by Business Associate on behalf of the Plan during the six years prior to the date of the request. Business
<br />Associate shall maintain and make available to the Plan, upon request, a record of all disclosures of PHI
<br />made by Business Associate, inciuding, at a minimum, the date of the disclosure, the name and address of
<br />the recipient of the PHI, a descriprion of the PHI disclosed, and the purpose of and basis for the disclosure.
<br />The accounting obligations of Business Associate hereunder shall not apply to (a) disclosures made for
<br />purposes of treahnent, payment, or health care operations (as defined in the Privacy Rule), (b) disclosures
<br />made to the individual who is requesring the accounting, (c) disclosures made prior to April 14, 2003, (d)
<br />disclosures made to law enforcement officers, conectional institutions, or for national security purposes, (e)
<br />disclosures incidental to a use or disclosure otherwise permitted or required as provided in 45 CFR 164.502,
<br />(~ pursuant to an authorization as provided in 45 CFR 164.508, (g) as part of a limited data set in
<br />accordance with 45 CFR 164.514(e).
<br />13. Books and Records. Business Associate shall make its internal practices, books, and records relating to the
<br />use and disclosure of PHI received from the Plan, or created or received by Business Associate on behalf of
<br />the Plan, available to the Secretary and to the Plan for purposes of determining the Plan's compliance with
<br />HIPAA, the Privacy Rule, and other applicable federal and/or state law. Business Associate shall notify the
<br />Plan immediately of any such requests and shail pravide the Plan with a copy of the request and any
<br />documents or information provided in response to such requests.
<br />14. Termination. Upon learning of any pattern of improper uses or disclosures by Business Associate that the
<br />Plan determines amounts to a material breach of Business Associate's obligations under this Addendum, the
<br />Plan shall promptly notify Business Associate in writing as to the nature and extent of such breach, and shall
<br />provide Business Associate a reasonable amount of time to cure such breach. A reasonable amount of time
<br />shall depend on the nature and extent of the breach, shall be clearly stated in the notice, but in no case shall
<br />the period for cure be less than 30 days: Notwithstanding the foregoing, should the Plan determine that the
<br />breach is incurable, or that Business Associate has repeatedly engaged in such impermissible uses or
<br />disclosures despite prior norice, the Plan may have the Plan Sponsor immediately terminate the Agreement
<br />to which this Addendum applies, upon written notice to Business Associate, without damages or liability to
<br />the Plan Sponsor or the Plan.
<br />15. Return of PHI Upon Termination. At temunation of the Agreement, Business Associate shall retum or
<br />destroy all PHI received from the Plan, or created by Business Associate on behalf of the Plan, that Business
<br />Associate maintains in any form. Business Associate shall retain no copies of such PHI. Upon request of
<br />the Plan, Business Associate shall provide a written certification of the return and/or destruction of the PHI.
<br />ff the parties agree that the return or destruction of such PHI by Business Associate is not feasible, then
<br />Business Associate shall continue to extend the protections required hereunder to the PHI for as long as it
<br />maintains the PHI. Further, Business Associate shall limit any further use or disclosure of the PHI to those
<br />purposes that make its return or destruction infeasible. This provision shall survive the termination of this
<br />Agreement.
<br />16. Prohibition against Sale or Marketing of PHI. Except as otherwise provided in Section 13405 of the
<br />HITECH Act, Business Associate shall not (a) directly or indirectly receive remuneration in
<br />exchange for any PHI of an individual; or (b) use or disclose PHI for any purpose related directly or
<br />indirectly to any marketing or marketing communication.
<br />B. Additional Permissible Uses and Disclosures of PHI bv Business Associate. Subject to the foregoing
<br />provisions, and in addition to the use and disclosure by Business Associate of PHI authorized elsewhere in this
<br />Addendum, Business Associate may use and disclose PHI for the following additional purposes:
<br />1. As necessary for data aggregation purposes relating to the health care operations of the Plan, but only as
<br />separately authorized by the Plan in writing,
<br />2. As necessary for data aggregation purposes of Business Associate, but only if the PHI is de-identified
<br />pursuant to 45 CFR 164.514,
<br />3. For the proper internal management and administration of Business Associate,
<br />4. To carry out the legal responsibilities of Business Associate, and
<br />Page 4 of 8
<br />Fachibit C~- North Carolina - BA Addendum 9/201 I
<br />
|