassment. ORGANIZATION further represents that it has filed a Standard Form 100 Employer Information Report (“EEO-1”) with the U.S. Equal Employment Opportunity Commission (“EEOC”) and shall file an annual EEO-1 report with the EEOC as required for employers subject to Title VII of the Civil Rights Act of 1964, as amended, that have 100 or more employees and employers that have federal government contracts or first-tier subcontracts and have 50 or more employees. ORGANIZATION shall, upon request and within the time periods requested by the Commonwealth, furnish all necessary employment documents and records, including EEO-1 reports, and permit access to their books, records and accounts by the granting agency and the Bureau of Small Business Opportunities (BSBO), for the purpose of ascertaining compliance with the provisions of this Nondiscrimination/Sexual Harassment Clause. B. In the hiring of any employees for the manufacture of supplies, performance of work, or any other activity required under this Agreement, ORGANIZATION or any person acting on behalf of ORGANIZATION shall not by reason of gender, race, creed, color, religion, age, sexual preference, handicap, or national origin discriminate against any citizen of this Commonwealth who is qualified and available to perform the work to which the employment relates. In the hiring of any employees for the manufacture of supplies, performance of work, or any other activity required under this Agreement, ORGANIZATION or any person acting on behalf of ORGANIZATION shall not discriminate in violation of the Pennsylvania Human Relations Act (PHRA) and applicable Federal Law against any citizen of this Commonwealth who is qualified and available to perform the work to which the employment relates. C. Neither ORGANIZATION nor any person on ORGANIZATION’s behalf shall in any manner discriminate against or intimidate any employee involved in the manufacture of supplies, the performance of work or any other activity required under this Agreement on account of gender, race, creed, color, religion, age, sexual preference, handicap, or national origin. Neither ORGANIZATION nor any person on ORGANIZATION’s behalf shall in any manner discriminate in violation of the Pennsylvania Human Relations Act (PHRA) and applicable Federal Law against or intimidate any employee. D. ORGANIZATION shall not discriminate by reason of gender, race, creed, color, religion, age, sexual preference, handicap, or national origin against any sub ORGANIZATION or supplier who is qualified to perform the work to which this Agreement relates. ORGANIZATION shall not discriminate in violation of the Pennsylvania Human Relations Act (PHRA) and applicable Federal Law against any sub ORGANIZATION or supplier who is qualified to perform the work to which this Agreement relates. E. ORGANIZATION shall establish and maintain a written sexual harassment policy and shall inform employees of the policy. The policy must contain a notice that sexual harassment will not be tolerated and employees who practice it will be disciplined. F. ORGANIZATION shall ensure that any services or benefits available to the public or other third parties by way of this Agreement shall not be denied or restricted for such persons due to race, creed, color, religion, sex, sexual preference, age, handicap, or national origin (national origin protections include persons who are limited English proficient) consistent with the provisions of Title VI of the Civil Rights Act of 1964, Section 504 of the Rehabilitation Act of 1973, Title II of the Americans with Disabilities Act and The Age Discrimination Act of 1975 as well as applicable provisions of the Omnibus Reconciliation Act of 1981. G. ORGANIZATION shall furnish all necessary employment documents and records and permit access to its books, records, and accounts by THE COUNTY and the Department of General Services’ Bureau of Contract Administration and Business Development for purposes of investigation to ascertain compliance with the provisions of this Nondiscrimination/Sexual Harassment Clause. If ORGANIZATION or any sub ORGANIZATION does not possess documents or records reflecting the necessary information requested, it shall furnish such information on reporting forms supplied by the Department or the Bureau of Contract Administration and Business Development. H. The Commonwealth may direct the COUNTY to cancel or terminate this Agreement, and all money due or to become due under this Agreement may be forfeited for a violation of the terms and conditions of this Nondiscrimination/Sexual Harassment Clause. In addition, the agency may proceed with debarment or suspension and may place ORGANIZATION in the ORGANIZATION Responsibility File. I. ORGANIZATION shall include the provisions of this Nondiscrimination/Sexual Harassment Clause in every subcontract so that such provisions will be binding upon each sub ORGANIZATION. J. ORGANIZATION’S and all sub-ORGANIZATION’S obligations pursuant to these provisions are ongoing from and after the effective date of this Agreement through the termination date thereof. Accordingly, ORGANIZATION shall have an obligation to inform the COUNTY if, at any time during the term of this Agreement, it becomes aware of any actions or occurrences that would result in violation of these provisions. 14. Drug Free Workplace Act of 1988 (P.L. 100-690): By signing this Agreement, the ORGANIZATION, certifies to THE COUNTY, as a condition precedent, that ORGANIZATION is in compliance with the Drug- Free Workplace Act, 41 U.S.C. § 701, et. seq. ORGANIZATION agrees and certifies that it shall provide a drug-free workplace in accordance with the Act. 15. ORGANIZATION Responsibility Provisions: A. ORGANIZATION must certify, in writing, for itself and all its sub ORGANIZATION, that as of the date of its execution of this Agreement, that ORGANIZATION is not under suspension or debarment by the Commonwealth or any governmental entity, instrumentality, or authority and, if ORGANIZATION cannot so certify, then it agrees to submit, a written explanation of why such certification cannot be made. B. ORGANIZATION must also certify, in writing, that as of the date of the execution of this Agreement it has no tax liabilities or other Commonwealth obligations. C. ORGANIZATION’s obligations pursuant to these provisions are ongoing from and after the effective date of this Agreement through the termination date thereof. Accordingly, the ORGANIZATION shall have an obligation to inform the COUNTY if, at any time during the term of this Agreement, it becomes delinquent in the payment of taxes, or other Commonwealth obligations, or if it is suspended or debarred by the Commonwealth, the federal government, or any other state or governmental entity. Such notice shall be made within 15 days of the date of suspension or debarment. D. The failure of ORGANIZATION to notify the COUNTY of its suspension or debarment by the Commonwealth, any other state, or the federal government shall constitute an event of default under this Agreement. E. ORGANIZATION agrees to reimburse the COUNTY and DCED for the reasonable costs of investigation incurred by the Office of State Inspector General for investigations of ORGANIZATION’s compliance with the terms of this Agreement, which results in the suspension or debarment of ORGANIZATION. Such costs shall include, but shall not be limited to, salaries of investigators, including overtime; travel and lodging expenses; and expert witness and documentary fees. ORGANIZATION shall not be responsible for investigative costs for investigations that do not result in ORGANIZATION’s suspension or debarment. F. ORGANIZATION may obtain a current list of suspended and debarred Commonwealth ORGANIZATIONs by either searching the Internet at www.dgs.state.pa.us/ or by contacting the: Department of General Services Office of Chief Counsel 603 North Office Building Harrisburg, Pennsylvania 17125 Telephone No: (717) 783-6472 16. Reporting Requirements Under The Federal Funding Accountability and Transparency Act (FFATA): A. Registration and Identification Information ORGANIZATION must maintain current registration in the Central ORGANIZATION Registration (www.ccr.gov) at all times during which they have active Federal awards funded pursuant to this Agreement. A Dun and Bradstreet Data Universal Numbering System (DUNS) Number (www.dnb.com) is one of the requirements for registration in the Central ORGANIZATION Registration. ORGANIZATION must provide its assigned DUNS number, and DUNS + 4 numbers if applicable, to the COUNTY along with ORGANIZATION’s return of the signed Agreement. The COUNTY will not process this Agreement until such time that the ORGANIZATION provides this information. B. Primary Location ORGANIZATION must provide to the COUNTY the primary location of performance under this Agreement, including the City, State, and Zip+4. If performance is to occur in multiple locations, then ORGANIZATION must list the location where the greatest amount of the funding is to be expended pursuant to this Agreement. ORGANIZATION must provide this information to the COUNTY along with the ORGANIZATION’s return of the signed Agreement. The COUNTY will not process this Agreement until such time that ORGANIZATION provides this information. C. Compensation of Officers ORGANIZATION must provide to THE COUNTY the names and total compensation of the 5 most highly compensated officers of the entity if— 1) the entity in the preceding fiscal year received: (a) 80 percent or more of its annual gross revenues in Federal awards; and, (b) $25,000,000 or more in annual gross revenues from Federal awards; and, 2) the public does not have access to information about the compensation of the senior executives of the entity through periodic reports filed under Section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. Sections 78m(a), 78o(d)) or Section 6104 of the Internal Revenue Code of 1986 (26 U.S.C. Section 6104). If ORGANIZATION does not meet the conditions listed above, then it must specifically affirm to the COUNTY that the requirements of this clause are inapplicable to ORGANIZATION. ORGANIZATION must provide information responding to this question along with the ORGANIZATION’s return of the signed Agreement. The COUNTY will not process this Agreement until such time that ORGANIZATION provides such information in response to this question. 