Orange County NC Website
required by law or for the purpose for which it was disclosed to the person, and (2) Business <br /> Associate will be notified by such person of any instances of which it becomes aware in which the <br /> confidentiality of the PHI has been breached. <br /> c. Data Aggregation. Business Associate may use and disclose PHI received by Business <br /> Associate in its capacity as Business Associate of Covered Entity to provide Data Aggregation <br /> services relating to the health care operations of Covered Entity only with permission of the <br /> Covered Entity. <br /> 4. Nondisclosure. <br /> a. As Provided in Agreement. Business Associate shall not use or further disclose Covered <br /> Entity's PHI otherwise than as permitted or required by this Agreement. <br /> b. Disclosures Required By Law. Business Associate shall not, without prior written consent of <br /> Covered Entity, disclose any PHI on the chance that such disclosure is required by law without <br /> notifying Covered Entity so that the Covered Entity shall have an opportunity to object to the <br /> disclosure and to seek appropriate relief. If Covered Entity objects to such a disclosure, Business <br /> Associate shall refrain from disclosing the PHI until Covered Entity has exhausted all alternatives <br /> for relief. Business Associate shall require reasonable assurances from persons receiving PHI in <br /> accordance with Section 3b that such persons will provide Covered Entity with similar notice and <br /> opportunity to object before disclosing PHI on the chance that such disclosure is required by law. <br /> c.Additional Restrictions. If Covered Entity notifies Business Associate that Covered Entity has <br /> agreed to be bound by additional restrictions on the uses or disclosures of Covered Entity's PHI <br /> pursuant to HIPAA or the HIPAA Regulations, Business Associate shall be bound by such <br /> additional restrictions and shall not disclose Covered Entity's PHI in violation of such additional <br /> restrictions. <br /> 5. Safeguards,Reporting,Mitigation and Enforcement. <br /> a. Safeguards. Business Associate shall maintain a comprehensive written information privacy <br /> and security program that includes administrative, technical and physical safeguards that <br /> reasonably and appropriately protect the confidentiality, integrity and availability of any electronic <br /> PHI it creates, receives, maintains or transmits on behalf of Covered Entity. In addition to any <br /> safeguards specifically set forth in this Agreement, Business Associate shall use any and all <br /> appropriate safeguards to prevent use or disclosure of Covered Entity's PHI otherwise than as <br /> provided by this Agreement. <br /> b. Business Associate's Agents. Business Associate shall not disclose PHI to any agent or <br /> subcontractor except with the prior written consent of Covered Entity. Business Associate shall <br /> ensure that any agents, including subcontractors, to whom it provides PHI received from, or <br /> created or received by Business Associate on behalf of, Business Associate agree in writing to be <br /> bound by the same restrictions and conditions that apply to Business Associate with respect to <br /> such PHI including appropriate safeguards. Business Associate shall be fully liable to Covered <br /> Entity for any acts, failures or omissions of the Agent in providing the services as if they were the <br /> Business Associate's own acts,failures or omissions,to the extent permitted by law. <br /> c. Reporting. Business Associate shall report to Covered Entity within twenty-four (24) hours <br /> any use or disclosure of Covered Entity's PHI in violation of this Agreement or applicable law of <br /> which it becomes aware. <br /> d. Mitigation. Business Associate shall have procedures in place to mitigate, to the maximum <br /> extent practicable, any deleterious effect from any use or disclosure of Covered Entity's PHI in <br /> violation of this Agreement or applicable law. <br /> e. Sanctions. Business Associate shall have and apply appropriate sanctions against any <br /> employee, subcontractor or agent who uses or discloses Covered Entity's PHI in violation of the <br /> Agreement or applicable law. <br /> Page 16 <br />