Orange County NC Website
18 <br /> Co..oMood Aweme.t.F1 Page 16 of 19 <br /> NORTH CAROLINA <br /> DEPARTMENT OF HEALTH AND HUMAN SERVICES <br /> BUSINESS ASSOCIATE ADDENDUM TO MEMORANDUM OF UNDERSTANDING <br /> This Agreement is made effective the 1st day of July,2009,by and between <br /> (name of Local Health Department or"Covered Entity')and the Division of Public Health("Business Associate') <br /> (collectively the"Parties"). <br /> BACKGROUND <br /> a. Covered Entity and Business Associate are parties to a Memorandum of Understanding "entitled"The FY2009 <br /> Consolidated Agreement(the"MOU"),whereby Business Associate agrees to perform certain services for or <br /> on behalf of Covered Entity. <br /> b. Covered Entity is an organizational unit of the North Carolina Department of Health and Human Services(the <br /> "Department')that has been designated in whole or in part by the Department as a health care component for <br /> purposes of the HIPAA Privacy and Security Rules. <br /> c. The relationship between Covered Entity and Business Associate is such that the Parties believe Business <br /> Associate is or may be a"business associate"within the meaning of the HIPAA Privacy and Security Rules. <br /> d. The Parties enter into this Business Associate Addendum to the MOU with the intention of complying with the <br /> HIPAA Privacy and Security Rules provision that a covered entity may disclose electronic protected health <br /> information or other protected health information to a business associate,and may allow a business associate to <br /> create or receive electronic protected health information or other protected heath information on its behalf,if the <br /> covered entity obtains satisfactory assurances that the business associate will appropriately safeguard the <br /> information. <br /> 2. DEFINITIONS. <br /> Unless some other meaning is clearly indicated by the context,the following terms shall have the following meaning in <br /> this Agreement: <br /> a. "Electronic Protected Health Information"shall have the same meaning as the term"electronic protected health <br /> information" in 45 CM l 60:103,limited to the information created or received by Business Associate from or <br /> on behalf of a Covered Entity. <br /> b. "HIPAA"means the Administrative Simplification Provisions,Sections 261 through 264,of the federal Health <br /> Insurance Portability and Accountability Act of 1996,Public Law 104-191. <br /> c. "Individual"shall have the same meaning as the term"individual"in 45 CM 160.103 and shall include a person <br /> who qualifies as a personal representative in accordance with 45 CM 164.502(g). <br /> d. "Privacy and Security Rules" shall mean the Standards for Privacy of Individually Identifiable Health <br /> Information and Security Standards for the Protection of Electronic Protected Health Information in accordance <br /> with 45 CM part 160 and part 164,subparts A and E. <br /> e. "Protected Health Information"shall have the same meaning as the term`protected health information"in 45 <br /> CM 160.103,limited to the information created or received by Business Associate from or on behalf of Covered <br /> Entity. <br /> f. "Required By Law"shall have the same meaning as the term"required by law"in 45 CFR 164.103. <br /> g. "Secretary" shall mean the Secretary of the United States Department of Health and Human Services or his <br />