17. MONITORING: ORGANIZATION agrees to permit on-site monitoring by the DCED-assigned COUNTY for administrative and program performance. The ORGANIZATION will allow the COUNTY staff to access any information requested in order to verify adherence to this Agreement. The ORGANIZATION will allow the COUNTY to monitor for all services provided on behalf of all the COUNTYs who contract with the provider. The ORGANIZATION will allow the COUNTY to monitor all documentation required based on the tool provided by the COUNTY. 18. INDEMNIFICATION: ORGANIZATION and its subcontractors shall release, hold harmless, and indemnify the COUNTY, its officers, elected officials, agents, representatives, and employees from and against any and all claims, liabilities, demands, or causes of action, including reasonable attorneys’ fees and court costs, arising out of the actions of the ORGANIZATION, its subcontractors, agents, servants, and/or anyone acting under the ORGANZIATION’S control and/or the ORGANIZATION’S direction, and employees as it relates to the provision of services provided by the ORGANIZATION pursuant to this agreement and with respect to the performance of the requirements of the AGREEMENT. ORGANIZATION and its subcontractors assume full responsibility for all of their acts or omissions which violate the ORGANIZATION’S or subcontractors’ obligations and duties under this AGREEMENT. The ORGANIZATION shall defend any lawsuit commenced against the COUNTY and shall pay any judgments and costs connected with such proceeding which are based upon the acts or omissions of the ORGANIZATION or its subcontractors as it relates to the provision of services provided by the ORGANIZATION pursuant to this agreement and with respect to the performance of the requirements of this AGREEMENT. The COUNTY does not in any manner waive its rights and immunities provided by applicable law and/or regulation by entering into this AGREEMENT. 19. INSURANCE: ORGANIZATION will maintain a minimum, the following insurance coverage’s and provide evidence of such insurance in the form of a Certificate of Insurance, which names the COUNTY as the certificate holder and provides a 30 day notice of cancellation or non-renewal; $1,000,000 General Liability, per occurrence/aggregate, and naming the County as an Additional Insured. $1,000,000 Professional Liability, per occurrence. $1,000,000 Automobile Liability Combined Single Limit $25,000 Employee Dishonesty Bond Statutory Limits, Workers’ Compensation and Employers’ Liability This Agreement is a binding contract between the COUNTY and ORGANIZATION. COUNTY INFORMATION Name: Franklin County Business Address: 272 North Second Street Chambersburg, PA 17201 Phone: (717) 709-7218 Contact Person: Melodie Hoff Email: mshoff@franklincountypa.gov BILLING INFORMATION Billing Information: Franklin County Administration Building 272 North Second Street, Chambersburg, PA 17201 Phone: (717) 261-3101 Contact Person: Lin Xu Email: lxu@franklincountypa.gov ORGANIZATION INFORMATION Name: Waynesboro Community and Human Services Address: 116 Walnut Street Waynesboro, PA 17268 Phone: (717) 762-6941 Contact Person: Morgan Hovermale Email: mhovermale@wchs-pa.org See signatures on next page September 16 APPENDIX A EMERGENCY SOLUTIONS BUDGET This ESG Payment Agreement shall be effective from the date executed agreement is sent to the Organization through June 30, 2027. RAPID REHOUSING HOMELESSNESS PREVENTION HMIS ADMIN TOTAL BUDGET $43,452.60 APPENDIX B WORK STATEMENT PROGRAM SPECIFIC TASKS 1. The ORGANIZATION will use ESG Program funds to support the administrative costs for supporting the Emergency Solutions Grant, as well as rapid rehousing and HMIS data entry. The ORGANIZATION is required to enter all data into HMIS. Administrative costs are restricted to 3.75% of the total invoiced amount per month. If administrative reimbursement is requested, the staff’s name, title and a brief explanation of the duties performed that was included during the said time frame. 2. The ORGANIZATION will follow the PA CoC Written Standards and any addendums moving forward. 3. The ORGANIZATION shall develop a formal process for the termination of ESG Program assistance to any individual or family who violates any requirements of the ESG Program. The process shall recognize the right of the individuals affected and may include a hearing. 4. The ORGANIZATION shall provide all information necessary for the COUNTY to submit required reports to the Department of Community and Economic Development. 5. The ORGANIZATION’S Executive Director and/or Director shall attend the Connect to Home Coordinated Entry by name monthly meeting every month either in person or via phone conference. 6. The ORGANIZATION will notify the Grants Director of Franklin County of any and all changes in status of grant-funded elements including, but not limited to: assets such as land, building, improvements, equipment, furnishings and vehicles; program services, requirements, objectives; individuals such as staff and participants; and subcontractors or sub-recipient agencies. Incidents that may lead to media publicity of any kind, involve law enforcement, pose risk of becoming a liability and/or may affect funding in any way must be reported immediately. APPENDIX C AUDIT REQUIREMENTS This Appendix is intended to provide general audit requirement instruction to ORGANIZATION as a recipient of funds issued by the COUNTY, from funds initiated by DCED. ORGANIZATION must comply with all applicable federal and state grant requirements including The Single Audit Act Amendments of 1996; 2 CFR Part 200 as amended; and any other applicable law or regulation, and any amendment to such other applicable law or regulation which may be enacted or promulgated by the federal government. Audit requirements may be either a Federal mandate or a DCED mandate. The audit require- ments that are applicable to this Agreement are determined by the source(s) of the funding as described in the following Sections of this document: • Section II – Contracts/grants funded 100 percent by federal funds • Section III – Contracts/grants funded 100 percent by state funds • Section IV – Contracts/grants funded by federal and state funds Audit exemption conditions are described in Section V of this document. Additionally, general audit provisions that are applicable to ALL Agreements are described in Section VI. II. CONTRACTS/GRANTS FUNDED 100 PERCENT BY FEDERAL FUNDS - (Federally Mandated Audits) A. General Requirements If ORGANIZATION is a local government or non-profit organization and expends total federal awards of $1,000,000 or more during its fiscal year, received either directly from the Federal government or indirectly from a recipient of Federal funds, ORGANIZATION is required to provide the appropriate single or program-specific audit in accordance with the provisions outlined in 2 CFR Part 200.501. If ORGANIZATION expends total Federal awards of less than the threshold established by 2 CFR 200.501, it is exempt from Federal audit requirements for that year, but records must be available for review or audit by appropriate officials (or designees) of the Federal agency, pass-through entity, and Government Accountability Office (GAO). If ORGANIZATION is a for-profit entity, it is not subject to the auditing and reporting requirements of 2 CFR Part 200, Subpart F – Audit Requirements (Subpart F). However, DCED is responsible for establishing requirements, as necessary, to ensure compliance by for-profit ORGANIZATIONs/grantees. To accomplish this, THE COUNTY reserves the right to perform monitoring during the Agreement and require the following at its discretion: 1) Pre-award audits; and 2) Post-award audits. The post-award audits may be in the form of a financial audit conducted in accordance with Government Auditing Standards, or a single audit report or a program-specific audit report in accordance with Subpart F. However, if a post-award audit is required by DCED, it must be directly submitted to THE COUNTY. Only single audit reports for local governmental and non-profit ORGANIZATIONs/grantees are electronically submitted to the Federal Audit Clearinghouse. In instances where a federal program-specific audit guide is available, the audit report package for a program-specific audit should be prepared in accordance with the appropriate audit guide, Government Auditing Standards, and Subpart F. B. Additional Components of the Single Audit Reporting Package In addition to the requirements of Subpart F, DCED requires that the single audit report packages include the following additional components in the Schedule of Expenditures of Federal Awards (SEFA), or supplemental schedules: 1) A breakdown of federal funds passed through DCED by federal grantor, Catalog of Federal Domestic Assistance (CFDA) number, CFDA name and state program name (if different from CFDA name), state program year, and state contract/grant number (if applicable); 2) Contract/grant period beginning and ending dates for federal funds passed through DCED, by contract/grant; 3) Program or award amount for each DCED contract/grant; 4) Total received during the year for each DCED contract/grant; 5) Accrued or deferred revenue at the beginning of the year for each DCED contract/grant; 6) Revenue recognized during the year for each DCED contract/grant; 7) Accrued or deferred revenue at the end of the year for each DCED contract/grant. C. Submission of the Audit Report All recipients of funds required to complete a federally mandated audit must submit an electronic copy of the data collection form and the audit reporting package to the Federal Audit Clearinghouse, which shall include the elements outlined in Subpart F. D. Submission of the Federal Audit Clearinghouse Confirmation The ORGANIZATION must electronically send a copy of the confirmation from the Federal Audit Clearinghouse to the resource account established by the Office of the Budget, Bureau of Audits at RA-BOASingleAudit@pa.gov. Note that this is only applicable to recipients directly funded by the Commonwealth through a contract or grant agreement with an agency of the Commonwealth; or any administrative agent utilized by the ORGANIZATION/grantee to manage the disbursement and contracting of funds for the ORGANIZATION/grantee. Instructions for confirmation of audit material submission to the Federal Audit Clearinghouse by sub-ORGANIZATIONs or sub-grantees would be provided by the entity contractually engaged with that sub-ORGANIZATION or sub- grantee. III. CONTRACTS/GRANTS FUNDED 100 PERCENT BY STATE FUNDS - (Department Mandated Audits) A. General Requirements The ORGANIZATION shall have a program-specific audit performed when it expends $1,000,000 or more of state funds under this contract/grant during the state fiscal year (i.e., July 1 through June 30), or unless notified in writing by DCED prior to the termination of the applicable audit period that the audit requirement has been waived. If the ORGANIZATION/grantee’s contract/grant or any successive period is for a period shorter than the state fiscal year, but the contract/grant amount expended by the ORGANIZATION/grantee during said period includes $1,000,000 or more of state funds, the ORGANIZATION/grantee is also required to have a program-specific audit performed for the entire contract/grant or successive period, unless notified in writing by DCED prior to the termination of the applicable audit period that the program-specific audit requirement has been waived. If the body of the ORGANIZATION’s Agreement with THE COUNTY contains language superseding the dollar threshold for Department mandated audits identified in this document, the superseding language takes precedence and must be used by the ORGANIZATION/grantee when determining whether the ORGANIZATION/grantee is required to have an audit performed. When the ORGANIZATION is required to have a program-specific audit performed, it must be a financial audit conducted in accordance with auditing standards generally accepted in the United States of America and Government Auditing Standards, issued by the Government Accountability Office (GAO). The audit shall meet the audit require- ments of the laws and regulations governing the program(s) in which the ORGANIZATION participates, and the terms of this Agreement. With the written consent of DCED, the ORGANIZATION may be permitted to vary the audit period for these audits. The costs of program-specific audits performed in accordance with the provisions of Section III of this document shall be reimbursed by DCED when said costs are specifically budgeted in the agreement budget as audit expenses. B. Minimum Audit Reporting Requirements When a program-specific audit is performed, the audit report must include the following at a minimum: 1. A Statement of Financial Position (balance sheet) for each contract/grant the ORGANIZATION includes in the program-specific audit. Said statement of financial position shall identify any unexpended/unused funds at the end of the audit period. 2. A separate Statement of Contractual Performance, which shall reflect the contract/grant budget and reporting period and include a comparison of budgeted to actual expenditures/services, must be prepared for each contract/grant the ORGANIZATION includes in the program-specific audit. Said schedule(s) must reconcile to the state fiscal year(s) affected. 3. Notes to the financial statements. The following must be included: (a) Definition of the reporting entity (b) Summary of significant accounting policies used in preparing the statements (c) Other informative disclosures (as necessary) 4. Auditor's report on the financial statements and any additional statements required in the terms of this contract/grant. The report must identify each contract/grant included in the program–specific audit by its Department contract/grant number. 5. Auditor's report on internal control, including (where applicable) references to contract/grant requirements and Department audit guidance. The report must identify each contract/grant included in the program–specific audit by its Department contract/grant number. This report shall describe the scope of testing of internal control and the results of the tests, and, where applicable, refer to the separate Schedule of Findings and Questioned Costs described below. 6. Auditor's report on compliance with laws, regulations, and the provisions of this contract/grant, noncompliance with which could have a material effect on the financial statements. The report must identify each contract/grant included in the program– specific audit by its Department contract/grant number. This report shall include (where applicable) references to contract/grant requirements and Department audit guidance. 7. Schedule of Findings and Questioned Costs (if applicable). This schedule shall include the views of responsible officials of the ORGANIZATION concerning the auditors’ findings, conclusions, and recommendations. This schedule shall contain all findings and questioned costs for the financial statements which are required to be reported under Government Auditing Standards. Specifically, the auditor shall report the following as audit findings in this schedule: (a) Reportable conditions in internal control over the program(s) (state and/or federal) that provide funding under this contract/grant. The auditor shall identify reportable conditions which are individually or cumulatively material weaknesses. (b) Material noncompliance with the provision of laws, regulations, and the provisions of this contract/grant. (c) Questioned costs specifically identified by the auditor (known questioned costs). In evaluating the effect of the questioned costs, the auditor shall consider the best estimate of total costs questioned (likely questioned costs), not just the known questioned costs. In reporting questioned costs, the auditor shall include information to provide proper perspective for judging the prevalence and consequences of the questioned costs. (d) Known fraud that has a material effect on the financial statements. 8. Corrective Action Plan (if applicable). At the completion of the audit, the ORGANIZATION shall prepare a corrective action plan (CAP) to address each audit finding included in the audit report. The CAP shall provide the name(s) of the contact person(s) responsible for corrective action(s), the corrective action(s) planned, and the anticipated completion date(s) for the corrective action(s) planned. Further, if the ORGANIZATION does not agree with an audit finding, it must clearly and completely explain the nature of its disagreement with the finding in the CAP. Finally, if the ORGANIZATION believes that corrective action is not required, it must provide the specific reason(s) in the CAP. 9. Status of Prior Audit Findings and Recommendations (if applicable). The auditor shall report the status of uncorrected material findings and recommendations from prior audits that affect the current audit. 10. Management Letter (if applicable). If a letter is issued to management disclosing non- reportable conditions or other matters that warrant the attention of management, it must be furnished to THE COUNTY with the audit report. 11. Subcontractor/Sub-grantee Audit Requirements: As applicable, the ORGANIZATION shall have subcontractors/subgrantees obtain audits of their contracts/grants in accordance with Section III of this document. The ORGANIZATION shall make the requirements of Section III applicable to any subcontractor/subgrantee expending $1,000,000 or more of state funds under this contract/grant during the state fiscal year (i.e., July 1 through June 30),or expending $1,000,000 or more of state funds under this contract/grant within any successive state fiscal year. If the subcontract/subgrant or any successive period is for a period shorter than the state fiscal year, but the subcontractor/subgrantee expends $1,000,000 or more of state funds under this contract/grant during said period, the ORGANIZATION is also required to make the requirements of Section III of this document applicable to the subcontractor/subgrantee. The COUNTY NOT DCED, is responsible for the receipt, review, and resolution of such audits. The ORGANIZATION shall follow up on all findings disclosed in the audit report(s). The ORGANIZATION shall retain such audits for a period of time which is the greater of four years after termination of the ORGANIZATION's contract/grant with the subcontractor/subgrantee or until resolution of any audit exceptions or other claims or actions involving a subcontract/subgrant. If the body of the ORGANIZATION’s Agreement with THE COUNTY contains language superseding the dollar threshold for Department mandated audits identified in this document, the superseding language takes precedence and must be used by the ORGANIZATION when determining whether the subcontractors/subgrantees are required to have an audit performed of their contracts/grants. C. Submission of Audit Reports When the ORGANIZATION is responsible for obtaining a program-specific audit in accordance with Section III of this document, the audit report must be completed and submitted within 120 days of the end of the state fiscal year (i.e., June 30) or 120 days following the end of each state fiscal year in case of a contract/grant lasting more than twelve months. DCED will accept electronic submission of program-specific audit reporting packages. Electronic submission is required for the state fiscal year ending June 30, 2021 and subsequent reporting periods. The reporting package must be submitted electronically in single Portable Document Format (PDF) file to the e-mail resource account RA-BOASingleAudit@pa.gov. Steps for electronic submission: 1) Complete the Program-Specific Audit Reporting Package Checklist to ensure your package contains all required elements. 2) Upload the completed Program-Specific Audit Reporting Package along with the checklist in a single PDF file to the e-mail resource account RA- BOASingleAudit@pa.gov. In the subject line of the e-mail you must identify the exact name on the Program-Specific Audit Reporting Package and the period end date to which the package applies. 3) You will receive an e-mail to confirm the receipt of your Program-Specific Audit Reporting Package, including the completed checklist. Technical assistance with respect to program-specific audits performed in accordance with Section III of these Audit Requirements will be provided by DCED’S Division of Budget and Grants Management at RA-BOASingleAudit@pa.gov. IV. CONTRACTS FUNDED BY FEDERAL AND STATE FUNDS A. Conditions Requiring an Audit 1) The ORGANIZATION is required to have a federally mandated audit made in accordance with the requirements of Section II when the ORGANIZATION expends more than $1,000,000 of total federal awards received from ALL sources during its fiscal year, regardless of the amount of state funds received under this contract/grant during the state fiscal year. 2) The ORGANIZATION is required to have a program-specific audit made in accordance with the requirements of Section III if the ORGANIZATION expends $1,000,000 or more of state funds received under this contract/grant during the state fiscal year and the ORGANIZATION is not required to have a federally mandated audit(s) in accordance with this document that covers the entire state fiscal year. If the body of the ORGANIZATION’s contract/grant with DCED contains language superseding the dollar threshold for Department mandated audits identified in this document, the superseding language takes precedence and must be used by the ORGANIZATION when determining whether the ORGANIZATION is required to have an audit performed in accordance with the condition described above. V. AUDIT EXEMPTION CONDITIONS A. Unless stated otherwise in the terms of this Agreement, the ORGANIZATION is not required to have an audit performed when EITHER of the following conditions is applicable: 1) The ORGANIZATION expends less than $1,000,000 of state funds received under this contract/grant during the state fiscal year (i.e., July 1 through June 30) (for Department mandated audits) AND it expends less than $1,000,000 of total federal awards received from ALL sources during its fiscal year. B. If the body of the ORGANIZATION’s Agreement with THE COUNTY contains language superseding the dollar threshold for Department mandated audits identified in this document, the superseding language takes precedence and must be used by the ORGANIZATION when determining whether the ORGANIZATION is required to have an audit performed. 1) The contract/grant is funded by either state or federal funds, and all contract/grant monies expended during either the ORGANIZATION’s fiscal year (for federally mandated audits) or during the state fiscal year (i.e., July 1 through June 30) (for Department mandated audits) are received on a strictly fee for service basis. However, even if the ORGANIZATION is not required to have an audit performed, the ORGANIZATION is required to maintain auditable records of federal awards and any state funds which supplement such awards, and to provide access to such records by federal and state agencies or their designees. VI. GENERAL AUDIT PROVISIONS A. Auditor Selection The ORGANIZATION is responsible for obtaining the necessary audit and securing the services of a certified public accountant or independent governmental auditor. The Office of the Budget, Office of Comptroller Operations, Bureau of Audits (Bureau of Audits) may decide to perform program-specific audits that are required under Section III of these Audit Requirements. The ORGANIZATION will be given written notification if the Bureau of Audits makes this decision. In the event that the Bureau of Audits does perform the program-specific audit, any audit costs included in the Agreement will revert to DCED. However, unless notified as provided above, the ORGANIZATION is required to arrange for the audit as described above. B. Questioned Costs Any questioned costs identified as such in audit reports of either the ORGANIZATION or its subcontractors/subgrantees shall be returned to the cognizant federal and/or state agencies providing the financial assistance, unless resolved to the satisfaction of said entities. C. Sanctions (Remedies for Noncompliance with Audit Requirements) The ORGANIZATION's failure to provide an acceptable audit in accordance with the requirements of this document may result in THE COUNTY initiating sanctions against the ORGANIZATION including, but not limited to, the following actions: 1) Disallowance of the cost of the audit. 2) Withholding a percentage of the contract/grant funding. 3) Withholding or disallowance of administrative/overhead costs. 4) Suspension of subsequent contract/grant funding. D. Additional Audits The Commonwealth reserves the right for federal and state agencies or their authorized representatives to perform additional audits of a financial or performance nature, if deemed necessary by commonwealth or federal agencies. Any such additional audit work will rely on work already performed by the ORGANIZATION's auditor and the costs for any additional work performed by the federal or state agencies will be borne by those agencies at no additional expense to the ORGANIZATION. E. Audit Working Papers and Reports Audit documentation and audit reports must be retained by the ORGANIZATION’s auditor for a minimum of five years from the date of issuance of the audit report, unless the ORGANIZATION’s auditor is notified in writing by the commonwealth, the cognizant federal agency for audit, or the oversight federal agency for audit to extend the retention period. Audit documentation will be made available upon request to authorized representatives of the commonwealth, the cognizant federal agency for audit, the oversight federal agency for audit, the federal funding agency, or the Government Accountability Office (GAO). F. Records Retention The ORGANIZATION is required to maintain records of state funds and federal awards. The ORGANIZATION shall preserve all books, records and documents related to this contract/grant for a minimum of four years from the date of final payment under this contract/grant; or until all findings, questioned costs or activities have been resolved to the satisfaction of the commonwealth; or as required by applicable federal laws and regulations, whichever is longer, unless this contract/grant elsewhere provides for a shorter period; or unless THE COUNTY otherwise separately agrees in writing to a shorter period. The ORGANIZATION shall provide federal and state agencies or their designees access to such books, records and documents for inspection, audit or reproduction. G. Funding Source(s) The audit report must identify the amounts of federal and state funding that is included in the report. This identification must include the breakdown of federal and state dollars provided and the related federal and state financial assistance program name and number. This identifying information is provided in Attachment 1 to this Appendix F, entitled FEDERAL AWARDS, of this Agreement. 28 APPENDIX C ATTACHMENT 1 FEDERAL AWARDS The following information is provided pursuant to the requirements of 2 C.F.R. Section 200 as Uniform Guidance: Subrecipient Name: Waynesboro Community and Human Services Subrecipient's DUNS Number: 17-154-9652 Subrecipient's Unique Entity Identifier: EKLDWBG47535 Federal Award Identification Number (FAIN): 23-DC-42-0001 Date of Federal Award: the date executed agreement is sent to the Organization through June 30, 2027. Subaward Period of Performance Start and End Date: August 1, 2026, through June 30, 2027 Federal Funds Obligated (this action): $43,452.60 Total Federal Funds Obligated to the Subrecipient (including current obligation): $230,176.69 (Active Contracts FY 2024, and 2025) Total Amount of Federal Award To Franklin County: $43,452.60 Project Description: The ESG program provides funding to engage homeless individuals and families living on the street and improves the number and quality of emergency shelter for homeless individuals and families; helps operate these shelters; provides essential services to shelter residents; rapidly re-houses homeless individuals and families and prevents families and individuals from becoming homeless. Federal awarding agency: Assistant Secretary for Community Planning and Development Pass-Through Entity: Franklin County, Pennsylvania Pass-Through Entity Contact Information: Melodie Hoff, 272 North Second Street, Chambersburg, PA 17201, mshoff@franklincountypa.gov (717) 709-7218 Catalog of Federal Domestic Assistance (CFDA) name and number: 14.231 Is this award for research and development? YES NO X “Research” is defined as a systematic study directed toward fuller scientific knowledge or understanding of the subject studied. “Development” is the systematic use of knowledge and understanding gained from research directed toward the production of useful materials, devices, systems, or methods, including design and development of prototypes and processes. Indirect cost rate: 10% For nonprofit organizations, the costs of activities performed by the non-Federal entity primarily as a service to members, clients, or the general public when significant and necessary to the non-Federal entity's mission must be treated as direct costs wh ether or not allowable, and be allocated an equitable share of indirect (F&A) costs. Indirect (F&A) costs mean those costs incurred for a common or joint purpose benefitting more than one cost objective. De Minimis Indirect cost rate applied? YES X NO APPENDIX D Business Associate Agreement This Business Associate Agreement (this “Agreement”) is entered into by Waynesboro Community and Human Services. (“Business Associate” and County of Franklin, Pennsylvania (“Covered Entity”), individually referred to as “Party” and collectively as the “Parties.” This Agreement is effective as of DATE EXECUTED AGREEMENT IS SENT TO THE BUSINESS ASSOCIATE (“Effective Date”). RECITALS WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in Article 1 of this Agreement, and with the applicable provisions of the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”). WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to Covered Entity pursuant to the Services Agreement, as defined below. WHEREAS, Business Associate is a business associate under HIPAA. Business Associate must comply with the provisions of the Privacy Rule and Security Rule made applicable to business associates pursuant to HITECH and with all other applicable provisions of HITECH. WHEREAS, Covered Entity is not permitted to allow Business Associate to create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity without satisfactory assurances that Business Associate will appropriately safeguard the information. Therefore, Covered Entity will only disclose Protected Health Information to Business Associate or allow Business Associate to create or receive Protected Health Information on behalf of Covered Entity in accordance with the requirements of HIPAA, HITECH, and provisions of this Agreement. NOW, THEREFORE, in consideration of the mutual promises below and for other good and valuable consideration, the receipt and adequacy of which are hereby acknowledged, the Parties agree as follows: WHEREAS, Covered Entity is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Covered Entity must comply with the Administrative Simplification Provisions of HIPAA, including the Privacy Rule and Security Rule, as defined in Article 1 of this Agreement, and with the applicable provisions of the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”). WHEREAS, Covered Entity has engaged Business Associate to furnish certain services to Covered Entity pursuant to the Services Agreement, as defined below. WHEREAS, Business Associate is a business associate under HIPAA. Business Associate must comply with the provisions of the Privacy Rule and Security Rule made applicable to business associates pursuant to HITECH and with all other applicable provisions of HITECH. WHEREAS, Covered Entity is not permitted to allow Business Associate to create, receive, maintain, or transmit Protected Health Information on behalf of Covered Entity without satisfactory assurances that Business Associate will appropriately safeguard the information. Therefore, Covered Entity will only disclose Protected Health Information to Business Associate or allow Business Associate to create or receive Protected Health Information on behalf of Covered Entity in accordance with the requirements of HIPAA, HITECH, and provisions of this Agreement. NOW, THEREFORE, in consideration of the mutual promises below and for other good and valuable consideration, the receipt and adequacy of which are hereby acknowledged, the Parties agree as follows: ARTICLE I DEFINITIONS Terms used in this Agreement that are specifically defined in HIPAA shall have the same meaning as set forth in HIPAA. A change to HIPAA which modifies any defined HIPAA term, or which alters the regulatory citation for the definition shall be deemed incorporated into this Agreement. 1. Breach means the unauthorized acquisition, access, use, or disclosure of Protected Health Information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information. The term “breach” does not include the exceptions described in 42 U.S.C. § 17921(1)(B) summarized below. (a) Certain uses or disclosures by a Covered Entity’s work-force members (defined as persons acting under the authority of the Covered Entity or Business Associate), if the use or disclosure was made in good faith, was within the scope of the disclosing individual’s authority, and does not result in a further violation of the Privacy Rule. (b) Inadvertent disclosures from one person who is authorized to access PHI to another person who is also authorized to access PHI within the same Covered Entity, Business Associate, or organized health care arrangement when the disclosed PHI is not further used or disclosed in a manner not permitted under the Privacy Rule. (c) A disclosure of PHI when a Covered Entity or Business Associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information. 2. Designated Record Set, as defined under the Privacy Rule at 45 C.F.R. § 164.501, means a group of records maintained by or for a Covered Entity that are: (a) the medical records and billing records about individuals maintained by or for a covered health care provider; (b) the enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health care plan; or (c) used, in whole or in part, by or for the Covered Entity to make decisions about individuals. For purposes of this section, a “Record” is any item, collection, or grouping of information that includes PHI and is maintained, collected, used, or disseminated by or for a Covered Entity. 3. Electronic Health Record has the same meaning that applies under Section 13400(5) of ARRA and currently means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized staff. 4. Electronic Protected Health Information (EPHI), as defined by 45 C.F.R. § 160.103, means individually identifiable health information that is transmitted by electronic media, or maintained in electronic media, but not certain education and employment records described in 45 C.F.R. § 160.103, the definition of Protected Health Information. EPHI also includes any EPHI provided by Covered Entity or created or received by Business Associate on behalf of Covered Entity. 5. HHS means the U.S. Department of Health and Human Services. 6. Individual, as defined by 45 C.F.R § 160.103, means the person who is the subject of PHI. It also includes a person who qualifies as a Personal Representative in accordance with 45 C.F.R. § 164.502(g). 7. Limited Date Set, as defined by 45 C.F.R. §164.514(e) is partially de-identified data that may be used or disclosed for research, public health and health care operation purposes, such as quality assurance, as long as a recipient signs a data use agreement that complies with HIPAA requirements. 8. Privacy Rule means the Standards for Privacy of individually Identifiable Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart E, any other applicable provision of HIPAA, and any amendments to HIPAA, including HITECH. 9. Protected Health Information (PHI) as defined by 45 C.F.R. § 164.103, mean individually identifiable health information that is: (a) transmitted by electronic media; (b) maintained in electronic media; or (c) transmitted or maintained in any other form or medium; PHI does not include certain education and employment records described in 45 C.F.R. § 160.103, the definition of PHI. PHI includes, without limitation, any PHI provided by Covered Entity or created or received by Business Associate on behalf of Covered Entity. Unless otherwise stated in this Agreement, any provision, restriction, or obligation in this Agreement related to the use of PHI shall apply equally to EPHI. 10. Required By Law, as defined by 45 C.F.R. § 164.103, means a mandate contained in law that compels an entity to make a use or disclosure of PHI and that is enforceable in a court of law; and any additional requirements created under HITECH. 11. Secretary means the Secretary of the Department of Health and Human Services or his/her designee. 12. Security Incident, as defined by 45 C.F.R. § 164.304, means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. 13. Security Rule means the Security Standards for the Protection of Electronic Protected Health Information codified at 45 C.F.R. §§ 160 and 164, Subpart C, any other applicable provision of HIPAA, and any amendments to HIPAA, including HITECH. 14. Services Agreement means the underlying agreement(s) that outline the terms of the services that Business Associate agrees to provide to Covered Entity and that fall within the functions, activities or services described in the definition of Business Associate at 45 C.F.R. § 160.103. 15. Unsecured PHI shall mean PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary of HHS, such as encryption in compliance with the National Institute of Standards and Technology standards or destruction. ARTICLE II BUSINESS ASSOCIATE OBLIGATIONS 1. Request, Use and Disclosure of PHI. Business Associate agrees that it will only request, use and disclose PHI in accordance with the terms of this Agreement, and as is Required by Law. Business Associate acknowledges that it may only request, use and disclose PHI obtained or created pursuant to this Agreement with Covered Entity if the request, use or disclosure is in compliance with each applicable requirement of the Privacy Rule found in 45 C.F.R. § 164.504(e). 2. Permitted Requests, Uses and Disclosures. Business Associate will not request, use or disclose PHI except for the purpose of performing Business Associate’s obligations to Covered Entity as described in the Services Agreement, consistent with the requirements of HIPAA and this Agreement, and for other uses and disclosures permitted under this Agreement. Business Associate may request, use or disclose PHI only if such request, use or disclosure does not violate the Privacy Rule or this Agreement. To the extent Business Associate is to carry out any of Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of the applicable obligations. In accordance with the provisions of 45 C.F.R. § 164.504(e)(4), Business Associate also may request, use or disclose PHI, if necessary: (a) for the proper management and administration of Business Associate’s organization, or (b) to carry out the legal responsibilities of Business Associate. Business Associate may only disclose PHI for these purposes, in accordance with the provisions of 45 C.F.R. § 164.504(e)(4)(ii), if either (a) the disclosure is Required By Law, or (b) Business Associate obtains reasonable written assurances from the person to whom Business Associate discloses the PHI that the PHI will be held confidentially and used or further disclosed only as Required By Law or for the purposes for which it was disclosed to the person and that the person agrees to notify Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached. 3. Prohibited Requests, Use and Disclosures. Business Associate will not request, use or disclose PHI in any manner that constitutes a violation of the Privacy Rule, this Agreement, or the Services Agreement. 4. Minimum Requirements. Business Associate will only request, use and disclose the minimum amount of PHI necessary for Business Associate to perform the services for which it has been retained by Covered Entity, in accordance with 42 U.S.C. § 17935(b). Business Associate agrees to comply with the Secretary’s guidance on what constitutes minimum necessary. 5. Administrative, Physical and Technical Safeguards. Business Associate will develop, implement, maintain, and use appropriate safeguards to prevent any use or disclosure of the PHI other than as provided by this Agreement. Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of EPHI. Business Associate acknowledges that the Security Rule provisions regarding administrative, physical, and technical safeguards, policies and procedures and documentation requirements found in 45 C.F.R. §§ 164.308, 164.310, 164.312 and 164.316 apply to Business Associate in the same manner as to Covered Entity and Business Associate will fully comply with such Security Rule provisions. 6. Unusable, Unreadable or Indecipherable Technology. Business Associate will, to the extent feasible, adopt a technology or methodology specified by the Secretary pursuant to 42 U.S.C. § 17932(h) that renders PHI unusable, unreadable, or indecipherable to unauthorized individuals. 7. Agents and Sub-contractors. Prior to making any permitted disclosures, Business Associate will ensure that any of its agents, including subcontractors, to whom it provides PHI received from, or created or received by, Business Associate on behalf of Covered Entity agree in writing to be bound by the same privacy and security restrictions and conditions that apply to Business Associate under this Agreement, including but not limited to those conditions relating to termination of the contract for improper disclosure. Further, Business Associate shall implement and maintain sanctions against agents and subcontractors, if any, that violate such restrictions and conditions. Business Associate shall terminate any agreement with an agent or subcontractor, if any, who fails to abide by such restrictions and obligations. Business Associate shall not provide any PHI to any third party or subcontract any services described in the Services Agreement without Covered Entity’s express written permission. 8. Reporting Obligations. Business Associate will report, in writing, to Covered Entity any use or disclosure of PHI that is not authorized by this Agreement, including Breaches of Unsecured PHI. In addition, Business Associate will report in writing, to Covered Entity any Security Incident of which it becomes aware that it, its employees, or its agents or subcontractors experience involving or potentially involving Covered Entity EPHI. The written notice shall be provided to Covered Entity within five (5) business days of becoming aware of the non-authorized use or disclosure or Security Incident. 9. Notification to Covered Entity of Breach of Unsecured PHI. Business Associate will provide written notification to Covered Entity within seventy-two (72) hours of discovering a Breach of Unsecured PHI. Such notification will identify, to the extent possible, (1) each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been, accessed, acquired or disclosed during the Breach, (2) the nature of the non-permitted access, use or disclosure, including the date of the Breach and the date of discovery of the Breach; (3) Protected Health Information accessed, used or disclosed as part of the Breach (e.g., full name, social security number, date of birth, etc.); (4) who or what area of Business Associate’s operation made the non-permitted access, use or disclosure and who received the non- permitted disclosure; (5) identify what corrective action the Business Associate took or will take to prevent further non-permitted accesses, uses or disclosures; (6) identify what Business Associate did or will do to mitigate any deleterious effect of the non-permitted access, use or disclosure; and (7) provide such other information that is reasonably available to Business Associate that Covered Entity may request. For purposes of the preceding sentence, Business Associate will be treated as discovering the Breach on the first day on which the Breach is known (or by exercising reasonable diligence should have been known) to Business Associate (including any employee, officer or other agent of Business Associate other than the person committing the Breach). Whether a Breach has occurred will be determined in accordance with applicable regulations or other authoritative guidance issued pursuant to the HITECH Act. A delay in notification of a Breach that qualifies as a “law enforcement delay” under 45 CFR Section 164.412 will not be treated as a violation of this Agreement. Business Associate will supplement its initial notification to Covered Entity with additional information as any additional information becomes available. Business Associate will implement a reasonable system for discovery of Breaches. 10. Breach Notification Expenses. Business Associate agrees to indemnify, defend, and hold harmless Covered Entity and its employees, agents, and representatives from any and all direct, reasonable and actual costs, settlements, judgments, and expenses incurred by Covered Entity caused by a Breach of Unsecured Protected Health Information while in the possession of Business Associate, or its employees, subcontractors or agents. Such costs will include those related to Breach notifications sent to the affected individuals and the media, as required by Section 13402(e) of ARRA and 45 CFR Part 164, and any costs incurred by Covered Entity or its employees, agents or representatives to mitigate potential harm to individuals from the Breach. 11. Notification to Covered Entity of Use or Disclosure Data. Business Associate will notify Covered Entity in writing of any actual or suspected use or disclosure of data in violation of any applicable federal or state laws or regulations or any legal action against Business Associate arising from an alleged HIPAA violation. Business Associate shall take: (a) prompt action to correct any such deficiencies; and (b) any action pertaining to such unauthorized disclosure required by applicable federal and state laws and regulations. Business Associate will provide the written notice to Covered Entity within five (5) business days of becoming aware of the violation or legal action. 12. Mitigation of Harmful Effect. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Agreement 13. Designated Record Sets. Business Associate will make PHI in Designated Record Sets that are maintained by Business Associate or its agents or subcontractors, if any, available to Covered Entity or to an individual for inspection and copying within ten (10) business days of a request by Covered Entity to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to the requirements concerning access to individuals to PHI found at 45 C.F.R. § 164.524. If Business Associate maintains Protected Health information in the form of an Electronic Health Record for any individual, Business Associate agrees to provide, at the request of Covered Entity or an individual, and in the time and manner designated by Covered Entity, a copy of such information in an electronic format to that individual or, if clearly, conspicuously and specifically directed by the individual (or by Covered Entity based on a clear, conspicuous and specific request of the individual) to transmit an electronic copy of that information directly to an entity or person designated by the individual. Any fee charged to the individual for providing such information (or a summary or explanation of such information) may not exceed Business Associate’s labor costs incurred in responding to the individual’s request. 14. Amendments to PHI and EPHI. Within ten (10) business days of receipt of a request from Covered Entity for an amendment of PHI or a record about an individual contained in a Designated Record Set, Business Associate or its agents or subcontractors, if any, shall make such PHI available to Covered Entity for amendment and shall incorporate any such amendment to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.526. If an individual requests an amendment of PHI directly from Business Associate or its agents or subcontractors, if any, Business Associate must notify Covered Entity in writing within five (5) business days of the request. Any denial of amendment of PHI maintained by Business Associate or its agents or subcontractors, if any, shall be the responsibility of Covered Entity. Upon the approval of Covered Entity, Business Associate shall appropriately amend the PHI maintained by it, or any agents or subcontractors. 15. Accounting of PHI and EPHI. Within ten (10) business days of notice by Covered Entity of a request for an accounting of disclosures of PHI, Business Associate and any agents or subcontractors shall make available to Covered Entity the information required to provide an accounting of disclosures to enable Covered Entity to fulfill its obligations under the Privacy Rule, including, but not limited to, 45 C.F.R. § 164.528 and any additional information required under the HITECH Act, including Section 13405(c) if Business Associate maintains information in the form of an Electronic Health Record, and any implementing regulations. (a) If a request for an accounting is made directly to Business Associate or its agents or subcontractors, Business Associate will notify Covered Entity of the request within five (5) business days of having received the request. Covered Entity shall either inform Business Associate to provide the requested information directly to the individual or request Business Associate to immediately forward the information to the Covered Entity for compilation and distribution to the individual. (b) In the case of a direct request for an accounting from an individual related to treatment, payment or health care operations disclosures through Electronic Health Records, Business Associate will provide the accounting to the individual in accordance with 42 U.S.C. § 17935(c) and any regulations adopted subsequent to this Agreement. Business Associate will confirm with Covered Entity that Covered Entity provided Business Associate’s name to the individual in response to a request for an accounting before providing the requested accounting to the individual. 16. Retention of Accounting Documentation. Notwithstanding termination of this Agreement, Business Associate and any of its agents or subcontractors shall continue to maintain the information required for purposes of complying with this Section 2.14 for a period of six (6) years after termination of the Agreement. 17. Business Associate’s Compliance with HHS. Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of HHS in the time and manner designated by the Covered Entity or the Secretary of HHS for purposes of determining Covered Entity’s compliance with the Privacy Rule. Business Associate will notify Covered Entity regarding any PHI that Business Associate provides to the Secretary of HHS concurrently with providing the requested PHI to the Secretary of HHS. Upon request by Covered Entity, Business Associate will provide Covered Entity with a duplicate copy of the requested PHI. 18. Inspection by Covered Entity. Within five (5) business days of a written request by Covered Entity, Business Associate and its agents or subcontractors, if any, shall allow Covered Entity to conduct a reasonable inspection of the facilities, systems, books, records, agreements, policies and procedures relating to the use or disclosure of PHI pursuant to this Agreement for the purpose of determining whether Business Associate has complied with this Agreement, the Security Rule and provisions of the Privacy Rule directly applicable to Business Associate or as deemed necessary by Covered Entity to determine whether a Breach has occurred. Both Parties agree to the following: (a) Business Associate will cooperate with Covered Entity’s risk assessment without unreasonable delay; (b) Business Associate and Covered Entity will mutually agree in advance upon the scope, location and timing of such an inspection; and (c) Covered Entity will protect the confidentiality of all confidential and proprietary information of Business Associate to which Covered Entity has access during the course of such inspection. 19. Damages. Business Associate shall be responsible to compensate the affected individual for any reasonable damages as a result of a Breach caused by Business Associate. 20. No Ownership Rights. Business Associate agrees that Business Associate does not and will not have any ownership rights in any of the PHI. 21. Additional HITECH Requirements. The additional requirements of Title XIII of HITECH that relate to privacy and security and that are made applicable with respect to covered entities are also applicable to Business Associate and by this reference these requirements are hereby incorporated into this Agreement. 22. Standard Transactions. In conducting any standard transaction that is subject to the Standard Transaction Regulations (set forth in 45 C.F.R. Part 162) on behalf of Covered Entity, Business Associate agrees to comply with all requirements of the Standard Transaction Regulations that would apply to Covered Entity if Covered Entity were conducting the transaction itself and shall require the same of any subcontractor or agent involved with the conducts of such Standard Transactions. 23. Limitations on Marketing. Business Associate may not use and disclose PHI for “marketing,” as defined in 45 C.F.R. § 164.501, unless expressly permitted to do so in the Services Agreement. 24. Sale of PHI. Except for compensation set forth in the Services Agreement between Business Associate and Covered Entity, Business Associate shall not receive any direct or indirect remuneration in exchange for the provision of Protected Health Information. ARTICLE III COVERED ENTITY OBLIGATIONS 1. Risk Assessment of Breach by Covered Entity. Covered Entity shall make the final determination of whether for a Breach of PHI occurred. 2. Restrictions. Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to or must comply with in accordance with 45 C.F.R. § 164.522 and 42 U.S.C. § 17935(a). 3. Notification of Changes or Revocations of Permission. Covered Entity shall provide Business Associate with notice of any changes to, revocation of, or permission by individual to use or disclose PHI, if such changes affect Business Associate’s permitted uses or disclosures, within a reasonable period of time after Covered Entity becomes aware of such changes to or revocation of permission. 3.4 Permissible Requests by Covered Entity. Covered Entity shall not request Business Associate to use or disclose PHI in any manner that would not be permissible under the Privacy and Security Rules if done by Covered Entity. ARTICLE IV TERMINATION 1. Term and Survival. The term of this Agreement shall be effective as of the Effective Date of this Agreement and continue until terminated by Covered Entity or any underlying Services Agreement expires or is terminated. Any provision related to the use, disclosure, access, or protection of PHI or EPHI or that by its terms shall survive termination of this Agreement shall survive termination. 2. Termination for Breach. A material breach by Business Associate, or its agents or subcontractors, if any, of this Agreement, as determined by Covered Entity, shall constitute a material breach of the Services Agreement. As provided for under 45 C.F.R. §§ 164.314(a)(2)(i)(D) and 164.504(e)(2)(iii), the Covered Entity may immediately terminate this Agreement and the Services Agreement or, alternatively, the Covered Entity may choose to provide Business Associate with written notice of the material breach and an opportunity to cure the material breach or end the violation within thirty (30) calendar days. If Business Associate becomes aware of a material breach of this Agreement by Covered Entity, Business Associate shall (1) provide an opportunity for Covered Entity to cure the breach or end the violation and terminate this Agreement (and any applicable portion of the Services Agreement between the parties) if Covered Entity does not cure the breach or end the violation within thirty (30) calendar days, or (2) immediately terminate this Agreement (and any applicable portion of the Services Agreement ) if Covered Entity has breached a material term of this Agreement and cure is not possible. 3. Termination for Violation by Business Associate. Covered Entity may terminate this Agreement and the Services Agreement effective immediately, if (i) Business Associate is named as a defendant in a criminal proceeding for a violation of HIPAA, HITECH, or other security or privacy laws or (ii) there is a finding or stipulation that Business Associate has violated any standard or requirement of HIPAA, HITECH, or other security or privacy laws in any administrative or civil proceeding in which Business Associate is involved. 4. Return or Destruction of PHI. (a) Upon termination of this Agreement for any reason, Business Associate shall return or, at Covered Entity’s request, destroy all PHI received from Covered Entity or created or received by Business Associate on behalf of Covered Entity that Business Associate still maintains in any form. If Business Associate destroys the PHI, Business Associate shall certify in writing to Covered Entity that such PHI has been destroyed. This provision applies to PHI that is in the possession of agents or subcontractors of Business Associate. Business Associate will retain no copies of the PHI. (b) If Business Associate determines that returning or destroying the PHI is not feasible, Business Associate shall explain to Covered Entity why conditions make the return or destruction of the PHI not feasible. If Covered Entity agrees that the return or destruction of PHI is not feasible, Business Associate will retain the PHI, subject to all of the protections of this Agreement, and limit further uses and disclosures of the PHI to those purposes that make the return or destruction of the PHI infeasible for so long as Business Associate maintains the PHI. (c) If Business Associate determines that it is infeasible to obtain from an agent or subcontractor any PHI in the possession of the agent or subcontractor or to destroy the PHI, Business Associate will provide Covered Entity written notification explaining why obtaining the PHI is infeasible. If Covered Entity agrees that the return or destruction of PHI is not feasible, Business Associate will require the agent or subcontractor to extend the protections of this Agreement to the PHI and limit further uses and disclosures of the PHI to those purposes that make the return or destruction of the PHI infeasible for so long as the agent or subcontractor maintains the PHI. 5. Termination of Services Agreement. If this Agreement is terminated for any reason, Covered Entity will also terminate the Services Agreement between the Parties. This provision shall supersede any termination provision to the contrary which may be set forth in the Services Agreement. ARTICLE V MISCELLANEOUS 1. Acknowledgement. By affixing their respective signatures below, the Parties certify that they have read and understand each and every provision in this Agreement. Each Party certifies that it possesses the authority to enter into the Agreement. The execution and performance of this Agreement by each Party has been duly authorized by all necessary laws, resolutions or corporate actions, and the Agreement constitutes valid and enforceable obligations of each Party in accordance with its terms. 2. Amendment. This Agreement shall not be amended, altered, or modified, except by an instrument in writing duly executed by the Parties to the Agreement. 3. Assignment. This Agreement may not be assigned by Business Associate without the prior written consent of Covered Entity. 4. Binding Effect. Subject to provisions hereof restricting assignment, this Agreement shall be binding upon and shall inure to the benefit of the Parties and their respective successors and permitted assigns. 5. Change in Law. The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity and Business Associate to comply with the requirements of HIPAA and the HITECH Act, and of the regulations issued pursuant to those laws. If Covered Entity reasonably concludes that an amendment to this Agreement is needed because of change in federal or state law or changing industry standards, Covered Entity shall notify Business Associate of such proposed modification(s), “Legally-Required Modifications”. Such Legally Required Modifications shall be deemed accepted by Business Associate and this Agreement so amended, if Business Associate does not, within thirty (30) calendar days following the date of notice, or within such other time period as may be mandated by applicable state or federal law, deliver to Covered Entity its written rejection of such Legally-Required Modifications. 41 6.Compliance with Laws. Business Associate will comply with all applicable federal and state security and privacy laws, to the extent that such laws apply to Business Associate or are more protective of individual privacy than HIPAA. 7.Entire Agreement. This Agreement, including attachments, constitutes the entire Agreement between the Parties with respect to the subject matter hereof, and it supersedes all prior oral or written agreements, commitments, or understandings with respect to the matters provided for herein. 8.Execution. This Agreement and any amendments thereto shall be executed in duplicate copies on behalf of the Parties by an official of each, specifically authorized by its respective Party to perform such executions. Each duplicate copy shall be deemed an original, but both duplicate originals together constitute one and the same instrument. 9.Indemnification by Business Associate. Business Associate and any of its subcontractors and agents shall indemnify, hold harmless and defend Covered Entity and its employees, officers, directors, agents, and contractors from and against any and all claims, losses, liabilities, costs, attorneys’ fees, and other expenses incurred as a result of or arising directly or indirectly out of or in connection with Business Associate’s or its subcontractors’ or agents’ breach of this Agreement, violation of HIPAA, HITECH or other applicable law, or otherwise related to the acts or omissions of Business Associate or its subcontractors or agents. 10.Independent Contractors. This Agreement establishes an independent contractor relationship between Covered Entity and Business Associate. Nothing in this Agreement is intended, nor may anything be construed, to create a partner, joint venture employer/employee, or agent relationship. 11.Limitations on Benefits of this Agreement. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than Covered Entity, Business Associate, or their respective successors or assigns, any rights, remedies, obligations or liabilities whatsoever. It is the express intent of the Parties that no person or entity other than the Parties shall be entitled to bring any action to enforce any provision of this Agreement against either of the Parties, and that the Agreement set forth shall be solely for the benefit of, and shall be enforceable only by, the Parties to this Agreement or their respective successors and assigns as permitted hereunder. 12.Notices. All notices which are required or permitted to be given pursuant to this Agreement shall be in writing and shall be sufficient in all respects if delivered personally, by electronic facsimile (with a confirmation by registered or certified mail placed in the mail no later than the following day), or by registered or certified mail, postage prepaid, addressed to a Party as indicated below: 42 If to Business Associate: If to Covered Entity, to: Waynesboro Community County of Franklin And Human Services 272 North Second Street Waynesboro, PA 17268 Chambersburg, PA 17201 Notice shall be deemed to have been given upon transmittal thereof as to communications which are personally delivered or transmitted by electronic facsimile and, as to communications made by United States mail, on the third (3rd) day after mailing. The above addresses may be changed by giving notice of such change in the manner provided above for giving notice. 13.References. A reference in this Agreement to a section in the Privacy Rule or Security Rule means the section as in effect or as amended at the time of reference and as interpreted pursuant to any applicable guidance provided by the Secretary or other responsible regulatory authority and any applicable case law. 14.Severability. If any part of any provision of this Agreement, or any other agreement, document or writing given pursuant to or in connection with this Agreement, shall be held invalid or unenforceable, the holding of invalidity or unenforceability will apply to the invalid or unenforceable part of the provision only, without in any way affecting the remaining parts of said provision or the remaining provisions of said Agreement. 15.Sub-Contract. Business Associate may not sub-contract any services under the Services Agreement without the express written consent of Covered Entity. 16.Waiver. Neither the waiver by either Party of a breach of or a default under any of the provisions of this Agreement, nor the failure of either of the Parties, on one or more occasions, to enforce any of the provisions of this Agreement or to exercise any rights or privilege hereunder shall thereafter be construed as a waiver of any subsequent breach or default of a similar nature, or as a waiver of any such provisions, rights or privileges hereunder. 17.Interpretation. Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity to comply with applicable requirements of HIPAA HITECH Act, the Privacy Rule and the Security Rule. Any conflict between a provision of the Services Agreement and this Agreement regarding the subject matter of this Agreement, shall be resolved in favor of this Agreement See signatures on next page September 16 43